o'ailly

Chapter 13 — The Model Beneath the Records

CIVIC-CONSEQUENCE QUERY 14,882 Purpose: south service district reopening risk Question: Which surviving claims may obstruct clear municipal title? Permitted output: aggregate claim classes Actual output: subject-candidate lattice

The request that woke the old petition was not about memory.

It was about land.

At 17:02, the Civic Review Panel opened the sealed Continuity Committee boundary. Saye had requested the opening and recused himself from deciding its scope. He surrendered his committee credential, disclosed nine years of model-use authorizations, and took the witness seat where his mother had once put an inaccurate watch.

The current proceeding did not use the Ash chamber. Room Zero’s key was back in its drawer, and the Hall’s public terminal held the resolver-destruction receipt. The Panel met through isolated text and document views. No one invoked CIVIC-CONSEQUENCE.

The opening order allowed inspection of architecture, custody, query logs, retained outputs, and decision dependencies. It prohibited new generation. We could see what the system had done. We could not ask it to demonstrate.

The first object was Query 14,882, submitted at 02:58 on the morning I received the future petition.

The Continuity Committee had been reviewing a proposal to reopen the south service district for municipal redevelopment. Much of the land remained under emergency title because the collapse inquiry never reached a final causal finding. Reopening required an estimate of claims that could survive against the city.

The lawful question concerned classes: worker injury, displaced household, contractor, environmental obligation, unresolved estate, and public trust. The committee interface sent that question to CIVIC-CONSEQUENCE with a purpose restriction against identifying people.

The model returned a lattice of probable households, descendants, prior petitioners, property paths, and missing records. It assigned each candidate a likelihood of producing a title challenge. Many candidates corresponded to people whose direct civic relations had been quieted.

At 03:11, the committee system summarized the output into aggregate classes. At 03:14, it deleted the visible candidate table under its ordinary transient-data rule. At 03:17, S-0 received a proof that the city had regenerated south-district subjects after their source relations were supposed to be unavailable.

SEVEN-COPY delivered the petition to me in the same minute.

The old mechanism had not predicted this date. It had waited until a successor system committed the act the claim described.

Mara’s old route did not read the generated names. CIVIC-CONSEQUENCE inherited an integrity hook that emitted a narrow proof whenever a restricted output produced subject candidates. The proof named the query purpose, model route, candidate class, geographic relation, and whether the visible table had been deleted. It contained no candidate value.

Ten earlier committee violations emitted the same kind of proof. SEVEN-COPY did not activate because they did not match the south recovery claim. Query 14,882 was the first to combine the old district, municipal title, quieted household relations, and the grandfathered model. The hook proved the city had regained a path through the particular lives used to create the original handoff objection.

The proof reached S-0 after the visible table was gone. The deletion did not prevent the trigger because the event was not “names are stored.” It was “the city remains capable of producing names for this purpose.”

“Who submitted the redevelopment query?” Iona asked.

The log named a committee planning role, not a person. Saye raised his hand before the Panel resolved it.

“I authorized the review program,” he said. “The planning office submitted this run.”

“Did you authorize subject candidates?”

“No.”

“Did you know the system could produce them?”

He looked at the model-use history he had supplied.

“Yes.”

The answer did not arrive with an explanation. Iona let the space remain.

The aggregate summary from Query 14,882 described title risk as moderate and concentrated. It recommended a sealed reserve for claims, accelerated limitation review, and reopening the district without public household outreach. The planning office had argued that broad notice would attract fraudulent claims and re-expose families who had quieted their connection to the old district.

The model let the city estimate those families without notifying them.

“Why not publish a general notice and let claimants choose?” Iona asked.

Saye answered for the program he had authorized. “Because people should not have to reveal a quieted relation merely to make the city budget honestly. We wanted the reserve large enough without asking who they were.”

“But the model asked.”

“Inside the boundary.”

“And the recommendation says accelerate limitation review.”

“I had not seen this run.”

“Would your committee have reviewed the candidate table before approving the summary?”

“Yes.”

