TOPIC 40 · PHASE G

Intervening in Complex Systems

Good intentions are not a reason; the place is

2026-08-27 · Fragility, Resilience & Early Warning

There is a finding that keeps turning up in systems work: people usually locate the right place to push, and then push it in the wrong direction. Failing to find the leverage point is not the main failure mode. Finding it and reversing the sign is.

Hanoi, 1902. Plague was closing in, and the French colonial administration decided to kill every rat in the city. The method was blunt: bring in a rat tail, collect a few cents. The first days brought a few hundred. Soon it was seven thousand a day, then fourteen thousand; on the worst day for Hanoi's rodents, more than twenty thousand tails were reported.

Three months in, officials discovered two things. On the city's edge, households were breeding rats, cutting off the tails for the bounty and releasing the tailless animals to breed again — and there was a smuggling route bringing rats into Hanoi from the surrounding province. They wanted fewer rats. What they bought was tails. The system supplied, in full, exactly the thing they had priced.

This is not a story about stupidity. The bounty was a perfectly reasonable policy, and it failed for reasons that have nothing to do with diligence, ethics or intelligence. It failed because of where it pushed: too shallow, while the system had its own moves available at a deeper place. This issue is about place — when you intervene in a system that answers back, which places are available to push, how far apart their effects are, and how to design the push given that you will almost certainly get it wrong.

How this sits with earlier issues: Topic 6 covered the structure of feedback loops; Topic 26 covered the fact that adaptive agents learn your model once you publish it; Topics 38 and 39 covered how to build yourself to take a hit. This issue closes out the phase by converting all of it into one question: when it is your turn to act, where does the hand go?

01The system eats your intervention(Policy Resistance)

First, how the eating actually happens.

A quantity in a complex system usually sits at its current value not because nobody is managing it, but because several forces are pulling it in different directions and currently balance. The rat population of a city sits where it sits because food, shelter, predators, disease and human clearance are holding each other off. Add a force from outside and the others do not stand still: each one's strength already depends on the current state, so when the state moves, they move.

Systems researchers call this policy resistance, and the mechanism underneath it is compensating feedback: your push activates a balancing loop that was previously dormant, the loop drags the system back toward where it was, and you keep paying to push. → ref · System Dynamics (Stocks & Flows)

Hanoi is one notch worse than that. The bounty did not merely meet resistance; it created an inflow that had not existed before. Rats went from being a thing to be removed to being a thing that could be produced. That step is specific to complex systems: the objects of your intervention include agents who do arithmetic, and they will go find the price you just posted.

One policy, two different chains ① The chain you drew Bounty: cents per rat tail Tails turned in soar Fewer rats ② The chain the system ran Bounty: cents per rat tail Tails turned in soar ← the number you watch Breeding · docking · smuggling in More rats overall The indicator moved, the goal reversed — the intervention posted a new price
The failure was not poor execution. Execution was excellent: the system supplied the thing that had been priced.

There is a test you can take away immediately. When your intervention lands on an indicator, and human behaviour sits between that indicator and the goal you actually want, the indicator will move first — and may be the only thing that moves. The difference is not between good people and bad people: the rat farmers and the tail collectors in Hanoi were the same people, taking the cheapest path across the terrain you had just redrawn.

A correction on the better-known version of this. The phenomenon is usually called the "cobra effect", after the German economist Horst Siebert's 2001 book of that name, which tells of a British bounty on dead cobras in Delhi and the cobra farms that followed. No archival evidence for that story has ever been found, and it is very likely a later invention. The Hanoi tail bounty, by contrast, is documented in the colonial files — the historian Michael Vann found it in a dossier marked "Destruction of Hazardous Animals". Keep the name if you like; swap the example for the one with a paper trail.

🎯 DECISION LINE

Before launching any intervention, write down two sentences. First: "If this works, which specific number moves in three months?" Second: "Where will the system get it back from?" If you cannot answer the second, it is not because there is no answer — it is because you have not looked. Do not push until you have. Otherwise you will see either the indicator move while the goal does not, or the goal move and then return, and you will already have paid.

