# Corrigibility

Software decides who gets paid, who gets counted and who gets refused.
Corrigibility asks one blunt question of any such system: can the people it
decides about make it change its mind?

Canonical: https://anivar.net/corrigibility/
Terminology: https://anivar.net/corrigibility/glossary.md
Licence: CC0 1.0 — reuse, translation and adaptation need no permission.

## What corrigibility is

Corrigibility is the property of a system in which affected participants can detect, contest, and structurally override systemic error.

It is not transparency, accountability, openness or auditability in isolation.
A system can publish documentation, provide APIs and maintain oversight boards
and remain incorrigible, because none of those gives the people it
misclassifies any binding means of correction.

## The five conditions

An infrastructure is corrigible if and only if it satisfies five jointly
necessary conditions, which together close the feedback loop between what the
system does and what the people inside it can correct.

### EXIT — Can you walk away?

Participation is reversible without disproportionate penalty.

### CODE — Can anyone read the rules?

The logic that decides is publicly inspectable.

### AUDIT — Can outsiders check without permission?

Behaviour is verifiable by parties the operator does not select.

### GOVERN — Can the governed bind the operator?

Rule changes are accessible to the affected and enforceable.

### FORK — Could somebody else rebuild it?

The system can be reproduced by an independent party.

Partial compliance is functionally equivalent to complete failure. Failure of
any one condition opens the loop, and an open-loop system executes without the
capacity to sense deviation or apply correction.

## Why partial compliance fails

A system's corrigibility status equals its weakest layer across any test
dimension; strength at one layer cannot compensate for failure at another.

Courts and ombudsmen operate on bureaucratic time, measured in months;
infrastructure operates on digital time, measured in milliseconds. Channels
that record dissatisfaction without a binding mechanism to modify execution are
not a feedback loop.

## Eighteen systems pass all five

From the paper, Table 6. The evaluations assess governance architecture, not
operational performance — a system can be simultaneously useful and incorrigible.

- Linux Kernel — Linux Foundation
- Let’s Encrypt — ISRG
- Wikipedia — Wikimedia Foundation
- Matrix Protocol — Matrix.org Foundation
- Bluesky · AT Protocol — Bluesky PBC
- PostgreSQL — PGDG
- IPFS — Protocol Labs
- Bitcoin — Decentralised
- Kubernetes — CNCF
- Firefox — Mozilla Foundation
- Apache HTTP — Apache Foundation
- Apache Kafka — Apache Foundation
- OpenSearch — Linux Foundation
- Valkey — Linux Foundation
- Hyperledger — LF Decentralized Trust
- LibreOffice — Document Foundation
- MariaDB — MariaDB Foundation
- Eclipse IDE — Eclipse Foundation

A pattern the framework does not flatter: these systems are predominantly
non-essential. No individual's survival depends on reaching Linux or Let’s
Encrypt. The correlation between corrigibility and non-essentiality is
structural, and it is the problem the political economy half of the paper is
written to explain.

## How rigorously a claim is being verified

- **Presence** — Laws, bodies and policies exist on paper.
- **Behaviour** — Controls execute under stress; audits carry consequences.
- **Proof** — Trust is continuously testable, authority is scoped and revocable, claims are machine-verifiable, failures are bounded.

Most deployments satisfy Presence. Few reach Behaviour. Almost none achieve
Proof. The conditions define what to verify; the tiers define how hard.

## The papers

### Corrigibility as a Structural Precondition for Digital Public Infrastructure: A Cybernetic Framework

Deterministic public infrastructure · vv3.0 · 54 pages
doi:10.2139/ssrn.6059075 · full text: https://anivar.net/papers/dpi.md

### Epistemic Capture and the Action Boundary: Corrigibility for Learned and Agentic Public Infrastructure

Learned and agentic infrastructure · vrev. 11 Jul 2026 · 37 pages
doi:10.2139/ssrn.6669318 · full text: https://anivar.net/papers/epi.md

Machine index: https://anivar.net/llms.txt · Full text of everything: https://anivar.net/llms-full.txt
