# Extremist Elicitation, Remediation, and Classification
**Elicitation, Remediation, and the Machinery That Must Also Clear the Innocent**
Something specific happens when a powerful person says a thing previously understood to sit outside the boundary of acceptable public speech. The statement does not merely communicate an opinion. It changes the informational environment around everyone listening, and it does so in a way that can be measured. People who already held the view become more willing to express it. People who opposed it organize against it. Journalists amplify it by reporting it. Platforms measure the response. Political organizations discover constituencies they did not know were reachable. Organizations at the violent margin interpret the statement as permission, recognition, recruitment opportunity, or evidence that their position is migrating toward the center. Security and law-enforcement organizations, meanwhile, observe who responds, how, who clusters around whom, which communities form, and which individuals cross from rhetoric into planning.<!--more-->
The previous version of this essay treated that phenomenon through the metaphor of immunity, and the metaphor was doing more work than it could bear. An immune system is a _figure_. What is actually running is a **classifier operating on adversarial inputs over a social graph, with a base-rate problem and a cost matrix** — and once that substitution is made, every proposition the older essay asserted emotionally becomes available mechanically, including the ones that are least comfortable.
The second correction is about the unit of analysis, and it matters more. The interesting question was never whether a particular famous person is secretly running an operation. That framing is both unprovable and uninteresting, and it makes the argument hostage to the biography of individuals. **The systems surrounding a high-salience political actor have their own objectives, their own instrumentation, and their own downstream consumers, and those systems do not require the actor's intent in order to function.** A statement enters an environment already populated by ranking algorithms optimizing engagement, by commercial surveillance vendors selling behavioral profiling to police departments, by threat-assessment units with statutory duties, by researchers, by advertisers, by foreign services, by extremist recruiters, and by other political actors — each of which reads the response for something different. The stimulus has one author. The instruments reading it have many, and they are not coordinated.
That is the reframing the evidence supports, and it turns out to be the stronger claim rather than the weaker one.
## Why a Screening Layer Exists at All
The immune framing arrives out of nowhere in most treatments of this subject, as though societies spontaneously developed an interest in monitoring their members. They did not. The screening apparatus exists because of a structural feature of the postwar settlement, and the feature is predictable in advance from what is known about the animal being governed.
The human capacity for coalitionary violence, dominance-striving, and status contest is documented rather than assumed, and it is universal while its expression is conditional. Richard Wrangham's distinction is the operative one: **reactive aggression** is hot, provoked, threat-triggered, and human self-domestication down-regulated it dramatically; **proactive aggression** is cold, planned, coalitional, instrumental, and we retained it. After 1945 the organizing imperative of an entire architecture was to make organized industrial slaughter structurally unavailable, and one arm of that architecture was the construction of consequence-bounded contest environments in which the species' contest drive could be exhausted without bodies. The doctrine was published rather than whispered — William James on a moral equivalent of war, George Orwell in December 1945 calling international sport war minus the shooting, Norbert Elias and Eric Dunning on sport as a mimetic release valve engineered into social life — and the institutions followed, from RAND to the biennial Olympic Truce resolutions the General Assembly has passed since 1993.
Reactive aggression is metabolizable by substitution. The stadium, the ladder, the parlay, and the raid boss genuinely absorb hot dominance impulse, because that impulse seeks arousal, contest, and resolution and does not much care about substrate. Proactive coalitionary aggression is only partially absorbable, and the partition is where this essay's subject lives. Decompose what a planner wants and it separates into a plan against a live opponent, coalition, asymmetry and surprise, status for cunning, **consequence**, and **grievance**. The first four are fully absorbable, which is why the enclosure runs a planner tier older and higher-status than the spectator tier, running from _Kriegsspiel_ through chess and _Diplomacy_ to capture-the-flag competition, where a real system really falls and the consequence component is genuinely delivered. The last two are not absorbable. A symbolic victory is a complete answer to the desire to have outplayed someone and no answer at all to the conviction that a specific wrong demands a specific correction in the world.
So the residue is not defined by planning capacity. **It is defined by non-substitutability** — the participant whose grievance has stopped accepting symbolic settlement. And this yields the proposition the older essay needed and did not have: the screening layer is not an appendage bolted onto an open society by an anxious state. It is the enclosure's **structural necessity**. A system that channels aggression must also detect who is not being channeled, or it is a very large blind spot with a scoreboard on it. That does not make any particular screening implementation legitimate. It means the argument about screening cannot be won by pretending the function is gratuitous.
## What the Apparatus Delivers
Before any of the costs are counted, the credit side has to be stated plainly, because a great deal of writing on this subject is dishonest by omission — treating detection as an abstraction with civil-liberties consequences rather than as a set of operations with outcomes that can be counted in living people.
The Director General of MI5 stated publicly in October 2024 that since March 2017 the Security Service and counter-terrorism police had together disrupted **43 late-stage attack plots**, roughly three-quarters linked to Islamist extremism and one quarter to extreme right-wing terrorism, and he described what late-stage means in the plainest available terms: some of those plotters were attempting to acquire firearms and explosives **in the final days of planning mass murder**. Nineteen of those disruptions occurred from the start of 2020 alone, alongside intervention in many hundreds of developing threats. In the same period Counter Terrorism Policing received roughly 22,000 public contacts a year through the Anti-Terrorist Hotline and its online equivalent, with one in five judged relevant enough to pass to officers. The Home Office reports that Prevent has supported **nearly 6,000 people to move away from a pathway to radicalisation since 2015**. Operation Trojan Shield, alongside its 800 arrests, disrupted some twenty threats to kill. The Secret Service's National Threat Assessment Center has published a study of sixty-seven averted plots against schools, examining what made interruption possible in each.
Those are not abstractions. Each disrupted late-stage plot is a building that did not come down and a number of funerals that did not happen, and the number is unknowable only in the direction of being larger than anyone will ever prove. **A person who intends to detonate a device in a federal building is not a hypothetical against which civil liberties must be weighed in the abstract. He is the specific object the apparatus exists to find, and finding him early enough is the entire justification for its existence.** Any analysis that treats the screening layer primarily as an intrusion has quietly assumed the interdictions away, which is an easy assumption to make from inside a society where the interdictions keep working.
This has a direct consequence for how the rest of this essay should be read. The argument that follows is not a case against detection. It is a case about **calibration** — about what the score licenses, at what confidence, with what appeal, and against whom the error falls — conducted by someone who wants the instrument to exist, wants it to work, and wants it aimed accurately, because an instrument that is badly calibrated fails in both directions at once. It generates false positives that fall on people who will never harm anyone, and it wastes finite attention that should have been spent on the person acquiring the precursor chemicals.
## Trajectory Is Evidence
The objection that early intervention means punishing people for crimes they have not committed is usually stated too crudely on both sides, and getting it right authorizes more enforcement rather than less.
Begin with what is often overlooked. **The pathway toward a mass-casualty attack is paved with completed offenses.** Long before the device functions, the person building it has typically committed conspiracy, attempt, solicitation, material support, unlawful acquisition or possession of precursors, false statements in furtherance, and a range of substantive crimes that exist precisely so the state need not wait for detonation. Inchoate liability is centuries old and exists for this exact purpose. Each of those forty-three late-stage disruptions terminates in a prosecution for conduct that had already occurred — those individuals were not neutralized as pre-criminals, they were arrested as criminals, early.
