The Sequence · Part II · What To Do
12. The Catches
Collusion, false tips, chilling effects, and everything else that goes wrong.
Everything up to here has been the case for. This page is the case against, and I have tried to write it the way an opponent would rather than the way an advocate would. Each objection gets stated at its full strength before I say anything in reply, and where I have no reply I say so instead of manufacturing one.
It is worth noticing before we start that the objections come in two kinds, and that almost all published discussion of bounty mechanisms only runs the first.
Failure modes are the ways the mechanism does not do what it says: it gets gamed, the arithmetic is wrong, the money does not flow, the incentives point somewhere unexpected. These are engineering problems. Some have fixes, some do not, and you can argue about them productively.
Success costs are what you get when the mechanism works exactly as designed. A society that has adopted this is a society with a standing cash price on informing against your colleagues, and that is true on the good branch, not the bad one. You do not get to design this away, because the informing is the mechanism.
I think the second kind is where the real problem lives, and I have put it last for that reason.
Collusion
The attack is straightforward and it is the first thing anyone with a taste for mechanism design will reach for. A bounty hunter who finds a violation has two options: turn it in for the statutory share, or go to the offender and sell silence for more. If the fine is $50 million and the informant’s share is $10 million, there is a wide band — anything from $10 million to $50 million — in which both parties strictly prefer the private deal to the public one. The mechanism has not created an enforcement market. It has created a blackmail market with better information.
The intended defense is competition. If many parties can investigate and any of them can turn in a colluding enforcer, then a private settlement is only worth buying if you are confident you have bought off everyone who knows, and that confidence is exactly what the design is meant to destroy.
Making collusion itself a separately bountied offence would close the loop more tightly — the second informant’s payday becomes the first informant’s deal — and it is the move most people reach for next. I am genuinely undecided about whether it is needed. It is a rider rather than a load-bearing component, and the reason it might be unnecessary only became clear to me after working through the section below.
That is a real answer and I do not think it is a complete one. The version of this objection raised against my own 2023 write-up is sharper than the naive one: it is not the offender who has the strongest incentive to settle privately, it is the insurer. A large gap between what the insurer stands to lose in court and what the bounty hunter stands to gain from filing creates enormous surplus from a quiet deal, and the insurer is a sophisticated repeat player with lawyers, unlike the offender. Narrowing the gap — a bounty that is a large fraction of the fine rather than a small one — shrinks the surplus but does not eliminate it, and it makes the fine expensive in other ways. I do not have a clean solution to this.
What Hanson says about blackmail, which cuts against me and then for me
It would be dishonest to raise this objection without noting that the author of the underlying mechanism has argued at length that blackmail should be legal, and that his reasoning bears directly on whether collusion is the failure I have just described.
Hanson’s position is that blackmail is gossip plus a price : if it is legitimate to tell people what someone did, it is hard to say why it becomes illegitimate to offer not to.
Hanson's three posts on blackmail
Nearly everything people dislike about blackmail, he argues, is something they dislike about gossip — and we permit gossip.
He goes further, arguing the ban is plausibly elite self-protection rather than public-spirited: law permitted gossip about elites only recently, and raised blackmail penalties in compensation.
And he weighs how much legalisation would really increase the hunt for secrets , concluding it would be mild for ordinary people and strong for the powerful.
I am not going to adjudicate that. I want the part that applies here, and applying it made me restate my own objection more precisely.
Collusion does not remove the deterrent. It redistributes the payment.
Work the numbers above. The offender pays somewhere between $10 million and $50 million either way. File, and the money goes to the state with a share to the hunter. Settle, and it all goes to the hunter. From the offender’s chair — the only chair a deterrent has to operate on — the expected cost of crossing the line is about the same in both worlds. This site’s claim is about shifting the Nash equilibrium of taking the job at all, and a large expected payment to a blackmailer shifts it roughly as well as a large expected payment to a court.
So my own sentence above — “it has created a blackmail market with better information” — is true, and is not the indictment I intended it as. A blackmail market with good information is a market in which dangerous conduct is expensive. That was the requirement.
This is also why I am no longer sure the anti-collusion rider is necessary. If private settlement preserves the deterrent, then criminalising it buys information rather than deterrence, and it should be argued for on that basis instead of being assumed.
What is actually lost, which is not deterrence
The public record. A quiet settlement means nobody learns the conduct happened. No corrective action, no regulatory learning, no update to anyone else’s picture of what labs are doing — and the conduct may continue, having been paid for rather than stopped.