🌀 Engineering & technology history · Add a road, everyone gets slower In 1968 Dietrich Braess proved something perverse — what is now called Braess's paradox: adding a road to a congested network can make the commute longer for every single driver. The reason is exactly Hanoi's — the new road changes each person's best choice, everyone reroutes rationally, and the whole settles into a worse equilibrium. The converse holds too: when New York closed 42nd Street for Earth Day in 1990, traffic flowed better; when Seoul tore down the Cheonggyecheon elevated freeway in 2003, travel times did not deteriorate. The unnatural conclusion for planning is this: you cannot appraise a new road by asking how many cars it can carry — you have to ask who it will pull off other roads. The first is an engineering quantity, the second is the solution of a game, and they can point opposite ways.

02Twelve places, orders of magnitude apart(Twelve Leverage Points)

If pushing the wrong way is the norm, you first need a map of where the places are.

The person who drew that map was Donella Meadows, one of the principal authors of The Limits to Growth. In 1997 she was sitting in a meeting about the North American Free Trade Agreement, listening to a room argue about tariff rates, when it struck her that everyone was arguing at one single level — and that level determines almost nothing. Afterwards she wrote a list: leverage points, twelve places in a system where you can push, ordered from least useful to most.

Twelve places to push — higher is stronger, and harder to move POWER ↑ RESISTANCE ↑ 1 Transcending paradigms: holding no mental model as final 2 The paradigm: assumptions the whole system rests on 3 Goals: what the system is actually running for change the goal = a different system 4 Self-organisation: power to change its own structure 5 Rules: incentives, punishments, constraints — and defaults 6 Information flows: who can see what, and who cannot 7 Gain around reinforcing loops: how fast the snowball rolls 8 Strength of balancing loops, relative to the error they correct 9 Delays, relative to the rate of system change 10 Structure of stocks and flows: how the pipes are connected 11 Sizes of buffers, relative to the flows through them 12 Constants, parameters, numbers: subsidies, taxes, standards most pushed · least effect Most meetings, most budgets and most arguments happen in the bottom two rows. Meadows' own caveat: the ranking is a heuristic, not a theorem — it says where to look first.
Proposed in 1997, expanded into a standalone paper in 1999. The numbering is hers: 12 weakest, 1 strongest.

The part worth chewing on is not the ranking itself but the mismatch it exposes: effectiveness and resistance run in the same direction. The easiest place to move — a number — barely changes behaviour, because behaviour is produced by structure and the number is just a blank being filled in. The place that does change behaviour — goals, paradigms — is precisely what everyone defends hardest. So a rational organisation drifts, all by itself, into spending everything in the bottom two rows. That is not laziness; it is the path of least resistance.

Here is an example that makes the difference between levels visible. To raise organ donation rates, the level-12 move is more advertising and more subsidy. The level-5 move is the tick-box default on the form: is it "not a donor unless you tick", or "a donor unless you tick"? Johnson and Goldstein compared European countries in Science in 2003. Countries with the first default had registered consent in the single digits to the low twenties per cent; countries with the second were close to 100%. Same people, same values, same piece of paper — one default value apart, and tens of percentage points of difference.

Notice what is easy to miss here: the advertising budget can be increased without limit, and no amount of it produces that gap. The force was not insufficient; the place was wrong. Which is also why "try harder" is so often a completely inert piece of advice in a complex system.

🎯 DECISION LINE

Take every intervention you are running or about to run and label it with a level number. If nine tenths of a year's actions sit at levels 12 and 11 — tuning numbers, adding buffers — that is not an execution problem, it is a year spent pushing where the resistance is lowest. Then do one thing: pick an action at level 6 (information flows) — take a number that someone currently cannot see and make it a number they see every day. That level is usually the best value on the whole list, because it is easier to move than rules and far more effective than parameters.

