Humans' early perceptions of safety were largely based on a simple intuition: the world should be a peaceful place, and danger is just an occasional aberration. As a result, we build walls, lock doors, add approval processes to systems, conduct audits on companies, and install firewalls on computers. Whenever new dangers emerge, our instinctive first response is to add another layer of defense.
This line of thinking is not wrong—it has constituted the most important security methodology for a considerable stretch of human civilization. But if we widen the lens, a more troubling question emerges: what if confrontation was never the anomaly? What if deception, conflict, self-interest, miscalculation, betrayal, incomplete information, and divergent interests are not noise that occasionally intrudes into systems, but rather integral components of the real world? If so, our understanding of security may have been missing a dimension from the very start.
The Implicit Assumption of Passive Defense: A Normally Functioning World
Behind every defense system lies an assumption rarely spoken aloud: that a world definable as "normal" exists. In this world, people act according to rules, organizations operate according to processes, machines execute according to programs, and transacting parties honor their commitments. Attackers, fraudsters, traitors, malfunctions, and misjudgments are the aberrations. The task of defense, therefore, is understood as identifying anomalies, isolating them, and returning the system to its normal state.
This terminology inherently carries spatial implications: inside and outside, within the walls and outside the walls, trusted and untrusted, legitimate users and attackers. It is highly intuitive - a city is safe because enemies have not breached it; a company's finances are safe because no one has embezzled funds.
The issue is that the real world rarely operates in such a binary structure. Many of the most severe failures are not about enemies breaching the walls, but rather about collapses that occur within. The collapse of corporate governance is often not due to sudden attacks by strangers, but rather the abuse of power by someone who already possesses legitimate authority; financial crises do not necessarily stem from criminal activity, but rather from each participant making choices that are locally optimal for themselves; and institutional failures are less often the result of too many bad people, but rather because the entire system requires too many participants to be simultaneously rational, restrained, kind, and accurate. Even for an ordinary person, the daily objects of game theory are not enemies, but rather one's own impulses, cognitive biases, and ignorance of the future.
This implies a more sobering fact: risks do not only exist outside the system, but also within its components. Therefore, the idea of "keeping dangers out" becomes insufficient, as some dangers were never external to begin with, but rather existed internally. Once this is acknowledged, the focus of the issue shifts from "who has the capability to act" to a more fundamental question: who has the qualifications to define the boundaries of these actions.
True Progress in Civilization Is Not Just About Finding Good People
Looking back at the development history of modern systems, it can be found that humans have actually been forced to answer this question for a long time.
Ancient governance relied heavily on human qualities: expecting wise rulers, expecting virtuous ministers, expecting honest officials and loyal generals. Whether a system could function depended on whether the people in key positions were good people. This is a very natural logic - if those in power are smart, kind, and self-disciplined, many complex systems are indeed unnecessary. The problem is that no civilization can guarantee that every generation of leaders will possess these qualities simultaneously.
Thus, the modern system underwent a crucial shift. It no longer primarily asked "how to always elect a good person," but instead began to ask: "if one day an ordinary person, or even a bad person, comes into power, can the system still function?" The separation of powers, budget supervision, auditing, judicial procedures, boards of directors and independent directors, dual signatures, and financial controls - these seemingly unrelated arrangements share a simple idea: do not base the safety of the entire system on the integrity of a single individual.
This is a profound transformation, where society shifts from "seeking trustworthy individuals" to "designing trustworthy structures". Mature companies will not cancel financial approvals just because the CEO is honest, nor will they cancel audits just because the CFO has been faultless for ten years. Banks will not permanently close risk control just because a certain client has never defaulted. These institutions do not assume that everyone is untrustworthy, on the contrary, they simply acknowledge a more mature fact: good people can make mistakes, smart people can misjudge, loyal people can be tempted by interests, and kind people can also make disastrous decisions based on incorrect information.
