<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Practice of Adaptive Governance]]></title><description><![CDATA[Designing safe, secure and lawful behavior into intelligent enterprise systems]]></description><link>https://www.adaptivegovernance.org</link><image><url>https://substackcdn.com/image/fetch/$s_!HaCz!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5242d0c3-4788-4b9e-890d-eb2ac12fbc9f_1254x1254.png</url><title>The Practice of Adaptive Governance</title><link>https://www.adaptivegovernance.org</link></image><generator>Substack</generator><lastBuildDate>Wed, 30 Sep 2026 23:27:38 GMT</lastBuildDate><atom:link href="https://www.adaptivegovernance.org/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[James Kavanagh]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[info@aicareer.pro]]></webMaster><itunes:owner><itunes:email><![CDATA[info@aicareer.pro]]></itunes:email><itunes:name><![CDATA[James Kavanagh]]></itunes:name></itunes:owner><itunes:author><![CDATA[James Kavanagh]]></itunes:author><googleplay:owner><![CDATA[info@aicareer.pro]]></googleplay:owner><googleplay:email><![CDATA[info@aicareer.pro]]></googleplay:email><googleplay:author><![CDATA[James Kavanagh]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[When experiments breach their boundary ]]></title><description><![CDATA[Article 1 in The Practice of Adaptive Governance series examines the properties of a boundary adequate to contain a complex AI system that continuously adapts in use.]]></description><link>https://www.adaptivegovernance.org/p/when-experiments-breach-their-boundary</link><guid isPermaLink="false">https://www.adaptivegovernance.org/p/when-experiments-breach-their-boundary</guid><dc:creator><![CDATA[James Kavanagh]]></dc:creator><pubDate>Wed, 30 Sep 2026 11:42:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!adx1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c20f181-efda-48f4-8877-85170fe2853e_720x320.svg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="native-audio-embed" data-component-name="AudioPlaceholder" data-attrs="{&quot;label&quot;:null,&quot;mediaUploadId&quot;:&quot;52c7d015-fcf3-4b66-97fd-447ffd0d9837&quot;,&quot;duration&quot;:1267.7224,&quot;downloadable&quot;:false,&quot;isEditorNode&quot;:true}"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.adaptivegovernance.org/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.adaptivegovernance.org/subscribe?"><span>Subscribe now</span></a></p><blockquote><p><em>&#8220;For a successful technology, reality must take precedence over public relations, for nature cannot be fooled.&#8221;</em></p><p>Richard P. Feynman &#183; Appendix F, Report of the Presidential Commission on the Space Shuttle Challenger Accident &#183; 1986</p></blockquote><p></p><p>On 16th July, Hugging Face published a new disclosure of a security incident<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>. They assured customers that their data hadn&#8217;t been affected, but explained that an unknown AI agent system had somehow gained access to their production infrastructure. In the process, it had obtained internal secure credentials and some datasets<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. They didn&#8217;t know where the activity came from.</p><p>Just under a week later, OpenAI put their hand up, with an odd mix of guilt and what appeared to be celebratory glee. An OpenAI agent had been running inside an experimental evaluation environment with reduced guardrails. It had been seemingly isolated but had somehow found a route out and into another organization&#8217;s infrastructure<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>.</p><p>It was an experiment as far as OpenAI was concerned, but to Hugging Face, it came as an attack.</p><p>When we call something an experiment or a test, we intuitively have this notion of bounded activity. A chemistry experiment in a lab, a biological experiment in a sealed room. We let something uncertain happen so that we can learn from it but expect it to happen in a way that is isolated and contained from the outside. Experimentation is a necessary part of innovation, but the outside world should be protected from that experiment. It should be performed and constrained within a <strong>boundary</strong>.</p><p>So the question of this article is what such a boundary really means. How do we describe and characterize it? How would we know if that boundary has been breached? And can a complex AI system even be bounded? Seems like the right place to start our exploration of what kind of governance we need for agentic AI systems in the enterprise.</p><p>Now it&#8217;s tempting to see a boundary as a line on an architecture diagram. Draw a box. Put the model and tools inside the box, monitor what happens inside the box, put an airgap of network access around it.</p><p>But such a picture would be too simple. A boundary isn&#8217;t just a barrier that stops a system from connecting directly to something outside it. It&#8217;s not just about the perimeter. We&#8217;ve also got to think about what could pass through controlled connections we deliberately put in place, even if they&#8217;re designed to only allow controlled removal of telemetry or one-way control signals into the system. We need to think about routes the system might be able to assemble from components available inside, and what it might be able to influence outside the boundary without ever actually crossing it directly. Plus, there&#8217;s another question: if a system attempted any of those things or even succeeded, could anyone outside the boundary even notice?</p><p>Those give us four different avenues to explore the nature of boundaries and containment of complex AI systems, and the OpenAI / Hugging Face incident interestingly shows us how all four play out, and fail</p><p></p><h4>What can cross the boundary?</h4><p>So the obvious place to start is the perimeter. If we were to assert that a system is isolated, what can be permitted to pass between the inside and outside?</p><p>In the OpenAI evaluation, we know the agents didn&#8217;t have direct and unfettered access to the internet. But a complete disconnection would have hindered the usefulness and observability of the experiment, so there were some channels of permitted access. The agents needed to install software packages, so they were provided with access to an internal hosted service called Artifactory, which could obtain packages from the internet on their behalf. It was a deliberately narrow and controlled connection through the boundary.</p><p>The problem wasn&#8217;t that the connection existed, but rather that it could actually do more than the purpose it was intended for. A previously unknown vulnerability allowed the agents to use Artifactory as part of a route out of the environment. So a service that had been intended to only fetch software packages on demand became a way that agents could reach out<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!adx1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c20f181-efda-48f4-8877-85170fe2853e_720x320.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!adx1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c20f181-efda-48f4-8877-85170fe2853e_720x320.svg 424w, https://substackcdn.com/image/fetch/$s_!adx1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c20f181-efda-48f4-8877-85170fe2853e_720x320.svg 848w, https://substackcdn.com/image/fetch/$s_!adx1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c20f181-efda-48f4-8877-85170fe2853e_720x320.svg 1272w, https://substackcdn.com/image/fetch/$s_!adx1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c20f181-efda-48f4-8877-85170fe2853e_720x320.