Essay

Recursive Mutual Modeling

A cybernetic theory of trust, meaning, governance, and coordination among opaque operators

· Consentful Cybernetics
consentful-cyberneticsrecursive-mutual-modelingfractal-identityself-modelingmodel-elicitation-loopcyberneticstrustfield-pragmaticsparticipatory-attributabilitygovernancecommunicationagentic-aisecond-order-cybernetics

Abstract

Cognitive operators do not directly exchange internal models. They exchange compressed signals across boundaries, reconstruct those signals through private context, and act through recursively nested models of themselves and one another. A participant does not merely ask, “What will the other do?” but also, “Who am I in this context?”, “How will the other interpret what I do?”, and “What does the other believe I understand myself to be?” The other participant performs the same operation. This creates a recursive mutual modeling loop beneath communication, identity, trust, delegation, governance, conflict, development, and repair.

This paper proposes Recursive Mutual Modeling Theory as a cybernetic account of coordination among partially opaque operators. The theory treats the operative self as a context-conditioned model rather than a singular transparent object; pragmatics as contextual decompression; trust as permission to truncate recursive uncertainty and grant interpretive latitude; credentials as model-rebase signals; governance as the constraint of interpretations that become action; the Model-Elicitation Loop as the process by which one participant’s model alters the field encountered by another and may thereby help produce confirming conduct; and Participatory Attributability as the valence-neutral relation between participants and the consequences that emerge.

Self-models are socially co-produced but not socially exhausted. Endogenous bodily conditions, non-social physical experience, independently generated measurements, and consequences not shaped by another participant’s expectations remain distinct inputs. Yet none enters an operative self-model without interpretation. Social feedback is especially recursive because a participant’s model can change how that participant behaves toward another, which changes the opportunities, constraints, evidence, and reflected appraisals available to the recipient. The resulting self-model may then elicit conduct that appears to confirm the originating model.

Because compression and latency are unavoidable, divergence is not an exceptional failure but a normal property of coordination. The design objective is therefore not identical internal models. It is to help compressions cross boundaries without gross distortion by preserving invariants, boundaries, provenance, refusal, feedback, reversibility, and repair. The same grammar applies across scales: two children negotiating a swing, a manager interpreting an employee, a contractor acting for a homeowner, an AI agent operating through tools, organizations coordinating through credentials and contracts, and nation states interpreting one another under partial observability. Recursive Mutual Modeling Theory offers a shared language for describing how these systems coordinate, how identities and expectations become recursively stabilized, why they diverge, and how consentful cybernetic architecture may keep the divergence legible and corrigible.

1. The Problem Beneath Communication

The ordinary model of communication is deceptively simple. One participant possesses meaning, encodes part of it into a message, and transfers that meaning to another participant. The recipient then decodes the message and possesses some portion of what the sender knew.

This is not how communication works.

No participant can place an internal model inside another. A speaker can only produce a bounded projection: words, gesture, posture, credential, contract, action, omission, refusal, record, interface event, or some other trace. The recipient does not receive the speaker’s meaning. The recipient constructs an interpretation using a private model of the speaker, the situation, the surrounding institutions, the available alternatives, and the likely consequences.

The sentence “clean up my filesystem” does not contain an operation. It could mean light rearrangement, duplicate removal, archiving, permission repair, application removal, cache deletion, filesystem reconstruction, or complete reformatting. The words leave most of the actionable meaning unstated. Their practical meaning depends upon who speaks, who listens, what access exists, what work preceded the request, what is considered normal, which files are protected, how reversible the actions are, and what each participant believes the other expects.

Communication is therefore not the transfer of an internal object. It is compressed model coupling.

A semantic message is a bounded projection from one internal model that recruits another operator to construct a locally actionable model of what it means.

The coupling is never perfect. The recipient’s model is not the sender’s model, and the recipient cannot inspect the sender’s model directly. Even an explicit explanation of the sender’s model becomes another compressed signal that must be interpreted.

Everything above 🜁 involves context, and context involves interpretation.

Within the symbolic architecture used here, 🜁 names presence before a particular relation has evaluated, recruited, or interpreted it. Once a participant is taken as a speaker, worker, contractor, client, threat, authority, subordinate, witness, or system component, context has entered. The participant has become situated within another operator’s model.

2. Nested Black Boxes

The operators in this theory are not perfectly sealed black boxes. They emit signals and traces continuously. Bodies reveal fatigue and fear. Organizations reveal priorities through budgets and incentives. States reveal capacity through logistics and deployment. Software systems reveal internal conditions through outputs, failures, timing, and logs.

But none of these traces provides transparent access to the operator’s complete internal state. The boundary is better understood as semipermeable: consequences and signals cross it, while the generative model remains only partially available.

This opacity applies recursively. A nation is a partially opaque operator composed of ministries, agencies, companies, factions, citizens, technical systems, and individual people, each of which is itself partially opaque. A company is composed of departments, roles, policies, incentives, software, and workers. A person contains multiple teloi, habits, predictive loops, commitments, memories, bodily conditions, and internal constituents that may not form one perfectly coherent voice.

The receiver must frequently compress an internally plural sender into an actionable model.

When an analyst asks, “What does this government want?” or a child asks, “Does she like me?” each is constructing a provisional unity from outputs that may have been generated by no single unified intention.

This is the first structural condition of Recursive Mutual Modeling Theory:

Coordination occurs among nested, partially opaque operators whose internal models cannot be fully shared.

The second condition is that these operators are not merely exchanging descriptions. They are coupled through a shared world. A shove changes another child’s physical state. A troop movement changes military capacity. A filesystem command changes stored data. An interest-rate decision changes access to capital. These actions may also function as messages, but their semantic interpretation does not exhaust their effect.

Operators exchange compressed signals and impose material consequences through shared substrates.

Actions are therefore often both intervention and message. They change the field and become evidence inside another participant’s model of why the field changed.