A truly well-designed system never seeks to prove that human nature is evil; it simply refuses to assume that people are always right as a precondition for its operation.
One of the most important advancements of modern civilization may not be that we have finally cultivated more perfect people, but rather that we have gradually learned to live with imperfect people. Trust is still precious, but it has been put back into human relationships, rather than being used as a substitute for institutions.
From 'Risk' to 'Game', the Nature of the World Has Changed
Once the system is no longer reliant on the perfection of the subject, the world it faces also changes. "Risk" and "game" sound similar, but in fact they represent two completely different worldviews. Risk implies that a certain event may occur; a game means that participants in the system will continuously adjust their behavior based on each other's actions.
Heavy rainfall is a risk, but competitors are not; server crashes are a risk, whereas board members, employees, customers, regulatory agencies, and market rivals constitute a web of constantly evolving relationships. Risks can be estimated using probability, but games change because of your strategy itself: you modify the rules, your opponents adapt; you increase audits, they find new paths; you announce policies, participants recalculate their gains; you tighten restrictions, some exit, while others start seeking arbitrage opportunities.
The system now faces a dynamic set of dangers, rather than a static one - a world that observes you, adapts to you, exploits you, misunderstands you, and even co-evolves with you. This also explains why many systems are initially very effective, but later become ineffective - it's not that the rules have changed, but rather the rules have changed the behavior of the participants, and the participants' new behavior has in turn changed the effects of the rules.
Accepting the game as part of the system redefines the meaning of "security". It no longer means eliminating all dangers, but rather ensuring that the system does not amplify local errors into overall disasters, regardless of the actions of participants. The former pursues purity, while the latter pursues resilience; the former attempts to eliminate conflict, while the latter acknowledges conflict and makes structural allowances for it; the former believes that the system is stable when unattacked, while the latter requires the system to remain viable even when attacks, misjudgments, and conflicts of interest persist over the long term.
Fourth, 'Integrity' is a Deeper Concept than 'Security'
This is also why there is a need to reunderstand the concept of "completeness". When people talk about safety, they often think of it as "nothing going wrong"; but a truly mature system does not assume that accidents will not happen, on the contrary, it is fully aware that accidents will inevitably occur.
The integrity of a bridge does not mean it never encounters wind, the reliability of an airplane does not mean its parts never fail, the stability of a financial system does not mean the market never panics, and the integrity of a democratic system does not mean everyone always agrees. What integrity truly means is that a system can withstand internal stress: it allows mistakes to occur without immediately collapsing; it allows participants to have differing opinions without losing common rules; it allows certain nodes to fail without causing the entire network to fail; it allows certain individuals to be untrustworthy without causing all power to lose its constraints.
The value of the term "antagonistic totality" lies here, as it does not describe a "non-antagonistic complete state", but rather poses a more difficult question:
If confrontation always exists, can integrity still exist?
If the answer is yes, then integrity no longer comes from absolute trust between participants, but from the structure itself. This means that trust can transition from a personal attribute to a structural attribute. We no longer need to prove that "this person is completely trustworthy," but rather that even if they make a mistake, the consequences are still limited by the structure; we no longer need to prove that "all participants will eventually reach a consensus," but rather guarantee that when consensus cannot be reached, the system has clear exit, rejection, arbitration, and failure paths. Such a system is without illusions, and it is precisely for this reason that it is more stable than systems built on illusions.
Five, Truly Hazardous Systems Require Everyone to Do Things Right
Viewing this standard in reverse reveals what a truly hazardous system looks like.
Consider two systems. The first is extremely simple: one person makes a decision, and the system carries it out. When that person is well-informed, rational, and well-intentioned, it is extraordinarily efficient—in most cases, it performs better than even the most elaborate systems. It has only one flaw: that person cannot make a mistake. The second system appears cumbersome: a decision requires multiple conditions to align simultaneously, power is dispersed, some participants hold veto authority, and in abnormal situations the system would rather halt than proceed on default. It sacrifices some efficiency but gains a different capability: the error of any single individual need not become the error of the system.