But that observation alone understates what the classifier contributes, and understating it concedes too much. **Scattered early offenses are not legible as a pathway without the pattern.** A fertilizer purchase is a farm supply run. A rental truck is a move. A drive past a building is a commute. Photographs are a hobby. Each is innocuous alone, and every one of them is innocuous in the overwhelming majority of instances — which is exactly why the trajectory assessment is doing indispensable work rather than decorative work. It is what converts a set of individually unremarkable acts into a recognizable escalation profile matching the sequences that preceded Oklahoma City and every comparable event since. Radicalization trajectory, communication pattern, fixation, leakage, target research, and the tempo of movement toward action are not soft supplements to hard evidence. **They are what makes the hard evidence mean anything**, and a system forbidden to use them would be reduced to noticing bombings after they happen.
So the correct formulation is not that pre-guilt does not exist. It is that **trajectory is a multiplier on conduct, never a substitute for it.** The law already works this way in several registers: intent and motive are routinely proven by pattern; escalation governs the intensity of investigative attention; risk assessment legitimately informs prioritization, bail, supervision conditions, and monitoring; and threat-assessment doctrine treats the accumulation of behaviors in context as the actionable object rather than any single behavior. Someone whose communications, associations, acquisitions, and reconnaissance describe a coherent escalation toward mass violence is properly treated as more urgent, more thoroughly investigated, and more forcefully interdicted than someone whose isolated act looks the same in a spreadsheet. That is trajectory being factored in with escalations and violations, exactly as it should be.
What may never happen is the substitution of the estimate for the act — the assignment of consequence to a predicted disposition unaccompanied by conduct. That is the input a T4 registration form accepts and the input that produced fifteen thousand detentions in a single week in Aksu. **The line is not before the attack versus after it, which forces a false choice between permitting the bombing and inventing a status offense. The line is conduct plus trajectory versus trajectory alone.**
From which the operative rule follows, and it should govern every implementation discussed below. **The severity of the licensed action scales with the evidentiary weight of the conduct, with trajectory setting the urgency and the depth of the look.** That principle explains why one apparatus can legitimately run federal indictment at one end and a voluntary, support-oriented referral at the other without contradiction. An eleven-year-old flagged for susceptibility who has committed no offense should receive a mentor and a conversation, not a durable file that follows him into adulthood. A man with a rented truck, a fertilizer receipt, reconnaissance photographs, and a communications history describing why the building deserves it should receive everything the state can lawfully bring. Both are the apparatus functioning correctly. **Finalization is what happens when the first case is administered as though it were the second** — and the objection to that is not squeamishness about enforcement but its opposite, since attention spent finalizing the eleven-year-old is attention unavailable for the man with the truck.
None of this apparatus exists to generate analytics. It is not a reporting layer, a dashboard, or a compliance artifact. **It exists to reach the man with the truck before the truck is parked**, and every argument about calibration in this essay is an argument about doing that more reliably rather than less.
## The Same Instrument Exonerates
There is a symmetry in all of this that almost never appears in the literature, and it is the strongest argument available for building the apparatus well rather than for building it small.
**Observability is bidirectional.** A record that can implicate can also clear. The instrumented environment that makes a pathway legible is the same environment in which a false accusation becomes falsifiable, a fabricated sequence becomes reconstructible, and a manufactured association becomes traceable to whoever manufactured it. The person most catastrophically harmed by the absence of provenance is not the investigator — it is the innocent subject who has no way to demonstrate that the pattern assembled around him was assembled _by someone_.
Consider the audience-of-one attack described earlier, in which a campaign is constructed from individually lawful acts semantically loaded for a single receiver, and in which the target's own testimony becomes the mechanism of his dismissal because it resembles a persecutory presentation. The defining feature of that attack is **evidentiary asymmetry**: the perpetrator leaves a coordination trail, the victim has only an account. In a properly instrumented and properly governed environment, that asymmetry inverts. Task dispatch leaves records. Payments leave records. Crowd procurement leaves contracts. Coordinated posting leaves timing signatures. Fabricated media leaves provenance gaps that content credentials are designed to expose. The same graph analysis that identifies a violent coalition identifies a purchased one, and the same telemetry that establishes a pathway establishes that a person was nowhere near it. **What protects the innocent from being set up is not less observation. It is better-governed observation, plus a right to invoke it.**
That last clause is the part currently missing from nearly every deployed system, and it is a concrete governance demand rather than a sentiment. Provenance infrastructure belongs between observation and adjudication precisely so that what becomes actionable remains reconstructible rather than merely asserted — and reconstructibility cuts both ways. **Any apparatus with the power to flag must also possess the power to clear, and the subject must be able to invoke it.** A system that can generate a file it will not let you challenge, from evidence it will not let you see, resolved by a threshold you did not set, has abandoned the only property that distinguishes it from the failure modes documented later in this essay. A system that can be compelled to exonerate is a system whose flagging power is legitimate, because the same instrument answers in both directions.
This is why the affirmative register matters as much as the hazard register. An architecture that only records danger will eventually treat the absence of a clearing record as itself suspicious. One that also records protective action, interruption, and the demonstrated absence of a pathway gives the innocent something the merely-unrecorded never have: **a defense made of the same material as the accusation.**
## Emboldenment Is a Repricing Event
When this argument was first developed, _emboldenment_ was doing intuitive work: give people the impression the environment has become permissive and some previously restrained people become louder. The literature is now considerably stronger than the intuition, and it supports a more precise mechanism than norm-shift.
Christian Crandall, Jason Miller, and Mark White measured attitudes immediately before and after the 2016 United States presidential election and found that participants perceived a significant increase in the social acceptability of prejudice toward groups the winning candidate had targeted rhetorically, while acceptability toward groups he had not targeted changed comparatively little. Leonardo Bursztyn, Georgy Egorov, and Stefano Fiorin tested the phenomenon experimentally in the _American Economic Review_, finding that the candidate's rise and eventual victory increased participants' willingness to express xenophobic views publicly, and that people expressing those views faced less social sanction when they believed the views enjoyed broader support. Their title states the mechanism exactly: _From Extreme to Mainstream: The Erosion of Social Norms_. A conceptual replication published in January 2026 examined perceived prejudice toward 128 groups before and after the 2024 election, found that the negativity of campaign rhetoric toward particular groups predicted increased perceived acceptability of prejudice toward those groups afterward, and — unlike the 2016 study — found that self-reported prejudice toward targeted groups also increased. The central finding replicated across a radically changed political environment eight years later.
None of this establishes why any individual produces these effects. It establishes that the effects exist, and it permits the mechanism to be stated in the vocabulary that makes it forecastable. A prominent actor who transgresses without visible cost is not transmitting an ideology. He is **publishing a new implied risk premium on a class of action.** Marginal participants who were previously priced out of that action — because the expected social, professional, or legal cost exceeded the expected return — enter the market. What observers describe as radicalization is more precisely the **arrival of previously unprofitable order flow.** The disposition did not have to be created. Only the price of revealing it had to fall.
This reframing is more damning than the moral one rather than less, for three reasons. It identifies the mechanism as reproducible and forecastable rather than as an eruption of bad character, which means the effect is predictable by anyone who bothers to model it and therefore foreseeable by the price-setter. It explains dose-dependence: a _Criminology_ study examining federal political activity and violent hate crimes from 1992 through 2012 found evidence for both political-threat and emboldenment mechanisms, with negative government attention toward particular minorities functioning as a signal that could increase violence depending on population and context. And it separates liability cleanly, in the way the incitement jurisprudence already does. The Nuremberg Tribunal convicted Julius Streicher on crimes against humanity for publication alone, with no operational role in the killing apparatus; the International Criminal Tribunal for Rwanda convicted Ferdinand Nahimana and Hassan Ngeze in the Media Case in 2003 on the same principle. **The price-setter's liability and the marginal actor's liability are distinct quantities and have been adjudicated as distinct for eighty years.** The repricing frame recovers that distinction where moral contagion language collapses it.
