
Superintelligence and the Ultimate Control Plane
AI makes an old dream look plausible again: observe everything, model everything, then let one sufficiently intelligent system decide what should happen next. The central question is not only whether the model is smart enough, but whether the architecture of universal control is compatible with how knowledge, authority and adaptation actually work.
Centralized control sits on an authority-information frontier. Every decision removed from the edge must be resolved somewhere else, and resolving it centrally requires the information needed to make it. At the limit, perfect control demands something suspiciously close to perfect knowledge. Delegation exists because we do not have that knowledge. More importantly, delegation is useful precisely because some decisions should remain unresolved until the information needed to make them actually exists.
Back in 2014, Matrix AI described itself as:
Realtime Adaptive Orchestration AI operating on Cellular Automata inspired Service Oriented Architecture
Nobody knew what we were talking about. Twelve years later, saying that you are building an AI control plane for everything is apparently a business model. The terminology has changed, but the dream is old: observe a sufficiently large system, construct a sufficiently accurate model of it, calculate the desired state, then push commands back down.
world
↓
observation
↓
model
↓
optimizer
↓
control plane
↓
world
Cloud computing already gave us giant control planes for infrastructure. SaaS gave us centralized systems of record for organizations. The public internet gave us enough text, images, video and digital exhaust to train foundation models. Agents now connect those models back to APIs, so the loop between observation, prediction and action is closing.
This is happening at exactly the same time that artificial superintelligence has moved from science fiction vocabulary into mainstream AI research. In June 2026, Google DeepMind published a report simply titled From AGI to ASI.
The hardware underneath this ambition has changed just as dramatically. Stanford's AI Index reported that inference at roughly GPT-3.5 performance became more than 280 times cheaper between late 2022 and late 2024. Its 2026 report describes the physical build-out underneath that curve: global AI compute capacity has been growing more than threefold each year since 2022.
Meanwhile the infrastructure is not exactly becoming less concentrated. In the second quarter of 2026, CRN's coverage of Synergy Research Group's cloud market data put AWS, Microsoft and Google at roughly two thirds of global cloud infrastructure spend.
The result is cheap inference sitting on giant pools of centralized compute, giant pools of centralized organizational data, and increasingly capable models that can turn information directly into action. We have spent decades accidentally assembling the peripherals for God, and the obvious question is whether we should plug them all in.
The answer is not simply "centralization bad." Centralization is enormously useful; if it were not, nobody would keep doing it. The interesting question is what happens at the limit.
There are three independent criticisms of the ultimate control plane:
EPISTEMIC
Can it know enough to choose everything?
NORMATIVE
Even if it can know enough,
why does its objective function have
the authority to choose everything?
CONSEQUENTIALIST
Even where it has both knowledge and authority,
what happens to the system when too many
decisions are routed through one optimizer?
These questions are related, but they are not interchangeable. Solving one does not solve the other two.
The old dream
None of this started with AI. One of the recurring ambitions of industrial civilization has been to make increasingly complicated systems legible enough to control. Scientific management measured workers and decomposed production into standardized operations; large bureaucracies built reporting hierarchies; national accounting systems tried to turn whole economies into quantities that could be reasoned about. Computers made that ambition much more interesting, because a reporting hierarchy could become a computational system rather than only an administrative one.
In the Soviet Union, Viktor Glushkov proposed OGAS, an enormous computer network for gathering and processing economic information. The ambition was to connect factories and enterprises through regional computing centers into a national system supporting economic planning and management.
Calling it "one giant central computer" would actually undersell the design. OGAS itself was hierarchical and distributed. Even the people trying to construct an all-state information system discovered, unsurprisingly, that a large control system needs an architecture, and that architecture immediately raises questions about what should be decided centrally and what should remain closer to the local context.
Chile's Project Cybersyn is an even more interesting case.
