Skip to content

The Unit of Defense

Coadaptive Layer · Chapter 03

This chapter extends: SF² Adaptive Capacity (Section 02), SF² Implementation Guides (Section 06). Scope: what the operating unit becomes when AI joins, and what property defends it.

Security was historically organized around the person and their tools. The analyst ran the query, the engineer pushed the fix, the tool did what it was told and nothing more. The older frameworks could assume the unit was a person, because it was. That is the assumption that breaks. The unit is whatever cell holds the authority to act, and its composition is no longer fixed: a lone human, a lone agent running on its own initiative, a human and their agents paired, or several agents working as one system. The pair is the case that names the era, and the rest of this chapter dwells on it, but it is one shape of the unit rather than the definition of it. Defending a cell is not the same as defending a person who holds tools. What every shape shares is that the cell can act on its own judgment, including the parts of it that decide for themselves, and what every shape has to defend is the same: adaptive capacity rather than rule-compliance. The composition changes; the property does not.

Paired intelligence, the characteristic shape

The useful mental model is augmentation rather than subordination. Science fiction has been rehearsing it for years, most sharply in Martha Wells's Murderbot: a construct that is neither a tool waiting for a command nor a replacement for the humans it works beside, but a second intelligence sharing the work, with its own judgment and its own failure modes. That is the shape the era makes common: a human and one or more agents, paired, each covering what the other cannot.

This changes org design before it changes anything else. When the unit of work is a paired-intelligence cell, the org chart of individual contributors with tools is describing a world that no longer exists. The role that emerges is the strategic translator: the person who can hold the business intent, the technical reality, and the agent's behavior in one head, and steer the cell toward an outcome. The defensive question stops being "what can this person do" and becomes "what can this cell do, including the parts of it that decide for themselves."

The earned human anchor

The pair carries a quiet assumption: that a human stays in the cell, anchoring it. Name it, because it does not always hold. As agents take on more, the human's share of the work trends down, and at the limit it reaches zero: a lone agent on its own schedule with no human in the cell, a coding agent wired into the pipeline that opens and merges its own changes, a triage bot that closes findings unattended. That is a real operating unit today rather than a forecast.

What keeps a human in the cell is the stakes rather than the definition of the unit. Above a certain criticality, organizations keep a human as the decision gate, less because the cell needs supervising than because some actions have a downside no one will delegate: moving money, dropping a production datastore, granting standing access. That gate is a narrow, deliberately placed authority point, the kind the substrate is built from, with a person standing in it rather than a policy. Below that line the cell runs on its own. The threshold moves as confidence grows, and the direction is down: each capability the cell earns lowers the criticality at which a human gate still pays for itself. How fast it falls depends on which gate you mean, because two different clocks run here.

The routine gates run on a competence clock. For a low-stakes call, the only thing ever in the way was whether an agent could finish the work unsupervised, and that is now a measured, moving quantity. METR's task horizon, the length of task a frontier model completes unsupervised, doubled about every seven months from 2019 to 2025, and roughly every four months across 2024 and 2025. The lowest gates have already gone on that clock, the unattended agents named above among them: the pipeline agent that merges its own changes, the triage bot that closes findings while no one watches. At that doubling, the next five to ten years move most of the routine decision-gates into the cell itself.

The high-criticality gates are not on that clock. A human stays on the wire transfer because when it goes wrong, someone has to answer for it, and the accountability concentrates on the people who deployed it rather than transferring to the agent. What moves a gate like that is a shift in who is liable. When the card networks pushed counterfeit-fraud liability onto whichever party had not adopted chip cards in October 2015, chip terminals were at checkout counters across the country within about two years. The chip was not new technology: EMV had existed for decades, and what put it at every counter was the liability shift rather than a new capability. That is the governance clock: it runs on liability and trust, which the competence curve does not produce. Its floor is governance rather than competence, and that is the more durable result and the more interesting one.