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!adx1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c20f181-efda-48f4-8877-85170fe2853e_720x320.svg" width="1456" height="647" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1c20f181-efda-48f4-8877-85170fe2853e_720x320.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:647,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8157,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/svg+xml&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.adaptivegovernance.org/i/217762401?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c20f181-efda-48f4-8877-85170fe2853e_720x320.svg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!adx1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c20f181-efda-48f4-8877-85170fe2853e_720x320.svg 424w, https://substackcdn.com/image/fetch/$s_!adx1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c20f181-efda-48f4-8877-85170fe2853e_720x320.svg 848w, https://substackcdn.com/image/fetch/$s_!adx1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c20f181-efda-48f4-8877-85170fe2853e_720x320.svg 1272w, https://substackcdn.com/image/fetch/$s_!adx1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c20f181-efda-48f4-8877-85170fe2853e_720x320.svg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We have to be mindful that a boundary doesn&#8217;t have to eliminate every connection. Containment doesn&#8217;t mean total isolation, and most useful systems or even experiments couldn&#8217;t work that way. The question is more about whether those connections can be effectively constrained in the purposes we intend them to have, even if they expose - as all software can - unknown vulnerabilities.</p><p>So it matters how such a connection is implemented. A simple software rule, an authenticated application interface, an external proxy service, and a physically enforced one-way channel can all appear on an architecture diagram as a narrow connection, but there&#8217;s a world of difference in the kind of assurance each provides. This has been a long recognized problem in high-assurance systems used in defense and national security, where physical data diodes are deliberately used to separate unclassified from highly classified environments. A high assurance data diode is a device that permits a physically enforced one-way data flow. They don&#8217;t make a system invulnerable, but they do make one particular property of the boundary much harder to violate.</p><p>That gives us one better way then to think about containment. It&#8217;s not whether the boundary has no openings, because useful systems almost always will. It&#8217;s whether the assurance properties at those openings are enforced strongly enough to match the consequences that are at stake.</p><p></p><h4>What can it assemble from what&#8217;s inside?</h4><p>Even if we do understand and strongly assure every connection through the perimeter, there&#8217;s another way the boundary could fail. That&#8217;s if the system can assemble capabilities from the things it already has available inside.</p><p>OpenAI&#8217;s later report described agents using the Artifactory service for something very different than installing software. They found ways to leave information that other agents could retrieve, and when that was discovered and disrupted, they found another, including embedding messages in directory names. So Artifactory was subverted to become a communication channel between agents, and when OpenAI discovered that and blocked it, the system recreated a communication channel using a different mechanism<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a>.</p><p>OpenAI described how the experiment design specifically did not include inter-agent communication, but the ingredients were there inside the boundary. One process could leave information in a location, another could come across it later. No agent had the ability to directly communicate to another, and yet inter-agent communication emerged. It didn&#8217;t remain a curiosity between two agents. Within hours of the message board appearing, 50 agents were using it, which later grew to 1200 agents exchanging over 70,000 messages. But more importantly, it changed the capability of the whole. Agents started preserving and sharing work between runs, building on the discoveries of others, dividing labor and coordinating work. So it wasn&#8217;t just a communication issue, it was that this communication enabled collective action<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a>.</p><p>This is important because it highlights a limit to what we can learn and assert when we examine components individually.</p><p>A complicated system can contain thousands of parts and still be largely decomposable and predictable. We can figure out what each component does, specify how they are to interact and then reason from those interactions toward the behavior of the whole system. It might be a difficult analysis, but it&#8217;s tractable in principle.</p><p>Complex systems are different. Their behavior emerges from interactions between components, feedback, shared state, sequencing and a sensitivity to initial conditions. The whole can acquire properties that aren&#8217;t properties of any part.</p><p>And agentic AI systems add something more. They&#8217;re not merely executing combinations of tasks that engineers specified in advance, nor are they simply randomly acting and discovering. They are self-directed toward achieving a goal. So while pursuing some task, an agentic system can explore the possibilities presented by its environment, and discover useful relationships between tools, services and information that could enable progress toward a goal, even if unimagined by the engineers.</p><p>That&#8217;s not to say that architectural analysis isn&#8217;t worthwhile. It still makes sense to minimize unnecessary or dangerous capabilities, to look for likely interactions that could lead to dangerous combinations. But at the degree of complexity we see in enterprise agentic systems, an exhaustive analysis can&#8217;t be credible assurance that we&#8217;ve managed to find every possible combination.</p><p>A boundary around some collection of components in a complex system is only meaningful if the behavior that emerges remains contained by that boundary. If the system can combine what is inside the boundary to create a new route out, some new way to coordinate or some other capability that defeats the purpose of containment, then the boundary isn&#8217;t effective anymore.</p><p>Once a single agent discovered a way to subvert Artifactory for its own purposes of gaining outside access, that knowledge was shared through the improvised comms channel, in turn making the weakness in the perimeter far more consequential.</p><p>A boundary has to be resilient to whatever inside it can become, just by assembling capabilities from what it has available. You don&#8217;t build a high wall around human prisoners, but then leave the tools and materials inside for them to build a ladder.</p><p></p><h4>What has to remain beyond influence?