Although I should immediately complicate that, because writing it out made me notice the arithmetic runs the other way.
A settlement is not a lump sum. It is the first instalment of an annuity, and it is an annuity with no contract behind it. Blackmail agreements are unenforceable by construction — you cannot sue to compel someone to keep accepting your money in exchange for silence — so the payer acquires no right to anything. What they have bought is one period of quiet from one person.
Now iterate. If the conduct continues, it keeps generating fresh grounds for a claim, so there is something new to be paid for next quarter. The payer’s accumulated exposure grows with every instalment, which means their willingness to pay rises over time, which means the rational blackmailer escalates. This is an ordinary hold-up problem and it has the shape everyone recognises from protection rackets: paying the mafia is famously not a purchase, it is a subscription with an escalator clause and no terms.
And has not gone anywhere. Every additional person who independently notices is an additional claimant who must also be paid, in parallel, with no discharge and no way to coordinate them without revealing the arrangement to all of them. How large actually is, and whether it is shrinking, is the question Team Size Is a Governance Variable takes up; the honest answer is that this whole section is an argument about a quantity nobody currently tracks. The conspiracy arithmetic from page 07 reappears on the blackmail side, and it is worse there, because a colleague who files is done with you and a colleague who is being paid never is. Any of them may hit their own liquidity problem, lose patience, be fired, or simply reconsider, at which point the payer has funded years of silence and still gets the claim.
Set the two options side by side properly and they are not close. Filing produces a liability that is bounded, adjudicated, insured and final. Settling produces one that is unbounded, unadjudicated, uninsured and perpetual, owed to a growing set of counterparties none of whom can be held to anything. The naive analysis that found a wide band in which both parties prefer the private deal is a single-period, single-counterparty analysis, and neither of those assumptions survives contact with a real organisation.
That is not a proof that collusion will not happen. People are myopic, the first payment is much cheaper than the first fine, and someone under acute pressure will take the deal that solves this month. But it does mean the equilibrium is considerably less attractive than it looks, and I had written the objection as though the offender got to buy their way out once. They do not.
The insurer-side version of the objection survives this, incidentally, and that is why it remains the sharper one. An insurer is a sophisticated repeat player, it can settle many claims as a portfolio, and it has lawyers who understand exactly the hold-up dynamics above. It is the one party in this picture equipped to make quiet settlement work as a strategy.
The price signal, which is the one that matters. Page 08 argues the load-bearing output here is not the fine but the premium: a continuously updated market estimate of how much your colleagues can be trusted. A settlement the insurer never hears about does not move that number. And in the sharp version of this objection, where the insurer buys the silence, the insured researcher pays nothing, learns nothing, and may see no repricing at all. That version does break deterrence, because it insulates the exact person whose behaviour the mechanism exists to change.
A fix for the second one, which I did not have before
The insurer-collusion case has an answer, and it is dull insurance drafting rather than clever mechanism design.
Rate the policy on incidents notified or settled, not on claims adjudicated. A great deal of professional liability already works this way: claims-made policies oblige the insured to notify circumstances that might give rise to a claim, and those notifications affect renewal whether or not anything is ever litigated. Write the trigger that way and an insurer’s quiet settlement still reprices the insured, because the settlement is itself the rating event. The surplus from a private deal shrinks toward the litigation cost it saves, which is the only part of it that ought to exist.
I will not stop on a win, because it leaves a hole. An insurer with a reason to keep an incident off the register now has a reason to keep it off the register, and verifying that insurers record what they settle means auditing insurers — reintroducing, in one narrow place, the regulator this mechanism was meant to avoid needing. It is a far smaller regulator than a licensing authority with a far more checkable job, and I would take that trade. But it is a trade, and page 11’s table scores my corruptibility row on the assumption that there is no chokepoint worth buying. This is the closest thing to one.
False and manufactured evidence
The same money that makes reporting attractive makes framing attractive. Any mechanism that pays for evidence is a mechanism that pays for the production of evidence, and the production of evidence is not reliably distinguishable from the fabrication of it by anyone standing outside the process.
The structural protection is that payment is contingent on conviction, not on accusation, which kills the low-effort version immediately — a frivolous filing earns nothing and costs the filer time. A refundable filing fee, ordinary standards of proof and judicial discretion do the rest of the routine work.
