← Back to list

The World War That Nobody Wanted

The First World War is usually explained by asking what people wanted. Historians have spent a century sorting the guilty from the merely…

Peter Kriger · 2026-07-26 01:07 · 14 claps · 234.8 min read
#history #world-war
Open on Medium ↗
Wiki topics: HIS · History

The World War That Nobody Wanted

The First World War is usually explained by asking what people wanted. Historians have spent a century sorting the guilty from the merely reckless, and the argument has produced magnificent scholarship without producing agreement. This book asks a different question. Not what the men of 1914 wanted, but how long they had.

Every government runs on two clocks. One measures how long it takes to turn information into a decision that carries authority: to decipher the telegram, to find the minister, to convene the council, to obtain the signature. The other measures how long remains before somebody else does something that cannot be undone. The difference between them is a reserve, and when that reserve runs out, nobody decides anything. Everyone simply executes the plan they prepared earlier, and the plans, having been written separately, produce together a result that appears in none of them.

In the last week of July 1914, that reserve went negative across an entire continent. The Kaiser’s considered judgment that there was no longer any reason for war reached Vienna after Vienna had declared it. Ultimatums that had begun by granting forty-eight hours were granting twelve. Nobody was asleep. Everybody was late.

The story does not end in 1918. Missile warning gives a president minutes. Cyber attribution takes weeks while retaliation takes hours. Trading algorithms act faster than any meeting can be convened. And the newest machines now compress the time needed to produce an answer without touching the time needed to authorize one, which makes the reserve look healthy at the precise moment it disappears. The financial markets, alone among these domains, have already installed the obvious remedy: a mandatory pause. Everyone else has decided that pauses are for other people.

The book is based on academic paper: Kriger, P. (2026). Latency Collapse: When Available Decision Time Falls Below Required Deliberation Time in Coupled Escalation Networks. IIIR Computational Humanities and Cultural Systems. https://doi.org/10.5281/zenodo.21568121

Keywords: history, First World War, decision-making, complex systems, artificial intelligence, nuclear risk, crisis

[embed]THE WORLD WAR THAT NOBODY WANTED The First World War is usually explained by asking what people wanted. Historians have spent a century sorting the…www.amazon.com

[embed]

