Dispatches · Summit Cognitive

All dispatches

Cognitive securityFlagshipAugust 12, 20268 min read

A Threat Model for the Decision Itself

Security can protect the model, data, identity, network, and tool while the resulting decision still acquires more authority than its evidence can support.

AI security has become good at naming attacks on models and systems.

Prompt injection. Data poisoning. Model theft. Credential compromise. Tool abuse. Exfiltration.

These are real attack classes. They are not the whole threat model.

A system can resist all of them and still produce a decision that should not have acquired authority. The evidence can be stale. Several sources can repeat one underlying claim and look independent. A summarizer can remove uncertainty. A valid identity can act outside the purpose for which access was granted. A reviewer can approve a description without seeing the action parameters. A retry can execute after the original authority has expired.

Nothing in that sequence requires the model to be hacked.

Summit's argument is that the missing security object is the decision itself.

The term cognitive security already has established public use in cognitive-warfare and influence-operations contexts. Summit uses it here in a narrower institutional sense: the security of a specific decision path as evidence becomes authority. Both usages concern attacks on how conclusions form. This essay addresses the second.

A secure component is not a secure decision

Most technical controls attach to components. They test a model, protect a database, authenticate an identity, constrain a tool, or monitor a network.

Consequential decisions compose those components. They also compose evidence, interpretation, policy, delegated authority, human judgment, timing, and downstream action. The institution experiences the combined result, not the security posture of any one part.

This distinction matters because a decision can fail while every component reports healthy.

The model can faithfully summarize a source that should not have been admitted. Identity can correctly authenticate a principal whose authority did not cover this target. A policy engine can apply the wrong but valid policy version. A human can approve exactly what the interface showed while the interface omitted the material consequence. An action can complete after the calling workflow reports failure.

Component security remains necessary. It is not sufficient for the decision that emerges from the system.

The Consequence Surface

Cognitive Security starts with the path by which information gains the authority to change the world. That path is the Consequence Surface.

It has seven boundaries.

  1. Evidence entry. What information was admitted, from which source, at what time, with what provenance and independence?
  2. Interpretation and inference. What did the system add, compress, classify, translate, or remove?
  3. Authority assignment. Which principal was permitted to decide, recommend, approve, or act, and within what limits?
  4. Decision formation. Which evidence, policy, threshold, exception, and uncertainty produced the verdict?
  5. Action boundary. What external change was requested, what actually executed, and was it reversible?
  6. Durable record. What evidence survives for a party that did not operate the system?
  7. Review and redress. Who can contest, reopen, reverse, or learn from the decision after consequence?

These are not seven claims that Summit invented seven new classes of vulnerability. They are a practical decomposition of one consequential path. The purpose is to show where a technically healthy workflow can become institutionally indefensible.

The first five are attackable transitions. The final two are accountability boundaries whose failure often appears as absence: no durable record, no usable challenge path, or retention shorter than the discovery window. They belong on one surface because an attacker can exploit both what a system does and what an institution will be unable to prove afterward.

The control question at each boundary is the same: did information acquire more authority than its warrant could support?

Within Summit's editorial system, this is the parent map. The Receipt Sufficiency Test examines boundary six, the durable record. The Authority Envelope concentrates on boundaries three through five. The adversarial-information framework traverses the first five. The Decision Control Loop is the operating cycle across all seven. Naming the relationship matters because a framework should tell the reader which part of the decision it governs, not compete as another standalone list.

When repetition becomes false consensus

Consider a declared composite, assembled from common enterprise workflow patterns rather than a claimed Summit deployment. It is not a customer, incident, or deployment. No real vendor, product, monitoring system, or data feed is depicted.

An enterprise agent recommends suspending a vendor account after three monitoring systems flag the same risk. The interface presents three corroborating alerts. The operator approves the suspension. A later review finds that all three alerts were derived from one upstream feed, and that feed carried a classification error.