I no longer think a special penalty for false claims is needed on top of that, and I suspect it would be actively harmful. Contingency plus a fee already makes speculative filing a losing proposition; an additional penalty mostly falls on the marginal honest reporter, who is uncertain whether what they saw crosses the line and is exactly the person you least want to frighten off. Ordinary sanctions for perjury and abuse of process already exist and are sufficient.
The market would do the screening
There is a second answer I find more persuasive than any of the procedural ones, and it follows from expecting this market to specialise rather than stay flat.
The likely shape is two-tier. A large number of people supply raw material — documents, observations, timelines — for relatively modest sums, because that is all their individual contribution is worth. A much smaller number of specialist firms buy, aggregate and synthesise that material into something a forum will actually accept, and those firms are paid on success.
Paid on success is the whole point. A synthesiser who advances a fabricated case loses its filing fee, its investigative cost, and its reputation with the forum it has to return to next month. It therefore has a powerful commercial reason to develop exactly the capability the objection says nobody has: distinguishing evidence that was found from evidence that was made. That screening function does not have to be legislated or staffed by a regulator, because somebody’s margin depends on performing it well.
This is not hypothetical either. The qui tam relator’s bar screens cases before filing because bad cases cost money. Bug bounty platforms run triage teams whose entire job is separating real findings from noise before anything reaches the vendor. Litigation funders underwrite claims on exactly this basis. In each case the vetting emerged from the incentive rather than from a rule requiring it.
Why the existing literature is a warning and not a comfort
The user of this argument should be careful, because the closest body of evidence about paid evidence is not encouraging.
Incentivised testimony is one of the best-documented failure modes in criminal justice. Jailhouse informant testimony is the canonical instance and it is notoriously unreliable, because a witness trading testimony for a sentence reduction is strongly motivated to say what the prosecution wants to hear. Anybody proposing to pay for evidence at a larger scale should read that record first, and I am not going to pretend it says something reassuring.
How often paid testimony goes wrong
From the National Registry of Exonerations, 56% of wrongful convictions cite false accusation or perjury as a contributing factor — rising to 68% in homicide cases.
What I will say is that the incentive structure which produced that record is close to the worst possible version, and differs from this one in three ways that matter. The jailhouse informant is paid in liberty, which is worth more than money and cannot be clawed back. They are paid by the prosecution, which is also the party deciding whether to believe them, so nobody with resources is adversarially testing the informant’s motive. And they bear no cost for being wrong.
Invert all three. A bounty claimant bears their own filing and investigative costs. The defendant is funded by an insurer with money at stake and a direct interest in exposing the claimant’s incentive, which is the adversarial test the criminal version lacks. And the payoff arrives only on a finding, not on an accusation. The law already knows how to handle incentivised evidence when it bothers to: corroboration requirements for interested testimony are old and standard, and would be the obvious thing to write into a bounty statute.
Better-designed is not the same as safe, and I do not want the previous paragraph to read as though the problem has been handled.
What none of that touches is the sophisticated case: a colleague with genuine access who arranges the record so that something ambiguous reads as something deliberate. Conviction-contingency is not much of a filter against someone who can make the case look real, because the case does look real. Every existing whistleblower reward program lives with some version of this and manages it rather than solving it, and I should be honest that I am proposing to live with it too, at a scale where the payouts are much larger and therefore the incentive is much stronger.
The definitional problem
Where is the line? The mechanism needs a statutory description of the prohibited activity precise enough for a court to apply and stable enough to plan a career around. Every candidate I can construct is either narrow enough to route around — a compute threshold you stay just beneath, a technique you rename — or broad enough to catch work that is fine, or actively good, including safety work itself.
That last part is the one that should worry a proponent most. A regime that makes interpretability research legally hazardous has damaged the thing it was trying to protect. Graduated penalties, good-faith defenses, and safe harbors for defensive work are the standard remedies and they are genuinely useful, but they reintroduce the discretion the mechanism was partly designed to remove.
Every alternative in Compare and Contrast has the identical problem. Licensing needs a line. Compute caps need a line. Moratoria need a line. That is not a reason to think mine works; it is only a reason not to treat this breakage as decisive between them.
Why I now think this is less hard than it looks
I have come round on this, and the reason is that I was assuming the line had to be a rule when it can be a standard.
A rule is specified in advance: cross this many floating-point operations and you are liable. It is predictable, and it is exactly as gameable as it is predictable, because a number written down is a number you can sit just beneath. A standard is specified after the fact by an adjudicator applying an objective test to what you actually did. Law runs on standards constantly and always has — reasonable care, material, good faith, unfair competition. Negligence has operated for several centuries without anyone enumerating the careless acts.