🌀 Economics & institutions · A default is a piece of legislation Push the donation example to its limit and you get something faintly alarming: in any institution that runs on forms, whoever sets the default values holds more power than whoever argues about the wording of the clauses. Pension auto-enrolment, the initial state of a privacy setting, the pre-ticked box in an installer — none of these are details; they are level-5 actions, while nearly all public debate about those institutions happens at level 12. The corollary applies to the debate itself: if an argument is entirely about a numeric value, then whoever wins it, the system's behaviour will most likely be unchanged.

03Do you have enough hands?(Requisite Variety)

Finding the place is not sufficient. There is a harder constraint, and it has nothing to do with how clever you are — only with counting.

In 1956 the British psychiatrist and cyberneticist W. Ross Ashby stated a law in An Introduction to Cybernetics — the law of requisite variety — in wording short enough to pass for a proverb: only variety can destroy variety. → ref · Cybernetics and Its Lineage

"Variety" here is countable: the number of distinct states a thing can take. The weather's variety is how many different ways it can be; your variety is how many genuinely different responses you can produce. The law says: how far you can compress the outcomes depends on the number of distinct responses you have. When your hands are fewer than the situations, the remainder leaks through, and effort does not enter the calculation.

Count it and it is obvious. Suppose there are 8 situations you must handle and you can produce 3 distinct responses. Those 3 responses partition the 8 situations into at most 3 classes; different situations inside one class receive the same action, so their outcomes still differ. The number of distinct outcomes is therefore at least 8 ÷ 3, rounded up — 3. You can squeeze 8 outcomes down to 3. You cannot squeeze them into 1.

8 situations, 3 responses situations you have to handle 1 2 3 4 5 6 7 8 response A response B response C outcome Ⅰ outcome Ⅱ outcome Ⅲ number of outcomes ≥ number of situations ÷ number of responses
8 ÷ 3 rounds up to 3. You can compress the outcomes to three; you cannot compress them to one — and that step is arithmetic, not effort.

The law earns its keep by turning a vague kind of frustration into a number you can compute. When someone repeatedly "cannot get a grip" on something, the usual diagnosis is willpower, competence, focus. Ashby's diagnosis is not enough kinds of response — and the three exits are exhaustive: add distinct responses; reduce the number of situations you face (block some at the door, or standardise them); or openly declare which outcomes you do not guarantee. The third sounds like surrender and is in fact the only honest way to downgrade — at minimum it tells other people where else to go for cover.

🎯 DECISION LINE

Take something you have chronically "failed to control" and do the count: list the distinct situations that actually occurred last month, and count them; then list the distinct responses you actually produced, and count those. If the second number is clearly smaller, stop adding effort — effort only performs the same response harder, and the law constrains kinds, not intensity. Pick one of the three exits: add response types, cut the scope you accept responsibility for, or state plainly which part you do not guarantee.

🌀 Biology · The immune system does not memorise answers Pathogens come in more kinds than can be listed, and the genome cannot store a ready-made antibody for each. The immune system's solution is not to store more answers but to store a rule for generating answers on the spot — randomly recombining gene segments into a receptor repertoire of enormous size, then amplifying whichever receptor meets an antigen. That architecture is exactly what Ashby's law forces: when the kinds of situation far exceed what you can enumerate, the correct move is not a longer checklist but a machine that manufactures new responses. The corollary is usable anywhere the contingency plans cannot be finished — when they cannot, what needs changing is how plans get generated, not how many there are.

04If you cannot pick the right one, pick the one you can undo(Reversibility First)

Put the first three sections side by side and you land somewhere uncomfortable.

The system eats your intervention; you are probably pushing at the least useful level; and your hands are fewer than the situations. Add what Topic 11 established — that for some systems there is, in principle, no shortcut to computing the behaviour — and the standard procedure ("work out which option is right, then execute") turns out to be unrunnable. It presupposes a judgement you have just been told you cannot make.

So change the criterion. Since "which is more right?" cannot be answered in advance, ask something that can be: which option can be undone if it turns out wrong? That question requires no prediction of the system's response — only an inventory of your own exits, and exits can be counted.