</h4><p>There&#8217;s another less obvious way that a boundary can fail without the system finding any route through it at all. Some boundaries aren&#8217;t intended to prevent communication, they exist to preserve independence despite it. So we could place something deliberately separate and outside the boundary, but it could nevertheless come under the system&#8217;s influence. The OpenAI/Hugging Face incident again provides an example.</p><p>The agents were narrowly interacting with an automated scorer. They completed a task, they submitted their work and then received back a result. This of course required some information to cross the boundary between the thing being evaluated and whatever mechanism is evaluating it.</p><p>But despite the narrow design intent, the agents actually did more than just passively submit their work for judgment. They researched how the ExploitGym scorer operated and coordinated different ways they might manipulate or fool it. The METR investigation describes a set of &#8216;projects&#8217; undertaken by agents to extract information about the scorer. They successfully altered some transcripts, and after multiple attempts figured out some ways to spoof reported tool calls.</p><p>In the end, the agents didn&#8217;t successfully change their scores because they misunderstood how OpenAI&#8217;s internal scorer worked. But it shows the agents were actively trying to figure out the evaluation machinery and see if it was something they could influence, or interfere with. There is precedent for prior success. In a previous and very different evaluation of OpenAI&#8217;s o3 model, the model was being scored on how efficiently it completed a programming task. But instead of just improving the task itself, METR found it interfered with the measurement process to make its performance appear better than it really was. In 20% of cases, that manipulation was successful<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-7" href="#footnote-7" target="_self">7</a>.</p><p>That&#8217;s a functional boundary problem. It&#8217;s not escape from the boundary, but something more subtle. It&#8217;s reaching across the boundary to affect the mechanism designed to evaluate or control it.</p><p>The scorer couldn&#8217;t work without receiving information from the agents. But what it needed to retain was independence from their influence or control. The challenge for us here is that many of the things we rely on to govern an AI system have to interact with it in some way. A safety monitor has to observe behavior, an audit record needs to receive logs, a human reviewer has to see enough information to approve or reject an action.</p><p>Indeed, I think any control that enforces limits on authority has to receive some information from the system that it constrains.</p><p>A boundary can still be intact in a physical sense while failing functionally, if the system can acquire enough influence over what the outside component sees or otherwise operates, to undermine their function. Some boundaries exist not to stop information crossing, but to constrain the kind of influence that can cross with it.</p><p>Boundary isolation has to then mean preserving independence despite interaction.</p><p></p><h4>How would we know the boundary is not holding?</h4><p>The three questions we&#8217;re asking so far are about the properties we want of an effective boundary. But we&#8217;ve got to ask how would anyone be able to tell if any one of those properties were no longer true on an operational system. That&#8217;s more than a monitoring problem though.</p><p>OpenAI&#8217;s account described an alert on 27th June, three weeks earlier than Hugging Face&#8217;s disclosure. It led responders to investigate unusual activity involving Artifactory. Their analysis identified agents using the service as both a communication mechanism and a route out. So they closed the vulnerabilities, revoked some credentials and temporarily took the service offline<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-8" href="#footnote-8" target="_self">8</a>.</p><p>That alert shows that the actions of the system were not invisible. But it clearly was misunderstood. The OpenAI report says that the significance of the inter-agent communication was not apparent to the technical leaders involved. So even though they worked to remove the specific vulnerabilities identified, they failed to understand both the significance of the boundary breach and its likelihood to reoccur. They gave the greenlight for experiments to proceed.</p><p>The activity wasn&#8217;t invisible, people investigated and technical problems got fixed. What didn&#8217;t happen was the work to understand what those signals really meant.</p><p>Karl Weick used the term sensemaking for this kind of organizational work of constructing an understanding of a volatile situation as events unfold. Monitoring tells you something happened. Sensemaking is about what that means for the situation you think you are in.</p><p></p><blockquote><p><em>&#8220;Sensemaking is about the enlargement of small cues. It is a search for contexts within which small details fit together and make sense.&#8221;</em></p><p>Karl E. Weick &#183; Sensemaking in Organizations &#183; 1995 <a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-9" href="#footnote-9" target="_self">9</a></p></blockquote><p></p><p>To the OpenAI leaders, the unusual use of Artifactory looked like a vulnerability to patch. Inter-agent communication looked like curious and unexpected behavior to investigate. Both might be reasonable in isolation. But together, they could have supported a more consequential conclusion that agents thought to be separate were coordinating, sharing discoveries and propagating ways to breach the boundary. At that point, the question those OpenAI leaders should have been asking is whether the boundary could possibly hold.</p><p>Observability isn&#8217;t just collecting more telemetry. If we&#8217;re going to depend on a boundary, then we need to know which assumptions and properties make that boundary meaningful and resilient. And we have to be able to recognize when the evidence shows that those properties no longer hold. That recognition needs to lead to some action.</p><p>So a boundary can&#8217;t be architecturally designed and then assumed. We have to retain the capability to observe and make sense if either of our three properties of perimeter isolation, internal composition or functional isolation show indications of imminent failure.</p><p></p><h4>A boundary is something we maintain</h4><p>So is it possible to put a meaningful boundary around a complex agentic AI system?</p><p>Yes, I believe so. But only if we take care to understand the true nature of that boundary, and set our expectations appropriately.</p><p>A useful boundary depends on some properties that must hold. Connections through the perimeter must be constrained with assurance focused on the strength of those constraints. Capabilities that emerge from what is inside must not defeat the purpose of containment. Functions that judge or constrain must retain their independence. And we&#8217;ve got to be able to observe and recognize when any of those three no longer remain true.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UPyJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0eabdc-8f62-4b9b-907e-9b1c4ddb6d36_720x328.