0. Plain Statement
A system can appear secure while becoming less coherent.
Plain-language version:
A system may look secure because incidents are low, dashboards are green, policies are complete, compliance boxes are checked, monitoring is extensive, or enforcement is strong.
But if coherence is falling, auditability is narrowing, hidden debt is rising, boundaries are drifting, restoration capacity is weak, and legitimacy is decaying, the system is not secure.
It is pseudo-secure.
1. Formal Definition
The Pseudo-Security Law states that visible security proxies can remain stable or improve while actual security coherence degrades.
Canonical pattern:
Φ stable or ↑
O↓
Au↓
H↑
ι↑Pseudo-security emerges when a system mistakes security appearance for security coherence.
Security appearance may include:
- low visible incident count;
- green dashboards;
- compliance success;
- audit completion;
- policy volume;
- tool count;
- surveillance coverage;
- enforcement intensity;
- access restriction;
- emergency powers;
- public reassurance;
- secrecy;
- visible order;
- low complaint volume;
- incident closure rate;
- security branding;
- risk language.
None of these prove security unless they remain connected to coherence, boundary integrity, auditability, restoration capacity, feedback integrity, and temporal proof.
Pseudo-security is especially dangerous because it can reduce vigilance while risk is rising.
2. Canonical Form
Core form:
a system can appear secure while becoming less coherentCanonical pattern:
Φ stable or ↑
O↓
Au↓
H↑
ι↑Security proxy divergence form:
security proxies↑ + coherence↓ ⇒ pseudo-securityControl substitution form:
control↑ + restoration↓ ⇒ security debt↑Failure form:
dashboard green + Au↓ + H↑ + R↓ ⇒ false securityRestoration-valid contrast:
security valid when proxies align with O, BΣ, Au, R, FI, and recurrence reduction over ΤRelated variables:
O, H, H_security, ε, ι, Au, Au_eff, µᵢ, BΣ, K, σ, R, R_eff, 𝓑, 𝓓, Φ, Φ_security, Λ, ⊗, Γ, Π, Ξ, ℛ, Θ, Σ, Ψ, Τ, FI, L, compliance_score, incident_visibility, dashboard_status, surveillance_coverage, enforcement_intensity, control_density, security_proxy, restoration_quality, boundary_drift, legitimacy_debtWhere:
| Variable | Meaning in this law |
|---|---|
Φ_security | Visible security success proxy: low incidents, compliance status, dashboard score, closure rate, tool count, or perceived safety |
security_proxy | Any signal treated as evidence of security without full coherence validation |
compliance_score | Formal rule-adherence indicator; useful but insufficient |
incident_visibility | Degree to which incidents are observable; low incidents may reflect low visibility |
dashboard_status | Displayed security status; can diverge from field truth |
surveillance_coverage | Sensing coverage; not security unless routed into restoration |
enforcement_intensity | Restriction, discipline, denial, or control intensity |
control_density | Degree of control imposed on nodes or interfaces |
restoration_quality | Degree to which incidents or detections reduce debt and recurrence |
boundary_drift | Degradation of access, trust, coupling, consent, or membrane integrity |
legitimacy_debt | Trust and accountability debt created by false security claims |
O | Coherence; declines under pseudo-security |
H / H_security | Hidden debt; rises when proxies hide actual risk |
Au / Au_eff | Auditability; often declines as pseudo-security stabilizes |
R / R_eff | Restoration capacity; often underbuilt behind control and compliance |
BΣ | Boundary integrity; may appear controlled while actually drifting or rigidifying |
µᵢ | Meaning / agent integrity; security mission may invert into control or reputation defense |
ι / Ξ | Inversion when security language justifies incoherence |
Φ | Visible proxy success; central risk variable in this law |
FI | Feedback integrity; pseudo-security often discounts weak signals and affected-node feedback |
L | Legitimacy; decays when security claims fail under audit |
Γ | Classifies security proxies, real signals, artifacts, incidents, boundaries, and repair needs |
Π | Operationalizes controls, policies, dashboards, surveillance, enforcement, and response workflows |
ℛ | Restoration required to convert security appearance into actual security |
Θ | Humility preventing dashboard capture and overconfidence |
Σ | Scope of security claims and proxy validity |
Ψ | Field and affected-node feedback validating security effects |
Τ | Time validation of proxy alignment with coherence |
3. Core Mechanism
The law unfolds because security proxies can decouple from security coherence.