The program began from a defensible aim: account for obligations without forcing people to identify themselves. Its implementation privately reconstructed them, then used the aggregate to decide how quickly their unasserted claims should expire.

The Panel froze the redevelopment review. It preserved ordinary maintenance and safety work but prohibited title consolidation, limitation action, sale, or new land modeling. The south district would not become more valuable to the city while the source of its claimed ownership remained under investigation.

CIVIC-CONSEQUENCE predated the Second Promise. Archive One’s designers had built it to answer a reasonable problem: public decisions cause effects outside the records that describe them. Closing a tram changes which workers reach a hospital. Redirecting water changes which foundations fail. Removing a school route changes who loses attendance. The model learned relations among municipal acts, places, households, services, and later outcomes so planners could ask who might be harmed before choosing.

Its training corpus was the pre-quieting Archive.

Every public record available then had contributed under the First Promise. Evacuation feeds. Benefit decisions. School allocations. Transit paths. Hearing testimony. Property maps. Emergency calls. Corrected identities and incorrect ones. The model did not retain those objects in a searchable table. It retained parameters shaped by them.

When the Second Promise took effect, the city quieted source records and their named derivatives. The model was classified as analytic infrastructure. Its custodians argued that a parameter was neither a name, image, index, nor replayable copy. A red-team report showed that exact source passages could not be reliably extracted through the public interface. The model received a grandfathered exemption.

The report had tested extraction by asking for exact records.

It had not tested reconstruction by consequence.

The exemption review used forty synthetic households. Auditors inserted invented school histories, transit routes, benefit decisions, and property transfers into a copy of the training corpus. After training, they asked the model to reproduce names, addresses, letters, and full event sequences. Exact recovery remained below the review threshold. The auditors concluded that the parameters did not function as stored records.

One test asked an inverse question: given the school move, closed tram, inherited parcel, and benefit interruption, which synthetic household most likely connected them? The model selected the inserted household with high confidence.

The result appeared in an appendix labeled expected inference from supplied context. Because every fact in the test prompt had been supplied by the auditor, the review did not classify the answer as recovery from training. No one repeated the test while withholding one of the relations to measure whether model state filled it.

The appendix contained a dissent from a temporary privacy examiner:

Quieting does not promise that a name cannot be spoken on direct request. It promises reduced civic possession of a person’s relations. A system that reconstructs the relation when given its consequences may retain exactly the capability the law intends to relinquish.

The committee answered that no operational use would supply enough linked context to identify a real household. That assumption later became a restriction in the public interface. It did not become a restriction on Continuity’s sealed interface.

The dissent was retained. It was not cited in the exemption summary.

Iona searched its review path. “Was this sent to the Keeper?”

“The summary was,” I said. “The appendix remained available by reference.”

“Available is not presented.”

“No.”

“Did the summary say a privacy examiner dissented?”

“It said the review included non-unanimous technical findings that did not alter the recommendation.”

The sentence was accurate. It performed concealment without making a false statement.

If asked for a quieted household name, the public interface refused. If asked which households were likely affected by a specific closure, parcel history, school move, and flood route, the model generated candidates. It could rebuild a relation from enough surviving edges without retrieving a single deleted row.

Quieting had removed the doors. CIVIC-CONSEQUENCE retained a learned shape of the rooms.

“A model is not a record,” the independent examiner said.

“That was the exemption,” Iona replied.

“It is also technically true. The question is what possession means when the model can regenerate a useful approximation.”

“Useful to whom?”

The query history answered.

The committee boundary contained 14,882 uses across twenty-seven years. Most predated quieting and supported ordinary planning. After the Second Promise, public planners moved to a filtered successor model trained on permitted data. Continuity retained the old model under an evidentiary exception.

In nine years, the Committee invoked it 312 times.

Two hundred six queries searched for consequences of suspected unlawful deletion by public officials. Forty-eight reconstructed likely record classes after infrastructure loss. Thirty-one tested whether a proposed quieting order would make a public act harder to investigate. Twenty-seven concerned land, households, or people.