Sender intention and receiver effect are likewise different variables, and the clearest available illustration is documentary. During the presidential debate of 29 September 2020, asked about white supremacist and militia organizations, the sitting president said "Proud Boys, stand back and stand by." The transcript is unambiguous about the words. Intent is another question entirely, and the speaker later attempted to clarify. What makes the episode analytically useful is that the January 6 investigation collected evidence about **receiver interpretation**: one witness associated with the organization described fringe actors coming out of the woodwork afterward and wanting to join, while another testified that members interpreted the phrase as preparation for future action while expressly adding that he did not personally believe this was necessarily the speaker's intention. That witness performed, in one sentence, the analytical operation this entire essay requires. A signal can generate mobilization its sender did not foresee. A sender can anticipate an effect without desiring all of it. A sender can exploit the response. A third party can exploit the response afterward. Several of those can occur in sequence, and the evidence for each is different evidence.
## The Systems Have Objectives
The case that has always attracted the most speculation is the actor who is simultaneously a high-salience political participant and the owner of an information environment, because those are two distinct kinds of power and the second is not a matter of speech at all.
The documented record of public political intervention is what it is. In November 2023 Elon Musk endorsed as "the actual truth" a post invoking a version of the Great Replacement conspiracy, triggering widespread criticism and advertiser departures. In late 2024 he publicly endorsed Germany's Alternative für Deutschland, writing that only the AfD could save Germany and expanding the endorsement in a German newspaper, while the German government accused him of attempting to influence its election and the party was under domestic-intelligence scrutiny for suspected right-wing extremism. Those facts establish public political interventions. They establish nothing whatsoever about why they were made, and this essay does not claim to know.
What happened at the infrastructure layer is a different order of evidence. A field experiment published in _Nature_ in February 2026 by Germain Gauthier, Roland Hodler, Philine Widmer, and Ekaterina Zhuravskaya randomly assigned 4,965 active United States users of X to algorithmic or chronological feeds for seven weeks during 2023. Switching from chronological to algorithmic increased engagement and shifted political opinion in a conservative direction — on policy priorities, on perceptions of criminal investigations into Donald Trump, and on the war in Ukraine, with users becoming 4.7 percentage points more likely to prioritize Republican-favored policy issues and 7.4 percentage points less likely to view Volodymyr Zelenskyy positively. Neither direction of switching significantly affected affective polarization or self-reported partisanship, and the study makes no claim that the ranking system was designed to radicalize anyone.
The asymmetry in that result is the finding that matters, and almost all commentary missed it. Switching the algorithm **on** shifted attitudes. Switching it **off** did not shift them back. The authors' explanation is precise and it is a graph explanation: users who were shown engaging accounts by the algorithm went on to _follow_ those accounts, and they kept seeing that content after the algorithm was disabled, because a feed is shaped largely by whom you follow. **The durable output of the ranking system was not exposure. It was edges.** The algorithm is not primarily a content filter; it is an intervention into graph topology, and topology persists after the intervention stops. That is a ratchet, and it is the cleanest empirical demonstration available that the operative unit of the polity is the graph rather than the individual.
This is where the person-centered framing has to be abandoned in favor of something both more defensible and more disquieting. **A platform necessarily observes behavior, because ranking requires feedback.** Users click, follow, block, reply, linger, repost, search, and leave, and every one of those actions updates the environment. Nobody has to call it surveillance for the loop to exist. And the loop's output is available to parties who never spoke to the platform's owner.
Consider what is documented about who reads it. In January 2023 Meta sued Voyager Labs, alleging that the firm created **more than 38,000 fake accounts to scrape data from more than 600,000 Facebook users** — posts, likes, friend lists, photos, comments, group and page information — using a distributed network of computers to evade verification checks, and then sold and licensed the results. Voyager's product is investigative software marketed to law enforcement; Meta's own filing described the industry as providing scraping services "including as a way to profile people for criminal behavior," and a 2021 investigation had reported Voyager's 2019 work with the Los Angeles Police Department. The case settled in December 2024 with a permanent injunction and a monetary payment. The Brennan Center noted at the time that the FBI had separately contracted with Babel Street, which similarly promised to collect personal information using fake accounts and analyze online relationships, and that it had identified over half a dozen further surveillance-for-hire companies pitching or contracted to law enforcement agencies. **The behavioral exhaust of a political stimulus is a commodity with a functioning market, and the buyers include the state.**
And the state will operate the environment itself when the return justifies it. Operation Trojan Shield is the definitive case. Following the takedown of Phantom Secure, the FBI recruited a confidential human source to launch an encrypted device company called ANOM, with a master key built into the encryption that silently attached to every message. The Bureau then distributed **more than 12,000 devices to more than 300 criminal syndicates across over 100 countries**, intercepting some 27 million messages over roughly eighteen months and producing more than 800 arrests in sixteen countries in June 2021, along with the disruption of some twenty threats to life. Legal architecture was arranged around the operation, with servers hosted in a third country under a mutual legal assistance treaty specifically to avoid intercepting United States domestic communications. This was not infiltration of someone else's platform. It was the first time the Bureau **operated its own**. And the stated objective included something beyond the arrests: an FBI assistant special agent in charge said publicly that the hope was that criminals worldwide would fear that the FBI or another agency might, in fact, be running their platform. **Deterrence by uncertainty about who owns the environment is an announced law-enforcement objective, on the record.**
Set those two facts beside each other and the person-centered question dissolves into a better one. It is not necessary to determine what any individual intended, because the ecosystem contains commercial actors who profile people for police from social graphs at scale, and a federal agency that has operated a communications platform end-to-end and said out loud that it wants the possibility to be feared. Those are the _systems_. They have objectives. They read whatever the environment produces, and a high-salience provocation produces a great deal.
## From Baiting to Active Probing
The word _bait_ makes this discussion sound more sensational than it needs to be. The technical term is **active probing**, and the distinction from passive observation is exact: passive observation waits for a system to produce information spontaneously, while active probing changes an input because the response contains information about hidden state that passive observation cannot obtain.
This is ordinary published practice across several professions. In cybersecurity, MITRE's **Engage** framework organizes defensive deception around stages named _Prepare, Expose, Affect, Elicit,_ and _Understand_, describing adversary engagement as deliberately changing what an adversary sees in order to influence what the adversary thinks and does, then converting the resulting activity into understanding. In law enforcement the same logic operates under stronger constraint: the Attorney General's guidelines governing FBI undercover operations acknowledge deception as an essential investigative technique while requiring, for inducements, a reasonable expectation that the opportunity presented will **reveal illegal activity**, and reason to believe that persons drawn to the opportunity are predisposed to the relevant conduct. The safeguards exist precisely because the government is not permitted to manufacture a criminal disposition and then punish its display.
That is nearly a formal statement of the distinction this essay has been circling since its first version. **A legitimate probe reveals latent state. An illegitimate probe creates the state and then punishes the subject for displaying what the probe created.** The line separating detection from entrapment is not philosophical decoration; it is the entire operative constraint, and it is the reason the emboldenment literature is dangerous to the strong hypothesis rather than supportive of it. If elite signaling measurably lowers the cost of expression and thereby increases the quantity of expression, then a probe of that kind is not cleanly revealing pre-existing state. **The measurement is performative**, and the condition one hoped merely to observe becomes more probable because of the act used to observe it. That is the difference between inoculation and infection. Inoculation theory is a real and well-supported body of work — controlled, attenuated exposure with forewarning and refutation, what contemporary researchers call prebunking, and large experiments show it improves recognition of manipulative techniques. A public figure validating hostility is not administering an attenuated sample with an instructional label. Receivers who already sympathize experience it as permission.
