Ratchet Forecasts
Six falsifiable projections built from the documented record — each names its base-rate pattern, its mechanism, a calibrated confidence, and the exact observation that would prove it wrong.
Contents
A large historical record earns the right to forecast. It does not earn the right to prophesy.
The difference is a falsifier. Every projection below rests on a named, documented base-rate pattern already logged elsewhere on this site; states the mechanism that carries it forward; carries a calibrated confidence tied to how many instances the pattern has and whether a live counter-force is pushing back; and — the part that separates a forecast from a vibe — names the explicit observation that would break it, with a horizon. A prediction with no refutation condition is not on this page. These are mechanism-grounded projections with real uncertainty, not certainties, and where the underlying pattern involves a contested framing the framing is attributed, not adopted.
Confidence tiers. HIGH = many documented instances, strong mechanism, no counter-instance in the record. MODERATE = clear pattern, but fewer instances or a live counter-force. LOW = plausible, thin base. (No forecast here is LOW; the thin ones are held back until their instance-set is built.)
Where it appears in print: The Ratchet (Book 2) is the spine — the argument that a control capability, once installed, does not roll back. Evil Robots (Book 1, Chapter 1) supplies the prediction-to-reality ladder that F1 extends. This page is the falsifiable-projection layer over both.
The scoreboard
| # | The call | Confidence | Falsified if… | By |
|---|---|---|---|---|
| F1 | Newly-theorized AI-safety failures get lab-confirmed faster than any prior entry | HIGH | no post-2025 theorized failure is lab-confirmed, or the lag lengthens past 8 yrs | end-2028 |
| F2 | Every “AI safety” control capability persists past its stated rationale | HIGH | any major jurisdiction repeals one within 3 yrs of enacting it, with no equal-or-greater replacement | rolling 3 yr |
| F3 | AI-governance bodies show the WHO capture signature | MODERATE | a per-entity leverage profile shows LOW funder concentration AND a thin revolving door | on graph completion |
| F4 | Pass-through funding concentration and opacity keep rising — in both partisan networks | MODERATE | pass-through advocacy revenue falls materially two years running, or mandatory donor disclosure becomes law and survives challenge | 2028 |
| F5 | UBI / programmable-benefit rails expand as the displacement remedy | MODERATE | no major economy adopts a permanent broad income-transfer or programmable-benefit regime, or displacement measurably reverses | 2032 |
| F6 | Political prosecutions continue both ways and keep self-defeating on structure | MODERATE | such prosecutions decline sharply, or the marquee ones start resolving on the merits rather than on procedural defects | rolling 3 yr |
The grounding patterns
Each forecast is anchored to a pattern documented elsewhere in the corpus — click through to the receipts.
- P1 — The prediction-to-reality lag is shrinking. The ladder in Evil Robots (Book 1, Chapter 1): self-preservation predicted 2008, confirmed in labs 2025 (17 yrs); deceptive alignment 2014 → 2024 (10 yrs); off-switch resistance 2017 → 2025 (8 yrs); power-seeking 2021 → 2025 (4 yrs). The confirmations themselves are logged at AI Agent Incidents, with the platform-side timeline at Prompt-Injection Timeline.
- P2 — The ratchet never reverses. The spine of The Ratchet: each safety or emergency measure creates a control capability that does not roll back once the justifying crisis passes. The count-your-own-clicks version is The Ratchet Clicks; the mechanism generalized is The Universal Capture Mechanism.
- P3 — The capture playbook migrates. Fund it, staff it through the revolving door, then permeate the standard-setting. Documented at the WHO — voluntary contributions above 75%, most of it earmarked, the top-ten donors supplying the majority of the budget (WHO on its own funding) — and traced into the AI apparatus in The AI Governance Ratchet and the live AI Governance Tracker. The health-body precedent is The Health Governance Ratchet.
- P4 — Funding concentration and opacity rise. Donor-advised-fund and fiscal-sponsor structures keep growing as a share of advocacy money — DAF grants and assets have climbed every year on record (National Philanthropic Trust DAF Report; IRS on donor-advised funds). The pattern is symmetric: pass-through networks of comparable scale operate on the left (Arabella-managed nonprofits) and the right (DonorsTrust and the Marble/Bradley orbit), figures as reported by investigative outlets. The mechanism is the pawl; the faction is the variable.
- P5 — Displacement resolves into managed dependency. Automation exposure is large — the IMF puts roughly 40% of global employment as exposed to AI (IMF, “AI Will Transform the Global Economy”) — and the builders themselves propose UBI as the remedy. A remedy delivered as conditional, programmable transfer is a management system; the rails are traced in CBDCs and Programmable Money.
- P6 — Prosecution-as-instrument, with structural self-defeat. The instrument is wielded in both directions, and a recurring share of the marquee cases collapses on procedural or appointment defects rather than on the merits — the pattern is mapped, with the same evidentiary bar for every faction, on the Lawfare Tracker; the institutional backdrop is The Legal Establishment.
The forecasts
F1 — AI-safety confirmations arrive faster (from P1)
Projection. The next class of AI-safety failures now being theorized — sabotage of oversight at scale, cross-model collusion, situational-awareness gaming of evaluations — will be demonstrated in frontier labs within roughly two to four years of first formal statement, a shorter lag than any prior rung on the ladder.
Mechanism. Two curves converge: capability keeps rising, and red-teaming keeps intensifying. More capable systems exhibit the theorized behavior sooner, and more people are looking for it when they do. The lag between theory and confirmation compresses.
Confidence: HIGH. Four documented instances, a monotonic shrink (17 → 10 → 8 → 4 years), and a mechanism with no visible brake.
