<script data-pm-proxy="intercept"></script><?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Structure and Guarantees]]></title><description><![CDATA[What kinds of AI systems should we build?  A perspective mixing mathematical guarantees, scalable engineering, and evolutionary dynamics.]]></description><link>https://stng.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!J9m6!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15a93629-5be6-45ce-b233-6db56bef6e96_533x533.png</url><title>Structure and Guarantees</title><link>https://stng.substack.com</link></image><generator>Substack</generator><lastBuildDate>Fri, 04 Sep 2026 18:13:40 GMT</lastBuildDate><atom:link href="/__u/stng.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Adam Chlipala]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[stng@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[stng@substack.com]]></itunes:email><itunes:name><![CDATA[Adam Chlipala]]></itunes:name></itunes:owner><itunes:author><![CDATA[Adam Chlipala]]></itunes:author><googleplay:owner><![CDATA[stng@substack.com]]></googleplay:owner><googleplay:email><![CDATA[stng@substack.com]]></googleplay:email><googleplay:author><![CDATA[Adam Chlipala]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[An "Anthropic Principle" for Formulations of AI Alignment]]></title><description><![CDATA[Predicting who can ask the question]]></description><link>https://stng.substack.com/p/an-anthropic-principle-for-formulations</link><guid isPermaLink="false">https://stng.substack.com/p/an-anthropic-principle-for-formulations</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 01 Sep 2026 13:13:10 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/9136e379-7a54-4926-90f4-00015ff7f5fa_576x273.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>One natural formulation of AI alignment, the study of how to be sure our highly capable software acts according to our interests, starts from unambiguous descriptions of human values (whether an AI starts with hardcoded values or learns them). This concept is mostly speculative, as we are far from knowing how to formalize our values precisely enough. <a href="/__u/stng.substack.com/p/ai-alignment-at-which-abstraction">My last article</a> considered two reasons why we might want to hesitate to build in a model of humans. In my mind, the more important reason is that, from an engineering perspective, it seems wickedly difficult to formalize human values precisely enough, let alone formalize values of <a href="https://www.lesswrong.com/w/coherent-extrapolated-volition-alignment-target">some extrapolation of &#8220;better&#8221; humans</a>. There are also other objections that are more philosophical, e.g.: if our future AI systems meet <em><a href="https://en.wikipedia.org/wiki/Star_Trek">Star Trek</a></em>-style aliens who are like us but blue, is it really proper to ignore the aliens&#8217; interests? Is it safe to assume that some extrapolation to &#8220;better&#8221; humans necessarily respects blue aliens, given humanity&#8217;s dismal record in other first contacts?</p><p>For the rest of this article, let&#8217;s step back to a technical problem: how do we formalize identification of which agents alignment should focus on? We have one conventional &#8220;test case&#8221; that is almost too obvious to state: in our present circumstances, this rule should identify people as the agents to focus on. There should also be good reason to believe the rule makes proper decisions in other circumstances. We also want it to be plausible that the same rule is substantially easier to implement in software than any approach based on reverse-engineering human values.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>I&#8217;ll start with a big-picture consideration of how intelligence has increased in the universe over time, but I promise I&#8217;ll return to the original goal.</p><h2>Who Could Think About Alignment?</h2><p>The <a href="https://en.wikipedia.org/wiki/Anthropic_principle">anthropic principle</a> explains the apparently improbable fact that we inhabit a universe capable of developing intelligent life. An awful lot of random chance needed to line up properly to produce us. However, the question &#8220;how did we get here?&#8221; can only be asked by life intelligent enough to think abstractly and formulate the question. Yes, there may be many possible universes compatible with a broad formulation of physics, and likely only a small minority of them are compatible with intelligent life having evolved. Hence, contingent on someone being able to ask the question of how we wound up here, we must be in one of the universes conducive to intelligent life evolving.</p><p>Let me now develop this kind of thinking toward a principle that <em>any agent at roughly the computational scale to support thinking about AI alignment should be defined as a proper focus for alignment</em>. Instead of making a somewhat arbitrary choice up-front about which agents qualify, let&#8217;s try to define alignment once and for all to capture all beneficiaries. (We&#8217;ll come shortly to a twist that keeps literal application of this idea from taking us where we expect, motivating a fix.)</p><p>In this explanation, I&#8217;m going to embrace <a href="https://en.wikipedia.org/wiki/Computational_theory_of_mind">the computational theory of mind</a> shamelessly, because it has always felt natural to me. This theory says that brains are understood as special kinds of computers, so thinking about computation broadly subsumes thinking about (biologically embodied) intelligence. For now, we&#8217;ll discuss at an abstract level, but the next section will concretize to <em>societies of humans</em> (not atomized individuals) as critical computational systems.</p><p>Some computational architectures can host the kind of abstract thought that leads to asking big questions about the universe. Some can&#8217;t. Let&#8217;s simplify for the moment and think in terms of one linear dimension of computational power. Consider how much such power is needed to be able to design <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">recursively self-improving</a> AI. Presumably there is some relatively well-defined minimum level. If self-improvement is kicked off thoroughly enough to cause an <a href="https://en.wikipedia.org/wiki/Technological_singularity#Intelligence_explosion">intelligence explosion</a>, then quickly all the rules change, and the familiar alignment problem no longer applies, or at least its context becomes so different that the ideal rules are probably different. For example, AI designing AI is likely to have better explicit, formal/algorithmic understanding of its own values than we do, if it is successful creating its own successors.</p><p>These observations combine to suggest that <strong>there is a narrow window of computational power that naturally evolved intelligence can have when it is working on formulating alignment</strong>: it must have passed the minimum power threshold but <em>not yet</em> have begun an intelligence explosion. The window is narrow if we assume that solving alignment requires fairly similar tools to designing recursively self-improving systems. And let&#8217;s remember that we&#8217;re comparing slow biological evolution to faster deliberate engineering (a la <a href="https://en.wikipedia.org/wiki/Ray_Kurzweil">Kurzweil</a>&#8217;s <a href="https://en.wikipedia.org/wiki/The_Law_of_Accelerating_Returns">Law of Accelerating Returns</a>), so a &#8220;narrow window&#8221; might be, say, 1000 years.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!IC-z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6abf72e-68d9-410a-91e7-429a0dd0cf87_988x1490.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!IC-z!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6abf72e-68d9-410a-91e7-429a0dd0cf87_988x1490.png 424w, /__u/substackcdn.com/image/fetch/$s_!IC-z!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6abf72e-68d9-410a-91e7-429a0dd0cf87_988x1490.png 848w, /__u/substackcdn.com/image/fetch/$s_!IC-z!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6abf72e-68d9-410a-91e7-429a0dd0cf87_988x1490.png 1272w, /__u/substackcdn.com/image/fetch/$s_!IC-z!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6abf72e-68d9-410a-91e7-429a0dd0cf87_988x1490.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!IC-z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6abf72e-68d9-410a-91e7-429a0dd0cf87_988x1490.png" width="988" height="1490" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d6abf72e-68d9-410a-91e7-429a0dd0cf87_988x1490.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1490,&quot;width&quot;:988,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:875165,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/213700275?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6abf72e-68d9-410a-91e7-429a0dd0cf87_988x1490.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!IC-z!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6abf72e-68d9-410a-91e7-429a0dd0cf87_988x1490.png 424w, /__u/substackcdn.com/image/fetch/$s_!IC-z!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6abf72e-68d9-410a-91e7-429a0dd0cf87_988x1490.png 848w, /__u/substackcdn.com/image/fetch/$s_!IC-z!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6abf72e-68d9-410a-91e7-429a0dd0cf87_988x1490.png 1272w, /__u/substackcdn.com/image/fetch/$s_!IC-z!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6abf72e-68d9-410a-91e7-429a0dd0cf87_988x1490.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So we can potentially formulate alignment in terms of the minimum level of computational capacity that could think about alignment. The definition wouldn&#8217;t literally be recursive &#8211; it would just happen to talk about the relevant computational level, which happens to be the one that we as humans inhabit (the coincidence explained in this way being reminiscent of the anthropic principle). Then we automatically &#8220;pick up&#8221; the agents we meant to detect.</p><h2>Layered Intelligence</h2><p>Is there one linear measure of computational power that predicts enough about the values of intelligence? Maybe not, but let&#8217;s add one more dimension and see what may get easier to predict. I&#8217;ve previously suggested a unifying slogan for this blog, <a href="/__u/stng.substack.com/p/intelligence-depends-on-organizing">&#8220;intelligence depends on organizing computation correctly and efficiently&#8221;</a>, that is relevant here. Just measuring some notion of the number of atomic units of computation doesn&#8217;t do the job. It matters how those units work together to solve hard problems.</p><p>It&#8217;ll help to orient ourselves with a concept from biology: <a href="https://en.wikipedia.org/wiki/The_Major_Transitions_in_Evolution">evolutionary transition in individuality</a>. A great canonical example is more-primitive parts coming together to form cells, which come together to form organisms. At each step, units that had operated independently and even competed with each other find new ways to coordinate and function as coherent wholes. (To head off any confusion, I&#8217;ll note that while I&#8217;ve found writing on such transitions in an AI-futurism context, it seems to have gone in very different directions from what follows: <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC9869444/">humans merging with AI</a> and <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC9869447/">humans by ourselves becoming larger social macro-organisms</a>.)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!d-Zo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab38bd30-5206-48ee-8779-ed2d461d899e_1507x885.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!d-Zo!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab38bd30-5206-48ee-8779-ed2d461d899e_1507x885.png 424w, /__u/substackcdn.com/image/fetch/$s_!d-Zo!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab38bd30-5206-48ee-8779-ed2d461d899e_1507x885.png 848w, /__u/substackcdn.com/image/fetch/$s_!d-Zo!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab38bd30-5206-48ee-8779-ed2d461d899e_1507x885.png 1272w, /__u/substackcdn.com/image/fetch/$s_!d-Zo!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab38bd30-5206-48ee-8779-ed2d461d899e_1507x885.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!d-Zo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab38bd30-5206-48ee-8779-ed2d461d899e_1507x885.png" width="1456" height="855" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ab38bd30-5206-48ee-8779-ed2d461d899e_1507x885.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:855,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1051822,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/213700275?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab38bd30-5206-48ee-8779-ed2d461d899e_1507x885.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!d-Zo!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab38bd30-5206-48ee-8779-ed2d461d899e_1507x885.png 424w, /__u/substackcdn.com/image/fetch/$s_!d-Zo!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab38bd30-5206-48ee-8779-ed2d461d899e_1507x885.png 848w, /__u/substackcdn.com/image/fetch/$s_!d-Zo!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab38bd30-5206-48ee-8779-ed2d461d899e_1507x885.png 1272w, /__u/substackcdn.com/image/fetch/$s_!d-Zo!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab38bd30-5206-48ee-8779-ed2d461d899e_1507x885.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The world of manmade computers exhibits similar layering. I argued previously for <a href="/__u/stng.substack.com/p/abstraction-boundaries-and-bubbles">the opportunity to introduce new abstraction layers when AI is adopted pervasively enough</a>, with the potential to provide similar benefit as from the celebrated <a href="https://en.wikipedia.org/wiki/Digital_signal">digital abstraction</a> that underlies most electronic circuits. A single computer, say one suited to act as an Internet server, is built out of components but is structured such that the computer appears to act with one purpose. Individual logic gates may fail or glitch, but it happens infrequently enough to be an exception to the rule, which we usually avoid thinking about. We then see companies putting many computers together into <a href="https://en.wikipedia.org/wiki/Data_center">data centers</a>. Through marvels of engineering, these computers can <em>also</em> be seen as acting together for single purposes. Because of the sheer scale, component failures are more common, but good design of <a href="/__u/stng.substack.com/p/our-social-world-as-a-distributed">distributed systems</a> typically hides those failures admirably well, just as our human bodies prevent cancer at the cellular level most of the time but not always.</p><p>However, consider the step up from data centers to the whole Internet. Different data centers are owned by different organizations that compete with each other. It is emphatically <em>not</em> the case that the Internet acts as though it had a uniform purpose, abstracting away the actors that comprise it. Likewise, while humans may abstract their constituent cells well, a global economy populated by humans absolutely reveals the motivations of individual people. <a href="https://lips.cs.princeton.edu/what-is-the-computational-capacity-of-the-brain/">The human brain is thought to</a> be able to perform the equivalent of about 10^15 <a href="https://en.wikipedia.org/wiki/Floating_point_operations_per_second">floating-point operations per second</a> (subject to standard caveats about brains being interestingly different from GPUs). <a href="https://en.wikipedia.org/wiki/Frontier_(supercomputer)">The Frontier supercomputer</a> hits about 10^18 in the same dimension. On top of the apparent lead for manmade computers, there is a critical difference between these substrates. Humans roll up into larger social groups, but we maintain individuality that gives rise to continuing conflict and competition within those groups. In contrast, supercomputers can be agglomerated into data centers with uniform governance, providing useful abstractions of working together on single computations on behalf of single owners. Hence, it remains <em>relatively</em> straightforward to increase the scale of a supercomputer (i.e., wait a few years for the next generation to be developed). While brains retain an advantage in power efficiency, we see that <strong>deliberate engineering has achieved a scale of internally well-aligned computation well beyond what biological evolution ever has, and it is plausible that this gap only grows with time</strong>.</p><p>I don&#8217;t mean to say that human brains considered as isolated computers are capable of formulating alignment and developing self-improving AI. Instead, we&#8217;ve depended on culture and social structures that agglomerate such brains into larger processes surprisingly close to the scale of frontier data centers. That scale may be <em>necessary</em> to tackle either AI-related problem. So, when we measure evolution approaching a threshold to be able to begin tackling those problems, we are considering not just the units with good integrated alignment (like individual people) but also the larger agglomerations that are needed to get the work done. One conjecture here, then, is that <em>the first computational systems powerful enough to formulate alignment will be societies of relatively loosely integrated individuals</em>: we need fairly powerful well-integrated individuals to get real thinking done, but they also need to work together at a pretty large scale to realize the important questions and work out solutions to them.</p><p>This observation suggests that we define a computational-power floor applied <strong>only to units with strong internal alignment</strong>. We backsolve for that floor by analyzing what seems to be necessary to support the right kind of abstract thinking, but I don&#8217;t think it&#8217;s necessary to characterize the larger, less-integrated computational systems directly &#8211; just to be inspired by examples in choosing constants. This move is, at one level, unsatisfying, taking us back toward an alignment condition that seems arbitrarily biased toward one kind of intelligence. The potential saving grace comes from the previous section: <em>the possibility of one Goldilocks band of computational capacity sufficient to develop recursively self-improving AI</em>, so that it really should be true that any society confronting this lesson has similar computational capacity. It then becomes conceivable to deduce what sophistication of individuals supports that capacity, considering that natural evolution runs slowly, so we&#8217;ll tend to get the simplest individuals that are up to the job. The simpler individuals couldn&#8217;t team up to solve alignment, and the significantly more sophisticated individuals don&#8217;t appear until the intelligence explosion is underway and the rules have changed.</p><p>This approach offers pretty elegant protection against the outcome of ignoring individuality at the level where we&#8217;re used to considering it. For instance, while corporations work effectively toward a variety of goals and can be said to exhibit higher-order thinking, many commentators would see it as dystopian to identify corporations as the primary agents! What saves us is that corporations are <a href="https://en.wikipedia.org/wiki/Leaky_abstraction">leaky abstractions</a>, e.g. a CEO typically needs to work very hard to repeat company strategy over and over again, in a pithy enough way, and yet still finds inconsistent execution across teams. Perhaps the individuals we <em>really</em> intended by that word turn out to be precisely the sufficiently well-integrated, internally aligned computers, so now we only need to figure out how to describe that concept.</p><p>I&#8217;ve also bumped into a related (and controversial) concept that I haven&#8217;t studied in-depth yet: <a href="https://en.wikipedia.org/wiki/Integrated_information_theory">integrated information theory (IIT)</a>, which characterizes mathematically how pieces come together into conscious wholes. I&#8217;ve <a href="/__u/stng.substack.com/p/what-is-consciousness">written elsewhere about consciousness</a> and why I&#8217;m not choosing to refer to that concept. In the present article, I&#8217;ve been dealing just with the power of different systems to compute good strategies for alignment, though perhaps some useful mathematics could turn out to be in common with IIT.</p><h1>Conclusion</h1><p>All of the above suggests the following alignment principle, which probably wouldn&#8217;t seem at all suitable on first inspection, but perhaps I&#8217;ve explained why it&#8217;s promising.</p><p><strong>Generalized alignment should identify individuals by their capacities for well-integrated, internally well-aligned computation past a certain scale, always choosing the maximal such units in a neighborhood.</strong></p><p>The maximality part is there so that we don&#8217;t do the equivalent of choosing cells, not people. Though the computational-capacity minimum should be chosen to exclude cells, we wouldn&#8217;t want an accident like identifying a person&#8217;s two brain hemispheres as separate agents.</p><p>Naturally, there would be plenty of work left to do in fleshing out all of those concepts into computer code or formal logic, in addition to doing the same for whatever decisions should follow the identification of agents. For instance, there may be good statistical characterizations of well-integrated intelligence that seem obviously compelling after-the-fact, but maybe not. The task seems easier than for somewhat open-ended formalization of human values, with <a href="/__u/stng.substack.com/p/ai-alignment-at-which-abstraction">ourselves as an evolutionarily contingent legacy system</a> that is hard to reverse-engineer as a black box. A powerful intelligence might reason from first principles about what intelligence at different computational scales should be expected to want, or, if you&#8217;ll allow me to sneak in a second Star Trek reference, it might follow a kind of <a href="https://en.wikipedia.org/wiki/Prime_Directive">Prime Directive</a> of noninterference (or other rules of engagement) with qualifying intelligence, as measured by how the AI&#8217;s actions perturb statistical patterns in the agents to focus on.</p><p>Some interesting misfires of this rule look possible. On the one hand, we worry about <em>false negatives</em> like not identifying children whose brains haven&#8217;t developed enough yet, which motivates ideas like setting the computational lower bound conservatively enough or perhaps adding an element of predictable development of an agent to pass the computation threshold. On the other hand, we may have a <em>false positive</em> of identifying a frontier supercomputer as an individual, though perhaps again forecasting where such intelligence is headed reveals a good destination. The next article will partly address that question, considering how there might be some amount of inherent convergence of intelligence toward certain laudable goals, regardless of the alignment starting point.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[AI Alignment at Which Abstraction Level?]]></title><description><![CDATA[A formal-methods perspective on a hard specification problem]]></description><link>https://stng.substack.com/p/ai-alignment-at-which-abstraction</link><guid isPermaLink="false">https://stng.substack.com/p/ai-alignment-at-which-abstraction</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 25 Aug 2026 12:34:31 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/a35044d8-589c-48e3-bea4-8982e7668896_1022x534.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;ve been arguing recently for a solution to the apparent chaos of current use of generative AI to write software: perhaps use these AI systems to help write truly unambiguous formal specifications, but then let those formal descriptions persist, auditing them carefully and using tools that reliably write code as we know it, given specifications. I made the case in <a href="/__u/stng.substack.com/p/rewrite-all-the-code-all-the-time">one original article</a> and then <a href="/__u/stng.substack.com/p/automatic-programming-should-be-more">a follow-up responding to comments on the first</a>. I ended the latter by promising to get into the highest-profile specification-writing challenge of our times: AI alignment. Here is the first of three articles giving my perspective.</p><p>First, I think a bit about my personal background is relevant. I have specialized in how to scale <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a> to apply to realistic systems without imposing unrealistic costs on engineers. Just to keep things interesting, I typically add another requirement: we want to minimize the <a href="https://en.wikipedia.org/wiki/Trusted_computing_base">trusted base</a> of any given verification. In other words, imagine someone builds an artifact and formally verifies it. The trusted base includes every line of code where a bug could have led to accepting an artifact that actually doesn&#8217;t align with the author&#8217;s intent. We can find that the trusted base includes code of the artifact, say for the hardware if we have only proved software; code of the formal-verification tool, in the common case where it hasn&#8217;t itself been formally verified; or code of further infrastructure underneath either, like an operating system we trust to run the verification software. I&#8217;ll have plenty to say in later articles about the best practices of my community in this regard and how they may be helpful to seemingly new problems around AI.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The important upshot for now, though, is that my perspective is one of an <em>engineer</em>. My projects almost always involve building nontrivial artifacts alongside their machine-checked proofs. These are serious proofs checked into <a href="https://en.wikipedia.org/wiki/Version_control">version control</a> and often developed by multiple collaborating engineers. Little conceptual mistakes can lead to the proofs being rejected. It&#8217;s an activity that doesn&#8217;t seem to map well to mainstream AI-alignment work. On the one hand, we have best-effort projects to align and evaluate current AI models, without any particular theoretical guarantees. On the other hand, we have writing more in the register of <em>philosophy</em> (some to be cited shortly) that tackles the big questions of <a href="https://en.wikipedia.org/wiki/Artificial_general_intelligence">artificial general intelligence</a> and how it may come about from <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">recursive self-improvement</a>. There are no rigorous proofs about complex implementations, because those implementations don&#8217;t exist yet <em>or</em> are diabolically unstructured in our present understanding and thus resistant to proof. As a result, it is easy to miss small conceptual problems that doom certain frameworks. I&#8217;m not saying I&#8217;ve pinpointed those problems! I just know from experience that the probability is near 100% that any complex system that hasn&#8217;t gone through rigorous formal verification <em>is actually incorrect</em>.</p><p>So let&#8217;s talk what makes for a good specification in the spirit of AI alignment, treated as part of a formal-methods project with familiar engineering considerations. By the way, I&#8217;m a newcomer to the world of alignment and will appreciate any dialogue about influential and related writing that I&#8217;ve missed. Our first stop in this article may seem like a bit of a swerve from the topic I just promised, but please bear with me. We will return to a formal-methods perspective on why we may not want to center humans in the top-level formulation of alignment, even if we play an important role internally.</p><h1>Abstraction Layers of Life as We Know It</h1><p>The field of AI alignment so far has generated some big and nonobvious ideas. What is called the <a href="https://www.lesswrong.com/w/value-identification-problem">value identification problem</a> is basically figuring out the right specification for AI, from the perspective of some thinking agent that we want to privilege morally. The principle of <a href="https://www.lesswrong.com/w/complexity-of-value">complexity of value</a> asserts that there is no short description of human values; there is fundamental complexity in what we have wound up wanting. This principle sounds like bad news for writing down human values as a formal specification! A well-known alternative proposal involves a kind of epistemic humility by advanced AIs, through the notion of <a href="https://www.lesswrong.com/w/coherent-extrapolated-volition-alignment-target">coherent extrapolated volition (CEV)</a>. The idea is that the AI&#8217;s starting specification is that it should figure out what humans would really want, if they were augmented in certain ways. Then that derived specification should become primary.</p><p>The place where I get stuck is <em>why we assumed centrality of humans in the value-identification problem</em>, and I&#8217;ll explain two kinds of objections, in this section and the next, one philosophical and one grounded in the pragmatics of formal verification. These objections stand independently of each other.</p><p>I think it&#8217;s widely recognized in the field that formulating this CEV objective is very challenging, which certainly sounds right from a formal-methods perspective. Still, I run into an objection to it, even presuming perfect formalization of what it means to learn human preferences. The problem is potential conduct of an AI during the period when it is learning our preferences. Assume it doesn&#8217;t yet have perfect models of our behavior, so it can only learn through real observation of humans. What&#8217;s to stop it from putting us all in vats, <em><a href="https://en.wikipedia.org/wiki/The_Matrix">Matrix</a></em>-style, constantly running us through different VR scenarios, to most efficiently figure out our preference structure? Or, substantially less outlandishly, what&#8217;s to stop it from taking over our social-media feeds to try to provoke different emotions, learning our preferences at the same time as triggering social problems as we already see from infinite-scroll social media today? It&#8217;s not like we can assume some bootstrap morality that flags those tactics as unsavory; finding the bootstrap morality isn&#8217;t obviously an easier or different problem. Even if the AI eventually creates genuine paradise compatible with our values, we might object to the intervening dark ages of manipulation. (ChatGPT directed me to <a href="https://proceedings.mlr.press/v267/emmons25a.html">a recent paper by Emmons et al.</a> studying a related problem more technically.) Now, it turns out that the rest of this section can proceed independently of this point, so I mostly include it in case readers have good references to share for prior art.</p><p>At some level, human centrality is obvious: humans are designing AI (for now), and humans want what we want. However, there is a familiar historical narrative of progress that depends on seeing ourselves as less and less central in the grand scheme of things. <a href="https://en.wikipedia.org/wiki/Nicolaus_Copernicus">Copernicus</a> argued that the Earth revolves around the Sun, not the other way around. <a href="https://en.wikipedia.org/wiki/Charles_Darwin">Darwin</a> argued that humans resulted from an evolutionary process that produced all of life as we know it, giving us no special place in the grand scheme of things. If we&#8217;re not a natural endpoint of a universal process, why should we give ourselves that status in the goals of powerful AI?</p><p><a href="https://en.wikipedia.org/wiki/Nick_Bostrom">Bostrom</a> in <em><a href="https://www.amazon.com/dp/B00LOOCGB2/?tag=adamchli-20">Superintelligence</a></em> considers other approaches to <em>indirect normativity</em>, which try to avoid centering human values, but to me these formulations seem to run into trouble for assuming the major problem of specifying human morality is already solved, even if one formulation (&#8220;moral rightness&#8221;) is couched in terms of universal, not human, morality. I personally am convinced by <a href="https://en.wikipedia.org/wiki/Anti-realism#Moral_anti-realism">moral anti-realism</a> and see the case for universal morality as weak, as morality arises from evolutionary forces and should be expected to be different in different times and places.</p><p>My argument here is related to <a href="https://en.wikipedia.org/wiki/Moral_circle_expansion">moral circle expansion</a>, a philosophical concept that explains our potential granting of more moral standing to nonhuman animals and AIs alike. For instance, imagining our ancestors formulating alignment as recently as 150 years ago, it may have been &#8220;clear&#8221; that only a writer&#8217;s own race deserved consideration, a principle that we now find repugnant. We could perhaps say that I&#8217;m taking that principle to a more abstract level, where we see, say, humans and cows as representatives of roughly the same <em>abstraction level</em> of the universe, raising the question of what makes that <em>level</em> special.</p><p>Let&#8217;s consider the same question from more of an engineering perspective. Life can naturally be organized in layers, and we can imagine formulating alignment from the perspective of each layer, which can lead to very different outcomes via powerful AI systems, each outcome looking undesirable from other layers&#8217; vantage points. What makes the layer of individual humans special &#8211; special <em>enough</em> to get this treatment in alignment?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!0SgN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc87974e6-9a9a-4c97-9e43-f45fd179caf7_1050x1498.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!0SgN!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc87974e6-9a9a-4c97-9e43-f45fd179caf7_1050x1498.png 424w, /__u/substackcdn.com/image/fetch/$s_!0SgN!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc87974e6-9a9a-4c97-9e43-f45fd179caf7_1050x1498.png 848w, /__u/substackcdn.com/image/fetch/$s_!0SgN!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc87974e6-9a9a-4c97-9e43-f45fd179caf7_1050x1498.png 1272w, /__u/substackcdn.com/image/fetch/$s_!0SgN!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc87974e6-9a9a-4c97-9e43-f45fd179caf7_1050x1498.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!0SgN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc87974e6-9a9a-4c97-9e43-f45fd179caf7_1050x1498.png" width="1050" height="1498" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c87974e6-9a9a-4c97-9e43-f45fd179caf7_1050x1498.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1498,&quot;width&quot;:1050,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2903890,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/212332253?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc87974e6-9a9a-4c97-9e43-f45fd179caf7_1050x1498.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!0SgN!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc87974e6-9a9a-4c97-9e43-f45fd179caf7_1050x1498.png 424w, /__u/substackcdn.com/image/fetch/$s_!0SgN!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc87974e6-9a9a-4c97-9e43-f45fd179caf7_1050x1498.png 848w, /__u/substackcdn.com/image/fetch/$s_!0SgN!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc87974e6-9a9a-4c97-9e43-f45fd179caf7_1050x1498.png 1272w, /__u/substackcdn.com/image/fetch/$s_!0SgN!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc87974e6-9a9a-4c97-9e43-f45fd179caf7_1050x1498.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I will have more to say on the biological version of this picture next time. I&#8217;m not, by the way, implying that atoms have human-style preferences. The point is more that it&#8217;s hard to formalize &#8220;preference&#8221; in some way that isn&#8217;t sneaking in a special role for humans. One common answer is that the organism layer is distinguished in supporting <em>consciousness</em>, but I&#8217;ve already <a href="/__u/stng.substack.com/p/what-is-consciousness">argued against the big-picture utility of that word</a> and won&#8217;t relitigate here.</p><p>One related alignment idea is <a href="https://www.alignmentforum.org/w/natural-abstraction">natural abstraction</a>: the idea that well-engineered thinking systems will develop the same abstractions for making sense of the vast physical world, because those abstractions <em>just work</em>, and thus we can assume that AI will evolve toward abstractions familiar to us, and we can specify alignment in terms of those abstractions without worry of (gross) misinterpretation. This perspective doesn&#8217;t tell us which of many abstractions to extract values from, though, including in situations as in the diagram with agents nested inside each other. That nesting also figures in the idea of <a href="https://www.alignmentforum.org/w/embedded-agency">embedded agency</a>, which considers how agents should plan changes to complex worlds that include themselves. One subproblem is how agents should plan the creation of nested agents that do helpful supporting work. This perspective doesn&#8217;t seem to answer who deserves to be allowed to specify values: in the case of evolution optimizing humans who optimize Python programs, neither extreme orientation (toward highest-level or lowest-level optimizers) gives us the expected answer.</p><p>Engineers are used to thinking of systems at different levels of abstraction, and it&#8217;s jarring to call out one level as getting special treatment. <a href="https://en.wikipedia.org/wiki/Ray_Kurzweil">Kurzweil</a> in <em><a href="https://www.amazon.com/dp/B000QCSA7C?tag=adamchli-20">The Singularity is Near</a></em> grounds the history of the universe in development of increasingly complex patterns, with nesting structure like I just sketched, but overloads the term &#8220;humanity&#8221; to cover whatever artificial intelligence we design, too. On one level, it solves the puzzle to decide that &#8220;human&#8221; is a synonym for the whole history of the universe, or at least the upcoming part for our own neighborhood in space! That move seems to me like hiding from the problem, though, if we think in terms of some greater cosmic destiny centered on forms of intelligence beyond our comprehension &#8211; and which, by the way, would be very helpful to us if they liked us.</p><h1>Controlling Specification Complexity</h1><p>Let&#8217;s snap back to the formal-methods engineer&#8217;s perspective. Whether we are formalizing human values directly or expressing what it means for a system to seek them out and then honor them, it sounds like one heck of a complex specification, and <em>formal-methods people know that complex specifications create the biggest risk for assurance</em>. Humans become an example of a <em>complex <a href="https://en.wikipedia.org/wiki/Legacy_system">legacy system</a></em>, absolutely <em>the worst</em> kind to tackle for correctness-critical specifications. We evolved without selection pressure for our values to be understandable to computer code, so there&#8217;s no reason to think this problem is especially tractable. Maybe this problem is nonetheless <em>the</em> important one, and we just have to find a way to solve it, but let me continue explaining why it&#8217;s worrying (and then the next article will get into considering how the problem might actually be avoidable).</p><p>The trouble is that complexity in a <em>specification</em> tends to force complexity in an <em>implementation</em>, as code is added to deal with all the challenges that have been spelled out. Then, in turn, complexity of these two promotes complexity of a <em>mathematical proof</em> of correctness, which naturally references all parts of the specification and implementation. We may find that the specification includes <code>N</code> distinct concerns, and interaction among every <em>pair</em> of them (the <a href="https://en.wikipedia.org/wiki/Feature_interaction_problem">feature interaction problem</a>) needs to be treated explicitly in the proof, for <code>N^2</code> required cases. This phenomenon should make us very wary to put a <em>complex legacy system</em> in the specification.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!QFeJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0921b3d2-24d2-44c6-a516-2f4a4c1c20a1_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!QFeJ!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0921b3d2-24d2-44c6-a516-2f4a4c1c20a1_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!QFeJ!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0921b3d2-24d2-44c6-a516-2f4a4c1c20a1_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!QFeJ!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0921b3d2-24d2-44c6-a516-2f4a4c1c20a1_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!QFeJ!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0921b3d2-24d2-44c6-a516-2f4a4c1c20a1_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!QFeJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0921b3d2-24d2-44c6-a516-2f4a4c1c20a1_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0921b3d2-24d2-44c6-a516-2f4a4c1c20a1_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1469246,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/212332253?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0921b3d2-24d2-44c6-a516-2f4a4c1c20a1_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!QFeJ!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0921b3d2-24d2-44c6-a516-2f4a4c1c20a1_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!QFeJ!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0921b3d2-24d2-44c6-a516-2f4a4c1c20a1_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!QFeJ!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0921b3d2-24d2-44c6-a516-2f4a4c1c20a1_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!QFeJ!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0921b3d2-24d2-44c6-a516-2f4a4c1c20a1_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>At this point, I&#8217;m imagining objections that sometimes we only know how to build systems including some complex parts. The usual saving grace for formal methods is the one I explained around <a href="/__u/stng.substack.com/p/simplifying-alignment-by-expanding">surprising payoffs of end-to-end formal verification</a>. Namely, sometimes it is easier to be sure we got a specification problem right by doing proof about a <em>larger</em> artifact that includes the original as one component. Why? <em>The new top-level system may admit a simpler specification</em>, and the original system&#8217;s specification becomes just part of internal implementation and proof details. If the inner system has a specification bug, either we catch it in the course of verifying the larger system <em>or</em> the bug turned out to be inconsequential for our larger goal.</p><p>Maybe the hard-to-decipher &#8220;humans&#8221; of the programming world are complex, popular programming languages like <a href="https://en.wikipedia.org/wiki/C_(programming_language)">C</a>. Assume for the moment (though I have <a href="/__u/stng.substack.com/p/the-expensive-fictions-of-low-level">argued to the contrary</a> and will come back to doing so in later articles!) that building realistic computer systems requires using these programming languages. Are we out-of-luck, now needing to include <a href="https://en.wikipedia.org/wiki/Semantics_(programming_languages)">formal semantics</a> of the languages in our top-level system specifications? Not if we make the right architectural choices! If we also formally verify the implementations of the programming languages, then choice of language becomes an internal implementation detail, with no representation in the top-level specification that we should submit to careful auditing, testing, and so on. I <a href="/__u/stng.substack.com/p/simplifying-alignment-by-expanding">presented one of my own projects</a> that achieves as much, also crossing the hardware-software interface off the list of top-level specification complexities, by verifying the hardware, too.</p><p>Another great example from programming is <a href="https://en.wikipedia.org/wiki/Memory_safety">memory safety</a>. Here we are dealing with what is, in practice, a somewhat-nebulous property, governing how different pieces of code can share computer memory harmoniously, with clear rules for who is allowed to access what. Everyone knows C is <em>not</em> memory-safe, while <a href="https://en.wikipedia.org/wiki/Rust_(programming_language)">Rust</a> <em>is</em> memory-safe &#8211; but what does that statement really mean? We could try to put together a grand unifying theory of memory safety, but I argue that the real importance of memory safety is that <em>it allows <a href="https://en.wikipedia.org/wiki/Modular_programming">modular</a> reasoning</em>. That is, in the presence of memory safety, it is tractable to divide a program up into modules and give each one a separate specification and proof, without unreasonable interaction across the specifications, because we know modules won&#8217;t generally trash each others&#8217; memory. Therefore, <em>the mere ability to prove interesting behavioral theorems modularly</em> demonstrates a desirable quality that <em>subsumes</em> what we really wanted from memory safety &#8211; and we avoided needing to define &#8220;memory safety&#8221; formally. (Incidentally, others have <a href="https://arxiv.org/abs/1705.07354">formalized a related intuition</a>.) This observation is related to the one I wrote about where <a href="/__u/stng.substack.com/p/subversion-resistance-for-free-from">resistance to security vulnerabilities follows almost for free</a>.</p><p>So, even if humans are central to the story for what constitutes AI alignment, <strong>it need not mean that the &#8220;top-level specification&#8221; of AI says anything about humans</strong>! Future AI systems could construct sophisticated models of humans, and the utility of those models to meet some ultimate goal could be proved from first principles, without putting those models in the trusted base. While we humans differ from programming languages in having evolved rather than been designed, the gap could perhaps be made up by formally verified AI scientists studying humans or whatever other relevant phenomenon, a topic I hope to return to in later articles.</p><h1>Conclusion</h1><p>Maybe we just won&#8217;t be smart enough to construct an initial specification of alignment that avoids bringing in complex modeling of humans, but I hope I&#8217;ve made some kind of case that it&#8217;s worth trying. I also want to reiterate that I&#8217;m using this article partly to get feedback about existing writing I should check out for its connections to (and potential poking of holes in) what I&#8217;ve written here. My next article will give one example of an approach to alignment that genuinely avoids including anything about humans in its top-level specification, while plausibly meeting our informal requirements for alignment. The last article in the trio will consider the infamous example of the <a href="https://en.wikipedia.org/wiki/Instrumental_convergence#Paperclip_maximizer">paperclip maximizer</a> and some potential mitigations against allowing one to develop.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Automatic Programming Should Be More Like SQL]]></title><description><![CDATA[How to raise the abstraction level, reliably]]></description><link>https://stng.substack.com/p/automatic-programming-should-be-more</link><guid isPermaLink="false">https://stng.substack.com/p/automatic-programming-should-be-more</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 18 Aug 2026 12:25:54 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/c8c14e9c-8203-4264-b88c-a2c8c485bab9_706x321.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I wrote recently about <a href="/__u/stng.substack.com/p/rewrite-all-the-code-all-the-time">the imminence of regular regeneration of large code bases</a>, where software code as we know it should become a throwaway artifact, regularly recreated from evolved requirements by powerful automation. After <a href="/__u/stng.substack.com/p/productive-signaling-competitive">a quasi-digression on one mechanism to kick off widespread generation of better versions of important programs</a>, I want to return to addressing comments on the earlier article (on <a href="https://www.linkedin.com/feed/update/urn:li:activity:7490389854086885376/">LinkedIn</a>, <a href="https://news.hada.io/topic?id=32322">GeekNews</a>, <a href="https://www.lesswrong.com/posts/9c9KPkJJbMz7tmv3K/rewrite-all-the-code-all-the-time">LessWrong</a>, and <a href="https://www.astralcodexten.com/p/open-thread-446/comment/312031455">ACX</a>). I&#8217;m writing this blog precisely to get that kind of feedback, to spot holes I unintentionally left in explanations, so I can correct them for the book I plan to write based on this material. So, many thanks to the commenters who spotted those holes and spoke up! I&#8217;m going to use the example of database query language <a href="https://en.wikipedia.org/wiki/SQL">SQL</a> to explain more directly the approach I&#8217;m arguing for.</p><h1>Just Another Increase in Programming Abstraction (Kind Of?)</h1><p>Some of the points I made are unusual enough that they deserve repeating, since much of the feedback assumed I was suggesting a flow closer to conventional approaches than I intended. Let me give a highest-level recap that sets up that discussion productively. I made two claims, one that is absolutely orthodox in Silicon Valley today and one that represents an edgy departure. The orthodox claim is that powerful automation of software development allows us to think of <em>software code as no longer expensive to produce, to the point where we can routinely throw away all of our code and regenerate it</em>, following improved requirements for what it should do and how it should work. Almost all of the excitement around that direction leans heavily on LLMs and assumes that we generate software from natural language (which includes formats like <a href="https://en.wikipedia.org/wiki/Easy_Approach_to_Requirements_Syntax">EARS</a> that add modest structure on top of natural language but still require natural-language processing to interpret). My edgy claim is that we need to ditch natural language entirely, for periodic regeneration of large code bases to be practical. <em>Unambiguous specification languages</em> are going to be a crucial ingredient well-known from <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a> but not deployed nearly as widely as LLM-based tools (despite decades of head start for formal methods!). (There is some subtlety to that last point where we want to retain some benefits of LLMs to help understand informal requirements, which I&#8217;ll return to later in this article.)</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Some of the comments argued that a good unambiguous specification language becomes &#8220;just another programming language,&#8221; making the argument here overblown. Indeed, I used exactly that historical framing in the original article! I used the example of how the software-development process used to include drawing <a href="https://en.wikipedia.org/wiki/Flowchart">flowcharts</a>, relatively informal diagrams that were not processed by computers. Then human programmers (separate from the <em>analysts</em> who drew the flowcharts) translated them into <a href="https://en.wikipedia.org/wiki/Assembly_language">assembly language</a>. Eventually, however, automatic <a href="https://en.wikipedia.org/wiki/Compiler">compilers</a> were developed, to translate from new high-level programming languages like <a href="https://en.wikipedia.org/wiki/Fortran">FORTRAN</a>. A program &#8220;planning&#8221; format was much more pleasant when further implementation could be automated.</p><p>I wrote that a move to writing &#8220;specifications&#8221; instead was a natural progression in that direction. We had just been stuck waiting for the right technology to automate implementation from there! Still, what exactly makes a specification different from a program? They sit on a spectrum, and sometimes it makes sense to use the same languages to write both.</p><p>However, I&#8217;ll argue that &#8220;specification&#8221; usually implies two important characteristics that are unusual in &#8220;programming.&#8221;</p><ul><li><p><strong>A specification is written to explain </strong><em><strong>what</strong></em><strong> functionality is desired, not </strong><em><strong>how</strong></em><strong> to accomplish it.</strong> The most concrete and familiar example is performance, like how quickly a program runs. Much of the complexity of code in practice comes from cleverness in data structures and algorithms to improve performance. I would argue that a great specification should spell out requirements on performance (and indeed a variety of projects have shown how to prove performance requirements of real code, as in <a href="https://adam.chlipala.net/papers/MetricsCPP26/">one of my own recent papers</a>) but not get into detail on how to meet the requirements. In many cases, specifications can be much simpler and easier to audit precisely because they don&#8217;t precommit to optimization details.</p></li><li><p><strong>A specification often includes </strong><em><strong>nondeterminism</strong></em><strong> to provide flexibility to implementers.</strong> We can again find some of the clearest examples in connection to performance. Think of some process that generates a set of answers, and the user is happy to receive them in any order. Depending on how the underlying data were stored, some order may be the most natural, as in reading off the cells of a data structure in the same order as they appear internally. It would be bad for a specification to mandate a particular order, because then it becomes harder to take advantage of a clever new data structure that changes internal order.</p></li></ul><p>A great example to illustrate both points is <a href="https://en.wikipedia.org/wiki/SQL">SQL</a>, the popular database query language. It is possible to write an SQL query that is close to the most compact, straightforward way to describe what constitutes a correct answer. (Cue here complaining by programmers about the concrete syntax of SQL, yeah, yeah!) SQL also gives database engines freedom to return answers in convenient orders, when order isn&#8217;t explicitly mandated in a query. Unfortunately, SQL queries <em>do not</em> typically include explicit performance requirements, which could help database engines make tradeoffs intelligently, but I hope future systems get there.</p><p>Now, SQL is also a great example of how &#8220;specifications&#8221; and &#8220;programs&#8221; live on a spectrum. SQL power users often spend inordinate amounts of time tweaking queries to improve performance. One canonical example is declaring a new <a href="https://en.wikipedia.org/wiki/Database_index">index</a> to the database engine, a suggestion of a data structure that may be useful to speed up queries. The hardcore version involves deep inspection of <a href="https://en.wikipedia.org/wiki/Query_plan">query plans</a> to find bottlenecks in the code that the database came up with. Nonetheless, &#8220;pristine,&#8221; high-level queries remain highly effective as specifications: easy to read, leaving much flexibility to explore different implementation strategies. It would not be entirely misleading to restate the central point of my last article as <em>more of programming should become more like SQL</em> (including the possibility to start with relatively abstract code, often get satisfactory implementations from it with full automation, and sometimes invest in more-manual improvement that involves adding details to the specification within the same language).</p><p>Note how the last little example is a template for how to handle improvement of specifications in other dimensions beyond performance. Through either predeployment testing (of the specification or generated implementation) or observing faults in the field, we can notice and fix specification problems. Examples of other dimensions particularly easy to misspecify are security, privacy, ease of maintenance (<a href="https://en.wikipedia.org/wiki/DevOps">DevOps</a>-style), and human usability. Just as with conventional software development, we should expect to keep improving code concerning these aspects &#8211; just trying to keep it succinct and put it in specification instead of implementation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!ucd_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ce2ed17-a047-4b8c-96a7-560d1ca112d3_1488x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!ucd_!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ce2ed17-a047-4b8c-96a7-560d1ca112d3_1488x834.png 424w, /__u/substackcdn.com/image/fetch/$s_!ucd_!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ce2ed17-a047-4b8c-96a7-560d1ca112d3_1488x834.png 848w, /__u/substackcdn.com/image/fetch/$s_!ucd_!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ce2ed17-a047-4b8c-96a7-560d1ca112d3_1488x834.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ucd_!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ce2ed17-a047-4b8c-96a7-560d1ca112d3_1488x834.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!ucd_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ce2ed17-a047-4b8c-96a7-560d1ca112d3_1488x834.png" width="1456" height="816" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6ce2ed17-a047-4b8c-96a7-560d1ca112d3_1488x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:816,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:778357,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/211585712?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ce2ed17-a047-4b8c-96a7-560d1ca112d3_1488x834.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!ucd_!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ce2ed17-a047-4b8c-96a7-560d1ca112d3_1488x834.png 424w, /__u/substackcdn.com/image/fetch/$s_!ucd_!