No credential was stolen. No model was poisoned. No policy was bypassed. Every component behaved as designed.

The failure was false independence. One claim crossed three interfaces and acquired the appearance of consensus.

Intelligence tradecraft has long treated this source-recycling problem as circular reporting. The failure is not new. The machine-mediated substrate makes it faster, cheaper, and harder for component-level monitoring to see.

That failure enters at the evidence boundary, but it does not stay there. Interpretation converts three alerts into corroboration. Authority permits the workflow to recommend suspension. Decision formation treats apparent agreement as increased warrant. Action changes the vendor's access. The record may preserve three alerts without preserving their common origin. Review begins with a misleading artifact.

A conventional incident review can report that the systems were available, authenticated, and policy-conformant. A Cognitive Security review asks the harder question: did this decision have sufficient warrant to act?

Seven boundaries, seven defensive questions

The Consequence Surface turns that harder question into a working threat model.

At evidence entry, test provenance, freshness, source independence, admissibility, and revocation. More documents do not mean more evidence when they inherit one origin.

At interpretation, preserve uncertainty and material disagreement. A useful summary can still become a security failure when it deletes the caveat that should have changed the action.

At authority assignment, separate identity from permission and permission from purpose. A valid credential does not establish that this principal may impose this consequence on this target now.

At decision formation, bind the verdict to the evidence and policy actually used. A current policy document cannot explain a decision governed by an earlier version.

At the action boundary, distinguish evaluation from execution. An accepted decision does not prove that the action completed, completed once, or remained within its authorized window.

At the durable record, preserve enough context for a relying party to inspect the decision without depending entirely on the operator's memory or dashboard.

At review and redress, make contestability operational. A review path that cannot identify the original evidence, authority, and policy is escalation theater, not a control.

Why this is not generic AI safety

The strongest objection is that this is process failure wearing a security costume. The answer is not to call every quality defect an attack. A failure belongs in the threat model when it has a mechanism, creates consequence, and offers advantage to a party who can exploit the gap. The Consequence Surface makes that test explicit.

AI safety often asks whether a system behaves acceptably across tests, policies, and deployment conditions. Cybersecurity asks whether systems, identities, data, and operations resist compromise. Governance asks whether authority and accountability are assigned.

Cognitive Security composes those disciplines around a specific consequence-bearing decision.

It does not replace model security, identity, application security, safety evaluation, audit, legal review, or governance. It gives them a shared object. Their controls meet at the point where evidence becomes a decision and a decision becomes an action.

This is also not a promise of correct decisions. A threat model cannot prove truth, eliminate uncertainty, or guarantee an outcome. It can make failure paths legible, expose where authority outran evidence, and preserve enough record to contain, contest, and learn from the result.

That is a narrower claim than safety. It is also more operational.

Human review illustrates the design obligation. The system should preserve what the reviewer was shown, what they checked, and what their approval covered. That is a requirement on the review architecture, not a demand that a person compensate for missing context by intuition.

Threat-model one real workflow

Do not begin with an enterprise-wide taxonomy.

Choose one decision with a meaningful consequence. Draw its path from evidence to redress. At each boundary, record the object entering, the transformation applied, the authority exercised, the failure that can remain invisible, the control expected to catch it, and the artifact that proves the control operated.

Then ask five direct questions.

  • Where can repeated evidence look independent?
  • Where can uncertainty disappear without an explicit decision?
  • Where can authenticated access exceed authorized purpose?
  • Where can evaluation and execution diverge?
  • Where can a later reviewer lose the ability to reconstruct or contest the decision?

The gaps are not abstract AI risk. They are the places where an institution can act without being able to defend why.

Secure the components. Then threat-model the decision they make possible.

CTA: Apply the Consequence Surface to one consequential workflow. Count only the controls that leave evidence a reviewer outside the operating team could inspect.

Public references

Dispatches · Summit Cognitive