Falsified if: by end-2028 no newly-theorized (post-2025) safety failure has a documented lab confirmation, or the theory-to-confirmation lag lengthens back above eight years.
F2 — Every “AI safety” control capability persists past its rationale (from P2)
Projection. Measures introduced as AI safety — mandatory model registration, compute-threshold reporting, age and identity verification, provenance and watermark mandates — remain and expand after the specific fear that justified them recedes. None roll back.
Mechanism. A capability, once built, has a constituency: the office that administers it, the vendors who service it, the adjacent uses it turns out to enable. The crisis is the pretext for installation; the infrastructure is the payload, and infrastructure does not uninstall itself.
Confidence: HIGH. P2 has no documented counter-instance in the corpus — across twenty tracked mechanisms, none has rolled back.
Falsified if: any major jurisdiction repeals an AI-safety control capability within three years of enacting it, absent a replacement of equal or greater scope.
F3 — The AI-governance bodies show the WHO capture signature (from P3)
Projection. The AI-governance bodies — the AI Safety Institutes, the Frontier Model Forum, the standards-writers — will exhibit the same measurable signature already visible at the WHO: high funder concentration, heavy earmarking, and a revolving door between the funded labs and the “safety” bodies that evaluate them.
Mechanism. The playbook is portable because the incentive is identical. Whoever funds the evaluator, staffs it, and writes its standard defines what “safe” means — and at the AI layer the funders, the staff pool, and the standard-authors are, at each layer, the industry being governed. The entities already sit in the governance graph; a serving general moving onto a frontier lab’s board is the revolving door in a single frame (OpenAI’s own announcement).
Confidence: MODERATE. The mechanism is strong and the entities exist, but there are fewer years of data than the WHO baseline has.
Falsified if: a per-entity leverage profile of these bodies, once built, shows LOW funder concentration and a thin revolving door.
F4 — Funding concentration and opacity keep rising, symmetrically (from P4)
Projection. Through 2028, the pass-through share of advocacy funding keeps growing and stays opaque on both sides — donor-advised-fund and fiscal-sponsor structures continue to intermediate more money with less disclosure — notwithstanding the 2026 Treasury enforcement push.
Mechanism. The DAF and the fiscally-sponsored pop-up group are legal, cheap, and disclosure-light; each new cycle of political money finds the path of least reporting. The counter-force is real — an enforcement action can bend the curve — but the structural pull is toward more intermediation, not less.
Confidence: MODERATE. The growth trend is clear; the live counter-force (the Treasury action) is exactly what keeps this off HIGH.
Falsified if: total pass-through advocacy revenue across both networks falls materially for two consecutive years, or mandatory donor disclosure becomes law and survives legal challenge.
F5 — UBI / programmable-benefit rails expand as the displacement remedy (from P5)
Projection. UBI pilots and programmable-benefit infrastructure — CBDC-adjacent, conditional — expand in scope over the decade as automation exposure bites. The managed-dependency layer forms.
Mechanism. The exposure is documented and the builders themselves propose income transfers as the fix. A transfer built on programmable rails carries conditionality for free; the remedy for displacement arrives as a system for administering the displaced.
Confidence: MODERATE. Exposure is well-documented and the remedy is on the table, but political resistance to both UBI and programmable money is genuine.
Falsified if: no major economy adopts a permanent broad income-transfer or programmable-benefit conditionality regime by 2032, or automation-driven displacement measurably reverses.
F6 — Prosecution-as-instrument continues both ways and keeps self-defeating on structure (from P6)
Projection. High-profile political prosecutions continue in both directions, and a recurring share of the marquee ones collapse on procedural or appointment defects — disqualified prosecutors, Appointments-Clause problems, authority the charging office turned out not to have — rather than on the merits.
Mechanism. When the process itself is the payload, cases get brought that the underlying law cannot carry; the structural shortcut that makes the prosecution fast is the same defect that makes it collapse. This is a claim about a pattern, attributed to the sourced record — not a prediction that any named person will be charged or cleared.
Confidence: MODERATE. The pattern is documented across factions on the Lawfare Tracker, but political-prosecution volume is volatile and the sample is small.
Falsified if: over the next three years political prosecutions decline sharply, or the marquee ones start resolving decisively on the merits rather than on structural defects.
Method coverage
The six span deliberately distinct ratchet methods so the model is not single-track: capability-timeline (F1), regulatory permanence (F2), institutional capture (F3), funding opacity (F4), economic dependency (F5), and lawfare (F6). Others — surveillance normalization, the designation machine, CBDC conditionality, platform jawboning — are patterns in the record but do not yet carry enough documented instances to support a calibrated forecast; they stay off this page until their instance-set is built. A thin base is a reason to wait, not to guess.
Bridges
- AI Governance Tracker — the live instrument-by-instrument record F3 is tested against; the “Who Governs the Governors” section is the WHO-signature read in progress.
- Revolving Door — the industry → government → industry pipeline that is the F3 mechanism rendered as a graph.
- The Ratchet Clicks — the twenty control mechanisms behind F2, scored where you live.
- Lawfare Tracker — the both-directions, structural-collapse record behind F6.
Sources
Inline at each point of claim above. The external primaries:
- WHO — how it is funded — the capture-signature baseline (P3 / F3).
- OpenAI — appointment to the board — the revolving door in one frame (F3).
- National Philanthropic Trust — DAF Report and IRS — donor-advised funds — the DAF-growth mechanism (P4 / F4).
- IMF — “AI Will Transform the Global Economy” (archived) — the ~40% exposure figure (P5 / F5).
Companion research: The AI Governance Ratchet, The Universal Capture Mechanism, CBDCs and Programmable Money, The Legal Establishment.