Interface failures are rarely novel.
Across domains—aviation, medicine, nuclear power, elections, software, and now AI—the same failure patterns recur, disguised by new technologies and vocabularies.
This essay proposes a functional taxonomy of interface failures, not to assign blame, but to make governance-visible what is otherwise misattributed to “human error.”
Category I: Ambiguous Authority Interfaces
Failure mode:
The interface does not clearly indicate who has authority, when, or over what.
Examples:
- Three Mile Island control panels, where conflicting indicators obscured reactor state
- EHR systems allowing junior staff to initiate high-risk prescriptions without friction
- AI chat interfaces that answer legal or medical questions with no visible boundary
Pathology:
Users act beyond mandate because the interface never signals limits.
Governance failure:
Authority is exercised implicitly instead of explicitly.
Category II: False Affordance Interfaces
Failure mode:
The interface suggests an action is safe, reversible, or routine when it is not.
Examples:
- Ballot designs that imply equivalence between unequal choices
- Missile alert systems with “test” and “send” options placed adjacently
- One-click AI deployment into production environments
Pathology:
Ease is mistaken for safety.
Governance failure:
Affordance is confused with permission.
Category III: Compression-Induced Misrepresentation
Failure mode:
Complex system states are collapsed into simplified outputs that obscure uncertainty.
Examples:
- Reactor dashboards summarizing multiple subsystems as “normal”
- Medical summaries hiding contraindications
- AI-generated summaries replacing primary sources
Pathology:
Confidence increases while understanding decreases.
Governance failure:
Compression is undisclosed and unbounded.
Category IV: Delayed or Absent Feedback Loops
Failure mode:
The system does not provide timely, interpretable feedback about consequences.
Examples:
- Financial trading interfaces where risk manifests only after delay
- Algorithmic content systems that externalize harm
- Language apps that never reveal pragmatic failure
Pathology:
Users cannot learn from action because consequences are invisible or displaced.
Governance failure:
Responsibility is temporally disconnected from action.
Category V: Irreversible Action Interfaces
Failure mode:
High-impact actions are triggered without sufficient friction, confirmation, or escalation.
Examples:
- Therac-25 radiation overdoses
- Automated content moderation takedowns
- AI systems executing actions without human sign-off
Pathology:
Speed substitutes for judgment.
Governance failure:
Irreversibility is hidden until too late.
Category VI: Role Confusion Interfaces
Failure mode:
The interface collapses multiple roles into a single interaction surface.
Examples:
- Pilots acting as system monitors, troubleshooters, and decision-makers simultaneously
- Teachers positioned as both evaluators and emotional supports
- AI systems acting as advisor, executor, and explainer at once
Pathology:
Cognitive overload masquerades as versatility.
Governance failure:
Roles are not separated or sequenced.
Category VII: Blame-Shifting Interfaces
Failure mode:
Design obscures systemic causes and localizes failure in the user.
Examples:
- “Operator error” findings following UI-driven accidents
- Complex forms that penalize mis-entry without guidance
- AI disclaimers that absolve system designers post hoc
Pathology:
Institutions learn nothing because failure is personalized.
Governance failure:
Accountability is displaced downward.
Why This Taxonomy Matters for AI
Most AI failures currently labeled as:
- hallucination,
- misuse,
- overreliance,
- or user misunderstanding
are interface failures belonging to one or more of the categories above.
They are predictable.
They are repeatable.
They are preventable.
But only if treated as governance problems, not optimization problems.
ACP’s Position
ACP does not claim to eliminate these failures.
It claims to:
- surface them earlier,
- signal them explicitly,
- and constrain their downstream impact.
A system that makes its failure modes legible is not safe—but it is governable.
That is the standard.
Member discussion: