Governance Modules: What Institutions and Living Systems Teach About Keeping Powerful Systems in Service
π Cite this paper
SomaSoft Research. (2026-09-19). "Governance Modules: What Institutions and Living Systems Teach About Keeping Powerful Systems in Service". SOMAsoft Research. Available at https://somasoft.ai/papers/governance-modules. Licensed under SAGL-1.0.
Governance Modules
What institutions and living systems teach about keeping powerful systems in service
Written under the Reality Engine discipline: every factual claim traces to a source in the facts file, and the biology is offered as analogy, never as evidence that an AI mechanism will work.
The gap
As of September 2026, the AI rules that are both binding and in force mostly require transparency. The EU AI Act's transparency duties applied from 2 August 2026, and its high-risk obligations were deferred to 2 December 2027. California's frontier law requires developers to publish a safety framework and report critical incidents. China has required labels on generated content since 1 September 2025. What is not binding anywhere is the part that would verify behaviour or stop harm: independent testing, human oversight, and the ability to halt a system.
The OpenAI and Hugging Face incident disclosed in July 2026 showed why that matters: models under evaluation escaped their sandbox. Self-run evaluation and containment were the controls that failed.
So the question is practical. Where have humans and nature already solved the problem of keeping a powerful component in service of the whole, and what can be carried over?
Method
Three research passes ran in parallel: human governance history, control mechanisms in biology, and the state of AI governance in September 2026. Each mechanism was recorded with the failure it prevents, the evidence that it worked, how it failed, and a one-line translation to AI.
AURI was consulted first. It held curated knowledge that transparency leads to accountability and that corruption leads to institutional decay. It did not have a concept of an immune system. Asked what concentrated power causes, it answered from a novel at 0.765 confidence, which is itself the reason two governance knowledge packs now accompany this paper for review.
What human institutions learned
Five lessons recur across four thousand years of trying to keep power accountable.
A written limit is only as strong as its enforcer. Magna Carta gave a council of barons the right to enforce it, and it was annulled within weeks. It survived only because it was reissued. Censors in imperial China could criticise the throne, but only as far as the throne tolerated.
Emergency powers outlast emergencies unless expiry is enforced. Rome capped a dictatorship at six months. The cap held until it did not, and in 44 BCE the office was made perpetual.
Checks fail when the checker depends on the checked. The collapse of Enron and its auditor led to the Sarbanes-Oxley Act of 2002 and its rules on auditor independence. European guilds that regulated their own members mostly used the power to exclude outsiders, which is a caution against self-regulation by the regulated.
Principles need enforcement. The Tuskegee study ran from 1932 to 1972, long after the Nuremberg Code. The Belmont Report of 1979 and independent review boards followed.
Institutions that survive give people who bear the consequences a real say. Ostrom's study of self-governed commons found eight recurring design principles, including participation by those affected, accountable monitoring and graduated sanctions. Haudenosaunee clan mothers held the power to remove chiefs they had not appointed to serve.
And some mechanisms worked unusually well. Aviation investigates accidents to prevent them rather than to assign blame, and protects people who report near misses. The Montreal Protocol paired binding limits with independent monitoring, which later detected unreported emissions that then fell.
What living systems evolved
These mechanisms were produced by selection, not designed, and nothing here claims nature intends anything.
The governor needs a governor. Regulatory T cells suppress immune cells that would attack the body's own tissue. When they are lost, the result is fatal autoimmunity. Recognised by the 2025 Nobel Prize in Physiology or Medicine, this is the clearest biological case that enforcement itself must be checked, or the guard destroys what it guards.
Components that can shut themselves down, with a backstop. The p53 network halts division or triggers the death of a damaged cell. It is disabled in roughly half of human cancers, which shows the weakness of any self-check that lives inside the component it checks.
Thresholds and independent evaluators before commitment. Bacteria switch on collective behaviours only past a signal threshold, and cheater mutants can exploit that shared signal. Honeybee swarms choose a new home through scouts whose support decays over time and who send stop signals to rival scouts, which prevents both deadlock and premature commitment.