Two clocks lower the human decision gate at different rates A chart of the criticality at which a human gate still pays for itself, plotted high to low against time. Two lines fall at different rates. The competence clock governs routine, low-stakes gates: it descends steeply and continuously, because the only thing ever in the way was whether an agent could finish the work unsupervised, and that is now a measured, moving quantity. METR's task horizon, the length of task a frontier model completes unsupervised, doubled about every seven months from 2019 to 2025, and about every four months across 2024 and 2025. At that rate, the next five to ten years move most routine decision gates into the cell itself. The governance clock governs high-criticality gates: it stays high and drops only in steps, when liability moves rather than when capability arrives. When the card networks shifted counterfeit-fraud liability in October 2015, chip terminals were at checkout counters across the country within about two years, though the chip technology itself was decades old; the liability shift moved it rather than a new capability. The governance gates hold longest because someone has to own the irreversible call, and that floor is governance rather than competence. Two clocks lower the human gate at different rates criticality a human gate still pays for high low time liability shift high-criticality gates governance clock: moves on liability rather than competence routine gates competence clock METR task horizon doubles about every 7 months (2019 to 2025), about every 4 months (2024 to 2025): 5 to 10 years moves most routine gates into the cell. EMV chip-card liability shift, October 2015: chip terminals nationwide in about 2 years. Routine gates fall on competence; high-criticality gates hold until liability moves. The gates that hold longest hold because someone has to own the irreversible call. Build that ownership now, at the gates capability will never hand you.
Two clocks. The competence clock drops routine gates steeply and continuously as the task horizon doubles; the governance clock holds high-criticality gates and lowers them only in steps, when liability moves. The governance floor is the durable one.

The gates that hold longest hold because someone has to own the irreversible call. The human-factors literature is blunt about the trap that floor sets. A person kept at the gate without real control becomes the moral crumple zone for the system that failed around them rather than anchoring responsibility. So the gate worth keeping is meaningful control rather than a name on the form, where the consequential call still traces back to a human who held the reasons for it. The move this points to is to build that ownership and judgment now, at the gates that will outlive the competence argument, because it is the part capability will never hand you.

Three things would falsify the timing. If the doubling stalls, the plateau the investment chapter hedges against, the competence clock slows and the routine-gate window stretches past ten years. If the routine gates stay manned anyway as the horizon keeps growing, then competence was never the binding constraint and this framework mistook a governance fact for a capability forecast. And if the high-criticality gates fall fast, because the liability moves rather than because the capability arrives, the way it moved for chip cards, then "the governance gates hold longest" is wrong at the top end; insurers are already drafting coverage for autonomous action and underwriting it by the level of authority the agent holds, and a market like that could empty a high gate without a single new model. The durable claim holds across all three: the cell is the unit, whatever its composition, and the human in it is the decision gate by criticality rather than by definition. Below the line the human is still in the cell, doing the work; what criticality earns is the gate rather than the presence.

Adaptive capacity as the property

The property that defends a paired-intelligence cell is the one resilience engineering has studied for decades. Adaptive capacity is the ability to keep functioning when conditions move outside what anyone planned for, and it sits above rule-following because rules only cover the situations someone anticipated. The same finding runs through Hollnagel, Woods, and Cook, whose full citations sit in the references: resilient systems are the ones that adapt at the edge of their envelope rather than the ones with the most rules.

This is continuity with the tradition rather than a break from it. The base framework's Adaptive Capacity condition carries the lineage; this chapter applies it to the new unit. A paired-intelligence cell defends itself by adapting, by sensing when the situation has left the map and adjusting, which is exactly the capacity the AI-era threat surface demands, because that surface generates situations faster than any rulebook can be written for them.

The holobiont undercurrent

A deeper framing is worth keeping in view, even though it does not belong on the cover. In biology, a holobiont is a host and its resident organisms treated as a single entity, coupled tightly enough that some argue selection acts on the whole rather than the parts. Whether that holds for real host-microbe systems is a live debate among biologists, so the analogy is the only thing being borrowed here. The human and their agents are coupled in something like the same way, which suggests that defending the human and the agents separately may be the wrong cut and the pair is the right unit of analysis. The biology is suggestive rather than load-bearing, and a framework that leads with "holobiont" spends credibility it should save for the argument, so the concept stays an undercurrent and earns its keep as vocabulary rather than as a name the layer flies under.

See also