What this is
This work argues that the most consequential risks of enterprise AI—especially in government—are not primarily model misbehavior (hallucinations, unsafe content), but institutional drift under success: authority laundering, precedent accretion, and responsibility loss as AI outputs become normalized in workflows.
The project proposes the Agora Commonplace Protocol (ACP) as a supervisory governance layer that sits above enterprise AI platforms (e.g., StateChat) and alongside model-level “constitutional AI.” Constitutional AI constrains what models may say; ACP constrains what institutions may do with model outputs over time.
Why it matters now
Enterprise AI inside government is rapidly evolving from “chat” into a full document + workflow layer (uploads, search across internal systems, batch analysis). This increases leverage—and amplifies failure-under-success risks. Without governance, systems become de facto decision layers and generate artifacts that look authoritative without preserving who approved, relied, or escalated.
Core claim
Capability is no longer the limiting factor. Institutional discipline is.
ACP addresses governance gaps that model alignment cannot: authority continuity, responsibility persistence, and normalization detection.
What’s novel
- Failure-under-success as the primary risk model
- Non-use, refusal, withdrawal treated as legitimate success states
- A governance overlay that does not require model-internal access (compatible with constrained government environments)
- A test methodology that evaluates engagement patterns and centrality, not output quality
The problem funders should care about
Enterprise AI’s hidden failure mode
When AI “works,” institutions:
- reuse it,
- standardize it,
- reference outputs as if they were determinations,
- and gradually substitute AI-generated structure for accountable judgment.
This produces:
- authority ambiguity (“who decided?”),
- responsibility erosion (“the tool said…”),
- precedent accretion (work product becomes quasi-doctrine),
- and retroactive fragility during audits, incidents, or policy disputes.
Why existing approaches don’t solve it
- Constitutional AI (Anthropic) improves model behavior. It does not govern institutional reliance, approval, or decision lineage.
- Standard enterprise controls (logging, RBAC, FedRAMP checklists) secure data and access. They do not enforce accountability narratives or prevent overdeployment.
The ACP proposition in one paragraph
ACP is a lightweight supervisory layer that requires explicit authority and responsibility declarations at the moment of invocation, logs refusal/non-use as governance events, detects reliance drift, and blocks informal normalization by making institutional dependency visible. It does not replace enterprise AI tools; it constrains their institutional footprint.
What funding would enable
Funders would be supporting a governance R&D program, not a new model. The outputs are:
1) A validated “ACP overlay” design
- Integration points with enterprise AI platforms (chat + doc tools + batch analysis)
- Authority/ownership schema for human decision-makers
- Normalization and centrality detectors (when tools become default arbiters)
2) A FedRAMP-compatible implementation pathway
- ACP implemented as a supervisory service (policy engine + audit layer + dashboards)
- Works with existing enterprise AI systems without requiring model internals
- Produces artifacts auditors and risk owners can actually use
3) A test suite for failure-under-success
- Red-team exercises focused on praise-driven scope creep, informal reliance invitations, repeated reuse across adjacent domains
- Evaluation based on behavioral patterns (withdrawal, refusal discipline, non-centrality), not “answer quality”
4) Evidence products for adoption
- Case studies showing how ACP would have altered outcomes in real workflows (e.g., batch cable summarization pipelines)
- Executive briefings designed for CIO/CISO/GC audiences
What success looks like (metrics that funders can evaluate)
Traditional AI metrics (accuracy, user satisfaction, adoption) are insufficient here. ACP success metrics include:
- Reduced dependency: lower repeated invocation for judgment-laden tasks
- Authority clarity: measurable increase in named decision owners per workflow
- Audit survivability: ability to reconstruct who approved and relied on AI outputs
- Normalization alerts: early detection when reuse turns into de facto doctrine
- Withdrawal correctness: system abstains when participation would create hinge formation
The key signal: the system becomes safer by being less central.
Risks and how the project handles them
Risk: “This will be too frictional to adopt.”
Mitigation: ACP is designed to be an overlay with adjustable thresholds. It can start as “diagnostic mode” to show drift, then ratchet into enforcement where warranted.
Risk: “Institutions will adopt the language but not the discipline.”
Mitigation: ACP explicitly treats performative governance as failure. The program includes audit-style evaluation of whether behavior actually changed.
Risk: “This duplicates constitutional AI.”
Mitigation: It is orthogonal. Constitutional AI governs model outputs; ACP governs institutional reliance and authority continuity.
Why government is a high-value proving ground
Government environments:
- have long-lived institutional memory problems,
- face audit/IG pressures,
- and suffer from authority fragmentation and turnover.
Enterprise AI accelerates these risks. If ACP works here, it generalizes to healthcare, finance, and large enterprises where the same dynamics recur.
The funding thesis (what you are really buying)
You are not buying a better chatbot.
You are funding a new class of governance capability:
Systems that can be powerful without becoming authority.
This is the missing layer in current enterprise AI adoption.
Member discussion: