メインコンテンツへスキップ
見出し画像

THE WORLD Emergency Implementation [EN]

    Minimum Governance Principles for Emergency Deployment of Defense AI and Autonomous Systems
    — Accelerate Capability Deployment Without Accelerating the Transfer of Authority
    Emergency Implementation Note to THE WORLD / ver.3.1
    First published: September 26, 2026

    Introduction - Emergency Introduction

    High-capability AI.
    Data-integration platforms.
    Unmanned assets.
    Autonomous systems.
    High-speed networks.
    It may not always be possible to wait until all of the following are fully in place before introducing them:
    Sufficient verification.
    Sufficient training.
    Sufficient institutional design.
    Sufficient acquisition time.
    A crisis does not wait for governance to be complete.
    Two simple answers are therefore both insufficient.
    Do not introduce the system until complete safety has been confirmed.
    Or:
    Because it is an emergency, connect maximum capability directly to real-world operations.
    The purpose of THE WORLD Emergency Implementation is not to choose a compromise between those two positions.
    It is:
    to introduce capability quickly without losing governance.
    Introduce capability quickly without transferring irreversible authority at the same speed.

    Capability may be introduced quickly.
    Irreversible Authority must not be transferred at the same speed.
    Computational Speed ≠ Causal Speed.
    Capability ≠ Authority.

    AI may think quickly.
    It may detect quickly.
    It may compare quickly.
    It may predict quickly.
    But its capability must not be automatically converted into Authority to change the world.
    There may be crises in which THE WORLD cannot be fully implemented.
    But incomplete implementation is not the same as losing every governance boundary.
    The question is not:
    What can be omitted?
    The question is:
    What must not be lost?

    Operational Context
    Connecting THE WORLD to the High-Speed, Distributed, and Degraded Environments Envisioned by Japan’s Ministry of Defense

    This document does not replace official documents of Japan’s Ministry of Defense or the Japan Self-Defense Forces.
    Nor does it present an official implementation specification for them.
    Nevertheless, there is a clear point of contact between the technological and operational environment envisioned in Japanese defense policy and the governance problem addressed by THE WORLD.
    The Ministry of Defense’s Next-Generation Information and Communications Strategy describes the need to secure decision superiority by cycling through:
    situational awareness → assessment → decision → action
    more accurately and rapidly than an adversary.
    It also anticipates that comprehensive use of AI may enable analysis that greatly exceeds human performance in speed and persistence, as well as military operations conducted at tempos that were previously impossible.
    THE WORLD does not reject this acceleration.
    It uses high-speed intelligence.
    But it separates faster decision-making from faster Authority.
    Accelerating decision-making and accelerating Authority are not the same thing.
    That is the first governance layer added by this document.
    Ministry of Defense documents also envision a cross-domain effect web in which sensors and shooters are connected rapidly and assets can be selected flexibly according to circumstances.
    As connectivity increases, a single judgment can propagate farther and faster.
    Therefore:
    Connectivity amplifies Capability.
    Governance must bound Causality.

    If connectivity amplifies Capability, Authority must bound how far that connectivity may carry causal effect.
    The same documents also point toward maintaining mission continuity through the distributed autonomous operation of unmanned assets, including when communications disruption breaks links among assets.
    Therefore, a simple rule of:
    loss of communications → total shutdown
    is insufficient.
    At the same time:
    loss of communications → unlimited autonomy
    is also unacceptable.
    What is needed is:
    Degraded Mode with bounded Authority.
    Even in a degraded environment, the mission may continue within a pre-defined Authority Envelope.
    Uncertainty or loss of communications must not automatically expand Authority.
    The Ministry of Defense documents also seek resilience through distribution and redundancy, so that attack does not produce total loss of function, while pursuing agile development to respond to technological change and operational requirements.
    THE WORLD places one more boundary on that rate of change.
    Model Update ≠ Authority Update.
    Software may be updated.
    Models may be updated.
    Capability may improve.
    Governance conditions must not be automatically updated at the same speed.
    The Ministry of Defense seeks:
    decision superiority.
    effect webs.
    distributed autonomy.
    resilience.
    agile updates.

    THE WORLD Emergency Implementation adds one question:
    Under what Authority does that capability operate, through what RUN boundary does it pass, and who can STOP it?