This matters because the whole complaint above is a complaint about rules. “Narrow enough to route around, or broad enough to catch good work” is the rule-maker’s dilemma, and Kaplow’s 1992 treatment of rules versus standards is the standard reference for why you pick one over the other: rules when conduct is homogeneous and frequent, standards when it is heterogeneous and rare. Frontier AI development is heterogeneous and rare. It is close to the textbook case for a standard.
It also resolves the tension with the Goodhart argument on the previous page. A rule is a specification, so it gets optimised against. A standard cannot be optimised against in the same way, because there is no document to satisfy — you find out afterwards whether what you did was over the line, which is uncomfortable and is also the entire point.
The “I know it when I see it” version, and why I will not lean on it
The tempting move here is Justice Stewart’s line about obscenity in Jacobellis in 1964: he could not define it, but he knew it when he saw it. Training a frontier model, or deliberately pursuing recursive self-improvement, feels like that kind of thing.
I want to resist the temptation, because that test is famous for failing. The Supreme Court abandoned it within a decade, replacing it in Miller with a three-part test, precisely because “I know it when I see it” gave lower courts and citizens no guidance at all. It is the canonical example of an unworkable standard rather than a model for one. A workable standard has an articulable test and accumulating precedent. Stewart’s had neither.
What does survive is the observation underneath it. The prohibited activity may be hard to define but it is not hard to recognise, because it has enormous physical and institutional signatures: accelerator procurement at scale, grid interconnects measured in tens of megawatts, export-controlled hardware, capital raises, and a labour market so small that hiring forty reinforcement-learning researchers in a quarter is visible to everyone in the field. Courts handle this kind of thing routinely — you do not need a precise definition of a trafficking organisation when you can show the money, the logistics and the personnel. Those signatures are also, as page 11 argues , exactly what an underwriter would want anyway.
On strategic ambiguity, where I part company with myself
There is a further argument that some vagueness is a feature, and I should say first that I think the deterrence of people who never start is the whole product rather than a bonus: if nobody is quite sure where the line is, firms and researchers stay well clear of it, and the deterrence of people who never start is where most of the value lives. I think the second half of that is right and the first half is the wrong way to get it.
The problem is that deliberately maintained ambiguity, justified by its chilling effect, is close to a textbook description of a statute that gets struck down. Void-for-vagueness and overbreadth doctrines exist for this, and “chilling effect” is a phrase courts use when invalidating a law rather than when praising one. A regime whose defenders say in public that the uncertainty is the point has handed its opponents the brief.
It is also in tension with the worry that opened this section. Ambiguity chills indiscriminately. The work most likely to be abandoned under an unclear rule is the marginal, cautious, well-documented project run by people with something to lose — which includes interpretability and safety work, and excludes precisely the actor who was going to proceed regardless.
The good news is that a standard delivers most of what strategic ambiguity was supposed to deliver, without either problem. Standards are uncertain at the margin, deliberately, and nobody thinks negligence is void for vagueness. The difference is that the uncertainty is bounded by an articulable test, narrowed by precedent as cases accumulate, and paired with explicit safe harbours for defensive and interpretability work. You still get the caution. You get it from a mechanism that survives judicial review and that a careful researcher can actually navigate.
So my position has moved. The definitional problem is real, it is not solved, and it is no longer the thing on this page I am most worried about.
Who can actually pay
The mechanism runs on the offender’s ability to pay, which means it bites hardest on whoever has the least capacity to absorb it.
Run it forward. Premiums scale with assessed risk. A large lab has capital, a compliance department, a relationship with an underwriter, and the ability to structure its work so as to price well. A four-person startup has none of that, and an unfunded open-source contributor cannot buy coverage at any price. The predictable equilibrium is that the mechanism becomes a moat: expensive but survivable for incumbents, prohibitive for everyone else. Since the point was to make large well-funded teams a worse proposition specifically, an outcome that entrenches exactly those teams is not a side effect. It is the failure mode pointed directly at the thesis.
I wrote that before working out the insurance leg properly , and I now think it is substantially wrong — the scaling is not something anyone has to specify, because the arithmetic does it.
The insured party is the individual, not the firm. So a four-person startup does not buy a corporate policy it cannot afford. Its four people each carry personal cover priced on their own exposure, and that exposure runs on , where is how many people know. At that number is small, so the premium is small, and nobody had to calibrate anything for it to come out that way. At it is close to one. Page 09’s table shows total liability rising superlinearly in headcount, which means the cost per person rises too.