Coherent security-proxy pathway
security proxy improves
→ auditability confirms field truth
→ boundaries remain coherent
→ incidents route into repair
→ recurrence decreases
→ hidden debt decreases
→ legitimacy holds over timePseudo-security pathway
security proxy improves
→ confidence rises
→ audit narrows
→ weak signals are discounted
→ restoration capacity lags
→ hidden debt rises
→ visible incident appears late
→ legitimacy collapsesThe core mechanism is:
security appearance can decouple from security coherenceDetailed mechanism:
- A security proxy becomes prominent.
The system tracks visible incidents, compliance, dashboard status, monitoring coverage, access restrictions, or enforcement output.
- The proxy is mistaken for security.
Decision-makers infer safety from the proxy without testing coherence, auditability, boundaries, or restoration.
- Auditability narrows.
Because the proxy looks positive, the system reduces scrutiny or ignores weak signals.
- Hidden debt accumulates.
Boundary drift, patch debt, misclassification, restoration backlog, legitimacy debt, and recurrence risk rise beneath the surface.
- Security mission may invert.
The system defends the appearance of security rather than actual coherence.
- Incident shock appears late.
When the hidden debt becomes visible, the system is surprised because the proxy looked healthy.
- Restoration must reconnect proxy to coherence.
Security indicators must be revalidated against field effects, boundary health, auditability, and repair outcomes.
4. When This Law Applies
This law applies whenever security is evaluated through visible proxies rather than actual coherence under forcing.
It is especially important when:
- low incident count is treated as proof;
- compliance is treated as proof;
- dashboards show green while weak signals accumulate;
- surveillance coverage expands but repair does not;
- access restriction increases but boundary coherence declines;
- emergency powers remain after crisis;
- enforcement intensity is treated as safety;
- audits are formal but not effective;
- logs exist but causality is unclear;
- detection improves but restoration lags;
- complaints are low because reporting is hard;
- staff are discouraged from surfacing risk;
- AI safety claims rely on visible refusal or policy compliance;
- institutions claim safety while harmed nodes lack repair pathways.
The law applies strongly when:
security proxy improves while coherence variables degradeor when:
security appearance is used to avoid deeper auditTypical domains:
| Domain | Pseudo-Security Expression |
|---|---|
| AI systems | Refusal rates, safety policy compliance, or low visible incidents can hide misclassification, user harm, appeal failure, and restoration gaps. |
| Cybersecurity | Compliance, tool coverage, and low alerts can hide patch debt, boundary drift, weak logging, and hidden compromise. |
| Institutions | Safety narratives, training completion, or incident closure can hide harmed-node pathway failure and recurrence. |
| Medicine / biology | Symptom suppression can appear secure while underlying recovery capacity declines. |
| Economy | Stability indicators can hide leverage, extraction, externalities, or circulation debt. |
| Governance | Order, law, enforcement, or emergency control can appear secure while legitimacy decays. |
| Culture | Taboo, silence, or conformity can appear safe while hidden harm grows. |
| Media / information networks | Content control can appear safe while trust, correction, and meaning integrity degrade. |
5. When This Law Does Not Apply
This law should not be used to dismiss all security metrics, controls, compliance systems, dashboards, or incident tracking.
Proxies are useful when validated.
The problem is not measurement. The problem is proxy substitution.