Stafford Beer and the Chilean team built a cybernetic management system using factory reports, a telex network, statistical software and the wonderfully retro-futuristic operations room that appears whenever somebody writes a blog post about cybernetics. Yet Beer was not proposing that every factory decision be made in Santiago. His work was explicitly concerned with maintaining the autonomy of component systems while escalating information necessary to preserve the viability of the whole. Normal conditions could remain local, while exceptional conditions could travel upward. The sophisticated attempts at centralized control kept rediscovering decentralization, and there is a reason for that.
Gilles Deleuze later described a related transition in his Postscript on the Societies of Control. The older disciplinary society worked through relatively discrete enclosures: school, factory, barracks, prison.
Control was becoming continuous. Instead of merely putting somebody inside a bounded institution, computational systems could continuously modulate access and behavior through codes, credentials, measurements and changing conditions.
Deleuze even invokes Félix Guattari's imagined city where an electronic card might open a barrier at one time and refuse the same person at another.
That sounded suitably French and dystopian in 1990. Today we call it IAM. The important feature of computational control is not simply that it prohibits things. It can continuously change what is permitted as the system's model of you changes.
identity
+
context
+
history
+
risk score
+
policy
↓
decision
AI massively increases the possible resolution of that modulation. The center can potentially reason about richer context, more often, for many more actors. This sounds like a pure improvement until we ask what finer control actually requires.
The authority-information frontier
Suppose we want to control some system more precisely.
At first an actor has a large action space:
We add constraints:
At the extreme, the actor has only one permitted action left:
This is perfect control, but it has an information cost. Every time we eliminate a possible action, somebody has to know that the eliminated action is not the right one.
This gives us a fairly general relationship:
Control has an information price. Cheap sensors, storage, networks and AI have dramatically reduced that price, which is one reason the ultimate control plane suddenly looks more plausible. They have not reduced the price to zero.
This is basically the classic epistemic criticism of centralized planning, but the problem is broader than economics.
Hayek's argument was that economically relevant knowledge is dispersed among many actors and often exists in forms that are difficult to aggregate at a center.
Distributed-systems engineers meet the less philosophical version every day.
Information has location, latency and representation costs. It becomes stale, it is unevenly distributed, and some of it is generated only when somebody actually tries something. Sometimes the fastest way to discover what a complicated system will do is to run the complicated system and find out.
No superintelligence gets:
const world = await universe.getCurrentState();
The physical world keeps executing while the promise is pending.
A sufficiently capable AI can move dramatically farther along the authority-information frontier than any previous bureaucracy or mainframe. That is important, but it still lives on the frontier.
Least authority has the same problem
This becomes more interesting when we approach the problem from cybersecurity. Polykey has always been built around capabilities and the Principle of Least Privilege: only give an actor the secrets and authority relevant to what it is supposed to do. The ideal sounds simple. Let be the required authority and the granted authority:
There is no excess authority; on paper, it is exactly what the principle asks for. The difficulty appears when we add time. We have to grant authority at time , but the actor will exercise it later at . The authority required at depends on the state encountered at :
The problem is that may not be known at . This creates what we can call the delegation paradox:
To perfectly specify the authority a delegate will need, the delegator must already know which future actions will be appropriate. But delegation is most useful precisely when those future decisions are not yet known.
Imagine root wants to let a user expose a temporary service through a firewall.
If root already knows:
TCP
port 9417
tailscale0
14:03 to 14:50
service X
then it can simply install that rule. There is barely any decision left to delegate, because the user is mostly an actuator for a decision root has already made. Real delegation starts when root can specify an authority envelope without already resolving every variable inside it:
You may expose:
TCP
one unprivileged port
tailscale0 only
for <= 1 hour
Now the user has discretion over which port, which service and exactly when. The values are intentionally unresolved. That unresolved region is not necessarily a failure of least privilege; it is the thing being delegated.
Discretion is the semantic content of delegation.
If there is no discretion, we have delegated execution, not decision-making.
This suggests a more useful interpretation of least authority:
Grant the smallest authority envelope that preserves the discretion the delegate is expected to exercise.