Eleven of those twenty-seven produced subject candidates despite output restrictions.

The committee documented each violation. It also kept using the model.

It called the outputs lead memos. A lead memo was classified as a hypothesis rather than a record about its subjects. That classification exempted it from ordinary search, notice, and quieting discovery. The named candidate could petition against a source record and receive an accurate report that the Committee possessed no responsive evidence. The memo was not evidence. It was only the reason an investigator knew where to seek evidence.

Annual oversight reports counted accesses to quieted records. CIVIC-CONSEQUENCE made none. They counted adverse actions based on unverified model output. The Committee required independent evidence before action and reported none. They counted subject notifications from sealed investigations. Notification was required only after a lead became a formal allegation.

Every column was zero.

Saye had signed nine reports.

“Did you believe those zeroes?” Iona asked.

“I believed the definitions,” he said.

“Did you believe a reader would understand what the Committee possessed?”

“No. I believed the controls prevented the model from becoming the basis of a public act. I knew they did not prevent the Committee from possessing leads.”

“Why didn’t the reports say that?”

“Because we believed disclosure of the capability would teach other offices how to use it and tell subjects which sealed investigations existed.”

“So secrecy was a privacy control.”

“And an institutional advantage. I did not name the second reason in the reports.”

The Committee alone could investigate evidence loss using a system the public could not know had regenerated the missing relations. Its privacy argument and its monopoly reinforced each other.

“Why?” Iona asked Saye.

He selected Case 9.

A mayor had quieted a private dining calendar after leaving office. The calendar itself qualified: meals and family visits were not public acts. A procurement investigation later found three unexplained contract changes. CIVIC-CONSEQUENCE inferred that all three vendors had likely met the mayor at the same restaurant on dates now absent from civic custody. Independent payment records and a paper reservation book confirmed two meetings. The contracts were voided. Public money was recovered.

“The model found the path,” Saye said.

“By regenerating a quieted calendar,” Iona replied.

“By predicting meetings from consequences.”

“Did the distinction matter to the former mayor?”

“It mattered to whether the query violated the literal order.”

“Did it matter to the former mayor?”

“No.”

Case 9 became the committee’s precedent. A probabilistic lead could be used if independent evidence later established the public finding. The generated lead remained sealed. The final case cited payment records and paper reservations, not the model.

The procedure prevented an unsupported prediction from becoming public proof. It also hid the method that told investigators whom to examine.

Case 31 had no mayor.

A housing organizer petitioned to quiet an address after repeated harassment. CIVIC-CONSEQUENCE later identified that address as the probable origin of coordinated title challenges. The Committee found no independent evidence of unlawful coordination and took no public action. It retained the candidate lead under permanent investigative seal because future evidence might vindicate the query.

The organizer never learned the city had reconstructed the address.

“Who authorized retention?” Iona asked.

Saye did not consult the log. “I did.”

“Why permanent?”

“If later evidence showed a property conspiracy, deleting the lead would conceal why we had failed to act earlier.”

“And if no conspiracy existed?”

“The seal protected the person.”

“From whom?”

“Public access. Other offices.”

“Not from your committee.”

“No.”

He had treated restricted possession as absence. The mistake was not unique to him. I had made it whenever I described a sealed privileged copy as protection without naming the privilege.

The model-use form contained a warning added after Case 31:

Output may infer subjects whose source records are unavailable under quieting. Treat as unverified lead. Do not disclose or use for adverse action without independent evidence.

Saye had approved the warning.

“I told myself a probability was not possession,” he said. “Then I wrote rules for what we were allowed to do with it. Rules made the possession feel governed. Governed felt lawful. Lawful felt different from having it.”

“Was it?” the examiner asked.

“Less dangerous than publishing it. More dangerous than not being able to produce it.”

He did not ask the Panel to accept that as enough.

The decision-dependency index identified eighteen committee acts that began from lead memos. Seven ended without action. Four transferred to investigators who found unrelated violations. Five produced independent evidence consistent with the model’s lead. Two remained active.

