Form of Life a public ethics instrument
Browse

Prevent the foreseeable failure

Cybernetic and systems Ethical Economic and class Media theoretic

A well-made system anticipates likely errors and reduces dependence on someone remembering to repair them later.

Craft includes an imagination of how the thing is likely to break. Recurrent mistakes, fragile handoffs, omitted fields, and dependencies on perfect memory are treated as design conditions rather than surprises reserved for a later repair.

Prevention takes the form of clear defaults, checks, durable state, and interfaces that make the next right action easier to recognize. It does not promise control over every outcome; it accepts responsibility for the failures that careful construction could reasonably foresee.

The philosophical claim

Design is responsible for breakdowns that ordinary attention to prior incidents, defaults, and handoffs could reasonably anticipate.

The ethic of precaution asks when possibility becomes responsibility, while systems design shows how individual error is often invited by structure. The concept refuses to treat every recurrent failure as a fresh surprise or a user's private defect. At the same time, prevention can become a fantasy of total control that burdens everyone with safeguards against remote scenarios. The governing question is proportionality: which foreseeable harms are serious and likely enough that craft should change the conditions under which action occurs?

Intellectual conversations

Mechanism and practice

How the claim operates

The maker studies incident patterns, fragile transitions, omitted information, and places where success depends on perfect memory. Each important failure receives an owner, a detectable precondition, a helpful default or validation, and a recovery path that preserves meaningful work. Safeguards are tested with the people who encounter them so protection does not merely relocate effort. New failures update the design system rather than remaining isolated anecdotes.

Philosophical implications

What follows if this idea is taken seriously

The claim underneath this idea is about where blame is allowed to settle. Individual error is very often invited by structure — by a fragile transition, an unhelpful default, information omitted at exactly the moment it was needed, or a design that quietly depends on somebody's perfect memory. Once a failure has recurred, describing it as a user's private defect is a decision about accounting rather than a finding, and it has the convenient property of requiring nothing to change. Treating the same breakdown as a fresh surprise each time performs the same service.

Prevention nevertheless has no natural stopping point, which is why proportionality rather than caution is the governing question. A sufficiently determined effort to eliminate remote scenarios burdens everyone with safeguards against events that will not happen, and the burden is real even when the risk is not. So the question is never whether harm is conceivable but whether it is serious and likely enough that craft should change the conditions under which people act. That is a judgment, made with incident data, and it is revisable when the data moves.

Each of the three failure modes is a way protection becomes its own hazard. Guardrails with enough friction get routed around, leaving people less safe than no guardrail would have — the safeguard has not failed to work, it has taught everyone to work without it. A control can signal responsibility while failing under the exact condition it claims to prevent, which is the worst case, because its presence removes the vigilance that would otherwise have covered the gap. And a check that cannot detect its own blindness reports clean whether or not anything was inspected. A guard is not proven by its existence, or by a quiet record; it is proven by having fired on something real.

The third failure runs in the other direction and deserves its own weight: hindsight makes an unusual event look obvious, and the language of foreseeability then turns into blame. Foreseeable is judged after the fact by people who now know what happened, and that knowledge reorganises the past into a sequence that appears to have been signposted. Holding design responsible for what ordinary attention could anticipate is meaningful only while ordinary attention means what was available beforehand. Otherwise the concept becomes a device for assigning fault after every accident, which is the opposite of the structural view it began from.

Tensions, failure modes, and change

Where the claim can fail

  • Guardrails can create so much friction that people route around them and become less safe.
  • A control can signal responsibility while failing under the exact condition it claims to prevent.
  • Hindsight can make an unusual event appear obvious and turn prevention language into blame.

No design can anticipate every misuse, dependency failure, or change in context. Safeguard cost should be proportionate to likely harm, and expert override or graceful escape may be necessary. The concept is contradicted when the same known failure repeats through an unchanged structure, when a check cannot detect its own blindness, or when prevention imposes greater harm than the event. Monitoring and actual incident data should revise both the safeguard and the estimate that justified it.

Lens-by-lens reading

Each lens contributes a different question.

  1. Cybernetic and systems

    The systems lens moves correction upstream. Recurrent failure becomes a signal to change defaults, validation, or handoff structure so that safety does not depend on a person remembering the same manual repair under pressure.

    It converges with ethics on responsibility for predictable effects and with media theory on how an interface can make the safe action normal rather than exceptional.

  2. Ethical

    The ethical reading treats known failure as a prospective obligation. Once a harmful or costly error is reasonably foreseeable, leaving its prevention to downstream vigilance shifts avoidable risk onto the people who did not choose the design.

    It converges with the economic lens on displaced maintenance labor and with cybernetics on changing the producing system rather than repeatedly praising individual rescue.

    Foreseeability is graded, not omniscience, and prevention competes with time, access, and other risks. The lens cannot infer culpability without knowing what was reasonably knowable and actionable.

  3. Economic and class

    The economic lens asks who pays for a failure that the system could have caught. Manual checks, re-entry, recovery, and repeated explanation consume labor, and their distribution can turn a small design omission into a durable inequality.

    It converges with ethics on avoidable burden and with media theory on whether warnings and controls are available to people with different time, access, and technical fluency.

  4. Media theoretic

    Media theory locates foreseeable failure in affordances and defaults. What the interface hides, preselects, remembers, or makes difficult shapes error before any user's intention enters, so prevention includes changing the path through the artifact.

    It converges with cybernetics on feedback-informed controls and with economics on how inaccessible design concentrates recovery work among expert users.

    An affordance analysis cannot establish how every user will act, and friction may be protective in one setting and exclusionary in another. The lens requires observed use rather than design inference alone.

System connections

Read beside, not in isolation

Related commitments: Place the phone face-down, Keep a writing medium ready

Related through-lines: Architecture protects relationships, rather than perception management