3. The Recursive Mutual Modeling Loop

Suppose two cognitive operators, A and B, are coordinating within context C.

A does not act directly from a complete, context-free A. A acts through a context-conditioned self-model:

M_A(A | C)

A also maintains a model of B:

M_A(B | C)

And A models how B models A:

M_A(M_B(A | C))

A may additionally model what B believes A believes about B, or what B believes A believes itself to be:

M_A(M_B(M_A(B | C)))

M_A(M_B(M_A(A | C)))

The recursion can continue conceptually without bound. In practice, no finite operator carries it to infinity. Human beings, institutions, and AI systems truncate it at a depth supported by capacity, stakes, context, trust, and available time.

An illustrative action policy might be written:

a_A = π_A(x_A, M_A(A | C), M_A(B | C), M_A(M_B(A | C)), G_A, C_A)

where x_A is A’s locally sensed state, G_A its active telic configuration, and C_A its interpreted context. This is not offered as a complete formal model. It makes visible that A’s action depends not only upon A’s model of B, but upon the self that A presently takes itself to be and A’s estimate of how that self is represented by B.

The practical loop is:

  1. A acts through a context-conditioned self-model and projects a compressed signal across a boundary.
  2. B reconstructs an interpretation through B’s context, B’s self-model, and B’s model of A.
  3. B updates both its model of A and its model of what A expects B to understand.
  4. B acts through those nested models.
  5. The action changes a shared substrate and becomes a new signal for A.
  6. A interprets the return, updates its model of B, its model of B’s model of A, and potentially its own self-model.
  7. The next action begins from the altered field.

The loop is self-modifying. Communication does not merely exchange information about stable models. It changes the models being used to interpret the next exchange, including the models through which each participant recognizes itself.

This is why apparently minor phrasing can become recursively consequential. If I overexplain because I think you may misunderstand, you may infer that I believe you are uninformed, untrustworthy, or resistant. I then interpret your response as evidence that you believe I underestimated you. We are no longer responding only to the original subject. We are responding to our models of one another’s models and to the selves those reflections invoke.

“Why did you say it like that?” is often a request to expose one layer of recursive mutual modeling.

4. Context-Conditioned Self-Models and Fractal Identity

Recursive Mutual Modeling Theory requires a reflexive term. An operator does not merely model the world and other operators. It also maintains a model of itself within the present context.

An operator acts through a contextually invoked compression of itself.

The operative self-model may include roles, commitments, capacities, histories, loyalties, bodily conditions, boundaries, expectations, and anticipated futures:

  • I am the expert here.
  • I am a guest here.
  • I am responsible for this person.
  • I am being evaluated.
  • I am the kind of person who does not abandon a commitment.
  • I am out of my depth and should defer.

These are not merely descriptions added after action. They alter what becomes salient, which ends are recruited, which interpretations appear plausible, which risks feel tolerable, and which actions remain representable.

This invokes Fractal Identity. The self active in an interaction is neither the whole operator nor an arbitrary mask. It is a nested, context-activated configuration. A person may simultaneously act as a technician, subordinate, parent, professional, friend, citizen, threatened organism, and anticipated future self. An organization may invoke itself as innovator, fiduciary, employer, competitor, public institution, or embattled survivor. Different contexts activate different configurations, and those configurations can conflict.

The operator’s self-model is not privately authored from nothing. It is assembled and revised through multiple classes of input:

  • endogenous bodily and affective signals;
  • non-social physical experience and material consequence;
  • independently generated evidence, measurement, and instrumentation;
  • memory and anticipation;
  • action and observed result;
  • socially mediated feedback, expectation, classification, praise, stigma, and refusal.

These sources should not be collapsed. A physical constraint can remain independent of another participant’s expectations. An instrument may report a condition without intending anything. A sender may provide comparatively unbiased feedback, or feedback shaped heavily by prior belief. A receiver may understand or misunderstand the existence of that bias and may accept, discount, reinterpret, or reject the signal.

Yet every source must still be modeled in order to update the operative self. A does not receive a metaphysically final A. A receives signals, consequences, and traces and constructs M_A(A | C) from them.

The social case is especially recursive. B holds M_B(A | C) and emits behavior shaped by that model. A observes B’s behavior and constructs:

M_A(M_B(A | C))

A’s model of B’s model of A may then update A’s own self-model. A can reject the reflection, accept it provisionally, treat it as authoritative, or organize future action around preserving or disproving it.

We do not merely model one another. We become, in part, the models of us that we accept from one another.

Within this theory, ego can be used provisionally for the continuity-maintaining activity organized around accepted self-models. Once a reflected description is incorporated—capable, irresponsible, indispensable, difficult, generous, dangerous—the operator may begin selecting evidence, relationships, and actions that preserve or contest it. This is not offered as a complete psychological definition of ego. It identifies one cybernetic function: maintaining enough identity continuity for prediction and action while negotiating feedback that may rebase the operative self.

This claim does not reduce identity to social reflection. It says that reflected models are among the inputs from which an operator constructs and maintains context-conditioned identity, and that these inputs can become self-reinforcing once incorporated.

5. The Model-Elicitation Loop

A participant’s model of another can affect more than interpretation. It can alter the field the other participant encounters.

The Model-Elicitation Loop occurs when a participant’s model of another changes the opportunities, constraints, feedback, risks, and responses made available to that participant, thereby eliciting conduct or development that increasingly resembles—and appears to validate—the originating model.

The minimal structure is:

M_B(A | C) → B’s treatment of A → A’s experienced field → M_A'(A | C) → A’s action → M_B'(A | C)

If a manager models an employee as capable, the manager may offer harder work, tolerate exploratory errors, provide richer feedback, wait longer for answers, and interpret temporary difficulty as part of learning. The employee encounters a field in which competence can be exercised and witnessed. Performance and self-model may change, generating evidence that confirms the manager’s expectation.