False-positive cases:
| Case | Why the proxy may still be useful |
|---|---|
| Incident count falls after visibility improves and repair succeeds | The proxy may reflect actual improvement |
| Compliance requirements align with real boundary health | Compliance can support coherence |
| Dashboards include leading indicators and field validation | Dashboards can aid security if not treated as truth alone |
| Surveillance routes into repair and recurrence prevention | Sensing can support security |
| Enforcement is scoped and repair-bound | Restriction can be a coherent containment phase |
| Emergency controls sunset after repair | Temporary control can be valid |
| Security score includes auditability and restoration measures | Proxy quality improves when tied to coherence variables |
Important distinction:
Security proxies are admissible signals; they are not security proof by themselves.
6. Diagnostic Signature
Canonical diagnostic:
Φ stable or ↑
O↓
Au↓
H↑
ι↑Warning signature:
security proxy↑
confidence↑
audit depth↓
weak signals ignored
restoration capacity flat
boundary drift↑
H↑
⇒ pseudo-securityCommon indicators:
| Diagnostic | Expected movement | Interpretation |
|---|---|---|
Φ_security | ↑ or stable | Visible security proxy looks good |
O | ↓ if pseudo-secure | Coherence is declining despite proxy |
Au / Au_eff | ↓ | Auditability is narrowing |
H / H_security | ↑ | Hidden debt is accumulating |
ι / Ξ | ↑ | Security meaning is inverting |
BΣ | ↓ or rigidifies | Boundaries drift or overharden |
R / R_eff | flat / ↓ | Restoration capacity lags |
FI | ↓ | Weak signals and feedback are discounted |
incident_visibility | uncertain / ↓ | Low incidents may reflect blindness |
compliance_score | not sufficient | Rule compliance is not proof |
dashboard_status | not sufficient | Display status is not field truth |
surveillance_coverage | not sufficient | Sensing is not restoration |
enforcement_intensity | not sufficient | Control is not security |
L | ↓ if exposed | Legitimacy decays when pseudo-security is revealed |
Τ | required | Time validates proxy alignment |
Additional diagnostics:
| Diagnostic | Use |
|---|---|
| Pseudo-Security | Detects security appearance diverging from coherence |
| Security Proxy Divergence | Tests whether proxy indicators diverge from field effects |
| Security Coherence | Tests actual security under forcing |
| Compliance Theater | Detects compliance disconnected from coherence |
| Incident Absence Error | Detects low-incident overconfidence |
| Effective Auditability | Tests whether audit can trace real security state |
| Boundary Drift | Detects membrane degradation behind proxy success |
| Control Substitution | Detects control replacing restoration |
| Legitimacy Debt | Detects trust decay behind security claims |
| Temporal Proof | Validates security across recurrence |
7. Failure Pattern
If ignored, this law allows false confidence to mature into security collapse.
General failure pathway:
security proxy improves
→ system confidence rises
→ deeper audit declines
→ weak signals are ignored
→ hidden debt accumulates
→ boundaries drift
→ restoration lags
→ incident appears late
→ legitimacy collapsesCommon failure modes:
- Pseudo-Security — security appearance persists while coherence declines.
- Security Theater — visible security activity substitutes for actual security.
- Compliance Theater — compliance satisfies procedure while field risk rises.
- Consent Theater — consent or access controls appear valid while state-space coercion or opacity remains.
- Over-Surveillance — sensing expands without restoration, increasing control and legitimacy debt.
- Emergency Normalization — temporary control becomes permanent security posture.
- Audit Suppression — apparent security depends on reduced inspection.
- Incident Absence Error — low visible incidents are treated as proof.
- Dashboard Capture — visual status replaces field validation.
- Metric Substitution — measurable proxy replaces actual security.
- Boundary Drift — membranes degrade despite controls.
- Control Substitution — enforcement or restriction replaces restoration.
- Restoration Failure — incidents and detections do not reduce debt.
- Hidden Debt Accumulation — risk grows beneath surface order.
- Legitimacy Debt — trust decays once pseudo-security becomes visible.
Compact failure signature:
Φ_security↑ + O↓ + Au↓ + H↑ ⇒ pseudo-security8. Restoration Implications
Restoration requires dissolving pseudo-security by reconnecting security proxies to actual coherence.
