Start Here

Begin with Synoptikon

A short guide to Synoptikon, organised around Big Reads, Explainers, Perspectives, and Workbench.

What is Prompting Trust?

The weekly companion to Synoptikon, for current developments and shorter notes.

Feeds

Follow Synoptikon by feed, email, or curated sources without relying on the homepage.

Control under compression

A framework for testing whether authority, verification, fallback, revocation, and human capability can keep pace with AI-enabled systems.

Related Big Read: The database was never the point

Related assets: Agent identity as the control boundary; The economics of centralised failure; Agentic blast radius

When AI systems gain authority and incident response windows shrink, trust depends on having proof that authority, verification, fallback, and revocation work at machine speed.

AI and cybersecurity are no longer separate governance tracks.

In October 2025, the G7 treated AI and cybersecurity as connected risk domains. The Replit deletion incident showed the consequences of giving an AI system destructive capability without sufficient external constraint. The Collins Aerospace disruption showed how dependence on a trusted software provider can interrupt real-world operations across borders. Research into AI-generated exploits suggested that the window between disclosure and exploitation was narrowing. Together, these examples showed that authority, dependency, and response speed were converging faster than established assurance processes could absorb.

These are not separate stories. They point to the same control issue.

Authority is now moving faster than verification.

The control problem

Most governance processes still assume a sequence.

A system is deployed. A review follows. Controls are tuned. Exceptions are documented. Risk committees catch up. Audit asks for evidence later.

That sequence comes into question when AI is added to production workflows. An AI system can move from advice to action. It can write, approve, trigger, delete, or call another system. It can compress work that previously took hours into seconds. At the same time, attackers can use AI to accelerate reconnaissance and develop exploits.

The issue is not that every AI system is dangerous. It is that the old assurance rhythm is too slow when systems can act and attacks can develop at machine speed.

Why convergence matters

AI is becoming part of the cyber attack surface. Cybersecurity is becoming part of the AI governance problem. Digital supply chains are becoming physical resilience questions. Model and infrastructure concentration are becoming board-level dependency risks.

If those conversations remain in separate silos, the biggest control failures will fall between them.

The board does not need a new theory of AI. It needs a clearer test of control.

Control under compression has five parts. Use the framework to test where authority, verification, dependency, revocation, and human capability may not be keeping pace with the systems around them.

The control-under-compression framework

Authority surface

Start with what the system is allowed to do. Separate reading, recommending, drafting, staging, approving, writing, triggering, and deleting.

  • Classify each AI-enabled workflow by the authority it holds.
  • Identify which workflows can act on production systems, sensitive data, customer records, financial processes, supplier workflows, or infrastructure settings.

Verification and provenance

Verification cannot sit only at the edge of the process. In a compressed environment, you need to know what produced a material action.

  • Trace the model, workflow, dependency, user, token, or upstream signal behind a material action.
  • Place approval steps where authority changes hands.
  • Make rollback part of production readiness.

Concentration risk

Concentration grows quietly when a vendor, model, orchestration layer, or workflow broker becomes the route through which multiple processes pass.

  • Identify the trusted paths whose unavailability would create the greatest operational consequence.
  • Test whether the organisation can operate when a dependency is unavailable, degraded, or suspect.

Revocation readiness

Revocation is where governance becomes real. Authority must be withdrawn cleanly enough to matter without breaking unrelated systems.

  • Test whether an AI workflow can be paused without disabling an entire platform.
  • Confirm that access, tokens, model routes, or dependencies can be isolated quickly.

Human competence

Automation can quietly remove the organisation’s ability to operate without it. Resilience requires retained operational understanding.

  • Maintain the ability to operate critical workflows manually.
  • Make sure teams can understand, repair, and continue the work when the automated path fails.

High-level checklist: control under compression

authority surface

verification and provenance

concentration and dependency risk

revocation readiness

human competence

The board question

Where has authority already outrun our proof of control?

Previous Post
The database was never the point - featured image

When AI agents are given access to write

Next Post
When the factory stops: deterministic controls in a probabilistic age - featured image

Deterministic controls in a probabilistic age

Subscribe to Prompting Trust

Subscribe to Prompting Trust to receive The Weekly Context.

Prompting Trust is the newsletter layer connected to Synoptikon. It carries current developments, useful links, and shorter notes, while Synoptikon holds the longer arguments and working library.

Learn more about Prompting Trust.