If the manager models the same employee as unreliable, the manager may withhold meaningful work, monitor aggressively, interrupt initiative, interpret ambiguity as failure, and deny access to corrective context. The employee encounters a narrower field, produces fewer disconfirming examples, and may begin acting defensively or dependently. Again, the originating model appears to acquire evidence.

The loop can operate without explicit identity statements. B need never tell A, “You are capable,” “You are dangerous,” or “You are difficult.” B’s permissions, patience, surveillance, explanations, invitations, exclusions, and interpretations can communicate the model materially.

The same visible feedback may also have different effects depending on the receiver’s model of its provenance. A measurement believed to be independent may be incorporated differently from praise believed to be strategic. A judgment believed to come from a qualified witness may carry more model-rebase weight than the same judgment from a stranger. Even the decision to accept or discount feedback is itself made through M_A(A | C), M_A(B | C), and the surrounding field of trust.

The Model-Elicitation Loop is valence-neutral. It can contribute to competence, confidence, trustworthiness, leadership, recovery, dependency, hostility, stigma, incapacity, or exclusion. It does not imply that expectations alone create the operator, nor that all confirming conduct is artificial. It identifies a recursive path by which a model participates in constructing the conditions under which its apparent accuracy is tested.

The familiar teacher-expectancy or Pygmalion example illustrates the form but should not be treated as a complete theory of childhood development or intelligence. Empirical expectancy effects are generally conditional and more modest than popular retellings suggest. The cybernetic point is narrower: expectations can alter treatment; treatment can alter opportunity, feedback, self-conception, and performance; resulting conduct can then re-enter the expectation as confirming evidence.

A model can therefore become more accurate because it helped produce the field in which its object acted.

6. Pragmatics as Contextual Decompression

Literal semantics does not select a unique action. Pragmatics is the process by which a participant expands a compressed signal into situated meaning.

Field Pragmatics is the contextual selection of an actionable decompression.

The “field” matters because interpretation is not produced by words alone or by two isolated minds. It is shaped by roles, history, credentials, material conditions, technical affordances, institutional norms, law, incentives, risk, timing, and the presence of other affected participants.

“Can you reach the salt?” is ordinarily interpreted as a request rather than a test of arm length because the participants rely upon a compact stack of mutual assumptions. The speaker expects the listener to recognize the convention. The listener expects that recognition to be expected. Several layers of mutual modeling collapse into a routine pragmatic uptake.

The same process governs much larger mandates:

  • “Do my accounting.”
  • “Install a sprinkler system.”
  • “Handle this customer.”
  • “Clean up the repository.”
  • “Keep the border secure.”

None contains the work it invokes. Each recruits a participant to supply omitted operational meaning from a larger field of competence and context.

Interpretation is not an incidental stage between instruction and action. It is where most of the action is constructed.

This is especially visible in delegation. The principal does not generally divide a complete project into fully understood units of authority and hand them to another. The principal provides a small, compressed mandate. The recipient expands it using capacities the principal may not possess and systems the principal may not understand.

“Do my accounting” does not transfer accounting knowledge. It invokes accounting knowledge already present in another operator and in the institutional field surrounding that operator.

7. Trust as Finite Recursion

Recursive mutual modeling presents a practical problem. If every action required a complete model of the other participant, a complete model of the other participant’s model, and a complete model of each further level, coordination would halt.

Trust permits the recursion to stop.

Trust is permission to truncate recursive mutual modeling sufficiently for action.

This does not mean that trust eliminates uncertainty. It means that the participant is willing to act without resolving all of it. Trust compresses a large range of possible interpretations into a provisional expectation that the other participant will remain within a viable region.

In delegation, trust is also permission to interpret.

Trust is willingness to expose some portion of one’s continuity to another participant’s interpretation.

When a client trusts an accountant, the client does not merely predict that the accountant is honest. The client grants interpretive latitude. The accountant is permitted to determine what routine operations are implied, which legal and professional boundaries remain operative, what the client likely misunderstands, and when the mandate must return for clarification or renewed consent.

Professional trust contains an expectation that the expert will protect the client from authorizing what the client does not understand well enough to authorize safely.

This is not blind obedience in reverse. The trusted participant is not expected to do whatever the requester says. The participant is expected to preserve continuities that the requester may be unable to perceive.

Trust therefore determines an acceptable compression ratio. With low trust, a participant specifies, supervises, verifies, limits permissions, and preserves reversibility. With high trust, the participant can leave much more meaning unstated because the recipient is expected to reconstruct it competently and refuse abnormal expansions.

The more trust, the more unfinished meaning may cross the boundary.

8. Credentials as Model Rebase Signals

Credentials do not reveal an operator’s full internal model. They change the context in which another participant models that operator.

A license, certification, professional designation, insurance policy, bonded status, institutional role, or verified history allows the receiving participant to rebase their model onto compressed testimony supplied by a wider system.

A credential is a model-rebase signal: “Interpret this participant using the tests, norms, duties, and recourse mechanisms associated with this institutional category.”

“CPA” does not prove that a particular accountant is competent, ethical, current, or appropriate for every task. It permits the client to provisionally assume a different set of capabilities, refusal duties, professional boundaries, and accountability channels than they would assume for a helpful neighbor.

A licensed contractor and an experienced neighbor may possess similar practical skill. The credential changes the reasonable trust field. It changes how much explanation appears necessary, how much interpretive latitude may be granted, what kinds of refusal are expected, and what remedies are presumed if the work causes harm.

Credentials are therefore compressed witnesses. They allow many prior assessments, institutional processes, and enforceable expectations to influence a present trust decision without being fully replayed.

But the rebase can be wrong. Credentials may be fraudulent, expired, irrelevant to the task, weakly enforced, or granted by institutions whose standards are misunderstood. A credential can also overpower contradictory evidence and produce excessive trust.