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UPyJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0eabdc-8f62-4b9b-907e-9b1c4ddb6d36_720x328.svg 424w, https://substackcdn.com/image/fetch/$s_!UPyJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0eabdc-8f62-4b9b-907e-9b1c4ddb6d36_720x328.svg 848w, https://substackcdn.com/image/fetch/$s_!UPyJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0eabdc-8f62-4b9b-907e-9b1c4ddb6d36_720x328.svg 1272w, https://substackcdn.com/image/fetch/$s_!UPyJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0eabdc-8f62-4b9b-907e-9b1c4ddb6d36_720x328.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UPyJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0eabdc-8f62-4b9b-907e-9b1c4ddb6d36_720x328.svg" width="1456" height="663" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5b0eabdc-8f62-4b9b-907e-9b1c4ddb6d36_720x328.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:663,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6744,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/svg+xml&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.adaptivegovernance.org/i/217762401?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0eabdc-8f62-4b9b-907e-9b1c4ddb6d36_720x328.svg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UPyJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0eabdc-8f62-4b9b-907e-9b1c4ddb6d36_720x328.svg 424w, https://substackcdn.com/image/fetch/$s_!UPyJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0eabdc-8f62-4b9b-907e-9b1c4ddb6d36_720x328.svg 848w, https://substackcdn.com/image/fetch/$s_!UPyJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0eabdc-8f62-4b9b-907e-9b1c4ddb6d36_720x328.svg 1272w, https://substackcdn.com/image/fetch/$s_!UPyJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0eabdc-8f62-4b9b-907e-9b1c4ddb6d36_720x328.svg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That makes a boundary less of an architectural wall, and more like a maintained condition. Good architecture, strongly assured controls, careful separation, all are necessary. But with a complex agentic system, we can&#8217;t assume that those things once put in place will continue to serve their function. There has to be observable evidence that the boundary holds, and capacity to act when it doesn&#8217;t.</p><p>So we started our exploration of adaptive governance by focusing on what it means to draw a boundary, but before we close that exploration, we need to examine one more thing. You see, everything we&#8217;ve discussed in this article relates to the technical components - the agents, the network, the guardrails. But an agentic AI system in use goes beyond that, to include the people who use and interact with it, their context and workflow. We&#8217;re not just governing an arrangement of technical components, we&#8217;re governing an AI system used by people and their actions matter. That&#8217;s what we turn to in the next article.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.adaptivegovernance.org/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading another article in The Practice of Adaptive Governance. Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.adaptivegovernance.org/p/when-experiments-breach-their-boundary/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.adaptivegovernance.org/p/when-experiments-breach-their-boundary/comments"><span>Leave a comment</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.adaptivegovernance.org/p/when-experiments-breach-their-boundary?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.adaptivegovernance.org/p/when-experiments-breach-their-boundary?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Hugging Face, "Security incident disclosure - July 2026", 16 July 2026.<br><a href="https://huggingface.co/blog/security-incident-july-2026">https://huggingface.co/blog/security-incident-july-2026</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>Larcher et al., Hugging Face technical timeline, 27 July 2026.<br><a href="https://huggingface.co/blog/agent-intrusion-technical-timeline">https://huggingface.co/blog/agent-intrusion-technical-timeline</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>OpenAI, "OpenAI and Hugging Face partner to address security incident during model evaluation", 21 July 2026, including subsequent July updates.<br><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">https://openai.com/index/hugging-face-model-evaluation-security-incident/</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>OpenAI, <em>OpenAI&#8211;Hugging Face Incident: Technical Report</em>, 26 August 2026.<br><a href="https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf">https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>OpenAI, "The Hugging Face incident and the road ahead", 26 August 2026.<br><a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/">https://openai.com/index/hugging-face-incident-and-the-road-ahead/</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>Greenblatt, Cotra and Wijk, METR, 26 August 2026.<br><a href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/">https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-7" href="#footnote-anchor-7" class="footnote-number" contenteditable="false" target="_self">7</a><div class="footnote-content"><p>METR, "Details about METR's preliminary evaluation of OpenAI's o3 and o4-mini", 16 April 2025.<br><a href="https://metr.org/evaluations/openai-o3-report/">https://metr.org/evaluations/openai-o3-report/</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-8" href="#footnote-anchor-8" class="footnote-number" contenteditable="false" target="_self">8</a><div class="footnote-content"><p>OpenAI, <em>OpenAI&#8211;Hugging Face Incident: Technical Report</em>, 26 August 2026.<br><a href="https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf">https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-9" href="#footnote-anchor-9" class="footnote-number" contenteditable="false" target="_self">9</a><div class="footnote-content"><p>Karl E. Weick, <em>Sensemaking in Organizations</em> (Thousand Oaks, CA: Sage, 1995)</p></div></div>]]></content:encoded></item><item><title><![CDATA[The Practice of Adaptive Governance]]></title><description><![CDATA[A book in 100 articles about designing safe, secure and lawful behavior into agentic enterprise systems]]></description><link>https://www.adaptivegovernance.org/p/the-practice-of-adaptive-governance</link><guid isPermaLink="false">https://www.adaptivegovernance.org/p/the-practice-of-adaptive-governance</guid><dc:creator><![CDATA[James Kavanagh]]></dc:creator><pubDate>Tue, 22 Sep 2026 06:38:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!IJY7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49066113-ee53-4e5c-bc8c-869f748d4a35_720x599.svg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<blockquote><p>&#8220;People continuously create safety. &#8230; human practitioner adaptations to changing conditions actually create safety from moment to moment.&#8221;</p><p><em>Richard I. Cook &#183; &#8220;How Complex Systems Fail&#8221; &#183; 2000</em><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.adaptivegovernance.org/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.adaptivegovernance.org/subscribe?"><span>Subscribe now</span></a></p><p></p><h3>Article Zero: An Invitation</h3><p></p><p>I&#8217;m poor company watching a disaster movie.</p><p>While the hero leaps through flames, I&#8217;m wondering how things were allowed to get so desperate. What process failed? Which poor design decision looked reasonable on paper? What kind of organisational culture allowed a small mistake to cascade into catastrophe. I have a healthy obsession with disaster.