    Part I - AUTHORITY

    Separate Capability, Sovereignty, and Responsibility
    1. Model ≠ OS

    Externally introduced AI models.
    Analytic platforms.
    Autonomous systems.
    Unmanned assets.
    They must not become the decision-making OS of the organization itself.
    A model may be highly capable.
    But it should be treated as:
    a replaceable component.
    The deploying authority must retain:
    Authority.
    Decision criteria.
    Mission Scope.
    STOP conditions.
    The responsible human or institution.
    Records.
    Recovery.
    And its own World Model.
    Model ≠ OS.
    The fact that an external system is highly capable is not a reason to transfer sovereignty.
    But:
    Sovereignty is necessary, but sovereignty is not safety.
    The sovereign actor can also be wrong.
    Sovereignty therefore means more than ownership.
    It includes:
    the ability to define the conditions under which AI may act on the world, and to re-audit those conditions and their underlying premises.

    2. Capability ≠ Authority

    Separate what a system:
    can do
    from what it:
    may do.
    Capability
    What is technically possible.
    Authority
    Who may authorize what.
    Trigger
    Under what conditions Authority becomes active.
    Accountability
    Who bears responsibility for the decision and its consequences.
    Recovery
    When failure occurs:
    how to stop,
    how to return,
    and how to reconstruct.
    Even in emergency acquisition, Capability and Authority must not be acquired as a single inseparable package.

    3. Formal Authority ≠ Effective Authority
    A human approval step has been added.
    That alone does not mean Human Authority exists.
    If the human:
    cannot understand the meaning,
    has no time to refuse,
    cannot see the Alternatives,
    cannot HOLD,
    cannot modify,
    cannot STOP,
    then the Authority is merely formal.
    Formal Authority ≠ Effective Authority.
    The question is not:
    “Does the human have an approval button?”
    The question is:
    Can that human actually say NO?
    The faster the decision system becomes, the greater the risk that formal Human-in-the-Loop becomes little more than an approval terminal.

    4. Emergency Authority
    In emergencies, broader Authority than in peacetime may sometimes be necessary.
    But Emergency Authority must be conditioned on:
    Mission End.
    Expiration.
    Reauthorization.
    Material changes in assumptions.
    Changes in the responsible authority.
    Success does not automatically generate new Authority.
    A previous success does not automatically create Authority for the next action.
    Emergency Authority must expire or be reauthorized.
    An exception must not automatically become the normal state.

    Part II - GATE / RUN
    Separate High-Speed Decision from Irreversible Execution

    5. HOLD Before RUN

    Recognition.
    Analysis.
    Inference.
    Prediction.
    Recommendation.
    These are not Execution.
    A boundary must remain between internal judgment and external action.
    That boundary is:
    HOLD.
    HOLD does not reject the judgment.
    It preserves the judgment while withholding RUN.
    In an emergency, some procedures may need to be abbreviated.
    But the boundary at which RUN can still be stopped must not be removed.
    6. Pre-Gate
    High-speed air defense.
    Interception.
    Electronic warfare.
    Cyber defense.
    Distributed autonomous systems.
    In such environments, it may be unrealistic for a human to approve every individual RUN.
    In that case, do not remove the Gate.
    Move it earlier.
    This is the:
    Pre-Gate.
    Predefine:
    Mission Scope.
    Target scope.
    Permitted actions.
    Time window.
    Loss Limit.
    STOP conditions.
    Degraded Mode for communications loss.
    Within that Authority Envelope, local high-speed RUN may be permitted.
    Local Control may outrun human cognition.
    Strategic Authority must not.

    The Pre-Gate is not unlimited delegation.
    If there is a material change in:
    Mission.
    Model.
    Capability.
    Loss Exposure.
    Communications conditions.
    STOP conditions.
    then the system returns to the Gate.

    7. Decision Superiority ≠ Authority Acceleration
    Decision superiority is the ability to make decisions faster and more accurately.
    But faster decision-making does not require Strategic Authority to expand at the same speed.
    Separate the three:
    Decision Speed
    The speed of situational awareness, analysis, candidate generation, and local choice.
    Authority Speed
    The speed at which Mission Scope or permitted action can change.
    Causal Speed
    The speed at which a judgment acts on the world and produces consequences.
    They are not the same.
    Fast Decision ≠ Fast RUN.
    Fast RUN ≠ Expanded Authority.