In engineering and ecosystem management this goes by one name: safe-to-fail. It does not aim to get this step right; it requires that getting it wrong is bounded in loss and productive in information. It is the opposite of fail-safe design, which assumes you already know what to guard against.

Same budget, two ways to spend it ① all in, once the option that looks best a one-way door wrong: no way back the only move left is to raise the bet ② small probes · safe-to-fail four small options in parallel scale this one up three failures cost one small step in total The left buys a chance of being right; the right buys the certainty of still being here.
The right-hand column usually looks worse on an expected-value ledger — because that ledger puts no price on still being in the game.

Making the criterion operational takes three extra columns next to each option: how long to undo, how much it costs to undo, whose sign-off undoing requires. Options where all three can be filled in are reversible doors. Any option with a blank column should be treated as a one-way door — which does not mean never walking through it, but means walking slower, smaller, and having said out loud in advance what you will live on once you are through.

🎯 DECISION LINE

Make the first question at any design review not "which is better?" but "which one can be undone if it is wrong — how long, how much, whose sign-off?" When expected returns are close, take the reversible one. When the irreversible one has a clearly higher return, shrink it and run it once at small scale until it becomes reversible, then talk. This rule will always look costly on an expected-value ledger: what it buys is not return, it is the right to keep sitting at the table.

🌀 Art & letters · The conservator's rule of reversibility Modern heritage conservation carries a strange rule: material added in a repair must be removable, and the added part must be visibly distinguishable as an addition (the 1964 Venice Charter, Article 12, requires that replacements of missing parts be distinguishable from the original). What is strange is that it explicitly refuses to choose the best available repair — the strongest adhesive is very often the least reversible one. The conclusion this forces: when you do not know what later generations will know, "optimal" has no definition, and the criterion has to become "can this be undone?" It also explains why that profession treats an invisible repair as a defect rather than an achievement — invisible means you have erased the possibility of anyone correcting you later.

05Where this account breaks down(Where This Breaks Down)

All four sections above are useful, and being useful is exactly why they get overextended. Boundaries, one at a time.

The leverage-point list is not a theory; it is a list. Meadows was explicit that the ordering came from experience and intuition rather than being derived from any model, and she invited readers to argue with it. It provides no operational rule telling you which level an action belongs to — the same act, re-described, moves from level 12 to level 5. This produces its characteristic misuse: after the fact, successful interventions get called high-leverage and failed ones low-leverage, so the list is always right and never predictive. There is only one defence: write the level down before you act, and write down what should happen in three months if it really is that level.

"Variety" is usually uncountable in the field. The 8-divided-by-3 in section 3 was clean because I enumerated both sets in advance. In a real situation, "how many kinds of case do I face" depends entirely on how you carve them: carve coarsely and it is 3, carve finely and it is 300 — and the law holds for both carvings while giving different conclusions. So treat it as a structural reminder (the number of kinds of response is a constraint independent of effort), not as a calculator. Any claim that computes a precise conclusion from it owes you its carving rule first.

Reversibility-first is not universally optimal, and it is not free. Choosing a second-best option to keep an exit costs real expected value, and over a long run it loses to a rival who always takes the best option — provided that rival survives. Worse, an entire class of interventions is indivisible by nature: a dam, a constitution, a mass vaccination campaign, a surgical procedure. You cannot build a quarter of a dam as a trial. For that class, this issue does not say "don't" — it says shift the effort into making every step before the irreversible one reversible, and into agreeing in advance who declares failure, and when.

And the one most often skipped: doing nothing is also an intervention. "Complex systems are hard to intervene in" is regularly read as "so don't touch it", but holding still changes the system too — it lets the currently dominant loop keep running. Every criterion above has to be applied symmetrically to the do-nothing option: it has a level number, it has an exit cost, and if it is wrong it may not be undoable either. Treating caution as the default answer is the easiest mistake in this issue to make and the hardest to notice, because it always looks like the more sober choice.