Which one is more advanced. If we only observe the days when things run smoothly, the first one often appears more attractive. The value of the second one is only revealed on bad days. This is where the true difficulty of civilization lies - we are accustomed to evaluating structures based on their efficiency in normal times, but often only realize the original significance of the structure after a disaster has occurred.
Thus, the most vulnerable part of a system often lies not in the number of vulnerabilities it has, but in the number of prerequisites that must be met simultaneously: the operator remains rational, the manager is impartial, the information is complete, the software is error-free, the network is functioning normally, the upstream judgment is correct, the downstream execution is accurate, and all participants understand correctly. Each prerequisite seems reasonable on its own, but when they are linked together, fragility is formed - it only holds if everyone does everything right.
Even if someone does it wrong, the system can still do it right.
Six: The Most Mature System Never Requires the Eradication of Human Nature
Once the goal shifts from "making people right" to "preventing mistakes from being amplified," the system's attitude towards human nature will also change.
Throughout history, many failed systems have shared a common trait: they attempt to create an ideal person - one who is more selfless, rational, loyal, and obedient to the public interest. In contrast, mature systems take a different approach. A market economy does not require merchants to abandon their pursuit of profit; instead, it seeks to create social value through competition, contracts, and rules, under certain conditions. The modern corporate system does not assume that the interests of shareholders, management, and employees are naturally aligned; on the contrary, it acknowledges that these interests may conflict, which is why incentives, supervision, and governance are necessary. The law does not require humans to lose their impulse to commit crimes; it simply changes the cost and consequences of doing so.
Low-maturity systems attempt to transform participants, while high-maturity systems design the relationships between them.
In other words, a mature structure does not require human nature to disappear—it incorporates human nature into its design. Greed can exist, fear can exist, miscalculation can exist, and competition, distrust, even malice can all exist. But the system must answer one question: once these forces enter the structure, what do they ultimately get amplified into?
This is one of the most profound implications of game theory. It's not about teaching people how to defeat others, but rather about changing our understanding of systems - the outcome of a system is not equal to the sum of all participants' intentions. Structure shapes outcomes, rules change behavior, power dynamics alter incentives, and modes of failure alter decision-making. Therefore, truly advanced governance is no longer just about distinguishing between good and bad people, but about managing something else: what can happen when anyone is in any given position.
AI Agents Expose Long-Standing Issues
Today, a new entity is rapidly entering production, finance, software, operations, and organizational decision-making: the AI Agent. It can generate illusions, misinterpret commands, be influenced by prompt injection, potentially call the wrong tools, or execute a correct action at the wrong time, and even make completely incorrect decisions with fully legitimate permissions.
Many discussions treat it as a brand new issue and thus produce an impulse: can we train an Agent that is safe, intelligent, and reliable enough? This question is certainly important, but it may also lead us back into an old trap - searching for the perfect subject. In the past, we expected monarchs to be forever wise, later we expected administrators to be forever loyal, and today we start expecting models to be forever aligned. History repeatedly shows that such expectations are fragile in themselves: as long as the system's establishment relies on the "subject must always be correct", what's left is not whether it will fail, but only when it will fail.
The real challenge brought by AI agents may not be that machines have become unreliable for the first time, but rather that it forces us to confront a fact that has existed for thousands of years: any entity with the ability to act should not be assumed to be perfect, whether it is humans, organizations, software, or AI.
This also means that the focus of AI governance needs to shift. Evaluating a model's capabilities and tendencies is certainly necessary, but the reliability of a model's internal state can never be fully proven; what can be observed, constrained, and must be constrained is the path by which it translates judgments into real actions - what tools it calls, what permissions it uses, and what irreversible real-world states it changes. Therefore, the object of governance is gradually shifting from "what the model says" to "what the system allows it to do".