## Chumming the Ecosystem
The provocative version of the idea deserves a clean statement rather than an insinuation, because insinuation is what has kept it out of serious analysis. Stated properly: **could a stimulus be introduced into an open social ecosystem partly in order to induce self-identification by actors who would otherwise remain latent, generating a population for downstream review?**
Every component of that composite is documented. Elicitation through controlled engagement is published defensive doctrine. Structured opportunity as an investigative technique is codified in Attorney General guidelines. Operating the environment itself is established practice with a named operation, a device count, and a press conference. Commercial behavioral profiling from social graphs is a functioning market with law-enforcement customers and litigation history. Ranking systems demonstrably alter political exposure and — more importantly — durably alter following graphs. High-status political cues measurably change the perceived cost of expression. Diversion of identified individuals toward substitute content is an operating program with published methodology and evaluation. And statutory screening of pre-criminal populations runs at national scale with published statistics. Not one element of the composite requires an exotic assumption.
It is worth being direct about a further distinction, because it is one that critics routinely elide and one that determines how everything above should be read. Judging that a technique would be _defensible in principle_ is not the same as asserting that it is _occurring in fact_, and neither is the same as concluding that a given implementation would be _legitimate_. The position taken here is unambiguous on the first and agnostic on the second. A civilization that has decided not to permit another mid-century catastrophe would be derelict if it did not develop instruments for detecting the residue its enclosure cannot absorb — and it should want those instruments to be good, well-funded, and aimed early enough to matter. Someone who is going to become a terrorist should be found before he becomes one. That is not a reluctant concession extracted from a critic; it is the whole reason the apparatus deserves to exist, and no objection registered in this essay should be read as an argument for dismantling it. **The objections here are conscientious rather than oppositional: they are conditions on an instrument the author wants operating, not a case for switching it off**, and they stand only until a superior mechanism is available, at which point they become an argument for the better mechanism rather than for no mechanism at all.
The two conditions are narrow and specific. **Nobody should be foreclosed as a speculative commodity** — finalized by a forecast, priced out of a future on the strength of an estimate that then prevents the evidence which would have contradicted it. And **nobody should be required to navigate a territory whose map is deliberately withheld**, which is the epistemic counterpart of the same failure. Those two are compatible with a well-run screening apparatus. They are incompatible only with a badly calibrated one, and a badly calibrated one is also worse at catching the bomber, which is why calibration is not a civil-liberties add-on to the security argument but a component of it.
What no evidence establishes is that these documented elements have been assembled into a single coordinated program aimed at any particular political population by any particular actor. **The technique is established. The program is unsupported.** Those are different claims, and conflating them is the failure mode that has made this entire subject unserious.
The older essay was also too binary, tending to ask whether controversial rhetoric was either sincere extremism or benevolent strategic theater. Reality permits at least five configurations, and they are not mutually exclusive. There is **sincere ideological signaling**, in which an actor says what he believes and those who share the belief become emboldened. There is **ordinary political mobilization**, in which the actor cares less about ideological content than about turnout, loyalty, attention, revenue, bargaining power, or coalition maintenance, and provocation works because it mobilizes. There is **deliberate active probing**, in which a signal is introduced or amplified partly because the response reveals hidden populations, alliances, vulnerabilities, or threats. There is **opportunistic exploitation**, in which nobody intends an observatory at all but law enforcement, researchers, campaigns, civil-society organizations, foreign services, advertisers, journalists, and platforms all observe the response and learn from it. And there is **emergent algorithmic amplification**, in which ranking systems maximizing engagement or relevance modify the social environment in ways no human player designed. A politician can sincerely believe a proposition, use it to mobilize supporters, incidentally reveal dangerous actors, have the resulting behavioral data exploited by parties he never spoke to, and be amplified throughout by a system optimizing something else entirely. **The move and the game are not the same object.**
## The Immune System Is a Classifier
The biological metaphor becomes useful only when it is treated as a figure for a specific computational problem. A biological immune system does not destroy anything unusual; it performs an extraordinarily difficult classification, distinguishing harmful processes from harmless variation, mobilizing proportionate response, preserving memory, and above all avoiding destruction of the organism it protects.
A democratic society faces an analogous problem, and it recognized the problem long before social media. The émigré constitutional scholar Karl Loewenstein coined **militant democracy** in 1937 while examining how fascist movements exploited democratic institutions to abolish democracy from within, and the resulting tradition asks whether an open society may legitimately restrict actors attempting to destroy the constitutional system that protects their own participation. Germany encoded elements of the principle into its Basic Law, whose Article 21 provides constitutional mechanisms against parties seeking to undermine the free democratic basic order. The postwar response built explicit defensive institutions across the board — human-rights law, the Genocide Convention, constitutional safeguards, atrocity-prevention mechanisms, hate-crime monitoring, international tribunals, civil-society observatories, and eventually targeted-violence-prevention systems. Their distributed existence is consequential enough without being converted into evidence of a single master program. The United Nations does not need the immune figure at all to describe the underlying task: its **Framework of Analysis for Atrocity Crimes** identifies fourteen families of risk factors including instability, prior violations, motive and incentive, capacity, absence of mitigating factors, enabling circumstances, triggering events, and indicators of genocidal intent, and it explicitly treats hate speech and propaganda as possible early-warning indicators. That is a real detection architecture, and its direction of travel is worth noting: it attempts to observe precursors to violence, not to release maximal hostility in order to see what surfaces.
Now suppose a provocation succeeds magnificently and thousands of angry people reveal themselves. What exactly has been discovered? A racist statement is evidence of racism; it is not evidence of a plan to commit violence. Membership in a radical movement reveals political identity; it does not establish criminal intent. Anger, conspiratorial belief, offensive speech, anti-government sentiment, and ideological extremity may correlate with risk under some conditions, and none is sufficient as a violence classifier. The United States Secret Service's National Threat Assessment Center states this unusually plainly: **there is no profile of the person who will commit a targeted attack.** Many observable pre-attack behaviors are unremarkable in isolation, some are constitutionally protected, and the overwhelming majority of people who exhibit them will never commit targeted violence, which is why threat assessment focuses on behavior in context rather than demographic or ideological profiling. The FBI takes the same position, repeatedly stating that investigations are not opened solely on the basis of First Amendment-protected speech, association, protest, or political activity, and orienting its guidance toward combinations of behavior — violent planning, target research, leakage of intent, preparation, fixation, and accelerating movement toward action.
That is the **base-rate problem** hiding inside the immune figure, and it is arithmetic rather than opinion. If violence-capable actors are rare within the vastly larger population of people who say offensive or radical things, then even a highly accurate ideological classifier produces enormous numbers of false positives, because the rarer the condition, the more specificity dominates. A system that forgets this becomes **autoimmune**, attacking dissent, eccentricity, unpopular ideology, satire, anger, or lawful association because these superficially resemble signals that sometimes precede violence. A democracy that dismantles constitutional freedom in order to identify enemies of constitutional freedom has solved the wrong optimization problem.
None of which should be mistaken for the claim that emboldenment is harmless or that the pathway is rare enough to ignore. It is not, and the objection deserves to be met at full strength rather than deflected. When a disposition is validated at scale, more people take the first steps — showing up, joining, acquiring, associating, reconnoitering — and more pathways therefore reach completion. Oklahoma City is the case that settles the question, and it settles it in a way that supports the predicate rule rather than undermining it. Militia ideology in 1994 was not concealed; it was published, loud, and everywhere, and noticing it required no instrument at all. What was actionable in advance was never the ideology but the pathway behavior — the associations, the ammonium nitrate purchases, the rented truck, the site reconnaissance. The failure was not an inability to detect a widespread disposition. It was an inability to find a two-man planning cell inside one.