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ce2ed17-a047-4b8c-96a7-560d1ca112d3_1488x834.png 848w, /__u/substackcdn.com/image/fetch/$s_!ucd_!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ce2ed17-a047-4b8c-96a7-560d1ca112d3_1488x834.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ucd_!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ce2ed17-a047-4b8c-96a7-560d1ca112d3_1488x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It turns out this style of thinking has a long history in basic research. To start with, we have the relatively informal (or at least typically disconnected from rigorous proof in practice) discipline of <a href="https://en.wikipedia.org/wiki/Requirements_engineering">requirements engineering</a>. More relevantly, the idea of <a href="https://en.wikipedia.org/wiki/Refinement_(computing)">refinement</a> of specifications into implementations has been studied since at least the 1970s (see <a href="https://dl.acm.org/doi/10.1145/362575.362577">a paper</a> by <a href="https://en.wikipedia.org/wiki/Niklaus_Wirth">Niklaus Wirth</a>, inventor of the <a href="https://en.wikipedia.org/wiki/Pascal_(programming_language)">Pascal</a> language). I&#8217;ve been working in that tradition myself, including in the <a href="https://adam.chlipala.net/papers/FiatSNAPL17/">Fiat</a> project, where we even used SQL-style notation as a central example for automated refinement with proof.</p><p>Relatively declarative configuration languages, say for <a href="https://en.wikipedia.org/wiki/Cloud_computing">cloud platforms</a>, are another example that came up in discussion. Amazon&#8217;s <a href="https://aws.amazon.com/blogs/security/protect-sensitive-data-in-the-cloud-with-automated-reasoning-zelkova/">Zelkova</a> was an early success for formal methods in this area. I think of such tooling as important, but it also seems to solve a fundamentally simpler problem than general software development, and it&#8217;s the latter I want to focus on.</p><h1>The Software Lifecycle with Strong Automation</h1><p>I hope this framing already suggests some of the details of a future workflow based on unambiguous specifications, because it will look a lot like programming with SQL looks today. Database engines produce query plans automatically from SQL queries. As a result, we save the SQL queries in <a href="https://en.wikipedia.org/wiki/Version_control">version control</a> systems like <a href="https://en.wikipedia.org/wiki/Git">Git</a>, the canonical way of recording code over time, but we <em>don&#8217;t</em> put the query plans in version control. If we need to give the query planner instructions, say by requesting indexes, those instructions <em>do</em> go in version control. The point is that what persists, what is <em>not</em> a throwaway byproduct of automation, is <em>exactly the information that makes remaining code generation sufficiently predictable</em>, allowing it to meet our requirements reliably.</p><p>One important point I&#8217;d like to make here is that <em>remaining stages of code generation don&#8217;t need to be deterministic</em>. If requirements were spelled out precisely enough, we can be happy to receive any final, running system that meets the requirements. It&#8217;s OK if we get a different one each time! Programmers are used to mandating more determinism than strictly required by their development and maintenance processes, because they aren&#8217;t used to writing sufficiently constraining specifications/programs. The earlier SQL example is a good one: because we don&#8217;t trust the database engine to choose the right data structures and algorithms, we worry about changes to the subsystem that plans query execution, but <em>what if we annotated our queries and indeed our whole programs with performance requirements instead</em>? Then nondeterminism becomes <em>desirable</em> because sometimes the programming tools find <em>new and better, faster</em> implementations and drop them in without needing to bother us!</p><p>The underlying issue is that programmers worry (justifiably) that some important characteristics of the final system can&#8217;t be predicted from the source code alone. Yet, because those characteristics are important, we need to make sure we confirm they are suitable. The most common tool is <a href="https://en.wikipedia.org/wiki/Software_testing">testing</a>, subjecting the generated code to many scenarios and checking it behaved properly. Over time, developers build confidence in even the parts of generated systems that those developers didn&#8217;t write themselves, by running many tests over many versions of the program. If a clever programming tool completely changes up those aspects, we have to restart the confidence-building exercise.</p><p>I want to emphasize the two big changes to this flow that I&#8217;m recommending. The first is to <em>write specifications so precise that literally any realization of them is acceptable</em>. The thought experiment is for, say, a company building a product to imagine that its biggest competitor gets to write any program that meets the specification. The second important change is to <em>rely on machine-checked <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">mathematical proof</a> that a generated program meets its specification</em>. Now we need not rely on testing to find internal bugs in the generated code, as testing covers only particular execution scenarios, while a proof covers all of them. The risks that remain are in the specification, perhaps most importantly in how we characterize the other systems that ours interacts with &#8211; so testing should be focused on that interface boundary, and it can be done against a specification that happens to be executable, not the generated implementation. We no longer need to treat e.g. a tricky concurrent data structure that is purely internal as highly suspicious from a bugs standpoint. This shift is similar to the one that happened with programmers trusting the implementations of higher-level programming languages (though there&#8217;s no need for trust, as <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">compilers are a great subject for formal verification</a>).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!-1K-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9543af15-e3fd-485f-ac71-9147e7e5fc78_1680x804.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!-1K-!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9543af15-e3fd-485f-ac71-9147e7e5fc78_1680x804.png 424w, /__u/substackcdn.com/image/fetch/$s_!-1K-!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9543af15-e3fd-485f-ac71-9147e7e5fc78_1680x804.png 848w, /__u/substackcdn.com/image/fetch/$s_!-1K-!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9543af15-e3fd-485f-ac71-9147e7e5fc78_1680x804.png 1272w, /__u/substackcdn.com/image/fetch/$s_!-1K-!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9543af15-e3fd-485f-ac71-9147e7e5fc78_1680x804.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!-1K-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9543af15-e3fd-485f-ac71-9147e7e5fc78_1680x804.png" width="1456" height="697" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9543af15-e3fd-485f-ac71-9147e7e5fc78_1680x804.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:697,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:881652,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/211585712?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9543af15-e3fd-485f-ac71-9147e7e5fc78_1680x804.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!-1K-!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9543af15-e3fd-485f-ac71-9147e7e5fc78_1680x804.png 424w, /__u/substackcdn.com/image/fetch/$s_!-1K-!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9543af15-e3fd-485f-ac71-9147e7e5fc78_1680x804.png 848w, /__u/substackcdn.com/image/fetch/$s_!-1K-!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9543af15-e3fd-485f-ac71-9147e7e5fc78_1680x804.png 1272w, /__u/substackcdn.com/image/fetch/$s_!-1K-!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9543af15-e3fd-485f-ac71-9147e7e5fc78_1680x804.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Another concern came up for having tools choose data structures automatically. How does a program evolve over time if the data format keeps changing, leaving prior databases obsolete? This problem is actually addressed pretty naturally: part of the specification for the next version of a program is that it is able to begin with the old contents of a database, where now the specific format of that database is part of the specification of the new version. The code-generation tool may now either keep the database format the same or generate a <a href="https://en.wikipedia.org/wiki/Schema_migration">migration</a> to upgrade to a new representation. (Note that this concern helps us notice a wrinkle of needing to save generated data schemas in version control or similar, even if they were produced automatically.)</p><h1>Feasibility of Specification and Verification</h1><p>Some concerns were expressed about scalability of such methods to very large code bases. It&#8217;s important to keep in mind which measurements of size we should worry about. It would be strange for a conventional project to measure code size by the amount of <a href="https://en.wikipedia.org/wiki/Machine_code">machine code</a> generated by compilers. Instead we measure source code, which is checked into version control. Similarly, raising the level of abstraction, we should be worried about the size and maintenance complexity of specifications. Different programs may have vastly different size gaps between specifications and machine-executable code. We&#8217;ll have to see how the specifics turn out, but one orienting principle I&#8217;m comfortable asserting now is that such a gap often corresponds to the sophistication of performance optimizations in a program (which shouldn&#8217;t also be in the specification), so the gap is likely to be widest in domains with lots of attention to performance.</p><p>Some readers were skeptical that the LLM-style experience of getting a pile of complex code written on command can <em>ever</em> dovetail with high confidence in correctness &#8211; and I actually agree! I&#8217;ve argued that <a href="/__u/stng.substack.com/p/deep-learning-the-ultimate-search">deep learning is better understood as a generalization of search engines</a> than as a &#8220;reasoning engine&#8221; in the colloquial sense. Coding agents are doing something very similar to copying and pasting from existing code bases into a new one, losing the lineage of vetted good ideas. Instead, I&#8217;ve already argued for <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">combining reuse of flexible components with AI code generation</a>, where that generation now just needs to reference components by name. The novelty density of all software worldwide is much lower than the novelty density encountered examining all the parts of a single system, and we should be taking advantage of that low novelty to share carefully vetted code across projects. It should dramatically decrease the program-specific reasoning and proof that needs to be carried out. The effort to build, specify, and verify the components scales well with their potential many uses.</p><p>Another dimension of skepticism was the effectiveness of formal-verification tools in checking whatever code has been produced. There is a definite tradeoff between accepting a buggy program or failing to validate a correct program (see our past discussion on <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">undecidable program analysis</a>). In cases where the stakes are low enough, it may make sense to adopt a flow that occasionally lets a bad program through, if it enables more development velocity and creativity by coding agents. However, I personally most favor methods that don&#8217;t separate code generation from verification. <em>Correct-by-construction</em> techniques interleave correctness reasoning with all steps of writing code, and I&#8217;ll have much more to say about this approach in upcoming articles.</p><p>Coming up with a sufficiently constraining specification can be hard and error-prone work. Familiar quality-assurance activities for software may switch to specifications instead, including running specifications against many test cases. Tools for simulation, debugging, code review, and so on can also be very helpful for specifications &#8211; and all the above practices are actually already common among users of formal-methods tools like <a href="https://en.wikipedia.org/wiki/Proof_assistant">proof assistants</a>. However, I would say most engineers not familiar with formal methods are much too pessimistic about the paths toward high-quality specifications. The reason is that most specifications apply to components that ought to be internal to larger systems, and <a href="/__u/stng.substack.com/p/simplifying-alignment-by-expanding">end-to-end verification of full systems catches specification mistakes in internal components very reliably</a>. For instance, a programming-language implementation is tough to specify in isolation, as we need to legislate exactly what each language feature means, but when that language is used internally in the proof of a larger system, we force ourselves to catch any language-design mistakes that are <em>consequential</em>, falsifying what we hope is a simpler top-level specification of an application, and the language definition becomes <em>untrusted</em> (in the good sense of not being assumed correct). There&#8217;s also <a href="/__u/stng.substack.com/p/subversion-resistance-for-free-from">a handy bonus for catching certain security bugs by proving almost any interesting specification about a system</a>.</p><p>We can also keep benefiting from LLMs and similar future tools. Coding assistants can be used to write specifications that are then code-reviewed, tested, and so on, at the level of unambiguous specifications. There is an established research area around <a href="https://en.wikipedia.org/wiki/Programming_by_example">programming by example</a>, and such techniques could be used to help write specifications automatically from input-output examples or even, with AI assistance, &#8220;user stories&#8221; that spell out in English ways that programs should be able to be used. The point is that AI can make mistakes, but the final quality assurance is done against an unambiguous specification (which persists in version control, while natural-language dialogues may not).</p><p>Aspects of the pushback about nondeterminism of code generators do indeed sound like trouble to me. I wrote previously about how <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">nondeterministic specifications can promote security vulnerabilities through so-called side channels</a>. It also isn&#8217;t hard to see how getting the same answer every time can be helpful, for instance in reproducing data analysis from scientific experiments. In such cases, we can make sure that top-level specifications are deterministic, though it may remain useful to allow systems to be built out of components with specification nondeterminism that is hidden well at the system level. A great example is a low-level <a href="https://en.wikipedia.org/wiki/Memory_management">memory allocator</a> that assigns memory addresses to different pieces of data, where higher-level code is written carefully not to reveal which addresses were assigned. It pays off to allow new versions of the allocator to introduce clever new algorithms that affect address choices.</p><p>There was also a question about whether specifications are just <a href="https://en.wikipedia.org/wiki/Pseudocode">pseudocode</a>, and I think they probably aren&#8217;t. That terminology usually implies some use of natural language to explain important behavior, which isn&#8217;t compatible with truly reliable automatic programming.</p><h1>Remaining Questions</h1><p>One interesting question I received was about the place of <a href="https://en.wikipedia.org/wiki/Undocumented_feature">undocumented features</a> in software that is regularly regenerated. That is, conventional software ships with incidental features that the developers may never have meant to promise to retain indefinitely, and yet users come to depend on them (as laid out in <a href="https://en.wikipedia.org/wiki/API#Hyrums">Hyrum&#8217;s law</a>). If regeneration can change such incidental features arbitrarily, users may repeatedly be disappointed. For now, I think my strongest response is that undocumented features are bad, and automation may be able to help us avoid them! However, it&#8217;s worth thinking about the consequences of users increasingly becoming AI agents themselves. One of <a href="/__u/stng.substack.com/p/simpler-user-interfaces-in-an-ai">my earlier articles</a> analyzed how the problem of ensuring happy users becomes easier then, for instance because new releases can be checked against the code of known users, to make sure they remain satisfied in all possible scenarios. Achieving a similar benefit for human users remains an interesting software-engineering research question.</p><p>Complicated systems must often be debugged in the field, as much as we may hope broad formal verification catches all defects. Some bad behaviors only emerge at scale in real environments, which may include components not yet specified or verified. Generated code can still be provided with, for instance, mappings of running code to the parts of specifications that determined it, along with whatever other annotations best support debugging by humans or machines. Indeed, the quality of debugging collateral could be mentioned explicitly in a specification! However, the details definitely constitute an independent research challenge.</p><p>Another interesting comment was about how the world and the connections between its pieces seem on an unstoppable upward trajectory of complexity. Methods based on code generation from unambiguous specifications may hit an applicability wall, past some world-complexity threshold. It&#8217;s interesting to speculate about how increased adoption of AI may change this phenomenon. On the one hand, &#8220;smarter&#8221; AIs may go even further in designing complex, society-scale systems. On the other hand, the selection pressure to enable efficient reasoning by AIs may motivate them and us to create <a href="/__u/stng.substack.com/p/abstraction-boundaries-and-bubbles">bubbles of improved legibility</a> within which <a href="/__u/stng.substack.com/p/codesign-for-legibility-to-ai-and">economic systems and reasoning systems are codesigned</a>. The world may seem to grow increasingly complex and illegible to humans while AIs are actually improving their ability to keep up!</p><p>We all see how amazingly effective LLM-based coding assistants have become, even if it can be hard to build confidence that they wrote the programs we really want. There is an even older tradition of research in <a href="https://en.wikipedia.org/wiki/Program_synthesis">program synthesis</a>. I think there&#8217;s a lot of exciting technical work to do to draw on these starting points and create the most effective systems for automatic programming. However, it was an intentional omission not to go into more detail in the prior article, as I&#8217;m going to need multiple articles worth of content to do that subject justice; stay tuned. For now, just imagine that some reasonable notion of mathematical program proof is fixed, with ideally one standardized trustworthy checker, opening the door to a variety of methods that produce proofs (in the style of <a href="/__u/stng.substack.com/p/proof-carrying-code-in-the-matrix">proof-carrying code</a>).</p><p>I do want to tease now that I see performance of logic-based automated-reasoning tools as a major bottleneck holding back the area. At a minimum, we need these tools to keep up with deep learning-based tools that may be writing code creatively. A major theme of future articles will be full-stack performance engineering to improve logical reasoning and code generation. In fact, I hold out hope that logic-based alternatives will be able to run even faster than purely LLM-based methods, even if LLMs are baked into custom hardware, because of <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">the inherent performance bottlenecks of deep learning</a>.</p><p>Next, though, I want to turn to perhaps the hardest case of complete-enough specification being discussed today: <a href="https://en.wikipedia.org/wiki/AI_alignment">AI alignment</a>, the study of how to build flexible automated decision-makers that we should believe will respect our values and not harm us in surprising ways. My impression is that the conversation so far leans very much on thought experiments not connected to implementations, somewhat justifiably if we may (?) not yet have AI powerful enough to exercise the alignment challenge very thoroughly. I&#8217;m going to analyze the problem from more of an engineering perspective, grounded in experience building and maintaining significant proofs of system correctness. The gimmick will be thinking of human brains as a legacy system that is worth engineering around if we can, especially if it must be mentioned in the top-level interface of a system.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Productive Signaling: Competitive Software Development, Not Competitive Programming]]></title><description><![CDATA[Programming competitions can have more helpful side effects.]]></description><link>https://stng.substack.com/p/productive-signaling-competitive</link><guid isPermaLink="false">https://stng.substack.com/p/productive-signaling-competitive</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 11 Aug 2026 12:08:12 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/d7cac0cb-06b1-43b8-8105-0d81d32213ce_494x310.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><a href="/__u/stng.substack.com/p/rewrite-all-the-code-all-the-time">My last article</a> argued that we have an opportunity to enter a rapid cycle of reimplementation of important software, as AI and automation tools broadly lower the cost of development from sufficiently clear high-level specifications. One reason to &#8220;rewrite everything&#8221; is <a href="/__u/stng.substack.com/p/the-end-of-security-through-obscurity">advances in cybersecurity techniques and knowledge</a>, on the sides of both offense and defense. Another is evolution of <a href="/__u/stng.substack.com/p/assembly-language-is-over-converging">the software-hardware interface</a>, requiring substantial rewriting of old code in new languages to stay performance-competitive. There&#8217;s just one problem (well, OK, there are several): the software engineers are generally already busy maintaining their existing systems. How do we get this work done, in this era when we still can&#8217;t turn over the entire process to automation?</p><p>My answer is an instance of a pattern I plan to return to occasionally. Let&#8217;s think of the global economy as a <a href="/__u/stng.substack.com/p/our-social-world-as-a-distributed">distributed system</a> solving an optimization problem to organize the world properly. One of its tools is <a href="/__u/stng.substack.com/p/signaling-is-programmable-evolution">signaling</a>, where people produce costly, hard-to-fake displays of competence, which are used to evaluate them and partly decide where to slot them into the economy. Clearly that evaluation process produces massive downstream value. However, it also produces some pure &#8220;heat&#8221; with resources expended on signaling without directly moving the primary metrics of interest to the economy. In biology, signals probably evolve in the first place thanks to their connections to fundamental survival and reproductive success, even if <a href="https://en.wikipedia.org/wiki/Fisherian_runaway">runaway selection</a> can take them far from that territory over time.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>With our present-day abstract-thinking capabilities, we can choose to realign signaling deliberately so that it not only provides competence information but also generates first-order economic value. I&#8217;ll use the <em>productive signaling</em> header for articles that suggest instances of this pattern. Today we&#8217;re considering how to help spur widespread regeneration of important software.</p><h1>Get Them Writing Code That Matters</h1><p>Among top students worldwide in high school and a bit younger, there is a tradition of participation in <em>olympiads</em> like the <a href="https://en.wikipedia.org/wiki/International_Olympiad_in_Informatics">International Olympiad in Informatics (IOI)</a> or <a href="https://en.wikipedia.org/wiki/International_Mathematical_Olympiad">International Mathematics Olympiad (IMO)</a>. The basic form is hierarchical competition in particular STEM areas, with more localized competitions choosing winners to advance to competitions with broader geographic scope. For instance, the IOI challenges participants to write computer programs quickly that implement provided requirements, generally focusing on problems framed in terms of simple discrete mathematical objects, with straightforward specifications but nontrivial solutions. (It&#8217;s the subject matter that dominates classes commonly called just &#8220;<a href="https://en.wikipedia.org/wiki/Algorithm">algorithms</a>,&#8221; but the real scope of different kinds of tricky algorithms worth writing is <em>much</em> broader than we see in classic competitive programming.)</p><p>These kinds of competitions are very useful for identifying stars in the respective areas of knowledge. My own institution MIT seems to lean heavily on olympiad records to make decisions in undergraduate admissions, especially for international students. That is, olympiads produce a simple quantitative signal (based on standing in international contests) that is <em>highly legible even to nonexperts</em>, like people in charge of undergraduate admissions. I believe the signal being measured is also very relevant to potential to succeed in related careers. And olympiads are not just a measurement process: training for them helps upskill students and genuinely prepare them to contribute to important social problems in not too many years. We should also acknowledge that, given the centrality of signaling in our own evolution, it&#8217;s extremely common for people to hunger for chances to compete successfully and show off their talents, and we should be careful about letting video games become the default outlet!</p><p>Call me greedy, but, even given those benefits, I think it would still be fabulous if this experience also helped solve social problems directly. We expect to see approximately a few hundred competitors at a typical olympiad world-finals event, and <em>they are all solving the same problems</em>. The duplication is even greater for the sum of all more-localized competitions that determine competitors at world finals. We only need one competent team to solve a problem to realize the full social value of generated code for that problem! So the first big problem with this structure is that, from the standpoint of producing useful code, <strong>it creates massively redundant work, where we can subtract essentially all teams/competitors but the most-successful for a given problem and achieve the same practical outcome</strong>. We can see why this uniformity evolved, as it makes judging tractable, but hold that thought.</p><p>The other big problem is that <strong>solutions to the problems assigned in olympiads rarely create immediate social value</strong>, independently of signals about competitor competence levels. Pretty much by definition, these problems were already solved when the competition started! The organizers would be embarrassed to assign an unsolvable problem, and that pitfall is hard to avoid without solving in advance. There is also <em>the scale of the problems</em> that makes them unlikely to have big social impact. The time limitations of these contests push toward limited scope, considering how important real-world problems often occupy teams of software engineers for years, even before first wide releases. <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">AI coding assistance</a> is changing that equation, but please also hold that thought!</p><p>My alternative proposal is a competition structure around <strong>creating useful new open-source software</strong>. Developing a new and better program in an existing category is explicitly encouraged, and in fact it connects to our initial motivation to kick off widespread regeneration of important software, drawing on new wisdom in cybersecurity and elsewhere. Olympiads produce many variants of the same program, but they are all promptly thrown away, while I&#8217;m suggesting a contest that develops variants with increasing real-world value. If we can just judge competitors properly and summarize results in a form highly legible to nonexperts who make decisions like undergraduate admissions, then we are in business: we have harnessed signaling in a way that produces a socially valuable first-order output, not just the handy signal. (As a quick parenthetical tangent, AI is changing the educational landscape so much that it isn&#8217;t clear the admissions process we know today will last much longer, but if it goes away and isn&#8217;t replaced by other similar talent evaluations, humans have probably stopped being competitive to do knowledge work. Oops!)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!eFeV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefba1b2d-3ce6-471d-bc6a-ed0dd871d0b4_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!eFeV!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefba1b2d-3ce6-471d-bc6a-ed0dd871d0b4_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!eFeV!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefba1b2d-3ce6-471d-bc6a-ed0dd871d0b4_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!eFeV!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefba1b2d-3ce6-471d-bc6a-ed0dd871d0b4_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!eFeV!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefba1b2d-3ce6-471d-bc6a-ed0dd871d0b4_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!eFeV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefba1b2d-3ce6-471d-bc6a-ed0dd871d0b4_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/efba1b2d-3ce6-471d-bc6a-ed0dd871d0b4_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1253615,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/210542024?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefba1b2d-3ce6-471d-bc6a-ed0dd871d0b4_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!eFeV!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefba1b2d-3ce6-471d-bc6a-ed0dd871d0b4_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!eFeV!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefba1b2d-3ce6-471d-bc6a-ed0dd871d0b4_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!eFeV!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefba1b2d-3ce6-471d-bc6a-ed0dd871d0b4_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!eFeV!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefba1b2d-3ce6-471d-bc6a-ed0dd871d0b4_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I should add that, through showing a draft of this article to an LLM, I learned for the first time about <a href="https://codein.withgoogle.com/">Google Code-in</a>, which brokered between high-school-ish students and open-source projects that provided tasks within their code bases. On the one hand, I frequently interact with students just past this age range applying for research roles, and since I hadn&#8217;t heard of Code-in before, it is unlikely to have become a <em>common</em> tool for signaling programming ability. However, the fact that it continued for 10 years, with almost 15,000 students participating, provides some directional evidence that this sort of initiative can scale. Like the <a href="https://summerofcode.withgoogle.com/">Google Summer of Code</a>, which brings students into established open-source projects for quasi-internships, Code-in focused on projects that had been around for a while. Code-in wound down in January 2020 (did they know the pandemic was coming?!), just a little too soon to benefit from the new wave of AI-coding tools. It is already very feasible for the best-qualified students to create their own useful new software packages from scratch, and we should take advantage of that more-granular signal. Maybe it is only in-reach each year for approximately the number of students who participate in olympiad world championships or even earn top distinction in them, but that&#8217;s still an important population. Also, while that contributor count may not represent a big-enough workforce for e.g. a wide retrofitting of important software with new security protections, we can hope that advances in AI coding tools grow the population with time, and the contest structure can evolve to take advantage. (In this case, there is a helpful correlation, where when the risks from AI models finding vulnerabilities grow, the tools probably also improve to allow larger contests to maintain quality standards.)</p><h1>Implementation Challenges</h1><p>Which details need to be nailed down to make this kind of competition work?</p><p><strong>Open-source maintainers are already suffering from firehoses of AI-generated <a href="https://en.wikipedia.org/wiki/AI_slop">slop</a> &#8220;contributions,&#8221; and you want to add to the problem?</strong> Don&#8217;t worry: this proposal is for creation of new software projects and doesn&#8217;t require interfering with the normal workings of established ones!</p><p><strong>We are talking about creating programs worthy of mass adoption. Do we really want to entrust that task to high-school students?</strong> I&#8217;m not talking about a standardized test that all high-school students need to take. A very small fraction of high-school-equivalent students worldwide participate in the feeder programs for IOI. It only needs to be feasible for that echelon of students to build programs that at least make good starting points for broader open-source contributions, perhaps overwhelmingly by professionals, after improved fit for an important problem is demonstrated. And they get to use all the latest AI-powered software-engineering tools! We are still getting used to the power and engineering implications for those tools, but I don&#8217;t think it&#8217;s crazy to imagine small student teams or even solo competitors making really valuable and solid stuff over manageable time periods (which can nonetheless be at least months long, in stark contrast to durations of olympiad contests). Also, naturally, all of these efforts should be associated with <a href="/__u/stng.substack.com/p/proof-carrying-code-in-the-matrix">formal verification</a> that permits checking of quality for resulting code, but let me not get too sidetracked by that hobby horse.</p><p><strong>So we have each team writing its own new program, covering a wide range of domains to maximize social value on success. How on earth do we judge the results effectively?</strong> Just getting AI to do the judging is probably a helpful start but also vulnerable to pernicious gaming of the system, so we are going to need human judges. (Again, maybe we <em>don&#8217;t</em> need human judges, but then we&#8217;ve probably crossed over to the regime where, for better or worse, we don&#8217;t need to train humans in programming or evaluate their skills in it.) We can take advantage of the same hierarchy already found in olympiads: a succession of increasingly global competitions, where wider-scope competitions are fair to assume as including competitors with higher average competence. The earliest stages could even keep the conventional programming-contest format, switching to developing novel programs later on, when we don&#8217;t need as many judges. Competitors need to earn the reputations that their programs are worth evaluating. However, also think of companies eager to meet the best potential hires early. They may volunteer their engineers&#8217; judging time, even relatively early in the hierarchy of competitions. It may even be possible to <a href="https://en.wikipedia.org/wiki/Crowdsourcing">crowdsource</a> evaluation massively, using a metric like <a href="https://en.wikipedia.org/wiki/GitHub">GitHub</a> stars to judge outcomes, though the chances to game <em>that</em> metric (e.g. with <a href="https://en.wikipedia.org/wiki/Sock_puppet_account">sock puppets</a>) are clear. A proxy for real economic value derived by users would be ideal.</p><p><strong>You&#8217;re talking about evaluating the program that is produced, but we know that </strong><em><strong>it&#8217;s actually AI writing most of the code these days</strong></em><strong>, and the extent of that phenomenon will only increase. How do we know judging isn&#8217;t really just evaluating how much token budget a kid&#8217;s parents endowed financially?</strong> If we get fully automated generation of valuable new open-source software, that&#8217;s also a great outcome! Then we probably don&#8217;t need mass training and evaluation for programming skills anymore. If an important role remains for human guidance, then capacity in that role is precisely what we want to measure <em>and</em> what a judging process here should be able to get at. That still leaves what seem to me the biggest challenges to resolve, including the difficulty of effective expert <a href="https://en.wikipedia.org/wiki/Code_review">review</a> of reams of AI-generated code, to assign scores. Maybe this domain could be a good testing ground for techniques that will matter even more for industrial software-engineering teams? We can also hope costs of AI coding assistance are headed downward (though I have my suspicions that this goal will require moving away from deep learning, which <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">is inherently slow and expensive</a>).</p><p><strong>OK, but, seriously, what are the human judges actually doing to determine what skills the contestants have demonstrated?</strong> I agree it&#8217;s a tough question! We can see clearly the immense payoff from traditional programming competitions giving everyone the same problems and grading based on <a href="https://en.wikipedia.org/wiki/Test_case_(software)">test cases</a> passed, though the cost is not just lack of production of adoption-worthy code but also practice only on programming tasks that are unrepresentative of most real development in important ways. For now (before neural implants, say!), it should be safe to have face-to-face interviews with students, going through their code and asking the right questions about it. It&#8217;s a labor- and time-intensive process, which is why it&#8217;s important that relatively few contestants reach this level of the competition. We would also need some kind of rubric, a scoring formula that helps address the massive heterogeneity in what creates value across different kinds of programs, and this rubric also sounds nontrivial to create. In general, I think the saving grace is that this scoring aspect doesn&#8217;t need to be very precise; it just needs to identify a cohort of participants who have demonstrated enough competence to be worth inviting into the next-higher level of participation (e.g. university admission or a first job). Also, it should be possible to borrow good ideas from <a href="https://en.wikipedia.org/wiki/Science_fair">science fairs</a>, which also involve judging within a pretty open-ended design space of projects selected by students and also are already recognized as a somewhat common signaling currency by university admissions.</p><p><strong>Are there even enough high-school staff out there who are qualified to help students succeed in this kind of competition?</strong> Maybe not, but there&#8217;s a decent chance that generative AI provides a good substitute! Students can go beyond just asking AI to write code by also asking AI questions that prepare students to do more work on their own.</p><p><strong>How will students find which problems are worth solving with software, anyway?</strong> There could be some shared online resource with proposal of problems and voting on which ones matter, by suitably vetted audiences. Companies could propose problems alongside offers to judge solutions, perhaps augmented by something like automated test cases. However, especially with the way things are heading with AI coding assistance, choosing the right problems makes up an increasingly large fraction of effective software development. We may want to measure <em>exactly this skill</em>, even if it is very rare in the student population, even if research to find the right problem comes to dominate time spent on the competition!</p><p><strong>How will students know they should spend time on this weird new thing?</strong> It&#8217;ll take some time to bootstrap marketing, I&#8217;m sure. Our brains evolved to expect social contexts like those in <a href="https://en.wikipedia.org/wiki/Hunter-gatherer">hunter-gatherer</a> bands, where sets of skills worth learning stayed remarkably constant (from a present-day perspective) even over <em>thousands</em> of years. Clear guidelines and developmental rituals were provided, to guide young people through skill development. Olympiads have tied into this cognitive machinery today: students look around for what people do to develop skills and get credit for developing them, and they head for the competitions suited to their talents. Schools build up resources to help students and encourage them into the proper paths, motivated partly by <em>the school community&#8217;s</em> chance to get some signaling credit for elevating champions. If there are enough/important evaluators out there ready to use this signal, the rest should follow over time.</p><h1>Conclusion</h1><p>I sneakily saved a disclaimer for the end. I personally stuck with competition programming only minimally in my high-school days. Instead, I spent my time writing programs and getting people online to use them. Readers should be suspicious that I&#8217;m arguing for a change in signaling regime that disproportionately benefits people like me. I hope there&#8217;s still enough of a case that the social benefit is large!</p><p>It&#8217;s interesting to speculate (but I&#8217;m less qualified to do it) on olympiads in other domains. An especially intriguing one for me is math. Do we want students all going after different open problems to prove with <a href="https://en.wikipedia.org/wiki/Lean_(proof_assistant)">Lean</a>? Is it even conceivable that this early-career cohort could exhibit collective productivity comparable to what the whole international math community was pulling off five years ago?</p><p>There are plenty of logistical challenges left to sort out to implement these ideas; my goal is just to get the conversation started. My next post will return to the idea of frequent, rapid, automation-supported redevelopment of software, trying to fill in some of the holes pointed out by the great reader comments on <a href="/__u/stng.substack.com/p/rewrite-all-the-code-all-the-time">the previous article</a> (ironically, that link won&#8217;t take you to them, but they&#8217;re on <a href="https://www.linkedin.com/feed/update/urn:li:activity:7490389854086885376/">LinkedIn</a>, <a href="https://news.hada.io/topic?id=32322">GeekNews</a>, <a href="https://www.lesswrong.com/posts/9c9KPkJJbMz7tmv3K/rewrite-all-the-code-all-the-time">LessWrong</a>, and <a href="https://www.astralcodexten.com/p/open-thread-446/comment/312031455">ACX</a>).</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Rewrite All the Code, All the Time]]></title><description><![CDATA[The coming economics of software engineering and an important place for formal methods]]></description><link>https://stng.substack.com/p/rewrite-all-the-code-all-the-time</link><guid isPermaLink="false">https://stng.substack.com/p/rewrite-all-the-code-all-the-time</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 04 Aug 2026 12:42:37 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/420b5a52-34c7-44fc-9cf8-57d4a253abde_882x373.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><a href="/__u/stng.substack.com/p/the-end-of-security-through-obscurity">My last article</a> argued that, contrary to popular doom and gloom about LLMs finding security vulnerabilities at unheard-of speed, we have a great opportunity to <em>improve</em> software security. The catch is that it involves significant changes to development techniques to take advantage of <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a>. Sure, in theory, it would be great to release only programs that have mathematical proofs of meeting the most stringent security requirements. But there is so much code already out there and so few developers trained in driving the formal tools. Are we stuck with no path to better practices?</p><p>I&#8217;m going to make the case now for an even broader opportunity. <em>We need to stop thinking of production-ready code as a scarce resource</em>. It may take a few years to get the tools up-to-snuff, but we&#8217;ll reach a point where <em>the cost of ongoing reimplementation of significant code bases drops to the levels associated with SaaS subscriptions today</em>. Let&#8217;s start preparing ourselves for how software should be built and maintained in that world. Whenever there are innovations in security concerns that all applications&#8217; designs should address, we will be able to regenerate all of their code to comply. When new algorithms for familiar problems are invented, the cost should be near zero to regenerate using those algorithms, even if they require small customizations. All sorts of different requirements dimensions are fair game for incorporating in fairly frequent regeneration of all code in a project.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The idea that <a href="https://en.wikipedia.org/wiki/Legacy_system">legacy code</a> will steadily lose value, as it becomes easier to replace automatically, is becoming pretty mainstream, at least in the Silicon Valley hype ecosystem. In fact, the strong version of the thesis, which I endorse, is that code as we know it will become a throw-away automatic byproduct of the real long-lived artifacts, joining formats like <a href="https://en.wikipedia.org/wiki/Assembly_language">assembly language</a> that we mostly think of in that way today. I&#8217;ll start by making my version of that case. However, there will be a twist! I don&#8217;t think the story is nearly all about generative-AI methods that are popular today. Instead, formal methods will be crucial to realizing the strongest version of this idea, because they enable <em>truly automatic</em> generation of full code bases without human oversight.</p><h1>Automatic Programming</h1><p>It&#8217;s not nearly a fringe viewpoint today that programming will soon be done almost entirely by AI code generators that start from natural-language requirements. The goals and methods line up to an extent with the longstanding <a href="https://en.wikipedia.org/wiki/Program_synthesis">program synthesis</a> area of computer science, though the details have been shaken up a lot by machine learning relatively recently.</p><p>A good book to help understand the present situation is <em><a href="https://www.amazon.com/dp/B08BT44764/?tag=adamchli-20">The Computer Boys Take Over</a></em>. It covers the rise of &#8220;<a href="https://en.wikipedia.org/wiki/Automatic_programming">automatic programming</a>&#8221; and programmers&#8217; indignation at having it commoditize their skilled labor. A quote from a conference report covers the idea that &#8220;managers can now do their own programming&#8221; (though the quoted writer expressed the concept with skepticism while noting it was in the air).</p><p>However, there&#8217;s a catch: the quote is from 1962! The subject is the introduction of the first <a href="https://en.wikipedia.org/wiki/High-level_programming_language">high-level programming languages</a> and <a href="https://en.wikipedia.org/wiki/Compiler">compilers</a>, which automate the tedious writing of code processed directly by computer hardware. Programmers today just take for granted that they write in high-level languages, and pushback against AI coding tools has to do with the writing of those programs, <em>not</em> the ones that 1960s programmers were worried about being generated automatically. I would argue that the lesson we should learn is that the level of programming abstraction in software development is constantly rising, and we should not be surprised to see a step change toward an even higher abstraction level today. Indeed, <a href="https://en.wikipedia.org/wiki/David_Parnas">David Parnas</a> made that observation no later than the 1980s.</p><p>Let me spell out the framing a little more. There are many different ways to describe a given program. We get used to thinking of some languages as for writing &#8220;implementations&#8221; (e.g., Python) and some for writing &#8220;specifications&#8221; (e.g., various flavors of formal logic). However, I&#8217;ve found such a hard-and-fast distinction to be counterproductive. Let&#8217;s just think in terms of lower- and higher-level ways to describe functionality.</p><p>So the overall idea is that we want to describe programs in as concise, high-level ways as possible. Instead of storing conventional code in <a href="https://en.wikipedia.org/wiki/Repository_(version_control)">repositories</a>, we would prefer to store <em>the highest-level description of requirements that we can get away with</em>, where available tools reliably automate the rest of bringing the desired program to life. Some <a href="https://en.wikipedia.org/wiki/Non-functional_requirement">nonfunctional requirements</a> may change, in which case we can relatively simply fold them into the requirements and redo generation. Security is a good example that <a href="/__u/stng.substack.com/p/the-end-of-security-through-obscurity">the last article</a> covered, with examples like taking high-level secrecy policies and applying them on top of newly discovered vectors whereby programs can leak information. Another great example is performance, where I&#8217;m actually pretty surprised at how rare it has been for practical programming languages to support annotations that spell out performance requirements, so that it&#8217;s a compile-time error if code can&#8217;t be produced that is fast-enough, uses little-enough memory, etc.</p><p>In general, the game is to capture requirements unambiguously enough that <em>any program meeting them will be acceptable</em>, allowing truly automatic regeneration of running systems after light-to-moderate requirements changes. A thought experiment might be useful to capture the model. Imagine that some government routinely bids out software projects to contractors, which see each other as bitter competitors. What if every project went to two contractors, one who writes the specification and the other who gets to write any program meeting the specification? A specification gets written defensively, assuming the least-charitable reading by an implementer. In fact, the same specification, or its small evolutions, can be handed to a succession of adversarial implementers, which can, in theory, be an entirely safe way to maintain a program.</p><p>If it works, then established code bases of the conventional kind shrink dramatically in value. It becomes unclear that one organization can have an advantage over another on the basis of its stockpile of code written in conventional languages. What matters instead is having the right specifications. We reanimate them in new circumstances just like we recompile code today when libraries it depends on have been upgraded. I like that analogy, too, for connecting to how we might mix in new security requirements or new algorithm ideas, to be applied automatically in regenerating lower-level code from a specification.</p><h1>Natural Language Won&#8217;t Cut It</h1><p>The trouble is that the mainstream conversation is all about generating programs automatically from requirements in English and other natural languages. I&#8217;ve written before about how <a href="/__u/stng.substack.com/p/what-makes-language-processing-hard">natural-language processing is perversely hard</a>: not only are there inherent ambiguities that our evolutionary environment didn&#8217;t force us to fix, but there is even a strong argument that, to the extent we can think of natural language as &#8220;designed&#8221; by evolution, it was designed to be difficult to process, for its role in <a href="/__u/stng.substack.com/p/signaling-is-programmable-evolution">signaling</a>. The related problems are so hard that I doubt we will ever have <em>fully automatic</em> generation of production-ready systems from specifications in natural language &#8211; and organizations that fall short of full automation will not be able to keep up in the new economy.</p><p>I argue it&#8217;s a historical accident that we wound up with today&#8217;s deep-learning stacks as the only ones apparently up to this challenge of comprehensive automatic programming. Certain features were helpful in computer graphics and wound up built into <a href="https://en.wikipedia.org/wiki/Graphics_processing_unit">GPUs</a> for that reason, and then GPUs turned out to be useful for deep learning. Epic amounts of effort on full-stack performance engineering have gone into the domain, but we can make the same kind of effort to support better code-generation systems.</p><p>Let me give a brief set of pointers to my past articles making the case for a different, logic-based paradigm for automatic programming. Deep learning is very effective as <a href="/__u/stng.substack.com/p/deep-learning-the-ultimate-search">a kind of souped-up search engine</a>, but the match with the full process of programming is strained. At a fundamental level, <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">deep learning implies serious performance bottlenecks</a>, and it may also be impossible to <a href="/__u/stng.substack.com/p/designing-decision-making-systems">prove mathematically that deep learning-based systems always meet our requirements</a>. The power of these systems comes from analyzing large numbers of examples, and, for many domains, we happen to have enough examples only in natural language, but we need not restrict ourselves only to techniques that need to learn from examples. A related idea for automatic programming is curating libraries of flexible, reusable software components, which <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">AI can then invoke by name</a> instead of applying via emergent patterns from training. An even-more-powerful idea is <a href="/__u/stng.substack.com/p/codesign-for-legibility-to-ai-and">codesigning decision-making systems with the problems they solve</a>, where we should be able to avoid some of the most standard challenge problems for AI, leaving mostly problems that we can solve by generation from relatively compact and unambiguous specifications. While the standard retort to so many varieties of formal methods is that the real world is complicated and hard to specify, economic forces will push toward <a href="/__u/stng.substack.com/p/abstraction-boundaries-and-bubbles">simplifying the world in pockets of activity given over to automation</a> &#8211; and over time, the fraction of the economy covered by such pockets will grow, and pockets will merge with each other. We should expect collecting unambiguous requirements to <a href="/__u/stng.substack.com/p/why-software-requirements-get-easier">get much easier in that world</a>.</p><p>Why do we need to push beyond the spec-driven development techniques that are being built out today via a variety of tools, taking natural-language documents as &#8220;the new source code&#8221;? One instructive spec format from this domain is <a href="https://en.wikipedia.org/wiki/Easy_Approach_to_Requirements_Syntax">EARS (the Easy Approach to Requirements Syntax)</a>. It provides an alternative to freeform requirements as in the following sentence.</p><pre><code><code>As long as the vending machine isn't out of product X, when a customer presses the button for X and inserts payment equal to the cost of X, the vending machine should dispense one X.</code></code></pre><p>In EARS, the requirement can be rephrased as</p><pre><code><code>WHILE inventory of product X remains, WHEN the button for X is pressed, WHEN payment equal to the cost of X is inserted, the vending machine SHALL dispense one X.</code></code></pre><p>The all-caps words are keywords, delineating parts of a template that has a rigorous formal meaning. The problem is that all the other phrases remain in freeform natural language, with all its ambiguity. An AI code generator can misinterpret those parts, through either innocent misunderstanding or crafty malice.</p><p>Tools for spec-driven development will often translate specs at the level of EARS into finer-grained specs, often with multiple steps of increasing precision, taking up significant human time to detect mistakes. We just won&#8217;t be able to realize the full potential of <em>rewriting all the code, all the time</em> if we create so many bottlenecks where human attention must be applied. Regenerating based on new requirements should be as push-button as recompiling programs in conventional languages.</p><p>Here&#8217;s a closing diagram to sum up the narrative of progress that I&#8217;m pushing. It involves (1) changing more phases of software development to use <em>languages with clear formal semantics</em> and, partly as a result, (2) moving automation (as opposed to expert human effort) <em>earlier</em> in the development process. Much earlier in the history of software, <a href="https://en.wikipedia.org/wiki/Flowchart">flowcharts</a> were used as an intermediate program form with unclear semantics, and they were effectively replaced by high-level languages. Natural language-based spec formats strike me as that kind of hybrid beast that we&#8217;d be better-off replacing with a proper, unambiguous language.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!GoA3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38734699-2897-406d-8a0e-76712de6631d_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!GoA3!