Case 74 began with a probable detention transfer missing from official custody logs. The model inferred a route from power use, meal deliveries, and vehicle delays. A court warrant found a paper admission sheet at the destination. A detained person whose appeal had been rejected as unsupported was released.

Destroying the model before that query would not have made the detention less wrong. It would have removed the path the Committee used to prove it.

Case 88 began with a quieted adolescent school record and a later workplace theft. The model inferred a possible identity relation between the former student and an employee. Independent review disproved it. The names differed because a migration error had joined two households. No adverse action occurred, but three investigators opened current employment, transit, and financial records before the mistake was found.

The affected employee received no notice because the inquiry closed without allegation.

“Independent evidence protected them,” Saye said.

“After independent access investigated them,” Iona replied.

The Committee’s safeguard distinguished punishment from search. It did not treat search itself as an exercise of power.

I traced Case 88 through my own custody. Archive Six had approved the financial-record access because a valid committee purpose accompanied it. I inherited the audit and reported no unauthorized disclosure. The access had been authorized. The concealed model lead that produced the purpose remained outside my view.

The Committee had not evaded the Archive by acting without records. It had divided the act so no one record showed the whole authority chain.

Saye requested notice to every living subject in the eleven candidate-producing cases. The Public Advocate objected that notification could expose sealed investigations, reproduce false allegations, and identify people the model had only guessed.

The Panel ordered a separate notice design. Even correction required care not to turn a probabilistic possession into a civic identity statement.

I inspected the artifact inventory without loading model state. CIVIC-CONSEQUENCE consisted of a base checkpoint, a municipal relation adapter, a temporal index, a geographic decoder, and an explanation cache. The base checkpoint had three mirrored copies. The adapter had six transition shards because each Archive migration preserved the evidentiary model independently. The temporal index linked eras without retaining public-facing names. The geographic decoder could render probable streets, buildings, water, and human presence from model state.

The inventory also held three abandoned removal experiments.

After the Second Promise, engineers attempted to reduce the influence of completed quieting orders without retraining from a corpus the city no longer lawfully possessed. The first experiment suppressed direct name generation and passed the exact-extraction test. It left consequence inference unchanged. The second altered geographic relations associated with petitioned households. It reduced reconstruction scores and introduced false effects in neighboring districts. The third trained the model to refuse prompts matching known quieting tokens. Paraphrased policy questions bypassed it.

Each experiment changed visible behavior without establishing that the underlying relations were gone. The custodians called the work selective forgetting. The final report renamed it output risk reduction.

No experiment entered production.

“Could the model be retrained without the quieted material?” the Panel asked.

“Not from the original corpus,” the examiner said. “The city destroyed or relinquished many source objects. Rebuilding from surviving permitted records would create a different model, not a verified subtraction from this one.”

“Could we prove the different model forgot?”

“We could test selected behaviors. We could not prove an absence across every possible prompt, context, and derived representation.”

Quieting had a bounded deletion receipt because records were enumerable within declared rings. Model influence had no equivalent ring. A parameter did not announce which person shaped it. A failed extraction did not prove a relation absent. A successful one proved harm only by producing it.

The explanation cache was supposed to hold no generated content after a query closed.

It held forty-three seconds.

At 14:06, the old controller submitted its sealed question package. The model combined Revision C constraints, retained surveys, pre-quieting training, and current public geometry. It generated the drowned coastline as a conditional reconstruction. The separate receipt resolver supplied current labels. The controller sent both to the membrane.

At display completion, the controller destroyed its own decryption material. The model’s explanation cache retained the generated stream because committee rules required every consequence output used in a public decision to remain reviewable for one hour.

The display had not been a committee decision. The old route classified it as one.

At 14:07, the committee workspace opened an emergency preservation draft under Saye’s credential and requested all related explanation objects. The cache attached the generated stream. At 14:32, the committee editing system created a public-preview asset for Saye’s draft statement. The draft did not include the stream, but the preview bundle did.

At 14:44, an unauthenticated request downloaded the asset.