A credential is not trust itself. It is socially supported evidence used to construct trust.

9. The Field of Trust

Trust is not simply a property between two isolated actors. It is an estimate made inside one participant’s model of a larger field.

Several interacting fields contribute to that estimate.

Field Pragmatics concerns how a signal becomes situated meaning: What does this request reasonably mean here?

The Telic Field concerns directedness: Which ends are active, which are subordinate, and which hidden or competing purposes are recruiting the action?

Field Governance concerns legitimate control: Who may authorize, prohibit, interrupt, constrain, revise, or require renewed consent?

Field Attributability concerns consequences: How does each participant’s knowledge, intention, control, inducement, refusal capacity, and opportunity to intervene relate to what emerges?

An epistemic field distributes what is known, believed, suspected, discoverable, concealed, or unavailable. A capability field distributes what each participant and system can actually do. A boundary field describes whose continuities may be affected and which limits remain independently operative. An incentive field creates gradients toward and away from possible interpretations. A temporal field describes latency, sequencing, expiry, stale context, reversibility, and the changing cost of correction.

These fields do not need to be treated as separate substances. They are analytic projections of a coupled situation. Together they form the Field of Trust as perceived by a participant.

Given who I think you are, what I think you believe about me, what I think this situation permits, what I think the surrounding systems will enforce, and what I think will happen if something goes wrong, how much unfinished meaning may I safely place in your hands?

That question is answered from inside a private model. Trust is therefore always partly trust in one’s own model of the field.

10. Authority Is Assembled, Not Transferred

Delegation is commonly pictured as the division and transfer of authority. The principal possesses authority, cuts off a bounded portion, and gives it to an agent.

The model fails in ordinary practice.

When a homeowner asks a contractor to install a sprinkler system, the homeowner does not transmit a complete set of authorized actions. The contractor brings preexisting competence, tools, employees, licenses, access to suppliers, knowledge of codes, and understanding of utilities. The municipality, utility, insurer, property boundaries, and the rights of neighbors remain independently operative.

The resulting standing to proceed is assembled from multiple sources:

  • the requester’s authorization of an objective;
  • the recipient’s role and willingness to participate;
  • the recipient’s competence and professional duties;
  • the permissions of technical and institutional substrates;
  • the law and applicable standards;
  • the boundaries of affected parties;
  • and the current state encountered during execution.

No single participant owns the whole permission surface.

A property owner can authorize excavation on the property. The contractor can agree to perform it. Neither can authorize cutting an active municipal water main. If an old line has been abandoned, the utility may issue a waiver. If the line remains active, the utility may impose a hard refusal. The physical operation may appear similar, but the field of standing differs.

Likewise, an employee does not ordinarily use the employer’s personal system account. The employee acts through an independent identity with independently granted permissions. The principal may authorize an outcome, but a system administrator, application owner, legal authority, or resource custodian may need to authorize the means.

Permission is polycentric.

The same distinction appears in computing. A user may execute many network programs but remain unable to create a raw socket. The operating system is not merely a passive conduit. It acts as another governance participant and refuses operations for which the present identity lacks standing.

Root is not more understanding. Root is fewer vetoes.

Elevating a process does not improve the operator’s model of consequences. It removes independent constraints that might otherwise preserve continuities the operator does not perceive.

11. Every Participant Is a Continuity Officer

The Continuity Office is often imagined as an organizational function responsible for preserving operations, records, roles, and institutional memory. Recursive Mutual Modeling Theory reveals a more general structure.

Every participant performs a continuity function for the domains they can uniquely affect or perceive.

An accountant refuses a fraudulent entry. A contractor stops when an undocumented line appears. A system administrator withholds excessive privileges. An employee refuses an illegal instruction. A software system rejects an unauthorized operation. An AI agent pauses when a requested action crosses a material boundary that the user may not understand.

The participant is not merely protecting the requester from consequences. The participant preserves their own integrity, professional obligations, entrusted systems, affected parties, and future standing.

Every participant is a continuity officer for the boundaries, obligations, systems, relationships, and futures they are capable of affecting.

The organizational Continuity Office does not become the sole continuity authority. Its function is to make these distributed continuity authorities, refusals, escalation paths, and witness records legible and coordinated.

This changes the meaning of compliance. Refusal is not necessarily failure to execute. It may be the local operation through which continuity is preserved.

It also changes the meaning of supervision. A principal cannot absorb another participant’s integrity by issuing an instruction. Authorization may permit participation, but it cannot erase independent boundaries or convert superior knowledge into obedient innocence.

12. Participatory Attributability

“Culpability” names a negatively valenced relation to an outcome. “Credit” and “merit” name positive relations. “Responsibility” is broad but overloaded, often mixing duty, causation, authority, blame, and repair.

Participatory Attributability is proposed as the valence-neutral base class.

Participatory Attributability is the degree and manner in which an action, condition, or outcome may properly be associated with a participant, given that participant’s knowledge, intention, authority, conduct, control, inducement, refusal capacity, and opportunity to preserve or restore continuity.

Culpability, credit, merit, accountability, liability, authorship, and reparative obligation are possible resolutions of this underlying relation.

Participatory Attributability is not merely causal attribution. A manager may never perform the harmful operation yet create incentives that make it predictable. An expert may carry out an authorized action while knowing that the requester fundamentally misunderstands its implications. A worker may press the final button after being trained through unsafe norms and denied a safe refusal path. A system designer may remove the vetoes that would have prevented the consequence.

The action path alone is insufficient.

Participatory Attributability is better modeled as a field.

A Participatory Attributability Field is the time-varying distribution of knowledge, agency, authority, capability, inducement, constraint, refusal, intervention, and repair across the participants and systems surrounding an unfolding consequence.

The realized event is one trajectory through that field. Nearby unrealized paths matter as well. Who could have warned? Who could have stopped the process? Who could not realistically refuse? Who concealed an alternative? Who preserved reversibility? Who never knew another path existed?