Confronting Adversity with Honesty, Not Pessimism
Many people, when they first hear of "adversarial completeness," think it's a pessimistic worldview: it assumes people will make mistakes, assumes systems will fail, assumes participants will clash, and even assumes that those empowered may also be part of the risk.
But the question worth asking is: is this pessimism, or honesty? A bridge designed with strong winds in mind does not mean the engineer is pessimistic; an aircraft built with redundancy for engine failure does not mean the aviation industry distrusts its engines; a company that institutes an audit system does not believe its employees are all criminals. Acknowledging that failure can happen is precisely the mark of humanity beginning to take reality seriously.
Fragile systems rely on hope - hoping everyone is kind, hoping every judgment is correct, hoping every communication is reliable, hoping every model understands accurately, hoping key nodes are always online. Mature systems, on the other hand, remove hope from their architecture: they allow hope to exist in human nature, but refuse to let the system's operation depend on hope.
The world doesn't have to be perfect before we can design reliable systems.
From Security Philosophy to Infrastructure Philosophy
When this set of judgments is extended to the infrastructure level, the issue becomes very specific. Imagine a type of infrastructure that provides a foundation for automated actions in the real world: when a real action needs to go through multiple entities, multiple systems, and multiple judgments to occur, why should we assume that any one of these nodes possesses ultimate correctness?
Once this assumption is abandoned, many things will naturally change. Power needs to be decentralized, and judgment and execution need to be distinguished - proposing an action and actually making it take effect in reality should not be the same thing. Different entities need to retain veto power, especially the ability to make a final refusal: no matter how confident and logical the upstream judgment is, the execution link can still say no, and this refusal does not need to prove that the upstream is wrong beforehand. Evidence cannot simply be post-event logs, but must become part of the structure, allowing each action to leave a traceable and accountable form as it occurs. Failure cannot be allowed to continue by default, and the system needs to have the ability to stop safely.
At this juncture, technology is merely the outcome of philosophy, not the other way around. The sequence is not to first decide on building a product and then search for a theory to justify it, but rather to first accept a judgment about the nature of reality—the premise that no subject deserves to be granted the assumption of absolute correctness—and then let architecture, protocols, hardware, governance mechanisms, and products grow forth from that judgment, layer by layer. Trust thus completes its migration: from trusted people to trusted structures.
This is also what makes infrastructure genuinely interesting. It has never been just code, servers, and equipment. Above all, it is a set of assumptions about how the world operates: how to understand trust, how to understand failure, how to understand power, how to understand human limitations, and what a system should actually do when faced with anomalies. Technology is merely the final, solidified shape these answers take.
Conclusion: Mature Systems Prevail Under Pressure
Perhaps one day, we will redefine the concept of "safety". Safety does not mean the absence of bad people, nor does it mean the absence of mistakes, conflicts, or even failures. True safety is first and foremost a structural sense of composure: even when these things do occur, the system still knows how to continue to function.
This marks the most significant shift from passive defense to game-theoretic ontology. We no longer view confrontation as an abnormal event that needs to be completely eliminated, but rather as a fundamental condition that exists in the real world in the long term; the goal of security is no longer to create a pure world, but to create a structure that can accommodate an impure world.
This may be one of the most important signs of a mature civilization. We no longer seek people who never make mistakes, no longer expect machines that are always correct, no longer fantasize about organizations without conflicting interests, and no longer try to build a world without confrontation. We have simply learned to do something more difficult and more realistic: how to make a world composed of imperfect entities still operate reliably.
And therefore, what ultimately needs to be governed is never a specific individual, nor a specific model.
What needs to be governed is the kind of unchecked power that directly turns judgments into reality.
Adversarial completeness is not a more pessimistic view of the world, but a more honest one. A truly mature system is also never built on the hope that "everyone will do the right thing" - it is built on the ability to continue functioning even if someone does the wrong thing.
