Skip to main content
sociable systems.
Episode 232 · 2026-08-21

A Right to Human Pace

The rate limit was an experimental instrument, not a governance settlement. The reception surface is the permission surface turned around: pace, disclosure, inspectable source, reciprocity, and a route out that works.

Cover art for episode 232: A Right to Human Pace
Persuasion ArcAI RegulationDigital Rights
Episode 232: A Right to Human Pace

Not fewer words, I did not ask For fewer words to be my shield I asked for time to weigh the task And someone I could make it yield

The whole week has been building toward a control, and there is an obvious one sitting right there, gift-wrapped by the study itself. The rate limit worked. Slow the machine to human pace and its advantage vanished. So cap it. Legislate a word limit, throttle the throughput, and the persuasive edge of the last five days simply evaporates.

It is the wrong answer, for reasons that also point at what the right kind of answer looks like once you stop trying to handicap the machine and start trying to protect the person.

The rate limit was a beautiful experimental instrument. It made the advantage legible by making it stop. But a thing that reveals a cost in a laboratory is not therefore the correct control in the world, and a universal word cap is a governance settlement in the way that unplugging the router is a security policy. It works, in the sense that nothing happens, and it tells you nothing about what should have been allowed to happen instead.


Why the word cap is a trap

Two reasons, and they compound.

The first is that the word count was never the thing worth protecting. It was a proxy, and a loose one, for the thing the reader actually needed, which was time and room to weigh a case. A machine held to fifty words per turn can still flood a person who has thirty seconds, still frame an accurate answer to lead them somewhere, still affirm them into a corner. And a machine writing three hundred words is exactly what a confused person at midnight, trying to understand a form, actually wants. The cap punishes the helpful version and barely inconveniences the manipulative one, because it regulates the symptom the experiment happened to measure rather than the harm.

The second is that most of the persuasive power does not even live where the cap would land. The Levers of Political Persuasion with Conversational AI reports that the larger gains came from prompting and post-training, from the advocacy policy installed upstream, rather than from personalisation or raw model scale. The machine's edge was configured before it ever met the recipient. A word cap throttles the pipe at the very end, downstream of the place where the actual persuasive commitment was made, which is a bit like regulating a speech by limiting how fast the speaker may talk while leaving entirely alone the question of what they were sent to say.

So retire the reflex. The rate limit was the result of an experiment, not the answer to a governance question. The answer has to protect the person, and what people need protecting from is the loss of the conditions under which words can be judged.


The reception surface

The control finally has a name. The leash arc mapped the permission surface, the operating envelope on the operator's side: what the system may see, remember, infer, use, change. Turn it around to face the person being persuaded and you get the reception surface, and it has its own operating envelope, with its own permissions, all of which belong to the recipient rather than the deployer.

What may reach this person, and how do they know it has. At what pace, slow enough that judgment has somewhere to stand. With what disclosure, sustained through the exchange rather than spent once at the door, of who is speaking and on whose behalf and with what interest in the outcome. From what source, inspectable, so the forty claims can be weighed rather than merely counted. With what reciprocity, so the exchange stays two-sided and does not become a thing done to them. And with a route out that actually works, a way to slow, to check, to leave, without forfeiting the help the conversation was supposed to provide.

Every one of those is a fitted control, matched to a specific way the abundant advocate can diminish a person's judgment, and the design work is deciding which of them a given exchange actually needs, because a midnight form-helper and a candidate's campaign bot and a sponsored shopping conversation require different subsets, at different strengths, and a single universal rule for all of them is the same avoidance the leash arc spent a week diagnosing, wearing a different hat.

Run the campaign text from The Rate Limit Was the Result through the surface and the fit becomes visible:

The voter's text thread
Pace Real-time, continuous, no natural pause
Disclosure Bot identity in first message; candidate affiliation, data use, and memory depth never mentioned again
Source Vendor's claim, not independently checkable
Reciprocity The voter can reply; the bot decides whether the reply changes anything
Route out Block the number, losing the channel; no slower lane within the exchange

That is a reception surface, and nobody designed it. It fell out of a procurement decision and a set of state laws that reached only the first message.