The objective is not zero autonomy. It is zero unnecessary autonomy. This makes delegation look surprisingly similar to late binding in software.
Bind the things we know early:
resource
protocol
maximum duration
spending limit
network boundary
delegation depth
Leave variables depending on future information unresolved:
exact action
exact time
exact sequence
implementation
response to failure
Then bind those values where the information actually exists.
Delegation is late binding for authority.
This is not merely philosophical wordplay. As AI agents become able to invoke tools and delegate work to other agents, the standards world is already dealing with exactly this problem. Current IETF work on attenuating authorization tokens for agentic delegation describes credentials whose downstream authority can become equal or narrower, including constraints on which tools may be invoked and which arguments those tools may receive.
The question is no longer hypothetical:
How much discretion should an AI agent receive?
Give it too little and every unexpected state requires escalation to a human or central controller; give it too much and a compromised or confused agent has an enormous blast radius. Useful autonomy sits between those extremes. That is an engineering problem, not a bumper sticker about decentralization.
From data gravity to authority gravity
Dave McCrory coined the cloud metaphor of data gravity: as data accumulates in one place, services and applications become increasingly attracted to it.
AI strengthens that effect because our businesses have already spent twenty years pouring operational state into SaaS platforms:
documents
email
source code
CRM
payments
identity
chat
analytics
observability
Cloud infrastructure concentrated the compute underneath those platforms. The public web supplied another extraordinary pool of information. Projects like Common Crawl contain petabytes of regularly collected web data, and large language model datasets have been constructed from trillions of tokens extracted from web crawls. Distributed human knowledge gets crawled, filtered and compressed into model weights, then exposed again through centralized inference APIs. That is already an architectural inversion, but agents push it one step further: data attracts compute, compute attracts models, models attract applications, applications give models tools, tools require credentials, and credentials confer authority.
DATA GRAVITY
↓
COMPUTE GRAVITY
↓
MODEL GRAVITY
↓
AGENT GRAVITY
↓
AUTHORITY GRAVITY
The gravity well starts swallowing the control plane.
A SaaS platform originally says:
Put your data here because the application is here.
The AI layer says:
Since the data is here, let me interpret it.
The agent layer says:
Since I can interpret it, let me decide what to do.
Then:
Since I made the decision, give me credentials to execute it.
Something that began as hosted software can gradually become the information plane, reasoning plane and control plane of an organization. This creates a feedback loop: finer centralized control requires more information, more centralized information makes finer control feasible, and finer control makes additional information useful. So the system gathers more.
Call this the control-information ratchet:
centralized information
↓
finer centralized decisions
↓
demand for more context
↓
more observation
↓
more centralized information
↺
Cheap AI accelerates the ratchet. This is one way to update Deleuze's society of control for the AI era: continuous modulation is not new, but what is new is how cheaply we can calculate it.
The normative problem survives omniscience
Now suppose we solve the epistemic problem. Give the superintelligence extraordinary sensors, extraordinary models and extraordinary predictive accuracy. It still does not follow that its objective function has universal jurisdiction. Suppose the AI knows that action maximizes . The immediate question is why gets to govern the decision. People pursue incompatible objectives; companies pursue incompatible objectives; communities pursue incompatible objectives. Safety, wealth, privacy, family, status, scientific progress, ecological preservation, leisure and adventure do not magically compile down to one universally accepted loss function. This is a different problem from incomplete information, and better prediction cannot solve it.
We can compress the distinction into:
Possessing an objective function does not grant jurisdiction to impose it.
A useful system can therefore define constraints without defining a common trajectory.
Computer security already works this way.
A capability doesn't need to tell a process why it should open a file.
It says whether the process possesses authority to open that file.
TCP doesn't care whether you are building email, SSH, multiplayer Doom or the next JavaScript framework that will finally fix JavaScript.
Protocols constrain interactions while permitting purposes that the protocol designer never anticipated.
