Class: where the framework offers safeguards but not sufficient protection. It runs on the hard standard below.
The threat
AI collapses the cost of watching — but the deeper change is what it does after watching. Surveillance stops being we recorded what you did and becomes we can infer what you are likely to do, what persuades you, whom you associate with, what you fear, whether your behavior is changing, and what intervention might alter it. That is qualitatively different, and from the framework’s view the deepest threat is not privacy as such but the gradual occupation of the participant’s interior and behavioral territory by the field. Old surveillance was geographically bounded — a prison, a workplace, a checkpoint. AI surveillance is participant-bound: your phone, face, payment history, social graph, voice, gait, and location move with you, and once the streams are integrated the system no longer sees acts, it constructs a model of the person. That is why this scenario sits upstream of gatekeeper AI: gatekeeping says based on our model, you don’t qualify; surveillance is the continuous construction of the model that the future gates will judge you by.
The NWG end state
The framework meets this with a boundary it already holds as non-negotiable — the participant has an interior the ecology does not own — and sharpens it for an age of inference: the right to opacity, the right not to be completely knowable to institutions. Not total opacity; a car on a road, a loan application, an airport all legitimately require some visibility. The discipline is bounded jurisdiction, and it turns on a distinction surveillance constantly collapses. Because a signal can be observed, the field assumes standing to observe it; because it has been observed, the field assumes standing to use it. Those are two different permissions — and the framework’s existing rule is that inferential access creates no jurisdiction: the capacity to know is never, by itself, a license to act on the knowledge.
Around that, the mature state holds six permanent protections. First, interior sovereignty: institutions do not automatically gain standing over inferred beliefs, associations, emotional states, vulnerabilities, or political tendencies merely because technology can infer them. Second, bounded observability: not is surveillance permitted? but what may this participant observe, for what purpose, for how long, and with what downstream jurisdiction? — the surgeon needs what the retailer does not. Third, the right to unobserved space: places to experiment, fail, think, change one’s mind, read, associate, and wander without every act becoming permanent institutional evidence, because emergence requires provisionality. Fourth, purpose cannot expand silently: a camera installed for building security does not thereby acquire facial recognition, sentiment inference, productivity scoring, and law-enforcement access — new use is new jurisdiction and requires new legitimacy, because collection creates no unlimited future license. Fifth, surveillance cannot become the price of standing: “you are free not to consent” is fictional when refusal means no banking, employment, healthcare, or transport — the same formal-versus-traversable distinction. Sixth, power must remain observable too: the greater an institution’s capacity to observe participants, the greater the participants’ capacity to observe its use of that power — audit trails, query logs, disclosure, oversight — because one-way visibility, both directions of signal, is what changes the power relationship.
The transition gap
The gap is that the infrastructure is already built and economically load-bearing — much of the digital economy runs on exactly this collection — and it advances under benign names: safety, personalization, efficiency, health. But the sharpest part of the gap is not technical, it is what surveillance does to people before any institution acts. The real mechanism of “1984” is not the state watching everyone and arresting dissenters; it is that people who know they are continuously legible begin to pre-edit themselves — anticipatory self-censorship, the field moving inside the participant. No arrest, no explicit censorship; interior sovereignty is colonized without technically disappearing, and exploration quietly contracts. AI deepens this from watching into shaping: observe enough and a system learns when a person is vulnerable, what language persuades them, what makes them afraid — turning surveillance into a loop of sense, predict, intervene, measure, refine. The field is no longer only reading the participant; it is experimentally shaping them. The framework will need a principle it has not fully developed here — roughly, that institutions may not use asymmetric psychological knowledge to covertly engineer behavior beyond the jurisdiction of the relationship — but the danger is already real, and it is why this scenario is more urgent than it looks: surveillance infrastructure becomes invisible once normalized.
Transition projects
The objective is to set limits on inference and purpose before integrated agents make cross-domain inference routine. The full set is on its own page: the transition program — eight projects (a surveillance jurisdiction map; inference rights; protected opacity zones; anti-persistence architecture so a participant can become newly legible; a ban on universal behavioral dossiers; participant-side visibility tools; surveillance firebreaks between domains; and protection for anonymous and pseudonymous participation) — with a timeline that runs from defining inference limits now, to building technical firebreaks, to preventing ambient surveillance from becoming the unquestioned default of ordinary life.
Capture risks
The most dangerous capture is specific to this framework: surveillance justified as ecological measurement. Because the framework values measuring capacity, a bad actor can dress total monitoring as “measuring participation” — which is exactly why the framework insists that capacity is measured to improve the field, never to price or track the participant. And the safeguards themselves can invert: a national data-rights portal could become the best map of everyone’s data, a universal identity-protection system could create universal identity, audit requirements could force greater retention, and a personal AI assistant could become the most intimate surveillance device ever built. The rule holds against benevolent intent too — a safeguard is judged by the same standard as the thing it guards against.
The limits
The framework can define a remarkably strong architecture here, and it cannot build the machinery: encryption, secure hardware, differential privacy, cybersecurity, identity protocols, access controls, constitutional law, law-enforcement constraints, and geopolitical agreements are the mechanism layer that instantiates these requirements. Nor can it dissolve the genuine tension between privacy and legitimate collective safety. Some surveillance really does save lives — suicide risk, domestic violence, medical emergencies, fraud, abuse — so the framework cannot answer privacy always wins, and it will not answer safety always wins. Instead it asks how much observability is commensurate with a particular obligation, which means there is no single universal surveillance rule, and some cases stay genuinely hard.
The hard standard
Standing carries the right to opacity, and this scenario shows how standing is hollowed when legibility becomes its price or when inference is treated as jurisdiction over the interior. Ecological capacity is attacked in the subtlest way in the whole set: nothing is banned, yet anticipatory self-censorship suppresses emergence as people police themselves, and the persuasion loop actively shapes participants — so capacity can fall while every safety metric rises. Ontological correctability depends on the sixth protection: one-way visibility lets power drift unobserved, while anti-persistence and symmetric transparency keep both the participant and the institution correctable.
The framework belongs in the second class because it has the right principles in unusual depth — an interior the ecology cannot own, inference that grants no jurisdiction, opacity as standing — and depends on cryptography, security, and law to make them hold against actors who find total legibility extremely valuable. The node most at risk is capacity-through-emergence, because the damage is done by self-policing before any institution has to act. The governing question is the framework’s real contribution: what degree of participant legibility is genuinely required for this relationship to function, and what prevents that visibility from acquiring jurisdiction beyond the relationship?
A civilization does not need to imprison people to eliminate human freedom. It can make every meaningful act permanently observable, inferable, and consequential until participants learn to imprison their own emergence.
Where this tends to land hardest — in the regional vulnerability map: China.