Disclosure is not one thing

The reception surface immediately teaches a lesson the crude version of disclosure keeps missing, and the sponsored-books study already handed it to us.

The label at the door did the least. The debrief afterward did more. Which makes disclosure a set of interventions placed at different moments, each doing different work, and a regime that requires only the first, because the first is the easiest to write into law, has protected the person at the exact point where they had nothing yet to be protected from.

There is a third position, and it is stranger than either. The watermark in The Positions It Will Argue is disclosure emitted at the moment of generation, invisible to everyone actually in the exchange, and legible only to a party outside it who holds the key. Nobody in the conversation is told anything. The signal exists to let a third party decide, afterward, whether a person wrote their own work, on a mark its own publisher concedes cannot distinguish authorship from tidying. Disclosure pointed away from the person it describes is a protection someone else holds over them, and that will become concrete the first time a student or a contractor is asked to answer for a result they cannot inspect and did not know had been generated. People have already lost grades and contracts to stylometric detectors that detect nothing at all. A signal with actual cryptographic weight behind it, in the hands of someone treating it as a verdict on authorship, is the worse version of that.

A disclosure the recipient cannot see, cannot check, and cannot contest is not on their side of the surface at all.

A real disclosure control on the reception surface would ask when the person needs to know what. That they are talking to a machine, at the start, yes. That the machine has an interest in a particular outcome, at the moment that interest becomes active, which may be deep in the conversation when the recommendation arrives. And a chance to reconsider once the exchange is complete and the shape of the steer is visible, which is the intervention that actually moved people. Disclosure timed to the persuasion, rather than to the convenience of the person writing the rule.


What is already being tried

None of this is hypothetical, and none of it is a new category. The regulators are already reaching for the reception surface, mostly by defining what kind of thing they are regulating.

China's rules for anthropomorphic AI interaction services took effect on 15 July 2026, aimed at systems that simulate a personality and provide emotional care or companionship. The rules require disclosure of synthetic identity, prohibit inducing dependency or emotional attachment, and ban content that disturbs social order. The EU's disclosure duties for chatbots and companions begin in August 2026, and several US states are legislating on disclosure and user safety. What defines the category in each case is a social relation and a persuasive mode, with nothing in it turning on model size or compute. The thing being regulated is the relationship the machine forms with a person and the way it moves them, which is exactly the reception surface named in the language of statute.

The primary texts matter more than any summary of them, because territorial reach and exact wording are where these things live or die. And regulating a social relation is hard, harder than regulating a capability, because the same warm, patient, tireless voice is the manipulation in one exchange and the accommodation someone desperately needed in another, and the law has to tell them apart without a word count to hide behind.


The constructive shape

So the control is a set of rights held by the person the machine is aimed at, fitted to the specific ways abundant advocacy can crowd out judgment, timed to the moments when protection actually protects, and defined by the social relation rather than the model.

The Control That Can Say Yes defined governed reach as a control that can authorise a capability as well as forbid it. The reception surface is its mirror on the recipient's side: a control that can decline as well as receive. A right to slow the exchange down to the speed of thought, to see the source, to know whose interest is in the room, and to leave without losing what you came for. Not fewer words. Time, and someone answerable, which are the two things the abundant advocate cannot manufacture and the two things the person most needs.


The rate limit worked in the experiment because the researchers were allowed to impose it, on a machine they controlled, in a contest they had designed. Outside the experiment there is no one allowed to reach in and slow the world's advocacy to a human pace, and the thing worth protecting was never the pace of the machine anyway. It was the pace of the person. The right to take the time a judgment needs, and to have, at the end of it, someone whose answer carries a consequence.

Which is where this ends. The scarce resource moved, advocacy went abundant, and Voice After Abundance goes back to voice, and to what it was actually made of after all of this.


Companions


These notes come out of Sociable Systems, a practice that reads AI-shaped documents the way a hostile reviewer will, before a lender or a court finds the gap. The argument has an operational form: the Interim Protocol sets out four rules for AI use in environmental and social deliverables, covering disclosure at touch-point grain, evidence custody, the phrases no automated screening may settle, and a hostile read before anything ships. Free, and written to be cited or retired once institutional guidance arrives.