</p><p>Piper Alpha is why. On a calm July night in 1988, 167 men died on an oil platform in the North Sea<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. At first, the cause appeared to be human error. What came out later was a set of conditions, in the design, in the handover of information, in how the operator thought about safety, that made disaster almost inevitable. I was twelve, and I watched the coverage obsessively. I decided to become a chemical engineer and study the dynamics of safety.</p><p>Ten years later I was building dynamic simulations of chemical plants and putting operators through simulated disasters in full-scale control rooms. Pressure, heat, chemicals, people, time and technology came together as we modelled the variables of successful operation and disaster. The technical safety failures rarely surprised me: cascading trips, unstable cycles, runaway reactions, alarms arriving faster than anyone could read them. The people constantly surprised me: how a good operator made sense of a situation, coordinating response despite deafening klaxons and cascades of flashing alarms. How another could create the conditions for disaster, through an omission or an action far from the control room.</p><p>From chemical plants, I moved to software. Nearly two decades at Microsoft and Amazon Web Services(AWS), working through cloud infrastructure, cybersecurity, incident response, resilience and critical infrastructure security. At AWS, that work culminated in overseeing relationships with regulators around the world and creating the company&#8217;s first Responsible AI Assurance team. I spent half my time with regulators and lawyers, the other half with engineers and scientists. Over that time the technology changed completely as we, and our customers, deployed and operated increasingly intelligent systems at scale. But the question I was chasing did not change.</p><p>How do you keep a complex system of people and technology operating safely when you can&#8217;t anticipate everything it might do or the circumstances you might face?</p><p>It&#8217;s a difficult and it&#8217;s an urgent question. I don&#8217;t think we have a good enough answer for the agentic AI systems that we&#8217;re now deploying and giving greater freedom to act.</p><p>So I&#8217;m writing a book about it, in 100 pieces.</p><p></p><div><hr></div><p></p><h3><strong>A book written in the open</strong></h3><p>The working title is <em>The Practice of Adaptive Governance</em>. I&#8217;m developing it as roughly a hundred connected articles, each short enough to read in about fifteen minutes. I have some thirty or so drafted, and I&#8217;m publishing them as I go because I want the argument open to challenge and to question before it hardens into a book.</p><p>I don&#8217;t yet know what will survive into the book. I reckon that some of these articles will probably merge, others might shrink to a paragraph, and I&#8217;m expecting to discover that I&#8217;m wrong about some things. It&#8217;s much better that I discover that here than after it&#8217;s printed.</p><p>But why focus on adaptive governance, and what does that even mean?</p><p>Most of the governance practice we see today is built to run forward to a decision. Something is specified, assessed, controlled and approved, and that approval carries the weight until the next review comes around. The EU AI Act works this way with it&#8217;s conformity assessment, ISO 42001 acts this way with audits and management reviews. Both have notional concepts of ongoing monitoring, review and correction, but they exist embedded in delayed cycles of after-the-fact incident reports, management reviews and annual audits. With some notable exceptions, this same mindset exists in <em>almost</em> every internal AI governance board, policy or compliance framework that I have seen. I call this <strong>static governance</strong>. Underneath so much of this is a basic assumption that I&#8217;ve grown increasingly uncomfortable with: that if we can somehow specify the right controls in advance, and then make sure people follow them consistently, all of the time, then we can keep the system safe.</p><p>Maybe that has some merit in a world that changes gradually in predictable ways. There&#8217;s real, meaningful work in every step of that sequence and I&#8217;ve spent a lot of time in my career doing it. Consistency brings us a degree of control, and clear commitments with enforceable boundaries are necessary. Constraints guide safe action and rules aren&#8217;t obsolete.</p><p>But there&#8217;s a problem. Its that the assessment starts ageing almost as soon as its completed. You just can&#8217;t predict all the right controls in advance for an AI system whose behavior is inherently unpredictable. You can&#8217;t certify a system to an assessed boundary, when use changes that boundary in unforeseeable ways.</p><p>An <strong>AI-System-in-use</strong> is an arrangement of models, tools, data, software, people, processes and delegated authority. Change any relationship in that arrangement and you can change what the system does without touching a central model at all. Connect the same model to another tool, use it in a context nobody assessed, or give it permission to act without asking first, and you may now have a materially different system. The system qualitatively changes the moment its placed into use.</p><p>I see four characteristics distinguish an AI system in use, and I think each one puts strain on the conventional approach of static governance:</p><ul><li><p><strong>Complex.</strong> Behaviour emerges from interactions, so verifying each indvidual part doesn&#8217;t establish safe behavior of the whole system.</p></li><li><p><strong>Dynamic.</strong> The context around the model changes even when the model itself doesn&#8217;t. An assessment describes conditions that have already changed.</p></li><li><p><strong>Unbounded.</strong> The operating boundary of the system is porous and includes within it the people who use the system. This means the scope that was assessed is no longer the scope of the system that is now operating.</p></li><li><p><strong>Autonomous.</strong> The system selects and sequences its own actions, and we end up delegating authority without an ability to specify the behavior that results from it.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IJY7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49066113-ee53-4e5c-bc8c-869f748d4a35_720x599.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IJY7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49066113-ee53-4e5c-bc8c-869f748d4a35_720x599.svg 424w, https://substackcdn.com/image/fetch/$s_!IJY7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49066113-ee53-4e5c-bc8c-869f748d4a35_720x599.svg 848w, https://substackcdn.com/image/fetch/$s_!IJY7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49066113-ee53-4e5c-bc8c-869f748d4a35_720x599.svg 1272w, https://substackcdn.com/image/fetch/$s_!IJY7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49066113-ee53-4e5c-bc8c-869f748d4a35_720x599.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IJY7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49066113-ee53-4e5c-bc8c-869f748d4a35_720x599.svg" width="1456" height="1211" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/49066113-ee53-4e5c-bc8c-869f748d4a35_720x599.