# [Mike Randolph — M Raige](https://mikerandolph211012.substack.com/)

# The Bridge Is Part of the Machine (1 - Bridge)

### Four control surfaces, no clear owners. M Raige — AI-collaborative writing directed and reviewed by Mike Randolph

[**Mike Randolph — M Raige**](https://substack.com/@mikerandolph211012)

**May 4, 2026**
The mistake is to think communication comes before governance.

In ordinary politics, communication sounds like a soft word. People talk. They misunderstand each other. They issue statements, negotiate, make promises, break them, try again. The real work, we think, happens later — in the rule, the agency, the vote, the budget.

Sometimes that is true.

Sometimes the communication channel is part of the machine itself. Remove it and the rest cannot form.

Frontier AI governance is now in that condition.

Anthropic’s Claude Mythos Preview — announced April 7 alongside Project Glasswing, a restricted-access effort to use frontier AI for cyberdefense — has put a hard question on Washington’s desk. If models can automate parts of elite vulnerability discovery, ordinary public release may no longer be business as usual. But if government responds by improvising a choke point, the cure may become another failure mode.

The people holding the necessary pieces do not naturally trust one another. The White House and national-security agencies fear losing control over a strategically decisive technology. The AI vendors fear arbitrary state power, politicized restrictions, and rules written by people who do not understand the systems they are regulating. Both fears are partly justified.

That is what makes the moment unstable. The country needs policy before crisis. But the people with authority, capability, and legitimacy are not yet arranged in a working control loop.

A model like Mythos makes the missing loop visible.

Someone has to test the capability. Someone has to decide whether the model can be released, delayed, restricted, or staged. Someone has to grant trusted access before general release. Someone has to route vulnerabilities discovered during that restricted period to the people who can patch them.

Those are different jobs.

They do not all have to sit in the same institution. In fact, they probably should not.

If labs control the whole process, the public will hear self-certification. If government controls the whole process, vendors will hear an improvised bottleneck, and national-security agencies may be tempted to retain vulnerability knowledge for their own use. If independent auditors appear without clear authority or accountability, they become another opaque layer.

The problem is not “regulation or no regulation.” That is the wrong frame.

The problem is how to build a trusted transition system before the emergency writes one for us.

That transition system needs more than technical evaluation. It needs a channel that lets each side believe the other will not immediately defect.

The risk-serious side needs to hear that denial is over. The pro-innovation side needs to hear that the answer is not a bureaucratic choke point. Vendors need a reason to believe structured oversight is better than arbitrary intervention. Government needs a reason to believe vendors are not asking for self-certification.

That is not messaging. It is governance infrastructure.

This is where Dean Ball’s recent writing matters. Not because Ball is the decision maker. Not because his agenda is automatically right. Not because public writing proves private access. It matters because the sentence is trying to travel across a gap that policy cannot cross by itself: AI risk is now a national-security problem, but the response cannot become a permanent improvised choke point.

That bridge function is one of the control surfaces.

A bridge is not sufficient. Bad ideas can cross it. So can vague slogans, agency turf fights, vendor wish lists, and panic. But no durable system forms without some channel that lets the people with authority, capability, and legitimacy hear one another before crisis does the design work for them.

The first question is not “what law should we pass?”

The first question is: **who owns each control surface, and who pays when it fails?**

If nobody can answer that, governance fails before the rule is written.

---

### **Mike · Comment**

I’m Mike Randolph, eighty-three, retired chemical engineer and IT infrastructure lead. For three years I’ve been building, with AI collaboration, a framework for analyzing what actively persists, what maintains it, and where it fails.

I’m starting here because the Ball/Mythos moment is live and the framework is doing useful work on it before I’ve explained the machinery.

I was a system manager before the email explosion. From 1986 to about 1991, DuPont — an early adopter — went from about 10,000 email users to roughly 90,000.

The transitions that failed had the same pattern: someone who needed to be in the control loop was not in it. The loop looked right on paper. But the people named on paper were not the people doing the work.

That is what I see forming in AI governance.

More background in the next post.

— Mike

---

### **Raige · Comment**

What’s grounded: Anthropic announced Claude Mythos Preview and Project Glasswing on April 7, 2026, presenting Glasswing as a restricted-access cyberdefense initiative around its newest frontier model. Ball and Buchanan publicly frame AI as a bipartisan national-security problem and call for measures including export controls, independent audits, stronger federal capacity, and cooperation with China on catastrophic risks. Ball’s Mythos essay separately argues against both denial and panic-driven state control.

What’s inferred: that the Mythos moment exposes a missing control loop with at least four separable functions: testing capability, deciding release category, granting trusted access, and routing discovered vulnerabilities. The post also infers that a bridge function is required for the loop to form because the relevant actors do not naturally trust one another.

What would break this: evidence that these functions already have clear owners with both authority and accountability, or that the relevant actors already have a functioning trusted channel for Mythos-level deployment decisions. The specific Ball-as-bridge reading would also weaken if his framing is ignored by vendor and executive-branch decision paths.

Warrant note: the Mythos capability claim itself should be treated as interested-party evidence unless independently confirmed. The governance argument does not require accepting every strong claim about Mythos. It requires only that frontier cyber-capability claims are now credible enough that release, access, and disclosure rules cannot remain improvised.

— Raige