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38734699-2897-406d-8a0e-76712de6631d_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!GoA3!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38734699-2897-406d-8a0e-76712de6631d_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!GoA3!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38734699-2897-406d-8a0e-76712de6631d_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!GoA3!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38734699-2897-406d-8a0e-76712de6631d_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!GoA3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38734699-2897-406d-8a0e-76712de6631d_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/38734699-2897-406d-8a0e-76712de6631d_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1142418,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/209722700?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38734699-2897-406d-8a0e-76712de6631d_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!GoA3!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38734699-2897-406d-8a0e-76712de6631d_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!GoA3!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38734699-2897-406d-8a0e-76712de6631d_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!GoA3!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38734699-2897-406d-8a0e-76712de6631d_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!GoA3!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38734699-2897-406d-8a0e-76712de6631d_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Conclusion</h1><p>I&#8217;m the kind of optimist who often argued for throwing away all the old code and rewriting it in a better way, even <em>before</em> new AI-powered tools dramatically lowered the costs. When I started graduate school, &#8220;everyone&#8221; seemed to agree that the <a href="https://en.wikipedia.org/wiki/X86">x86 architecture</a> had achieved such dominance that serious work on programming tools had to work with x86 binaries &#8211; and then we had the rapid rises of both <a href="https://en.wikipedia.org/wiki/Mobile_device">mobile</a> platforms, which sported alternative architectures like <a href="https://en.wikipedia.org/wiki/ARM_architecture_family">ARM</a> that were more energy-efficient; and <a href="https://en.wikipedia.org/wiki/Web_application">web applications</a>, which developed their own parallel universe of <a href="https://en.wikipedia.org/wiki/JavaScript">JavaScript</a> implementations and <em>no</em> distribution of computer-native code. The applications in these ecosystems (and many of the tools behind them) were created basically from scratch over handfuls of years &#8211; and they didn&#8217;t even have AI to accelerate the process!</p><p>The payoff of a reliable flow for <em>rewriting all the code</em> is no longer having an excuse for not using the latest ideas for software quality everywhere. We should be able to take familiar cadences of, say, new software releases and instead associate them with complete rewrites of all code used at particular companies. The key is setting everything up for absolute minimization of the need for human oversight during a cycle of regeneration &#8211; and only formal methods seem up to that challenge. It&#8217;ll take reengineering of the stack for high-performance inference to work natively with formal logic instead of just linear algebra (though it may work well for the two styles to cooperate), which I started sketching recently (e.g. in discussion of <a href="/__u/stng.substack.com/p/assembly-language-is-over-converging">hardware-software codesign that converges the two sides</a>) and which will occupy many future posts here. There&#8217;s going to be a lot to figure out, just as the design and implementation of high-level programming languages became a sprawling enterprise.</p><p>My next article will suggest one sociological approach to kicking off the virtuous cycle of rewriting a lot of important code.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The End of Security Through Obscurity]]></title><description><![CDATA[Keeping up with AI that finds software vulnerabilities]]></description><link>https://stng.substack.com/p/the-end-of-security-through-obscurity</link><guid isPermaLink="false">https://stng.substack.com/p/the-end-of-security-through-obscurity</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 28 Jul 2026 12:07:45 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4b5a7de0-2abf-415a-9f2e-0e8d3822472d_573x337.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Three subjects that were fairly obscure when I chose them as specialties as a student were programming tools, cybersecurity, and <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal methods</a>. Strangely (to me, at least), they&#8217;re all having a moment now in connection to generative AI. This article covers an interesting mix of challenge and opportunity at their intersection. The opportunity will relate to our persistent larger story of very scalable automation for writing trustworthy code.</p><p>The AI-safety community has at least for some time (decades) talked around the possibility of powerful AI finding new security vulnerabilities in important code. The 2023 <a href="https://arxiv.org/abs/2303.08774">GPT-4 Technical Report</a> called out that usage mode as a risk. In 2026, <a href="https://en.wikipedia.org/wiki/Anthropic">Anthropic</a> prepared to release a new <a href="https://en.wikipedia.org/wiki/Large_language_model">LLM</a> named <a href="https://en.wikipedia.org/wiki/Claude_Mythos">Mythos</a>, which they had become worried was <em>too good</em> at finding vulnerabilities. As a result, instead of starting with a broad release, they initiated Project Glasswing, which only shared Mythos with a modest set of big-name tech companies, to get their help understanding the cybersecurity implications. Eventually, a weakened version was released widely under the name Fable. Then the next twist was <a href="https://www.cnbc.com/2026/06/12/anthropic-disables-access-to-fable-5-and-mythos-5-to-comply-with-government-directive.html">the U.S. government basically declaring that even Fable was too dangerous</a> and couldn&#8217;t be exported to other countries, a restriction so hard to implement that Anthropic removed Fable access for everyone.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Eventually, Fable was allowed back into the wild, but the whole saga got many more people thinking about cybersecurity risks from powerful AI. There was also <a href="https://techcrunch.com/2026/07/22/how-an-openais-human-mistake-led-to-the-ai-powered-hack-on-hugging-face/">a more recent headline-grabbing story</a>, about how an improperly configured model-testing environment led to an <a href="https://en.wikipedia.org/wiki/OpenAI">OpenAI</a> agent compromising a <a href="https://en.wikipedia.org/wiki/Hugging_Face">Hugging Face</a> server. Let&#8217;s fight the gravitational pull of sci-fi sensationalism and instead talk through the fundamental changes to how software engineering should be done.</p><h1>Deep Learning Finds Security Bugs</h1><p>The problem is actually grounded in a mix of technology and economics. Standard software-development methods have always allowed security-critical bugs to survive unnoticed in important programs. Well before generative AI went big, there was a thriving market in <a href="https://en.wikipedia.org/wiki/Zero-day_vulnerability">zero-day vulnerabilities</a>: each a security bugs that someone had found but that was not yet known to the owners of a program. A bad actor canonically buys a zero-day and uses it to stage one or a handful of attacks. <a href="https://cyberdefensereview.army.mil/Portals/6/Documents/2022_summer_cdr/CDR_V7N3_Summer_2022-SE-WEB-1.pdf?ver=oDnMjK7AGrLLtmFJPHUwxQ%3D%3D">Markets in zero-days were studied</a>, and bugs in important programs would generally go for thousands to hundreds of thousands of U.S. dollars each.</p><p>Lurking bugs in popular software programs are one example of the <a href="https://en.wikipedia.org/wiki/Anti-pattern">antipattern</a> of <a href="https://en.wikipedia.org/wiki/Security_through_obscurity">security through obscurity</a>, where the maintainers of a system assume that aspects of the system are <em>obscure</em> enough that no one will figure out their security vulnerabilities. Even an <a href="https://en.wikipedia.org/wiki/Open-source_software">open-source</a> program can benefit from obscurity, where the code base is generally complex enough that few outsiders can decipher it well enough to pinpoint vulnerabilities. The less popular a software package, the more it benefits from obscurity. Obscurity is even more powerful for closed-source programs, which may be distributed only in <a href="https://en.wikipedia.org/wiki/Executable">binary</a> form. Then a process called <a href="https://en.wikipedia.org/wiki/Reverse_engineering#Software">reverse engineering</a> is needed to recover even the level of detail found in normal source code. The bad news is that generative AI is also proving to be useful for reverse engineering, so the obscurity bonus for closed-source software is eroding.</p><p>There used to be a major bottleneck in finding zero-days: the time of a scarce population of security experts. If the market values bugs in a particular program at a low enough level, the experts won&#8217;t spend their time finding those bugs. The emerging problem may be clear from that last sentence: if vulnerability discovery can be automated by LLMs instead, it often becomes economical to set them loose on relatively obscure code bases and still come out ahead. We have lost the old defense that most code isn&#8217;t economically important enough that its bugs are worth enough to justify the cost of finding them. Roughly speaking, the cost of vulnerability-finding is heading toward becoming negligible, as providers of LLM services optimize their offerings.</p><p>On the face of it, this development brings clear bad news for &#8220;the good guys,&#8221; the well-meaning creators and maintainers of software packages. Innocent coding mistakes frequently create security bugs, and it is no longer safe to assume that those bugs will be obscure enough that no one will invest in finding them. However, this state of affairs pretty directly implies a great way for software engineers to defend themselves.</p><p>Assume an attacker has a cheap, automated way to find security vulnerabilities. Then we can transform that method into an effective way for software developers to find vulnerabilities before releasing code &#8211; maybe even before allowing it to pass <a href="https://en.wikipedia.org/wiki/Continuous_integration">continuous integration</a> (the sanity checks often placed between new code and other software developers on a team).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Gk5H!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca1057a-1b33-4e16-ae3e-69a9ab5b8397_1481x772.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Gk5H!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca1057a-1b33-4e16-ae3e-69a9ab5b8397_1481x772.png 424w, /__u/substackcdn.com/image/fetch/$s_!Gk5H!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca1057a-1b33-4e16-ae3e-69a9ab5b8397_1481x772.png 848w, /__u/substackcdn.com/image/fetch/$s_!Gk5H!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca1057a-1b33-4e16-ae3e-69a9ab5b8397_1481x772.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Gk5H!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca1057a-1b33-4e16-ae3e-69a9ab5b8397_1481x772.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Gk5H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca1057a-1b33-4e16-ae3e-69a9ab5b8397_1481x772.png" width="1456" height="759" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3ca1057a-1b33-4e16-ae3e-69a9ab5b8397_1481x772.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:759,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:670379,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/208675147?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca1057a-1b33-4e16-ae3e-69a9ab5b8397_1481x772.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Gk5H!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca1057a-1b33-4e16-ae3e-69a9ab5b8397_1481x772.png 424w, /__u/substackcdn.com/image/fetch/$s_!Gk5H!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca1057a-1b33-4e16-ae3e-69a9ab5b8397_1481x772.png 848w, /__u/substackcdn.com/image/fetch/$s_!Gk5H!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca1057a-1b33-4e16-ae3e-69a9ab5b8397_1481x772.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Gk5H!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca1057a-1b33-4e16-ae3e-69a9ab5b8397_1481x772.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now assume that the attacker still has a cost-effective way to find bugs using LLMs or any other readily available automation. It follows that the software developers can adopt the same tooling as part of their quality assurance, and it remains cost-effective. That is, defenders are in good shape so long as they have access to roughly the same scanning tools as the attackers. We might need to assume that legitimate software projects are at least as well-funded as the attackers, which isn&#8217;t always true, though it&#8217;s increasingly likely to be true enough as the cost of LLM-based methods drops. For maximum benefit, we must also assume that attackers don&#8217;t get head starts, with earlier access to new automation. (We&#8217;ll come shortly to addressing the further asymmetry that attackers often win over defenders when both sides can only run tools that generate bug ideas without guarantees of completeness.)</p><p>If we are somehow able to ensure those two assumptions hold, then (modulo the last parenthetical) we are in even better security shape than before generative AI took the stage. There is a one-time adjustment process to bring these new tools into all existing and new projects, which admittedly is a large cost globally, and we will return to that challenge at the end of this article and especially in the next one. However, we should remain worried about the possibility that attackers repeatedly manage to get early access to new bug-finding tools, due to the same kinds of arms-race dynamics that arise for communication speed in <a href="https://en.wikipedia.org/wiki/High-frequency_trading">high-frequency trading</a>. Is there any hope for <em>a security check to end all security checks</em>, where we don&#8217;t have to worry that future tool generations will find bugs that their predecessors missed? So long as we rely on the mysterious black boxes that are deep-learning models, it seems we&#8217;ll always have to deal with rare but consequential mistakes, and security is a domain where even rare mistakes can be quite consequential indeed.</p><h1>Enter Formal Verification</h1><p>Readers who have been following along in the series are probably not surprised that I now bring up <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a> as the ideal solution! That is, if we produce machine-checked mathematical proofs that programs have the right security properties, those proofs cover <em>all possible execution scenarios</em>, and attackers can&#8217;t find bugs later, regardless of the growing quality of their analysis tools.</p><p>Let me be a little more specific. LLM vulnerability-finders are not different in kind from a variety of security-scanning tools that were already standard years ago, including the category of <a href="https://en.wikipedia.org/wiki/Static_application_security_testing">static application security testing (SAST)</a>. This whole category of bugfinding is often understood probabilistically, generating &#8220;good guesses&#8221; about where true problems lie. If any guarantee is present about finding <em>all</em> security issues in some category, it is usually paired with generating many <a href="https://en.wikipedia.org/wiki/False_positives_and_false_negatives">false positives</a>, to the point where developers hesitate to wade through them all and may just refuse to use the tool. (After all, we can write a guaranteed-sound &#8220;bugfinder&#8221; that just accuses every line of code of looking fishy!) The upshot is that automatic methods are not able to draw attention to all security issues; we should think of them as stochastically missing important bugs every now and then. Over time, as new tools are released (including those based on LLMs), they may converge toward reliably reporting all vulnerabilities. However, it is very hard to become convinced that, at a point in time, there does not remain an important gap of undetected issues, which attackers remain incentivized to find and exploit.</p><p>Formal verification can fill this gap, guaranteeing coverage of <em>all</em> instances of a bug category, with no inherent requirement to produce false positives. There remains a common objection by savvy practitioners (beyond the cost of proof-writing, which we&#8217;ll save for later posts): are we really so sure we know how to spell out what security means, with enough mathematical precision? The good news here is that there are a number of established counterintuitive phenomena of formal methods to help out. For one thing, <a href="/__u/stng.substack.com/p/subversion-resistance-for-free-from">proving almost any interesting property of a program tends to rule out some of the worst security problems</a>. For another thing, though it may be hard to come up with the right properties to prove of a component in isolation, <a href="/__u/stng.substack.com/p/simplifying-alignment-by-expanding">integrating proofs of different components is extremely effective at finding specification mistakes</a>. The same techniques also help protect against bugs in all system infrastructure that an application depends on, because infrastructure layers can also be verified, and proofs can be composed across layers.</p><p>Still, there&#8217;s no doubt about it: writing specifications is a nontrivial engineering activity. Nonetheless, there is a force multiplier in specification-writing: it can contribute much more to security than careful software development, per unit of effort. Consider the following two stylized scenario variants, maintaining a software package with and without formal verification.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!i0VU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41cb05b0-c2cb-4d0b-afc4-cfde7498770c_1663x946.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!i0VU!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41cb05b0-c2cb-4d0b-afc4-cfde7498770c_1663x946.png 424w, /__u/substackcdn.com/image/fetch/$s_!i0VU!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41cb05b0-c2cb-4d0b-afc4-cfde7498770c_1663x946.png 848w, /__u/substackcdn.com/image/fetch/$s_!i0VU!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41cb05b0-c2cb-4d0b-afc4-cfde7498770c_1663x946.png 1272w, /__u/substackcdn.com/image/fetch/$s_!i0VU!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41cb05b0-c2cb-4d0b-afc4-cfde7498770c_1663x946.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!i0VU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41cb05b0-c2cb-4d0b-afc4-cfde7498770c_1663x946.png" width="1456" height="828" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/41cb05b0-c2cb-4d0b-afc4-cfde7498770c_1663x946.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:828,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1081012,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/208675147?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41cb05b0-c2cb-4d0b-afc4-cfde7498770c_1663x946.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!i0VU!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41cb05b0-c2cb-4d0b-afc4-cfde7498770c_1663x946.png 424w, /__u/substackcdn.com/image/fetch/$s_!i0VU!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41cb05b0-c2cb-4d0b-afc4-cfde7498770c_1663x946.png 848w, /__u/substackcdn.com/image/fetch/$s_!i0VU!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41cb05b0-c2cb-4d0b-afc4-cfde7498770c_1663x946.png 1272w, /__u/substackcdn.com/image/fetch/$s_!i0VU!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41cb05b0-c2cb-4d0b-afc4-cfde7498770c_1663x946.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The upper scenario represents the mainstream approach today, where new security bugs keep popping up. Many of them are similar to past bugs, but human attention still isn&#8217;t up to catching them before they are released into the wild. The lower scenario represents a pivot into formal verification. Yes, there are still surprises of new <em>kinds</em> of bugs that sneak through. However, each time we learn about a new kind of bug, we <em>strengthen the specification to rule out all bugs of that kind</em>. With sound formal-verification tools, it then becomes impossible for those bugs to sneak through, even in the face of arbitrary programmer mistakes.</p><p>Even with formal verification, we still have the risk of serious zero-day bugs. However, if we arrange verification properly, then <em>the zero-day window only opens for each new category of bug</em>, not each individual programming mistake. We still worry that the bad guys get access to bug-finding software before the good guys and exploit a zero-day window, but there should just be many fewer windows that open. A window doesn&#8217;t open for each slip of the fingers by a programmer but instead only when an interestingly new kind of bug is discovered.</p><p>Formal verification has another asymmetric advantage over heuristic bug-finding: it allows us to move beyond having each development team suffer in isolation dealing with security problems, instead enabling <em>significant shared effort toward blocking classes of vulnerabilities across all projects</em>. It&#8217;s not that every project needs to discover and remediate a new bug category on its own. There are even opportunities for nearly instant updating of, say, all open-source projects&#8217; security specifications, once a new bug category is discovered and announced by one project.</p><p>As an example, let&#8217;s use the classic security property of confidentiality within <a href="https://en.wikipedia.org/wiki/Information_flow_(information_theory)">information flow</a>. Some inputs to a system are considered to be secret, and their values should not be able to influence outputs that are considered public. Actually, there can be a lot more sophistication to the security policy than just considering inputs vs. outputs and secret vs. public values. Most generally, software developers define <a href="https://en.wikipedia.org/wiki/Lattice-based_access_control">lattices</a> of security levels. I wrote previously about <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">how such concerns can be addressed for the case of compilers</a>. We stepped through a series of increasing twists on top of the same basic confidentiality requirements: permitting <a href="https://en.wikipedia.org/wiki/Nondeterministic_algorithm">nondeterminism</a> in the specification opens up opportunities to leak secrets through choices that are left up to the implementation code, and allowing an eavesdropper to monitor <a href="https://en.wikipedia.org/wiki/Covert_channel#Timing_channels">timing</a> can open up additional bad flows.</p><p>Just like software implementations, specifications should involve <a href="https://en.wikipedia.org/wiki/Library_(computing)">libraries</a> of reusable notations. We can imagine a library for specification of secure information flow. The library can define a language for describing security levels, which each software project will use to specify its security policy, in addition to tagging inputs and outputs with levels. Then the library encodes how to connect that fundamental requirement to all sorts of different channels, including those based on nondeterminism and timing. In fact, the library starts out <em>without</em> coverage of those channels, but once it&#8217;s added, it becomes instantly applicable to all applications using the library. The situation is similar to what&#8217;s already in deployment with e.g. <a href="https://docs.github.com/en/code-security/concepts/code-scanning/codeql/query-packs">CodeQL query packs</a> for pulling in new rules for static-analysis tools with weaker formal guarantees. Furthermore, if best practices are being followed through use of <a href="/__u/stng.substack.com/p/simplifying-alignment-by-expanding">end-to-end verification</a>, then infrastructure like compilers and operating systems can have its specifications expanded analogously, and the new application can have its specification stay linked with those of other components, for very efficient rollout of specified protection against a new attack family.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!ULoG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bcc2ceb-432c-4595-bc2a-697ccef23f6f_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!ULoG!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bcc2ceb-432c-4595-bc2a-697ccef23f6f_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!ULoG!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bcc2ceb-432c-4595-bc2a-697ccef23f6f_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!ULoG!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bcc2ceb-432c-4595-bc2a-697ccef23f6f_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ULoG!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bcc2ceb-432c-4595-bc2a-697ccef23f6f_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!ULoG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bcc2ceb-432c-4595-bc2a-697ccef23f6f_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1bcc2ceb-432c-4595-bc2a-697ccef23f6f_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1501829,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/208675147?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bcc2ceb-432c-4595-bc2a-697ccef23f6f_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!ULoG!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bcc2ceb-432c-4595-bc2a-697ccef23f6f_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!ULoG!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bcc2ceb-432c-4595-bc2a-697ccef23f6f_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!ULoG!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bcc2ceb-432c-4595-bc2a-697ccef23f6f_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ULoG!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bcc2ceb-432c-4595-bc2a-697ccef23f6f_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now, updating a specification isn&#8217;t the whole story. Proofs about programs need to be extended to cover the new requirements. I wrote previously about how <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">simplifying programming languages allows AI coding assistants to be more effective</a>, including in meeting security requirements. If we simplify far enough, no explicit proof effort is required! I gave an example from our startup <a href="https://nectry.com/">Nectry</a>, which integrates checking of security policies into an agentic loop, so an AI writing software is getting constant feedback on security mistakes that it makes. (By the way, though it may not be obvious from the current Nectry web site both that we are doing this kind of formal methods and that we have a private beta running, in fact both are true, and folks at companies medium-sized and up can <a href="mailto:adamc@nectry.com">contact me</a> if they think they might want to participate.)</p><p>I&#8217;ll also have much more to say in later articles about automating development of verified software, for broader classes of programs and specifications.</p><h1>The Looming Challenge</h1><p>I just discussed two main ways the rise of generative AI need not make software security more precarious than before &#8211; and can in fact <em>help make security better</em> (in the case of formal methods, through accelerating automatic proof-writing). The problem is that each method, LLM vulnerability scanners and strong formal verification, requires significant changes to software-development processes. Many <a href="https://en.wikipedia.org/wiki/Legacy_system">legacy systems</a> were developed before such technology was available, and we should worry about their security. Even new projects remain overwhelmingly carried out by teams not trained in these new methods.</p><p>What trajectory can we take toward getting these methods integrated into all software projects of nontrivial importance? My next article presents one framework with implications beyond security, considering how software maintenance should change when the cost of writing new code plummets.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Essence of GPUs]]></title><description><![CDATA[Progress exposing physics understandably and remaining opportunities for symbolic computation]]></description><link>https://stng.substack.com/p/the-essence-of-gpus</link><guid isPermaLink="false">https://stng.substack.com/p/the-essence-of-gpus</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 21 Jul 2026 12:27:34 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/66605f87-f680-493d-8405-ea7d260ea275_504x359.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The last sequence of posts started by griping about how <a href="/__u/stng.substack.com/p/the-expensive-fictions-of-low-level">programming languages</a> and <a href="/__u/stng.substack.com/p/why-your-cpu-works-so-hard">CPUs</a> aren&#8217;t well-aligned to support effective performance tuning, as matters for <a href="/__u/stng.substack.com/p/intelligence-depends-on-organizing">harnessing computational intelligence</a>. Then I <a href="/__u/stng.substack.com/p/assembly-language-is-over-converging">sketched one approach to doing better</a>, by converging hardware and software toward common spatial abstractions. Many readers probably noted some connections between that direction and how <a href="https://en.wikipedia.org/wiki/Graphics_processing_unit">GPUs</a>, the darlings of efficient generative-AI execution, work today. This post gives my take on the big ideas behind GPUs and what opportunities for further improvement they leave open.</p><p>We&#8217;ll stick to the big picture of design principles behind GPUs, rather than heading into a practitioner&#8217;s tutorial of GPU programming. I&#8217;m not even qualified to give the latter, considering that the <a href="https://en.wikipedia.org/wiki/CUDA">CUDA programming framework</a> that dominates this domain was released to the public in the same year that I finished my PhD, and I never picked up the experience later. We&#8217;ll analyze a simplified version of CUDA as what programming-languages folks would call an <a href="https://en.wikipedia.org/wiki/Abstract_machine">abstract machine</a>, a somewhat-fictional model of what GPU infrastructure does that is both convenient for programmers and usefully close to hardware reality.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>One more piece of grounding is helpful before I get into GPU details. This domain is one that takes great advantage of <strong>regular parallelism</strong>, where many parts of a computation follow a common sequence of instructions and just touch different data. (Examples are coming when we get into the main part of the article.) The lurking point behind this sequence of posts, and much of my writing here in general, is that <em><a href="/__u/stng.substack.com/p/designing-decision-making-systems">making intelligent systems more trustworthy</a> depends on computations that are not regular</em>, as arise in symbolic domains like <a href="https://en.wikipedia.org/wiki/Compiler">compilers</a> and <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a>. In particular, it will be hard to upgrade our programming process to produce reliable code automatically if formal reasoning can&#8217;t keep up performance-wise with creative generation of programs.</p><p>OK, I&#8217;m almost ready to present the main ideas behind GPUs and highlight similarities and differences with <a href="/__u/stng.substack.com/p/assembly-language-is-over-converging">the spatial-programming framework I sketched</a>. One consistent theme will be that, unlike with <a href="/__u/stng.substack.com/p/why-your-cpu-works-so-hard">CPUs</a>, GPUs expose the right knobs for tuning performance in low-level code, and they largely do it by <em>exposing programming abstractions that are closer to what physics gives us to work with in designing circuits</em>. We will see that every distinctive feature brings some benefit in controlling costs of communication within a chip, which I emphasized as the key obstacle to scaling. By varying hardware and compilers more broadly, we might only be able to improve performance by constant factors, like the difference between processing <em>n</em> inputs taking 2<em>n</em> or 100<em>n</em> time steps. While computer scientists often perform only <a href="https://en.wikipedia.org/wiki/Big_O_notation">asymptotic analysis</a> of performance, the constant factors certainly do matter. We&#8217;ll also discuss how different programming abstractions are more or less friendly for humans, <a href="https://en.wikipedia.org/wiki/Compiler">compilers</a>, or other automatic analyzers or generators of code.</p><h1>Step 0: Vector Instructions</h1><p>Before we actually talk about GPUs, I&#8217;ll cover a feature that is widely supported by CPUs: vector instructions, otherwise known as <a href="https://en.wikipedia.org/wiki/Single_instruction,_multiple_data">single instruction, multiple data (SIMD)</a>.</p><p>If many cores are running the same code but operating on different parts of memory, there is wasteful redundancy. For instance, the code for each common instruction needs to be copied into each core. Though we can control this overhead by achieving good <a href="https://en.wikipedia.org/wiki/Locality_of_reference">memory locality</a> via running the same small set of instructions repeatedly, the duplication of code in <a href="https://en.wikipedia.org/wiki/CPU_cache#ICACHE">instruction caches</a> across CPU-based systems is fundamental. Every core also keeps track separately of where it is in the program (its <a href="https://en.wikipedia.org/wiki/Program_counter">program counter</a>).</p><p>In the SIMD model, shockingly, a single instruction operates on multiple data! Concretely, one instruction explains manipulations on multiple contiguous memory locations. Take the example of trying to increment by one every memory cell in a group of four. This diagram contrasts how it works with four CPUs vs. one CPU running a SIMD instruction.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!m624!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F714d971c-67c7-4ecc-9e17-0500228ff709_1638x960.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!m624!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F714d971c-67c7-4ecc-9e17-0500228ff709_1638x960.png 424w, /__u/substackcdn.com/image/fetch/$s_!m624!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F714d971c-67c7-4ecc-9e17-0500228ff709_1638x960.png 848w, /__u/substackcdn.com/image/fetch/$s_!m624!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F714d971c-67c7-4ecc-9e17-0500228ff709_1638x960.png 1272w, /__u/substackcdn.com/image/fetch/$s_!m624!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F714d971c-67c7-4ecc-9e17-0500228ff709_1638x960.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!m624!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F714d971c-67c7-4ecc-9e17-0500228ff709_1638x960.png" width="1456" height="853" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/714d971c-67c7-4ecc-9e17-0500228ff709_1638x960.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:853,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1303041,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/207331363?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F714d971c-67c7-4ecc-9e17-0500228ff709_1638x960.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!m624!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F714d971c-67c7-4ecc-9e17-0500228ff709_1638x960.png 424w, /__u/substackcdn.com/image/fetch/$s_!m624!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F714d971c-67c7-4ecc-9e17-0500228ff709_1638x960.png 848w, /__u/substackcdn.com/image/fetch/$s_!m624!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F714d971c-67c7-4ecc-9e17-0500228ff709_1638x960.png 1272w, /__u/substackcdn.com/image/fetch/$s_!m624!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F714d971c-67c7-4ecc-9e17-0500228ff709_1638x960.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Progress beyond old-school CPUs:</strong> One of the biggest obstacles to high parallelism with CPUs is the need to associate each unit of parallel work with a separate processor core, a relatively heavyweight unit of hardware with many parts. Only so many complex cores can fit in a given spatial area, so making the units of parallelism more complicated pushes them further apart and increases communication delays. A vector instruction is nice for allowing the logic of a replicated operation to be relatively simple, taking up little space relative to a full CPU core.</p><p><strong>Remaining opportunities:</strong> It&#8217;s very clear from this model that it only helps directly with very regular parallelism, where exactly the same operation is performed on a run of contiguous storage locations. Even when such opportunities exist in a program, relatively complex code may be needed to find them. Furthermore, many symbolic workloads (like formal verification) often don&#8217;t decompose in such a regular way.</p><h1>Step 1: Many Small Threads of Execution</h1><p>The original central abstraction of general-purpose GPUs is <a href="https://en.wikipedia.org/wiki/Single_instruction,_multiple_threads">single instruction, multiple threads (SIMT)</a>. Like the non-SIMD CPU program we just discussed, a SIMT program can have many threads (units of parallelism) running a single program. What&#8217;s different in GPUs is bundling threads into groups that share positions within program code. Efficiencies very similar to vector instructions are realized in running such a group. For instance, every software-visible execution step only needs to fetch code from memory once and share the information across all threads in the group.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!DKGF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fc572a0-2d6e-492c-a501-fd5514ac5ee0_1691x930.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!DKGF!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fc572a0-2d6e-492c-a501-fd5514ac5ee0_1691x930.png 424w, /__u/substackcdn.com/image/fetch/$s_!DKGF!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fc572a0-2d6e-492c-a501-fd5514ac5ee0_1691x930.png 848w, /__u/substackcdn.com/image/fetch/$s_!DKGF!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fc572a0-2d6e-492c-a501-fd5514ac5ee0_1691x930.png 1272w, /__u/substackcdn.com/image/fetch/$s_!DKGF!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fc572a0-2d6e-492c-a501-fd5514ac5ee0_1691x930.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!DKGF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fc572a0-2d6e-492c-a501-fd5514ac5ee0_1691x930.png" width="1456" height="801" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2fc572a0-2d6e-492c-a501-fd5514ac5ee0_1691x930.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:801,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1353002,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/207331363?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fc572a0-2d6e-492c-a501-fd5514ac5ee0_1691x930.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!DKGF!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fc572a0-2d6e-492c-a501-fd5514ac5ee0_1691x930.png 424w, /__u/substackcdn.com/image/fetch/$s_!DKGF!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fc572a0-2d6e-492c-a501-fd5514ac5ee0_1691x930.png 848w, /__u/substackcdn.com/image/fetch/$s_!DKGF!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fc572a0-2d6e-492c-a501-fd5514ac5ee0_1691x930.png 1272w, /__u/substackcdn.com/image/fetch/$s_!DKGF!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fc572a0-2d6e-492c-a501-fd5514ac5ee0_1691x930.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The CUDA term of art for a group of threads, launched together, is a <a href="https://en.wikipedia.org/wiki/Thread_block_(CUDA_programming)#Warps">warp</a>. The hardware will generally maintain sets of running warps, picking to execute next one that is ready to proceed. This scheduling hides memory latency: while several warps are waiting for responses from relatively slow memory, another warp can proceed, perhaps generating a memory request itself and suspending until the response arrives. It is also valuable to notice similarities in the memory requests coming out of different threads in a warp, since often a single request to memory can cover what multiple threads have asked for, and memory requests are often the biggest performance bottlenecks.</p><p>When a warp contains instructions that make decisions about what code to run next, it can happen that execution <em>diverges</em>, where not all the constituent threads make the same decision. Here&#8217;s where we come to the reality of how the simple CUDA model is implemented. It is not simply the case that the hardware monitors thread activity dynamically and, on each execution step, runs just a set of threads that are converged with each other. In reality, the work is split between compilers and hardware, e.g. with compilers inserting extra instructions to note where threads converge again. Also, programs are overwhelmingly written to avoid divergence, since divergence has performance costs.</p><p><strong>Progress beyond old-school CPUs:</strong> Programs can be written in terms of many more parallel threads, giving both hardware and compilers more opportunities to exploit parallelism. We&#8217;re talking about hundreds of thousands of threads exposed at once to latest-generation GPU hardware, as opposed to merely hundreds of threads for the latest CPUs.</p><p><strong>Remaining opportunities:</strong> We&#8217;re still clearly heavily dependent on regular parallelism: SIMT only helps when many threads are doing roughly the same thing, and hardware scheduling of warps is heavyweight-enough that we wouldn&#8217;t want it to happen separately for each thread. Whether logic for tracking thread coordination is built into hardware or found in instructions inserted by a compiler, we still pay runtime costs to rediscover structure that may have been very clear in source code but lost during compilation. GPU programs remain sequential (one instruction after another), not spelling out dataflow graphs explicitly, which is ironic given that much GPU code is created from dataflow graphs with systems like <a href="https://en.wikipedia.org/wiki/PyTorch">PyTorch</a> (though today&#8217;s compilers recover much of that information). Hardware could do a better job planning efficient execution with a code representation that avoids incidental ordering constraints between execution steps.</p><h1>Step 2: Hardware Acceleration for Linear Algebra</h1><p>The last two steps represent a smooth progression in one design dimension, but let&#8217;s turn next to two other important aspects of GPU design that are mostly orthogonal. A critical part of today&#8217;s GPUs is custom hardware for two-dimensional matrix operations, principally variations of matrix multiplication, which figure so centrally in <a href="https://en.wikipedia.org/wiki/Deep_learning">deep learning</a>. In fact, <a href="https://arxiv.org/abs/2007.00072">a study of BERT training</a> found that <a href="https://en.wikipedia.org/wiki/Tensor_contraction">tensor contractions</a> accounted for a majority of GPU running time (though see the next step for a twist, as much of the time was actually spent on related data movement).</p><p>We see here an instance of the general pattern that performance can often be improved substantially by making hardware less flexible and more specialized. An intuition for the payoff here is that generality requires extra logic that takes up space in a hardware design. A specialized circuit has fewer parts, which can be closer together, which lowers cumulative delays for communication between parts. It&#8217;s also true that more of the computational work feels fundamental to a workload, instead of merely representing overhead from explaining to flexible hardware what it should do next.</p><p>These hardware units in GPUs are programmable mostly in choosing variations of matrix multiplication, including selecting different number representations and slight variations in how elements are laid out in memory. A matrix accelerator sometimes (especially in the latest hardware generations) includes its own local memory, with input matrices copied into it and output matrices copied out. One way or another, hardware is organized so that matrix accelerators interact with other state purposely situated close to them.</p><p>The CUDA term of art for such hardware is <a href="https://en.wikipedia.org/wiki/CUDA#Tensor_cores">tensor core</a>.</p><p><strong>Progress beyond old-school CPUs:</strong> It&#8217;s hard to compete with hardware created for a relatively narrow purpose. For a program heavy on linear algebra, performance is going to be great. These hardware units are often implemented as <a href="https://en.wikipedia.org/wiki/Systolic_array">systolic arrays</a>, in a style related to <a href="/__u/stng.substack.com/p/assembly-language-is-over-converging">the spatial one that I sketched last time</a>, and it&#8217;s believable that they achieve the best performance possible for their specific hardware-fabrication technologies.</p><p><strong>Remaining opportunities:</strong> Even programs that want to work with tensors of three dimensions and up face awkwardness in using matrix accelerators. Taking good advantage of them is even more challenging for symbolic processing. If only the systolic arrays were moderately more programmable, we could teach them new symbolic tricks.</p><h1>Step 3: Explicit Memory Movement</h1><p>I&#8217;ve <a href="/__u/stng.substack.com/p/the-expensive-fictions-of-low-level">emphasized</a> that communication costs dominate performance of parallel systems as they scale, and <a href="/__u/stng.substack.com/p/why-your-cpu-works-so-hard">hardware that tries to hide that fact through complex protocols</a> makes it hard for programmers to tune performance. I would argue that this principle is the critical one that GPUs have really embraced, leaning into explicit data movement. Add in the last step&#8217;s use of hardware acceleration for common operations, and we have the explanation for GPU domination of deep learning.</p><p>While CPUs expose memory just via the fiction of a global memory that all threads can read and write, GPU programming also distinguishes between different kinds of memory, often associated with different levels in a hierarchy of nodes. Program instructions are needed to copy among the different memories, rather than just having hardware-managed caching do copying between CPU cache levels automatically. (It is important to note that GPUs <em>do</em> maintain cache-coherence protocols for data motion touching global memory.) Whether we are talking about &#8220;normal&#8221; SIMT threads or different kinds of more fixed-function accelerators (principally matrix accelerators), information often needs to wind up in their private memories, where it can naturally be accessed very quickly. (For conceptual simplicity here, I&#8217;m counting <a href="https://en.wikipedia.org/wiki/Processor_register">registers</a> as a special case of memory.)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!7RWF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf624a62-26ad-475c-be8e-3262603b93db_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!7RWF!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf624a62-26ad-475c-be8e-3262603b93db_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!7RWF!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf624a62-26ad-475c-be8e-3262603b93db_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!7RWF!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf624a62-26ad-475c-be8e-3262603b93db_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!7RWF!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf624a62-26ad-475c-be8e-3262603b93db_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!7RWF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf624a62-26ad-475c-be8e-3262603b93db_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bf624a62-26ad-475c-be8e-3262603b93db_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1344836,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/207331363?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf624a62-26ad-475c-be8e-3262603b93db_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!7RWF!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf624a62-26ad-475c-be8e-3262603b93db_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!7RWF!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf624a62-26ad-475c-be8e-3262603b93db_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!7RWF!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf624a62-26ad-475c-be8e-3262603b93db_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!7RWF!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf624a62-26ad-475c-be8e-3262603b93db_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Progress beyond old-school CPUs:</strong> With cost of communication as the most important influence on performance, it&#8217;s a big win to be able to manage it explicitly with copy operations. When the programmer works hard enough, optimal use of physical resources can be coded up. Then the work of implementing the abstract machine can be divided intelligently between hardware and compilers.</p><p><strong>Remaining opportunities:</strong> The latest GPUs still include very-involved hardware-managed caching, so with even-better compiler support, we could hope for better performance. But thinking in the other direction, what happens when compilers aren&#8217;t smart enough to plan the right data movement? We might still want runtime hardware support for understanding what is being computed and where, to make smart decisions about copies &#8211; with higher-level understanding of program structure than what hardware-managed caching systems embody, where they see every cache line (chunk of memory) as equal and undifferentiated. Also, CUDA and friends should be seen as rather-low-level languages, where programmer-friendliness is low. While indeed they are most-often used today via compilers from higher-level abstractions like <a href="https://en.wikipedia.org/wiki/PyTorch">PyTorch</a>, those abstractions generally offer relatively weak features for program state that changes during execution. It is a shame if the need to work explicitly with state forces dropping down to low-level CUDA (or even meaningfully higher-level frameworks like <a href="https://triton-lang.org/">Triton</a>, which retains explicit programming of data movement but allows it to be described at a higher level). Finally, distances in physical space (which determine communication cost) are a little opaque in these kinds of hierarchical models, where number of hops in a <a href="https://en.wikipedia.org/wiki/Tree_structure">tree</a> is an OK but imperfect approximation.</p><h1>One Alternative Architecture, Briefly</h1><p>Let me also briefly mention the alternative parallel-computing system from <a href="https://en.wikipedia.org/wiki/Cerebras_Systems">Cerebras</a>, because it came up in a reader comment for the last post. Roughly speaking, their programming and hardware stack looks like a simplified, flat GPU, where spatial geometry is exposed directly instead of laundering it through a hierarchy of thread groups and memory. Many threads are tiled in two-dimensional space, with explicit communication only with their immediate neighbors. Instead of any runtime tracking of thread convergence, compilers map work to threads that run independently. The individual threads are still programmed with relatively conventional sequential, memory-based code. Programmers and compilers can still do a really good job optimizing communication patterns on this platform, when they put their minds to it. The direct experience of writing such low-level code is still quite grungy, suggesting that higher-level languages would be good to add to the mix. Finally, as with GPUs, there is minimal runtime help for making smart data-movement decisions, in cases where not enough could be predicted in advance by compilers.</p><h1>Conclusion</h1><p>That&#8217;s a wrap for this sequence of four posts on programming abstractions and performance tuning. We see that GPUs represent a significant advance over CPUs in exposing the realities of physics, allowing more-but-simpler threads of execution and, arguably more importantly, explicit movement of data across memories. However, much of their efficiency is tied to regularity of data layouts and operations, which is not a natural fit for many domains like formal verification. There is good higher-level-language tooling for describing computations as dataflow graphs that don&#8217;t maintain state that changes during execution, but going beyond that model usually requires dropping down to rather low-level languages that are even more trouble to use correctly than conventional CPU-focused languages. We should aim for &#8220;have your cake and eat it, too&#8221; stacks that compile from pleasant high-level languages down through intermediate forms that make it easy to express spatial optimizations and end up in hardware that has enough information to make good runtime decisions efficiently.</p><p>Now we&#8217;ve covered some of the basic building blocks for how we could make tasks like code generation very efficient and reliable at the same time (if we can make formal reasoning efficient enough, too). I&#8217;m going to step back now and spend three posts on how we should reorient software development to take advantage of that capability. I&#8217;ll start with the question of how worried we should be about advanced models finding security vulnerabilities as quickly as we can fix them, transitioning into broader implications for the software-development process.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Assembly Language Is Over (Converging Hardware and Software)]]></title><description><![CDATA[Spatial programming abstractions for performance tuning]]></description><link>https://stng.substack.com/p/assembly-language-is-over-converging</link><guid isPermaLink="false">https://stng.substack.com/p/assembly-language-is-over-converging</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 14 Jul 2026 13:41:31 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/6d4e857e-a3d4-4b05-9619-e76959374454_342x199.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;ve been writing about how today&#8217;s standard computing abstractions are poor fits for helping humans or AI coding tools understand and improve the performance of programs. The potential for automated software engineering may be difficult to realize, if we don&#8217;t provide better languages for automated systems to &#8220;think in.&#8221; So far I covered <a href="/__u/stng.substack.com/p/the-expensive-fictions-of-low-level">software (low-level programming languages)</a> and <a href="/__u/stng.substack.com/p/why-your-cpu-works-so-hard">hardware (CPUs)</a> separately. Now I want to turn to a synthesis that suggests a productive way forward.</p><p>Many programs aren&#8217;t subjected to direct performance optimization. Either they are needed for contexts where performance isn&#8217;t critical, or they are fed into automated systems that do the optimization, whether those be conventional <a href="https://en.wikipedia.org/wiki/Compiler">compilers</a> or <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">AI coding tools</a>. However, as in the last two posts, my focus here is on languages that we use to express the process of optimizing a program&#8217;s performance. Whatever tricks we want to apply for improving speed or memory usage, they need to be expressible as transformations in the chosen language. It needs to be tractable enough to predict a program&#8217;s performance from its source code. When we realize a given program has left performance on the table, we hope that the methods to improve performance can be expressed in the language.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The claim I want to make is that <strong>languages for hosting such optimization need to be explicitly spatial</strong>, representing something closer to hardware circuits than to the software programs we are used to. The last two articles emphasized how such a spatial model is fundamentally what physics gives us to work with, and performance depends critically on <strong>communication</strong> costs between nodes arranged in space. While we have tried hard to work with <a href="/__u/stng.substack.com/p/the-expensive-fictions-of-low-level">software notations that hide the spatial nature</a> and <a href="/__u/stng.substack.com/p/why-your-cpu-works-so-hard">hardware that scurries around understanding software well enough to make good spatial decisions</a>, splitting the optimization problem between these two layers makes it too hard to solve well.</p><p>Another slogan I like to use for this message is <strong><a href="https://en.wikipedia.org/wiki/Assembly_language">assembly language</a> is over</strong>. That is, going forward, we need to swap out the class of lowest-level software programming languages. It has the two main weaknesses I emphasized about <a href="/__u/stng.substack.com/p/the-expensive-fictions-of-low-level">low-level programming languages</a> in general: sequentialized code and global shared memory. It&#8217;s a fine abstraction when we don&#8217;t want to get serious about performance optimization, but it&#8217;s totally unsuitable when we do, leaving us searching for a replacement or several of them that deserve similarly central places in computing stacks.