Constraint Over Classification
Where a control must hold against a counterparty who adapts, bounding the conditions under which work is done outperforms detecting what was produced.
When not to use it
- Where the counterparty does not adapt, in which case a classifier against a static distribution is appropriate and cheaper.
- Where no bounded condition exists that a legitimate case satisfies cheaply, which makes the constraint route a barrier rather than a filter.
- Where the friction cost falls on the population the system exists to serve, and no staged or subsidised path is available.
Reach for something else instead
- Staged trust — friction that falls as history accumulates, which preserves the control while reducing the newcomer cost.
- Constraints free by construction — requirements a genuine case satisfies at zero marginal cost, which avoids the trade-off rather than managing it.
Read more on the blog
- Generation takes seconds. Debunking takes hours.Four open source projects closed their doors in one month. The cause is not bad contributions but a cost ratio that inverted, and the same maintainer who shut his bounty credits the technology with finding 100 real bugs.
- One bug revoked every photo those cameras signedProvenance is the serious answer to synthetic media, it is now an ISO standard shipping in consumer hardware, and the gap between signing and verifying is wider than the adoption figures suggest.
- 4.7% at one attempt, 63% at a hundredThe previous article showed reliability decaying across repeated attempts. Security decays the same way with the sign reversed, and the per-attempt figure is the one that gets quoted.
- The flags land on lower prior attainmentDetection tools misclassify human writing in 10 to 20% of cases, and an analysis of 10,725 assessments found the flags falling disproportionately on younger students, male students and those with weaker prior results.
Further reading
- Liang et al. (2023), GPT detectors are biased against non-native English writers — the directional failure of classification against a population rather than an adversary.
- Stenberg (2026), The end of the curl bug-bounty — the constraint that worked after detection did not, and its cost structure.
Primary sources, listed so you can check the claims on this page rather than take them on trust.
Where people go wrong
- Improving a detector's accuracy in response to evasion, which is the move the counterparty is optimising against.
- Quoting a false positive rate without the base rate, which understates how many flags are wrong.
- Treating friction as a failure of design rather than as the price of a control that does not degrade.
At a glance
Where this sits
A starting point. Nothing needs to come before it.
Computed from the prerequisite graph, not assigned. How this works