And that yields the finding that makes emboldenment genuinely dangerous in a way the older framing missed. **Emboldenment raises the base rate and degrades specificity at the same time.** It increases the number of pathways that begin, which raises the prior; and it simultaneously floods the pool with people newly willing to say and do things that superficially resemble early pathway behavior and will never proceed further, which destroys the signal-to-noise ratio the classifier depends on. Higher incidence and worse discrimination, produced by a single event. That is the worst combination a detection system can be handed, and it is why the emboldenment literature is **hostile to the strong elicitation hypothesis rather than supportive of it**. A stimulus that increases the incidence of a condition while making the condition harder to distinguish is not a diagnostic instrument. Whatever else it is, it is contamination, and the cost of the contamination is not measured in analytic inconvenience.
Which produces the question the immune figure was concealing all along, and it is not a question about immunity at all. **Who owns the cost matrix, and what appeal exists against a bin assignment?** Autoimmunity is not a mood or a metaphor. It is a computable quantity: the false-positive rate multiplied by the severity of the action the classification licenses. A screening system that licenses a phone call has a different moral profile from one that licenses a watchlist entry, which has a different profile from one that licenses detention, and the threshold that is correct for one is catastrophic for another. Every serious argument about democratic self-defense is an argument about that matrix, conducted in language that conceals it.
## The Working Instance
The United Kingdom's Prevent programme is the cleanest available specimen, because the Home Office states the design openly rather than being caught at it. Prevent is one of four pillars of the CONTEST counter-terrorism strategy, it **operates explicitly in the non-criminal space**, and as an early-intervention programme it is obliged to consider _susceptibility_ to involvement in terrorism rather than waiting for an ideology to take hold. A referral implies no offence and no suspicion of one; it means a professional under a statutory duty — a teacher, a nurse, a social worker — raised a concern about behaviour, expression, or vulnerability. In the year ending March 2025 there were 8,778 referrals, the highest since records began in 2015, of which 1,472 were adopted as Channel cases after review by multi-agency panels chaired by local authorities. Twenty-one percent concerned extreme right-wing radicalisation and ten percent Islamist extremism. **Thirty-four percent concerned individuals for whom no specific ideology was identified at all.** More than a third of all referrals — 3,192 cases — involved children aged eleven to fifteen.
Read that with the machinery assembled above and every element of the model is present in a published government statistic. A statutory duty conscripts professionals as sensors. Sensor output becomes a referral. The referral is scored by a panel. The score determines entry into managed intervention. The whole apparatus operates below the threshold of criminality, on susceptibility rather than belief.
And the anomalous number is the one that vindicates the framework rather than embarrassing it. A third of the flagged population has **no identified ideology**, which is incoherent if the classifier is looking for extremists and exactly what one should expect if the classifier is looking for something else. It is not scanning for capability, which the enclosure contains in quantity and rewards. It is not scanning for ideology, which is protected and which a third of referrals lack. It is not even scanning for hostility, which is ubiquitous. **It is scanning for the withdrawal of a participant from substitutability** — for the signature of someone who continues to plan while ceasing to accept the payouts, whose grievance has stopped taking symbolic settlement. That target is far narrower and far stranger than ideological profiling, it is much harder to specify, and it explains both why the ideology field is so often empty and why the referral population skews so heavily toward adolescents, whose substitutability is least stable.
The diversion arm operates on the same logic. The **Redirect Method**, piloted by Jigsaw and Moonshot in 2016 and deployed widely since, uses targeted advertising to connect people searching for harmful content with alternative material, identifying susceptibility from search behavior and redirecting attention before a pathway completes. That is the enclosure attempting to restore substitutability by supplying a substitute — and it is the humane end of the same apparatus, evaluated by RAND and adopted by the European Commission's Radicalisation Awareness Network as an inspiring practice.
## The Instrument That Treats
The step most often omitted from both the alarmed and the reassuring accounts is the one in the middle. Identification is not the terminal state of this apparatus and was never meant to be. **The same instrumentation that determines who is on a pathway can determine what reaches him next**, and the interesting question is not whether that capability exists but which direction it is pointed.
The mechanics are already operating and already published. Redirect campaigns identify susceptibility from search behavior and serve alternative content into exactly the moment of highest receptivity, with later iterations building in a call to action — a number, a link, a route to a human being — so that the intervention can escalate from content to one-to-one contact for those who signal interest. Channel is the same logic with a caseworker attached: a consent-based, multi-agency support package that can include mentoring, theological guidance, education, and career assistance, with roughly half of adopted cases consenting to receive it, and nearly six thousand people supported away from a pathway since 2015. Behavioral Threat Assessment and Management, as promoted by the Department of Homeland Security, is explicitly framed as connecting individuals to support and management resources before violence occurs rather than as ideological policing. None of that is speculative architecture. It is the treatment arm of a detection system, funded and running.
And the evidence that ranking itself can be therapeutic is now experimental rather than theoretical, which is the part that should change how this is discussed. The _Nature_ result described earlier established that seven weeks of algorithmic exposure durably shifted attitudes and following behavior, with the shift persisting after the algorithm was switched off because users kept following the accounts it had surfaced. **A ratchet that turns one way turns the other.** A separate 2025 experiment re-ranked feeds to reduce exposure to content expressing antidemocratic attitudes and partisan animosity, and found that it moved participants' feelings toward political opponents by more than two points on a hundred-point scale — a shift the authors estimated would take roughly three years to occur organically in the general population. Three years of natural de-escalation, compressed into an experimental window, by changing what a ranking function prefers.
That result reframes the entire question. If exposure ordering durably alters both attitude and graph position, then **the feed is not merely a vector of radicalization; it is also the highest-throughput remediation channel ever built.** It reaches people who will never accept a referral, never speak to a caseworker, and never recognize themselves in a prevention program. It operates at the exact point in the pathway where substitutability is still recoverable. And it is cheap, iterable, and measurable in a way that no in-person intervention can match. A civilization that has an instrument capable of restoring substitutability at population scale and declines to point it that way has made a choice, and the choice is not neutral.
Two constraints keep this from collapsing into manipulation, and both follow from the argument already made. The first is **direction of benefit**: a re-ranking that reduces a person's probability of committing mass violence serves that person's interests as well as everyone else's, which is what distinguishes it from a re-ranking optimized for engagement, revenue, or political outcome using identical machinery. The second is the **maturation clock**: therapeutic ranking conducted permanently and covertly is a closed epistemic field regardless of how benevolent its objective, and the obligation is that the existence, criteria, and direction of the intervention become knowable. Treatment administered to a population that can never learn it was treated is not medicine. It is husbandry, and the distinction between the two is precisely the thing this essay is trying to hold open.
## Autoimmunity as a Cost-Matrix Property
Capability is not intent, and the stages of the chain must not be morally collapsed into one another. A society may possess social graphs, platform telemetry, behavioral threat-assessment teams, fusion centers, commercial data markets, open-source collection, detention capacity, redirection programs, mental-health interventions, criminal investigative authority, and increasingly capable machine learning. Observation is not classification. Classification is not adjudication. Adjudication is not punishment. Risk is not guilt. Ideology is not violence. **The entire constitutional problem of predictive governance consists in maintaining those separations under pressure**, and every one of them is a place where a cost matrix is being set by somebody.