Which inverts the objection. A moat is created by fixed compliance costs, because fixed costs fall hardest on the small — that is Stigler’s account of licensing on the previous page, and it is a real description of what a licensing regime does. This mechanism has near-zero fixed cost and a variable cost that climbs with team size. It is close to the opposite profile. The large well-funded lab does not absorb it more comfortably than the startup; it pays superlinearly more than the startup, per person, for the same work.
The unfunded open-source contributor is the remaining case, and the answer there is that they are outside the mechanism rather than crushed by it. With of one or two, is nearly zero and so is any premium worth quoting. I should say plainly what follows: this mechanism does very little to deter the lone actor. It is not designed to, and the reason the site is comfortable with that is page 09’s argument that nobody builds a frontier model alone, in a world where nobody can make a pencil alone either. If that assumption fails, a great deal more than this section fails with it.
Two residues I will not pretend away. A large lab has a broker, a claims history and a relationship; a startup faces worse terms for identical risk simply through inexperience, which is a real if modest incumbent advantage. And if labs reimburse premiums, the ability to absorb the cost re-enters as an advantage for whoever has the most cash — which is the reimbursement problem from page 08 arriving here in different clothes. The related question of what happens when the guilty party simply cannot pay is worked through in a separate note .
The arithmetic is more fragile than it looks
Page 07 rests on a piece of arithmetic: with a hundred people each independently silent nine times in ten, somebody talks about two-thirds of the time. The load-bearing word is independently, and it is false.
Colleagues are not independent draws. They share a workplace culture, a set of beliefs about whether the work is dangerous, the same employment lawyer, the same non-disclosure agreement, the same social network, and the same set of consequences for defection. Silence is correlated, and correlated silence is far more stable than the formula implies.
The damage is worse than a knocked-down number, and I have put the cohesion term into the model on page 07 rather than repeating the derivation here. The result is the part that hurts: under correlation the discovery rate does not merely fall, it stops climbing. It flattens at a ceiling set by how cohesive the team is, and no amount of further hiring raises it. Page 07’s most distinctive move — that the mechanism gets stronger as the team gets bigger, so the largest and most dangerous efforts are the most exposed — depends entirely on that curve continuing to go up. Under correlation it does not. It asymptotes, at a number that is plausibly higher at exactly the well-funded, high-conviction, mission-driven organisations the argument is aimed at.
The honest response is that a large bounty is itself a decorrelating device: it is a shock applied individually to each person, and money is quite good at dissolving shared conviction. That is the argument, I believe it, and it is not the same thing as the tidy exponential. It also means the quantity the mechanism has to move is cohesion rather than headcount, which is a harder thing to measure and nobody is measuring it — the team-size paper is about how badly.
Whether the insurance leg works at all
This is the strongest technical objection I know of, and it comes from outside the AI-risk conversation entirely.
The Insurer claims that the premium, not the bounty, is what does the continuous deterring — that underwriters price your specific behavior with their own money at stake and raise your bill the moment you start looking dangerous. Daniel Schwarcz and Josephine Wolff have argued directly against the general form of that claim in The Limits of Regulating AI Safety Through Liability and Insurance: Lessons From Cybersecurity . Their case is that insurers cannot price this class of risk in a way that improves safety, because there is no reliable historical loss data, the technology changes faster than an actuarial model can be built, the systems are opaque even to the firms operating them, and AI is too deeply integrated into operations to isolate. The cybersecurity precedent is the evidence: faced with exactly those conditions, cyber insurers ended up helping clients limit liability rather than reduce risk.
If that is right, the deterrence I attribute to the underwriter’s office is imaginary. The insurance leg would still supply capital to pay fines, which is not nothing, but the continuous, priced, pre-prosecution pressure that page 08 treats as the working half of the mechanism would simply not exist.
My answer is that every obstacle they identify is an obstacle to pricing harm, and the premium in this design does not price harm — it prices the chance that somebody in the room files a claim, which is a question about organisational secrecy rather than about machine learning. Page 08 makes that case in full , along with the two structural differences between a cyber claim and this one, and I am not going to re-run it here.
What belongs on this page is that the objection is not fully answered. Part of it survives the reply, and the surviving part is aimed at the half of page 08 I would otherwise have leaned on: insurance as a non-price regulator, the audit rights and the coverage conditions, is exactly what cyber insurers attempted and it underdelivered. So the honest position is narrower than page 08 started out claiming. This mechanism should be expected to work through the premium, and not at all through the underwriter’s clipboard.
