After major system failures, institutions almost always reach for the same explanation: human error.
This is rarely a neutral diagnosis. It is a governance move.

Labeling failure as human error reallocates responsibility downward, away from system designers, managers, and institutions, and toward operators who were acting under constrained, ambiguous, and often misleading conditions. Interface design plays a decisive role in this shift. What appears as individual failure is frequently the predictable outcome of how information, authority, and action are structured at the interface level.

Design, in other words, is not merely about usability or efficiency. It is about who is allowed to know what, when action becomes irreversible, and where blame ultimately lands.


The Problem with “Human Error”

Human factors research has shown for decades that error is not an aberration but a normal feature of complex systems. Operators do not fail in isolation; they fail in context. When interfaces obscure system state, overload attention, or present misleading signals, error becomes not just possible but inevitable.

Yet institutional narratives often reverse this causality. Instead of asking whether the system made correct action possible, post-incident reviews ask why the operator failed to act correctly. This framing preserves institutional legitimacy by treating failure as a deviation rather than a design outcome.

The result is a paradox: the more complex and opaque the system, the more blame is placed on the humans least able to see or influence it.


Three Mile Island: A Canonical Interface Failure

The 1979 Three Mile Island nuclear accident is often described as a near-miss caused by operator mistakes. A closer examination tells a different story.

In the early hours of the incident, a relief valve stuck open, allowing coolant to escape from the reactor core. The control room indicator, however, showed that the valve had received a signal to close—not that it was actually closed. Operators believed the system was retaining coolant when, in reality, it was steadily losing it.

At the same time, the control room was flooded with alarms—hundreds of them—without prioritization or clear causal grouping. Operators were forced to infer the state of the reactor from fragments: component statuses, indirect measurements, and contradictory signals. Crucially, the interface did not present an integrated view of system state. It showed parts, not behavior.

The operators’ actions were not irrational. Given the information available to them, they were locally reasonable. The failure lay in the interface’s inability to represent reality in a way that supported safe decision-making under pressure.

To call this “human error” is to misunderstand the nature of the failure. The system made correct interpretation structurally difficult, if not impossible.


A Repeating Pattern Across Domains

Three Mile Island is not an outlier. The same pattern appears across high-risk domains.

In the Therac-25 radiation therapy accidents, operators administered lethal overdoses because the interface provided no feedback indicating unsafe internal states. The system allowed actions that appeared valid on the surface but were catastrophic underneath. Post-incident blame again focused on users, despite the absence of diagnostic visibility.

In elections, poorly designed ballots have repeatedly led to systematic misvotes. These errors are predictable, repeatable, and distributed across populations—classic signs of interface-induced failure. Yet responsibility is often attributed to voter confusion rather than design geometry.

Across cases, the structure is consistent: interfaces hide critical constraints, users act on incomplete representations, and institutions retroactively assign blame to individuals.


Design as Governance

Interfaces govern by shaping action space. They determine what can be seen, what must be inferred, and when decisions become irreversible. Whether acknowledged or not, this is an exercise of power.

An interface that presents an action as available implicitly authorizes it. An interface that fails to signal uncertainty invites overconfidence. An interface that offers no path to refusal or escalation silently enforces compliance.

These are not neutral choices. They embed assumptions about trust, expertise, and responsibility directly into the system’s surface. Governance happens not only through policy documents and oversight bodies, but through dashboards, alerts, forms, and buttons.


Why AI Systems Intensify the Risk

AI systems amplify these dynamics because they compress complexity into outputs that appear authoritative while obscuring uncertainty, provenance, and limits. The interface becomes the primary site where epistemic authority is exercised.

When an AI system presents a synthesized answer without signaling omission or ambiguity, it invites deferral. When it lacks visible refusal or escalation mechanisms, it appears competent even where it should not act. The problem is not intelligence but presentation.

This is not a tradeoff to be optimized away. It is the cost of deploying systems whose interfaces do not truthfully represent what they can and cannot safely do.


ACP’s Intervention: Making Limits Visible

The Agora Commonplace Protocol (ACP) does not attempt to eliminate error or perfect interfaces. Instead, it insists that interfaces must declare their constraints.

ACP treats refusal, deferral, and uncertainty as first-class interaction states. It requires visible authority boundaries, explicit ownership, and disclosure of compression where it occurs. Rather than assuming that correct behavior will emerge from better alignment, ACP demands that systems make their limitations legible before harm occurs.

In this sense, ACP reframes interface design as an institutional responsibility. It shifts the question from “Why did the user fail?” to “What did the system make possible, visible, or unavoidable?”

That shift is not cosmetic. It is the difference between blaming operators after the fact and designing institutions that can account for failure in advance.


Design does not merely shape experience. It allocates responsibility.
When interfaces fail, institutions reveal what they value—and who they are willing to sacrifice to preserve it.