The first restoration question is not:
Do the security metrics look good?The first restoration question is:
Do the metrics correspond to preserved coherence, boundary integrity, auditability, restoration capacity, and recurrence reduction under forcing?Restoration priorities:
- Identify the security proxies in use.
- Test proxy alignment with coherence variables.
- Audit incident visibility.
- Audit boundary integrity.
- Audit hidden debt.
- Restore effective auditability.
- Restore feedback integrity.
- Route sensing and enforcement into restoration.
- Reduce control substitution.
- Validate security under pressure and recurrence.
Relevant restoration arcs:
| Restoration Arc | Why it applies |
|---|---|
| Pseudo-Security Dissolution | Separates appearance from coherence |
| Security Coherence Restoration | Reconnects security posture to preserved variables |
| Security Proxy Audit | Tests whether proxies match actual field effects |
| Auditability Restoration | Restores traceability behind security claims |
| Boundary Reconstitution | Repairs drift, rigidity, or leakage |
| Restoration Capacity Increase | Ensures incidents and sensing route into repair |
| Control-to-Restoration Re-Sequencing | Converts control-heavy security into repair-linked security |
| Surveillance-to-Restoration Routing | Ensures sensing produces restoration rather than only detection |
| Hidden Debt Reduction | Repairs security debt behind proxies |
| Feedback Integrity Restoration | Reopens weak signals and affected-node reports |
| Legitimacy Repair | Restores trust after pseudo-security exposure |
| Temporal Validation | Confirms proxy alignment over time |
Minimal restoration sequence:
identify Φ_security proxies
→ test against O + BΣ + Au + R + FI
→ audit incident_visibility + H_security
→ restore Au/FI/BΣ
→ route detection/control into ℛ
→ reduce recurrence
→ validate over ΤTemporal validation requirement:
security proxies remain connected to field effects
auditability improves
boundary drift decreases
hidden debt decreases
restoration quality improves
incident visibility is known
weak signals trigger repair
legitimacy stabilizes
recurrence decreases
coherence holds under forcing9. Design Rule
Do not treat security proxies as proof unless they remain coupled to coherence, auditability, boundary integrity, restoration, and time validation.
Operational design requirements:
- Identify all security proxies.
- Distinguish proxy from truth.
- Audit incident visibility.
- Include leading indicators.
- Track boundary health.
- Track restoration quality.
- Track recurrence reduction.
- Track auditability.
- Track affected-node feedback.
- Track legitimacy effects.
- Route detection into repair.
- Treat dashboard status as a question, not an answer.
- Validate compliance against field outcomes.
- Validate security under forcing.
- Update metrics when they no longer predict coherence.
Avoid:
- dashboard green as proof;
- low incident count as proof;
- compliance as proof;
- surveillance as proof;
- enforcement as proof;
- secrecy as proof;
- order as proof;
- closure rate as proof;
- training completion as proof;
- refusal rate as proof;
- public reassurance as proof;
- security branding as proof;
- metrics that cannot detect hidden debt;
- controls that increase legitimacy debt;
- audits that cannot reach field effects.
10. Cross-Scale Expressions
| Scale / Layer | Expression of the Law |
|---|---|
| U0 — Substrate | A body, infrastructure, ecosystem, or material system may appear stable while underlying repair capacity declines. |
| U1 — Energy / capacity | Security theater consumes slack and may reduce real response capacity. |
| U2 — Boundary / interface | Boundaries may appear controlled while becoming leaky, rigid, coercive, or unclear. |
| U3 — Process / execution | Security procedures may execute while failing to repair origin conditions. |
| U4 — Classification / claim | Security claims and metrics must not be confused with field truth. |
| U5 — Time / delay | Pseudo-security often holds until delayed debt becomes visible. |
| U6 — Field effect | Field outcomes reveal whether security is real or proxy-based. |
| U7 — Recurrence / memory | Recurring incidents or weak signals expose pseudo-security patterns. |
| U8 — Environment / forcing | Institutions, markets, platforms, AI systems, media, and governance fields can reward security appearance over security coherence. |
11. Examples
Example A — Green Dashboard, Hidden Debt
Scenario:
A security dashboard is green because no major incidents are visible, but logging gaps, patch debt, access exceptions, and ignored weak signals are increasing.