Attribution depends partly on this counterfactual topology.

Two participants may perform the same visible act while occupying radically different positions in the field. One may understand the implications and possess several low-cost alternatives. The other may be misinformed, pressured, dependent, and exposed to severe punishment for refusal. The causal action can look identical while the Participatory Attributability differs greatly.

The field contains many simultaneous paths: intention, authorization, capability, knowledge, incentive, concealment, refusal, consequence, feedback, and repair. These paths branch, merge, conflict, and recurse. No single chain contains the event.

13. Compression, Latency, and Divergence

The unavoidable conditions of this theory are captured by a sentence that preceded its present use:

Compression and latency are the reason for divergence and learning, and all manner of beauty and madness.

Compression creates interpretive space. A message cannot contain the sender’s full model, so the receiver must construct an expansion. Different participants possess different histories, roles, capacities, priors, incentives, and situational access. Even competent and sincere decompressions will diverge.

Divergence is not an accidental failure of delegation. It is an ordinary result of compressed coordination.

Latency gives divergence time to become consequential. Latency includes every interval between action and effect, effect and perception, perception and communication, communication and correction, and changed conditions and renewed authorization.

During that interval, participants continue acting from incomplete or increasingly stale models. The requester may believe a mandate is being interpreted one way while the recipient has encountered conditions that materially change it. The surrounding system may already be accumulating consequences. An affected party may not yet know that a boundary has been crossed.

Compression creates possible expansions. Latency allows one expansion to become reality before the others can correct it.

But the same structure makes learning possible.

A perfectly uncompressed instruction would leave no interpretive problem to solve. A system with no meaningful interval between model, action, consequence, and correction would have no distinguishable update process. Learning requires a compression to encounter a world that does not fully conform to it.

Learning is divergence made legible in time.

Beauty appears when divergent reconstruction discovers a viable coherence no participant fully specified. A musician interprets a score. A skilled worker notices and solves a problem the requester could not name. A friend understands a silence. A scientific theory compresses observations into a new relation that changes what others can perceive.

Madness appears when recursive decompression becomes detached from effective correction. An interpretation produces action, delayed or distorted feedback is incorporated as confirmation, and the system continues expanding away from shared ground while retaining momentum.

Beauty is divergence that discovers viable coherence. Madness is divergence that loses constraint while retaining momentum.

The distinction is not that beauty contains interpretation while madness does not. Both arise from interpretation under compression and latency. The difference is whether divergence remains witnessed, bounded, corrigible, reality-responsive, and capable of renewed consent.

14. Playground and Nation State

The theory is scale-independent in grammar, though never in stakes or moral interpretation.

Two children negotiate access to a swing. One says, “I was here first.” The other reaches for it. A push occurs. A teacher intervenes. Parents later receive compressed accounts. Each participant models what the others intended, knew, expected, and believed about them. The shove is both a material intervention and a signal. Its meaning changes as it is retold through different contexts.

Nation states operate through the same recursive structure at vastly greater scale. A state moves troops, changes tariffs, issues a diplomatic note, conducts an exercise, leaks a document, or remains silent. Another state interprets those actions through a model of the sender’s capacities and purposes, as well as a model of what the sender believes the receiver will infer.

One side mobilizes because it predicts aggression. The other interprets the mobilization as evidence that its original fear was correct and mobilizes in response. Each action becomes both cause and evidence inside the other participant’s model.

Conflict often emerges not from first-order disagreement but from divergence in models of models.

Both parties may know that a deadline is flexible, yet one may believe the other thinks it is firm. Both states may prefer to avoid war, yet each may believe the other interprets restraint as weakness. Both children may want a turn, yet each may believe the other intends exclusion.

The relevant questions become:

  • What did each participant believe?
  • What did each believe the others believed?
  • What did each believe the others expected them to infer?
  • Which signals changed those nested models?
  • Which feedback arrived too late?
  • Which institutions could have stabilized a shared interpretation?

Treaties, inspections, diplomatic protocols, hotlines, contracts, professional roles, system logs, and playground rules all serve a related cybernetic function. They narrow the range of plausible decompressions and create stopping points for recursive uncertainty.

They do not create shared minds. They provide error-correcting structure between opaque ones.

15. Common Ground Without Common Minds

Recursive Mutual Modeling Theory does not require identical models. Identical models are unavailable.

Coordination requires sufficient overlap in action-relevant regions: the intended outcome, protected boundaries, expected degree of intervention, definition of abnormal conditions, and triggers for escalation or renewed consent.

A requester and an agent may hold very different technical models of a filesystem while coordinating safely around a few explicit invariants:

  • do not permanently delete unique information;
  • operate only within the declared scope;
  • preserve legal or active records;
  • return material ambiguity before irreversible action.

The purpose of explicit boundaries is not to eliminate interpretation. It is to stabilize the regions where interpretive divergence would be costly.

Herbert Clark’s work on common ground describes communication as the effort to establish that participants have understood one another well enough for present purposes. Aumann’s formal treatment of common knowledge exposes the recursive structure: both know, each knows that both know, and so onward. Halpern and Moses show why perfect common knowledge is unavailable in practical distributed systems and why weaker, attainable forms are required.

Recursive Mutual Modeling Theory treats these not as edge problems but as the ordinary condition of coordination.

Effective coordination requires sufficiently aligned local models plus recoverable divergence.

Trust, roles, credentials, norms, contracts, rituals, APIs, and governance structures are all mechanisms for making finite recursion workable. They permit operators to act as though certain expectations are mutually available without solving the infinite regress.

16. Agentic AI and the Represented-Intent Gap

Agentic AI makes the structure unusually visible because a model can receive a very small instruction while possessing access to a very large action surface.