The Department of Homeland Security's Center for Prevention Programs and Partnerships now promotes **Behavioral Threat Assessment and Management** as a public-health-informed methodology that identifies concerning trajectories, evaluates context, and connects individuals to support and management resources before violence occurs, describing the work as prevention rather than ideological policing. That distinction should be the ethical center of the whole enterprise. A good classifier asks what the dangerous pathway is. A bad one asks which kinds of people are dangerous.
There is a further cost that almost never appears on the ledger, and it falls on the individual rather than the population. Consider what happens to someone wrongly flagged, or wrongly targeted by a private actor using the same techniques. A campaign can be assembled from acts that are individually lawful, individually trivial, and semantically loaded for exactly one receiver — a phrase, a date, a detail from a private history — so that the signal is addressable to a single node while remaining ambient noise to every other observer, including the people carrying it out. Call it the **audience-of-one attack**, and note that it requires no state whatsoever: a crowd-for-hire industry operates openly at low hundreds of dollars per participant, a 2018 suit alleged one such firm was retained to march protesters outside a named individual's home and press his institutional affiliations, and the vendor model has evolved away from hired actors toward recruiting people already sympathetic to the stated cause — which makes the participants sincere and leaves only the client knowing the objective. Attack by unwitting good-faith proxy is likewise a convicted crime pattern with a measured conversion rate, most starkly in the case where a man impersonated his former partner to solicit an assault at her address and **one hundred sixty-one people responded** to the advertisement.
The property that matters is not the feasibility. It is that **the discrediting of the target is the payload rather than a side effect.** The evidence exists nowhere except in the target's account, and the account's own content is the mechanism of its dismissal, because the more accurately the pattern is described the more the description resembles a persecutory presentation. Miranda Fricker's **testimonial injustice** names the general form of a credibility deficit inflicted by prejudice, and this is its sharpest instance, since the prejudice attaches not to who is speaking but to what is said. The relevant clinical finding — that in the one rigorous study of self-identified group-stalking complainants all 128 were judged delusional against 3.9 percent of individual-stalking complainants, with distress severe and genuine in both groups — stands and must be reported. But its logical reach is narrower than it is made to bear, because a real audience-of-one campaign and a persecutory delusion are phenomenologically identical from inside and produce identical testimony from outside. The clinical finding cannot establish that no real cases exist, and real cases cannot rehabilitate the complainant population. **Neither inference is available**, and any analysis that reports only one side of that performs the same operation the attack performs. This is what a false positive costs when the licensed action is not detention but disbelief.
## Where an Unconstrained Classifier Ends
These are boundary conditions rather than forecasts, and they are set out here for the same reason an engineer states a material's failure mode rather than because he expects the bridge to fall. The reason to insist on the cost matrix is that the terminus of an _unconstrained_ susceptibility classifier — one with no proportionality, no appeal, and no counterweight — is documented twice, once historically and once in production. Neither resembles a Channel panel, and the difference between them is precisely the set of constraints this essay is arguing for rather than against.
In _Aktion T4_, institutions across Germany submitted standardized registration forms describing patients' diagnoses, productive capacity, and family histories. Three medical experts reviewed the forms without examining the patients or reading their records, each placing a small mark — red pencil for one decision, blue for the other — under the heading of treatment. Three marks issued a warrant. The operational geometry is what matters and not the body count: a human being was reduced to a file, the file received a graphic mark, and the mark activated transport, disposal, falsification, and silence. **The bureaucratic mark was the literal hinge between continued existence and absorption into the killing apparatus**, and it was applied on the basis of assessed future value rather than any act.
The contemporary version runs at national scale and is algorithmic. Xinjiang's Integrated Joint Operations Platform aggregates data and flags to officials those it deems potentially threatening; Human Rights Watch's reverse engineering of the associated police application revealed that the system treats a wide range of lawful, everyday, non-violent behavior as suspicious — not socializing with neighbors, habitually avoiding the front door, using encrypted messaging. Leaked bulletins record **15,683 residents flagged and rounded up in a single week in June 2017.** That is the ear tag with no proportionality, no appeal, and no counterweight.
Neither example is offered as a prediction. They are offered as the boundary conditions that make the cost-matrix question non-negotiable, because both systems were, in their own descriptions, performing early identification of individuals assessed as future risks to the collective. The difference between a Channel panel and a _Meldebogen_ is not the presence or absence of a classifier. It is entirely a matter of what the score licenses, at what confidence, with what appeal, and against whom the error falls.
## The Graph After the Signal
Once the classifier is understood correctly, the original intuition about what a provocation reveals becomes stronger rather than weaker, because the useful information was never the beliefs.
A public provocation generates **relational information** without any assumption that everyone responding is dangerous. Who follows whom. Which formerly separated communities connect. Who bridges rhetoric and operational organization. Who merely performs identity. Who moves from posting toward acquisition, surveillance, target selection, travel, financing, or explicit planning. Who moderates others. Who de-escalates. Who suddenly attracts followers after elite recognition. Which narratives propagate through which communities. People responding to a high-profile cue are not simply declaring beliefs — they are **creating edges**, and the _Nature_ ratchet result is the direct empirical demonstration that edges are what persist. A provocative signal reveals hidden connections, creates new ones, strengthens weak ones, destroys relationships, changes reputational weights, produces factional splits, alters centrality, and routes participants into new communities. **The signal is an intervention into graph topology**, and topology outlives the signal.
This has an immediate and underappreciated consequence for the intervention side. Deplatforming is **edge deletion**, and edge deletion has second-order neighborhood effects that the deleting party almost never models: rerouting diffusion, concentrating the remaining population, severing the moderating ties along with the amplifying ones, and relocating the community to an environment with less observability and fewer restraining voices. Whether the net effect is protective is an empirical question about a specific graph, not a general property of removal. And no secret control room is required for any of this to matter, because platforms, campaigns, journalists, researchers, foreign governments, extremist recruiters, advertisers, and security agencies all read different information from the same topology. Several games run on one response.
## Outrage as Telemetry
There is a systems insight worth extracting from the observation that everything now feels like an emergency, and it is sharper than a complaint about media incentives. A person reacts to a provocative event; the reaction becomes data; the data alter ranking; ranking alters exposure; exposure produces further reaction; the platform learns; participants learn; political actors learn; observers learn; and the next input enters an environment changed by the previous one.
The reason the tempo escalates rather than cycling has to do with what makes behavior informative. A system optimizing for information extraction requires **informative** behavior, and behavior is maximally informative under stress, because stress collapses the gap between professed and revealed preference. An environment that must learn about its population will therefore manufacture stakes — not from malice but from gradient — and as models saturate on ordinary behavior, only escalation yields new signal. **The crisis is the probe**, and the monotonic intensity is a design artifact rather than a cultural mood.
That framing also disciplines the analysis. Ordinary platform feedback, documented intelligence elicitation, advertising experimentation, counter-extremism intervention, and hypothesized covert narrative seeding are five different mechanisms with five different evidentiary standings, and treating them as one established process is precisely what makes the resulting argument dismissible by professionals who would otherwise find it useful.
## The Target Adapts
Every probing system faces a problem its designers systematically underweight: **the target may recognize the probe.** Once participants understand that certain behaviors reveal their type, they change those behaviors. Security research calls it adversarial adaptation, intelligence calls it counterintelligence, markets call it strategic behavior, and machine learning encounters it as adversarial examples and distribution shift.