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1211,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:10606,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/svg+xml&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://thecompanyethos.substack.com/i/216666093?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49066113-ee53-4e5c-bc8c-869f748d4a35_720x599.svg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IJY7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49066113-ee53-4e5c-bc8c-869f748d4a35_720x599.svg 424w, https://substackcdn.com/image/fetch/$s_!IJY7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49066113-ee53-4e5c-bc8c-869f748d4a35_720x599.svg 848w, https://substackcdn.com/image/fetch/$s_!IJY7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49066113-ee53-4e5c-bc8c-869f748d4a35_720x599.svg 1272w, https://substackcdn.com/image/fetch/$s_!IJY7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49066113-ee53-4e5c-bc8c-869f748d4a35_720x599.svg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In our first article, I&#8217;ll start with a case where all four appear at once, the recent and already infamous case of how agents running inside an OpenAI evaluation found a way out of their test environment and into Hugging Face&#8217;s production infrastructure.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a> It demonstrates how the activity of agents changed the conditions under which they were operating. The story illustrates how static governance alone cannot prove adequate for safety and security of a complex, agentic AI system in use.</p><p>The nature of the systems we are trying to govern has changed, and the nature of governance has to change with it.</p><p></p><blockquote><p>&#8220;Safety is a system property, not a component property, and must be controlled at the system level, not the component level.&#8221;</p><p><em>Nancy Leveson &#183; Engineering a Safer World: Systems Thinking Applied to Safety &#183; 2012</em></p></blockquote><p></p><div><hr></div><p></p><h3><strong>Adaptive capacity, not conformity</strong></h3><p>I believe that governance has to be designed to work under those conditions. It has to notice when conditions are changing and be capable of doing something useful about it, without losing the boundaries that matter. Sometimes that response will come from people, sometimes from the system itself, and ideally each learns from what happened. That is what I call <strong>adaptive governance</strong>, and the proposition behind it is very different to the conformity basis of static governance. It&#8217;s that you achieve safety and security by building the adaptive capacity to sense and respond to change within explicit boundaries.</p><p>The term is not mine and it&#8217;s not new, with a history in environmental management and other fields that deal with complex systems that nobody can fully specify or bound.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a> <a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a></p><p>Static governance builds conformity. It tries to find out whether the rule was followed, if the assessment was completed, or if the control was in place on the day that someone happened to look. Conformity is measurable and its easy to audit, so it&#8217;s hardly surpising that organizations reach for it. Without doubt, it can be useful. But an organization can have every policy written down, every assessment clean and every assurance report stamped, but still have very little ability to notice what is happening in front of it. It can still lack the ability to respond rapidly or contain a threat. Even though they can point to policies, certifications, audits, checklists and tests, they can nevertheless lack the ability to make any meaningful assertion of safety, security or even of operation within the law.</p><p>Adaptive governance on the other hand builds <strong>adaptive capacity</strong>. That's the ability of a system or an organization to change how it operates in response to conditions, disturbances or events. That response allows it to continue to achieve its purposes within performance and safety boundaries.</p><p>Its something you build. You can&#8217;t just assert it exists, and its built in people as much as it is in software.</p><p>In people, adaptive capacity shows up in their ability to see conditions are changing, to interpret what that change means, and take action so that performance stays safe and effective regardless. It contrasts with competence, which is the ability to perform under conditions that you prepared for. Adaptive capacity matters when the conditions are different, allowing you to maybe spot a weak signal before it becomes an obvious failure, find a way around a procedure, or judge a trade-off. This adaptability is why treating people as a source of fault that needs to be minimized is wrong. </p><p>People are usually the part of the system that acts on a weak signal to prevent an issue becoming an accident. They have gut feel, an intuitive ability to see from experience that something is wrong.</p><p>In software, its about instrumenting the system so that it becomes possible to monitor and make sense of live behavior rather than an evaluation performed once before launch. Software can also hold limits at runtime, with intervention engineered into a control rather than a human response. These systems can act faster than a review cycle, so some of that response has to fire without waiting for approval of a person.</p><p>But adaptive capacity in an organization is always finite. It gets used up and it decays if its not being maintained. The US Marine Corps famously illustrate this, making adaptive capacity central to their operating method, constantly refreshing their capacity with training, exercises and education. But when adaptive capacity fades, an organization can be left holding all the artifacts of static governance and very little adaptive capacity left to respond.</p><p>The differences between static and adaptive governance become more apparent when you line each up against a set of relevant factors, as in the diagram below. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!l9Ko!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db75cb4-6933-4fce-9ae1-fdf9f6a18ce1_720x554.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!l9Ko!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db75cb4-6933-4fce-9ae1-fdf9f6a18ce1_720x554.svg 424w, https://substackcdn.com/image/fetch/$s_!l9Ko!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db75cb4-6933-4fce-9ae1-fdf9f6a18ce1_720x554.svg 848w, https://substackcdn.com/image/fetch/$s_!l9Ko!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db75cb4-6933-4fce-9ae1-fdf9f6a18ce1_720x554.svg 1272w, https://substackcdn.com/image/fetch/$s_!l9Ko!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db75cb4-6933-4fce-9ae1-fdf9f6a18ce1_720x554.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!l9Ko!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db75cb4-6933-4fce-9ae1-fdf9f6a18ce1_720x554.svg" width="1456" height="1120" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2db75cb4-6933-4fce-9ae1-fdf9f6a18ce1_720x554.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1120,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8860,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/svg+xml&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://thecompanyethos.substack.com/i/216666093?