Contents

Preface. 6

Chapter One — The Telegram That Arrived Too Late. 15

Chapter Two — Two Clocks. 23

Chapter Three — The Phrase That Was Manufactured. 30

Chapter Four — Everyone Wanted a Different War 36

Chapter Five — Twenty-Five Days and Forty-Eight Hours. 43

Chapter Six — The Cipher Clerk Was Not Asleep. 49

Chapter Seven — What a Default Is. 54

Chapter Eight — The Legation That Packed Its Bags. 60

Chapter Nine — Plans That Cannot Be Executed Together 65

Chapter Ten — The Ratchet 70

Chapter Eleven — Six Steps, Whatever Their Size. 75

Chapter Twelve — War by Timetable and the Man Who Demolished It 79

Chapter Thirteen — The Partial Mobilization That Did Not Exist 84

Chapter Fourteen — Turn the Army East 89

Chapter Fifteen — Halt in Belgrade. 94

Chapter Sixteen — Abilene Has a Road Back. 99

Chapter Seventeen — Why Not Nineteen Eleven. 105

Chapter Eighteen — The Regulation of Nineteen Thirteen. 109

Chapter Nineteen — Survival Is Depletion. 113

Chapter Twenty — Avoidable Everywhere, Inevitable in Aggregate. 118

Chapter Twenty-One — The Four Years Afterward. 122

Chapter Twenty-Two — Thirteen Days, Deliberately Slowed. 126

Chapter Twenty-Three — The Line Moved Outward. 131

Chapter Twenty-Four — The Hotline. 135

Chapter Twenty-Five — Twenty-Six Minutes. 139

Chapter Twenty-Six — The Room Where Nobody Can Be Reached. 143

Chapter Twenty-Seven — The Man Who Did Not Report 147

Chapter Twenty-Eight — Attribution Takes Longer Than Retaliation 151

Chapter Twenty-Nine — Faster Than the Meeting Can Be Called. 156

Chapter Thirty — The Pandemic Clock. 160

Chapter Thirty-One — Apparent Time and Real Time. 164

Chapter Thirty-Two — Machines That Never De-escalate. 169

Chapter Thirty-Three — Circuit Breakers for Everything Else. 173

Conclusion. 178

Case Study One — Able Archer, November 1983. 183

Case Study Two — The Norwegian Rocket, January 1995. 188

Case Study Three — The Faulty Chip and the Training Tape, 1979 and 1980. 193

Case Study Five — The Vincennes and Iran Air 655, July 1988. 202

Case Study Six — Überlingen, July 2002. 207

Case Study Eight — Ten Seconds and a Single Sensor, 2018 and 2019 216

Case Study Nine — Three Mile Island, March 1979. 220

Case Study Ten — Chernobyl, April 1986. 225

Case Study Twelve — Deepwater Horizon, April 2010. 233

Case Study Thirteen — Challenger, January 1986. 237

Case Study Fourteen — The Northeast Blackout, August 2003. 241

Case Study Sixteen — Knight Capital, August 2012. 248

Case Study Seventeen — The Lehman Weekend, September 2008. 252

Case Study Eighteen — NotPetya, June 2017. 256

Case Study Twenty — The Year Two Thousand. 264

Timeline. 289

Literature. 299

Preface

There is a particular kind of book about the summer of 1914, and you have almost certainly read one. It opens with an archduke, a wrong turn, a sandwich that may or may not have existed, and a nineteen-year-old with a pistol. It proceeds through a tangle of alliances drawn as a diagram with arrows, arrives at a moral, and closes with the observation that it all could have been avoided if only somebody had been wiser. The moral varies by nationality of author. The arrows do not.

This is not that book, though it will visit most of the same rooms. The difference is in what it counts. Ordinary histories of the July crisis count intentions: who wanted what, who lied, who blundered, who could have stopped it and chose not to. Those are excellent questions and a century of brilliant people have failed to settle them, which is itself a piece of evidence worth taking seriously. When a question resists that many good minds for that long, the trouble is sometimes not with the answers but with the question.

What this book counts is time. Not the vague time of narrative, the fateful summer and the gathering storm, but the specific and boring kind: how many hours a government needed to decipher a message, locate a minister, assemble a council, obtain a signature, and transmit an order. And against that, how many hours it had before somebody else did something irreversible. Both numbers are recoverable. That is the accident of fortune that makes this book possible.

It is an accident worth explaining, because it is unusual. Most historical crises are documented in a way that permits argument but not measurement. Somebody’s memoir says the mood was tense. Somebody else recalls that the decision came quickly. Historians are obliged to work with this, and they do it superbly, but you cannot put a stopwatch to an impression. The July crisis is different for a reason that has nothing to do with the crisis and everything to do with what happened afterward. When the war ended, the question of who had started it became a matter of treaty law with money attached, and four governments responded by publishing enormous collections of their own diplomatic correspondence. Telegrams carry the hour of dispatch and the hour of receipt. Ultimatums state their own deadlines. Councils record when they met. What was assembled as a legal defense turned out to be, quite by accident, the most precisely timestamped political catastrophe before the invention of the recording device.

So we can do something with 1914 that we cannot easily do with other disasters. We can put a clock on it.

When you do, a shape appears that the intentions literature keeps stepping over. The response times shrink. Vienna took twenty-five days to compose its note to Belgrade and gave Belgrade forty-eight hours to answer it. A week later Berlin was issuing ultimatums with twelve-hour limits. By the fourth of August the intervals had fallen to a length that no government on earth could have used for anything, because deciphering the message and finding the person entitled to answer it took longer than the deadline allowed. The windows kept halving. The machinery for filling them did not get any faster, because it could not. Cipher clerks were already working through the night. The constitution still required the sovereign’s signature. The ministers were still, in some cases, at sea.