The informant economy, which I can only partly answer
Here is the objection I have no good answer to, and I have thought about it more than any other item on this page.
Suppose it all works. The line is drawn well, collusion is suppressed, the evidence is sound, the premiums are priced, the dangerous projects do not get staffed. What you have built is a country in which a large cash reward attaches to informing on the people you work beside, in which insurers hold audit rights over technical work — the monitoring flagged as a feature on page 08 — and in which every professional relationship in a whole industry carries a quiet financial reason to defect.
The twentieth century ran informant systems at scale in several countries, and the temptation is to reach for them here. I have decided not to, because on reflection I think the comparison is not merely unfair but actively misleading, and reaching for it would concede something that is not true.
The variable that matters is not whether informing is paid. It is how large and how well-defined the prohibited class is. The secret-police systems of the last century targeted speech, association and belief — categories that were open-ended by design, so that everyone was a plausible subject and no one could establish that they were safe. That is what produced the damage to ordinary trust that people who lived under them describe. It was not the payment. It was the unboundedness.
Now look at the closest live comparison, which is not a police state at all. The United States has run a paid informant system continuously since 1863, the sums are frequently enormous, and it has been strengthened rather than curtailed for over a century.
The paid informant system already running
The False Claims Act pays private relators between fifteen and thirty per cent of what the government recovers. The precedents on page 07 include a relator taking roughly $266 million of a $900 million settlement.
The SEC and IRS whistleblower programmes do the same thing with similar money.
Has American social trust been corroded by this? I see no evidence for it, and the reason is instructive: almost nobody knows the False Claims Act exists. Its covered class is people submitting claims for payment to the federal government. If you are not doing that, the statute is not about you, and you will live your whole life without encountering it. The people who lose sleep over qui tam are people running large-scale billing fraud, which is the intended population and a very small one.
That is the right reference class for a keyhole policy aimed at a few thousand people doing one defined activity. It is a much better comparison than the Stasi, and I was wrong to let the darker analogy stand unchallenged.
I should add that I considered and rejected a second comparison, because I think it would do the argument harm. It is sometimes pointed out that heavily surveilled societies can be popular with their own citizens — Singapore is the usual example. I do not want to lean on that, for two reasons. Approval figures gathered where press freedom and political competition are constrained are weak evidence about what people actually believe, and citing them invites the obvious reply. More importantly it is an argument about state surveillance, which is the thing this mechanism is supposed to be an alternative to. Reaching for it concedes the frame. The False Claims Act is the better example precisely because it is private, financial, adversarial, and operating inside a liberal democracy with a free press and a functioning bar.
What survives, which is smaller but real
Three things, and I would rather keep them than declare the objection closed.
Individual relators still suffer, even where society does not. Retaliation against False Claims Act whistleblowers is extensively documented, and the personal experience of bringing one is frequently years of litigation and a finished career. “No damage to ordinary trust” is a claim about the social aggregate and it is entirely compatible with the individual cost being brutal. That is the same worry as the chilling-effects material and it does not go away.
The ratio here is unusual. A False Claims Act relator takes a share of a corporate recovery. What is proposed here is a bounty deliberately calibrated to be life-changing relative to the target’s own income — which is a stronger incentive, pointed at a colleague rather than at an employer’s billing department.
And the population is small and tightly networked. A few thousand people who mostly know each other, move between the same handful of employers, and will work together again. The same workplace is affected repeatedly in a way that a diffuse national programme is not. I would expect a measurably larger effect on professional life than the False Claims Act produces, while expecting it to remain enormously closer to the False Claims Act than to anything with secret police in it.
I want to be precise about why this one is different from the others on this page. Every objection above describes a way the mechanism might not work. This one describes the price of it working — a smaller price than I had it, but a price. And the price cannot be designed down, because every adjustment that reduces the denunciation reduces the deterrence by the same stroke: a smaller bounty is a weaker incentive to inform and a weaker incentive to quit, and there is no dial that separates them. The corrosion is not a side effect of the mechanism. It is the mechanism, viewed from the inside of a workplace.
The best I can say is that I think the alternative is worse, and that Part I is four pages of argument for why I think that. But “I have weighed this against the end of everything that experiences anything and I still choose it” is not an answer to the objection. It is a statement of the exchange rate I am using, offered so that anyone who declines the trade knows exactly what they are declining and can say so.