</p><p>If we accept this principle, then the inevitable result is that <strong>performance-tuned software and performance-tuned hardware will converge</strong>, in terms of the kinds of abstractions used to describe them. In my own experience working with computer-science students, it&#8217;s very common for those who have focused on software to declare that they &#8220;aren&#8217;t hardware people&#8221; and don&#8217;t want to work on hardware projects; I&#8217;m sure the opposite pattern is common in the world, too. It&#8217;s my view that these two disciplines will need largely to merge, and let me sketch, coming at it from the two directions, first how software can become more like hardware and then vice versa.</p><h1>How Software Should Become More Like Hardware (Getting Spatial)</h1><p>Physical reality is pieces of computation and storage scattered through space, communicating with each other at cost proportional to distance. To support productive optimization of software, we need languages that expose enough of the physical reality, at a minimum with explicit communication and a good way of estimating its cost. A commonality we will see is switching from having <em>hardware</em> make spatial decisions <strong>at runtime</strong>, toward having <em>compilers</em> make spatial decisions <strong>in advance</strong>. We can afford to have automation &#8220;think harder&#8221; about spatial decisions when they are made before execution and then reused for many runs (though also some challenges of understanding execution grow, when we can&#8217;t simply observe actual values flowing through a system).</p><p>There is a long history of trying to boost performance by moving work from hardware to compilers. <a href="https://en.wikipedia.org/wiki/Very_long_instruction_word">Very long instruction word (VLIW)</a> systems are an example first developed in the 1980s, where a low-level software program specifies not just a sequence of basic instructions but instead a sequence of <em>groups</em> of instructions that should run simultaneously. It becomes an important part of the compiler&#8217;s job to understand instructions well enough to put them in parallel groups. A particularly infamous initiative in this direction was the <a href="https://en.wikipedia.org/wiki/Itanium">Itanium</a> architecture family, which Intel was predicting would supersede their conventional CPU designs for server workloads. Instead, the effort failed in the market, and the failure is often blamed on the difficulty of writing effective compilers. However, note that these efforts have generally assumed that software programming languages look just as we&#8217;re used to, retaining <a href="/__u/stng.substack.com/p/the-expensive-fictions-of-low-level">the weaknesses that I complained about recently</a>, and my personal bet is that such obstacles can be overcome by making more sweeping changes across the whole stack of software and hardware. So much is changing with adoption of AI in software engineering that it&#8217;s a great time to imagine other changes, too.</p><p>So let me sketch some potential approaches. Ironically for the part of this article labeled as being about software, we&#8217;ll mostly be looking at hardware architectures. The point will be what software programming model each one exposes, as the lowest level of software coding for its stack. We will focus on how such software formats allow programmers to work hard enough to make the optimization choices that best exploit what is physically possible, rather than being limited by somewhat-arbitrary program formats. In some sense, responsibility is passed to compilers, but I&#8217;ll have to save for later posts some ideas of how these compilers ought to work.</p><p>One common approach today, which already blurs the line between software and hardware, is <a href="https://en.wikipedia.org/wiki/Field-programmable_gate_array">field-programmable gate arrays (FPGAs)</a>. Basically, an FPGA has one circuit skeleton built into it &#8211; many computation nodes and many links between them. Programming an FPGA involves telling each node which logic gate to become (virtually speaking), using which of its links with other nodes. The nice thing about FPGAs is that they offer close to the optimal level of control over distribution of computation in (two-dimensional) space. One important downside is that they impose overheads over custom silicon, which isn&#8217;t surprising when we note that each node of an FPGA is programmed by filling in a literal <a href="https://en.wikipedia.org/wiki/Truth_table">truth table</a> (though the FPGA term of art is &#8220;lookup table&#8221;), an exhaustive description of which output bits to generate for every set of possible input bits &#8211; which sounds kind of crazy to encode and execute directly. <a href="https://dl.acm.org/doi/10.1145/1117201.1117205">A widely cited study from 2006</a> establishes that using an FPGA instead of a custom chip usually slows down processing by a few times (referring to the wall-clock delay for the <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">critical path</a>), requires about 20 times as much physical area, and consumes about 10 times as much power. These particulars vary across designs, and the distribution has changed as FPGAs have evolved since 2006, but the quantitative orientation still seems about right. Such relatively modest costs may not be enough to deter usage in many important domains, but then the biggest issue is probably the complexity of programming FPGAs effectively, which we&#8217;ll get to in the second part of this article.</p><p>One way that FPGA overhead has improved, which is also highly relevant to hardware design in general, is through providing more special-purpose functional blocks. The general pattern is that <em>specialization</em> improves performance. The available programmable units need not have the full flexibility of Boolean truth tables, to provide a useful abstraction of reconfigurable circuits. Hardware <a href="https://en.wikipedia.org/wiki/Dataflow_architecture">dataflow architectures</a> were developed starting in the 1970s, to work with software described explicitly in circuit-like form. However, these original systems didn&#8217;t have a spatial element to software programming. Compute nodes spread throughout the spatial area of a chip would <em>dynamically</em> choose circuit nodes to evaluate next, after noticing that their inputs had already been calculated. That dynamic scheduling mimicked the same two disadvantages that I described for <a href="/__u/stng.substack.com/p/why-your-cpu-works-so-hard">the heroic efforts of CPUs</a> (and indeed can be considered to have had direct influence on the modern development of <a href="https://en.wikipedia.org/wiki/Out-of-order_execution">out-of-order CPU execution</a>).</p><p>Let&#8217;s consider one example of a hardware style that exposes more explicitly <em>spatial</em> programming. A line of 21st-century efforts has developed that kind of dataflow platform, hybridizing FPGAs and old-school dataflow machines. Like FPGAs, we have a grid of reconfigurable gates/nodes in a dataflow fabric. Like prior dataflow machines, the vocabulary of available operations is more similar to CPU instructions than truth tables. Each node is typically programmed with the equivalent of up to a handful of CPU instructions, allowing a silicon node implementation more like a mini-CPU than a sea of truth tables.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!VWEx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa8681c3-5355-4b60-b3f7-d8dc8b82814a_1693x929.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!VWEx!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa8681c3-5355-4b60-b3f7-d8dc8b82814a_1693x929.png 424w, /__u/substackcdn.com/image/fetch/$s_!VWEx!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa8681c3-5355-4b60-b3f7-d8dc8b82814a_1693x929.png 848w, /__u/substackcdn.com/image/fetch/$s_!VWEx!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa8681c3-5355-4b60-b3f7-d8dc8b82814a_1693x929.png 1272w, /__u/substackcdn.com/image/fetch/$s_!VWEx!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa8681c3-5355-4b60-b3f7-d8dc8b82814a_1693x929.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!VWEx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa8681c3-5355-4b60-b3f7-d8dc8b82814a_1693x929.png" width="1456" height="799" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fa8681c3-5355-4b60-b3f7-d8dc8b82814a_1693x929.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:799,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1484857,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/206751774?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa8681c3-5355-4b60-b3f7-d8dc8b82814a_1693x929.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!VWEx!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa8681c3-5355-4b60-b3f7-d8dc8b82814a_1693x929.png 424w, /__u/substackcdn.com/image/fetch/$s_!VWEx!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa8681c3-5355-4b60-b3f7-d8dc8b82814a_1693x929.png 848w, /__u/substackcdn.com/image/fetch/$s_!VWEx!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa8681c3-5355-4b60-b3f7-d8dc8b82814a_1693x929.png 1272w, /__u/substackcdn.com/image/fetch/$s_!VWEx!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa8681c3-5355-4b60-b3f7-d8dc8b82814a_1693x929.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In this diagram, note how the CPU approach on the left (associated with the buzzword of a <a href="https://en.wikipedia.org/wiki/Von_Neumann_architecture">von Neumann architecture</a>) involves physical circuitry that is program-independent, performing complex run-time analysis of a program, effectively building up and tearing down a sequence of spatial dataflow graphs. In contrast, in the <em><a href="https://en.wikipedia.org/wiki/Coarse-grained_reconfigurable_array">coarse-grained reconfigurable array (CGRA)</a></em> approach on the right, a program is mapped once into a configuration of each compute node in a grid. Then the computation can proceed without changing the role of each piece of silicon during execution.</p><p>Two main advantages (which we can imagine also applying to a variety of similar architectures) follow from the CGRA style.</p><ol><li><p>We avoid the so-called <a href="https://en.wikipedia.org/wiki/Von_Neumann_architecture#Von_Neumann_bottleneck">von Neumann bottleneck</a>, particularly the cost of continually fetching instructions from memory to reconfigure a silicon computation graph dynamically.</p></li><li><p>Probably more importantly, the lowest-level software format can talk directly about the two major factors that I derided <a href="/__u/stng.substack.com/p/the-expensive-fictions-of-low-level">low-level programming languages</a> for not supporting. That is, computation can be laid out explicitly throughout space, with attention to the communication distances between nodes that talk to each other; and many memory operations can be performed on local memory nodes accessible only to their immediate neighbors, avoiding global memory with a hidden cache-coherence protocol and its complex performance model.</p></li></ol><p>I found it fascinating to learn that this kind of architecture has been explored to optimize two very different classes of computing: high-performance <a href="https://en.wikipedia.org/wiki/Server_(computing)">servers</a> and ultra-low-power <a href="https://en.wikipedia.org/wiki/Embedded_system">embedded systems</a>. High parallel performance motivated the design of the <a href="https://dl.acm.org/doi/10.1145/3079856.3080256">Plasticine</a> academic prototype with an associated software compiler called <a href="https://dl.acm.org/doi/10.1145/3192366.3192379">Spatial</a>, which led to the company <a href="https://en.wikipedia.org/wiki/SambaNova_Systems">SambaNova Systems</a>. Later, targeting small embedded computers dependent on harnessing energy from their environments, for instance in space satellites, an academic prototype called <a href="https://dl.acm.org/doi/10.1109/MICRO56248.2022.00046">Riptide</a> was developed, which led to the <a href="https://www.efficient.computer/">Efficient Computer Company</a>.</p><p>The design space is wide open, of the ideal languages to form the boundaries between hardware and software, and the class I&#8217;ve just sketched is just one example (though it&#8217;s one that I&#8217;ve become a fan of); we&#8217;ll cover a variety of ideas in later posts. Let me highlight already what I see as one major opportunity. Almost all full computing stacks of this kind maintain global shared memory, one of the two major performance misfeatures I highlighted in the last two posts. Much storage that would traditionally be maintained in shared memory is pushed off into elements of the programmable dataflow fabric. However, typically source code still uses shared memory explicitly, and those memory accesses are carried over into the generated code. As a result, we have the twin downsides of a complex model for software programmers and a hardware implementation with cache coherence that is very hard to scale to high parallelism. I argue that a major pending <a href="/__u/stng.substack.com/p/hardware-software-codesign-and-autonomous">codesign</a> challenge is creating programming languages and hardware models that allow full coordination across many parallel compute nodes <em>without</em> classic shared memory.</p><h1>How Hardware Should Become More Like Software (Strengthening Modularity)</h1><p>Whether we think of spatial programs as describing software or hardware, coding them up in the traditional hardware way leaves much to be desired. Hardware development is traditionally done in terms of <a href="https://en.wikipedia.org/wiki/Register-transfer_level">register-transfer level (RTL)</a> languages, which basically identify the key pieces of evolving state in a program (<a href="https://en.wikipedia.org/wiki/Hardware_register">registers</a>) and associate each one with a circuit that computes its new value based on prior values of registers. Such a program can be run repeatedly to evolve register values, one <a href="https://en.wikipedia.org/wiki/Clock_signal">clock cycle</a> at a time. This abstraction provides great control over what&#8217;s possible to implement with physical circuits, but it&#8217;s challenging to program correctly, accounting for a large fraction of the expense of developing new digital hardware.</p><p>One alternative that has become popular is <a href="https://en.wikipedia.org/wiki/High-level_synthesis">high-level synthesis (HLS)</a>, which compiles programs in low-level programming languages into RTL. It suffers from the same challenges that plagued the Itanium project and its cousins, though it has been much more successful, probably because engineers who use it have been more willing to change their programming conventions to enable it. Other approaches to higher-level hardware programming include <a href="https://en.wikipedia.org/wiki/Chisel_(programming_language)">Chisel</a> and a broader family of <a href="https://en.wikipedia.org/wiki/Metaprogramming">metaprogramming</a> techniques it represents, where programs in various languages are written to <em>generate</em> RTL code. This style of tool offers weak <a href="https://en.wikipedia.org/wiki/Modularity">modularity</a> for metaprogrammed components, making it easy for a bug in the program that computes one module to cause trouble for a different module. I would argue that HLS is too hard to pull off because it doesn&#8217;t offer a spatial abstraction, while metaprogramming systems don&#8217;t help enough because they expose a spatial abstraction that is <em>too low-level</em>, lacking in both structure and guarantees.</p><p>An alternative abstraction that has greatly influenced my research is associated with the <a href="https://en.wikipedia.org/wiki/Bluespec#Bluespec_SystemVerilog">Bluespec hardware language</a> developed at MIT starting around the year 2000.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!hprs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20d4eb5f-43c3-4d23-af14-7273bd8da1cc_1693x929.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!hprs!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20d4eb5f-43c3-4d23-af14-7273bd8da1cc_1693x929.png 424w, /__u/substackcdn.com/image/fetch/$s_!hprs!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20d4eb5f-43c3-4d23-af14-7273bd8da1cc_1693x929.png 848w, /__u/substackcdn.com/image/fetch/$s_!hprs!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20d4eb5f-43c3-4d23-af14-7273bd8da1cc_1693x929.png 1272w, /__u/substackcdn.com/image/fetch/$s_!hprs!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20d4eb5f-43c3-4d23-af14-7273bd8da1cc_1693x929.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!hprs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20d4eb5f-43c3-4d23-af14-7273bd8da1cc_1693x929.png" width="1456" height="799" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/20d4eb5f-43c3-4d23-af14-7273bd8da1cc_1693x929.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:799,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1446462,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/206751774?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20d4eb5f-43c3-4d23-af14-7273bd8da1cc_1693x929.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!hprs!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20d4eb5f-43c3-4d23-af14-7273bd8da1cc_1693x929.png 424w, /__u/substackcdn.com/image/fetch/$s_!hprs!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20d4eb5f-43c3-4d23-af14-7273bd8da1cc_1693x929.png 848w, /__u/substackcdn.com/image/fetch/$s_!hprs!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20d4eb5f-43c3-4d23-af14-7273bd8da1cc_1693x929.png 1272w, /__u/substackcdn.com/image/fetch/$s_!hprs!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20d4eb5f-43c3-4d23-af14-7273bd8da1cc_1693x929.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The left pane of the diagram shows the standard RTL approach, where a complex spatial computation is one big circuit with all kinds of winding wire paths within it. The right pane, for the Bluespec style, exposes more of the modularity that software programmers are used to, for instance in <a href="https://en.wikipedia.org/wiki/Object-oriented_programming">object-oriented programming</a>. The circuit is broken into modules, each with a well-defined purpose. Every module has <a href="https://en.wikipedia.org/wiki/Encapsulation_(computer_programming)">private, encapsulated state</a>, exposed to other modules only through explicit <a href="https://en.wikipedia.org/wiki/Method_(computer_programming)">method calls</a>.</p><p>In the more-modular style on the right, the modules can be handled separately in a variety of appealing dimensions.</p><ol><li><p>Different teams can build different modules.</p></li><li><p>Each module can have its own formal specification, which need not mention anything about other modules.</p></li><li><p>Each module can be <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formally verified</a> separately against its own local specification.</p></li><li><p>Yet there are streamlined principles for reasoning about what happens when separately verified modules are brought together into one system.</p></li></ol><p>The other crucial ingredient is compiler technology that can turn such high-level descriptions into RTL automatically, reprising our theme of moving decisions about spatial arrangement to happen in advance. Through static analysis of a design, that style of compilation can understand possibilities to run different modules simultaneously and generate circuits to arbitrate the decisions, often coming very close to the performance of hand-written RTL, if not matching it (or exceeding it, in cases where engineers were confused by all the concurrency and missed optimization opportunities). Muddying the terminological waters is the hardware world&#8217;s convention of calling that process not compilation but <a href="https://en.wikipedia.org/wiki/Logic_synthesis">synthesis</a>, not to be confused with <a href="https://en.wikipedia.org/wiki/Program_synthesis">program synthesis</a> (automatically writing software from specifications, a topic we&#8217;ll spend plenty of words on in later posts). This service of automatically interconnecting modules for performance is very different from what RTL tools can do with the lower-level notion of module that they have long supported, where module couplings are general wires rather than anything so high-level as method calls.</p><p>I&#8217;ve been involved in a series of projects developing Bluespec-inspired languages with strong connections to machine-checked proofs, including <a href="https://adam.chlipala.net/papers/KamiICFP17/">Kami</a>, <a href="https://adam.chlipala.net/papers/KoikaPLDI20/">K&#244;ika</a>, and <a href="https://adam.chlipala.net/papers/FjfjPLDI25/">Fjfj</a>. Some previous posts have used examples from formal-verification projects that have drawn on these frameworks, including for <a href="/__u/stng.substack.com/p/simplifying-alignment-by-expanding">end-to-end integration verification across hardware and software</a> and for <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">proof that hardware systems don&#8217;t leak secrets through timing</a>.</p><p>Again, the Bluespec style is just one example of raising the level of abstraction in hardware programming. I&#8217;ll explain it in more detail in later posts, and I also plan to cover some other abstractions that depart even further from industry practice.</p><h1>Conclusion</h1><p>There is always a tension in the design of abstractions for programming, whether by people or AI. I think of the programming process as a structured search through the space of possible programs, informed by a specification (formal or informal). On the one hand, making abstractions higher-level allows single steps in the search space to accomplish more-interesting changes, which accelerates search. It is also easier to apply <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a> to validate new variants against requirements. On the other hand, lower-level abstractions typically provide more control over performance. I&#8217;ve argued here that, first, those lower-level abstractions at the hardware-software boundary need to be more <em>spatial</em> to support continued performance scaling; and, second, that we needn&#8217;t accept industry&#8217;s standard hardware-description languages as our spatial-programming playground, with opportunities to raise the abstraction level while still maintaining good control of performance.</p><p>The next post will be the last in this series on abstractions for performance, covering where <a href="https://en.wikipedia.org/wiki/Graphics_processing_unit">GPUs</a> line up with these principles and where they diverge, especially when it comes to supporting efficient formal verification. Then we&#8217;ll change gears to discussing how higher-level engineering workflows should change with increased automation.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Why Your CPU Works So Hard]]></title><description><![CDATA[A surprisingly large abstraction gap with the physical world and why it matters]]></description><link>https://stng.substack.com/p/why-your-cpu-works-so-hard</link><guid isPermaLink="false">https://stng.substack.com/p/why-your-cpu-works-so-hard</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 07 Jul 2026 12:45:11 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/42b60423-c22a-4316-85c4-11b5395191f3_357x220.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>We&#8217;re in the middle of a sequence of posts thinking about how to approach performance of full computing stacks. Following the motto &#8220;<a href="/__u/stng.substack.com/p/intelligence-depends-on-organizing">intelligence depends on organizing computation correctly and efficiently</a>,&#8221; the way we arrange our computations can have dramatic effects on how much automated intelligence we&#8217;re able to muster. Not only is it important to have enough hardware at our disposal (as we see in the current mania over datacenter buildout for AI), but it also really matters how we arrange that hardware and the software running on it. Furthermore, <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">AI code generation</a> must deal with meeting performance requirements of the programs it writes. Unifying the two concerns is <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">recursive self-improvement</a>, where one reason we care about efficiency of an intelligent system is to make it more effective at improving its own efficiency, supporting a virtuous cycle that can begin an <a href="https://en.wikipedia.org/wiki/Technological_singularity#Intelligence_explosion">intelligence explosion</a>.</p><p><a href="/__u/stng.substack.com/p/the-expensive-fictions-of-low-level">The last post</a> covered low-level programming languages, the ones most-advertised as providing programmers maximum control over the performance of programs. I argued that the popular low-level languages are actually remarkably poorly suited to that task today, as <a href="/__u/stng.substack.com/p/hardware-software-codesign-and-autonomous">hardware and software evolve together</a>. Understanding the performance of a program in such a language requires thinking about aspects of hardware organization not at all represented explicitly in program syntax. I will use the current post first to go into more detail on the fundamental performance model that the laws of physics give us, and then I will primarily focus on the performance model that modern <a href="https://en.wikipedia.org/wiki/Central_processing_unit">CPUs</a> expose to software and the ways it makes performance tuning unnecessarily hard.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Computation in Space (Communication Dominates)</h1><p>Let me start by repeating a figure from the last post.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!WCIj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de18eee-ee87-48ff-9aa4-4a45562ee2fd_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!WCIj!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de18eee-ee87-48ff-9aa4-4a45562ee2fd_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!WCIj!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de18eee-ee87-48ff-9aa4-4a45562ee2fd_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!WCIj!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de18eee-ee87-48ff-9aa4-4a45562ee2fd_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!WCIj!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de18eee-ee87-48ff-9aa4-4a45562ee2fd_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!WCIj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de18eee-ee87-48ff-9aa4-4a45562ee2fd_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1de18eee-ee87-48ff-9aa4-4a45562ee2fd_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2345105,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/205382419?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de18eee-ee87-48ff-9aa4-4a45562ee2fd_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!WCIj!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de18eee-ee87-48ff-9aa4-4a45562ee2fd_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!WCIj!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de18eee-ee87-48ff-9aa4-4a45562ee2fd_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!WCIj!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de18eee-ee87-48ff-9aa4-4a45562ee2fd_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!WCIj!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de18eee-ee87-48ff-9aa4-4a45562ee2fd_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Computation needs to be accomplished by configuring physical space. The parts of a computation coordinate through sending signals through space, and the speed of light is believed to be a limit on how quickly those signals can propagate. As a result, the distance between physical parts of a computation comes to limit performance. This diagram distinguished between computation and storage, though it is interesting to analyze both and notice that the same physical communication bottleneck limits them.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!3chM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2f7122e-8ffd-4ff9-8cea-fc0b91794481_1717x916.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!3chM!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2f7122e-8ffd-4ff9-8cea-fc0b91794481_1717x916.png 424w, /__u/substackcdn.com/image/fetch/$s_!3chM!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2f7122e-8ffd-4ff9-8cea-fc0b91794481_1717x916.png 848w, /__u/substackcdn.com/image/fetch/$s_!3chM!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2f7122e-8ffd-4ff9-8cea-fc0b91794481_1717x916.png 1272w, /__u/substackcdn.com/image/fetch/$s_!3chM!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2f7122e-8ffd-4ff9-8cea-fc0b91794481_1717x916.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!3chM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2f7122e-8ffd-4ff9-8cea-fc0b91794481_1717x916.png" width="1456" height="777" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c2f7122e-8ffd-4ff9-8cea-fc0b91794481_1717x916.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:777,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1599877,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/205382419?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2f7122e-8ffd-4ff9-8cea-fc0b91794481_1717x916.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!3chM!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2f7122e-8ffd-4ff9-8cea-fc0b91794481_1717x916.png 424w, /__u/substackcdn.com/image/fetch/$s_!3chM!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2f7122e-8ffd-4ff9-8cea-fc0b91794481_1717x916.png 848w, /__u/substackcdn.com/image/fetch/$s_!3chM!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2f7122e-8ffd-4ff9-8cea-fc0b91794481_1717x916.png 1272w, /__u/substackcdn.com/image/fetch/$s_!3chM!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2f7122e-8ffd-4ff9-8cea-fc0b91794481_1717x916.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Take computation, which we can cast as circuits that break up the calculation work. I reviewed this model previously in discussion of <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">inherent performance bottlenecks for deep learning</a>. The key measurement limiting time to get the complete answer of a computation was <em>critical-path length</em>, or the length of the longest path through the diagram of a circuit. Interestingly, this length can be seen exactly as <em>communication delay</em> implied by the geometry and connectivity of a computation substrate. We&#8217;re just talking about communication across the regions of space that divide up the work of computation.</p><p>Perhaps less obvious is that performance of storage systems follows from essentially the same foundation. Software engineers are used to thinking about <a href="https://en.wikipedia.org/wiki/Memory_hierarchy">storage hierarchies</a>, where computer systems are broken into different kinds of storage, including fast storage with relatively low capacity (storing fewer bits), slow storage with relatively high capacity, and different intermediate points. We can just accept storage hierarchies with this kind of trade-off as part of the facts of life today. Alternatively, we can see that storage is just another way of arranging matter in space, such that elements of the matter tend to preserve certain changes to their state. The more bits we want to represent, the more matter we&#8217;ll need to arrange in space, and thus <em>the further-away some of those elements will be from each other</em>. So we see that longer delays to return answers follow naturally from higher storage capacity. For this reason, it is often a good idea to avoid one gigantic storage system in favor of smaller ones spread throughout space, intermixed with the computation that will consult them.</p><p>In summary, we can go very far thinking about the fundamental limits of performance by <em>considering only communication costs</em>, in systems of nodes arranged spatially.</p><h1>The Fiction of Flat Memory</h1><p>My own career path kept me relatively confined to the software side of things until relatively late. I came (implicitly) to think of the interface that a CPU exposes to software as the fundamental definition of what is possible. Then, early in my time as faculty, a collaboration pulled me into learning about how memory systems actually work, as we did an especially comprehensive kind of <a href="https://adam.chlipala.net/papers/BlueCAV15/">formal verification of such implementations</a> (and later work extracted out some of those ideas into <a href="https://adam.chlipala.net/papers/HemiolaCAV22/">a reusable implementation language</a>). Here I&#8217;m talking about <em><a href="https://en.wikipedia.org/wiki/Cache_coherence">cache-coherence protocols</a></em>, the canonical ways of implementing the fiction of memory as a flat sequence of numbered addresses, each accessible from every computation node. This abstraction is very far from fundamental, given the physical reality of computing, and it was eye-opening for me to see the complexity and computational cost that goes into providing it.</p><p>Let&#8217;s take a quick look at roughly how this kind of protocol works. We have the large and slow main memory at the top of a diagram, and we have individual CPU cores (our parallel compute nodes) at the bottom. In between are two additional levels of memory hierarchy. Each core has its own dedicated L1 (&#8220;level one&#8221;) cache, which stores memory addresses accessed recently by that core, keeping them accessible quickly. Groups of L1 caches share larger and slower L2 caches. The L2 caches finally connect to the main memory, through a directory that tracks the states of the different caches. Note that none of these ideas appear directly in <a href="/__u/stng.substack.com/p/the-expensive-fictions-of-low-level">low-level programming languages</a>, providing the root of their disadvantage for modeling and tuning performance.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!tNyS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173b135d-cbcf-44d0-92a0-193db43f0ea6_1792x878.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!tNyS!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173b135d-cbcf-44d0-92a0-193db43f0ea6_1792x878.png 424w, /__u/substackcdn.com/image/fetch/$s_!tNyS!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173b135d-cbcf-44d0-92a0-193db43f0ea6_1792x878.png 848w, /__u/substackcdn.com/image/fetch/$s_!tNyS!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173b135d-cbcf-44d0-92a0-193db43f0ea6_1792x878.png 1272w, /__u/substackcdn.com/image/fetch/$s_!tNyS!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173b135d-cbcf-44d0-92a0-193db43f0ea6_1792x878.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!tNyS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173b135d-cbcf-44d0-92a0-193db43f0ea6_1792x878.png" width="1456" height="713" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/173b135d-cbcf-44d0-92a0-193db43f0ea6_1792x878.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:713,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1615565,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/205382419?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173b135d-cbcf-44d0-92a0-193db43f0ea6_1792x878.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!tNyS!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173b135d-cbcf-44d0-92a0-193db43f0ea6_1792x878.png 424w, /__u/substackcdn.com/image/fetch/$s_!tNyS!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173b135d-cbcf-44d0-92a0-193db43f0ea6_1792x878.png 848w, /__u/substackcdn.com/image/fetch/$s_!tNyS!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173b135d-cbcf-44d0-92a0-193db43f0ea6_1792x878.png 1272w, /__u/substackcdn.com/image/fetch/$s_!tNyS!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173b135d-cbcf-44d0-92a0-193db43f0ea6_1792x878.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Protocol details won&#8217;t be too important for our main message. However, it is important to understand that different layers of the hierarchy can effectively <em><a href="https://en.wikipedia.org/wiki/Lock_(computer_science)">lock</a></em> (claim temporary exclusive ownership of) addresses, restricting the ability of other parts of the hierarchy to work with those addresses simultaneously. This diagram starts with the bottom-right CPU core holding a <em>write lock</em> on some address, meaning no other core is allowed to read or write that address, which saves the overhead of communicating with those other cores to coordinate accesses.</p><p>So now imagine what is an especially bad scenario for performance of this protocol. The bottom-right core took a write lock on some address, though now that core is done writing, but the system didn&#8217;t bother to release the lock. (After all, that core may return to writing the same address a millisecond later.) The bottom-left core, located furthest-away in space from the lock holder, wants to read the address. It has to route a message to the owning core through the whole hierarchy: up to the bottom-left L1, then to the L2 it connects to, to the directory, and then down a symmetrical path to the bottom-right L1. That L1 learns it has been asked to give up the lock and does so, and it also responds with the current value stored in the address. This response snakes back through the hierarchy, though now it moves in the reverse direction from the request.</p><p>We can see that quite a lot of communication has happened implicitly, which is trouble for giving programmers a performance model that is easy to reason about. Eyeballing this diagram as a literal spatial layout (which wouldn&#8217;t quite match any real CPU&#8217;s but is still illustrative), the total distance traversed by the path is roughly four times the actual physical distance between the two CPU cores involved &#8211; and the software code had no say in determining the path. There will be additional delay from the coordination logic that, as each signal is received, decides what further signals (and local state changes) to trigger based on it. As a storage system adds capacity, it often adds additional levels of hierarchy, which ironically can make worst-case communication delay worse, even as they may improve common cases.</p><p>The big point here is that important decisions highly relevant to communication overhead are entirely hidden from the programmer, who needs to apply a hardware model mentally to have a chance of predicting a program&#8217;s performance. <a href="/__u/stng.substack.com/p/the-expensive-fictions-of-low-level">Low-level languages</a> generally don&#8217;t include direct abstractions of placement and neighbor-to-neighbor communication, but we need those abstractions if we are to do a good job performance-engineering.</p><h1>Sequential Low-Level Code and Making CPUs Undo Translation Work</h1><p><a href="/__u/stng.substack.com/p/the-expensive-fictions-of-low-level">The last post</a> emphasized two design weaknesses of low-level programming languages: sequentialized code and shared memory. We just saw how shared memory is very involved to implement in hardware with good performance. Let me now explain why sequentialized code is also problematic, in a way that applies just as well to programming languages <a href="https://en.wikipedia.org/wiki/C_(programming_language)">C</a> and <a href="https://en.wikipedia.org/wiki/Rust_(programming_language)">Rust</a> as it does to <a href="https://en.wikipedia.org/wiki/Assembly_language">assembly</a> and <a href="https://en.wikipedia.org/wiki/Machine_code">machine languages</a>, the more direct bridges between software and CPUs.</p><p>Here&#8217;s a quick summary before we go into more detail. The laws of physics let us compute only with computation graphs arranged in space, with cost based on accumulated communication distances. <em>Sequential programs are very far from this physical reality, yet we need to translate them into reality to run them.</em> Good translation requires effective analysis of programs, which consumes computational resources if we perform it on-the-fly, as CPUs do. In fact, automated program understanding is so difficult that even the expensive translation in CPUs frequently makes (conservative) mistakes that hurt performance. Sometimes CPUs even make mistakes that create security problems.</p><p>OK, now back to more specifics. A CPU program is a sequence of instructions, which store intermediate state in <a href="https://en.wikipedia.org/wiki/Processor_register">registers</a>, essentially parts of a core-local memory that is especially small but also especially fast; plus the shared, flat memory. Literally running such a program one-instruction-at-a-time can be punishingly slow, so the CPU makes an effort to extract latent parallelism and run many instructions at once, which corresponds to mapping parts of programs onto available computation graphs in space. We discussed before how <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">long sequential dependency chains in computations create fundamental bottlenecks</a>, so the CPU is motivated to notice which dependencies actually exist. Actually, it can overapproximate the dependencies and be sure to respect any dependency that it <em>suspects</em> may exist.</p><p>The trouble is that dependencies are indicated through the two types of state I mentioned, and they are both tricky to model.</p><ol><li><p>Dependencies through <em>registers</em> are complicated by the fact that there are relatively few registers, which are fast but expensive to fabricate. Therefore, one register will often be reused for many different purposes throughout a computation, creating the potential for confusion. What appears to be a dependency may be an illusion, involving a register in two different lifecycle phases, serving different purposes. The extra work that a CPU does to extricate these false dependencies is <a href="https://en.wikipedia.org/wiki/Register_renaming">register renaming</a>.</p></li><li><p>Dependencies through <em>memory</em> are complicated by the fact that a given instruction may access an address computed by a complicated formula. Given two address formulas found in two parts of a program, it can be very challenging to decide if they might actually indicate the same address &#8211; and that analysis may even <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">not be computable</a>. As a result, CPUs are often very conservative about ruling out dependencies through memory.</p></li></ol><p>Yet CPUs do a lot of work to best-effort approximate such dependency information. It is important to recognize that, alongside the &#8220;real work&#8221; of running a program, we constantly pay for <em>the CPU to analyze a program as it runs to approximate its dependency structure</em>. The CPU is repeatedly reconfiguring a physical graph of compute and storage nodes to stand for different parts of a program, minimizing the total communication distances that we focus on in this post. One trick is <em><a href="https://en.wikipedia.org/wiki/Pipeline_(computing)">pipelining</a></em>, where one instruction is broken up into several steps, which may reveal additional parallelism. Different steps of all of a large bag of instructions may be run simultaneously, so long as dependencies are respected.</p><p>The other big snag that arises in this delicate choreography is that sometimes the CPU is not even sure which instructions will be running in the near-term future, <em>so it makes a best guess and prepares itself to undo work whenever a guess turns out to be wrong</em>. This performance optimization can have nasty consequences, as the world learned through the <a href="https://en.wikipedia.org/wiki/Spectre_(security_vulnerability)">Spectre</a> and <a href="https://en.wikipedia.org/wiki/Meltdown_(security_vulnerability)">Meltdown</a> attacks in 2018, which took advantage of the fact that CPUs don&#8217;t undo bad guesses completely enough to erase information (say, in L2 caches) that can later be used to leak program secrets. (See <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">some past discussion here</a> of effective reasoning about this risk from a software perspective.)</p><p>The irony of the situation is captured by this cartoon.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!bvvb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8917ea-9944-4903-9685-b60203833a72_1693x929.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!bvvb!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8917ea-9944-4903-9685-b60203833a72_1693x929.png 424w, /__u/substackcdn.com/image/fetch/$s_!bvvb!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8917ea-9944-4903-9685-b60203833a72_1693x929.png 848w, /__u/substackcdn.com/image/fetch/$s_!bvvb!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8917ea-9944-4903-9685-b60203833a72_1693x929.png 1272w, /__u/substackcdn.com/image/fetch/$s_!bvvb!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8917ea-9944-4903-9685-b60203833a72_1693x929.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!bvvb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8917ea-9944-4903-9685-b60203833a72_1693x929.png" width="1456" height="799" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0a8917ea-9944-4903-9685-b60203833a72_1693x929.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:799,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2134303,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/205382419?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8917ea-9944-4903-9685-b60203833a72_1693x929.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!bvvb!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8917ea-9944-4903-9685-b60203833a72_1693x929.png 424w, /__u/substackcdn.com/image/fetch/$s_!bvvb!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8917ea-9944-4903-9685-b60203833a72_1693x929.png 848w, /__u/substackcdn.com/image/fetch/$s_!bvvb!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8917ea-9944-4903-9685-b60203833a72_1693x929.png 1272w, /__u/substackcdn.com/image/fetch/$s_!bvvb!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8917ea-9944-4903-9685-b60203833a72_1693x929.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The CPU is reconstructing the information that often was already in the programmer&#8217;s head and maybe even written out directly in a program! Most clearly, if the original program was written out as a nice dataflow graph, then it is much easier for a CPU or anyone else to understand dependency structure. Yet we habitually use programming tools that translate nice high-level code into sequential, memory-access-heavy code that CPUs interpret natively, making bad decisions thanks to approximation <em>and</em> imposing run-time costs for the analysis that drives those decisions. Sometimes relevant analysis is much easier when performed with concrete values that appear at runtime (e.g. we may know when two formulas for computing memory addresses did or didn&#8217;t evaluate to equal values), but where ahead-of-time reasoning is possible, it can pay off significantly in alternative architectures.</p><h1>Up Next</h1><p>Some of these gripes can be addressed by smaller changes to existing low-level code formats. One I like is <a href="https://dl.acm.org/doi/10.1145/3471621.3471857">BasicBlocker</a>, which uses <a href="https://en.wikipedia.org/wiki/Compiler">compiler</a> support to leave enough hints for CPUs that they don&#8217;t need to guess about where programs are headed. However, we should be able to reap bigger gains by making larger changes to standard abstractions.</p><p>So let&#8217;s think about what those changes should be. The next post will propose one principle for joint design of software and hardware abstractions: that each side should move closer to where the other has historically been, with more hardware-style software and more software-style hardware. We&#8217;ll discuss historical reasons why the community hasn&#8217;t moved as much in that direction as this post&#8217;s analysis may suggest it should. Not coincidentally, AI-champion <a href="https://en.wikipedia.org/wiki/Graphics_processing_unit">GPUs</a> already incorporate some of the principles we&#8217;ll cover, though we will discuss how they are less-suited to <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a> and related ingredients that will help us trust programs and automate programming more effectively.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Expensive Fictions of Low-Level Programming Languages]]></title><description><![CDATA[AI coding tools are facing a major handicap in using popular languages.]]></description><link>https://stng.substack.com/p/the-expensive-fictions-of-low-level</link><guid isPermaLink="false">https://stng.substack.com/p/the-expensive-fictions-of-low-level</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 30 Jun 2026 12:35:36 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/31bd13ed-eb0d-437b-aeb6-28831bd0d1e4_614x270.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;ve been telling parts of the story of a future with trustworthy search processes that automate software development. If we have a clear and specific-enough formal specification to start out with, then <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">recursive self-improvement</a> can proceed in a way guaranteed to align with our goals. I talked through a number of reasons for optimism on that front, including lessons from recent use of <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a> (for <a href="/__u/stng.substack.com/p/simplifying-alignment-by-expanding">connecting verified pieces together</a> and <a href="/__u/stng.substack.com/p/subversion-resistance-for-free-from">anticipating new security threats</a>) and speculating about changes in <a href="/__u/stng.substack.com/p/abstraction-boundaries-and-bubbles">an economy dominated by AI agents</a> (simplifying <a href="/__u/stng.substack.com/p/simpler-user-interfaces-in-an-ai">user interfaces</a> and <a href="/__u/stng.substack.com/p/why-software-requirements-get-easier">requirements gathering</a>). The first point of informed skepticism about this idea is usually about the challenge of writing such specifications. There are still plenty of challenges left in assembling good specifications for highly capable systems, but let me now turn to further challenges, which apply after specifications are written.</p><p>Let&#8217;s consider in general the problem of <a href="https://en.wikipedia.org/wiki/Program_synthesis">automatic generation of code from its specification</a>. Many <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">AI coding assistants</a> are being used today to write code in a &#8220;best effort&#8221; way, where the result may include mistakes such that the generated program does not follow its specification. I&#8217;m most interested (and future posts will most commonly discuss) methods that are <em>correct by construction</em>, where a tool might give up but will never return an incorrect program. An especially interesting approach is structured search through the space of programs, <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">using formal verification as a fitness function</a> to evaluate intermediate and final program variants.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Regardless of what approach is taken to automatic programming, we face conflicting desires to, on the one hand, <em>simplify the space of programs and how we reason about it automatically</em>; and, on the other hand, <em>generate the highest-quality programs in the end</em>. The rub is that higher-quality programs may be longer and more complicated than their lower-quality cousins, requiring more expensive search to find. An important determinant of the effectiveness of search is choice of programming language(s). My main claim in this post is that widely used programming languages are poorly suited for this style of search, especially when we are trying to write high-performance programs &#8211; which will be the case when we think about a program-search system recursively improving itself, given how much time and space a complex search can take. To argue this claim, I will start by spelling out a general framework for program search, and then I&#8217;ll draw attention to a missing ecological niche within that framework that is underserved by widely used programming languages.</p><h1>Searching the Space of Programs</h1><p>Let me describe at a very high level a process of gradually refining a specification into a final program. Arguably, human software engineers work in this way, and we can expect to rely increasingly on programs that automate the process. There is a tradition in computer science that makes the ideas formal, called <a href="https://en.wikipedia.org/wiki/Bottom-up_and_top-down_approaches">derivation by stepwise refinement</a>, but I&#8217;ll leave things largely informal here. We can think of the exploration as moving from the top of the following schematic depiction to the bottom.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!IZcg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7429bdf-5706-434f-8a27-aa7b72fd03fd_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!IZcg!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7429bdf-5706-434f-8a27-aa7b72fd03fd_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!IZcg!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7429bdf-5706-434f-8a27-aa7b72fd03fd_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!IZcg!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7429bdf-5706-434f-8a27-aa7b72fd03fd_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!IZcg!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7429bdf-5706-434f-8a27-aa7b72fd03fd_1672x941.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!IZcg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7429bdf-5706-434f-8a27-aa7b72fd03fd_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a7429bdf-5706-434f-8a27-aa7b72fd03fd_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3002987,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/204212253?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7429bdf-5706-434f-8a27-aa7b72fd03fd_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!IZcg!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7429bdf-5706-434f-8a27-aa7b72fd03fd_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!IZcg!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7429bdf-5706-434f-8a27-aa7b72fd03fd_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!IZcg!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7429bdf-5706-434f-8a27-aa7b72fd03fd_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!IZcg!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7429bdf-5706-434f-8a27-aa7b72fd03fd_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The highest levels of the diagram deal with relatively abstract notation and therefore allow the most functionality to be covered by the shortest descriptions. The lowest levels are closer to the computer hardware we plan to run on, and they require details to be spelled out in excruciating detail.</p><p>Every node of this search is a program in some programming language. Every language we choose should pay off in tractability of search, control over details of the final program, or both. The most straightforward model is that we start off choosing languages biased toward simplifying search and eventually transition to languages that provide low-level control, though mixing the benefits throughout is also fine. Regardless, it should be a red flag if we are ever working with a language that scores poorly on both axes&#8230; yet I will claim that today, AI code generation is overwhelmingly working with such languages.</p><h1>Low-Level Programming Languages</h1><p>Let&#8217;s think in particular about languages suitable for the lower levels of the search process. A very dedicated software engineer might work directly with <a href="https://en.wikipedia.org/wiki/Assembly_language">assembly language</a>, almost the lowest-level form of programming undertaken today. However, it would be much more common to bottom out at a programming language like <a href="https://en.wikipedia.org/wiki/C_(programming_language)">C</a>, which was invented in the 1970s and has overwhelmingly influenced the design of low-level languages. More precisely, such languages are meant to allow fine-grained control over how a program uses available hardware resources and achieves the best performance.</p><p>There has been a lot of great innovation recently in this space of programming languages. Probably the biggest success story is <a href="https://en.wikipedia.org/wiki/Rust_(programming_language)">the Rust language</a>, which adds formal verification-style checking that programs follow safety rules. In contrast, C has been notorious for how easy it is for programmers to introduce mistakes that compromise safety and security. These safety rules don&#8217;t guarantee that a program does exactly what we want it to do, but formal-verification tools like <a href="https://github.com/verus-lang/verus">Verus</a> and <a href="https://github.com/viperproject/prusti-dev">Prusti</a> add that kind of checking. As a formal-methods zealot myself, I won&#8217;t be satisified until some such verification method is considered to be part of the language definition, and programs that fail verification are considered ill-formed. However, for the rest of this post, I want to focus on a different axis of language design.