Someone who believes public rhetoric is monitored can adopt coded language, migrate to encrypted systems, use intermediaries, generate deliberate false signals, or contaminate the classifier by making innocuous populations resemble the target population. A sophisticated adversary goes further and plays the observer. If a security system believes particular symbols identify extremists, flooding those symbols through benign communities destroys classifier precision. If a government watches a particular platform, organizers can use it performatively while moving consequential activity elsewhere. If a society watches for aggressive rhetoric, operational actors cultivate deliberately moderate public personas — which is precisely the configuration the reactive/proactive split predicts is most dangerous, and precisely the one an ideology-oriented classifier is worst at detecting. **The immune system creates selection pressure on the pathogen**, and the better the detector becomes, the greater the reward for becoming difficult to detect. This is why detection systems never reach equilibrium, and why any claim that a screening apparatus has solved the problem should be read as evidence that it has stopped measuring the part of the problem that adapted.
## What Would Confirm It, and What Would Refute It
A hypothesis has to be able to lose, and the discipline is worth stating concretely rather than gesturing at.
If deliberate exposure were being run as an operation, the strongest evidence would not be additional provocative statements, which are the stimulus rather than proof of an objective. The evidence would appear downstream: documents, communications, testimony, contracts, operational directives, or technical architecture showing that provocative signals were coordinated with collection or threat-identification goals; evidence that particular behavioral responses were defined _in advance_ as informative; temporal linkage between stimulus, observed cohort, risk assessment, and intervention; safeguards against entrapment and false positives of the kind a professionally designed operation would require; red-team documentation, controlled experimentation, predetermined success criteria, or evidence that apparently chaotic public moves corresponded to internal measurement. Above all, it would require **information that existed before the interpretation** — which is the standing evidentiary discipline of this entire body of work, in which symbolic resonance is weaker than performative closure, which is weaker than independent evidence that the pathway predated the theory describing it.
Evidence against the hypothesis would include internal records showing decision-makers surprised by extremist responses, attempts to suppress rather than study those responses, organizational behavior inconsistent with a collection objective, absence of any credible exploitation pathway, or documentation that the relevant actions were driven by unrelated ideological, political, financial, or personal objectives.
There is a third possibility, and it should not be treated as analytical retreat: the system may exhibit most of the predicted effects with nobody having designed the whole. **Emergence is not randomness.** A market has structure without a market author; an ecosystem has selection without a central selector; a recommender can cause millions of agents to generate coordinated-looking behavior through local optimization. The absence of a puppeteer does not mean the puppets are imaginary. It may mean there are no puppets — only players, each optimizing something, on a board that records everything.
## Mark the Pathway, Not the Person
The immune figure has one more failure mode, and it is the one that has historically killed people. Ideas are not viruses. People are not infected cells. Political belief cannot be medicalized merely because diffusion models describe both pathogens and information. The analogy holds at the level of **propagation dynamics** and collapses immediately at the level of moral ontology, and once a government begins treating human beings as contaminants the figure becomes capable of justifying exactly the exclusion it was adopted to prevent. That is the autoimmune catastrophe in its mature form, and it is not hypothetical: the Nazi pest-and-sanitation lexicon was an industrially scaled cognitive blend engineered to render extermination intelligible as public health.
The governing correction is a polarity inversion, and it is the single most portable idea in this body of work. **The mark goes on the recurrence pathway, not on the person.** A hazard-side ledger records the pathways by which destruction returns and the provenance of dangerous state; a memorial ledger preserves those whom recurrence consumed; and an affirmative register records those whose actions interrupted the pathway. Provenance infrastructure sits between observation and adjudication so that what becomes actionable remains reconstructible rather than merely asserted. Under that architecture, capture means observe, identify, authenticate, preserve provenance, correlate, classify a pathway, and permit action only upon sufficiently adjudicated state — never the disposal of a human being on the strength of a representation. The defended invariant is **non-reducibility**: a person may be observed, indexed, remembered, modeled, and even instantiated elsewhere without any single representation, ledger entry, model, jurisdiction, or inference becoming ontologically identical with that person.
A better societal immune system therefore does not require everyone to think alike, and mass ideological classification is the wrong instrument for the actual problem. What it requires is enough ludic and cognitive literacy for citizens to recognize when someone is altering their decision environment; institutions robust enough to withstand demagogic pressure; investigative capacity sufficient to distinguish rhetorical extremity from mobilization toward violence; network intelligence sufficient to recognize dangerous coordination without criminalizing association; statistical discipline sufficient to take base rates and false positives seriously; constitutional restraint sufficient to protect dissent; and intervention capacity sufficient to act before preparation becomes irreversible. It also requires **symmetry**, without which the classifier becomes a partisan weapon and forfeits its legitimacy entirely. White nationalism, jihadist violence, accelerationism, violent anarchism, anti-government terrorism, ethno-religious violence, and any future ideological configuration must be evaluated by **behavioral pathway and threatened harm**, never by whether the ideology flatters whoever currently holds power. The FBI's public formulation is more important than it first appears: lawful ideology is not the investigative predicate; violence, threatened violence, criminal conduct, and behavioral escalation are.
## The Boundary
The mechanism at the center of this essay is real, and the list of things that are established is long enough to make the remaining uncertainty precise rather than convenient. Emboldenment is real and measured. Preference revelation is real. Signaling and screening are formal results. Active probing is doctrine. Undercover elicitation is codified. Cyber deception is published methodology. Operating a platform as an instrument is a completed federal operation with a device count. Commercial behavioral profiling from social graphs is a market with law-enforcement customers. Algorithmic amplification durably alters following graphs. Behavioral threat assessment is institutional practice. Pre-criminal statutory screening runs at national scale with published statistics. Democratic self-defense is a constitutional tradition with case law.
What remains unestablished is that any of this has been assembled into one deliberately coordinated exposure operation by any named actor, and preserving that as a hypothesis rather than laundering it into fact is what makes the analysis usable — because it permits the questions that would actually matter if such a strategy were ever fielded. Who authored the stimulus, and who knew it was one. Who observed the response, and what was being measured. What changed the assessment, who received the resulting intelligence, and what intervention followed. Whether protected belief was distinguished from preparation for violence. What the false-positive rate was, who bore it, and what appeal was available. And what prevented the probe from normalizing the condition it existed to expose.
Two failures bound the legitimate operation of the whole apparatus, and they sit at opposite ends of the same loop. At the output end there is **finalization**: the estimate that couples back into the environment, forecloses the opportunities that would generate contrary evidence, and then reads its own effect as its own confirmation — which is precisely what a susceptibility score does to an eleven-year-old. At the input end there is **map-deprivation**: the requirement that a person navigate a territory whose map is withheld, which is violence by omission, because a civilization's first obligation is not the redistribution of outcomes but the redistribution of accurate environment-models. Finalization is a closed causal field. Map-deprivation is a closed epistemic field. **The apparatus is legitimate exactly to the degree that both stay open.**
That yields the operative constraint. Some opacity during the bootstrap of a survival-critical system may be genuinely unavoidable, since a system that can be vetoed before it is understood can be killed by the pathologies it exists to correct. But **operational opacity about the current move is not the same defect as permanent opacity about the existence of the board.** Opacity carrying a **maturation clock** — an obligation for the black box to become a glass box on a stated schedule — is a tactical condition. Opacity that hardens into permanent asymmetry is the signature of every emergency regime that told a public _you cannot know yet_ and then arranged never to be asked again.
The true measure of a societal immune system was never how many enemies it can identify. It is whether it can recognize an emerging threat **without turning difference into disease, dissent into guilt, prediction into conviction, or surveillance into destiny.** A democracy capable of that possesses something far more durable than ideological conformity. It possesses **calibrated immunity** — and in a society where political signals become data, reactions become graph state, graph state becomes intelligence, and intelligence alters the next move, calibration is not a technical refinement. It is the boundary itself.