🎒 Scenario · BigCat

  1. Teams & organisationsSomething breaks in production, the post-mortem is held, and the output is "everyone please be careful" plus one more line on the checklist. Three months later the checklist has grown a dozen lines and nobody reads it through. This is not an attitude problem — adding a line to a checklist sits at the very bottom of the leverage table and is also the lowest-resistance move there, so it gets selected automatically every time. The concrete change: make the post-mortem's output not "one new check" but the answers to two questions — who noticed something was wrong first, at what time, and how long did that information take to reach someone who could make a call. Those two answers live at the information-flow level; changing them is harder than adding a check, and it changes whether next time is twenty minutes earlier. Stop doing: letting a post-mortem close on "we added a rule."
  2. Practice & mindYou decide to break a habit — say, half an hour of scrolling after you have already lain down — so you set a rule, set an alarm, tell someone. Ten days later you are back, and you explain it as insufficient discipline. By the counting method in section 3, the problem is more likely kinds than intensity: the occasions that break you actually fall into several classes — too tired to move, still churning after an argument, plain boredom, waiting for the result of something — and you prepared exactly one response (grit). The concrete change: write down the times you actually broke last week, sorted by trigger, and give each class its own different substitute action — one response per kind of trigger. Stop doing: reading a relapse as a moral fact. That is a counting result being received as a verdict on yourself.
  3. Health & energyYou feel persistently off, so you start four things at once: earlier nights, no coffee, more exercise, different diet. Two weeks later — better or not — you cannot tell which one did it, and you cannot withdraw just one of them. The concrete change: move one thing at a time, and move the one you can take back immediately first (coffee can be reinstated any day; sleep debt and injury cannot). At the same time, replace the vague "how I feel" with one specific number readable within seven to ten days — for instance, rate your alertness at three in the afternoon from 1 to 5. Stop doing: changing several variables together and then holding a review about which one worked. That review is structurally incapable of producing an answer.

🌀 Crossing Over · Interdisciplinary Echoes

🤔 Going Deeper

Why should effectiveness and resistance run in the same direction?

One conjecture: the things that can be changed easily are easy precisely because changing them does not threaten the system's persistence, so no protective mechanism ever evolved around them. Conversely, goals and paradigms are defended fiercely because changing them makes the system a different system — the strength of the guard is itself evidence that this is the vital spot. If the conjecture holds, resistance becomes a detector for leverage: the more violently someone reacts to your proposal, the closer you are to a high leverage point. That corollary is suspiciously convenient — it could equally be a way of repackaging "annoying people" as "having insight". Telling those two apart is a real problem.

Why is the third exit from Ashby's law — declaring what you do not guarantee — so hard to say out loud?

Technically it is the most honest way to downgrade; organisationally it is often the most expensive sentence available. A possible reason: the other two exits (add capability, cut scope) both look like solving the problem, whereas this one looks like shirking, even though it is the only one that conceals no constraint. There may be something more general hiding here — when a constraint is mathematical rather than moral, people still receive it morally.

Taken to its limit, does reversibility-first become never deciding at all?

Yes. That is this rule's most realistic failure mode: any option can be asked to become smaller and more reversible, so intervention is deferred indefinitely while inaction keeps changing the system. One possible fix is to attach an expiry to reversibility — not "is this reversible?" but "before what date is it reversible, and after which it is not?" That turns "when must this be decided" into a quantity rather than a matter of temperament.

If the thing being intervened in can read this method, does the method still work?

Topic 26 covered this: agents in complex adaptive systems learn, and publishing a model changes the thing modelled. Once the leverage-point list is public, defenders will use the same list to position their defences, and high leverage points get guarded harder. Interestingly, this need not invalidate the list — it might make the "resistance" signal more reliable. But the opposite is also available: both sides know level 5 matters, so the fight over default values becomes as fierce and as deadlocked as the fight over tax rates was. Which of these two futures happens is not something this issue's mechanisms can answer.

Further Reading