That is the whole argument of this book in one paragraph, and I have put it here rather than saving it for a dramatic reveal in chapter thirty, because a book that withholds its thesis to maintain suspense is a book that does not trust its reader. The thesis is this. In the last week of July 1914 the time available for deciding fell below the time required for deciding, everywhere at once. When that happens, decisions stop being made. What happens instead is that everyone executes the plan they wrote earlier, when there was time, and the plans had been written separately by people who had never checked them against one another. The result belonged to no one. Not because no one was responsible, but because responsibility had been discharged years earlier, in peacetime, by men who wrote plans that could not all be true at once and then went home.

I want to be exact about what this does and does not claim, because the argument has an ugly cousin and I would rather not be mistaken for it.

The ugly cousin says: nobody wanted it, nobody could have stopped it, therefore nobody is to blame. This is a comfortable position and it has been very popular, and chapter three explains why it was popular and who worked to make it so, which is a story most readers will not have heard and which does no credit to anyone involved.

The argument of this book is not that one. It says something harder. It says that the men of July 1914 mostly understood their situation correctly, including the fact that they were running out of time, and that understanding it did not help them, because you cannot make a council of ministers assemble faster by understanding that it needs to. It relocates the failure rather than dissolving it. The culpable decisions on this account were taken in the years before, with all the time in the world available: the decision to write war plans that assumed a cooperative enemy, the decision to convert measures that had required specific authorization into measures available automatically, the decision to build no institution whatever capable of stopping a clock once it began to run down. Those were leisurely decisions, made by men who could have consulted anybody they liked. If you want somebody to blame, they are standing right there, and they are not in a hurry.

There is a second reason for writing this now, and it has nothing to do with 1914.

The structure described above is not a historical curiosity. It is a design pattern, and we have been installing it energetically for eighty years. A ballistic missile crossing the pole gives a national leadership somewhere between fifteen and thirty minutes, of which detection, verification, and communication consume most, leaving an interval for the actual decision that would have struck the men of 1914 as a joke in poor taste. Because that interval is too short for deliberation, the response is pre-authorized: a plan written in advance, to be executed when there is no time to think. That is precisely the arrangement this book identifies as the mechanism of catastrophe, and we adopted it deliberately, as policy, and called it deterrence.

Cyber operations have the same shape with the numbers reversed: attribution takes weeks, retaliation takes hours, and the gap between them is filled by whatever was decided in advance. Pandemic response has it too, as anyone who watched a national government try to convene an emergency committee about an exponential curve will recognize. Financial markets had it in the most literal possible form, when algorithms began transacting faster than any human oversight could be summoned.

The markets are the interesting case, because the markets fixed it. After the crash of 1987 and again after the flash crash of 2010, exchanges installed circuit breakers: mandatory halts triggered automatically when prices move too fast, whose entire function is to manufacture a pause that nobody has to request. They are crude. They are unpopular with people who make money from speed. They work. And their existence proves that the absence of such a mechanism elsewhere is a choice rather than a law of nature, which is the least comfortable sentence in this book.

Then there is the newest arrival, which deserves its own warning. Machines are now very good at producing an assessment quickly. They are not, and cannot be, good at producing an authorized political decision quickly, because authorization is a constitutional and human process rather than a computational one. So the two intervals come apart in the most dangerous possible direction: the time you feel you need collapses while the time you actually need does not move. A leader with an excellent analysis in hand at three in the morning may reasonably believe he has time to spare. He does not. He has an answer. Having an answer and being able to act on it lawfully are different achievements, and only one of them has been accelerated.

A word on how to read what follows. The first twenty-one chapters stay in the past, because the past is where the evidence is precise enough to argue over. They rebuild the July crisis as a scheduling failure, and along the way they take apart several explanations you may be attached to, including the one about the trip to Abilene, which is a fine parable about family dinners and a poor one about this. The remaining chapters move forward: Cuba in 1962, which had the identical structure and did not collapse, and why; the room where nobody can be reached; the man at Serpukhov who declined to report what his screen was telling him; and the machines that, in every simulation run so far, have never once chosen to step down.

The book contains no mathematics. This is not a concession to the reader’s supposed inability, which is usually an insult dressed as a courtesy. It is a discipline for the writer. An argument that survives translation into plain language is an argument you can check. If you finish this book unconvinced, I would like you to be unconvinced for reasons you can articulate, rather than because you were shown an equation and decided not to argue with it.

I should also say what is missing, since a book is defined by its omissions as much as by its contents. There is almost nothing here about the war itself. The trenches appear only twice and briefly. Verdun does not appear at all. This will strike some readers as a grotesque omission in a book with a world war in the title, and the objection is fair enough to answer directly: the subject is the door, not the room. How a system enters a state it cannot leave is a question with an answer; what it suffers once inside is a question with a literature, and that literature is enormous and better than anything I could add to it. The one aspect of the war’s duration that belongs here is why it lasted, since the mechanism that made stopping expensive is the same mechanism that made starting irreversible, and one chapter takes that up.

There is a final difficulty, which is emotional rather than intellectual, and it is only fair to name it at the outset. This argument takes away the villain. Readers do not like that, and they are not wrong to dislike it. A story with a culprit is a story with a lesson, and the lesson is comforting even when the story is not: identify the guilty party, avoid becoming him, sleep soundly. A story about response intervals offers no such comfort. It suggests that a system can be staffed entirely by conscientious people of average decency and still produce a catastrophe, provided the intervals are wrong. I have some sympathy with the reader who finds this bleak. My own view is the opposite, and it is the reason the book exists. A catastrophe caused by wickedness can only be prevented by producing better people, which nobody has ever managed reliably. A catastrophe caused by scheduling can be prevented by changing the schedule, which is dull, achievable, and has already been done once, by stock exchanges, of all unlikely institutions.

One last thing, and it is a confession rather than a claim. This book is itself another account of 1914, written a hundred and twelve years later by someone with a thesis, which is exactly the sort of object the third chapter teaches you to be suspicious of. I have tried to earn the suspicion honestly by saying where the evidence is thin, which is more often than an author’s vanity prefers. The conclusion returns to this, and does not let me off.

The clocks are the story. Let us start with a telegram that arrived too late.

Chapter One — The Telegram That Arrived Too Late

The document was four pages long and it was late. The Serbian reply to the Austro-Hungarian note had been typed, then partly handwritten when the typewriter failed, then carried through the streets of Belgrade by the prime minister himself, who arrived at the Austro-Hungarian legation at six in the evening on the twenty-fifth of July with two minutes to spare against a deadline of forty-eight hours.

Baron Giesl, the Austro-Hungarian minister, read it in about ten minutes. He had already sent his luggage to the railway station. His staff had burned the codebooks that afternoon. The reply, as it happened, conceded almost everything: Serbia accepted the great majority of the demands, hedged on one, and offered to submit that one to international arbitration. Giesl was not empowered to evaluate any of this and did not attempt to. He had instructions that any answer other than unconditional acceptance was to be treated as a rejection, and this answer was not unconditional acceptance. He wrote a short note breaking off relations, handed it over, and caught the six-thirty train. He was across the frontier within the hour.

What matters here is not Giesl, who was doing his job, and not the reply, which historians still argue over. What matters is where that document went next, and how long it took to get there.

It went to Berlin. The German government, whose assurance of support had made the Austro-Hungarian note possible in the first place, had not seen the note before it was delivered and had not seen the reply either. This is worth pausing on, because it is the sort of thing that sounds like a mistake in the telling and was in fact routine. Allies did not routinely show each other their diplomatic correspondence in advance. The most consequential document in Europe travelled to the capital of the power that would have to fight the resulting war by the ordinary channels, at the ordinary speed, arriving in the way that things arrived.

The German Emperor was not in Berlin. Wilhelm the Second was on his annual Norwegian cruise, which he had been urged to take precisely so that the crisis would appear unremarkable, and which he cut short on his own initiative when the newspapers alarmed him. He returned to Potsdam on the twenty-seventh. The Serbian reply reached him on the morning of the twenty-eighth of July.

He read it and was delighted. In the margin, in the vigorous pencil he used for everything, he wrote that this was more than one could have expected, a great moral victory for Vienna, and that with it every reason for war fell away. He then wrote out a proposal. The Austrians should occupy Belgrade as a pledge, hold it while the remaining points were settled, and stop there. He sent this to his chancellor with instructions to convey it to Vienna.

It was a serious proposal, made by the one man in Europe whose word could have stopped the Austro-Hungarian government, on the basis of a correct reading of a document, arrived at through exactly the process one would want. He read the evidence. He changed his mind. He acted.

Vienna had declared war on Serbia that same morning. The declaration went out by telegram, which was itself unusual and which the Austro-Hungarian foreign minister had chosen deliberately in order to make the thing irreversible before anyone could propose an alternative. The Kaiser’s proposal was converted into instructions during the day, delayed further in the German Foreign Office by a chancellor with his own views about how much pressure Vienna should be under, and reached the Austro-Hungarian government late that night, by which point the state of war had existed for some fourteen hours and the first shells had been fired at Belgrade across the Danube.

There is a version of this story in which the villain is the chancellor, who slowed the message, or the Austro-Hungarian foreign minister, who accelerated the declaration. Both accusations have merit and both have been made at length. But strip out the villainy entirely. Suppose the chancellor had been perfectly loyal and had transmitted the Kaiser’s view within the hour. It would still have arrived after the declaration, because the declaration was issued in the morning and the Kaiser read the document in the morning, and no amount of loyalty makes a message overtake an event that has already happened.

That is the whole shape of the thing, visible in a single day, before we have said a word about railways or alliances. A head of state formed a considered judgment that would have prevented a war. The judgment was correct, it was timely by any standard that would have applied five years earlier, and it was useless, because the interval required to read a document, form a view, translate that view into instructions, and transmit them was longer than the interval before the act it was meant to prevent.

We are trained to read such episodes as tragedy, and tragedy has a grammar. In tragedy the near miss is meaningful. The letter goes astray, the messenger is delayed, and we feel the shape of a world that almost went otherwise. It is a satisfying feeling and it is the wrong one here, because it treats the timing as accident. The timing was not accident. It was the ordinary operating speed of a European government in 1914 running against a deadline that a European government had set. Nobody had built anything capable of moving faster, because until that month nobody had needed to.

Consider what the process actually required. A document arrives at a legation. It must be enciphered before transmission, because it is confidential, and encipherment in 1914 was a manual operation performed by a clerk with a codebook, at a rate measured in words per hour rather than words per minute. It travels by wire, which is fast. At the far end it must be deciphered by another clerk at a similar rate, then translated if necessary, then typed, then circulated to the officials whose business it is, then brought to the person entitled to make a decision, who may be at his country house or on a battleship or asleep. If the decision requires a council, the council must be summoned, and the members must physically travel to the room. If it requires a sovereign’s signature, the sovereign must be found. Then the resulting order goes back down the same chain in reverse, enciphered again, transmitted again, deciphered again.

None of these steps is unreasonable. Each exists for a good reason. Encipherment protects secrets, councils prevent tyranny, signatures establish accountability. Together they meant that a European government in 1914 needed something on the order of half a day to produce a decision that it could stand behind, and rather longer if the persons required were dispersed, which in late July, at the height of the holiday season, they invariably were. The French president and prime minister spent the decisive days on a battleship in the Baltic, where they could receive garbled wireless messages and send almost nothing. This was not negligence. Nobody had told them the world was going to end that week.

Against that half day, look again at what the crisis was handing out. Forty-eight hours to Belgrade. Then, within a week, twelve hours to St Petersburg and eighteen to Paris and twelve to Brussels. A government that needs twelve hours to answer and is given twelve hours to answer has, in practice, no time at all, because the twelve hours it needs assume that everyone is already in the room and nobody has to be woken.

Here I want to head off a misreading that will otherwise follow us through the whole book. The claim is not that these men were overwhelmed, or panicked, or lost their heads. Several of them behaved with conspicuous composure. The Kaiser’s marginal notes on the twenty-eighth of July are among the most sensible things he wrote in his life, which is admittedly a low bar, but they were also produced quickly and under strain and they were right. The system’s problem was not that its people failed. Its problem was that even flawless performance took longer than was available.

That is an unfamiliar kind of failure and our language is not well equipped for it. We have rich vocabularies for incompetence, for malice, for cowardice, for wishful thinking. We have almost no words for the situation in which everyone does their job properly at the maximum speed the job permits and the result is a catastrophe anyway. The nearest thing we have is a shrug about bad luck, which is not an explanation but an admission that we have stopped looking.

There is one more feature of the twenty-eighth of July that will matter later, and it is easy to miss. When Vienna sent its declaration of war by telegram, it was not merely being efficient. Telegraphic declaration was legally irregular; the Serbian government initially suspected the message was a forgery, since nobody had ever declared war that way before. The point of doing it was speed, and the point of speed was to close the question before the Kaiser’s proposal, or the British mediation offer, or anybody else’s second thoughts could reach the table. The Austro-Hungarian foreign ministry was not a victim of the shortening intervals. It was using them. It had worked out that in a system where deliberation takes half a day, an irreversible act performed in ten minutes cannot be deliberated about at all.

This is the discovery that runs through the rest of the crisis and through most of the twentieth century afterward. If your opponent needs twelve hours to think, you do not have to defeat his thinking. You only have to act inside twelve hours. Whether the Austro-Hungarian ministers understood the general principle or merely stumbled onto a useful trick is unknowable and does not much matter. What matters is that the trick works, that it worked repeatedly over the following week in the hands of several different governments, and that every use of it made the next use more attractive.

The Kaiser’s proposal, when it finally arrived in Vienna, was not rejected. That would have required a decision. It was simply overtaken, discussed for a while as a possible basis for something later, and rendered irrelevant by events moving at a speed the discussion could not match. Within seventy-two hours the Russian army was mobilizing, and after that nobody in Europe was reading anything carefully.

Chapter Two — Two Clocks

Ask a diplomat what makes a crisis dangerous and you will hear about time pressure, a phrase that sounds precise and is not. Time pressure is a feeling, and feelings are not the sort of thing that can be measured, compared between countries, or engineered. Underneath the feeling are two separate quantities that behave differently, belong to different people, and can be changed by different means. Almost everything interesting about crises follows from the fact that these two have been persistently mistaken for one.

The first is how long you need. Call it your response time. It is the interval between a piece of information arriving somewhere in your government and a decision leaving it with authority attached: the ciphering, the carrying, the finding, the convening, the signing, the transmitting. It is a property of your own institutions and it is fantastically boring to study, which is why almost nobody does.

The second is how long you have. Call it your window. It is the interval before somebody else does something that removes an option you currently possess. Sending an army across a border removes options. So does firing a shot, breaking off relations, or issuing a demand that expires. Your window is not a fact about you at all. It is a fact about other people.

The difference between the two is your reserve. When your window is longer than your response time, you have a genuine choice: information arrives, you deliberate, you decide, and the decision is still relevant when it emerges. When your window is shorter, you do not have a choice in any sense that would survive scrutiny. You have a reflex.

Setting the two side by side produces the first useful observation of this book, which is that they have different owners. Your response time belongs to you. Your window belongs to your adversary. This asymmetry is so obvious once stated that it seems hardly worth stating, and it has enormous consequences that almost nobody acts on.

The consequence is this. If you want more reserve, you have exactly one variable you control, and it is the slow one. You can shorten your own response time, but only by rebuilding your institutions, and institutions cannot be rebuilt during a crisis. Your window, meanwhile, can be halved by a foreign minister in another country in the time it takes him to dictate a sentence. The quantity you control moves in years. The quantity you do not control moves in minutes. Every crisis is therefore fought with a reserve that was fixed long before it began and can only be spent, never replenished, once it starts.

There is a moment in the diplomatic record where this becomes almost comically explicit. On the twenty-ninth of July the Russian government wished to indicate resolve without provoking Germany, and hit upon partial mobilization, aimed at Austria-Hungary alone. It seemed the obvious middle path. The army informed the government that no such plan existed. Mobilization plans were built as single interlocking objects; the railway schedules for a partial call-up had never been written, and improvising them would wreck the general plan if a general call-up were later required. The government had assumed it possessed an option that its own institutions had never constructed, and discovered the truth on the day it needed it.

This is the ordinary condition of governments and it deserves a name. What you can do in a crisis is not what you can imagine doing. It is what somebody built the machinery for, at some earlier date, usually in response to a different problem, often by people now dead. The Russian ministers had every right to want a graduated response. Wanting it did not conjure a timetable.

Now hold the two clocks together and watch what happens when a crisis escalates, because the pattern is not symmetrical and the asymmetry is the entire story.

Escalation shortens windows. That is nearly the definition of escalation: each act removes options from somebody, and the sharper the act, the less time remains before further options vanish. An ultimatum is the purest form, since it announces its own expiry, but a mobilization order does the same thing more slowly and more thoroughly, and so does a fleet putting to sea.

Escalation does not lengthen response times, but it does not shorten them either, and this is the part that surprises people who expect crises to concentrate the mind. Concentration of the mind is a cognitive phenomenon and response time is not cognitive. A minister who grasps the urgency perfectly still cannot make the cipher clerk faster, cannot make his colleagues arrive sooner, cannot dispense with the signature that his constitution requires. In extremity a few hours can be shaved. It is nothing against a window that halves.

So one quantity falls fast and the other holds roughly still, and there is only one way that ends. The lines cross. Before the crossing you have a system of states making choices. After it, you have a system of states executing whatever they prepared earlier. Nothing announces the crossing. There is no alarm, no moment where a light goes red. Individuals experience it, if they experience it at all, as an increasing sense that events are getting ahead of them, which they attribute to their own inadequacy or to the malice of others.

A word about that phrase, events getting ahead of them, which appears constantly in the memoirs of 1914 and which we tend to read as an evasion. It is not an evasion. It is an accurate report of the crossing, made by people who had no vocabulary for what they were describing. When a man writes that events had acquired a momentum of their own, we hear an excuse. He was reporting an observation: his response time now exceeded his window, and the world had begun happening to him rather than through him.

It is worth being clear about what this framework does not say, since it invites two misreadings.

It does not say that speed is good and slowness bad. The reserve is a difference, not a rate, and a fast government facing a faster adversary is worse off than a slow government facing a patient one. Some of the most dangerous innovations of the last century have been speed improvements, because a state that can respond in minutes will accept windows of minutes, and windows of minutes are unforgiving of error in a way that windows of days are not. Reducing your response time is only a gain if your windows do not shrink to match. Historically they always have.

Nor does it say that having a plan is a mistake. A plan is exactly what a sensible government prepares against the possibility of a negative reserve, and preparing one is prudence. What matters is not whether you have a plan but whether your plan and everyone else’s can be executed at the same time without producing something none of you wanted. Nobody in Europe had checked. Nobody had thought to ask the question, because each general staff regarded its plan as its most closely guarded secret, and the whole point of a secret is that the people who would need to check it are the people forbidden to see it.

Which brings us to the strangest feature of the two clocks, and the reason this book exists. The reserve is not observable. You cannot look at a government and see whether its window exceeds its response time, because the window depends on what somebody else is about to do and nobody announces that. Governments therefore estimate their reserve, and they estimate it from experience, and their experience consists entirely of crises they survived.