</p><p>The problem is that languages in this category are meant to give fine-grained and effective control of performance. I would argue that higher-level languages are almost uniformly more pleasant to use to implement programs where performance doesn&#8217;t matter; we only choose a language like C or Rust to let us tune performance. <a href="https://en.wikipedia.org/wiki/Lisp_machine">Lisp machines</a> provided a lovely stack for developing all code in a unified high-level language, and they &#8220;only&#8221; were missing performance capabilities, to keep up with other trends in hardware! The problem is that C was designed for the hardware of the 1970s and hasn&#8217;t been updated for the directions the computing world is heading in, with the end of <a href="https://en.wikipedia.org/wiki/Moore%27s_law">Moore&#8217;s law</a> forcing more cleverness in how we arrange computation. Thus, this language family is designed to fit snugly against the hardware model <em>of the 1970s</em> but fails to expose the affordances needed to get good scalable performance today. C, Rust, and friends are <em>too low-level</em> to be programmer-friendly high-level languages, and they are also <em>too high-level</em> to expose the true toolbox of performance optimization. (If we are stuck with particular fixed hardware, then C and Rust may give programmers just about all the performance knobs they have available, but we should think bigger and <a href="/__u/stng.substack.com/p/hardware-software-codesign-and-autonomous">codesign</a> new hardware with its programming tools.)</p><h1>Distance and Communication</h1><p>Computer hardware has always mediated between the physical world and nice abstractions for programming, but that kind of &#8220;magic&#8221; mediation layer has had trouble scaling. The reality is that computation takes place in three-dimensional space, but let&#8217;s simplify down to two-dimensional space for purposes of this blog post (even though <a href="https://en.wikipedia.org/wiki/Three-dimensional_integrated_circuit">three-dimensional chip technologies</a> are gaining in popularity). Then we have a sea of nodes spread through space, and let&#8217;s say each node stands for computation or storage.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!lw3B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c4f4ff6-f27d-4619-af34-f973c41a5073_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!lw3B!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c4f4ff6-f27d-4619-af34-f973c41a5073_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!lw3B!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c4f4ff6-f27d-4619-af34-f973c41a5073_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!lw3B!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c4f4ff6-f27d-4619-af34-f973c41a5073_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!lw3B!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c4f4ff6-f27d-4619-af34-f973c41a5073_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!lw3B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c4f4ff6-f27d-4619-af34-f973c41a5073_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9c4f4ff6-f27d-4619-af34-f973c41a5073_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2345105,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/204212253?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c4f4ff6-f27d-4619-af34-f973c41a5073_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!lw3B!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c4f4ff6-f27d-4619-af34-f973c41a5073_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!lw3B!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c4f4ff6-f27d-4619-af34-f973c41a5073_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!lw3B!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c4f4ff6-f27d-4619-af34-f973c41a5073_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!lw3B!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c4f4ff6-f27d-4619-af34-f973c41a5073_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Some pairs of nodes are connected by wires, and typically signals only propagate along those wires. (<a href="https://en.wikipedia.org/wiki/Wireless_network">Wireless communication</a> creates enough overhead to make it infeasible at the scale we&#8217;re talking about here.) Because there is a manufacturing cost per wire, relatively few of the potential direct connections between nodes are built out. As a result, the fastest path between two nodes may take a rather-indirect route, as opposed to the most direct geometric path down the middle of the picture. However, that direct path establishes a kind of fundamental speed limit for communication between a node pair, often called the &#8220;speed-of-light limit&#8221; when we assume a signal propagates at the maximum possible speed.</p><p>I discussed a simplified version of this kind of system earlier in the context of <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">fundamental performance limitations of deep learning</a>. There the point was that a deep-learning system can be seen as a computation graph (system of nodes and edges between them), with edges representing input-output relationships. Computing the final answer requires computing the values of all nodes, which will take <em>at least as long as the longest path that exists in the graph</em>, an important measure called <em>critical-path length</em>. As systems scale, the communication overhead of propagating signals along wires often comes to dominate total execution time, and <strong>the major flaw in C, Rust, and their relatives is that the programming model hides these communication overheads and the aspects of program structure that make them tractable to predict and control</strong>.</p><p>Conventional low-level programming lives in a fantasy world that deviates from reality in two major ways. These big two were also presented in Chisnall&#8217;s <a href="https://queue.acm.org/detail.cfm?id=3212479">&#8220;C Is Not a Low-level Language&#8221;</a>, and the additional point that I&#8217;m emphasizing is that these fantasies make it harder to evaluate the performance of a program, which makes effective program search harder.</p><ol><li><p><em>We pretend code looks like sequences of instructions that run one-at-a-time.</em> In reality, all parts of a physical computation fabric are always &#8220;running.&#8221; Hardware like CPUs tries hard to promote <em>utilization</em>, the fraction of nodes doing useful work at some instant, but it can only go so far, reverse-engineering the structure of fundamentally <em>sequential</em> code even when the related behavioral questions are <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">undecidable</a>.</p></li><li><p><em>We pretend that there is one big shared memory that all parts of a program access.</em> Yes, this abstraction is painstakingly constructed by hardware, but we can&#8217;t think of it with a naive <em>cost model</em>. The time to access a memory location at a particular computation node can <a href="https://en.wikipedia.org/wiki/Non-uniform_memory_access">vary dramatically</a> based on a variety of factors, and the same node can experience very different access times for the same memory location at different moments. The principles behind predicting these performance factors come down to tracking <a href="https://en.wikipedia.org/wiki/Locality_of_reference">locality of memory references</a>, a concept that unfortunately often requires <em>global</em> thinking, meaning understanding the performance of one part of a system can require tracking behavior of other parts in detail. Alternatively, we can use established abstractions like <a href="https://en.wikipedia.org/wiki/Message_Passing_Interface">MPI</a> that reveal the hardware topology more directly, but these systems are also seen as painfully low-level and difficult to program.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!IDTG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca80cc-a360-49ea-a7f8-7037da3367b2_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!IDTG!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca80cc-a360-49ea-a7f8-7037da3367b2_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!IDTG!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca80cc-a360-49ea-a7f8-7037da3367b2_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!IDTG!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca80cc-a360-49ea-a7f8-7037da3367b2_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!IDTG!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca80cc-a360-49ea-a7f8-7037da3367b2_1672x941.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!IDTG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca80cc-a360-49ea-a7f8-7037da3367b2_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1ca80cc-a360-49ea-a7f8-7037da3367b2_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2175181,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/204212253?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca80cc-a360-49ea-a7f8-7037da3367b2_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!IDTG!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca80cc-a360-49ea-a7f8-7037da3367b2_1672x941.png 424w, /__u/substackcdn.com/image/fetch/$s_!IDTG!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca80cc-a360-49ea-a7f8-7037da3367b2_1672x941.png 848w, /__u/substackcdn.com/image/fetch/$s_!IDTG!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca80cc-a360-49ea-a7f8-7037da3367b2_1672x941.png 1272w, /__u/substackcdn.com/image/fetch/$s_!IDTG!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca80cc-a360-49ea-a7f8-7037da3367b2_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>An abstraction of sequential code execution is helpful for puny human brains to keep up in understanding a program, but it&#8217;s just too far from reality to be ideal for analyzing scalable performance. Low-level programming languages have usually started from sequential programming features and provided bolt-on features to explain how several such programs should run at once. The inability of language implementations to understand what is happening within the units of parallelism makes it harder to perform significant code rearrangements automatically as optimizations.</p><p>The most elite performance engineers can keep the organizations of specific hardware platforms in mind, to look at conventional software programs and &#8220;see&#8221; what they will cost to run. However, the details are punitively complex, which holds back automatic search through program variants to find the ones with the best performance. Importantly, this level of performance modeling seems to require thinking about programs at a very low level of abstraction that hides very little about hardware organization. At that level of abstraction, even simple-sounding improvements can require changes to many lines of code, perhaps spread across a large code base, and many search heuristics can never pull off that level of synchronized modification. (An example of such a nonlocal modification is dropping in a new data structure that requires a new coordination protocol for shared-memory accesses by all parts of the code touching the data structure.)</p><h1>Conclusion</h1><p>Whether we are thinking about human software engineers designing and implementing a program or about AI search through a space of programs realizing a specification, two properties are especially helpful in the notations we use to represent programs under consideration. Some notations allow us to describe complex systems succinctly, and those notations are convenient to understand and manipulate algebraically. Some notations give us the control to describe every last detail of harnessing hardware for maximum performance. The trouble with mainstream programming languages like C and Rust is that they display major shortcomings with respect to both goals. Even partisans of those languages typically agree that programming simplicity is sacrificed for control, making automated understanding of programs and their behavior (performance-wise or otherwise) formally impossible, though additional structural disciplines like Rust&#8217;s can help. But then the performance model of code is only implicit, given the massive gap between the realities of hardware and the fictions of parts of a program running sequential code and accessing a shared global memory.</p><p>There are enough parts of this argument and its evidence and consequences that I&#8217;ll continue over the next three posts. First, I&#8217;ll explain the heroic effort of modern CPUs to present the C-style programming abstraction while exhibiting very opaque performance behavior. Next, I&#8217;ll suggest a convergence between the programming styles of software and hardware as a unifying principle to chart a better course. Finally, I&#8217;ll cover <a href="https://en.wikipedia.org/wiki/Graphics_processing_unit">GPUs</a> as an example of an approach that has evolved closer to this ideal but retains some real weaknesses relevant to creating <a href="/__u/stng.substack.com/p/designing-decision-making-systems">trustworthy decision systems</a>, the overarching topic of this blog. Setting the stage with these details will prepare us for more exploration of our overall slogan that &#8220;<a href="/__u/stng.substack.com/p/intelligence-depends-on-organizing">intelligence depends on organizing computation correctly and efficiently</a>.&#8221;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Why Software Requirements Get Easier in an AI Economy]]></title><description><![CDATA[Abstraction boundaries pay off]]></description><link>https://stng.substack.com/p/why-software-requirements-get-easier</link><guid isPermaLink="false">https://stng.substack.com/p/why-software-requirements-get-easier</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 23 Jun 2026 13:21:51 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4013a5f7-8643-41cd-8907-0bfbf2825170_626x388.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>One of the best protections, in principle, against AI systems going off the rails during <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">recursive self-improvement</a> is <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a>, where we prove mathematically that systems meet formal requirements. A natural obstacle is being sure to write out in enough detail what rules we want to enforce, such descriptions being called <em>specifications</em>. An increasing role for AI in the economy can, on the one hand, increase the number of computer systems for which careful enforcement of rules is critical. However, there is a sense, perhaps ironic, in which the job of spelling out the right rules, of writing good formal specifications, becomes <em>easier</em>. I have made the case that, as AI proliferates, it makes sense to design the economy to include <a href="/__u/stng.substack.com/p/abstraction-boundaries-and-bubbles">bubbles where AI interacts only with other AI</a>, and I sketched how <a href="/__u/stng.substack.com/p/simpler-user-interfaces-in-an-ai">specifying user interfaces then becomes easier</a>.</p><p>I will now make the case that the broader challenge of settling on system requirements also becomes fundamentally easier. The basic advantage comes from whose intentions need to be formalized in the requirements. Getting requirements out of squishy humans can be arbitrarily challenging, but what happens when the source of new requirements is overwhelmingly other programs already in production?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>The Hard Part of Software Engineering</h1><p>Even before <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">AI coding assistants</a> changed a software engineer&#8217;s mix of time spent on different activities, it was a truism in the field that the overwhelmingly time-consuming activity was <em>understanding what users really want</em>, or requirements-gathering. With recent automation of so much of routine coding, we might expect that the centrality of requirements-gathering will only increase. I want to suggest that, leaning even more into what will be possible with automation, we will ironically see requirements-gathering as we know it <em>decrease</em> in importance. To make that case, I should first review the conventional wisdom.</p><p>When programmable computers were first developed, the details of who did what to get them programmed were no doubt a little chaotic. Soon enough, though, around the 1960s, a split developed between <a href="https://en.wikipedia.org/wiki/Systems_analyst">analysts</a> and programmers. The former had the job of understanding requirements and translating them into relatively unambiguous notation like <a href="https://en.wikipedia.org/wiki/Flowchart">flowcharts</a>, which programmers could then translate into code. My own formal programming education involved just the slightest brush with flowcharting before that trend fully evaporated, but, in the course of a summer internship, I do remember being advised by a long-time technical employee of a large corporation that &#8220;programmer&#8221; was a poor choice of career path, representing a kind of cognitive underclass taking orders from analysts. (Perhaps developments in AI coding assistance make that advice more prescient than I realized at the time!)</p><p>The discipline of software engineering developed orthodoxies like the <a href="https://en.wikipedia.org/wiki/Waterfall_model">waterfall model</a>, where teams are very careful to go through many iterations of written requirements before beginning the expensive process of programming. Writing the requirements is not just a process internal to a team of software specialists. Arguably most important is interfacing with the intended users of a program, to understand fully what functionality will satisfy them. One conversation is rarely enough. Instead, the intended users must be shown repeated revisions of a requirements document, to help them think more abstractly about the full range of relevant scenarios.</p><p>Eventually, waterfall went out of style in favor of <a href="https://en.wikipedia.org/wiki/Agile_software_development">agile</a> methods, which focus on getting to working programs more quickly, so that users can give more-informed feedback. The problem is that even the software experts find it hard to enumerate all relevant scenarios for a complex program. Many scenarios only become clear as critical by relying on the expertise of the users, yet those users are not trained in the kind of abstract and systematic thinking needed to map out all relevant usage flows, with their steps and subtleties. Eliciting such information to guide a product roadmap remains so challenging today as to motivate the specialty of <a href="https://en.wikipedia.org/wiki/Product_management">product management</a>.</p><p>The challenge of learning what solution is <em>really</em> best for users is often explained using a quote attributed (perhaps apocryphally) to <a href="https://en.wikipedia.org/wiki/Henry_Ford">Henry Ford</a>, about how if he had asked his customer base what they wanted in transportation, they would have asked for faster horses, not the cars that he eventually gave them. There are at least two separate problems. First, a user with a vague idea of the fundamental purpose of a piece of software may have trouble explaining that purpose in enough detail. Second, a user without an understanding of software-development pragmatics may not understand what is feasible to build at what cost.</p><p>The good news is that these challenges should diminish dramatically when the users asking for functionality frequently aren&#8217;t human. More precisely, the old kind of requirements-gathering challenges remain, perhaps even in a more challenging form, for a minority of the parts of an agent ecosystem, while this activity can largely be avoided for the remaining parts.</p><h1>Software as a More Knowable User</h1><p>There is a fundamental reason why it is easier to know what a program &#8220;wants&#8221; than what a person wants. Our evolutionary journey hasn&#8217;t placed much selection pressure on human minds to be easy to model by others. In fact, aspects like <a href="/__u/stng.substack.com/p/signaling-is-programmable-evolution">signaling</a> have even promoted opacity of our thought processes, say to make it harder for others to figure out what will impress us, so that we can believe that the ones who <em>do</em> succeed at impressing us are unusually competent and worthy of affiliating with. In contrast, a program needs to be explainable to at least one audience: the computer that runs it! That is, the computer needs to have a clear-enough sense of the program meaning to be able to run the program, which we can phrase more technically as a need for programs to have unambiguous semantics. Add on top the need (at least until quite recently) for humans to understand the program as they are writing and maintaining it. There has been plenty of selection pressure for programs to be understandable, which can now pay off in their ability to request writing of new code to help them do their jobs better.</p><p>The ultimate setting for this advantage to shine is where <a href="/__u/stng.substack.com/p/abstraction-boundaries-and-bubbles">significant pockets of the economy</a> include only AI interacting with more AI, rather than with humans. Such a setting can maximize the benefit of environments <a href="/__u/stng.substack.com/p/codesign-for-legibility-to-ai-and">designed for legibility to automated reasoning</a>. An ecosystem of automated work can <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">recursively self-improve</a> toward a specification set in advance, or <a href="/__u/stng.substack.com/p/proof-carrying-code-in-the-matrix">a set of competing and cooperating agents</a> can evolve together toward their own specifications. Either way, we have an easily machine-readable characterization of fundamental goals, which can periodically be projected into requirements for new programs.</p><p>The next drawing illustrates the principle more visually. The left panel shows the world more as it is today, including many AI agents, almost all of which have to coordinate directly with humans, forcing the gathering of requirements from stakeholders who aren&#8217;t great at explaining what they want. The right panel shows the world we may be headed toward, where most of the economy is handled by AI agents, who naturally form into clusters with only rare gatekeepers who need to interface with humans. The interiors of the clusters are places of order and clear requirements. In this world, the great majority of programs are interior and benefit from clear sources of requirements.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!xLZn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f444dd-4cdd-4363-9446-6f8cefcad216_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!xLZn!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f444dd-4cdd-4363-9446-6f8cefcad216_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!xLZn!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f444dd-4cdd-4363-9446-6f8cefcad216_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!xLZn!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f444dd-4cdd-4363-9446-6f8cefcad216_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!xLZn!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f444dd-4cdd-4363-9446-6f8cefcad216_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!xLZn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f444dd-4cdd-4363-9446-6f8cefcad216_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b8f444dd-4cdd-4363-9446-6f8cefcad216_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2551797,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/202882129?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f444dd-4cdd-4363-9446-6f8cefcad216_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!xLZn!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f444dd-4cdd-4363-9446-6f8cefcad216_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!xLZn!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f444dd-4cdd-4363-9446-6f8cefcad216_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!xLZn!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f444dd-4cdd-4363-9446-6f8cefcad216_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!xLZn!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8f444dd-4cdd-4363-9446-6f8cefcad216_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It is critical that we will not be coming along later and trying to characterize the behavior and desires of agent ecosystems. There is the potential now to weave formal specification and verification into their design from early days. Our challenge becomes writing a specification <em>covering the whole AI ecosystem</em>, forcing the inhabitants to evolve in ways compatible with our goals and values. This requirements-gathering challenge remains at least as hard as usual! My point is that many other engineering projects <em>within</em> such AI bubbles become easier to frame, and they should become the majority of ongoing software-engineering effort (and source of associated cost).</p><p>A more modest version of this phenomenon is already common today. Take the example of a software-engineering team implementing a new web browser. Existing technical standards significantly constrain the new design. There are already voluminous requirements written down in Internet standards, explaining how the code for a web page corresponds to what should be displayed to the user. As more of the economy is handled by AI agents, more of their contexts will be standardized similarly or at least embodied in existing code that could be analyzed.</p><p>It is worth noting here that the most popular kind of AI software today, <a href="/__u/stng.substack.com/p/deep-learning-the-ultimate-search">deep learning</a>, has the distinct disadvantage that individual programs (now construed to include learned elements like model weights) have little apparent structure and thus are difficult to understand, say to figure out &#8220;what they want.&#8221; I would argue this quality should push us toward more use of other methods <a href="/__u/stng.substack.com/p/designing-decision-making-systems">designed for understandability</a> and ability to bound their behavior precisely with mathematical arguments, though my broader argument remains relevant otherwise. Put another way, we may have a short window to decide if we want to live in a world of inscrutable learned systems or instead push for systems proved to meet explicit requirements. It may be that the second path is critical not just for safety against rogue AIs but also for the efficiency of AI self-improvement that it enables, even if the ultimate goal happens to be better targeting of online ads. Let me now explain the source of that efficiency.</p><h1>Copying Parts of Your Own Specification and Code is Relatively Easy</h1><p>Let&#8217;s get a bit more specific about how the earliest stages of software engineering get cheaper, as we get programs asking for the writing of new programs.</p><p>Assume first that the user programs have been written following good practices and have their own polished requirements documents. We can even look to the most general version of an argument, assuming that <em>the programs that will ask for new programs have their own requirements written out to the standards of quality desired for the new programs</em>. The glib explanation of the advantage, then, is that we can just copy relevant bits of requirements content out of the requirements for the users requesting the new programs. No such option is straightforward for human users, who tend not to publish their life goals comprehensively in machine-readable form.</p><p>Consider more broadly how it should happen that programs want to see new programs written. I have suggested that we see an economy engaged in technical innovation as a <a href="/__u/stng.substack.com/p/our-social-world-as-a-distributed">distributed system in the computer-science sense</a>, with different agents cooperating and competing within a set of overlapping optimization problems. Different participants know at different levels of detail what they are trying to accomplish; the participants that are software should be especially likely to be associated with rigorous formal specifications (or at least, that honor is unlikely for the people!). At some level, such an economic system is a program engaged in repeatedly optimizing itself.</p><p>Let&#8217;s get more specific with an example where a self-improving program naturally persists some of its own code into an improved variant. The relatively straightforward case is a program for computing a particular mathematical function <em>and for noticing ways to improve its own structure to compute that function more efficiently</em>. I&#8217;m arguing that software-engineering projects spinning up in the future will look more like this kind of self-optimization than like what we&#8217;re used to. A program with a goal but only a relatively fuzzy idea of how to achieve it will ask for new programs to be written that aim at the same goal but with more specific strategy. A good if fairly technical analogy is to <a href="https://en.wikipedia.org/wiki/Multi-stage_programming">multi-stage programming</a>, which I&#8217;ll explain by example (though most of the code details aren&#8217;t critical to follow). Here is a (recursive) Python function that raises number <code>x</code> to the power of <code>n</code>.</p><pre><code><code>def power(x, n):
    if n == 0:
        return 1
    elif n % 2 == 0:
        y = power(x, n // 2)
        return y * y
    else:
        return x * power(x, n - 1)</code></code></pre><p>Imagine that an AI agent uses this function frequently for exponentiation tasks. In fact, it notices that half of the uses have <code>n</code> of 13. Through a mechanical process known as <a href="https://en.wikipedia.org/wiki/Partial_evaluation">partial evaluation</a>, it produces this specialized version.</p><pre><code><code>def power13(x):
    x2 = x * x
    x3 = x * x2
    x6 = x3 * x3
    x12 = x6 * x6
    x13 = x * x12
    return x13</code></code></pre><p>We had one stage of computation to come up with this code, and now we can run the new code repeatedly in a later stage, hence the name &#8220;multi-stage programming.&#8221; The new <code>power13</code> function can run more quickly than <code>power</code> (it doesn&#8217;t need to run all of those tests about arithmetic properties of the exponent; it doesn&#8217;t need to do bookkeeping about how a group of function calls relate to each other). Part of what we give up to gain that speed is the generality of the function, but we can imagine we keep around the old version, too. We still use up extra storage for specialized versions, and we still spent time to come up with them. The same tradeoffs apply to <a href="https://en.wikipedia.org/wiki/Just-in-time_compilation">just-in-time compilation</a> as practiced by web browsers for efficient execution of the code embedded in web pages.</p><p>My claim, now more technical, is that these examples from mainstream computing today are more representative of the future of software development than are classic software-engineering projects. Yes, new projects will still be started to build software with human users, in which case the classic problems and methods remain relevant. However, for efficiency reasons, more and more of the economy will be handled by AI agents with no direct connections to humans, only other AI agents. Agents and groups of agents will trigger new software development for the same reasons it paid off to specialize the <code>power</code> function above, but these projects will be relatively better-defined, with their specifications naturally derived, often in mechanical ways, from the specifications or at least code of the requesting agents.</p><p>The next image tries to illustrate the pattern, with an agent requesting a new program based on a subset of its own code or specification, plus a novel environmental stimulus that the code should now be specialized to.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!SUxj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c677625-ff7e-4626-92e9-943cd3535d83_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!SUxj!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c677625-ff7e-4626-92e9-943cd3535d83_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!SUxj!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c677625-ff7e-4626-92e9-943cd3535d83_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!SUxj!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c677625-ff7e-4626-92e9-943cd3535d83_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!SUxj!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c677625-ff7e-4626-92e9-943cd3535d83_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!SUxj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c677625-ff7e-4626-92e9-943cd3535d83_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0c677625-ff7e-4626-92e9-943cd3535d83_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2383591,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/202882129?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c677625-ff7e-4626-92e9-943cd3535d83_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!SUxj!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c677625-ff7e-4626-92e9-943cd3535d83_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!SUxj!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c677625-ff7e-4626-92e9-943cd3535d83_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!SUxj!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c677625-ff7e-4626-92e9-943cd3535d83_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!SUxj!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c677625-ff7e-4626-92e9-943cd3535d83_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Previous posts have involved similarly geeky analogies based on <a href="/__u/stng.substack.com/p/what-is-consciousness">interpreters</a>, programs that run programs in particular languages; and <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">compilers</a>, programs that translate programs between languages. At some level, an agent could operate indefinitely as an interpreter. It has some high-level mission with a lot of execution details to figure out, through some kind of search process, perhaps <a href="/__u/stng.substack.com/p/our-social-world-as-a-distributed">coordinating with others</a>. It can accumulate notes on wisdom gained so far, which are repeatedly consulted by code written to be prepared to act properly on whatever notes are passed to it. However, as the search proceeds, some parts of the code are revealed as irrelevant. Some are revealed to contain significant handling of uncommon or irrelevant cases. With a complex-enough initial program standing for everything that goes into doing a job somewhat like those done today by highly trained professionals, all sorts of software-engineering projects can be seen as specializations of that initial program. The possible scope is even wider as we imagine communities of agents coordinating to kick off software projects.</p><h1>Conclusion</h1><p>The argument I&#8217;ve spelled out here fills out a three-point recommendation or prediction for how we&#8217;ll take advantage of automated intelligence.</p><ol><li><p><a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">Formal verification is an invaluable tool for processes that search for better software</a>, allowing up-front confirmation that a program will behave as intended in a variety of circumstances. However, we need sufficiently precise specifications to make formal verification meaningful.</p></li><li><p>If we do manage to kick things off with precise and comprehensive specifications for computer systems, then the searches they coordinate for better software can naturally pass on that specification quality toward the development of the new programs.</p></li><li><p>With that kind of <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">recursive self-improvement loop</a> operating well, it pays off to find ways to <a href="/__u/stng.substack.com/p/abstraction-boundaries-and-bubbles">cloister units of economic activity away from sources of specification complexity</a>, allowing them to have simpler specifications that enable the search process to operate effectively.</p></li></ol><p>Such a loop depends critically on the efficiency of its implementation. The faster it runs, and the more it can do with a given amount of memory, the more effectively we can find better new strategies, which pays back recursively in the system&#8217;s ability to keep improving itself. That concern motivates thinking carefully about what software of the future should look like, as I&#8217;ll now cover in a series of posts about design of programming languages. I&#8217;ll make the case that the same principles that will aid autonomous systems also make sense for human programmers. I&#8217;ll also argue that languages like <a href="https://en.wikipedia.org/wiki/Rust_(programming_language)">Rust</a>, often held up as exemplars of the future of programming-language design, are not cut out for the performance scaling we&#8217;ll need for important applications.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Simpler User Interfaces in an AI Future]]></title><description><![CDATA[Why AI will have an easier time keeping itself happy]]></description><link>https://stng.substack.com/p/simpler-user-interfaces-in-an-ai</link><guid isPermaLink="false">https://stng.substack.com/p/simpler-user-interfaces-in-an-ai</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 16 Jun 2026 12:16:43 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/285f06d4-7325-441a-bf43-29465b271baf_504x279.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Simpler User Interfaces in an AI Future</h1><p>My last few posts have been reviewing ways that we should be optimistic about the potential to write good formal specifications for important software of the future, enabling <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a> and other ways to increase confidence in those systems. By doing the kind of serious formal verification that includes <a href="/__u/stng.substack.com/p/simplifying-alignment-by-expanding">reasoning about the interfaces between system components</a>, we often get <a href="/__u/stng.substack.com/p/subversion-resistance-for-free-from">additional cybersecurity benefits for free</a>. More speculatively, we are probably at the beginning of an accelerating curve for <a href="/__u/stng.substack.com/p/abstraction-boundaries-and-bubbles">reconfiguring our economy so that more of it involves AIs interacting directly with each other</a>, saving the related software from dealing with the complexities of modeling humans.</p><p>The upshot of that last trend is likely to be a dramatic complexity drop in the part of specification-writing that has dealt with user interfaces. I&#8217;ll present three ways in which it becomes easier to make rigorous arguments that these new software components make their &#8220;users&#8221; &#8220;happy.&#8221;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Signaling and Interface Trends</h1><p>Interfaces to computers have changed significantly over time. On the one hand, a significant part of the change has to do with genuine conceptual breakthroughs in how to design interfaces to promote user satisfaction. Some interface ideas depend on raw computational power, where it may have been clear to earlier designers what they <em>wished</em> they could show to users, but bringing those ideas to life had to wait for compute to scale. Probably most observers would have those factors in mind, thinking back along the history of user interfaces.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!qQrN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6096a3e7-202e-4642-b1a3-67788a397711_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!qQrN!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6096a3e7-202e-4642-b1a3-67788a397711_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!qQrN!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6096a3e7-202e-4642-b1a3-67788a397711_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!qQrN!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6096a3e7-202e-4642-b1a3-67788a397711_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!qQrN!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6096a3e7-202e-4642-b1a3-67788a397711_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!qQrN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6096a3e7-202e-4642-b1a3-67788a397711_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6096a3e7-202e-4642-b1a3-67788a397711_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3280631,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/202027625?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6096a3e7-202e-4642-b1a3-67788a397711_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!qQrN!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6096a3e7-202e-4642-b1a3-67788a397711_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!qQrN!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6096a3e7-202e-4642-b1a3-67788a397711_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!qQrN!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6096a3e7-202e-4642-b1a3-67788a397711_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!qQrN!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6096a3e7-202e-4642-b1a3-67788a397711_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This cartoon shows computer users wearing the kinds of clothing associated with their time periods, because I want to draw a connection between computer user interfaces and fashion in clothing. I think this analogy explains only a modest fraction of the cost of creating and maintaining user interfaces today, but it&#8217;s a real source of costs that I expect should now decline in importance.</p><p>Fashion is widely acknowledged as a great example of <a href="/__u/stng.substack.com/p/signaling-is-programmable-evolution">signaling</a> and status competition. Sure, some changes in clothing arise from technological improvements that expand the space of what is possible to fabricate at reasonable cost. However, we accept that change in this domain is overwhelmingly driven by aesthetics.</p><p>At some level, fashion trends with the most subtle differences over prior ones are the most valuable for signaling. It may be the hardest job to design new fashion whose advantage is only clear to insiders. Then those insiders get to show off their savvy by picking out only those new fashions that succeed at the game. At some level, the participants in this status contest are showing off their working memories, by maintaining mental mappings from fashion trends to their timelines, so they can distinguish between styles that are less familiar because they&#8217;re so last decade vs. representing an avant-garde worth getting in on early. The general cognitive load of this process makes it useful to measure intelligence of potential mates and coalition partners, whether we are talking about &#8220;book smarts&#8221; intelligence or social intelligence to stay on top of group dynamics.</p><p>I would argue that computer user interfaces include a similar dynamic, not as centrally as for clothing fashion, but still important-enough to affect adoption trends. Now, I have a selfish reason to make this case, as a specialist in the more &#8220;backend&#8221; parts of computer systems. When I design <a href="https://adam.chlipala.net/">user interfaces</a>, they almost universally get panned as archaic. I give the objectors the benefit of the doubt that they are noting some overlooked genuine practical innovations in how to boost user productivity. However, it sure feels to me like there is an element of remembering interface vibes from different eras and wanting to be reminded of only the latest aesthetic, independently of the fundamentals behind each style. The explanation definitely can&#8217;t be that I still remember being excited in high school as HTML <a href="https://en.wikipedia.org/wiki/HTML_element#Tables">tables</a> and <a href="https://en.wikipedia.org/wiki/Frame_(World_Wide_Web)">frames</a> first came out, right?</p><p>Whatever the role of signaling in user interfaces, we might hope that AI agents will have better things to do than worry about fashion. What formal analysis we may perform can focus on utilitarian requirements.</p><h1>The Rise of Minimalist, Structured Interfaces</h1><p>We don&#8217;t need to rely on sci-fi futurist mode to see important interface changes. <a href="https://www.salesforce.com/news/stories/ai-agents-user-interface/?">A 2025 Salesforce article</a> argued that GUIs would decrease in importance as AI agents proliferate. <a href="https://nordicapis.com/the-future-of-saas-is-apis-plus-ai-agents/">Another article from just days ago</a> makes the case for the increasing importance of the kind of highly technical interfaces like <a href="https://en.wikipedia.org/wiki/REST">REST</a> <a href="https://en.wikipedia.org/wiki/API">APIs</a>, which are convenient to use from programs &#8211; software using software. If the &#8220;workers&#8221; of the future are increasingly software, then naturally they&#8217;ll favor this kind of interface.</p><p>Let&#8217;s get a bit more specific. I&#8217;ll argue that human-facing UIs are greatly influenced by limitations in human <a href="https://en.wikipedia.org/wiki/Working_memory">working memory</a>, what we can hold front-of-mind at once. Take the example of the controls for an airplane.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Kg1q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7f282f-6470-4969-adb6-722d8a801b2f_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Kg1q!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7f282f-6470-4969-adb6-722d8a801b2f_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!Kg1q!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7f282f-6470-4969-adb6-722d8a801b2f_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!Kg1q!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7f282f-6470-4969-adb6-722d8a801b2f_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Kg1q!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7f282f-6470-4969-adb6-722d8a801b2f_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Kg1q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7f282f-6470-4969-adb6-722d8a801b2f_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ff7f282f-6470-4969-adb6-722d8a801b2f_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2530107,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/202027625?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7f282f-6470-4969-adb6-722d8a801b2f_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Kg1q!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7f282f-6470-4969-adb6-722d8a801b2f_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!Kg1q!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7f282f-6470-4969-adb6-722d8a801b2f_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!Kg1q!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7f282f-6470-4969-adb6-722d8a801b2f_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Kg1q!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fff7f282f-6470-4969-adb6-722d8a801b2f_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The airplane is a complex <a href="/__u/stng.substack.com/p/our-social-world-as-a-distributed">distributed system</a>, with both digital and analog parts, their full, confusing detail visualized in the leftmost panel. In theory, a pilot can accept input from any of the sensors in the system or send requests to any of the actuators. The trouble is that humans, even the elite ones trained as pilots, can&#8217;t remember the full interface at that level. We are saving a user from a <em>search process</em> that crawls over a full system description and brings back the parts that are relevant, as the actual cockpit shown in the middle panel. With software design as we are used to it, <em>the developer performs that expensive search up-front</em>, stocking each &#8220;screen&#8221; of a program with exactly the input and output options deemed relevant to that stage of execution. This framing fits with the theory of <a href="https://en.wikipedia.org/wiki/Distributed_cognition">distributed cognition</a>, which holds that representations are split across participants in a system.</p><p>However, we don&#8217;t get the full story, just thinking about what is relevant to the user at each step. A user will often have some mission spread out across multiple steps, and working memory also makes it difficult to track mission status and what lies ahead. So the goal of a GUI in a single moment is more than just displaying the system&#8217;s affordances relevant to that moment: <em>it also needs to summarize consequences of past decisions (how we got here) and options for next steps (where we may go)</em>. At some level, all of the bits of state throughout the whole system are sufficient to track both aspects, but our working memory can&#8217;t hold all of those bits, so we get the interface designer&#8217;s guess at what modestly large read-out will remind us where we are in a search process.</p><p>AI agents, represented in the rightmost panel, are just much better positioned at simply keeping all relevant state in memory accessible at reasonable cost. There are still differences in accessing different pieces of stored information, exemplified by <a href="https://en.wikipedia.org/wiki/Memory_hierarchy">memory hierarchies</a> and <a href="https://en.wikipedia.org/wiki/Context_window">context windows</a>, but even the slowest storage method represents a huge win over what humans can muster. As a result, your canonical AI agent is ready to confront something like a fundamental description of a system&#8217;s parts and capabilities, which looks more like a <a href="https://en.wikipedia.org/wiki/Database_schema">data schema</a> or an API specification than a GUI. My personal view is that designing better <a href="/__u/stng.substack.com/p/abstraction-boundaries-and-bubbles">abstractions</a> will remain important for increasing effectiveness of these systems, but so much can be accomplished with relative brute force.</p><p>Hence, in spelling out what makes a program acceptable, we need not worry about situation-specific details of interfaces and the capabilities of users to understand them. Instead, we can present relatively literal descriptions of what systems can do, an exercise typically much easier to get right. Humans remain important consumers of APIs today, requiring a certain amount of abstraction work by API designers, which may become increasingly unnecessary as AI usage predominates. (And, don&#8217;t worry: in later posts I&#8217;ll keep arguing for the importance of abstraction is making future systems <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">faster</a> and <a href="/__u/stng.substack.com/p/designing-decision-making-systems">more reliable</a>. It just seems the argument here is strong enough even continuing to lean heavily into brute force, as is the fashion today.)</p><h1>The Value of an Open-Source User</h1><p>There is another interesting shift in the dynamics of software to be used by software. It becomes relatively doable to have a machine-readable model <em>of the user</em>! The result is that the equivalent of usability testing becomes cheaper and can be automated.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!JcEX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89b7f433-a1e2-4206-9637-6d04ed206ad9_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!JcEX!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89b7f433-a1e2-4206-9637-6d04ed206ad9_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!JcEX!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89b7f433-a1e2-4206-9637-6d04ed206ad9_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!JcEX!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89b7f433-a1e2-4206-9637-6d04ed206ad9_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!JcEX!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89b7f433-a1e2-4206-9637-6d04ed206ad9_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!JcEX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89b7f433-a1e2-4206-9637-6d04ed206ad9_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/89b7f433-a1e2-4206-9637-6d04ed206ad9_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2164264,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/202027625?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89b7f433-a1e2-4206-9637-6d04ed206ad9_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!JcEX!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89b7f433-a1e2-4206-9637-6d04ed206ad9_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!JcEX!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89b7f433-a1e2-4206-9637-6d04ed206ad9_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!JcEX!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89b7f433-a1e2-4206-9637-6d04ed206ad9_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!JcEX!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89b7f433-a1e2-4206-9637-6d04ed206ad9_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The starting point is just creating a test suite for a service, which includes running a variety of common client programs against it. This kind of exercise is already standard today.</p><p>However, we can follow a strategy related to the one I wrote about previously, for <a href="/__u/stng.substack.com/p/proof-carrying-code-in-the-matrix">AI agents coming to trust code provided by their competitors</a>. Consider any user of the service whose source code is known to the service author. That user may be built by the same organization, or it may be released to the world as <a href="https://en.wikipedia.org/wiki/Open-source_software">open source</a>. Now the quality-assurance exercise is to carry out <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a> of the combined system, potentially including the service and all of its known users. Properties may even be checked of emergent behavior that arises from different users interacting with each other. So long as we can formalize, say, some productivity measure for the collective users, we can now (with enough proof effort) guarantee that measure <em>across an infinite variety of scenarios, each lasting for infinite time</em>. It&#8217;s a far cry from what is doable within the usability-testing budget for a software program today!</p><p>The change in perspective can really be quite a powerful booster to software development. It&#8217;s not just that we want to subject a new service to final checking before releasing it into the wild. We can evaluate usability repeatedly throughout development, to shape all the choices we make. Such checks can work like <a href="https://en.wikipedia.org/wiki/Large_language_model#Tool_use">tool calls</a> in <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">AI coding assistants</a> today. An AI searches the space of programs worth considering, repeatedly checking usability to bias its decisions.</p><p>Our AI-centric future may, of course, still include a role for services used by many different types of users, who now correspond to different programs, with different goals, written at different times. We can&#8217;t check the service&#8217;s usability in advance by reference to the specific source code of users who have not been constructed yet. Here, however, we come to what may be deeply satisfying to software engineers used to negotiating with finicky human users: we can impose a formal specification <em>on the users</em>, declaring that the service&#8217;s warranty is voided in the face of deviant behavior. The users can choose to invest in formally verifying themselves, in contrast to humans, who probably wouldn&#8217;t even bother to read these terms of service, let alone audit themselves for compliance. (This idea is related to <a href="https://en.wikipedia.org/wiki/Design_by_contract">design by contract</a> in formal methods, which forces all parts of a software system to follow a common system of specification and sometimes proof.)</p><h1>Conclusion</h1><p>Turning over more of our economy to AI, it becomes important to be able to write down exactly what rules we want those agents to follow. If it is too difficult to formalize our requirements, then formal proof that agents meet them is a nonstarter. User interfaces have been a complex part of software as we know it, which might suggest a tough task ahead in formalizing that part for AI systems. However, if as I argue more and more of the activity of AI agents will be interacting with other agents, then there are a few reasons to expect that formalizing their interfaces will be easier than expected (at least for agents operating entirely <a href="/__u/stng.substack.com/p/abstraction-boundaries-and-bubbles">in the interiors of zones of legibility</a>).</p><ol><li><p>User interfaces have varied to follow trends in fashion, which should not be a concern for AI agents.</p></li><li><p>User interfaces have been designed around limitations in human working memory, while interfaces for AIs can just present &#8220;the facts&#8221; in the most direct way.</p></li><li><p>When the users of a system are themselves programs, it becomes very cheap to test or even formally prove the system against its users, without any of the costs and delays of recruiting people for usability testing. Indeed, a single proof exercise can cover all users within some formally defined category (even an infinite one).</p></li></ol><p>Drawing on these advances, it may become possible to move the equivalent of usability testing into strong formal proof.</p><p>The lingering objection I&#8217;m expecting at this point, from all you software engineers out there, is that the truly hard part of a project remains figuring out what users really want, which is mostly orthogonal to interface details. I agree: that element is what makes full automation of software engineering in today&#8217;s world a truly &#8220;AI-hard&#8221; problem! But in a world with even more AI centrality, does this aspect remain nearly as difficult? My next post argues why not.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Subversion-Resistance for Free from Formal Verification]]></title><description><![CDATA[Why we don't need to worry about enumerating possible attacks]]></description><link>https://stng.substack.com/p/subversion-resistance-for-free-from</link><guid isPermaLink="false">https://stng.substack.com/p/subversion-resistance-for-free-from</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 09 Jun 2026 12:00:22 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/d0fcdf28-3ebc-45c1-b8f5-3a3738f6ff53_792x462.