When people talk about AI governance, they usually mean policies, laws, ethics statements, or alignment strategies. Design is treated as something secondary: usability, aesthetics, convenience. This is a mistake. Interface design is one of the primary ways governance is exercised, often more powerfully than formal rules, precisely because it operates silently.

Across disciplines—aviation, nuclear energy, medicine, cartography, industrial safety, and military systems—this has long been understood. Interfaces do not merely display information; they structure perception, constrain action, allocate responsibility, and shape error. A poorly designed interface does not simply confuse users. It governs them into predictable failure modes and then assigns blame downstream.

This is not a theoretical claim. It is an empirical one, documented repeatedly in accident investigations, safety standards, and design literature.

In nuclear engineering, the Three Mile Island accident revealed how control-room interfaces obscured system state and misled operators under stress. In medicine, interface design in electronic health records has been shown to increase unsafe prescribing—not because clinicians are careless, but because the system makes dangerous actions easier than safe ones. In elections, ballot design has demonstrably altered democratic outcomes by nudging voter behavior through layout and affordance. In aviation and defense, entire fields of interface management exist precisely because human error is often a design artifact, not a human trait.

A particularly clear modern example is the 2018 Hawaii false missile alert. There was no AI failure, no malicious actor, no lack of training. The interface presented a live emergency option indistinguishable from a test option, with no friction, confirmation gradient, or visible escalation boundary. Once triggered, the system provided no immediate reversal pathway. The interface did not merely allow an error; it encoded one. Governance failed at the level of design.

This is where the NFPA analogy becomes useful. In industrial systems, hazards are not hidden to preserve user comfort. They are signaled explicitly—through labels, color codes, access restrictions, and graduated warnings. The purpose is not to eliminate risk, but to make risk legible. No one mistakes a high-voltage panel for a light switch, because design communicates authority, danger, and constraint.

AI interfaces do almost the opposite. They present extraordinary capability through conversational familiarity, flatten uncertainty into fluent output, and obscure where compression, omission, or probabilistic inference is occurring. The user is invited to treat the system as confident, coherent, and authoritative—without any equivalent of hazard signaling.

The core claim of the ACP design arc is simple but demanding:

If an interface shapes decisions, it is exercising governance—and must be designed as such.

This has several implications.

First, compression must be disclosed. Every interface is an abstraction, but abstractions govern differently depending on what they reveal and what they hide. Maps are a useful analogy: contour lines compress terrain into legible gradients that support navigation, while clearly signaling that the map is not the land. A map that hid elevation while suggesting flatness would not be “neutral”—it would be dangerously misleading. AI interfaces often do exactly this with epistemic terrain.

Second, authority must be visible and bounded. Users should be able to tell when a system is suggesting, summarizing, refusing, deferring, or requiring human judgment. Authority should never be inferred from tone or fluency alone.

Third, failure must be anticipated at the interface level, not explained away afterward. Post-hoc narratives about “user misuse” are usually confessions of design negligence. Systems should make unsafe actions harder than safe ones, and irreversible actions visibly costly.

Finally, design must support refusal, override, and escalation as first-class interactions—not exceptional breakdowns. A system that cannot say “I don’t know,” “I can’t do that,” or “This requires human review” is not aligned; it is unmanaged.

These principles are not speculative. They are drawn from decades of work in safety engineering, human factors, cartography, military interface management, accessibility design, and accident investigation. What is unusual is not the ideas themselves, but their absence from mainstream AI discourse.

ACP treats interface design as a governance surface because institutions already do. Regulators audit interfaces. Investigators reconstruct them. Operators live inside them. Power flows through what systems allow, discourage, hide, and normalize.

This design arc will examine interface failures, safety analogies, and concrete design patterns—not to optimize user engagement, but to make authority, risk, and limitation legible. Language learning, explored later, will serve as a deliberately “soft” domain to demonstrate how the same principles apply even where stakes are low—precisely because governance is easiest to see there.

Design is not downstream of governance.
It is where governance quietly happens first.