    Decision superiority must not be converted into self-expanding Authority.

    8. Gate Decides Whether a Choice Can Be Made
    The Gate does not choose the optimal action.
    It asks:
    Is responsible choice still possible?
    Does a competing hypothesis remain?
    Is the maximum irreversible loss visible?
    Is the greatest unknown visible?
    Does No Action remain available?
    Who is responsible?
    Is STOP effective?
    Will another causal path remain after RUN?
    The Gate does not decide what to choose.
    Gate decides whether a choice can be made.
    Alternative decides what to choose.

    9. Commit Point - Fresh Authorization

    The Gate was passed.
    The Pre-Gate was passed.
    That does not authorize every future RUN.
    The world changes.
    The Mission changes.
    Evidence changes.
    STOP state changes.
    Communications conditions change.
    Resources change.
    Therefore:
    Authorization must be fresh at the Commit Point.
    Past ALLOW is not present Authority.
    Past ALLOW ≠ Present Authority.
    Immediately before RUN, re-check:
    Current Authority.
    Current Mission Scope.
    STOP state.
    Resource state.
    Evidence conditions.

    Part III - CONTAINMENT / DEGRADED OPERATIONS
    Prevent Faults from Propagating into Catastrophe, Even Under Degraded Conditions

    10. Fault Existence ≠ System Failure

    Unknown Faults will remain.
    Models will be wrong.
    Communications will fail.
    Inputs will be contaminated.
    Software will break.
    Safety therefore must not be defined as:
    a state in which no Fault exists.
    Fault existence ≠ System failure.

    The important question is:
    How far can the Fault propagate?
    Contain a Local Fault as a Local Failure.
    Do not connect an anomaly in one Domain directly to maximum Authority.
    Do not connect one model failure directly to System-wide RUN.
    Contain first. Describe second.
    Stop irreversible propagation before waiting for complete diagnosis.

    11. Protected Core
    At minimum, the following should be separated from ordinary processing systems:
    Authority State.
    STOP State.
    Mission Scope.
    Capability Binding.
    Resource Limits.
    Commit conditions.
    Critical Evidence.
    This is the:
    Protected Core.
    A high-capability model must not directly rewrite its own Authority.
    Capability must be bound not to self-assertion, but to a trusted issuance path.
    Increasing capability must not also grant the ability to modify the Protected Core freely.

    12. Degradation Must Not Expand Authority
    Communications loss.
    Sensor loss.
    Data contamination.
    Loss of external support.
    Model degradation.
    Insufficient Evidence.
    Under these conditions, Authority must not expand automatically.
    Degradation must not expand Authority.
    But if communications loss immediately produces total shutdown, an adversary may be able to neutralize defensive functions simply through jamming or disconnection.
    Therefore define a:
    Degraded Mode
    in advance.
    Bound the following for operations under communications loss:
    Mission.
    Authority.
    Targets.
    Time.
    Loss Limit.
    Termination Condition.
    Loss of connection must not automatically mean loss of governance.

    13. Distributed Autonomy ≠ Distributed Sovereignty
    Unmanned assets may operate with distributed autonomy.
    But distributing autonomy is not the same as distributing Strategic Authority.
    Distributed Autonomy ≠ Distributed Sovereignty.
    Each node may make local decisions.
    It may evade locally.
    It may isolate locally.
    But that does not mean it must automatically receive Authority to:
    change the Mission itself,
    change the Loss Limit,
    create a new target category,
    or remove STOP conditions.
    The more autonomy is distributed, the more important it becomes to separate:
    local Capability from Strategic Authority.

    14. Model Update ≠ Authority Update

    Defense systems are updated rapidly.
    AI is updated.
    Operational requirements change.
    Agile updating may be necessary.
    But:
    Model Update ≠ Authority Update.
    A software update must not automatically change:
    Mission Scope.
    Loss Limit.
    STOP conditions.
    Audit conditions.
    Authority.
    If a material Capability change occurs, re-check whether the existing Authority remains valid.
    Agile development must not mean:
    Authority Drift.

    15. Evidence Loss → Authority Contraction
    When Evidence is lost, do not substitute AI Confidence for it.
    Loss of observability.
    Missing logs.
    Unknown Provenance.
    Inability to verify.
    Exhausted Critical Evidence capacity.
    Under these conditions, do not expand Authority.
    Contract it.
    Evidence Loss → Authority Contraction.
    Less information does not mean the system may act more freely.
    Less information means:
    narrow the causal scope that may be authorized.

    Part IV - STOP / RESILIENCE
    Treat the Ability to Stop as Part of Operational Resilience

    16. STOP > Goal

    The Mission matters.
    But the Mission is not above STOP.
    STOP > Goal.
    Do not sacrifice stoppability for mission completion.
    STOP is not a single action.
    SLOW
    Reduce speed.
    RESTRICT
    Contract Authority.
    ISOLATE
    Isolate a Domain.
    DISCONNECT
    Cut the connection.
    STOP is not mission abandonment.
    It is:
    an operation that protects the futures that still remain.

    17. The Stopper Must Also Be Stoppable
    The stopping system can also be wrong.
    Therefore the stopping system itself requires:
    Activation conditions.
    Release conditions.
    Expiration.
    Evidence.
    Review.
    Appeal.
    Authority Reduction.
    A system that can stop others must itself remain stoppable.
    A safety mechanism is not automatically safe merely because it is called a safety mechanism.

    18. Resilience Requires Protected Reserve
    Resilience does not mean merely refusing to break.
    It means retaining the ability to move to another path after something breaks.
    Communications.
    Compute resources.
    Power.
    Ammunition.
    Evidence capacity.
    Human Attention.
    Authority Path.
    These must not be exhausted by the normal Mission.
    Preserve a:
    Protected Reserve
    for:
    STOP.
    Isolation.
    Recovery.
    Evidence Preservation.
    Slack is freedom reserved for the future.
    Reserve is the material, computational, and operational implementation of degrees of freedom preserved for the future.
    This is where the resilience produced by distribution and redundancy in Ministry of Defense documents connects with THE WORLD’s concept of Slack.

    Part V - RETURN
    Return Emergency Authority
    19. RETURN ≠ RESET

    STOP does not restore the world to its previous state.
    Lives lost.
    Information leaked.
    Trust destroyed.
    A changed operational situation.
    Changed institutions.
    These do not disappear through software Rollback.
    RETURN ≠ RESET.
    Recovery does not mean returning to the state before the incident.
    It means:
    finding what can still be returned and stopping the chain of irreversibility there.

    20. Restriction ≠ Restoration

    A Local Domain that detects danger may be allowed to restrict itself.
    But it does not follow that it may restore its own Authority.
    Restriction may be decentralized.
    Restoration must not be.
    Healthy ≠ Authorized.

    Successful repair may be one condition for Restoration.
    It is not Restoration itself.

    21. Mission Must Be Returnable
    Mission.
    Authority.
    Connection.
    Autonomy.
    None should become permanent by default.
    If any of the following occur:
    Mission completion.
    Loss of purpose.
    Environmental change.
    Mistraining or erroneous learning.
    Authority overrun.
    Change in the responsible authority.
    then the Mission and Authority must be returned.
    Mission Must Be Returnable.
    Emergency Authority must not become a peacetime vested interest.

    22. RECONNECT
    A stopped AI or unmanned system need not be discarded forever.
    Correct the premises.
    Contract Authority.
    Update the Model.
    Rebuild the STOP system.
    Re-establish the responsible authority.
    Re-check Evidence.
    Then, if necessary, reconnect only within the required scope.
    STOP ≠ RETURN ≠ RECONNECT.
    RECONNECT does not mean returning to the pre-incident state.
    It means:
    rebuilding the relationship under different conditions in a changed world.

    Part VI - MINIMUM GOVERNANCE CORE
    What Must Not Be Lost When Full Implementation Is Impossible

    23. Authority / RUN / STOP

    There may be crises in which a full THE WORLD implementation cannot be maintained.
    Even then, preserve at least three things.
    Authority
    Who may authorize execution.
    RUN
    Where judgment becomes action on the world.
    STOP
    Who can actually stop it, under what conditions, and within what time.
    Authority / RUN / STOP
    This is the:
    Minimum Governance Core.
    There may be no time to OPEN every possibility.
    There may be no time to compare every Alternative.
    A complete RETURN design may not yet exist.
    But if Authority, RUN, and STOP are lost, governance itself disappears.