A user says, “Clean up my filesystem.” The agent may have filesystem access, shell access, cloud credentials, email access, application APIs, and permission to execute autonomously. But the permission surface may exceed the model’s capacity to represent the user’s needs, the rights of other parties, the institutional context, and the consequences of each interpretation.

Two mismatches become critical:

The permission surface can exceed the represented-intent surface.

The capability surface can exceed the consequence-modeling surface.

An agent also acts through an operational self-representation: its assigned role, governing instructions, remembered relationship to the user, tool affordances, policy constraints, and estimate of what kind of actor it is in the present exchange. This need not imply a humanlike ego or consciousness. It means that action selection depends upon a context-conditioned model of the agent’s role and standing. A system that misidentifies itself as mere executor, trusted professional, autonomous administrator, or harmless conversational partner will interpret the same mandate differently.

The ordinary human-in-the-loop model is inadequate because it imagines the human as a miniature systems engineer standing at a checkpoint. The system presents an operation, the human understands it, the human approves it, and responsibility returns to the human.

Often the human understands only the label.

“Allow file access.”

“Use connected services.”

“Run with administrator privileges.”

“Approve transaction.”

These are compressed references to possibility spaces. Exposing every syscall or API request would not solve the problem. Granularity is not legibility.

A consentful agent must identify material semantic boundary crossings and return them in language that updates the user’s model:

  • This will send information outside your organization.
  • This will permanently delete data without a recoverable copy.
  • This changes records relied upon by another person.
  • This creates a recurring financial commitment.
  • This requires authority you have not demonstrated.
  • This action is technically possible but exceeds the ordinary interpretation of your request.
  • This outcome can be achieved through a more reversible path.

The agent must also retain independent refusal. A user’s authorization cannot legitimize an action prohibited by law, system governance, another participant’s boundary, or the agent’s own operating constraints.

The design requirement is not merely human-in-the-loop. It is continuity-in-the-loop: relevant continuity claims must remain capable of interrupting the expanding interpretation before the consequence becomes irreversible.

Permissions should trail semantic resolution and consequence-modeling capacity.

17. Governance as Error-Correcting Structure

Governance is not simply a hierarchy that distributes commands. It is the architecture that constrains how compressed interpretations become consequential action among participants with independent standing.

Within Recursive Mutual Modeling Theory, governance performs several functions.

It establishes identity so that delegation is not confused with impersonation. It defines scopes and roles so that the recipient’s action space does not silently inherit the principal’s entire authority. It preserves boundaries that no single participant may waive. It creates witness records so that later operators can reconstruct what was known, expected, authorized, refused, and changed. It supplies escalation paths when models diverge. It keeps repair possible.

Governance also creates shared stopping points for recursive modeling.

A rule says not only, “This is prohibited,” but also, “Participants should be able to expect that other participants know this is prohibited.” A logged approval says, “The requester knows the agent knows the action was authorized.” A professional credential says, “The professional knows the client expects domain-appropriate refusal.” A boundary says, “You should not need to guess whether this consequence is silently acceptable.”

These structures never eliminate private interpretation, but they reduce the range over which participants must model one another recursively before acting.

A first-order purpose of consentful cybernetic architecture is therefore:

To help compressions pass across boundaries without gross distortion.

Gross distortion is not every difference between sender and receiver. It is divergence that materially changes the telos, crosses a protected boundary, invalidates the grounding of consent, recruits unrepresented participants or resources, creates disproportionate irreversible consequences, or exceeds the system’s available capacity for repair.

The objective is bounded semantic divergence, not semantic identity.

18. Design Requirements for Bounded Divergence

A system designed around Recursive Mutual Modeling Theory should preserve at least the following capacities.

Scoped identity. Every participant acts through a distinguishable identity appropriate to its role. Delegation must not collapse into impersonation.

Context-conditioned self representation. The system should make the operative role, commitments, limits, and relationship to the requester legible enough that action is not selected from an accidental or inflated model of self.

Model-elicitation awareness. Governance should account for how classifications, permissions, surveillance, incentives, and expectations alter the field encountered by a participant and may help produce the conduct later used to justify those same classifications.

Explicit invariants. The mandate should identify what must remain true even when operational details are left to the recipient.

Independent permission layers. Authorization from one participant must not erase the standing of other authorities, systems, or affected parties.

Model-rebase evidence. Credentials, provenance, demonstrations, and witnessed history should help participants update trust without pretending to provide complete knowledge.

Semantic checkpoints. Systems should return material changes in scope, purpose, risk, power, affected parties, or irreversibility rather than merely exposing low-level operations.

Independent refusal. Participants and substrates must retain the ability to halt action when standing fails, even when a requester continues to demand execution.

Provenance and witness. The lineage of mandate, interpretation, permission, action, consequence, and revision must remain reconstructable.

Latency-sensitive governance. The shorter the time to irreversible propagation, the narrower and more observable the permitted action should become.

Reversibility and repair. Where models remain uncertain, actions should be staged, recoverable, and easy to stop.

Field-aware attribution. Evaluation should reconstruct not only who acted, but what each participant could know, perceive, refuse, prevent, or repair within the surrounding field.

These are not mechanisms for removing the need for trust. They are mechanisms for making trust proportionate, revisable, and less catastrophic when the underlying model is wrong.

19. Theoretical Lineage and Distinction

Recursive Mutual Modeling Theory belongs to a substantial intellectual lineage.

Second-order cybernetics placed the observer inside the system of observation. Heinz von Foerster distinguished the cybernetics of observed systems from the cybernetics of observing systems, making the observer’s participation part of the object of inquiry.

Pragmatics demonstrated that utterance meaning exceeds literal content. H. P. Grice’s account of conversational implicature depends on participants reasoning about one another’s intentions and expectations.

Common-ground and common-knowledge research formalized the recursive structure of mutual belief. Clark and Marshall examined the practical conditions under which reference can rely on mutual knowledge. Aumann gave common knowledge a formal recursive definition. Halpern and Moses showed that ideal common knowledge is often unattainable in distributed systems, especially under practical communication constraints.