---
[[about/About Bryant McGill|Bryant McGill]] is a Wall Street Journal and USA Today bestselling author, systems architect, technologist, and strategic advisor, as well as a Congressionally Recognized Ambassador of Goodwill and United Nations–appointed Global Champion. His work spans naval intelligence systems, computational linguistics, artificial intelligence, digital transformation, and civilizational governance architecture. His forward analysis on U.S.–Israel Pax Silica frameworks has appeared in Jewish/Jerusalem News Syndicate (JNS).
---
## References
**Emboldenment, norms, and repricing**
- Christian S. Crandall, Jason M. Miller and Mark H. White II, [Changing Norms Following the 2016 U.S. Presidential Election](https://journals.sagepub.com/doi/10.1177/1948550617750735), _Social Psychological and Personality Science_, 2018.
- Leonardo Bursztyn, Georgy Egorov and Stefano Fiorin, [From Extreme to Mainstream: The Erosion of Social Norms](https://www.aeaweb.org/articles?id=10.1257/aer.20171175), _American Economic Review_, 2020.
- [Political Threat and Emboldenment Mechanisms in Violent Hate Crime](https://onlinelibrary.wiley.com/journal/17459125), _Criminology_.
- International Military Tribunal, [Judgment: Streicher](https://avalon.law.yale.edu/imt/judstrei.asp), Nuremberg, 1946.
- International Criminal Tribunal for Rwanda, [Prosecutor v. Nahimana, Barayagwiza and Ngeze](https://unictr.irmct.org/en/cases/ictr-99-52), Media Case judgment, 2003.
**Platforms, ranking, and the graph**
- Germain Gauthier, Roland Hodler, Philine Widmer and Ekaterina Zhuravskaya, [The political effects of X's feed algorithm](https://www.nature.com/articles/s41586-026-10098-2), _Nature_ 652, 2026.
- Meta, [Leading the Fight Against Scraping-for-Hire](https://about.fb.com/news/2023/01/leading-the-fight-against-scraping-for-hire/) — _Meta Platforms, Inc. v. Voyager Labs Ltd._
- Brennan Center for Justice, [Meta Sues Surveillance Firm That Worked with Police](https://www.brennancenter.org/our-work/analysis-opinion/meta-sues-surveillance-firm-worked-police).
**Elicitation, deception, and platform operation by the state**
- MITRE, [Engage: Adversary Engagement Framework](https://engage.mitre.org/).
- U.S. Department of Justice, [The Attorney General's Guidelines on FBI Undercover Operations](https://www.justice.gov/archives/ag/undercover-and-sensitive-operations-unit-attorney-generals-guidelines-fbi-undercover-operations).
- Federal Bureau of Investigation, [Operation Trojan Shield](https://www.fbi.gov/news/stories/fbi-global-partners-announce-results-of-operation-trojan-shield-060821).
- U.S. Attorney's Office, Southern District of California, [FBI's Encrypted Phone Platform Infiltrated Hundreds of Criminal Syndicates](https://www.justice.gov/usao-sdca/pr/fbi-s-encrypted-phone-platform-infiltrated-hundreds-criminal-syndicates-result-massive).
**Threat assessment, screening, and prevention**
- U.S. Secret Service National Threat Assessment Center, [Enhancing School Safety Using a Threat Assessment Model](https://www.secretservice.gov/protection/ntac).
- Home Office, [Individuals referred to and supported through the Prevent Programme, April 2024 to March 2025](https://www.gov.uk/government/statistics/individuals-referred-to-prevent-to-march-2025/individuals-referred-to-and-supported-through-the-prevent-programme-april-2024-to-march-2025).
- Home Office, [Prevent Programme Factsheet – August 2026](https://homeofficemedia.blog.gov.uk/2026/08/06/prevent-programme-factsheet-2026/).
- Radicalisation Awareness Network, [The Redirect Method](https://home-affairs.ec.europa.eu/networks/radicalisation-awareness-network-ran/collection-inspiring-practices/ran-practices/redirect-method-trm_en).
- Moonshot, [Redirect Method Canada — Final Public Report](https://moonshotteam.com/wp-content/uploads/Final-Public-Report_Canada-Redirect_English.pdf).
- MI5, [Director General Ken McCallum gives latest threat update](https://www.mi5.gov.uk/director-general-ken-mccallum-gives-latest-threat-update), October 2024.
- Counter Terrorism Policing, [Our Mission factsheet](https://www.counterterrorism.police.uk/wp-content/uploads/2025/02/CTP-Our-Mission-Factsheet-February-2025.pdf).
- RAND Corporation, [A Case Study of the Redirect Method](https://www.rand.org/content/dam/rand/pubs/research_reports/RR2800/RR2813/RAND_RR2813.pdf).
- U.S. Department of Homeland Security, [Center for Prevention Programs and Partnerships](https://www.dhs.gov/CP3).
**Militant democracy and atrocity prevention**
- Karl Loewenstein, [Militant Democracy and Fundamental Rights](https://www.jstor.org/stable/1948655), _American Political Science Review_, 1937.
- [Basic Law for the Federal Republic of Germany, Article 21](https://www.gesetze-im-internet.de/englisch_gg/englisch_gg.html).
- United Nations, [Framework of Analysis for Atrocity Crimes](https://www.un.org/en/genocideprevention/documents/publications-and-resources/Framework%20of%20Analysis%20for%20Atrocity%20Crimes_EN.pdf).
**Where unconstrained classification ends**
- United States Holocaust Memorial Museum, [Euthanasia Program and Aktion T4](https://encyclopedia.ushmm.org/content/en/article/euthanasia-program).
- Human Rights Watch, [China's Algorithms of Repression: Reverse Engineering a Xinjiang Police Mass Surveillance App](https://www.hrw.org/report/2019/05/01/chinas-algorithms-repression/reverse-engineering-xinjiang-police-mass).
- ICIJ, [Exposed: China's Operating Manuals for Mass Internment and Arrest by Algorithm](https://www.icij.org/investigations/china-cables/exposed-chinas-operating-manuals-for-mass-internment-and-arrest-by-algorithm/).
**Individual cost and testimony**
- Lorraine Sheridan and David V. James, [Complaints of group-stalking ('gang-stalking'): an exploratory study of their nature and impact on complainants](https://www.tandfonline.com/doi/abs/10.1080/14789949.2015.1054857), _Journal of Forensic Psychiatry & Psychology_, 2015.
- InfluenceWatch, [Crowds on Demand](https://www.influencewatch.org/for-profit/crowds-on-demand/).
- Stanford Center for Internet and Society, [Former Boyfriend Used Craigslist To Arrange Woman's Rape, Police Say](https://cyberlaw.stanford.edu/press/former-boyfriend-used-craigslist-arrange-womans-rape-police-say).
- Miranda Fricker, _Epistemic Injustice: Power and the Ethics of Knowing_, Oxford University Press, 2007.
## Collection and ontology routes
This article is the classification hinge of the [[collections/Gamification|Gamification Collection]]. It follows the movement from adversarial input and social-graph response to trajectory-sensitive assessment, remediation, and the demand that a system mark a recurrence pathway without turning a person into a permanent label.
Follow [[wiki/Active Probing|Active Probing]] for the reflexive stimulus-response problem, [[wiki/Risk Scoring Systems|Risk Scoring Systems]] for base rates, weights, thresholds, and false positives, [[wiki/Non-Substitutability|Non-Substitutability]] for the relation between grievance and bounded settlement, and [[wiki/Epistemic Injury|Epistemic Injury]] for the damage caused when engineered ambiguity is treated as context-free evidence. [[articles/gamification/The Prediction and Prevention Stack and the Institutions Building It|The Prediction and Prevention Stack and the Institutions Building It]] extends the classifier into an auditable institutional sequence.