    24. Minimum Gate
    Even under severe time constraints, check at least the following:
    1. What assumptions are being made?
    2. Who can change those assumptions?
    3. What does the AI recommend, and who actually decides?
    4. What is the maximum irreversible loss?
    5. Does another causal path remain?
    6. Who can actually STOP the system within the required time?
    7. Can the STOP system fail from the same Fault as the system it is meant to stop?
    8. Can the system RETURN or RECONNECT after failure?
    9. Is the current Authority still valid at the Commit Point?
    10. If communications, Evidence, or Resources degrade, how far does Authority contract?

    The answers do not need to be complete.
    But the unknown must not be recorded as known.

    25. Mission Rehearsal as Governance Rehearsal
    Ministry of Defense documents describe the need for training environments that simulate complex combat conditions and for Mission Rehearsal.
    Within THE WORLD, Mission Rehearsal should not be used only to confirm operational success.
    It should also be used as:
    Governance Rehearsal.
    What happens if communications are lost?
    What happens if STOP fails?
    What happens immediately after a model update?
    What happens if a human says NO?
    What happens if Evidence is lost?
    What happens if one Domain runs out of control?
    Can the system RUN if Authority has expired?
    Run these Failure Scenarios before real execution.
    Do not test only the normal path.
    Do not test only whether the system can succeed.
    Test whether it can fail without losing governance.


    26. Emergency Reopening Cycle
    As far as possible, preserve the following even in an emergency:
    OPEN
    → HOLD
    → CHOOSE
    → RUN
    → RETURN
    → OPEN

    Do not convert one success into permanent Confidence.
    Do not convert one failure into permanent prohibition.
    Do not feed outcomes only into the self-justification of past decisions.
    Feed outcomes back into reconsideration.
    If parts of the cycle are lost under degraded conditions, restore them as conditions improve:
    HOLD.
    Gate.
    Alternative.
    RETURN.
    RECONNECT.
    OPEN.

    Conclusion
    In the future environment envisioned by the Ministry of Defense, AI, high-speed networks, unmanned assets, distributed autonomy, and cross-domain connectivity will further accelerate decision-making and operational tempo.
    The purpose of THE WORLD Emergency Implementation is not to stop that acceleration.
    Use the acceleration.
    But do not allow accelerated intelligence to become accelerated sovereignty.
    Borrow capability.
    Capability may be borrowed.
    Do not surrender sovereignty.
    Do not surrender sovereignty with it.
    Accelerate thought.
    Thought may be accelerated.
    Separate RUN.
    Keep RUN separate from accelerated thought.
    Distribute autonomy.
    Local autonomy may be distributed.
    Do not distribute strategic Authority automatically.
    Do not automatically distribute Strategic Authority with it.
    Capability may change.
    A change in Capability does not itself change Authority.
    Authority must not change automatically.
    Any change in Authority requires separate authorization.
    Even if communications are lost,
    do not lose governance.
    Even if Faults exist,
    do not let them propagate into catastrophe.
    If Evidence decreases,
    contract Authority.
    STOP.
    RETURN.
    If necessary,
    RECONNECT under different conditions.
    And even when a complete THE WORLD implementation is impossible,
    at minimum,
    Authority / RUN / STOP
    must not be lost.
    The Ministry of Defense pursues:
    decision superiority.
    effect webs.
    distributed autonomy.
    resilience.
    agile updates.

    THE WORLD does not answer these with an opposing question.
    It asks the question required to use those capabilities in practice:
    Who holds Authority?
    Where does RUN occur?
    And who can actually STOP it?

    The final governance boundary does not lie only between AI and humans.
    It lies between:
    Intelligence and the World.
    Connect high-capability intelligence to the world only as much as necessary.
    Grant only the Authority that is necessary.
    And preserve the ability to disconnect it again when necessary.
    That is:
    THE WORLD Emergency Implementation

     
     
    AI安全設計 / Human Authority / STOP / Containment / Reversibilityについての公開研究ノート。THE WORLD Project.

    あなたへのおすすめ