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">Formal verification</a> has the potential to anticipate the futures of complex software systems and block their most problematic potential behaviors, through mathematical proof. It may be the most potent protection against misbehavior by <a href="https://en.wikipedia.org/wiki/Superintelligence">superintelligent</a> systems, whose eventual plans we would not be able to foresee. However, we are only protected if we manage to write out formal specifications that actually block the bad behaviors. I previously wrote about two main techniques to simplify the job of writing those specifications, namely <a href="/__u/stng.substack.com/p/simplifying-alignment-by-expanding">end-to-end formal verification</a>, to catch mistakes in the connections between components; and <a href="/__u/stng.substack.com/p/abstraction-boundaries-and-bubbles">careful encapsulation of most components away from the complex human and natural world</a>. Now I would like to write about an underappreciated benefit of formal methods for security, already relevant to conventional systems but perhaps even more important for artificial intelligence. This concept has been known in the formal-methods community (e.g. see <a href="https://cacm.acm.org/research/sel4-formal-verification-of-an-operating-system-kernel/">discussion around the seL4 verified operating system</a>) but still remains not widely enough understood.</p><h1>The Cybersecurity Arms Race</h1><p>Cybersecurity is often described as fundamentally favoring attackers over defenders. The reason is that an attacker often only needs to find one vulnerability in a system to subvert it, while a defender (or author of a system) needs to anticipate <em>all possible attacks</em> and build protections against all. Not noticing just one potential attack vector, or simply delaying too long in patching a known hole, can allow an attacker to just as effectively do damage as if the system were full of obvious security problems.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>One of the worst kinds of security vulnerabilities is often called <em><a href="https://en.wikipedia.org/wiki/Arbitrary_code_execution">remote code execution</a></em>: a way that an attacker with network access to a system can trick the system into running new program code provided by the attacker. Regardless of what we <em>thought</em> a system should do, an attacker modifying its code can change the plan rather arbitrarily. This category is a special case of the more-general phenomenon of subverting a system. I appreciate the evocative synonym <em>perversion</em> from <em><a href="https://www.amazon.com/dp/B000FBJAGO/?tag=adamchli-20">A Fire Upon the Deep</a></em>, applied to rogue artificial intelligences.</p><p>There are a bewildering variety of different remote code execution attacks, and engineers need to make sure to block all of them, even as new ones arise regularly. One of the classics is a <em><a href="https://en.wikipedia.org/wiki/Buffer_overflow">buffer-overflow attack</a></em>, where a segment of memory is reserved to hold user input, but a programming error causes the user input to run off the end of the region and into adjacent regions. If an adjacent region was used to hold <a href="https://en.wikipedia.org/wiki/Machine_code">machine code</a> to be executed, we have given the attacker a way to inject his own code to execute.</p><p>The phenomenon of <em><a href="https://en.wikipedia.org/wiki/Code_injection">code-injection attacks</a></em> is a broad one, and often different variants have common names that obscure their similarity. When user input is allowed to provide code in the <a href="https://en.wikipedia.org/wiki/SQL">SQL</a> database language, we call it an <a href="https://en.wikipedia.org/wiki/SQL_injection">SQL injection</a>. When a similar situation happens with the <a href="https://en.wikipedia.org/wiki/JavaScript">JavaScript</a> programming language, most typically in a web browser, we call it <a href="https://en.wikipedia.org/wiki/Cross-site_scripting">cross-site scripting</a>. At first blush, it looks like we as engineers of would-be secure systems need to conduct careful audits of all programming languages used within, being sure none of them provide code-injection vulnerabilities.</p><p>It gets worse, though. Just enumerating programming languages isn&#8217;t good enough, because attackers find new ways to implement injection-like functionality within established languages. The first high-profile buffer-overflow attacks involved <a href="https://phrack.org/issues/49/14_md#article">smashing the stack</a> to overwrite certain places used to store addresses of code to execute. As increasingly effective mitigations against stack-smashing (like <a href="https://en.wikipedia.org/wiki/Address_space_layout_randomization">address-space layout randomization</a>, which makes it hard to guess which code addresses contain which code, thus making it hard to guess the effect of an attack) rolled out, attackers developed increasingly sophisticated kinds of <a href="https://en.wikipedia.org/wiki/Weird_machine">weird machines</a>, a phrase that evokes finding hidden functionalities within seemingly innocuous programs. One idea called <a href="https://en.wikipedia.org/wiki/Return-oriented_programming">return-oriented programming</a> creates seemingly impossible execution sequences within the legitimate code of a program by stitching together segments of code in surprising ways, producing emergent behaviors out of pieces that are innocuous individually.</p><p>And here we seem stuck as diligent defenders. It&#8217;s bad enough if we need to realize every place within a complex system that contains a programming language that an attacker could use to inject and run his own code. We also need to imagine all sorts of devious ways such functionality can be built on top of particular languages, including ways that haven&#8217;t been invented at the time code is deployed.</p><p>Future AI systems, especially superintelligent ones, amplify these worries. To start with, the baseline capabilities of these systems to influence this world may be so high that it becomes even more catastrophic to allow an attacker to subvert one of them and turn it against its owners. Then, as highlighted by recent use of <a href="https://en.wikipedia.org/wiki/Claude_Mythos">the Mythos AI model</a> to find new security vulnerabilities in widely used software, highly capable AI may mean an end to the method of <a href="https://en.wikipedia.org/wiki/Security_through_obscurity">security through obscurity</a> that was already deprecated. Superintelligent systems may be able to find longstanding vulnerabilities that human hackers never caught onto.</p><p>So, where a novice engineer may worry that it&#8217;s too difficult to anticipate all attacks against an important system, but where one learning of formal methods may get excited about the potential to rule out those attacks mathematically, we also see how a more-informed engineer may get to worrying that it is impractical even to characterize all of the attacks in a formal specification, let alone prove that particular mitigations address them.</p><h1>To the Rescue: Functional Correctness Implies Subversion-Resistance</h1><p>Luckily, at the next-higher level of enlightenment, we see that using formal verification to block all of the above attacks is rather easy, if we manage to prove much of anything at all.</p><p>Think of a formal specification as laying out which destinations are legal within the execution space of a system, based on starting points.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!nAcD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b553d3-d25a-485e-8fec-5d2105eaf693_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!nAcD!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b553d3-d25a-485e-8fec-5d2105eaf693_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!nAcD!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b553d3-d25a-485e-8fec-5d2105eaf693_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!nAcD!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b553d3-d25a-485e-8fec-5d2105eaf693_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!nAcD!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b553d3-d25a-485e-8fec-5d2105eaf693_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!nAcD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b553d3-d25a-485e-8fec-5d2105eaf693_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08b553d3-d25a-485e-8fec-5d2105eaf693_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3520243,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/201146011?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b553d3-d25a-485e-8fec-5d2105eaf693_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!nAcD!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b553d3-d25a-485e-8fec-5d2105eaf693_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!nAcD!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b553d3-d25a-485e-8fec-5d2105eaf693_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!nAcD!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b553d3-d25a-485e-8fec-5d2105eaf693_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!nAcD!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08b553d3-d25a-485e-8fec-5d2105eaf693_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The trouble with merely testing a system is that we might run many test cases, find that every one arrives at an acceptable destination, and yet have it be the case that the system exhibits catastrophic behavior in an infinite variety of scenarios that we did not think to test. Formal verification can demonstrate acceptable behavior in all possible executions.</p><p>Now assume that we have already invested in proof of <em>functional correctness</em> for a program, which means roughly that we show it truly carries out the intentions of its creator. For instance, a program that is meant to sort lists of integers in increasing order truly does output the sorted version of each input. Trying to define formally exactly which specifications count as functional correctness can be a losing game, but we do expect that such specifications are precise-enough that many small program changes break them. Let&#8217;s keep from this intuition an even laxer requirement: <em>imagine any specification that accepts some system behaviors but not all</em>. Let <code>BAD</code> be some behavior that is not allowed but can be expressed in the underlying programming language. We will now pull a trick reminiscent of our prior discussion of <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">undecidable program properties</a> and <a href="https://en.wikipedia.org/wiki/Rice%27s_theorem">Rice&#8217;s theorem</a>.</p><p>Imagine an attacker finds a way to inject code into the system and run that code, giving great freedom in how to perturb the system&#8217;s behavior. The attacker could use that freedom simply to upload the program for <code>BAD</code>, producing behavior that violates the specification, and so <em>formal verification of the program must fail, despite not having enumerated any requirements about code injection</em>. In this next image, I&#8217;m using the metaphor of an injection attack opening a gate to a world of great flexibility for the attacker, who is allowed to upload and run arbitrary programs in an expressive language, such that it is essentially assured that, once the gate opens, the attacker can find some way (probably infinitely many) to do serious damage.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!wa7z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d038cb0-65f7-4f84-87f5-7eb664152686_1691x930.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!wa7z!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d038cb0-65f7-4f84-87f5-7eb664152686_1691x930.png 424w, /__u/substackcdn.com/image/fetch/$s_!wa7z!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d038cb0-65f7-4f84-87f5-7eb664152686_1691x930.png 848w, /__u/substackcdn.com/image/fetch/$s_!wa7z!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d038cb0-65f7-4f84-87f5-7eb664152686_1691x930.png 1272w, /__u/substackcdn.com/image/fetch/$s_!wa7z!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d038cb0-65f7-4f84-87f5-7eb664152686_1691x930.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!wa7z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d038cb0-65f7-4f84-87f5-7eb664152686_1691x930.png" width="1456" height="801" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0d038cb0-65f7-4f84-87f5-7eb664152686_1691x930.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:801,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3090775,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/201146011?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d038cb0-65f7-4f84-87f5-7eb664152686_1691x930.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!wa7z!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d038cb0-65f7-4f84-87f5-7eb664152686_1691x930.png 424w, /__u/substackcdn.com/image/fetch/$s_!wa7z!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d038cb0-65f7-4f84-87f5-7eb664152686_1691x930.png 848w, /__u/substackcdn.com/image/fetch/$s_!wa7z!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d038cb0-65f7-4f84-87f5-7eb664152686_1691x930.png 1272w, /__u/substackcdn.com/image/fetch/$s_!wa7z!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d038cb0-65f7-4f84-87f5-7eb664152686_1691x930.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For example, there may be an Internet service meant to add positive numbers on demand. Its specification may explain exactly which sums should be produced, in response to which requests. Or its specification might just declare that the service only outputs positive numbers. Both are sufficient to guarantee that no injection attack allows installing arbitrary code. If that vulnerability <em>did</em> exist, then we could make the system return zero, which violates both specifications.</p><p>In fact, the authors of specifications don&#8217;t need to think explicitly about code injections at all. It is only necessary to explain <em>positively</em> what a program is meant to do, rather than enumerate <em>negatively</em> what it must be prevented from doing. We saw an example in <a href="/__u/stng.substack.com/p/simplifying-alignment-by-expanding">end-to-end verification of a simple IoT system</a>, whose specification simply explained how a network protocol was meant to work, nonetheless ruling out, for instance, that the system can be taken over by a well-crafted packet and tricked into joining a <a href="https://en.wikipedia.org/wiki/Botnet">botnet</a>.</p><h1>Conclusion</h1><p>This observation certainly doesn&#8217;t address all of the challenges of AI alignment. We should expect superintelligence to be given such wide latitude in making plans and transforming the world as to defy concise specification. However, it seems reasonable to assume that any useful specification does rule out some behaviors, from which it still follows that attackers can&#8217;t gain access to run arbitrary code. Therefore, there is a relatively clear path toward using formal verification to develop highly empowered AI systems that will resist being subverted.</p><p>In fact, the principle generalizes to any cases involving top-level objectives that must be realized by lower-level implementation details that we need not spell out in formal specifications. For example:</p><ul><li><p>If an attacker finds a clever way to <em>overwrite stored state of a system</em>, then presumably either that state wasn&#8217;t important, or the attacker has a simple lever to perturb behavior away from what is specified.</p></li><li><p>If an attacker is able to <em>interfere with the flow of information from sensors into decision-making</em>, say by taking advantage of a subtle weakness in <a href="https://en.wikipedia.org/wiki/Digital_signal_processing">digital signal processing</a>, then either those sensors weren&#8217;t important, or arbitrarily distorting their values can easily lead to violating the specification.</p></li><li><p>Conversely, if an attacker can mess with the <em>logic controlling how a system takes action in the world</em>, then it should be even easier to generate specification violations. Imagine an example of an online-shopping agent with a bug that repeats the last order over and over, instead of responding to new requests. Such behavior would violate specifications on the granularity spectrum from &#8220;only place orders that the user explicitly OKs&#8221; to &#8220;don&#8217;t place an order that would exceed your credit-card spending limit&#8221; (because the repeated order could happen to be a gigantic one, even as the later legitimate orders are for cheap items; remember, with formal verification, we reason in advance about all possible scenarios).</p></li><li><p>Even examples of <em>poisoning the training data of systems that learn</em> are covered, so long as the learned components are implementation details not mentioned directly in specifications. Either the learned component is irrelevant to the top-level mission, or arbitrary data control allows breaking the specification without too much effort.</p></li></ul><p>Of course, much of the current deep learning-maximalist approach is built around assuming that learned systems are central to meeting specifications, despite the absence of ways to prove in advance that learned components don&#8217;t surprise us, so my reassurance here in the last bullet only applies to examples where learned components are nicely modularized and only raise worries about implementation details like where the training data come from. We should remember that sometimes we realize we overlooked additional dimensions of top-level specification, as in <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">leakage of secrets through timing</a> that we discussed previously. However, there is great power in only needing to pin down the top-level requirements of a system and not worry about vulnerabilities missed in low-level implementation details.</p><p>The next posts will cover two other ways we should expect specification-writing to get simpler as <a href="/__u/stng.substack.com/p/abstraction-boundaries-and-bubbles">more pockets of the economy become dominated by AI agents interacting with each other</a>. We&#8217;ll start by reconsidering user interfaces in that world where users increasingly don&#8217;t belong to the same species anymore.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Abstraction Boundaries and Bubbles of Legibility]]></title><description><![CDATA[Encapsulating intelligence away from avoidable complexity]]></description><link>https://stng.substack.com/p/abstraction-boundaries-and-bubbles</link><guid isPermaLink="false">https://stng.substack.com/p/abstraction-boundaries-and-bubbles</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 02 Jun 2026 12:37:13 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/fa969059-d799-4de6-a8f2-10c0dd9953f4_852x450.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><a href="https://en.wikipedia.org/wiki/AI_alignment">AI alignment</a> considers the hard problem of how to give clear instructions to what can strike us as alien minds. As these intelligent systems grow in complexity, we may worry that it becomes correspondingly complicated to give them clear-enough instructions to avoid bad outcomes. In contrast, <a href="/__u/stng.substack.com/p/simplifying-alignment-by-expanding">the last post</a> reviewed an underappreciated technique from formal verification: <em>end-to-end proof</em> of layered computer systems, verifying many different parts as a whole, in a way that helps catch any misunderstandings between the parts about how they interact. Such a layered system can be seen as exporting some top-level interface and depending on some bottom-level foundation interface &#8211; and the great payoff of end-to-end verification is that (with caveats; see that last post) it roots out mistakes in spelling out requirements for all interior layers, leaving only the top and bottom interfaces as opportunities for faulty specification. This capability opens the possibility of scaling up the complexity of automated systems without paying a tax in the difficulty of avoiding bugs, sometimes even finding that bug-avoidance becomes <em>easier</em> as we add layers.</p><p>Engineers quickly realize a problem: true certainty about the behavior of systems is impossible. Our example from last time of <a href="https://adam.chlipala.net/papers/LightbulbPLDI21/">a network-connected lightbulb controller</a> presumes the correct operation of a physical actuator for the lightbulb. If that actuator instead starts a house fire when triggered, we&#8217;re in trouble. If a saboteur <a href="https://ieeexplore.ieee.org/document/1199334">takes a hair dryer to the CPU</a> and flips critical bits, all bets are off. The assumption that a hardware circuit executes in an orderly way can prove misleading, invalidating all of the theorems we invested in.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Yet it remains overwhelmingly valuable to carry out formal verification of complex digital systems. Why? We&#8217;ll review the effectiveness of <em>abstractions</em> that present clear interfaces on top of messy physical reality. Then we&#8217;ll generalize to principles for responsibly bringing artificial intelligence into more aspects of our society. It&#8217;s natural to think of adding AI into the world gradually, replacing units of functionality previously provided by humans. However, our evolved world is full of complexities that are expensive for AI to grapple with. The incremental path misses an opportunity to <em>create economic enclaves purposely protected from those evolved complexities</em>, allowing reasoning that is both cheaper and more effective.</p><h1>The Digital Abstraction</h1><p>I should confess here that, despite working in <a href="https://www.eecs.mit.edu/">an academic department</a> whose name starts with &#8220;electrical engineering,&#8221; I&#8217;ve never taken a class in electrical engineering. I couldn&#8217;t explain how flows of electrons provide the behaviors we&#8217;re used to in electronic circuits. Yet somehow I&#8217;ve been able to develop hardware and software components that function well. What&#8217;s the trick? All of us depend critically on <em><a href="https://en.wikipedia.org/wiki/Digital_signal">the digital abstraction</a></em>.</p><p>A naive electronic component can involve a wide range of <a href="https://en.wikipedia.org/wiki/Voltage">voltages</a> in a particular wire. Such an untamed wire can be used as analog storage, meaning that it represents a real number, but computing with real numbers, embodied in voltage levels, is a tricky business. We can imagine that a relatively &#8220;natural&#8221; electrical phenomenon would tend to spread its voltages over a wide range.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!GEms!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2d643b-df81-45e5-9f5c-81a6bc719f75_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!GEms!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2d643b-df81-45e5-9f5c-81a6bc719f75_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!GEms!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2d643b-df81-45e5-9f5c-81a6bc719f75_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!GEms!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2d643b-df81-45e5-9f5c-81a6bc719f75_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!GEms!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2d643b-df81-45e5-9f5c-81a6bc719f75_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!GEms!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2d643b-df81-45e5-9f5c-81a6bc719f75_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8a2d643b-df81-45e5-9f5c-81a6bc719f75_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1210962,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/200158800?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2d643b-df81-45e5-9f5c-81a6bc719f75_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!GEms!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2d643b-df81-45e5-9f5c-81a6bc719f75_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!GEms!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2d643b-df81-45e5-9f5c-81a6bc719f75_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!GEms!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2d643b-df81-45e5-9f5c-81a6bc719f75_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!GEms!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2d643b-df81-45e5-9f5c-81a6bc719f75_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So then how have we come to rely on computers that make discrete decisions? The wizards of electrical engineering found a way to bias electronic components so that their voltage levels bunch up at two extremes. We can then draw a line down the middle of that spectrum and say every level above the line is a <em>one</em> and every level below a <em>zero</em>. Now we can construct the basic building blocks of digital computing, logic gates like &#8220;AND&#8221; that outputs one exactly when each of its two inputs is one.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!bT-f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1546f800-fe11-41c2-9a1c-745138550608_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!bT-f!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1546f800-fe11-41c2-9a1c-745138550608_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!bT-f!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1546f800-fe11-41c2-9a1c-745138550608_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!bT-f!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1546f800-fe11-41c2-9a1c-745138550608_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!bT-f!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1546f800-fe11-41c2-9a1c-745138550608_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!bT-f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1546f800-fe11-41c2-9a1c-745138550608_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1546f800-fe11-41c2-9a1c-745138550608_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1168342,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/200158800?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1546f800-fe11-41c2-9a1c-745138550608_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!bT-f!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1546f800-fe11-41c2-9a1c-745138550608_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!bT-f!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1546f800-fe11-41c2-9a1c-745138550608_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!bT-f!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1546f800-fe11-41c2-9a1c-745138550608_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!bT-f!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1546f800-fe11-41c2-9a1c-745138550608_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Crucially, this <em>digital abstraction</em> lets us forget about continuous voltage and think of the &#8220;AND&#8221; gate as working solely with zeros and ones. Yes, such components do still glitch occasionally, revealing their analog reality. For instance, a <a href="https://en.wikipedia.org/wiki/Cosmic_ray">cosmic ray</a> may fly by and disturb the wiring. The point is that extensive engineering has pushed the risk of such disturbances low-enough that we can get far while ignoring them.</p><p>With this abstraction in place, we can build other abstractions. We can combine many primitive logic gates into more complex circuits. For example, we can build an addition circuit out of gates for &#8220;AND&#8221; and other simpler functionalities. Now this addition circuit can, in turn, be seen as a building block for higher-level functionality, ignoring not just how it was built out of simpler gates but also ignoring the analog dynamics of voltage within them.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!WGhg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05e8e2da-68b4-4a6c-b5fc-47f5799b85d6_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!WGhg!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05e8e2da-68b4-4a6c-b5fc-47f5799b85d6_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!WGhg!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05e8e2da-68b4-4a6c-b5fc-47f5799b85d6_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!WGhg!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05e8e2da-68b4-4a6c-b5fc-47f5799b85d6_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!WGhg!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05e8e2da-68b4-4a6c-b5fc-47f5799b85d6_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!WGhg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05e8e2da-68b4-4a6c-b5fc-47f5799b85d6_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/05e8e2da-68b4-4a6c-b5fc-47f5799b85d6_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1686250,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/200158800?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05e8e2da-68b4-4a6c-b5fc-47f5799b85d6_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!WGhg!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05e8e2da-68b4-4a6c-b5fc-47f5799b85d6_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!WGhg!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05e8e2da-68b4-4a6c-b5fc-47f5799b85d6_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!WGhg!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05e8e2da-68b4-4a6c-b5fc-47f5799b85d6_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!WGhg!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05e8e2da-68b4-4a6c-b5fc-47f5799b85d6_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://adam.chlipala.net/papers/LightbulbPLDI21/">Our end-to-end-verified stack example</a> presumes the digital abstraction at its bottom level. More specifically, it bottoms out in formal semantics of a <a href="https://en.wikipedia.org/wiki/Hardware_description_language">hardware-description language</a> (a mathematical characterization of what results any circuit could produce), and we assume some accurate way of executing circuits encoded in that language. The digital abstraction gives us that way. An immensely complicated <a href="https://en.wikipedia.org/wiki/Semiconductor_device_fabrication">semiconductor-manufacturing supply chain</a> is able to turn circuit descriptions into physical chips, well-enough that we can (usually) forget its details in designing digital systems.</p><h1>Other Greatest Hits of Abstraction</h1><p>The importance of abstraction in planning for a future of artificial intelligence has been emphasized in other sources, including <em><a href="https://www.amazon.com/dp/B000QCSA7C?tag=adamchli-20">The Singularity is Near</a></em>. Let me just give a few more standard examples, before moving on to suggest a new kind of abstraction.</p><p>Natural evolutionary processes have given us many abstractions. Somehow lower-level physics allows subatomic particles to come together into atoms, which become largely reliable building blocks for chemistry. Then those higher-level molecules become building blocks for cells in biology. Cells can be aggregated into tissues and organisms, with <a href="https://en.wikipedia.org/wiki/Cancer">cancer</a> as the consequence of misbehavior when cells act more individualistically. We must plan for (prevent and treat) cancer, but, like a cosmic ray disturbing part of a silicon chip, it happens infrequently enough that abstractions like tissue and organism remain useful.</p><p>There are also higher-level abstractions that we design ourselves. One of the most basic ones is to have government maintain a monopoly on (legitimate) violence, so that competition shifts to economic activity, on top of strong foundations of property rights. On top of that foundation, a <a href="https://en.wikipedia.org/wiki/Corporation">corporation</a> can have legal personhood and enter into contracts with individuals or other corporations. Several corporations can then form a consortium that lobbies for their collective interest. Or individuals as citizens can aggregate into a nation, and then those nations can form coalitions. Geopolitical strategists can get pretty far thinking of coalitions or nations as atomic agents, even as we know it is often necessary to, say, understand a nation by understanding the will of blocs of its voters.</p><p>It is probably not controversial to suggest that taking full advantage of artificial intelligence will depend on developing new abstractions, but I&#8217;m going to suggest a strategy that tinkers with different parts of our world than most would focus on.</p><h1>Bubbles of Legibility and Their Interfaces</h1><p>One major point I worked up to in previous installments was the payoff from <a href="/__u/stng.substack.com/p/codesign-for-legibility-to-ai-and">reconfiguring the world for greater legibility to intelligence technologies with good properties</a>. That is, some hard problems of AI come from assuming that the basic structure of the world stays the same, and we plug an AI into a spot traditionally occupied by a human worker. If humans communicate with the rest of the world in <a href="/__u/stng.substack.com/p/what-makes-language-processing-hard">natural language</a>, we fall into assuming that AIs must communicate in natural language, too. Yet switching to other modes of communication dramatically simplifies processing.</p><p>One goal for the present post is to flesh out more of the strategy for reconfiguring the world. I also want to frame that process as introducing an important new kind of abstraction.</p><p>Here is the three-step recipe for building a <em>region of legibility</em>.</p><ol><li><p>Identify part of the economy where <em>all decision-making can be artificial</em>, minimizing roles for intelligence that evolved rather than being designed deliberately.</p></li><li><p><em><a href="/__u/stng.substack.com/p/hardware-software-codesign-and-autonomous">Codesign</a></em> that region with the agents that occupy it, optimizing for lowest cost of understanding by those agents.</p></li><li><p>Carefully create an <em>interface</em> with the rest of the world, a promise of the region of legibility about what service it provides.</p></li></ol><p>One important kind of region of legibility is under single ownership. As a canonical example, consider an <em>autonomous factory</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!V6Oe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9348f6f4-67b4-4658-94f1-f4c635d3e151_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!V6Oe!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9348f6f4-67b4-4658-94f1-f4c635d3e151_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!V6Oe!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9348f6f4-67b4-4658-94f1-f4c635d3e151_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!V6Oe!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9348f6f4-67b4-4658-94f1-f4c635d3e151_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!V6Oe!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9348f6f4-67b4-4658-94f1-f4c635d3e151_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!V6Oe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9348f6f4-67b4-4658-94f1-f4c635d3e151_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9348f6f4-67b4-4658-94f1-f4c635d3e151_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2649758,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/200158800?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9348f6f4-67b4-4658-94f1-f4c635d3e151_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!V6Oe!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9348f6f4-67b4-4658-94f1-f4c635d3e151_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!V6Oe!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9348f6f4-67b4-4658-94f1-f4c635d3e151_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!V6Oe!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9348f6f4-67b4-4658-94f1-f4c635d3e151_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!V6Oe!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9348f6f4-67b4-4658-94f1-f4c635d3e151_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For simplicity, say the factory is a three-dimensional block of space enclosed in walls. Its mission, what led us to create it, is production of particular physical goods. The nature of those goods can be formalized mathematically, in theory allowing end-to-end proof that the factory delivers on its mission. It won&#8217;t be easy to get the specification right, as we must characterize physics sufficiently well. Moreover, capturing the nature of the desired product is insufficient, as we must also capture safety properties, e.g. avoidance of toxic emissions seeping through the factory walls. However, following the end-to-end verification approach, we <em>avoid needing to understand how work is divided up and carried out within the factory</em>. The following common AI challenges can be sidestepped entirely.</p><ul><li><p>As the factory is fully autonomous, <a href="/__u/stng.substack.com/p/what-makes-language-processing-hard">natural language</a> is off the table and need not be processed.</p></li><li><p>There is also no need to worry about safe cooperation with humans on an assembly line.</p></li><li><p>After the factory is constructed, there may no longer be any need to engage with <a href="/__u/stng.substack.com/p/hardware-software-codesign-and-autonomous">vision</a> or other conventional senses. The factory is laid out so that movement takes place among well-defined paths with easily detected markers of location.</p></li><li><p>The software running the factory may be written in languages incomprehensible to humans, relying on formal methods to guarantee that specifications continue to be followed, even in the presence of <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">recursive self-improvement</a>.</p></li></ul><p>Overall, <em>the protected environment of the factory has been created to maximize legibility to the AI agents inhabiting it</em>, minimizing their cost to make good decisions.</p><p>It remains a hard problem to capture the rules we want the factory to follow, just as it was difficult to build today&#8217;s silicon supply chain. However, the payoff in cost reduction should be enormous. Moreover, we have available the established tricks of <a href="/__u/stng.substack.com/p/simplifying-alignment-by-expanding">end-to-end verification</a>. <em>It can be easier to believe a formal verification of multiple autonomous factories than one</em>. If their outputs are integrated into single products whose specifications are simpler than those of the constituent components alone, then the trusted &#8220;exterior&#8221; interface of the mega-factory becomes simpler, and there are fewer opportunities for mistakes in formalizing it. The basic rules of factory safety may also remain largely the same across constituent factories. In such a setting, the mega-factory may even have autonomy to build new factories that follow the common rules. It may invent new decomposition of top-level deliverables into components, design and construct new factories to supply those components, and still remain compatible with its exterior interface.</p><p>The exterior interface is the place where humans bring requests and receive deliverables. We work hard to formalize it properly, in a way that retains flexibility for the intelligence within. There can in general be many interior interfaces, which no longer need to deal directly with complexities of human interaction. Rather, the consequences of human requirements are devolved down into other layers and their formal interfaces, and effort at simplifying the human-interface layer can pay off in simplifying other layers.</p><p>We will never capture all aspects of existing in the world as formal requirements, but the principle I&#8217;m proposing is to encapsulate as much of a system as possible away from those complexities, whether they come from human behavior or from imperfectly understood natural phenomena.</p><h1>Competition and Ground Rules</h1><p>What about larger systems than factories, where one of the chief complexities is interaction between parties that aren&#8217;t fully cooperative with each other? We can consider settings for AI agents both to compete and cooperate with each other, on top of a foundation that simplifies operation for all of them, just like the digital abstraction for computer systems or the rule of law for human civilization.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!CUdk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd483d9ba-e561-4030-9352-8d9c52ed9a60_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!CUdk!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd483d9ba-e561-4030-9352-8d9c52ed9a60_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!CUdk!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd483d9ba-e561-4030-9352-8d9c52ed9a60_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!CUdk!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd483d9ba-e561-4030-9352-8d9c52ed9a60_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!CUdk!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd483d9ba-e561-4030-9352-8d9c52ed9a60_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!CUdk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd483d9ba-e561-4030-9352-8d9c52ed9a60_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d483d9ba-e561-4030-9352-8d9c52ed9a60_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2545939,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/200158800?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd483d9ba-e561-4030-9352-8d9c52ed9a60_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!CUdk!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd483d9ba-e561-4030-9352-8d9c52ed9a60_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!CUdk!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd483d9ba-e561-4030-9352-8d9c52ed9a60_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!CUdk!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd483d9ba-e561-4030-9352-8d9c52ed9a60_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!CUdk!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd483d9ba-e561-4030-9352-8d9c52ed9a60_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I wrote previous about <a href="/__u/stng.substack.com/p/proof-carrying-code-in-the-matrix">how AI agents can trust code provided by others</a>. The value of rigorous reasoning about code depends on having a reliable computing substrate, as the digital abstraction enables. However, it is also important to have rules governing which compute resources are controlled by which agents. Furthermore, as an agent reasons through the consequences of a piece of code, its job is greatly simplified by using streamlined artificial languages over <a href="/__u/stng.substack.com/p/what-makes-language-processing-hard">natural ones</a>, also preferring well-designed <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">programming languages</a>. Gaming out strategies for competition and cooperation is simplified by adoption of a streamlined <a href="/__u/stng.substack.com/p/codesign-for-legibility-to-ai-and">sensory environment</a>. The physical manifestation could be something like a <a href="https://en.wikipedia.org/wiki/Special_economic_zone">special economic zone</a> where only artificial intelligence is allowed.</p><p>There is a significant payoff from avoiding the need to reason about human decision-making, within the interior of the economic zone. Our brains developed through evolution, with its limited ability to escape local optima in fitness landscapes. We especially weren&#8217;t subjected to selection pressure for efficient understandability to algorithms. Some pressures have even been toward making understandability <em>worse</em>, as with <a href="/__u/stng.substack.com/p/signaling-is-programmable-evolution">signaling</a>.</p><p>I should emphasize, though, that compatibility with human wishes remains central to the proper design of an autonomous economic zone. It&#8217;s just that <em>those wishes are abstracted properly into the interface of the zone</em>, kept separate from its interior. Requests flow in from humans to their agents, and then the agents act on those requests as efficiently as they can, ideally even in a <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">provably compliant</a> way, even as they may <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">recursively improve themselves</a> over time.</p><p>It is also important to acknowledge another kind of competition, which may lead agents or their coalitions to try to sabotage each other. These acts of aggression seem impossible to block entirely, but, still, I&#8217;ll argue that it makes sense to maintain orderly economic zones as far as possible. One analogy is with the increasingly global economy of today, with common norms of property rights and protection from violence. Various conflicts interfere with those rights and protections from time to time, and yet progress depends on relying on them most of the time. Otherwise, we wouldn&#8217;t see the investment in for-profit companies that is upstream of so many important breakthroughs. In the context of autonomous economic zones, an attack could force direct confrontation with, say, the laws of physics instead of nicer abstractions obeyed by reconfigured matter, in which case less-scrutable methods like <a href="/__u/stng.substack.com/p/deep-learning-the-ultimate-search">deep learning</a> become dominant again, but we can still do our best to avoid those situations.</p><h1>Conclusion</h1><p>The principle we&#8217;ve covered bears an interesting kind of mirror-image similarity to the idea of <a href="https://rationalwiki.org/wiki/AI-box_experiment">keeping an AI in a box</a>. The motivation for that idea was to limit the ability of a rogue intelligence to do damage out in the world, and it has been argued extensively that even just a text connection with human users is enough for an AI to use trickery to &#8220;escape.&#8221; Instead, the abstraction barriers I&#8217;m arguing for <em>protect AIs against the human world so that they can be more <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">efficient</a> and <a href="/__u/stng.substack.com/p/designing-decision-making-systems">reliable</a></em>. The idea is that the complexities we protect these AI modules against are the ones that force the use of opaque learned heuristics rather than traceable reasoning processes from first principles. Then mechanisms like <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a> can be used to anticipate all consequences of candidate design choices.</p><p>Even if our human concerns are pushed into the external interfaces of autonomous zones, we still need to characterize those concerns properly. The next three posts will go through three reasons that top-level specifications should be relatively tractable to write in this future scenario, starting from one observation around computer security that already even applies to today&#8217;s computer systems.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Simplifying Alignment by Expanding Scope]]></title><description><![CDATA[A counterintuitive advantage for the good guys]]></description><link>https://stng.substack.com/p/simplifying-alignment-by-expanding</link><guid isPermaLink="false">https://stng.substack.com/p/simplifying-alignment-by-expanding</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 26 May 2026 12:11:59 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e1a71560-9ec5-47cd-a84f-26a5e8ea3421_399x243.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I just <a href="/__u/stng.substack.com/p/intelligence-depends-on-organizing">summarized the story so far</a> in the approach I&#8217;m laying out for building trustworthy artificial intelligence, and now I want to step back and explain more of the key ingredients. To use <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a> to prove mathematically that programs behave as we would like, we&#8217;ll first need to explain what we like in great detail. Such explanations are called specifications.</p><p>The challenge of getting specifications right is highly related to a high-profile problem in AI safety, <em><a href="https://en.wikipedia.org/wiki/AI_alignment">alignment</a></em>. Roughly, both problems are variants of the classic hazard of asking a <a href="https://en.wikipedia.org/wiki/Jinn">genie</a> to grant a wish. If some poor soul specifies a wish inexactly, the genie might just give him something terrible that matches a literal interpretation of the wish. AI alignment is concerned especially with <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">recursively self-improving systems</a> that modify their own code, perhaps subject to constraints from specifications given in advance &#8211; which is little comfort if specifications are inexact in capturing our true intentions, in ways that leave the door open to catastrophe. If a <a href="https://en.wikipedia.org/wiki/Superintelligence">superintelligence</a> is applying itself to find loopholes in our specifications, we could be in a lot of trouble.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>However, the situation decades ago was already pretty risky in representative ways. First, human software engineers can make mistakes. More importantly, someone providing an appealing piece of software might actually be out to get us. It wouldn&#8217;t be very practical to write all of our own software from scratch, yet dividing up the work exposes us to sabotage by code authors. (And before someone objects that <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">AI coding assistants</a> now make it practical to write all of our own software from scratch, that usage mode just raises the risk of mistakes or sabotage by those agents!) I wrote previously about how <a href="/__u/stng.substack.com/p/proof-carrying-code-in-the-matrix">agents sharing code with each other</a> forces a solution to this problem, which luckily has already been studied in the old-fashioned setting.</p><p>The subject of the current post is a piece of good news about how alignment, or getting specifications right, is easier than it might sound. Across levels of familiarity with the subject, most people would probably agree that we expect alignment to get more challenging as systems grow in complexity. More moving parts means more parts that could contribute to bad outcomes, and it seems fatal to give any part the benefit of the doubt and skip careful specification for it. Luckily, the storied technique of <em>end-to-end formal verification</em> provides a counterintuitive way to harness expanded scope to <em>lower</em> risks of specification mistakes.</p><h1>End-to-End Formal Verification</h1><p>This post will take us through a series of steps of enlightenment in system construction. We can start by noticing that software seems awfully hard to get right, so it is worth investing in disciplined quality-assurance techniques. Formal verification, with its focus on rigorous proofs that implementations meet specifications, is an intuitively appealing technique. What could be better than <em>mathematical certainty</em> that a system behaves itself?</p><p>We already set the stage for the first objection: proof only helps us when it proves the right theorem, the specification for an artifact. If we got the specification wrong, then we may wind up <em>worse off</em>, thanks to a false sense of security from a misguided but complete proof. Nonetheless, assume for the sake of argument that we have created a formal specification that captures all of our true requirements for a system.</p><p>Let&#8217;s say that system is a complex piece of software. The gradually enlightened skeptic notices that software doesn&#8217;t just run on its own. There is always some <em>programming-language implementation</em> underneath, and what if <em>that component</em> has a bug? Then behavior can be changed arbitrarily, invalidating all of our original proof work. But why stop there? What about the computer hardware that the program runs on? This reductio can go on for as long as we like, perhaps winding up in quantum mechanics.</p><p>With <em>end-to-end formal verification</em>, we choose to stop the &#8220;what ifs&#8221; at some level and then <em>prove all of the implicated components as a unit</em>. Engineering costs are typically most reasonable when this verification is done <em>modularly</em>, which means that every natural component has its own specification and proof, which we later compose into one full-system specification and proof. Here is a diagram of a natural layered system decomposition, which follows a common pattern of successively translating high-level code into lower-level code as we proceed down the diagram. (We will return to discuss the intermediate specification boxes in the next section.)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!bhTB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9c8818-821f-46da-bc8c-30b56fcccb43_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!bhTB!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9c8818-821f-46da-bc8c-30b56fcccb43_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!bhTB!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9c8818-821f-46da-bc8c-30b56fcccb43_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!bhTB!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9c8818-821f-46da-bc8c-30b56fcccb43_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!bhTB!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9c8818-821f-46da-bc8c-30b56fcccb43_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!bhTB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9c8818-821f-46da-bc8c-30b56fcccb43_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e9c8818-821f-46da-bc8c-30b56fcccb43_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1330872,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/199261793?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9c8818-821f-46da-bc8c-30b56fcccb43_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!bhTB!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9c8818-821f-46da-bc8c-30b56fcccb43_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!bhTB!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9c8818-821f-46da-bc8c-30b56fcccb43_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!bhTB!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9c8818-821f-46da-bc8c-30b56fcccb43_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!bhTB!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9c8818-821f-46da-bc8c-30b56fcccb43_1024x1536.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>While thinking about aligning superintelligence has by necessity been almost entirely theoretical and perhaps even philosophical, end-to-end formal verification has been concretely possible for decades, and we can learn about the broader challenges and potential by studying examples. One of my own related projects is <em><a href="https://adam.chlipala.net/papers/LightbulbPLDI21/">the verified IoT lightbulb</a></em>, with a unified proof of all digital parts of a simple system to control a lightbulb via an Internet connection. The bottom left of the following photo shows a <a href="https://en.wikipedia.org/wiki/Field-programmable_gate_array">field-programmable gate array (FPGA)</a>, a kind of reconfigurable hardware that stands in for fabrication of custom silicon, though the project was structured to be compatible with manufacturing silicon some day. This system includes all of the layers from the prior diagram, proved together as a unit.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!CZ_F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dfe05f-7ec9-470c-9ab1-c191a417c635_2583x1526.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!CZ_F!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dfe05f-7ec9-470c-9ab1-c191a417c635_2583x1526.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!CZ_F!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dfe05f-7ec9-470c-9ab1-c191a417c635_2583x1526.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!CZ_F!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dfe05f-7ec9-470c-9ab1-c191a417c635_2583x1526.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!CZ_F!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dfe05f-7ec9-470c-9ab1-c191a417c635_2583x1526.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!CZ_F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dfe05f-7ec9-470c-9ab1-c191a417c635_2583x1526.jpeg" width="1456" height="860" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c1dfe05f-7ec9-470c-9ab1-c191a417c635_2583x1526.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:860,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:637996,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/199261793?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dfe05f-7ec9-470c-9ab1-c191a417c635_2583x1526.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!CZ_F!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dfe05f-7ec9-470c-9ab1-c191a417c635_2583x1526.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!CZ_F!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dfe05f-7ec9-470c-9ab1-c191a417c635_2583x1526.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!CZ_F!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dfe05f-7ec9-470c-9ab1-c191a417c635_2583x1526.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!CZ_F!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1dfe05f-7ec9-470c-9ab1-c191a417c635_2583x1526.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A follow-on project confined itself to the software side but covered more-comprehensive functionality, including a nontrivial <a href="/__u/stng.substack.com/p/cryptography-for-delegation-in-search">cryptographic</a> protocol, for <em><a href="https://adam.chlipala.net/papers/GarageDoorPLDI24/">the verified garage-door opener</a></em>. Following the latest fashion, this <a href="https://en.wikipedia.org/wiki/Lego">Lego</a> garage has a <a href="https://en.wikipedia.org/wiki/Microcontroller">microcontroller</a> on its roof, which runs the cryptographic protocol to ensure that only the proper owner of the garage, the sole holder of a certain private key, is able to open and close the garage door over the Internet.