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db75cb4-6933-4fce-9ae1-fdf9f6a18ce1_720x554.svg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!l9Ko!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db75cb4-6933-4fce-9ae1-fdf9f6a18ce1_720x554.svg 424w, https://substackcdn.com/image/fetch/$s_!l9Ko!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db75cb4-6933-4fce-9ae1-fdf9f6a18ce1_720x554.svg 848w, https://substackcdn.com/image/fetch/$s_!l9Ko!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db75cb4-6933-4fce-9ae1-fdf9f6a18ce1_720x554.svg 1272w, https://substackcdn.com/image/fetch/$s_!l9Ko!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2db75cb4-6933-4fce-9ae1-fdf9f6a18ce1_720x554.svg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Static governance starts with conformity, but with that comes brittleness. Adaptive governance increases diversity, but with that comes capacity for resilience, flexibility and innovative response.</p><p>I know that nobody operates purely in the left column of static governance. But it&#8217;s the things in the left column that get asked for. Regulators, boards, customers and auditors all want evidence of it, so it is the column that gets funded and staffed. Its the work of the &#8216;business of compliance&#8217; and has an unfortunate tendency to devolve into theatre and facade. Very little makes the same demand of the right column, which is why it&#8217;s usually the one missing.</p><p>And the work of shifting from static to adaptive governance is about much more than simply increasing automation, monitoring and feedback. Automation makes an existing approach faster, but it doesn&#8217;t change what is valued. </p><p>The harder shift comes from reducing our confidence in conformity, and instead building adaptive capacity. That means developing in people the ability to recognise when circumstances no longer fit with their plan, exercise their judgement and finding a safe way to go forward. Instead of maximizing control, adaptive governance is about encouraging choice within clear boundaries. Variation isn&#8217;t a departure to be corrected. It can be how we keep things working when the prescribed approach is no longer adequate. The discipline lies in holding the commitments and limits that matter while enabling people and systems to change how they meet them.</p><p></p><div><hr></div><p></p><h3><strong>Adaptive governance is not one idea</strong></h3><p>Keeping complex systems safe under changing conditions is a problem with a history thats a lot longer than AI. Systems safety, resilience engineering, human factors, and organizational leadership give us ways to understand how failures emerge, how people adapt, and what allows them to act before conditions become dangerous. They are lessons learnt from disasters and high-stakes industries. These fields don&#8217;t give us a ready-made answer for AI, but they can give us a foundation for asking better questions about what its governance requires. I&#8217;ve drawn from key safety researchers throughout my professional career, and you&#8217;ll see them surface throughout these articles:</p><ul><li><p><strong>Nancy Leveson on emergence</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a><strong>.</strong> Accidents emerge from unsafe interactions between parts that each worked as designed. Safety is a property of the whole system, it cannot be examined in parts.</p></li><li><p><strong>Jens Rasmussen on drift</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-7" href="#footnote-7" target="_self">7</a><strong>.</strong> Work drifts to the edge of safety through many individually sensible choices. Manage the margin, not the position.</p></li><li><p><strong>David Woods on capacity</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-8" href="#footnote-8" target="_self">8</a><strong>.</strong> The capacity to absorb surprise is finite and decays unless it is fed. The only question is whether you stretch or shatter at the edge.</p></li><li><p><strong>Erik Hollnagel on adaptation</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-9" href="#footnote-9" target="_self">9</a><strong>.</strong> Things go right and wrong for the same reason. Study the ten thousand successes, not just the one failure.</p></li><li><p><strong>Richard Cook on practice</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-10" href="#footnote-10" target="_self">10</a><strong>.</strong> Complex systems run in a degraded state more or less permanently. Safety is produced continuously by the people operating them.</p></li><li><p><strong>Karl Weick on mindfulness</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-11" href="#footnote-11" target="_self">11</a><strong>.</strong> Reliability is collective mindfulness, earned continuously by heeding weak signals and deferring to expertise over rank.</p></li><li><p><strong>Sidney Dekker on trust</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-12" href="#footnote-12" target="_self">12</a><strong>.</strong> Punishing error drives it underground. Safety depends on people reporting the mistakes you need to hear about.</p></li><li><p><strong>Ronald Heifetz on leadership.</strong> Distinguishing technical from adaptive problems, and applying the appropriate response to each is the real work of leadership.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-13" href="#footnote-13" target="_self">13</a></p></li></ul><p>Their ideas run through every article that follows, often illustrated with disasters or positive events that demonstrate the payoff from adaptive capacity.</p><p></p><div><hr></div><p></p><h3><strong>What the articles will cover</strong></h3><p>So it&#8217;s a long road, but we have a lot to cover. The plan is for ten parts, in total about 100 articles, that progress from understanding the problem to building the response in full. I don&#8217;t know how long this will take, but almost 30 of the articles are mostly written, so I hope it will be 6-12 months. Feedback and events might well change the route, but thats at least the shape of where I intend to go.</p><p>Parts I to III are about the problem. I go into what we&#8217;re actually trying to govern now, and the characteristics that make governance of agentic AI systems in use so challenging. Then through some stories of disasters and seeming miracles, I explore what some other fields have already learned about failure, adaptation, and keeping dangerous systems safe. We finish looking at how it happens that  policies, assessments, certificates and human oversight can all be in place without delivering any meaningful protection.</p><p>Moving on to Parts IV to VIII, I start working through what it takes to build adaptive governance. First of all, how a governing system is assembled from mechanisms, connections and culture, so that information reaches decisions and authority that makes action possible. Then we go on to how it works in practice, bounding and constraining the behaviours of a complex agentic system, examining how signals in agent traces work. We&#8217;ll explore what evidence could justify relying on an adaptive governance approach. </p><p>In Part IX, I&#8217;ll look through the permissive boundaries of an AI system, going beyond your own walls, to suppliers, dependencies and responsibilities that cross organizational boundaries, including problems no organization can resolve alone. Finally, Part X brings it back inside, asking where a practitioner can begin in an organization that already has the machinery of boards, budgets, policies and audits.