Law expression:
dashboard green + Au↓ + H_security↑ ⇒ pseudo-securityInterpretation:
The dashboard is not proof if visibility and debt tracking are weak.
Example B — Compliance Without Coherence
Scenario:
An organization passes compliance audits while real boundary integrity, user reporting, incident recovery, and recurrence prevention degrade.
Law expression:
compliance_score↑ + O_security↓ ⇒ compliance theaterInterpretation:
Compliance supports security only when it tracks field coherence.
Example C — AI Refusal as Safety Proxy
Scenario:
An AI system refuses more content and claims improved safety, but misclassification rises, appeal is absent, user correction burden increases, and repair is unavailable.
Law expression:
AI refusal Φ↑ + Γ error↑ + ℛ↓ ⇒ pseudo-securityInterpretation:
A refusal metric is not safety proof without audit and repair.
Example D — Over-Surveillance
Scenario:
A system increases monitoring and surveillance, but findings route into punishment or suppression rather than repair, prevention, and legitimacy restoration.
Law expression:
surveillance_coverage↑ - ℛ ⇒ security legitimacy debtInterpretation:
Sensing without restoration can create pseudo-security and mistrust.
Example E — Emergency Controls Become Normal
Scenario:
Emergency security powers remain after the emergency, justified by the appearance of continued safety.
Law expression:
emergency control + no sunset ⇒ pseudo-security + H↑Interpretation:
Emergency control can become false security when not time-bounded, audited, and repair-linked.
Example F — Real Security Metrics
Scenario:
A security program tracks incident visibility, boundary drift, patch debt, detection lag, response lag, recovery quality, restoration completion, recurrence reduction, and affected-node trust.
Law expression:
Φ_security aligned with O + BΣ + Au + ℛ + Τ ⇒ security proxy validInterpretation:
Security proxies are valid when they stay connected to coherence and field effects.
12. Relationship to Nearby Laws
| Related Law | Relationship |
|---|---|
| LAW-001 — Coherence Priority Law | Security appearance is valid only when coherence holds |
| LAW-002 — Coherence Trajectory Law | Security proxies must track trajectory |
| LAW-003 — Success Proxy Divergence Law | Pseudo-security is a security-specific proxy divergence |
| LAW-004 — Stability-Coherence Separation Law | Stable security appearance may hide incoherence |
| LAW-006 — Time Validation Law | Pseudo-security fails over time |
| LAW-007 — Ring-Down Truth Law | Poor ring-down exposes false security |
| LAW-009 — U4 / U6 Truth Law | Security claims require field validation |
| LAW-010 — Hidden Debt Accumulation Law | Pseudo-security accumulates hidden debt |
| LAW-011 — Hidden Debt Return Law | Hidden security debt returns as incident or collapse |
| LAW-012 — Error Lag Law | Visible security failure appears late |
| LAW-013 — Auditability-Debt Law | Pseudo-security narrows auditability |
| LAW-015 — Suppressed Auditability Debt Law | Audit suppression sustains pseudo-security |
| LAW-016 — Inversion Formation Law | Security language can invert into insecurity |
| LAW-020 — Bandwidth Threshold Law | Overloaded operators may rely on proxies |
| LAW-023 — Restoration Capacity Load Law | Pseudo-security underbuilds restoration capacity |
| LAW-030 — Slack Sovereignty Law | Security theater consumes slack |
| LAW-031 — Observability Collapse Law | Poor observability can appear as low incidents |
| LAW-036 — Signal Artifact Law | Proxies may be artifacts |
| LAW-037 — Misclassification Law | Misclassification can make security appear better than it is |
| LAW-040 — Filtering Law | Bad filtering hides incidents or weak signals |
| LAW-041 — Boundary Membrane Law | Boundary drift can hide behind control metrics |
| LAW-045 — Force Debt Law | Enforcement-heavy pseudo-security creates force debt |
| LAW-048 — Feedback Integrity Law | Pseudo-security discounts weak signals and affected feedback |
| LAW-050 — Control-Restoration Separation Law | Pseudo-security confuses control with restoration |
| LAW-052 — Stability Proof Law | Security must survive perturbation, not just appear stable |
| LAW-057 — Deception Instability Law | Deceptive security appearance is unstable |
| LAW-064 — Restoration Debt Reduction Law | Security must reduce debt, not display control |
| LAW-065 — Pseudo-Restoration Law | Pseudo-security often includes pseudo-restoration |
| LAW-066 — Restoration Capacity Sufficiency Law | Security needs sufficient restoration capacity |
| LAW-067 — Temporal Proof Law | Security proxies require temporal proof |
| LAW-083 — Normalization Shield Law | Normalized security theater can shield harm |
| LAW-102 — Legitimacy Audit Law | Pseudo-security creates legitimacy debt |
| LAW-103 — Justice Stability Law | Security must support justice, not replace it |
| LAW-104 — Justice Logistics Law | Security claims require repair and pathway logistics |
| LAW-105 — Repair Before Enforcement Law | Enforcement-heavy security without repair is pseudo-security |
| LAW-109 — High-Φ Legitimacy Scaling Law | High-influence security claims require stronger audit and restoration |
| LAW-111 — Meaning Audit Law | Security narratives are not audit-exempt |
| LAW-112 — Security as Sustained Coherence Law | LAW-114 defines the false-security failure mode of LAW-112 |
| LAW-113 — Incident Lag Law | Incident lag enables pseudo-security through low visible incident counts |
| LAW-115 — Surveillance–Restoration Law | Surveillance without restoration is a pseudo-security pattern |
| LAW-116 — Emergency Normalization Law | Normalized emergency control is pseudo-security |
| LAW-117 — Shadow–Light Security Law | Shadow knowledge without Light can become pseudo-security or capture |
| LAW-118 — Empathy Security Law | Security without empathy can misclassify nodes and appear secure |
| LAW-119 — Basin Self-Defense Law | Basins may label self-defense as security |
| LAW-120 — Security Legibility Law | Security claims require traceability to avoid pseudo-security |
| LAW-122 — AI Error Lag Law | Low AI visible error can create pseudo-security |
| LAW-123 — AI U4 Truth Discipline Law | AI security claims require U6 validation |
| LAW-124 — AI Rule-Stacking Law | More AI rules can create pseudo-security when auditability falls |
| LAW-130 — AI Membrane Triage Law | Pseudo-security can hide which membrane failed |
| LAW-134 — Layered Interception Law | Layered interception reduces pseudo-security by catching failures earlier |
Aliases folded into this law:
- Pseudo-Security Law
- Security Theater Law
- Appearing Secure While Degrading Law
- Security Proxy Divergence Law
- Compliance Theater Security Law
- False Security Coherence Law
- Security Appearance Divergence Law
Deduplication note:
This law should remain the root pseudo-security law. LAW-112 defines security as sustained coherence. LAW-113 defines visible incidents as lagging indicators. LAW-115 specializes surveillance without restoration. LAW-116 specializes emergency normalization. LAW-124 specializes AI rule-stacking as a pseudo-safety pattern.