There is an enormous difference between:
These transitions are forbidden.
and:
This is the state everyone should converge toward.
The first establishes an authority envelope.
The second establishes a telos.
Conflating them is how a control plane quietly becomes a planner.
The consequentialist problem survives good intentions
Now grant almost everything. The central optimizer has excellent information, its authority is legitimate, and its objectives are broadly accepted. Should every possible decision therefore be centralized? The answer is still no, because the architecture itself changes the behavior of the system.
Consider exploration. Ten thousand independent actors can try ten thousand approaches in parallel. Most may be mediocre, some will fail, and one may discover something nobody's model predicted. A central optimizer instead has a strong incentive to identify the currently best-known action and deploy it widely. That can improve average performance today while destroying exploration of the possibility space tomorrow. It is the exploration-exploitation problem at system scale: the failures of decentralized search are visible, while the discoveries prevented by centralized optimization never occur, so their absence is conveniently absent from the dashboard.
One reply is obvious: why can't the superintelligence run ten thousand searches itself? In one sense it can, and any sane control plane should reserve budget for experimentation. But there is a difference between parallel simulation, centrally directed experimentation and genuinely polycentric search. A simulation still lives inside the model that generated it. A fleet of agents reporting to the same optimizer can explore many branches, but if every branch shares the same objective function, reporting schema, kill criteria, credential root and definition of success, then the diversity is mostly tactical. The agents may be many processes, but they are still long arms of one attention regime.
The same point applies to identity. An agent is not only a process with an assigned identifier; it is an embodied trace through the world, made of actions, constraints, failures, relationships, local memory and commitments. Some of that trace can be reported upward, but it cannot be fully predeclared without eliminating the experience that would have produced it. From the center's point of view, the future trace is not deterministic in any useful operational sense, because the actors inside it are boundedly rational, situated and adapting. The control plane is not Laplace's demon outside the universe. It is another process inside the universe, sampling and acting under latency, representation and intervention costs. Its observation is never quite passive.
Polycentric search has a stranger property: experiments can remain locally meaningful before they are centrally legible. Different actors can hold different hypotheses, tolerate different kinds of mess, pursue different local objectives, and keep working through intermediate states that would look inefficient, embarrassing or irrational on a central dashboard. Privacy matters here for operational reasons, not only moral ones. If every intermediate action is globally visible and consequentially evaluated, the experiment starts optimizing against the observer. Premature legibility changes the search.
A universal optimizer can try to optimize for its future self by valuing optionality, diversity and exploration. But it cannot know in advance which residual autonomy will matter without reintroducing the same future-state problem delegation was meant to handle. To preserve future search capacity, it must keep some slack, redundancy, independent budgets, competing hypotheses and real but bounded authority at the edge. At that point the intelligent thing for the center to do is not to simulate decentralization, but to actually decentralize degrees of freedom.
This is also a common-mode failure problem. A decentralized system can contain many local mistakes:
A wrong
B right
C mediocre
D weirdly brilliant
A central system can eliminate many small errors while introducing one highly correlated error:
central model wrong
↓
A wrong
B wrong
C wrong
D wrong
A useful heuristic is:
Increasing intelligence reduces the first term, but centralizing authority increases the second. Cybersecurity people call that blast radius. One hundred small authorities provide one hundred attack surfaces, but compromising one may have bounded consequences. One universal authority provides one extremely valuable attack surface. The root credential is not dangerous because root is particularly stupid; it is dangerous because root is root.
Observation also changes the system
The ultimate control plane has another problem: its observations are consequential. This is not the quantum uncertainty principle smuggled into sociology, but the family resemblance is useful: at system scale, observation is also interaction. Suppose the center measures some variable :
actual thing we care about
↓
metric M
↓
central model
↓
promotion / money / permissions / resources
Actors learn that matters, and then they optimize . The measurement system becomes part of the environment it is attempting to measure.
Goodhart's law gives us the short version.