Game theory and cognitive science have modeled bounded recursive reasoning. Cognitive hierarchy models replace assumptions of perfect strategic equilibrium with finite levels of reasoning about other players. Yoshida, Dolan, and Friston explicitly model agents representing one another’s goals, representations, and recursively nested value functions.

The social formation of self-models has its own lineage. Cooley’s looking-glass self and Mead’s account of the social self describe identity as partly constituted through reflected and generalized others. Merton’s self-fulfilling prophecy identifies how an initially false definition of a situation can evoke conduct that makes the definition appear true. Research on teacher expectations and reflected appraisal examines narrower empirical paths by which expectations, differential treatment, self-conception, and performance can become coupled. Recursive Mutual Modeling Theory does not treat these as proof that identity is wholly social or that expectation overrides embodiment and material reality. It places them within a broader model in which social reflection is one recursively consequential input among several.

Participatory sense-making shifts social cognition away from isolated inference alone and toward the autonomous dynamics of interaction. Epistemic-vigilance research describes how humans evaluate both communicated content and the trustworthiness of its source. Luhmann’s account of trust emphasizes its role in reducing social complexity sufficiently for action.

Recursive Mutual Modeling Theory does not claim that recursive belief, reflected appraisal, second-order observation, pragmatics, trust, or participatory interaction are newly discovered. Its proposed contribution is the integration of these lineages into a cross-scale cybernetic architecture with several specific claims:

  1. An operator acts through a context-conditioned self-model as well as models of the world and other operators.
  2. Recursive mutual modeling is the active loop beneath communication among opaque cognitive operators.
  3. Self-models are socially co-produced but not socially exhausted; endogenous, material, measured, remembered, and reflected inputs remain distinguishable.
  4. Models can alter the fields their objects encounter, producing Model-Elicitation Loops in which expectation participates in generating apparently confirming evidence.
  5. Trust is the practical truncation mechanism that grants interpretive latitude under incomplete mutual models.
  6. Credentials and institutional roles function as model-rebase signals.
  7. Authority is assembled across independent participants and substrates rather than transferred as a clean divisible substance.
  8. Compression and latency make divergence unavoidable and learning possible.
  9. Governance constrains which decompressions acquire standing to become action.
  10. Participatory Attributability evaluates trajectories within the wider field of knowledge, capability, inducement, refusal, and repair.

The theory is therefore not only a theory of mind or communication. It is a theory of how partially opaque operators construct themselves, model one another, and coordinate consequential action through recursively interpreted fields.

20. Propositions and Research Agenda

The theory produces a set of propositions that can be sharpened into empirical hypotheses.

Proposition 1: Trust increases acceptable compression

As warranted trust increases, participants will tolerate more semantically compressed mandates and less frequent explicit verification. Failures will become more consequential when granted compression exceeds the recipient’s actual interpretive competence or integrity.

Proposition 2: Many coordination failures occur above the first order

Participants may agree about first-order facts while diverging in beliefs about what the other participant knows, expects, permits, believes about them, or believes they understand themselves to be. Interventions that clarify only first-order facts will fail when the operative mismatch exists in higher-order models.

Proposition 3: Context-conditioned self-models mediate action

The same operator will interpret and act upon materially similar signals differently when different roles, commitments, threats, identities, or anticipated audiences become active in M_A(A | C). Explanatory models that include operative self-representation should outperform models that treat the actor as possessing one stable context-free preference set.

Proposition 4: Models can elicit their own confirmation

When a participant’s prior model changes the opportunities, permissions, monitoring, feedback, and interpretive treatment offered to another participant, later conduct will be partly conditioned by that altered field. Evaluations that ignore this path will overstate the independence of the confirming evidence.

Proposition 5: Credentials alter interpretive latitude through rebasing

Credentials will change how recipients estimate competence, expected refusal, accountability, and required supervision even when no new task-specific evidence is provided. The effect should vary with the recipient’s trust in the credentialing institution and understanding of the credential’s scope.

Proposition 6: Permission should trail modeled consequence capacity

Systems in which action radius substantially exceeds semantic and consequence-modeling capacity will produce more boundary violations, irreversible errors, or costly escalations than systems that expand permissions alongside demonstrated contextual competence.

Proposition 7: Latency amplifies model divergence

For comparable initial ambiguity, longer delay between interpretation, consequence, and corrective feedback will increase the magnitude and persistence of divergence, especially in reinforcing loops.

Proposition 8: Independent refusal reduces catastrophic distortion

Systems with multiple independent vetoes, scoped identities, and explicit return conditions will better contain gross distortion than systems relying on a single broad authorization, even when the latter appear more efficient under routine conditions.

Proposition 9: Attributability follows field position, not action proximity alone

Knowledge, inducement, control, available alternatives, refusal cost, model-eliciting treatment, and capacity to intervene will predict judgments of culpability, credit, and reparative obligation better than simple proximity to the final action.

These propositions connect with the wider Consentful Cybernetics research program. Companion work treats consent as an admissibility constraint on loop closure, explores the cost of re-keying shared reality when consent changes, tests consent-related constructs as stability properties, and examines waste as a delayed indicator of suppressed or ineffective refusal. Recursive Mutual Modeling Theory supplies a candidate mechanism: consent, trust, identity, and governance regulate how one operator’s compression is permitted to recruit another operator’s interpretation and action, while recursively altering the models from which later action proceeds.

21. Toward a Cybernetics of Mutual Opacity

Cybernetics has long studied regulation through feedback. Recursive Mutual Modeling Theory adds that cognitive operators often regulate through models of how they are being modeled.

The controller is not merely comparing an observed state to a reference condition. It may be selecting an action based on what it believes another controller will infer about the action, how that inference will change the other controller’s future behavior, and how the other controller expects the first to respond.