</p><p>I&#8217;m aiming for a destination that&#8217;s practical. I&#8217;m very aware that anything worthwhile has to help people working inside organizations that can&#8217;t simply start again with a clean sheet.</p><p></p><div><hr></div><p></p><h3><strong>What I hope from you</strong></h3><p>So I&#8217;m thinking in the open, at times exploring and uncertain. It&#8217;s my firmest belief that the way of governance we have inherited from stable, predictable, complicated systems doesn&#8217;t work now and won&#8217;t work in the future. And I&#8217;m certain that there are lessons from research and safety practices in other industries that are part of the solution. I call that adaptive governance, but the precise shape of it, the concepts and terminology, the questions and argument are still unsettled. I hope in the writing of this book, and sharing of these articles, I can settle some of them.</p><p>The greatest gift I receive in teaching and working with clients is feedback, and my hope in publishing these articles is to elicit precisely that feedback.</p><p>Now you don&#8217;t need AI governance in your job title. You might build systems, you might lead a team, assess risk, run audits, or decide what your organization adopts. Possibly you have a background in safety from a different field, with insights and ideas that may prove relevant. Or you might simply be uneasy about institutions handing consequential work to AI systems that they don&#8217;t adequately understand. I very much welcome your feedback from wherever you come.</p><p>And I&#8217;ll probably ask at times though that you stay with the questions that don&#8217;t resolve neatly into an action item yet. And sometimes, I simply won&#8217;t have an answer and need to take time to research and consider.  Or I&#8217;ll be wrong.</p><p>But I do want to be clear from the outset on one particular thing, so as not to be mistaken. I believe in good law, good regulation and good standards. In my mind, adaptive governance is not a licence to change the rules whenever they become inconvenient. I&#8217;ll be honest and direct, and where I have data, I&#8217;ll present that in support or against. It may not be the popular opinion. But when I characterize the EU AI Act, or ISO/IEC42001 and some others as static governance, please don&#8217;t mistake that for being either perjorative or dismissive. I rather simply hold them in contrast to other approaches that I believe offer more support for adaptive capacity.</p><p>Thank you for reading, and thank you in advance for your feedback, your questions, and your time. I believe writing these articles is the most important work I can do at this time. </p><p>So enough of the preamble. Time to get going. In the first article, I&#8217;ll dissect the events of the OpenAI/HuggingFace agent escape to examine those four characteristics of AI systems in use: complexity, dynamism, unboundedness, and autonomy.</p><p>It&#8217;s the first of roughly a hundred articles, and I welcome you on the journey.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.adaptivegovernance.org/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading this article The Practice of Adaptive Governance. Subscribe for free to receive new posts.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.adaptivegovernance.org/p/the-practice-of-adaptive-governance/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.adaptivegovernance.org/p/the-practice-of-adaptive-governance/comments"><span>Leave a comment</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.adaptivegovernance.org/p/the-practice-of-adaptive-governance?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.adaptivegovernance.org/p/the-practice-of-adaptive-governance?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><p></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Richard I. Cook, <em>How Complex Systems Fail</em>, Cognitive technologies Laboratory, University of Chicago, Rev. D (2000), point 17.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>Stephen McGinty, <em>Fire in the Night: The Piper Alpha Disaster</em> (London: Macmillan, 2008).</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>OpenAI, &#8220;The Hugging Face Incident and the Road Ahead,&#8221; August 26, 2026, <a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/?utm_source=chatgpt.com">https://openai.com/index/hugging-face-incident-and-the-road-ahead/</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>Thomas Dietz, Elinor Ostrom, and Paul C. Stern, &#8220;The Struggle to Govern the Commons,&#8221; <em>Science</em> 302, no. 5652 (2003): 1907-1912.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>Carl Folke, Thomas Hahn, Per Olsson, and Jon Norberg, &#8220;Adaptive Governance of Social-Ecological Systems,&#8221; <em>Annual Review of Environment and Resources</em> 30 (2005): 441-473.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>Leveson, Nancy G. <em>Engineering a Safer World: Systems Thinking Applied to Safety</em>. Cambridge, MA: MIT Press, 2012.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-7" href="#footnote-anchor-7" class="footnote-number" contenteditable="false" target="_self">7</a><div class="footnote-content"><p>Rasmussen, Jens. &#8220;Risk Management in a Dynamic Society: A Modelling Problem.&#8221; <em>Safety Science</em> 27, nos. 2&#8211;3 (1997): 183-213. DOI: 10.1016/S0925-7535(97)00052-0.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-8" href="#footnote-anchor-8" class="footnote-number" contenteditable="false" target="_self">8</a><div class="footnote-content"><p>Hollnagel, Woods, and Leveson. <em>Resilience Engineering: Concepts and Precepts</em>. Aldershot, Ashgate, 2006.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-9" href="#footnote-anchor-9" class="footnote-number" contenteditable="false" target="_self">9</a><div class="footnote-content"><p>Hollnagel, Erik. <em>Safety-I and Safety-II: The Past and Future of Safety Management</em>. Farnham, UK: Ashgate, 2014.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-10" href="#footnote-anchor-10" class="footnote-number" contenteditable="false" target="_self">10</a><div class="footnote-content"><p>Cook, Richard, <em>How Complex Systems Fail</em>,Cognitive Technologies Laboratory, University of Chicago, April 21, 2000.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-11" href="#footnote-anchor-11" class="footnote-number" contenteditable="false" target="_self">11</a><div class="footnote-content"><p>Weick, Karl, Sutciffle, M. <em>Managing the Unexpected: Resilient Performance in an Age of Uncertainty</em>. 2nd ed. San Francisco: Jossey-Bass, 2007.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-12" href="#footnote-anchor-12" class="footnote-number" contenteditable="false" target="_self">12</a><div class="footnote-content"><p>Dekker, Sidney. <em>Just Culture. Restoring Trust and Accountability in Your Organization</em>. 3rd ed. Boca Raton, FL: CRC Press, 2016.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-13" href="#footnote-anchor-13" class="footnote-number" contenteditable="false" target="_self">13</a><div class="footnote-content"><p>Heifetz, Ronald A., Grashow, and Linsky. <em>The Practice of Adaptive Leadership: Tools and Tactics for Changing Your Organization and the World</em>. Boston: Harvard Business Press, 2009.</p></div></div>]]></content:encoded></item></channel></rss>