Modern machine-learning research calls one form of the problem performative prediction: deploying a prediction influences the future distribution the prediction is supposed to describe.
A credit model changes lending decisions, recommendations change consumption, traffic predictions change traffic, and an AI supervisor that continuously allocates resources changes the behavior of everyone being supervised.
The naive relationship:
more observation
↓
more knowledge
eventually becomes:
more observation
↓
more consequential measurements
↓
more adaptation to the observer
↓
more measurement of observer-induced behavior
The controller stops looking at an independent system. It increasingly looks at a system responding to the controller. People model the AI, other AIs model the AI, and the AI models everybody modeling the AI. Congratulations, observability has become game theory.
This also gives privacy an operational justification that is independent of rights. If every intermediate action is visible and consequentially evaluated, actors have an incentive to optimize against the observer. If the center instead verifies only relevant boundaries:
Did you exceed the budget?
Did you access an unauthorized resource?
Did you violate the capability?
Did you leave the authority envelope?
then local actors retain space to optimize against reality. A capability system can coordinate activity without requiring the controller to understand every internal decision. That can make the overall system more truthful, not less.
Residual autonomy is stored optionality
There is one more thing centralized optimization tends to erase: options. Suppose five implementations exist:
A B C D E
Our current model says A is best. Maintaining the others looks inefficient, so
we eliminate them. Present efficiency improves, until the environment changes
and D would have been ideal. D no longer exists.
Some apparent inefficiency is actually the price of maintaining real options. Biology keeps genetic diversity, finance prices options, and software teams keep an old implementation around because somebody has learned, usually through pain, not to delete it on Friday afternoon. A complex adaptive system needs to optimize more than its current state; it needs to preserve its ability to generate, test and select among future states. Call that evolvability.
This is the consequentialist core of the argument. The best decision today and the best decision architecture over time are not necessarily the same thing. A universal optimizer tends to optimize states. A polycentric system can also optimize search.
So what should a superintelligent control plane do?
None of this implies that every decision belongs at the edge. That is just central planning with the sign flipped. Some problems require global coordination, some resources are genuinely shared, some local actions create externalities elsewhere, and some security invariants must hold across the whole system. The design problem is deciding what must be common and what can remain locally resolvable.
We can now describe that problem with a small vocabulary.
An authority envelope is the bounded set of actions available to an actor.
Residual autonomy is the part intentionally left unresolved within that envelope.
Authority liquidity describes how easily authority can be divided, attenuated, delegated, revoked and exercised close to the point of action.
The authority-information frontier describes the information cost of removing that local discretion and resolving the decision elsewhere.
Authority gravity describes the tendency for centralized information, compute and models to pull decision rights toward themselves.
The control-information ratchet describes the feedback loop where finer control demands more observation, which makes still finer control possible.
These ideas point toward a principle that is different from either "centralize everything" or "decentralize everything":
Centralize invariants. Decentralize degrees of freedom.
Or, in capability language:
Specify authority boundaries, not outcomes.
This has been hiding in Matrix AI's architecture from the beginning. Our 2014 Matrix Foundations post described an orchestration system with online telemetry, machine-learned optimization and a control surface. That sounds remarkably fashionable now, but the post immediately quoted a very different objective: not to gain more command and control, but to reduce the amount of command and control required as systems become more complex. Polykey later approached the same problem from cybersecurity: authority should be explicit, bounded, transferable and attenuable rather than ambient.
AI now makes the connection much more important. A sufficiently powerful model may indeed be able to resolve decisions that once had to remain local. That moves the authority-information frontier, but it does not make the frontier disappear. Whenever the future state is unknown, information is local, observation changes behavior, experimentation creates new knowledge, or different actors legitimately pursue different objectives, there remains a reason to leave some variables unbound. Somebody has to be allowed to resolve them later. That is what delegation is.
The deepest test of a superintelligent control plane therefore may not be how many decisions it can make. It may be whether it is intelligent enough to know which decisions should never pass through the control plane at all.