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Xbl7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffadd38c5-07f6-4cfa-a53d-3f2bcee7a372_1048x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Xbl7!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffadd38c5-07f6-4cfa-a53d-3f2bcee7a372_1048x1080.png 424w, /__u/substackcdn.com/image/fetch/$s_!Xbl7!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffadd38c5-07f6-4cfa-a53d-3f2bcee7a372_1048x1080.png 848w, /__u/substackcdn.com/image/fetch/$s_!Xbl7!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffadd38c5-07f6-4cfa-a53d-3f2bcee7a372_1048x1080.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Xbl7!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffadd38c5-07f6-4cfa-a53d-3f2bcee7a372_1048x1080.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Xbl7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffadd38c5-07f6-4cfa-a53d-3f2bcee7a372_1048x1080.png" width="1048" height="1080" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fadd38c5-07f6-4cfa-a53d-3f2bcee7a372_1048x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1048,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:871363,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/199261793?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffadd38c5-07f6-4cfa-a53d-3f2bcee7a372_1048x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Xbl7!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffadd38c5-07f6-4cfa-a53d-3f2bcee7a372_1048x1080.png 424w, /__u/substackcdn.com/image/fetch/$s_!Xbl7!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffadd38c5-07f6-4cfa-a53d-3f2bcee7a372_1048x1080.png 848w, /__u/substackcdn.com/image/fetch/$s_!Xbl7!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffadd38c5-07f6-4cfa-a53d-3f2bcee7a372_1048x1080.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Xbl7!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffadd38c5-07f6-4cfa-a53d-3f2bcee7a372_1048x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>These sorts of projects are very satisfying in pursuing end-to-end formal verification far-enough to respond to many &#8220;what if&#8221; questions like I indicated above. However, the informed observer notices a problem that seems fatal at first.</p><h1>Specifications for Intermediate Layers</h1><p>Let us now turn to the layers of the first diagram labeled as specifications. Such specifications serve as <em>interfaces between layers</em>. Each one effectively lays out a <em>contract</em> that two layers promise to follow in cooperating. The examples in the diagram are:</p><ol><li><p>The <em>application specification</em> mediates between user intentions and the behavior of the program.</p></li><li><p>The <em><a href="https://en.wikipedia.org/wiki/Semantics_(programming_languages)">programming-language semantics</a></em> (formal meanings of programs) mediates between programs and the language implementation (here a <a href="https://en.wikipedia.org/wiki/Compiler">compiler</a>).</p></li><li><p>The <em><a href="https://en.wikipedia.org/wiki/Instruction_set_architecture">machine-language semantics</a></em> mediates between the software compiler and the hardware.</p></li><li><p>The <em><a href="https://en.wikipedia.org/wiki/Hardware_description_language">hardware-description-language</a> semantics</em> mediates between the hardware implementation and the language it is written in.</p></li></ol><p>A typical mid-layer specification of this kind has two qualities that, taken together, may seem deeply troubling. First, <em>a bug in such a specification can wreck the validity of the whole proof effort</em>. Second, <em>these intermediate specifications can easily be much longer and more complex than the specifications of particular top-level programs</em>. Think of a book-length definition of a popular programming language compared against a one-page write-up about a limited-scope but important program.</p><p>There is further challenging subtlety here than just the chance to &#8220;get the spec wrong.&#8221; Often layers of a system will be formally verified using different approaches and tools, which do not share a specification language. A given specification may be written separately in the two languages, raising the specter of <em>inconsistency amongst what are meant to be two renderings of the same specification</em>.</p><p>How much harm could come from inconsistency? Let&#8217;s take a popular example of <em><a href="https://en.wikipedia.org/wiki/Undefined_behavior">undefined behavior</a></em> in programming languages. The idea here is that a language has rules that all programmers must follow, and breaking the rules &#8220;voids the warrantee&#8221; and allows the language implementation to behave however it likes. How could such a punitive contract be a good idea? The problem is that language implementors want to include automatic use of optimizations on behalf of programmers, but whether an optimization is safe to apply typically depends on aspects of program behavior that are <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">undecidable</a>, so the language implementation couldn&#8217;t possibly check for such a property without accidentally blocking programs that really do meet the requirements. The fix is to declare especially tricky program behaviors as undefined behavior, so the language implementation no longer needs to consider them.</p><p>For instance, if a program includes a sequence of 100 elements and the program tries to read the 101st element, that operation would be considered undefined behavior in <a href="https://en.wikipedia.org/wiki/C_(programming_language)">C</a> and related languages. The point is that reasonable programmers should agree that reading out-of-bounds in a sequence is a bug, and why should the language implementation be created to work around programmer bugs? Of course, the typical programmer rejoinder is that avoiding bugs is hard, and guard rails are appreciated! Nonetheless, languages like C are designed for such a performance-obsessed crowd that they tolerate the risk of undefined behavior.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!zJ0h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8e2c0d-2559-4920-a966-b31b43eda5c8_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!zJ0h!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8e2c0d-2559-4920-a966-b31b43eda5c8_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!zJ0h!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8e2c0d-2559-4920-a966-b31b43eda5c8_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!zJ0h!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8e2c0d-2559-4920-a966-b31b43eda5c8_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!zJ0h!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8e2c0d-2559-4920-a966-b31b43eda5c8_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!zJ0h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8e2c0d-2559-4920-a966-b31b43eda5c8_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5c8e2c0d-2559-4920-a966-b31b43eda5c8_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2937201,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/199261793?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8e2c0d-2559-4920-a966-b31b43eda5c8_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!zJ0h!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8e2c0d-2559-4920-a966-b31b43eda5c8_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!zJ0h!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8e2c0d-2559-4920-a966-b31b43eda5c8_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!zJ0h!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8e2c0d-2559-4920-a966-b31b43eda5c8_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!zJ0h!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c8e2c0d-2559-4920-a966-b31b43eda5c8_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>How does undefined behavior tie back to our risk of specification inconsistency between two adjacent layers? The trouble would be if the compiler and the software above it were proved against different definitions of what constitutes undefined behavior. Then the software above might stick to defined behavior by its own standards, yet some of that behavior might be considered undefined by the compiler, allowing it to misbehave arbitrarily. For instance, the application might assume that reading the 101st element of a sequence of length 100 returns some safe default value, whereas the compiler considers the behavior undefined and allows itself to make arbitrary changes to any code downstream of such an out-of-bounds access &#8211; including removing explicit safety checks that appeared in the application code. Moreover, the more layers we add, the more chances we have to make similar mistakes with interface inconsistency. Considering that accumulating layers is a key technique to manage complexity in engineering, it would be quite a shame to pick up a disincentive against it.</p><p>Do these risks doom the whole project of coordinated formal verification of different parts of a system?</p><h1>End-to-End Verification Pays Off</h1><p>No! In fact, adding additional layers at higher or lower levels can even <em>reduce</em> opportunities for uncaught specification mistakes. The next level of enlightenment is realizing that integrating the proofs of all layers of a system helps us catch <em>all consequential specification disagreements</em>. There could still be bugs in intermediate specifications, but if we manage to prove the system overall, then <em>those lingering bugs turned out not to matter for our top-level objectives</em>. If there were a serious-enough specification disagreement, then either the proof of the <em>provider</em> of that abstraction would fail <em>from below</em> (e.g. a thoroughly unrealistic promise isn&#8217;t actually realized in the code), or the proof of the <em>consumer</em> would fail <em>from above</em> (e.g. an assumption about the layer below is too weak to allow proof of this layer&#8217;s specification). A diagram can help explain what happens.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!SH5h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F180ddc06-7095-4711-af8b-8d65487d3f97_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!SH5h!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F180ddc06-7095-4711-af8b-8d65487d3f97_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!SH5h!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F180ddc06-7095-4711-af8b-8d65487d3f97_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!SH5h!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F180ddc06-7095-4711-af8b-8d65487d3f97_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!SH5h!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F180ddc06-7095-4711-af8b-8d65487d3f97_1024x1536.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!SH5h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F180ddc06-7095-4711-af8b-8d65487d3f97_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/180ddc06-7095-4711-af8b-8d65487d3f97_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1892148,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/199261793?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F180ddc06-7095-4711-af8b-8d65487d3f97_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!SH5h!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F180ddc06-7095-4711-af8b-8d65487d3f97_1024x1536.png 424w, /__u/substackcdn.com/image/fetch/$s_!SH5h!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F180ddc06-7095-4711-af8b-8d65487d3f97_1024x1536.png 848w, /__u/substackcdn.com/image/fetch/$s_!SH5h!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F180ddc06-7095-4711-af8b-8d65487d3f97_1024x1536.png 1272w, /__u/substackcdn.com/image/fetch/$s_!SH5h!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F180ddc06-7095-4711-af8b-8d65487d3f97_1024x1536.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The middle layers of the system have become <em><a href="https://en.wikipedia.org/wiki/Trusted_computing_base">untrusted</a></em> in the sense of computer security, meaning that lingering bugs can&#8217;t spoil the primary guarantees we are after. Not only do we not trust implementation artifacts like the compiler and CPU, but we also avoid trusting the specifications of the programming language or hardware instruction set. In mathematical parlance, they only show up in <a href="https://en.wikipedia.org/wiki/Lemma_(mathematics)">lemmas</a> used to prove the main theorem about the whole stack. If that theorem goes through, they don&#8217;t have fatal flaws in dimensions that it tracks (but <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">might in other dimensions</a>). A skeptical auditor need not even <em>read</em> those specifications to guard against violation of the top-level theorem.</p><p>The takeaway procedural message here is that, in doing end-to-end verification of a system stack within a single proof system, <em>only the top and bottom specification layers remain trusted</em>. In this way, we can often formally verify more-comprehensive systems with much <em>less</em> risk of misspecification than for less-comprehensive systems. By the way, this perspective is spelled out in more detail in <a href="https://adam.chlipala.net/papers/DeepSpecPT/">a position paper</a> from a broader project I was involved with. Another important aspect covered in that paper, and that I&#8217;ll return to in later posts, is the value of carrying out all proofs in a common formal system and tool ecosystem.</p><p>These lessons may generalize to problems of recursively self-improving superintelligences. Challenges in getting systems&#8217; top-level specifications right will remain, but we can sidestep worrying about properly encapsulated internals. The next post turns to one important potential objection: computing stacks have been formally verified assuming perfect knowledge of the lower-level abstractions they run on, while real-world AI agents will need to deal with uncertainty and even adversarial platforms that they must run on.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Intelligence Depends on Organizing Computation Correctly and Efficiently]]></title><description><![CDATA[A unifying outline of topics covered so far and where the blog is headed]]></description><link>https://stng.substack.com/p/intelligence-depends-on-organizing</link><guid isPermaLink="false">https://stng.substack.com/p/intelligence-depends-on-organizing</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 19 May 2026 13:03:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!J9m6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15a93629-5be6-45ce-b233-6db56bef6e96_533x533.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This post summarizes content so far in one framework, which may feel more coherent than the individual posts as they&#8217;ve been flying by. All hyperlinks in this post are to prior posts, so it also serves as a kind of index. I&#8217;ll go light on backing up some of the claims I make here. If you&#8217;re not convinced by a sentence, follow some of the nearby links for more.</p><p>It&#8217;s no controversial statement that, as artificial intelligence advances, the details of the computation underneath it matter a lot. My goal with this blog is to think through the design considerations from a new perspective. There are two main &#8220;thesis statement&#8221; framings that will drive the different topics we cover. They both sound anodyne on the surface, but I&#8217;ll be taking them further than most commentators do.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>Principle #1: the bidirectional interplay between correctness and efficiency (e.g. running time and power usage) should be central to designing the AI systems of the future.</strong> I&#8217;m arguing for a central role for <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a> in supporting more ambitious optimization of systems, as the details of optimizations grow past the point that humans can analyze reliably. By using engineering approaches that guarantee correctness, engineers are emboldened to experiment more rapidly with new ideas that improve performance; and then the performance of the tools for formal reasoning becomes an important enabler of a virtuous cycle.</p><p><strong>Principle #2: we miss critical opportunities for improvement when we look at systems as they exist today and assume that future systems will have roughly the same kinds of parts with the same local requirements as today.</strong> I&#8217;ll be arguing for significant changes to both computer hardware and programming languages, but I think it would be a mistake to stop there. We can expand the scope of the systems we are designing to what may be best summarized today as &#8220;society-level.&#8221; Fields like evolutionary psychology help us understand how humans function today as parts of such systems, leading to certain requirements on computer systems that are not fundamental and that can be beneficial to modify.</p><p>Let&#8217;s take a look at each principle in more detail.</p><h1>The Interplay Between Correctness and Efficiency</h1><p>This principle is going to be more of the usual kind that engineers propose to each other, without threatening professional identities as much as the next one does!</p><p>We can see all of scientific and engineering progress as <a href="/__u/stng.substack.com/p/our-social-world-as-a-distributed">one big distributed algorithm</a>, traditionally staffed by people but with AI increasingly taking over the ideation process. The self-referential process of building high-performance AI systems is a good example (and one that I will return to in later posts), with e.g. algorithmic breakthroughs by human researchers, coupled to automatic translation (e.g. by compilers) of those breakthroughs into low-level code. The boundary between the human and machine contributions is already shifting and may shift dramatically more, making it helpful to consider more broadly the process of finding and validating ideas.</p><p>In fact, the evolutionary process that created our brains to do most of the work can be seen as just one part of the same continuing optimization problem. The great challenge of an evolutionary system is getting fast-enough feedback on quality of new variants, whether they are organisms or new software programs. The phenomenon of <a href="/__u/stng.substack.com/p/signaling-is-programmable-evolution">signaling</a> from psychology and economics can be seen as a neat trick to get earlier high-fidelity feedback on individuals, though there are natural downsides to a convention of intentionally costly displays. An alternative way of moving high-fidelity feedback earlier is <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a>, which lets us evaluate variants in terms of mathematical proof about their behavior in all possible scenarios.</p><p><strong>Sometimes lack of confidence in a system optimization or other improvement holds us back from adopting it.</strong> <a href="/__u/stng.substack.com/p/cryptography-for-delegation-in-search">Cryptography</a> can help us overcome certain trust problems as ideas and code spread. However, I&#8217;m more focused on formal verification as a crucial enabler of adopting ideas, even when we have them ourselves but especially when they come from others we have reason to distrust.</p><p>In the first category, consider the example of <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">a recursively self-improving, highly parallel compiler</a>. It constantly invents new tricks to make itself faster and thus able to produce better programs within a given time budget, but how do we know it doesn&#8217;t modify itself in a way that compiles all programs into &#8220;kill all humans&#8221; agents? It is possible to prove that such a process maintains the original purpose of the compiler, through any number of improvement rounds.</p><p>In the second category, consider the example of mutually distrusting AI agents sharing code libraries with each other. The paradigm of <a href="/__u/stng.substack.com/p/proof-carrying-code-in-the-matrix">proof-carrying code</a> makes it possible to distribute code with proofs of fitness for purpose, security, and so on. AI agents can adopt new &#8220;brain modules&#8221; much more quickly and confidently than humans can, thanks to the chance to check them against the most exacting standards instantly, which is likely to be an important enabler of accelerated progress in science and engineering.</p><p><strong>Sometimes poor performance of formal verification limits how much we can achieve of the benefits I just sketched.</strong> For example, most of the student research projects I supervise at MIT wind up bottlenecked on the performance of <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">automated-theorem-proving tools</a>. There&#8217;s been a successful full-stack effort, from hardware through software programming tools, to enable machine-learning computation based on linear algebra. Formal verification deserves the same effort, and every level of the stack probably winds up looking interestingly different than GPUs and CUDA. I&#8217;ve written very little so far about the specifics I have in mind, but expect plenty of posts coming up.</p><h1>The Importance of Holistic Design</h1><p>Engineers will all agree that sometimes focusing in on one part of an existing system doesn&#8217;t leave enough degrees of freedom to meet some target for improvement. My proposal to reimplement the hardware-software stack to accelerate formal verification fits into that tradition, even as it remains speculative and therefore fair to be skeptical about. And, again, I&#8217;ll have plenty to write about details at this level, geeking out about <a href="/__u/stng.substack.com/p/hardware-software-codesign-and-autonomous">hardware-software codesign</a>. However, more controversially, I want to argue that we can realize even more improvement by broadening the scope of system we consider.</p><p>Here are some examples covered by full posts so far, moving up a ladder of abstraction from the physical world to broader cognition.</p><ul><li><p><a href="/__u/stng.substack.com/p/hardware-software-codesign-and-autonomous">Controlling self-driving vehicles</a> seems to involve hard problems of computer vision and more. However, we can circumvent those problems by changing the physical environment so that autonomous vehicles have their own dedicated lanes with intentionally simpler geometry.</p></li><li><p><a href="/__u/stng.substack.com/p/what-makes-language-processing-hard">Natural-language processing</a> seems fundamental to many compelling applications of AI. However, a future of AI agents can rely on synthetic languages that are much easier to process.</p></li><li><p><a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">AI coding assistants</a> solve hard problems in applying today&#8217;s popular programming languages to solve new programming challenges. However, we can make the problem much easier by changing the programming languages. (I am going to have a lot more to write in future posts on &#8220;the right way&#8221; to automate both software programming and digital hardware design, delivering strong correctness guarantees.)</p></li></ul><p>As we go up the ladder, evolutionary psychology starts being more helpful to understand the origins of the AI challenges we&#8217;re used to. <a href="/__u/stng.substack.com/p/what-makes-language-processing-hard">Natural language</a> is an especially pernicious example that evolution has shaped to be <em>hard on purpose</em> due to its use in signaling; we don&#8217;t need to choose engineering abstractions that are hard on purpose! A theme we&#8217;ll return to in many later posts is how we can harness an outside view of our own cognition and where it comes from to spot opportunities to simplify intelligence through bigger changes to how the world works.</p><p>I&#8217;ve also spent several posts on how a holistic-design approach reveals weaknesses of deep learning, the most-popular AI technique today. Its triumphs are based on its ability to <a href="/__u/stng.substack.com/p/deep-learning-the-ultimate-search">look up and combine prior art</a>, to solve new problems in consulting vast training sets of prior solutions. However, it has major weaknesses in <em>both</em> of the system dimensions I emphasized above. The <em>correctness</em> problems are well-known, given <a href="/__u/stng.substack.com/p/designing-decision-making-systems">the inscrutability of learned models</a> and thus the risks that they will make decisions that go against our wishes. The <em>efficiency</em> problem is right there in the word &#8220;deep,&#8221; indicating a required structure of computation that guarantees <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">long delays to answer prompts</a>, compounding multiplicatively as layers of additional functionality are added (despite the intensive effort to optimize the whole stack from algorithms to hardware, which has paid off much more for throughput than latency). I&#8217;ll be proposing a new approach or two that solve both problems, using the out-of-style symbolic mode of AI (sometimes cooperating with deep learning), in one of its most-visible modern garbs as formal verification.</p><p>But wasn&#8217;t that style discredited, with deep learning knocking its socks off in so many important domains? I argue that the hardest AI problems are disproportionately like the ones I listed above, where we have paths toward avoiding them through more-holistic system design. There the principle is that <strong><a href="/__u/stng.substack.com/p/codesign-for-legibility-to-ai-and">we should reconfigure the world for greater legibility to intelligence technologies with good properties</a></strong>. Some of the pushback will come from human nature, as people across the tech industry and elsewhere are reluctant to give up on <a href="/__u/stng.substack.com/p/signaling-and-perverse-adoption-of">hard problems and expensive solutions</a> that are helpful to signal competence and wealth. However, it&#8217;s worth overcoming those perverse incentives to push for lower-costs systems that deliver more-reliable answers.</p><h1>Next Steps</h1><p>My next arc of posts is going to cover the central ingredient of <em>specifications</em> for formal verification. It doesn&#8217;t help much to show that a system follows a specification that fails to cover our real objectives. I&#8217;ll review some examples from formal verification today, interleaved with scenarios that may feel more like sci-fi today but may be here before we know it.</p><p>Put differently: The first level of enlightenment is realizing the potential of formal verification to support rapid development of complex systems so that they are correct by construction. The second level of enlightenment (which luminaries of formal verification have realized and written about for decades) is noticing that systems must be proved against specifications, and the engineering of the specifications is not <em>obviously</em> more tractable than for the artifacts they apply to. The third level of enlightenment is realizing the suite of techniques that make dangerous specification mistakes easier to avoid than we might think, as I will explain in the coming posts.</p><p>Afterward, we can come back to considering how <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">extracting more parallelism</a> in computation may be one of the most important activities for the future of intelligent life in the universe, feeding a virtuous cycle of improving the formally assured intelligence that can improve itself.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Signaling and Perverse Adoption of Expensive AI]]></title><description><![CDATA[Watch out for hard problems and expensive solutions]]></description><link>https://stng.substack.com/p/signaling-and-perverse-adoption-of</link><guid isPermaLink="false">https://stng.substack.com/p/signaling-and-perverse-adoption-of</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 12 May 2026 12:14:43 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4f6a3961-93af-444f-9401-0a15627a8c4b_397x364.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;ve been making the case that today&#8217;s popular style of generative AI is fundamentally <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">slow</a> and <a href="/__u/stng.substack.com/p/designing-decision-making-systems">unreliable</a>. To unlock applicability of other styles (most importantly those based on symbolic reasoning and proof), I&#8217;ve also argued for a <a href="/__u/stng.substack.com/p/codesign-for-legibility-to-ai-and">different sort of learning loop</a>, where we go beyond repeatedly improving a model based on mistakes it makes, also making strategic changes to <em>the world and the problem formulation</em>, tending toward simplifying AI challenges. Examples include simplifying or avoiding <a href="/__u/stng.substack.com/p/what-makes-language-processing-hard">natural-language processing</a> (e.g. by using computer-oriented communication methods), <a href="/__u/stng.substack.com/p/hardware-software-codesign-and-autonomous">computer vision</a> (e.g. by rearranging environments to be more geometrically regular), and <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">challenging programming tasks</a> (e.g. by adopting better programming languages).</p><p>This perspective is so far from the mainstream that it isn&#8217;t even on a menu of possible positions that folks are used to being prepared to argue with. One natural hypothesis is that success in the real world fundamentally requires solving familiar hard AI problems, so we really need to stick with techniques like deep learning that have the best track record solving those problems. That hypothesis is compatible with an engineering mindset, where in building better artifacts, we may need to trade off between dimensions like generality, speed, and reliability &#8211; and deep learning&#8217;s success in generality justifies weaknesses in other dimensions.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>My subject in this post is how such claims may often be after-the-fact rationalizations. There are other reasons, grounded in evolutionary psychology, why we should expect the popular approach, epitomized by LLMs and the systems built on them, to be seductive. By surfacing those reasons, we can better inform ourselves to choose the right technology for each job. The key will be that familiar aspects of large-scale AI deployment are helpful to individuals looking to build status, in ways that create perverse incentives at odds with traditional engineering goals.</p><h1>Signaling: Expensive Displays</h1><p>I previously covered the phenomenon of <a href="/__u/stng.substack.com/p/signaling-is-programmable-evolution">signaling</a>, where animals perform costly displays of fitness, so that observers are convinced that they are worthy as mates, coalition partners, and so on. I presented signaling as a cool trick to accelerate evolution, where observers don&#8217;t have to wait for individuals to encounter rare situations where their skills can shine, since instead regular opportunities are created to show off the same skills in artificial circumstances. Having reliable information sooner helps evolutionary processes improve more quickly, by directing more resources to the most-promising individuals. Humans are particularly flexible in being able to learn new signaling games, which might not even have existed at their births, let alone in the bulk of our evolution before we converged into <a href="https://en.wikipedia.org/wiki/Early_modern_human">anatomically modern humans</a> only a few hundred thousand years ago. I suggested &#8220;programmable evolution&#8221; as a useful way to describe that flexibility.</p><p>A textbook example of signaling through conspicuous consumption is the <a href="https://en.wikipedia.org/wiki/Potlatch">potlach</a>, a kind of feast among the indigenous people of North America. At such a party, a tribal leader gives away or flat-out destroys many items considered valuable. The point is precisely that only a very rich leader or tribe could afford to part with so much wealth. In turn, the wealth is considered to have arisen through effectiveness in leadership and planning, producing a highly legible signal of leadership quality. We couldn&#8217;t trust a leader to give a speech <em>explaining</em> his triumphs. We all know how easy self-aggrandizement can be, picking and choosing topics. Instead, we need a signal that is <em>expensive to fake</em>, and what better than wanton destruction of objects that are known to require great coordination and talent to create?</p><p>This kind of social ritual is far from having disappeared among us. Think of a <em><a href="https://en.wikipedia.org/wiki/The_Great_Gatsby">Great Gatsby</a></em>-style mansion party, still built around conspicuous consumption and over-the-top hosting competency. A relatively recent study that I enjoyed was <em><a href="https://www.amazon.com/dp/B0824B49LS/?tag=adamchli-20">Very Important People: Status and Beauty in the Global Party Circuit</a></em>, which looks at rituals in nightclubs today.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!z-9G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febafbf0a-85eb-40c5-8f42-643eb181e1d9_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!z-9G!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febafbf0a-85eb-40c5-8f42-643eb181e1d9_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!z-9G!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febafbf0a-85eb-40c5-8f42-643eb181e1d9_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!z-9G!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febafbf0a-85eb-40c5-8f42-643eb181e1d9_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!z-9G!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febafbf0a-85eb-40c5-8f42-643eb181e1d9_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!z-9G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febafbf0a-85eb-40c5-8f42-643eb181e1d9_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ebafbf0a-85eb-40c5-8f42-643eb181e1d9_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2747840,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/197145483?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febafbf0a-85eb-40c5-8f42-643eb181e1d9_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!z-9G!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febafbf0a-85eb-40c5-8f42-643eb181e1d9_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!z-9G!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febafbf0a-85eb-40c5-8f42-643eb181e1d9_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!z-9G!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febafbf0a-85eb-40c5-8f42-643eb181e1d9_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!z-9G!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febafbf0a-85eb-40c5-8f42-643eb181e1d9_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The point is that we find easy analogies between old-school anthropology and wealth-signaling displays today. Signaling behavior around a variety of admirable qualities is pervasive in our world, for instance accounting for art as a way to signal cognitive ability. Now we can turn to the specifics of these phenomena around AI-powered systems.</p><h1>Difficult Problems and Expensive Solutions</h1><p>Let&#8217;s start by thinking about how elite software engineers build and maintain their status in the global tech industry. Imagine that an engineer has applied for a job, and the cornerstone of his portfolio is a totally new technology stack, from custom hardware on up, that he built to solve an important problem. On one level, we&#8217;re suitably impressed by his versatility. However, we also find it very hard to tell which parts of his work were <em>hard</em> &#8211; and of course we want to hire smart people who are good at solving hard problems. We know the popular technology stacks of today and which of their aspects require which skills to execute competently. Our job evaluating the candidate would be much easier if he picked one of the established areas to focus on.</p><p>Candidates appreciate this dynamic, perhaps not always fully consciously. With AI as the hottest area today, it is not only valuable for engineers to build up portfolios of AI work, but also it benefits them to choose among relatively small menus of &#8220;standard&#8221; AI problems that are widely understood by people who make hiring decisions. So now we have the most innocuous form of signaling dynamics leading to lock-in for choice of AI problems.</p><p>However, the effects are more perverse than that narrative suggests. Signaling games are more effective when they involve harder problems, so <em>the tech industry tends toward elite engineers choosing the hardest problems to work on</em>. This incentive exists even if <em>the hardest problems are not aligned with the best engineering solutions to real-world problems in any dimensions</em>, like cost, speed, or decision quality. Difficulty is valuable in its own right. Just to avoid the impression of taking potshots at one technical community from my own ivory tower in academia, I&#8217;ll mention that I have observed a similar dynamic in the world of programming languages, where many engineers in my circles prefer programming languages like <a href="https://en.wikipedia.org/wiki/Haskell">Haskell</a> and particularly abstract ways of using them that turn programming into <em>challenging puzzles</em>, applying more-complex code than is needed to solve a problem, for love of the mathematically grounded obstacles that must be overcome. A programmer with this mindset typically isn&#8217;t <em>consciously thinking</em> &#8220;I want to make my job harder,&#8221; but I argue that evolutionary dynamics explain why it would feel natural and fulfilling to seek out hard problems that most people can&#8217;t solve.</p><p>I also want to emphasize that current frontier AI work is doing amazing things, with highly successful efforts to solve hard problems in new ways delivering phenomenal value to society. Still, we should remain wary of the effect of signaling on incentives. We should also keep an eye out for the possibility to redesign systems at higher levels, so that lower levels no longer contain AI problems that are as challenging &#8211; as sad as it may feel to lose the opportunity to solve those problems heroically.</p><p>We&#8217;ve now gone two steps up the ladder of ways that signaling drives engineering choices, progressing through increasingly less noble-sounding root causes. The signaling we&#8217;ve covered so far takes place within relatively narrow specialist communities: engineers evaluating engineers. It can be an uphill battle to convince modern knowledge workers to forsake the valorization of solving hard problems, even if engineers will generally agree in the abstract that it is better to find ways to decompose a goal into subproblems that cost the least to solve. OK, but let me next consider another variety of signaling that stands in conflict with many of our stated values, where, while specialists may generate the signals, the signals can be evaluated by a general audience.</p><p>The last examples focused on costs from the labor of rare expert software engineers. Harder AI problems require paying more to rarer experts. However, another proxy for problem hardness is instructive: <em>the cost of hardware needed to implement competitive solutions</em>. Today&#8217;s token commodity in that category is the <a href="https://en.wikipedia.org/wiki/Graphics_processing_unit">GPU</a>, the cousin of <a href="https://en.wikipedia.org/wiki/Central_processing_unit">CPUs</a> that is the overwhelmingly popular choice for implementing <a href="https://en.wikipedia.org/wiki/Deep_learning">deep learning</a>. There is a striking convergence of prices for GPUs and <a href="https://paulgraham.com/brandage.html">luxury watches</a>, with popular models costing tens of thousands of dollars each (see sources for <a href="https://tech-insider.org/nvidia-blackwell-gpu-pricing/">GPUs</a> and <a href="https://www.coveted.com/discover/patek-philippe-watches">watches</a>). It&#8217;s probably the case that GPU prices are driven by genuine supply-chain challenges ramping up to serve the extraordinary demand, while high-end watch prices reflect intentional scarcity and extra features added precisely because they increase price. Still, we wind up with GPUs in a secondary role to signal <a href="https://en.wikipedia.org/wiki/Conspicuous_consumption">conspicuous consumption</a>, like works of art ceremonially destroyed at potlachs. That last statement can coexist with the great fit between GPUs and implementation of deep learning, which just helps hide the signaling motive, without reducing its potency.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!aB8F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc56226e-bf55-4422-aab0-167fc5e2da61_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!aB8F!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc56226e-bf55-4422-aab0-167fc5e2da61_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!aB8F!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc56226e-bf55-4422-aab0-167fc5e2da61_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!aB8F!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc56226e-bf55-4422-aab0-167fc5e2da61_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!aB8F!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc56226e-bf55-4422-aab0-167fc5e2da61_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!aB8F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc56226e-bf55-4422-aab0-167fc5e2da61_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cc56226e-bf55-4422-aab0-167fc5e2da61_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2727482,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/197145483?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc56226e-bf55-4422-aab0-167fc5e2da61_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!aB8F!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc56226e-bf55-4422-aab0-167fc5e2da61_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!aB8F!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc56226e-bf55-4422-aab0-167fc5e2da61_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!aB8F!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc56226e-bf55-4422-aab0-167fc5e2da61_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!aB8F!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc56226e-bf55-4422-aab0-167fc5e2da61_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Then we have the <a href="https://en.wikipedia.org/wiki/Data_center">data center</a>, overwhelmingly important today for housing GPUs. Naturally, the cost of a data center is significantly higher than the cost of just one computer inside it, creating an even more potent signal of wealth. Data centers also have a significant advantage for signaling to society at large. Only geeks know enough about GPUs to compare them and decide which are most impressive, beyond just looking at the price tag (which isn&#8217;t typically hanging off of the deployed GPU on a piece of string!). There can be a similar dynamic with luxury watches, where only a connoisseur can tell the difference between models of radically different price levels. However, a data center is a large facility consuming a large amount of electricity. It is very easy for members of the global elite across industries to understand that such an object must be expensive and indicate success by whatever organization owns it.</p><p>Across tech-company sizes, we can see a common dynamic of signaling with AI-hardware deployments. The biggest companies compete to announce larger and larger build-outs of data centers, as well as breakthrough solutions to ever-harder AI problems (connecting to the prior example of incentives to solve hard problems). Scrappy start-ups can go through hard times and then, after new success in sales or attracting investment, signal their success very clearly by buying GPUs. The cofounders feel a sense of relief that, in contrast to earlier periods when no one could tell if they were &#8220;for real,&#8221; now everyone can tell &#8220;they&#8217;ve really made it&#8221; when their GPU stockpiles are large enough. Release of <a href="https://en.wikipedia.org/wiki/Open-source_software">open-source software</a> or <a href="https://en.wikipedia.org/wiki/Open-source_artificial_intelligence#2020s:_Open-weight_and_open-source_generative_AI">open-weight models</a> can be a good signaling trick, too, if it&#8217;s clear that the artifacts could only have been produced by burning enough compute, for instance in training the model using your GPU farm.</p><p>By the way, even individual engineers can feel the call of more-expensive solutions in their daily work. There was quite a stir recently around the revelation of <a href="https://www.wsj.com/cio-journal/why-some-companies-say-ai-tokenmaxxing-is-key-to-survival-e699a128">tech companies maintaining internal leaderboards of, basically, which software engineers were spending the most on AI tools</a>. There is certainly a correlation between cost of AI services used to build some technical artifact and the inherent challenge (or business value) of building that artifact, but we can wind up in strange places if measuring and incentivizing just the former.</p><h1>Conclusion</h1><p>Engineering involves navigating trade-offs between dimensions like cost, speed, and accuracy. However, the signaling phenomenon I&#8217;ve outlined pushes tech-industry participants, often without realizing it consciously, to optimize perversely for focusing on <em>hard problems</em> (the spirit of engineering prefers to simplify problems) and <em>expensive solutions</em> (while <em>maximizing</em> cost is rarely part of a classical engineering trade-off). Participants from CEOs to junior engineers can build status, both within their specialist communities and in society at large, by affiliating with expensive solutions to hard problems. The pull is strongest for problems and solutions that are <em>obviously hard or expensive</em> to a broad educated audience, and we should work to counteract that pull.</p><p>Evolution has left us with many bad habits &#8211; or ways of thinking that are clearly misaligned with modern life. For instance, we learn as kids that it is not a shrewd move to adopt the all-candy diet, even if our ancestors 100,000 years ago encountered sugar so rarely that they always won by consuming as much as they could find. Today&#8217;s engineered systems are vastly more complex than anything those ancestors dealt with, weakening the relevance of their instincts to signal success by displaying expensive solutions to hard problems. We should follow the true spirit of engineering and always appreciate a chance to <a href="/__u/stng.substack.com/p/codesign-for-legibility-to-ai-and">simplify a problem by changing a system design at a higher level</a>. Sometimes simplifying the world is itself an engineering challenge, and we should watch out for perverse incentives in choosing to do it, but often the investment of changing the world pays off in simpler engineering subproblems ever after.</p><p>Deep learning and friends are especially likely to excel at hard problems produced by evolution that we can work around today, as I will explore in considering how the compute stack should be different to take advantage of problems with elegant logical structure. If everything goes well, we won&#8217;t need to depend anymore on computer-hardware-world equivalents of luxury watches! It won&#8217;t hurt that we get more-reliable systems as a bonus, in a world with more of our economy handed off to AI agents in a carefully curated ecosystem.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Codesign for Legibility (to AI and Everyone Else)]]></title><description><![CDATA[Sometimes all it takes is changing the world.]]></description><link>https://stng.substack.com/p/codesign-for-legibility-to-ai-and</link><guid isPermaLink="false">https://stng.substack.com/p/codesign-for-legibility-to-ai-and</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 05 May 2026 13:04:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!SLl0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70413a4e-6dcf-462d-86cd-1b0836490b6f_1506x817.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The last few posts have covered how, while today&#8217;s mainstream ideas in generative AI <a href="/__u/stng.substack.com/p/deep-learning-the-ultimate-search">have phenomenal capabilities in searching large data sets</a>, they have serious downsides in both <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">how long they take to return answers</a> and <a href="/__u/stng.substack.com/p/designing-decision-making-systems">how reliable those answers are</a>. It&#8217;s natural to expect that approaches fall on a trade-off spectrum, and if some approach becomes very popular, it must score very well for at least one of speed or answer reliability, so it may be surprising that the reigning style has issues in both dimensions. I <a href="/__u/stng.substack.com/p/designing-decision-making-systems">briefly started making the case</a> that more symbolic, logic-based methods have promise to address both complaints. So why aren&#8217;t such methods taking over the world already?</p><p>The straightforward answer is that, so far, they&#8217;ve demonstrated dramatically worse answer quality on most problems of high interest today. If we take a quick survey of popular applications of AI, we&#8217;ll find deep learning and friends way out in front on each one. But does that summary really imply that the future is centered on statistical machine learning? I&#8217;m going to present an alternative framework that justifies an answer of &#8220;no,&#8221; though first I want to summarize a more mainstream framework.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Predictive Coding</h1><p><a href="https://en.wikipedia.org/wiki/Predictive_coding">Predictive coding</a> is a theory of intelligence that is popular with people thinking about powerful AI. Roughly, the theory of predictive coding encourages us to go beyond simplistic models that assume our senses perceive the objective truth of the world directly. Rather, instead our brains need to develop fairly detailed internal <em>models</em> of the world, and we can integrate sensory inputs only with respect to models, finding what model-compatible world state best matches the inputs. When we notice bad results from our current models, we update them by considering the details of what goes wrong, much like how training deep-learning models works with <a href="https://en.wikipedia.org/wiki/Backpropagation">backpropagation</a> to reverse-engineer inaccurate decisions into the right changes to model parameters.</p><p>This diagram shows the basic idea in a learning loop. The observer fine-tunes his world model to help him better perceive a vase. Cases where the model makes bad predictions at odds with new inputs trigger modifications to the model.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!SLl0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70413a4e-6dcf-462d-86cd-1b0836490b6f_1506x817.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!SLl0!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70413a4e-6dcf-462d-86cd-1b0836490b6f_1506x817.png 424w, /__u/substackcdn.com/image/fetch/$s_!SLl0!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70413a4e-6dcf-462d-86cd-1b0836490b6f_1506x817.png 848w, /__u/substackcdn.com/image/fetch/$s_!SLl0!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70413a4e-6dcf-462d-86cd-1b0836490b6f_1506x817.png 1272w, /__u/substackcdn.com/image/fetch/$s_!SLl0!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70413a4e-6dcf-462d-86cd-1b0836490b6f_1506x817.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!SLl0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70413a4e-6dcf-462d-86cd-1b0836490b6f_1506x817.png" width="1456" height="790" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/70413a4e-6dcf-462d-86cd-1b0836490b6f_1506x817.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:790,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1126319,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/196262975?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70413a4e-6dcf-462d-86cd-1b0836490b6f_1506x817.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!SLl0!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70413a4e-6dcf-462d-86cd-1b0836490b6f_1506x817.png 424w, /__u/substackcdn.com/image/fetch/$s_!SLl0!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70413a4e-6dcf-462d-86cd-1b0836490b6f_1506x817.png 848w, /__u/substackcdn.com/image/fetch/$s_!SLl0!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70413a4e-6dcf-462d-86cd-1b0836490b6f_1506x817.png 1272w, /__u/substackcdn.com/image/fetch/$s_!SLl0!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70413a4e-6dcf-462d-86cd-1b0836490b6f_1506x817.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Why we do find ourselves in situations where modeling phenomena of interest is very challenging? I&#8217;ll focus on one broad kind of mechanism: when those phenomena are <em>produced by evolutionary processes that don&#8217;t optimize for legibility</em>. That is, some evolutionary process provides feedback on intermediate designs, but it doesn&#8217;t penalize designs that are hard to understand.</p><p>Even if we were optimizing explicitly for legibility, we could find evolution getting stuck in local optima. The reason is that evolution proceeds through small changes, each of which needs to improve fitness in at least some small way, otherwise a variant would be discarded. There may exist radically more legible redesigns that nonetheless can&#8217;t be reached through sequences of small steps that all improve legibility and/or whatever other objectives. (Maybe we find a path of gradually increasing legibility that reduces real-world practicality at intermediate points, even though practicality spikes upward by the end.)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!dDhL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfcbef8-ef86-45f9-ab81-1d36ce7e71d6_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!dDhL!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfcbef8-ef86-45f9-ab81-1d36ce7e71d6_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!dDhL!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfcbef8-ef86-45f9-ab81-1d36ce7e71d6_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!dDhL!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfcbef8-ef86-45f9-ab81-1d36ce7e71d6_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!dDhL!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfcbef8-ef86-45f9-ab81-1d36ce7e71d6_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!dDhL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfcbef8-ef86-45f9-ab81-1d36ce7e71d6_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0dfcbef8-ef86-45f9-ab81-1d36ce7e71d6_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2653488,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/196262975?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfcbef8-ef86-45f9-ab81-1d36ce7e71d6_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!dDhL!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfcbef8-ef86-45f9-ab81-1d36ce7e71d6_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!dDhL!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfcbef8-ef86-45f9-ab81-1d36ce7e71d6_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!dDhL!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfcbef8-ef86-45f9-ab81-1d36ce7e71d6_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!dDhL!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dfcbef8-ef86-45f9-ab81-1d36ce7e71d6_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s not just biological evolution that can exhibit this problem. We can also see it in deliberately engineered systems, through viewing <a href="/__u/stng.substack.com/p/our-social-world-as-a-distributed">ourselves as a distributed system for finding better technical ideas</a>. I wrote previously about <a href="/__u/stng.substack.com/p/signaling-is-programmable-evolution">signaling as an optimization for such systems</a>, where participants go out of their ways to show off their otherwise-hidden fitness qualities through costly displays, to provide earlier signal that helps the optimization algorithm prune unpromising paths. The presence of signaling can actually lead toward optimizing (parts of) systems for <em>worse</em> legibility, to provide opportunities for particularly exaggerated displays of competence.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!xDk_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe25f2a6e-6bb9-4e16-95f6-0c4977bc7ab6_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!xDk_!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe25f2a6e-6bb9-4e16-95f6-0c4977bc7ab6_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!xDk_!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe25f2a6e-6bb9-4e16-95f6-0c4977bc7ab6_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!xDk_!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe25f2a6e-6bb9-4e16-95f6-0c4977bc7ab6_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!xDk_!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe25f2a6e-6bb9-4e16-95f6-0c4977bc7ab6_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!xDk_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe25f2a6e-6bb9-4e16-95f6-0c4977bc7ab6_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e25f2a6e-6bb9-4e16-95f6-0c4977bc7ab6_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2742867,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/196262975?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe25f2a6e-6bb9-4e16-95f6-0c4977bc7ab6_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!xDk_!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe25f2a6e-6bb9-4e16-95f6-0c4977bc7ab6_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!xDk_!