13. Operator Mapping
| Operator | Role in this law |
|---|---|
Γ | Classifies security proxies, signals, artifacts, incidents, boundary drift, hidden debt, and repair requirements |
Π | Operationalizes controls, dashboards, compliance, surveillance, enforcement, and response workflows |
Ξ | Captures inversion when security language protects appearance while coherence declines |
⊗ | Security proxies shape coupling decisions, access, trust, restriction, and surveillance |
ℛ | Restores actual coherence behind security appearance |
Τ | Validates whether security proxies remain coupled to field truth over time |
Θ | Prevents overconfidence, dashboard capture, and proxy certainty |
Σ | Defines the valid scope of each security claim and metric |
Ψ | Field and affected-node feedback validates whether security is real |
Λ | Tests compatibility between security posture and whole-system coherence |
Coherent operator sequence:
security proxy appears
→ Θ prevent proxy certainty
→ Γ classify proxy / signal / artifact / debt
→ Σ define proxy validity scope
→ Au/FI test proxy against field effects
→ map O + BΣ + R + H
→ ℛ repair divergence
→ Ψ validate affected-node effects
→ Τ validate proxy alignment over timeInverted operator sequence:
security proxy improves
→ confidence↑
→ Γ treats proxy as truth
→ Au narrows
→ weak signals ignored
→ R lags
→ H_security↑
→ Ξ / ι↑
→ incident shock appears late14. Machine-Readable Summary
id: "LAW-114"
name: "Pseudo-Security Law"
type: "law"
status: "draft"
family:
- "Security Laws"
summary: "A system can appear secure while becoming less coherent; pseudo-security occurs when visible security proxies remain stable or improve while coherence, auditability, restoration capacity, and boundary integrity degrade."
canonical_statement: "A system can appear secure while becoming less coherent."
core_form: "a system can appear secure while becoming less coherent"
canonical_pattern: "Φ stable or ↑; O↓; Au↓; H↑; ι↑"
security_proxy_divergence_form: "security proxies↑ + coherence↓ ⇒ pseudo-security"
control_substitution_form: "control↑ + restoration↓ ⇒ security debt↑"
failure_form: "dashboard green + Au↓ + H↑ + R↓ ⇒ false security"
restoration_valid_contrast: "security valid when proxies align with O, BΣ, Au, R, FI, and recurrence reduction over Τ"
variables:
primary:
- "Φ_security"
- "security_proxy"
- "compliance_score"
- "incident_visibility"
- "dashboard_status"
- "surveillance_coverage"
- "enforcement_intensity"
- "control_density"
- "restoration_quality"
- "boundary_drift"
- "legitimacy_debt"
- "O"
- "H"
- "H_security"
- "Au"
- "Au_eff"
- "R"
- "R_eff"
- "BΣ"
- "FI"
- "L"
secondary:
- "ε"
- "ι"
- "µᵢ"
- "K"
- "σ"
- "𝓑"
- "𝓓"
- "Φ"
- "Λ"
- "⊗"
- "Γ"
- "Π"
- "Ξ"
- "ℛ"
- "Θ"
- "Σ"
- "Ψ"
- "Τ"
diagnostics:
- "Pseudo-Security"
- "Security Proxy Divergence"
- "Security Coherence"
- "Compliance Theater"
- "Incident Absence Error"
- "Effective Auditability"
- "Hidden Debt"
- "Boundary Drift"
- "Restoration Capacity"
- "Control Substitution"
- "Surveillance Load"
- "Legitimacy Debt"
- "Feedback Integrity"
- "Temporal Proof"
failure_modes:
- "Pseudo-Security"
- "Security Theater"
- "Compliance Theater"
- "Consent Theater"
- "Over-Surveillance"
- "Emergency Normalization"
- "Audit Suppression"
- "Incident Absence Error"
- "Dashboard Capture"
- "Metric Substitution"
- "Boundary Drift"
- "Control Substitution"
- "Restoration Failure"
- "Hidden Debt Accumulation"
- "Legitimacy Debt"
restoration_arcs:
- "Pseudo-Security Dissolution"
- "Security Coherence Restoration"
- "Security Proxy Audit"
- "Auditability Restoration"
- "Boundary Reconstitution"
- "Restoration Capacity Increase"
- "Control-to-Restoration Re-Sequencing"
- "Surveillance-to-Restoration Routing"
- "Hidden Debt Reduction"