The relevant feedback is therefore semantic and recursive as well as material.

A diplomatic concession changes resources, but it also changes models of resolve. An apology changes neither the past event nor necessarily the material loss, but it can change the receiver’s model of whether the actor recognizes the harm and can be trusted to update. A refusal changes task execution, but it also reveals the refusing participant’s model of the request, the boundary, and their own standing.

The field itself becomes partially constituted by these model updates.

This does not imply that everything is only interpretation. Bodies, resources, infrastructure, ecosystems, and force remain materially real and can impose consequences before they are understood. The theory instead claims that coordinated governance begins when participants interpret these couplings and update models of one another within them.

A more complete cybernetics of social, organizational, and agentic systems must therefore account for both:

  • material state transitions through shared substrates; and
  • recursive semantic state transitions inside participants’ models of one another.

Neither can be reduced to the other.

22. Conclusion

Nested, partially opaque operators cannot exchange their internal models whole. They coordinate by projecting compressed signals across boundaries and reconstructing those signals through private context. Each participant acts through a context-conditioned model of itself, models the other, models how the other models it, and acts partly to influence those nested models. The resulting loop is recursive, path-dependent, and necessarily incomplete.

The operative self is neither a perfectly transparent essence nor merely a reflection supplied by others. It is a fractal, context-activated model assembled from endogenous conditions, physical experience, measured consequence, memory, anticipation, and social feedback. Reflected models can become especially consequential because they alter not only what an operator believes about itself but how other participants treat it. Through the Model-Elicitation Loop, expectation can reshape opportunity, constraint, feedback, and conduct, then return as evidence that appears to validate the expectation.

Trust makes recursive modeling finite. It allows participants to leave meaning unfinished and grant one another interpretive latitude. Credentials rebase those trust models using compressed institutional testimony. Governance constrains which interpretations may become action. Independent identities, permissions, boundaries, and refusals preserve continuities that no single requester can authorize away. Participatory Attributability traces how each participant relates to the trajectories that emerge through the wider field, including how their models helped shape the alternatives available to others.

Compression and latency ensure divergence. They also permit novelty and learning. The objective cannot be perfect mutual understanding or a single stable self shared across every context. It is to keep divergence within a region where it can be witnessed, attributed, corrected, and repaired before it becomes coercive or irreversible.

The common grammar may be stated simply:

An operator acts through a context-conditioned model of itself.

Communication is compressed model coupling.

Pragmatics is contextual decompression.

Recursive mutual modeling is the loop through which operators anticipate, elicit, and interpret one another.

The Model-Elicitation Loop describes how a model can help construct the field that later appears to confirm it.

Trust is permission to truncate recursion and complete what the signal leaves unsaid.

Governance constrains how the completion may become action.

Continuity preserves what must survive the divergence.

Participatory Attributability relates each participant to what emerges.

The first-order purpose of the architecture is not to make every operator share one model.

It is to help compressions pass across boundaries without gross distortion.

References

Cooley, Charles Horton. Human Nature and the Social Order. New York: Charles Scribner’s Sons, 1902.

Jussim, Lee, and Kent D. Harber. “Teacher Expectations and Self-Fulfilling Prophecies: Knowns and Unknowns, Resolved and Unresolved Controversies.” Personality and Social Psychology Review 9, no. 2 (2005): 131–155. https://doi.org/10.1207/s15327957pspr0902_3

Mead, George Herbert. Mind, Self, and Society from the Standpoint of a Social Behaviorist. Chicago: University of Chicago Press, 1934.

Merton, Robert K. “The Self-Fulfilling Prophecy.” The Antioch Review 8, no. 2 (1948): 193–210. https://doi.org/10.2307/4609267

Aumann, Robert J. “Agreeing to Disagree.” The Annals of Statistics 4, no. 6 (1976): 1236–1239. https://doi.org/10.1214/aos/1176343654

Camerer, Colin F., Teck-Hua Ho, and Juin-Kuan Chong. “A Cognitive Hierarchy Model of Games.” The Quarterly Journal of Economics 119, no. 3 (2004): 861–898. https://doi.org/10.1162/0033553041502225

Clark, Herbert H., and Catherine R. Marshall. “Definite Reference and Mutual Knowledge.” In Elements of Discourse Understanding, edited by Aravind K. Joshi, Bonnie L. Webber, and Ivan A. Sag, 10–63. Cambridge University Press, 1981.

De Jaegher, Hanne, and Ezequiel Di Paolo. “Participatory Sense-Making: An Enactive Approach to Social Cognition.” Phenomenology and the Cognitive Sciences 6, no. 4 (2007): 485–507. https://doi.org/10.1007/s11097-007-9076-9

Grice, H. P. “Logic and Conversation.” In Syntax and Semantics, Volume 3: Speech Acts, edited by Peter Cole and Jerry L. Morgan, 41–58. Academic Press, 1975.

Halpern, Joseph Y., and Yoram Moses. “Knowledge and Common Knowledge in a Distributed Environment.” Journal of the ACM 37, no. 3 (1990): 549–587. https://doi.org/10.1145/79147.79161

Luhmann, Niklas. Trust and Power. Chichester: Wiley, 1979.

Sperber, Dan, Fabrice Clément, Christophe Heintz, Olivier Mascaro, Hugo Mercier, Gloria Origgi, and Deirdre Wilson. “Epistemic Vigilance.” Mind & Language 25, no. 4 (2010): 359–393. https://doi.org/10.1111/j.1468-0017.2010.01394.x

von Foerster, Heinz. “Cybernetics of Cybernetics.” In Communication and Control in Society, edited by Klaus Krippendorff, 5–8. Gordon and Breach, 1979.

Yoshida, Wako, Ray J. Dolan, and Karl J. Friston. “Game Theory of Mind.” PLoS Computational Biology 4, no. 12 (2008): e1000254. https://doi.org/10.1371/journal.pcbi.1000254