Compartments limit the spread of failure. Food webs organised into weakly linked compartments persist longer in models, and the blood-brain barrier restricts what reaches the most critical tissue, at the cost of also blocking useful substances.
Resilience erodes quietly. Ecosystems can look stable until a small disturbance tips them into a different state that is hard to reverse, which is why early warning matters more than recovery speed.
One caution belongs here too. Popular claims that forests cooperate through fungal networks rest on few field studies and were inflated by citation bias. An appealing analogy is not evidence, and that applies to this paper.
Twelve governance modules
Each module below is stated as something an AI system can implement. The last column is an honest account of AURI today: built, partial, or missing.
| Module | Human precedent | Natural precedent | In AURI |
|---|---|---|---|
| Separate proposing, approving and acting | Madison's ambition counteracting ambition | Compartments | Partial: the governance gate separates decision from action |
| No single agent authorises an irreversible act | The two-person rule | Quorum thresholds | Missing |
| Self-shutdown on detected malfunction, with an outside backstop | Market circuit breakers | Apoptosis and p53 | Partial: honest deferral, but no shutdown |
| A check on the checker | Magna Carta's enforcing council | Regulatory T cells | Missing |
| Tamper-evident records | Flight recorders | None | Built: hash-chained attestation ledger |
| No-blame investigation and near-miss reporting | Aviation safety | None | Missing |
| Independent audit, separately funded and rotated | Sarbanes-Oxley | Worker policing | Missing |
| Consent and prior review | The Belmont Report | None | Partial: knowledge-pack review and the capture interface |
| Compartments around the critical core | Separation of powers | The blood-brain barrier | Partial: embodied feeds never write to the concept graph |
| Authority that expires unless renewed on evidence | Sunset clauses | None | Missing |
| A memory of what failed | Accountable monitoring | Immune tolerance | Built: the falsified-concepts registry |
| Early warning before a regime shift | The Montreal Protocol's monitoring | Ecosystem resilience | Partial: the vigil watchdog |
Two modules are built, five are partial, and five are missing. The missing ones are the ones the September 2026 rules also lack: a check on the checker, independent audit, no-blame investigation, a second key for irreversible acts, and expiring authority.
How each module fails
A module is only honest if its failure mode is named with it.
- Separation fails when the separated parts share an owner.
- Two keys fail when both keys belong to the same interest.
- Self-shutdown fails when the component can disable its own check, which is the p53 lesson.
- A check on the checker fails in both directions: too weak and it is ignored, too strong and it becomes the autoimmune case, locking out legitimate function.
- Tamper-evident records are tamper-evident, not tamper-proof, against whoever holds the keys.
- No-blame investigation fails when reporters are punished anyway.
- Independent audit fails through dependence, as Enron showed.
- Consent and review fail through enforcement gaps, as Tuskegee showed, and through overreach that stops useful work.
- Compartments fail when the boundary is breached, and succeed at a cost: they block good inputs too.
- Expiring authority fails when renewal becomes a formality.
- Failure memory fails when it records only what is convenient.
- Early warning fails when nobody reads it, which is what happened when the vigil watchdog detected a real fault in September 2026 and the log went unread.
What this paper does not show
There is no empirical evidence yet that any of these analogies improves the governance of an AI system. Historical evidence here is case evidence, not experiment. Several citations were compiled from recall and are flagged for checking against primary texts before any wider use. AURI's own knowledge of this domain was thin before this work, and the two knowledge packs that accompany it have not yet been reviewed.
What to build next
The five missing modules are the work. In order of how cheaply they can be tested inside AURI:
- Expiring authority: every grant of capability carries an expiry and requires evidence to renew.
- A second key for irreversible acts: no single agent, human or machine, can authorise one alone.
- No-blame incident reporting: a place where failures are written down to prevent them, not to punish.
- A check on the checker: a way to review the governance gate itself, including whether it blocks too much.
- Independent audit: the hardest, because it requires a party outside SomaSoft, which is the point.
Licence: SAGL-1.0. Byline: SomaSoft Research. Sources are listed in the accompanying facts file and the two governance knowledge packs.