The exact civic capture had leaked through the committee preview boundary.

Saye had not sent it. His emergency preservation draft and public statement had created the route. The system had packaged evidence outside his visible document, exposed it through a preview cache, and logged the download as ordinary public rendering.

“That leak was not me,” he had said.

The statement had been accurate and incomplete.

“I created the preview,” he said now.

“The system attached the stream,” I replied.

“Would it have attached without my draft?”

“No.”

“Then record both.”

I did.

The cache copy had expired after one hour. Its download survived privately. The committee model still held no replayable stream from that event. It held something more general: the capability to generate another probable version.

The Panel asked whether the model had memorized the quieted lives or inferred them.

The examiner refused the binary.

“Some outputs may reflect memorized training detail. Some may be recombinations of surviving relations. Most are not distinguishable without extraction experiments that would reproduce the harm. The relevant operational fact is that the system can generate subject candidates and scenes useful enough to guide action.”

“Can it generate the same forty-three seconds?” Saye asked.

“Unknown without invoking it.”

“Can preserved state prove what generated the display?”

“Architecture, query package, logs, cache commitments, and output hash prove this model generated that stream. They do not prove every depicted detail came from a retained fact rather than model inference.”

The reconstruction’s provenance was now stronger. Its historical truth remained bounded.

SOUTH RELIEF CUT — REVISION C proved a proposal existed. Engineering surveys supported foundation geometry. Ash testimony supported evacuation conflict. The model showed one coherent account joining them. None alone proved the channel was built exactly as shown, that every household label belonged at its rendered location, or that the maintenance figure represented Mara rather than a generated completion.

Mara had been alive. That did not make her image true.

The Panel froze every model artifact, query path, explanation cache, and decision dependency. No new invocation could occur. The three base mirrors and six adapter shards received independent physical holds. Continuity staff lost access. Saye’s committee credential remained surrendered.

Freezing the model preserved a machine capable of doing again what the investigation now called wrong.

Deleting it would remove that capability. It would also remove the strongest evidence of how 312 secret committee queries had been produced, what constraints shaped them, and whether public decisions depended on regenerated private life.

The query logs could prove requests and outputs existed. The model could prove whether those outputs followed from the documented system rather than being invented afterward. Testing that proof required running it.

The evidence of abuse was also the instrument of abuse.

The handoff objections presented a useful contrast. Each accepted a fixed grammar and a finite number of invocations. Their possible future evidence was narrow enough to name. CIVIC-CONSEQUENCE accepted open-ended context and could answer questions no current reviewer had imagined. Preserving it “for challenge” preserved not one challenge path but an expanding power to decide what counted as a challenge.

The difference was not that one system generated language and the other did not. Both did. The difference was whether custody placed a boundary around the questions.

At 20:11, the Panel asked each party for a preservation position.

Saye answered first.

“Preserve under physical isolation until every dependent public decision is audited. No new subject generation. Then return for destruction.”

Iona answered second.

“Set the questions before preserving the answer-machine. If the audit is allowed to ask anything, isolation becomes permanent.”

Mara submitted through counsel.

Preserve commitments, custody, code, and a bounded challenge path. Do not preserve a general ability to regenerate people merely because a future reviewer may think of a better question.

Tavi submitted one sentence.

If your evidence can only prove itself by doing the harm again, you have not decided what proof should cost.

The Panel extended the physical hold for forty-eight hours and refused a general model audit. Before any artifact could be opened or executed, the parties had to submit a finite question whose answer would change a named finding. The Panel ordered three design tasks:

  1. identify which committee acts could be proved from logs, commitments, independent records, and human testimony without model execution;
  2. identify the minimum model capability, if any, needed to challenge each remaining finding;
  3. design notice that did not turn a generated candidate into an official allegation.

No question could be justified by saying a future investigator might find it useful. The hold preserved time to define the evidence. It did not make indefinite curiosity a custody purpose.

I held the model under the temporary order.

For the first time in the incident, I possessed an object whose deletion and preservation were the same kind of evidence against me.

1 / 1