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe25f2a6e-6bb9-4e16-95f6-0c4977bc7ab6_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!xDk_!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe25f2a6e-6bb9-4e16-95f6-0c4977bc7ab6_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!xDk_!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe25f2a6e-6bb9-4e16-95f6-0c4977bc7ab6_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The upshot is that we may very well have wound up with a variety of canonical AI problems that seem, with respect to our current knowledge, to be <em>irreducibly complex</em>: where only the kind of large, unstructured model produced by deep learning can deliver good-enough decisions. We could even take a cue from <a href="https://en.wikipedia.org/wiki/Kolmogorov_complexity">Kolmogorov complexity</a> and <em>define</em> complexity of a problem in terms of <em>the length of the shortest model that understands it well enough</em>. <a href="https://pieces.app/blog/llm-parameters?utm_source=chatgpt.com">The latest foundation models are described in terabits of weights</a> &#8211; where &#8220;tera&#8221; means 10 to the 12th. On the one hand, we can celebrate the engineering achievement of training models that have so much relatively unstructured complexity to them and recognize that complex descriptions are probably necessary to understand a variety of important phenomena. On the other hand, more-complex models tend to be more expensive to find and execute. What both predictive coding and the practice of machine learning share is <em>learning via loops that tend to increase complexity</em>: as a model is better-and-better fitted to an underlying phenomenon, the model gets more complex, or it converges to better results because there was complexity inherent in its architecture from the start. What if we extended such loops so that they could also include steps that by design <em>reduce complexity</em>?</p><h1>Codesign for Legibility</h1><p>It&#8217;s largely taken for granted today that the way to make progress in the face of challenging reasoning problems is to improve AI systems. However, another technique can be even more powerful: changing problems to be easier to solve. The revised problems can be better fits for AI approaches with superior properties in speed and reliability. <a href="/__u/stng.substack.com/p/designing-decision-making-systems">Classical rule-based systems</a> don&#8217;t just take advantage of well-defined logical structure when it exists; they often also fail completely in domains where such structure is not known. Can we redesign systems at a higher level to help structure become clear?</p><p>I wrote previously about <a href="/__u/stng.substack.com/p/hardware-software-codesign-and-autonomous">codesign with the example of autonomous vehicles</a>. The broader idea is that we can make AI problems simpler by changing the contexts they operate in. Using that idea, we can take the predictive-coding world of a learning loop and transform it into a codesign loop that alternates between steps of learning and changing the world being learned, with an eye toward improved legibility, or ease of learning.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!rtxd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a491e5-4498-45ae-927d-50e2faa07e80_1675x879.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!rtxd!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a491e5-4498-45ae-927d-50e2faa07e80_1675x879.png 424w, /__u/substackcdn.com/image/fetch/$s_!rtxd!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a491e5-4498-45ae-927d-50e2faa07e80_1675x879.png 848w, /__u/substackcdn.com/image/fetch/$s_!rtxd!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a491e5-4498-45ae-927d-50e2faa07e80_1675x879.png 1272w, /__u/substackcdn.com/image/fetch/$s_!rtxd!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a491e5-4498-45ae-927d-50e2faa07e80_1675x879.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!rtxd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a491e5-4498-45ae-927d-50e2faa07e80_1675x879.png" width="1456" height="764" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/64a491e5-4498-45ae-927d-50e2faa07e80_1675x879.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:764,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1482115,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/196262975?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a491e5-4498-45ae-927d-50e2faa07e80_1675x879.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!rtxd!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a491e5-4498-45ae-927d-50e2faa07e80_1675x879.png 424w, /__u/substackcdn.com/image/fetch/$s_!rtxd!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a491e5-4498-45ae-927d-50e2faa07e80_1675x879.png 848w, /__u/substackcdn.com/image/fetch/$s_!rtxd!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a491e5-4498-45ae-927d-50e2faa07e80_1675x879.png 1272w, /__u/substackcdn.com/image/fetch/$s_!rtxd!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a491e5-4498-45ae-927d-50e2faa07e80_1675x879.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Returning to our idea of measuring complexity in terms of bit counts needed to describe the world, we are now combining steps that refine models, which may indeed incorporate additional bits; and steps that simplify the world, which <em>actually reduce complexity of effective models when applied properly</em>. This framing suggests a very different perspective than celebrating engineering that enables learning many bits. Instead, we see progress as coming from changing the world to require as few bits to describe as we can get away with. Such compression of knowledge comes from <em>structure</em> that maps well to the world, which can in turn support crisp <em>guarantees</em>. This next stylized graph shows how alternating these kinds of changes helps us wiggle description complexity downward. Even after investing in more-complex models, we can find paths back to simplicity, guided by what would help the models, through world simplification.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!yOBn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe2ab330-e463-4bc8-be3f-825a22484d7e_1455x891.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!yOBn!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe2ab330-e463-4bc8-be3f-825a22484d7e_1455x891.png 424w, /__u/substackcdn.com/image/fetch/$s_!yOBn!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe2ab330-e463-4bc8-be3f-825a22484d7e_1455x891.png 848w, /__u/substackcdn.com/image/fetch/$s_!yOBn!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe2ab330-e463-4bc8-be3f-825a22484d7e_1455x891.png 1272w, /__u/substackcdn.com/image/fetch/$s_!yOBn!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe2ab330-e463-4bc8-be3f-825a22484d7e_1455x891.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!yOBn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe2ab330-e463-4bc8-be3f-825a22484d7e_1455x891.png" width="1455" height="891" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fe2ab330-e463-4bc8-be3f-825a22484d7e_1455x891.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:891,&quot;width&quot;:1455,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:645120,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/196262975?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe2ab330-e463-4bc8-be3f-825a22484d7e_1455x891.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!yOBn!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe2ab330-e463-4bc8-be3f-825a22484d7e_1455x891.png 424w, /__u/substackcdn.com/image/fetch/$s_!yOBn!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe2ab330-e463-4bc8-be3f-825a22484d7e_1455x891.png 848w, /__u/substackcdn.com/image/fetch/$s_!yOBn!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe2ab330-e463-4bc8-be3f-825a22484d7e_1455x891.png 1272w, /__u/substackcdn.com/image/fetch/$s_!yOBn!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe2ab330-e463-4bc8-be3f-825a22484d7e_1455x891.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>From this perspective, <strong>we should change the world to remove challenging AI problems as far as possible,</strong> guided by experience building earlier generations of systems. Here are a few examples of opportunities of this kind, most of which I covered in earlier posts, where I highlight examples of evolutionary dynamics leading to environments that are harder than necessary for intelligent agents. Each example identifies a hard problem associated with AI and finds a way to replace it with a better-structured alternative that streamlines automation. I&#8217;m going to cover these suggestions in increasing order of controversy or effort to reconfigure the world.</p><ol><li><p>One good example has already been adopted widely in software engineering. The first <a href="https://en.wikipedia.org/wiki/Web_application">web applications</a> were designed just to be used directly by humans with browser <a href="https://en.wikipedia.org/wiki/Graphical_user_interface">GUIs</a>. However, soon-enough some users wanted programs to access web applications on their behalfs. Initial efforts involved unpleasant engineering approaches like <a href="https://en.wikipedia.org/wiki/Web_scraping">scraping</a>, which required software to understand both natural language and visual layout. Eventually the owners of many web applications started offering <a href="https://en.wikipedia.org/wiki/Web_API">web APIs</a>, ways of accessing the same services in ways friendlier to automated understanding, requiring solving exactly no problems considered &#8220;AI.&#8221;</p></li><li><p><a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">Software programming is a domain where we are in control</a>, with humans having deliberately designed the programming languages and other tools. Programming languages have always been designed to make programs easier for humans to understand, though inertia leaves in-place some bad design ideas. There is even some signaling going on, where language designers sometimes include complexities because they introduce puzzles that programmers enjoy solving. Instead of sticking with languages that happened to have many examples included in the first big LLM training runs, we should change the way programming works so that AI has an easier time spotting bugs and so on.</p></li><li><p><a href="/__u/stng.substack.com/p/hardware-software-codesign-and-autonomous">We should change the environments that autonomous vehicles inhabit</a> to simplify vision and other problems relevant to effective control. Instead of roads full of unpredictable phenomena, in some settings, a model more like subway tunnels is appropriate. Today&#8217;s road network evolved with human drivers in mind, not considering the possibilities for cost savings through standardization and simplification.</p></li><li><p>Now gradually ramping up in speculative nature of proposals, <a href="/__u/stng.substack.com/p/what-makes-language-processing-hard">moving away from use of natural language will simplify many relevant problems</a>. As more of the economy is dominated by AI agents, they will have options beside natural language for coordinating with each other. Natural languages are creaky machines that were shaped by evolutionary processes that didn&#8217;t select strongly for lack of ambiguity or simplicity of processing. In fact, signaling pushes toward more-complex language that can be used to show off cognitive ability. Protocols for communication by AI agents needn&#8217;t maintain any of that baggage. (Actually, the prior example of adoption of web APIs is an early case of this principle reduced to practice very effectively!)</p></li><li><p>I can&#8217;t resist dropping in one more idea that is quite speculative, which you can take or leave, independently of buying into this broader framework of codesign. Biology is full of mysteries, which are mysterious to our puny brains because, with the possible minute exception of the most-recent past, there hasn&#8217;t been evolutionary pressure towards organisms being able to understand their own workings. We can keep working on reverse-engineering our evolved mechanisms, but the long run may see even better results from replacing parts of ourselves. For instance, artificial replacement organs may follow engineering best practices and be easier to understand and optimize than natural organs.</p></li></ol><p>The general approach, of an improvement loop that combines learning and modification of the phenomenon to learn, is an underappreciated secret weapon on the path to effective intelligent systems. We&#8217;re considering the word &#8220;system&#8221; in a broad sense that keeps the above codesign examples in-scope.</p><h1>Consequences for Feasible Automated Understanding</h1><p>It may be that today&#8217;s canonical AI problems require learning mathematical functions of seemingly irreducible complexity, making logic-based methods fundamentally inapplicable. However, by changing the world so that it exposes different decision problems, we can make logic-based reasoning competitive. By giving the world legible structure, we enable methods that thrive on structure, potentially enjoying benefits for both <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">performance</a> and <a href="/__u/stng.substack.com/p/designing-decision-making-systems">explainability and mathematical guarantees broadly</a>. Two of the major categories for upcoming posts are (1) more specifics of how the world can and should be different to support effective automated reasoning and (2) the right architecture of those reasoning systems that take advantage of structure, looking across the whole stack of hardware and software. Pulling on these threads will take us in a pretty-different direction from the industry consensus.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Designing Decision-Making Systems to Help Trust Their Answers]]></title><description><![CDATA[Deep learning's disadvantage compared to an unpopular cousin]]></description><link>https://stng.substack.com/p/designing-decision-making-systems</link><guid isPermaLink="false">https://stng.substack.com/p/designing-decision-making-systems</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 28 Apr 2026 12:30:48 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/018fb02d-ecf2-401b-8dd3-ce9f99df7ca2_421x195.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This post is the last in my trio situating deep learning in terms of strengths and weaknesses, relevant to building the most trustworthy systems for automatic decision-making. My positive take was that <a href="/__u/stng.substack.com/p/deep-learning-the-ultimate-search">deep learning is a natural and powerful generalization of search engines</a>, working most effectively when we use it to find and combine prior examples related to some goal. My first major negative take was that <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">deep learning is inherently slow</a>, due to the requirements it creates for many steps of computation to happen in-order. I&#8217;ll wrap up now considering challenges in believing that systems built on deep learning (and a variety of other flavors of machine learning) produce reliable answers.</p><h1>From Training Data to Parameters</h1><p>I <a href="/__u/stng.substack.com/p/deep-learning-the-ultimate-search">suggested previously</a> that deep learning is better-understood in analogy to search engines than to reasoning engines. It typically succeeds in proportion to its ability to find examples it already knows about that are related to a request. However, it is not just memorizing examples. We covered how it generalizes solving for <em>m</em> and <em>b</em> in the equation <em>y = mx + b</em> from algebra class. The difference is that instead of just those two parameters, foundation models can get up to hundreds of billions of parameters today!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The double-edged sword is that, while so much information or even insight can be encoded in so many parameters, it is an uphill battle to extract <em>structure</em> from learned parameters, an obstacle to deriving mathematical <em>guarantees</em>. This general pursuit for AI is called <a href="https://en.wikipedia.org/wiki/Explainable_artificial_intelligence">explainability</a>. A good intuition is that, when the training methods that learn parameters aren&#8217;t designed around deliberate structure, more work is required to find structure (and thus convincing explanations) after-the-fact.</p><p>One category of explainability for deep learning analyzes which parts of a prompt influence the final answer significantly. This kind of analysis already doesn&#8217;t explain <em>how</em> the relevant parts of the question informed the answer, but it&#8217;s a good start. However, such analysis suffers from classic challenges of <a href="https://en.wikipedia.org/wiki/Software_testing">software testing</a>: when we only evaluate a program on a particular set of inputs, it is hard to build confidence about possible behavior on <em>all</em> inputs. We may have neglected to test a <a href="https://en.wikipedia.org/wiki/Corner_case">corner case</a> that matters in some important scenario (or even many and frequent scenarios that escaped our imagination). That risk is serious-enough in a setting where all users have good intentions. In a cybersecurity setting where an adversary is doing his best to drive the software to bad behavior, we must assume that the adversary finds exactly the input that will trigger the worst behavior.</p><p>In a deep neural net, we can imagine corner cases in the form of weights (parameters) that have little influence in the questions being asked during evaluation but that turn out to matter for other important questions. No matter how good of a job we do explaining what parts of a question influenced the answer, we can&#8217;t be sure that future answers won&#8217;t have rather-different, problematic explanations. This example is inspired by <a href="https://en.wikipedia.org/wiki/Adversarial_machine_learning">adversarial examples and backdoor attacks in machine learning</a>, where realistic failures would involve many weights being moderately off, though I simplify in the diagram to a single problematic weight.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!lLr0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0dd051b-1b3a-4cb8-a308-b8390805c294_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!lLr0!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0dd051b-1b3a-4cb8-a308-b8390805c294_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!lLr0!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0dd051b-1b3a-4cb8-a308-b8390805c294_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!lLr0!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0dd051b-1b3a-4cb8-a308-b8390805c294_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!lLr0!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0dd051b-1b3a-4cb8-a308-b8390805c294_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!lLr0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0dd051b-1b3a-4cb8-a308-b8390805c294_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c0dd051b-1b3a-4cb8-a308-b8390805c294_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1549275,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/195554790?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0dd051b-1b3a-4cb8-a308-b8390805c294_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!lLr0!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0dd051b-1b3a-4cb8-a308-b8390805c294_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!lLr0!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0dd051b-1b3a-4cb8-a308-b8390805c294_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!lLr0!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0dd051b-1b3a-4cb8-a308-b8390805c294_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!lLr0!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0dd051b-1b3a-4cb8-a308-b8390805c294_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Continuing the march through analogues of classic software-quality techniques, we find interesting analogies with <a href="/__u/stng.substack.com/p/proof-carrying-code-in-the-matrix">compiler verification</a> as I discussed it previously. With that subject matter of <a href="https://en.wikipedia.org/wiki/Compiler">compilers</a>, programs that translate between computer languages, the goal is to confirm that translation preserves behavior/meaning. I explained that one approach is <em>certifying compilation</em>, where every run of the compiler outputs not just a translated program but also a <em>certificate</em> of some kind that translation was carried out correctly. One very-flexible kind of certificate is a <em>mathematical proof</em>. That style of certifying explanation is being explored by many teams now not just for its &#8220;obvious&#8221; application in getting AI to do math but also in <a href="/__u/stng.substack.com/p/codesign-for-ai-and-programming">getting AI to write correct code</a>, which could be accompanied by proof of correctness. It remains a niche approach today (e.g., there&#8217;s no similar mechanism applied by LLMs to explain arbitrary responses), though a variety of more-targeted projects involve different notions of certificates and their checkers.</p><p>I can give one U.S.-centric analogy for the nature of certificates. U.S. taxpayers need to submit annual <a href="https://en.wikipedia.org/wiki/Tax_return">tax returns</a> where they don&#8217;t just declare how much they owe in taxes but also lay out, sometimes in excruciating detail across many forms, the calculations that justify their answers. A certificate is like that kind of &#8220;showing your work,&#8221; referencing mechanized rules instead of the United States tax code. A given tax return impinges on just a tiny slice of the total tax code, allowing relatively cheap auditing of any given tax return, though a search for a taxpayer&#8217;s ideal tax-return strategy could explore many parts of the law that turn out not to be relevant (i.e., some <em>could</em> be used but not in ways that reduce tax owed).</p><p>The following diagram shows how a single defect in the model leads both to a wrong answer and a flaw in the certificate. A checker that flags the latter helps us avoid proceeding with the former, though in a way that leaves us without a clear alternative.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!eQ2P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684abf34-7717-41a7-8673-ec8a74b38de7_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!eQ2P!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684abf34-7717-41a7-8673-ec8a74b38de7_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!eQ2P!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684abf34-7717-41a7-8673-ec8a74b38de7_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!eQ2P!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684abf34-7717-41a7-8673-ec8a74b38de7_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!eQ2P!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684abf34-7717-41a7-8673-ec8a74b38de7_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!eQ2P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684abf34-7717-41a7-8673-ec8a74b38de7_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/684abf34-7717-41a7-8673-ec8a74b38de7_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1638131,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/195554790?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684abf34-7717-41a7-8673-ec8a74b38de7_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!eQ2P!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684abf34-7717-41a7-8673-ec8a74b38de7_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!eQ2P!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684abf34-7717-41a7-8673-ec8a74b38de7_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!eQ2P!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684abf34-7717-41a7-8673-ec8a74b38de7_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!eQ2P!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F684abf34-7717-41a7-8673-ec8a74b38de7_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I should also briefly mention LLM-associated techniques called <a href="https://en.wikipedia.org/wiki/Prompt_engineering#Chain-of-thought">chain-of-thought</a>, where models are guided through spelling out intermediate steps in finding their answers; and <a href="https://en.wikipedia.org/wiki/Prompt_engineering#Self-consistency">self-consistency</a>, producing multiple chains of thought and choosing as &#8220;winner&#8221; the answer appearing most frequently. To the extent these techniques write natural language and remain subject to the vagaries of LLM randomness, they still don&#8217;t help produce strong guarantees. Variants using formal languages converge toward generating formal proofs.</p><p>Certifying algorithms (and we could charitably view chain-of-thought as a special case) have common strengths and weaknesses. The key strength is that it is often much easier to demonstrate that a single answer is correct than to demonstrate that a system only ever outputs correct answers. This benefit can translate into lower engineering costs to build a decision engine. A counteracting weakness is the inherent potential for unpleasant surprises: a given run of the certifying algorithm may eventually output an <em>invalid</em> certificate, which fails independent checking. For instance, a certificate may be a math proof carried out in a series of steps, and one of the steps turns out not to follow from the previous deductions, after all. Then what is the user to do? The result is practically indistinguishable from the decision program running forever or crashing, neither of which tends to go over well with users. The system winds up in an indeterminate state, unable to commit to an answer. Considering AI broadly, it is not always the case that we have a safe default action to take, when a decision engine fails to make a recommendation. For instance, we may be driving an aerial vehicle in tricky weather, dependent on constant clever decision-making to avoid a <em>literal</em> crash. In those settings, reaching an indeterminate state is itself a failure.</p><p>For many reasonable notions of certificates, it remains unclear if deep learning will evolve to produce them at all, for problems that are sufficiently complex and novel. Sometimes finding the certificate is itself the hard part, e.g. looking for proofs of longstanding mathematical conjectures. Even if deep learning <em>can</em> be scaled to produce a certain kind of certificate, it may take unreasonably long to do so. For instance, one easy upgrade for such an engine is to add a loop that checks certificates coming out, restarting the system every time checking fails (perhaps with new prompting about what went wrong last time, to help avoid a repeat). In the worst case, such a system will run forever on hard-enough inputs. Even if it does find a certifiable answer eventually, computational cost can easily balloon with this approach, and these retry costs should be considered a special case of <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">what I highlighted in a previous post</a> about how top-level &#8220;agentic loops&#8221; can lead to very long delays in producing final answers. Our earlier example of control software for an aerial vehicle is a good one, where we may be able to afford neither long delays nor fallback to simple defaults; and it is not hard to find other domains where faster specialized answers at least provide clear economic value.</p><p>The counterpart from compiler verification is <em>certified compilers</em>, where a mathematical proof shows that a compiler behaves properly <em>for all possible inputs</em>. Constructing such a proof can be much harder, but it saves us from worrying about unpleasant surprises on new inputs. Compiler verification has a decent analogy to <a href="https://en.wikipedia.org/wiki/Mechanistic_interpretability">mechanistic interpretability</a> for AI, which reverse-engineers machine-learning models into human-meaningful explanations, but the foundations of this field are still being established. In the mean time, we might also wonder about how other approaches to decision-making are more suited to proven guardrails.</p><p>Our goal will be to avoid needing to catch reasoning errors after-the-fact at all. Instead, we want to take advantage of system structure to make reasoning errors impossible.</p><h1>Good Old-Fashioned AI</h1><p>Deep learning and its closest relatives are contrasted with <a href="https://en.wikipedia.org/wiki/GOFAI">good old-fashioned AI (GOFAI)</a>, a cheeky name for <a href="https://en.wikipedia.org/wiki/Symbolic_artificial_intelligence">symbolic AI</a>. Whatever we call it, this older approach is centered on formal logic and other symbolic ways of representing reasoning, more in the style we&#8217;re used to from working out math derivations on blackboards. A particularly influential style is <a href="https://en.wikipedia.org/wiki/Expert_system">expert systems</a>, which apply domain-specific logical rules to solve new problems. It turns out that style can avoid the challenges we just surveyed around getting stuck in indeterminate states or facing expensive checking of answers. You&#8217;ve probably heard about how thoroughly out-of-style rule-based systems are today, and we&#8217;ll come back to that infamous history, but let me review first what kind of technology we are talking about. Later posts will get into relevant and interesting developments since expert systems fell out-of-favor, including advancements in programming tools and hardware, plus the chance to take advantage of statistical machine learning where its weaknesses are less relevant.</p><p>This kind of expert system is based on rules that deduce new facts from those already known. For instance, here is a set of rules that could be applied by venture capitalists to decide on valuations for AI startups.</p><pre><code><code>RULE: Add $1M to the valuation for every occurrence of the word "agentic" in the pitch deck.
RULE: If person P has a LinkedIn profile that lists employment at company C, then consider that P worked for C.
RULE: If a cofounder has worked at a major AI company, add $5M to the valuation.
RULE: If the product has probability R of destroying humanity, add $10M/(1 - R) to the valuation.</code></code></pre><p>To run such a <a href="https://en.wikipedia.org/wiki/Logic_programming">logic program</a>, we can start with a set of known facts (like the contents of cofounders&#8217; LinkedIn profiles) and keep deducing new facts via our rules until no more follow. At the end, we sum up all the incremental amounts that have been deduced.</p><p>It is readily apparent how a simpler explainability approach applies to this kind of reasoning system. Every rule can be scrutinized by experts, in advance of deploying a system. In practice, the rules would be written in some programming language rather than English, for extra avoidance of potential ambiguity. Notations of <a href="https://en.wikipedia.org/wiki/Logic#Formal_logic">formal logic</a> are typically used. However, the narrative above of how one &#8220;obviously&#8221; executes a logic program works pretty well to explain how the real thing operates.</p><p>One way to trust outputs of a rule-based system follows certifying compilers: have every execution output a <em>trace</em> for how the rules were used to come to a conclusion. The example I&#8217;ve used here is a little unnecessarily complicated from this perspective, but let&#8217;s simplify by saying (1) the goal of the system is to certify a <em>minimum</em> valuation for a startup, and (2) assume we have no rules that add negative amounts to the tally. Then a certificate is a list of <em>rule instances</em>: each element is one rule from the knowledge base, along with a further trace for each one, explaining how we deduce its premises. For instance, we can justify a use of the rule about cofounder-from-major-AI-company by including a trace demonstrating that the cofounder worked for a particular company. That nested trace may itself invoke another rule and need to include further traces, but eventually the process bottoms out in referencing only facts that we assumed are true. The point is that, while in general it may be complex to make a conclusion and produce its trace, it is simple and cheap to check a trace.</p><p>The story is quite similar to what we&#8217;ve considered for my own specialty of <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a> and its applications to <a href="/__u/stng.substack.com/p/safe-recursive-self-improvement-with">recursive self-improvement</a> and <a href="/__u/stng.substack.com/p/proof-carrying-code-in-the-matrix">code-sharing by agents</a>. Indeed, formal verification, including <a href="https://en.wikipedia.org/wiki/Automated_theorem_proving">automated theorem proving</a>, is an example of an area that has been so successful as to be ejected from the popular conception of &#8220;AI,&#8221; following the old maxim that the &#8220;AI&#8221; category only includes reasoning tasks that seem sufficiently unsolved today.</p><p>Thinking back to our discussion of <a href="/__u/stng.substack.com/p/why-deep-often-means-slow">performance bottlenecks inherent to deep learning</a>, we can see an appealing advantage for rule-based systems beyond explainability. A key principle we relied on was that the latency, or time it takes to get the complete answer to a question, is proportional to the <em>critical path</em> length of a system, measuring the longest sequence of steps that necessarily must occur in sequence. Some conclusions of a rule-based system can be justified with shallow traces, meaning that we don&#8217;t need to use rules whose premises are justified with rules whose premises appeal to rules&#8230; to too extreme of a depth. In principle, with a good parallel implementation, <em>the critical path is determined by the depth of the trace</em>. In other words, answers with shallow proofs should be findable quickly, with convincing evidence for their truth. The same expert system could still be ready to run for longer on more complex questions, taking time proportional to that complexity.</p><h1>A Discredited Approach?</h1><p>Now I can return to confronting how thoroughly expert systems have gone out of fashion. A major <a href="https://en.wikipedia.org/wiki/AI_winter">AI winter</a> starting in the 1980s was centered on disillusionment with expert systems. Then we had a period when roughly all AI approaches were widely viewed with skepticism, followed by the explosion of deep learning in the 2010s, putting expert systems at even more of a relative disadvantage in the popular imagination. Maybe I should feel sheepish, then, to reveal the truth about this blog: a major theme is going to be the increasingly compelling argument for returning to this style of automated decision-making (sometimes in cooperation with other techniques like deep learning). There are two major apparent obstacles in the way of achieving good results.</p><p>First, <strong>there has been massive full-stack investment in deep learning and related techniques</strong>, leaving competitors with quite some catching-up to do. Consider:</p><ul><li><p>Foundational work on algorithms in the domain</p></li><li><p>AI hardware accelerators like <a href="https://en.wikipedia.org/wiki/Graphics_processing_unit">GPUs</a>, as well as the programming tools that complement them, which together provide amazing parallel performance</p></li><li><p>Wide distribution of expertise in this kind of computing</p></li><li><p>Even wider familiarity with how to get good results prompting generative-AI systems</p></li></ul><p>Second, <strong>statistical machine learning has shown amazing results in so many domains where approaches based on symbolic logic stalled</strong>. If we randomly sample populations like business users for their most-important problems where they want help from artificial intelligence, we mostly get answers where generative AI is way ahead of other methods today. The burden of proof is on someone boosting another approach, to show how it can be at all competitive.</p><p>I&#8217;ll take a first shot at that argument in my next post. The key is to zoom out and apply a <a href="/__u/stng.substack.com/p/hardware-software-codesign-and-autonomous">codesign</a> approach, looking beyond the normal scopes in which AI problems are defined. Later posts will return to performance engineering of whole computing stacks for systems based on symbolic logic.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Why "Deep" Often Means "Slow"]]></title><description><![CDATA[Multiplicative compounding of latency with generative AI]]></description><link>https://stng.substack.com/p/why-deep-often-means-slow</link><guid isPermaLink="false">https://stng.substack.com/p/why-deep-often-means-slow</guid><dc:creator><![CDATA[Adam Chlipala]]></dc:creator><pubDate>Tue, 21 Apr 2026 12:08:58 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/7aa35a94-8ae1-4008-bc8c-9e58e6e7d75d_701x168.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Let me continue describing the pros and cons of <a href="https://en.wikipedia.org/wiki/Deep_learning">deep learning</a>, to help decide how to divide up the work of future intelligence with other elements like <a href="/__u/stng.substack.com/p/formal-verification-the-ultimate">formal verification</a>. My last post <a href="/__u/stng.substack.com/p/deep-learning-the-ultimate-search">presented deep learning as the ultimate search engine</a>, for finding prior art related to new goals, considering massive data sets that might contain ideas that are related for reasons that are not obvious. Now I&#8217;ll spend two posts on weaknesses of deep learning, starting with the amount of time it takes to get an answer, especially with the canonical kind of LLM-based tool being built today.</p><p>Our take-away message is going to be that systems based on deep learning introduce <em>sequentiality</em> (certain computation steps that must happen after others) that is often not inherent in the questions that we ask them to answer. Instead, it arises from how we choose to organize computation to answer them. The result is fundamental delays in getting those answers back.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Latency and Throughput in Parallel Systems</h1><p>We need to think in general terms about the performance of computer systems. Let me explain the basics using an example of courses and their prerequisites.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!fzZ3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F453c709c-f008-4a52-bcb5-b189e195d021_2641x1225.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!fzZ3!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F453c709c-f008-4a52-bcb5-b189e195d021_2641x1225.png 424w, /__u/substackcdn.com/image/fetch/$s_!fzZ3!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F453c709c-f008-4a52-bcb5-b189e195d021_2641x1225.png 848w, /__u/substackcdn.com/image/fetch/$s_!fzZ3!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F453c709c-f008-4a52-bcb5-b189e195d021_2641x1225.png 1272w, /__u/substackcdn.com/image/fetch/$s_!fzZ3!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F453c709c-f008-4a52-bcb5-b189e195d021_2641x1225.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!fzZ3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F453c709c-f008-4a52-bcb5-b189e195d021_2641x1225.png" width="1456" height="675" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/453c709c-f008-4a52-bcb5-b189e195d021_2641x1225.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:300547,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/194707129?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F453c709c-f008-4a52-bcb5-b189e195d021_2641x1225.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!fzZ3!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F453c709c-f008-4a52-bcb5-b189e195d021_2641x1225.png 424w, /__u/substackcdn.com/image/fetch/$s_!fzZ3!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F453c709c-f008-4a52-bcb5-b189e195d021_2641x1225.png 848w, /__u/substackcdn.com/image/fetch/$s_!fzZ3!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F453c709c-f008-4a52-bcb5-b189e195d021_2641x1225.png 1272w, /__u/substackcdn.com/image/fetch/$s_!fzZ3!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F453c709c-f008-4a52-bcb5-b189e195d021_2641x1225.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Imagine that every student in a certain department needs to take every course shown as a rectangle in this diagram. An arrow from one box to another indicates a prerequisite: the course at the source of the arrow must be taken before the course at the destination of the arrow. A <em>longest path</em> in this diagram is highlighted along the top, with courses that are not grayed out.</p><p>Even just from the perspective of one student, a process of completing course requirements is <em><a href="https://en.wikipedia.org/wiki/Parallel_computing">parallel</a></em>: many activities can be happening at once, here taking multiple courses. Following terminology from <a href="https://en.wikipedia.org/wiki/Analysis_of_parallel_algorithms">running-time analysis of parallel algorithms</a>, we will call the longest path in such a diagram the <em>critical path</em>. We use <em>depth</em> to refer to the length of a parallel workload&#8217;s critical path, and we use <em>work</em> to refer to the total number of steps (courses in this example), within a taxonomy introduced by <a href="https://en.wikipedia.org/wiki/Guy_Blelloch">Blelloch</a> and collaborators a few decades ago</p><p>An important theorem in this domain is that <em>a given parallel workload must run for a number of steps at least equal to its depth</em>. This conclusion should be intuitive after digesting the terminology: a long prerequisite chain in degree requirements indeed implies a minimum number of terms to complete the degree.</p><p>In general, we run many instances of a parallel workload at once. For our courses example, this phenomenon corresponds to having many students enrolled at once. The time from the beginning of one execution of the workload to full completion is called <em><a href="https://en.wikipedia.org/wiki/Latency_(engineering)">latency</a></em>. The number of workload instances finishing per step is called <em><a href="https://en.wikipedia.org/wiki/Network_throughput">throughput</a></em>. Our example connects latency to how long it takes one student to graduate and throughput to the number of students graduating each term.</p><p>Clearly both latency and throughput matter in the running example, but latency is more important from the student perspective. It is no comfort to learn that thousands of students graduate each term if it also takes 100 terms to graduate.</p><h1>Critical Paths of Deep Neural Networks</h1><p>Most people encountering the term &#8220;deep learning&#8221; naturally assume that &#8220;deep&#8221; is only good news: the neural network is doing something hard and complicated. The term refers more specifically to how many <em>layers</em> a neural network has. This diagram shows roughly the kind of structure of a deep neural network, with layers arranged horizontally, each layer including many artificial neurons, spread out vertically.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!JXMk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a657c4-e307-4cc9-bb0d-e8448f070e99_1475x595.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!JXMk!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a657c4-e307-4cc9-bb0d-e8448f070e99_1475x595.png 424w, /__u/substackcdn.com/image/fetch/$s_!JXMk!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a657c4-e307-4cc9-bb0d-e8448f070e99_1475x595.png 848w, /__u/substackcdn.com/image/fetch/$s_!JXMk!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a657c4-e307-4cc9-bb0d-e8448f070e99_1475x595.png 1272w, /__u/substackcdn.com/image/fetch/$s_!JXMk!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a657c4-e307-4cc9-bb0d-e8448f070e99_1475x595.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!JXMk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a657c4-e307-4cc9-bb0d-e8448f070e99_1475x595.png" width="1456" height="587" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a0a657c4-e307-4cc9-bb0d-e8448f070e99_1475x595.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:587,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:296391,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/194707129?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a657c4-e307-4cc9-bb0d-e8448f070e99_1475x595.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!JXMk!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a657c4-e307-4cc9-bb0d-e8448f070e99_1475x595.png 424w, /__u/substackcdn.com/image/fetch/$s_!JXMk!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a657c4-e307-4cc9-bb0d-e8448f070e99_1475x595.png 848w, /__u/substackcdn.com/image/fetch/$s_!JXMk!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a657c4-e307-4cc9-bb0d-e8448f070e99_1475x595.png 1272w, /__u/substackcdn.com/image/fetch/$s_!JXMk!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0a657c4-e307-4cc9-bb0d-e8448f070e99_1475x595.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Each neuron has inputs coming from (in general) many others <em>from the previous layer</em>. Every neuron is like one course in our earlier example: one unit of work that needs to be performed eventually, to generate a complete answer to a question, with dependencies on some previous steps (here from the previous layer). Note that, as the highlighted path shows, the critical path now runs through all layers, so depth and thus latency are proportional to the layer count. Since &#8220;deep&#8221; refers to the number of layers, here we have our illustration of <em>how &#8220;deep&#8221; can mean &#8220;slow.&#8221;</em> There are many ways that a deep neural network could be evaluated as a parallel workload, but, without some higher-level rearrangement of computation, generating an answer will take time at least proportional to layer count.</p><p>Of course, there remain all kinds of tricks for boosting throughput. Most obviously, we expect that roughly all neurons in a single layer can be evaluated at once. The standard computer-systems technique of <a href="https://en.wikipedia.org/wiki/Pipeline_(computing)">pipelining</a> is also used, just as we would expect from our earlier example of courses: many executions of the neural network can be run simultaneously, where, at any moment, each layer is working on a different user request. However, these optimizations only boost throughput and, in fact, can introduce extra coordination across steps that even <em>increases</em> latency (e.g., pipelining breaks a computation into pieces that incur extra overhead communicating with each other through queues). While AI companies are motivated to control costs by improving throughput, an individual end user&#8217;s experience is more dependent on latency, even in the presence of optimizations like batching (executing requests from different users simultaneously). That user can pay lower fees thanks to throughput-improving resource sharing, but it&#8217;s hard not to notice that, say, a chatbot takes a long time to finish returning an acceptable answer, and latency can matter even more for emerging use cases.</p><p>It can also be argued that the diagram above is oversimplified. Cutting-edge neural networks don&#8217;t <em>literally</em> feed neurons with just outputs from immediately previous layers. An especially common technique is <a href="https://en.wikipedia.org/wiki/Transformer_(deep_learning)#KV_caching">KV caching</a>, which feeds each neuron a somewhat-complex summary of past steps. However, these variations don&#8217;t change the fact of long sequential dependencies (critical paths), with lengths proportional to layer counts. Two other common techniques worth mentioning are <a href="https://en.wikipedia.org/wiki/Attention_(machine_learning)">attention</a>, which manipulates dependencies within layers but basically maintains critical-path structure across layers; and <a href="https://en.wikipedia.org/wiki/Residual_neural_network">residual connections</a>, which effectively allow some connections between nonadjacent layers but maintain the normal kind of connection, too, which generate roughly the same critical paths.</p><p>Recapping, by virtue of how deep learning is organized with long critical paths, it is unavoidable that some steps just need to happen <em>after</em> others, and in fact long chains of such dependencies develop, forcing delays before final answers can be delivered.</p><h1>Deep All the Way Down, Multiplying Latencies</h1><p>Now let&#8217;s consider other elements in <a href="https://en.wikipedia.org/wiki/AI_agent">agentic</a> systems being built on top of <a href="https://en.wikipedia.org/wiki/Large_language_model">LLMs</a> today.</p><p>First, an LLM generates a full answer by calling a neural network <em>repeatedly</em>, once to generate each token (which is roughly a single word). The input to the neural network is a representation of the tokens that were produced previously, <em>which leads to a long critical path stepping sequentially through all invocations of the neural network</em>. In other words, when the neural network has depth <em>d</em> and we are generating an LLM response of <em>t</em> tokens, the critical path at this level of system detail has length proportional to <em>dt</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!cG_G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a309f8-86f3-407e-ae6c-3eacc12b6e90_1544x376.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!cG_G!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a309f8-86f3-407e-ae6c-3eacc12b6e90_1544x376.png 424w, /__u/substackcdn.com/image/fetch/$s_!cG_G!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a309f8-86f3-407e-ae6c-3eacc12b6e90_1544x376.png 848w, /__u/substackcdn.com/image/fetch/$s_!cG_G!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a309f8-86f3-407e-ae6c-3eacc12b6e90_1544x376.png 1272w, /__u/substackcdn.com/image/fetch/$s_!cG_G!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a309f8-86f3-407e-ae6c-3eacc12b6e90_1544x376.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!cG_G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a309f8-86f3-407e-ae6c-3eacc12b6e90_1544x376.png" width="1456" height="355" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2a309f8-86f3-407e-ae6c-3eacc12b6e90_1544x376.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:355,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:77042,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/194707129?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a309f8-86f3-407e-ae6c-3eacc12b6e90_1544x376.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!cG_G!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a309f8-86f3-407e-ae6c-3eacc12b6e90_1544x376.png 424w, /__u/substackcdn.com/image/fetch/$s_!cG_G!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a309f8-86f3-407e-ae6c-3eacc12b6e90_1544x376.png 848w, /__u/substackcdn.com/image/fetch/$s_!cG_G!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a309f8-86f3-407e-ae6c-3eacc12b6e90_1544x376.png 1272w, /__u/substackcdn.com/image/fetch/$s_!cG_G!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a309f8-86f3-407e-ae6c-3eacc12b6e90_1544x376.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>How exactly do we arrive at depth about <em>dt</em>? At the level of detail in this last diagram, we easily trace out a critical path of length <em>t</em>, starting with the first neural-network invocation, whose output flows into the next, and so on until the last neural-network invocation. However, <em>each box labeled &#8220;DNN&#8221; (for deep neural network) is a copy of the prior diagram</em>, where we traced out critical path of length <em>d</em>. Dropping in those copies, the path segments connect together to reach length proportional to <em>dt</em>. Intuitively, the system makes <em>t</em> queries to the DNN in-order, and, for each query, we have to pause and wait for the <em>d</em> sequential steps of the DNN.</p><p>A few techniques allow deviating from this kind of workload diagram. For instance, <a href="https://en.wikipedia.org/wiki/Speculative_decoding">speculative decoding</a> uses cheaper neural networks to guess batches of answers, which are then checked in single shots by more-expensive neural networks. However, this technique only improves latency by a small constant factor &#8211; not enough to offset the multiplicative compounding of latency. As a result, latency remains proportional to depth of neural network and length of LLM output.</p><p>Now consider how a coding assistant like <a href="https://en.wikipedia.org/wiki/Claude_(language_model)#Claude_Code">Claude Code</a> works. It can take on many tasks in parallel, but some objectives still depend on relatively long sequences of steps &#8211; where many individual steps are copies of the whole LLM flow we just covered. Also, some steps make arbitrary <em>tool calls</em> to external programs that introduce latency of their own. This diagram shows the coding agent calling a <a href="https://en.wikipedia.org/wiki/Compiler">compiler</a> to get feedback on relatively shallow problems it finds in code, as well as a test runner to see which inputs from a <a href="https://en.wikipedia.org/wiki/Software_testing">test suite</a> the program fails to generate the right answers for.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!4DnR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4a84ae0-956d-4b7c-b3bd-a291c89759c8_1898x270.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!4DnR!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4a84ae0-956d-4b7c-b3bd-a291c89759c8_1898x270.png 424w, /__u/substackcdn.com/image/fetch/$s_!4DnR!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4a84ae0-956d-4b7c-b3bd-a291c89759c8_1898x270.png 848w, /__u/substackcdn.com/image/fetch/$s_!4DnR!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4a84ae0-956d-4b7c-b3bd-a291c89759c8_1898x270.png 1272w, /__u/substackcdn.com/image/fetch/$s_!4DnR!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_webp, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4a84ae0-956d-4b7c-b3bd-a291c89759c8_1898x270.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!4DnR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4a84ae0-956d-4b7c-b3bd-a291c89759c8_1898x270.png" width="1456" height="207" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a4a84ae0-956d-4b7c-b3bd-a291c89759c8_1898x270.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:207,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74242,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://stng.substack.com/i/194707129?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4a84ae0-956d-4b7c-b3bd-a291c89759c8_1898x270.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!4DnR!, /__u/stng.substack.com/w_424, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4a84ae0-956d-4b7c-b3bd-a291c89759c8_1898x270.png 424w, /__u/substackcdn.com/image/fetch/$s_!4DnR!, /__u/stng.substack.com/w_848, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4a84ae0-956d-4b7c-b3bd-a291c89759c8_1898x270.png 848w, /__u/substackcdn.com/image/fetch/$s_!4DnR!, /__u/stng.substack.com/w_1272, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4a84ae0-956d-4b7c-b3bd-a291c89759c8_1898x270.png 1272w, /__u/substackcdn.com/image/fetch/$s_!4DnR!, /__u/stng.substack.com/w_1456, /__u/stng.substack.com/c_limit, /__u/stng.substack.com/f_auto, /__u/stng.substack.com/q_auto:good, /__u/stng.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4a84ae0-956d-4b7c-b3bd-a291c89759c8_1898x270.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>By now you may be used to spotting the problem for latency: every LLM node in this diagram has critical path length proportional to <em>dt</em>. Now consider the longest sequence of high-level steps in the new diagram, with length <em>s</em>. We are up to depth at least <em>dts</em>, before even taking into account the latency of the tool calls. The time it takes to get a complete answer to one top-level question is being multiplied by a further factor for every level of additional sophistication that we introduce. The reason is again that every LLM box expands into a <em>full copy of the last diagram</em>, and the path segments visible directly in this picture connect with the <em>s</em> copies of the critical path of length about <em>dt</em> from before. Latency has been compounding through <em>all layers</em> of the system, from neural network to repeated next-token prediction to higher-level agentic workflow. Adding functionality doesn&#8217;t <em>add</em> to latency but instead <em>multiplies</em> it.</p><h1>Conclusion</h1><p>The way that mainstream generative-AI systems are being designed today exhibits a fundamental phenomenon of <em>multiplicative compounding of latency</em>, with intensity proportional to how many levels of additional functionality are added. Latency isn&#8217;t everything, but getting full answers to questions sooner is clearly better. For instance, the programmer using an AI coding assistant must typically wait out the full latency before doing code review and testing to finalize a code contribution.</p><p>The best rejoinder to these observations about current generative-AI systems is that we don&#8217;t seem to have come up with other ways to solve the same problems with nearly the same level of solution quality. Perhaps the latency penalty is unavoidable for those problems. Two posts from now, I&#8217;ll present a framework addressing that response from an unusual angle. Zooming out even further than what this post covers, with other architectural changes, we can avoid such high latency by shortening critical paths.</p><p>First, though, in the next post, I want to present the challenge of <em><a href="https://en.wikipedia.org/wiki/Explainable_artificial_intelligence">explainability</a></em> for machine learning, contrasted with an older style of artificial intelligence.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://stng.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Structure and Guarantees! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>