← AIMS

Safety

Irreversible harm is prevented by structure — not hoped away by process theatre

Aim

High-stakes domains fail closed: irreversible actions require committed authority, appropriate evidence, boundaries that cannot be bypassed silently — and people can raise harm without fear.

Safety is the aim that consequential domains fail closed — when uncertainty, authority, or evidence is insufficient, the system holds rather than proceeds, and every override is visible in the record. Psychological safety and contestability are part of safety: people must be able to stop the line without organisational toxicity.

The aim

Safety is not the absence of risk. It is the presence of structural guardrails at commitment boundaries: named authority, evidence snapshots, policy version, moment — and no silent path around them. Break-glass exists when it must; it always emits an accountable event.

Organisations pursuing safety refuse dark patterns that deliver a feeling of control while eroding the conditions that make harm detectable and attributable.

In software systems

Safe systems separate reversible preparation from irreversible commitment, require explicit L0 events before external effects, and treat admin mutation without compensating events as an architectural defect — not an operational convenience. Contest and override paths are tested, not decorative (GDPR Art. 22 where applicable).

In human organisations

Safe organisations strengthen weak boundaries with certification and review (Article 20) rather than removing them. They measure override rates and time-on-task at commitment points — boundary theatre is treated as a safety signal, not a compliance checkbox. Speak-up theatre is refused: safety is contestability plus anti-retaliation, not posters alone.

In socio-technical systems

LLM and automation deployments in high-stakes domains default to L2/L3 until human or certified commitment. Safety requires the harness, not merely the model — and refuses patterns that substitute surveillance or consent theatre for genuine authority.

What threatens this aim

Failure modes: Wrong-boundary automation removes human judgment where severity demands it. Silent override bypasses the record when something goes wrong. Organisational toxicity and forced alignment suppress early warnings.

Anti-patterns: Loyalty over truth treats dissent as betrayal when harm is visible.

Dark patterns: Surveillance as accountability, consent theatre, speak-up theatre, and PIP for —negativity— create the appearance of safety without structural commitment — or punish people who use speak-up channels.

Principled support: Commitment boundary with reservation patterns (Article 19) and contestability advance safety without blocking reversible preparatory work.