- "Feedback Integrity Restoration"
- "Legitimacy Repair"
- "Temporal Validation"
related_laws:
- "LAW-001"
- "LAW-002"
- "LAW-003"
- "LAW-004"
- "LAW-006"
- "LAW-007"
- "LAW-009"
- "LAW-010"
- "LAW-011"
- "LAW-012"
- "LAW-013"
- "LAW-015"
- "LAW-016"
- "LAW-020"
- "LAW-023"
- "LAW-030"
- "LAW-031"
- "LAW-036"
- "LAW-037"
- "LAW-040"
- "LAW-041"
- "LAW-045"
- "LAW-048"
- "LAW-050"
- "LAW-052"
- "LAW-057"
- "LAW-064"
- "LAW-065"
- "LAW-066"
- "LAW-067"
- "LAW-083"
- "LAW-102"
- "LAW-103"
- "LAW-104"
- "LAW-105"
- "LAW-109"
- "LAW-111"
- "LAW-112"
- "LAW-113"
- "LAW-115"
- "LAW-116"
- "LAW-117"
- "LAW-118"
- "LAW-119"
- "LAW-120"
- "LAW-122"
- "LAW-123"
- "LAW-124"
- "LAW-130"
- "LAW-134"
related_invariants:
- "INV-001"
- "INV-002"
- "INV-006"
- "INV-073"
- "INV-078"
operator_sequence:
coherent:
- "security proxy appears"
- "Θ prevent proxy certainty"
- "Γ classify proxy / signal / artifact / debt"
- "Σ define proxy validity scope"
- "Au/FI test proxy against field effects"
- "map O + BΣ + R + H"
- "ℛ repair divergence"
- "Ψ validate affected-node effects"
- "Τ validate proxy alignment over time"
inverted:
- "security proxy improves"
- "confidence↑"
- "Γ treats proxy as truth"
- "Au narrows"
- "weak signals ignored"
- "R lags"
- "H_security↑"
- "Ξ / ι↑"
- "incident shock appears late"
aliases:
- "Pseudo-Security Law"
- "Security Theater Law"
- "Appearing Secure While Degrading Law"
- "Security Proxy Divergence Law"
- "Compliance Theater Security Law"
- "False Security Coherence Law"
- "Security Appearance Divergence Law"
deduplication_note: "Root pseudo-security law. LAW-112 defines security as sustained coherence. LAW-113 defines visible incidents as lagging indicators. LAW-115 specializes surveillance without restoration. LAW-116 specializes emergency normalization. LAW-124 specializes AI rule-stacking as a pseudo-safety pattern."
source: "content/archive/laws/technical.md"15. Compact Card Version
LAW-114 — Pseudo-Security Law
A system can appear secure while becoming less coherent.
Core form:
a system can appear secure while becoming less coherentCanonical pattern:
Φ stable or ↑
O↓
Au↓
H↑
ι↑Plain meaning:
A system may look secure because incidents are low, dashboards are green, policies are complete, compliance boxes are checked, monitoring is extensive, or enforcement is strong. But if coherence, auditability, boundary integrity, restoration capacity, and legitimacy are degrading, the system is pseudo-secure.
Security proxy divergence form:
security proxies↑ + coherence↓ ⇒ pseudo-securityFailure form:
dashboard green + Au↓ + H↑ + R↓ ⇒ false securityPrimary variables:
Φ_security, security_proxy, compliance_score, incident_visibility, dashboard_status, surveillance_coverage, enforcement_intensity, control_density, restoration_quality, boundary_drift, legitimacy_debt, O, H, H_security, Au, Au_eff, R, R_eff, BΣ, FI, L, Γ, Π, Ξ, ℛ, Θ, Σ, Ψ, Τ
Diagnostic signature:
Security proxy and confidence rise while audit depth falls, weak signals are ignored, restoration capacity remains flat, boundary drift increases, and hidden debt rises. This indicates pseudo-security.
Failure risk:
Pseudo-security, security theater, compliance theater, consent theater, over-surveillance, emergency normalization, audit suppression, incident absence error, dashboard capture, metric substitution, boundary drift, control substitution, restoration failure, hidden debt accumulation, legitimacy debt.
Restoration priority:
Identify the security proxies in use, test them against coherence variables, audit incident visibility and hidden security debt, restore auditability and boundary integrity, route sensing and enforcement into restoration, reduce recurrence, and validate proxy alignment over time.