That is a catastrophic way to estimate anything. It is like judging the depth of a river by the fact that you have crossed it several times without drowning, when the river has been rising all along. Five European crises between 1905 and 1913 were survived. Each survival was read as evidence that the system was sound. Each had in fact consumed something, and what it consumed was not stockpiles or treasure but the interval between the two clocks. That process, and the reason it is invisible to those undergoing it, is the subject of a later chapter. For now it is enough to see that the two clocks exist, that only one of them is yours, and that the gap between them is the most consequential quantity in international politics and appears in no country’s national accounts.

Chapter Three — The Phrase That Was Manufactured

In the autumn of 1919 the German Foreign Office established a small section with an unglamorous name. It was called the Kriegsschuldreferat, the War Guilt Section, and its business was the origins of the war that had ended eleven months earlier. It was not a historical research unit in any sense a modern university would recognize, though it employed people with historical training and produced work that historians read. It was an instrument of state policy, and its policy was to demonstrate that Germany had not been responsible for the war.

The policy had a price attached, which is why it existed. The Treaty of Versailles contained an article assigning to Germany and her allies responsibility for the loss and damage of the war, and that article was the legal foundation of reparations. Establishing that the responsibility was not Germany’s alone, or was not Germany’s at all, was therefore not an academic exercise. It was a strategy for reducing a bill, and everyone involved understood it that way.

The section’s principal product was documentary. Between 1922 and 1927 the German government published forty volumes of its own diplomatic correspondence from the years before the war, under a title that translates as The Great Politics of the European Cabinets. It was an extraordinary act of apparent transparency, unmatched by any other government, and it was received in the scholarly world as an immense gift. It was also a selection. The documents were chosen and edited by people whose task was to establish a conclusion, and the criteria for inclusion were not published. The most damaging material was, unsurprisingly, not there.

A second body was created in 1921 with the innocuous name Central Office for the Study of the Causes of the War. It published a journal devoted to the question of war guilt, it corresponded with sympathetic scholars abroad, it funded translations, and it was covertly financed by the Foreign Office, a fact not established publicly until long afterward. Its director was a former officer, not a historian.

The results were remarkable. Within a decade the confident Allied consensus of 1919 had been substantially dismantled, not by German propagandists, who would have been dismissed as interested parties, but by American and British scholars writing in good faith, working from the published documents, and arriving at the conclusion that responsibility was distributed, that the alliance system was the true culprit, and that no government had actually wanted the war. Some of these scholars had been in contact with the German apparatus and had received assistance of one kind or another. Most had simply used the documents available, which is precisely what a conscientious scholar does, and the documents available had been curated.

Meanwhile the dissenting German work was suppressed. A jurist named Hermann Kantorowicz was commissioned by a parliamentary committee to study the question and produced an assessment considerably less favorable to his own government than the official line. His study was not published. It sat unread for four decades and appeared only in the nineteen sixties, by which time its author had been dead for twenty-five years.

So the phrase that gives this book its title has a history, and it is not an innocent one. The proposition that nobody wanted the war did not emerge from the archives on its own. It was, in substantial part, produced. It was produced by an institution with a financial motive, using a genuine documentary base assembled with a thumb on the scale, and it was carried into the world by honest scholars who did not know what had been left out.

The obvious question is whether that makes it false. It does not, and this is where the chapter turns, because the easy move at this point is the wrong one.

A claim’s origins do not settle its truth. Interested parties say true things constantly, for their own reasons, and dismissing an argument because of who benefits from it is a fallacy with a Latin name and a long record of preventing people from noticing things. The German Foreign Office wanted it to be true that nobody had willed the war. It does not follow that somebody did.

What the provenance does establish is which version of the claim we should expect to find in circulation, and that is a subtler and more useful point. The Kriegsschuldreferat did not need the claim in its precise form. It needed the exculpatory form. It needed a story in which the war was a fog, an accident, a tragedy of the alliance system, nobody’s fault in particular, so that a bill addressed to one government could be returned to sender. And that is exactly the version that took hold and that most people carry around today: the sleepwalkers, the tangle of alliances, the sense of an impersonal catastrophe descending on a continent of essentially decent statesmen.

There is a defensible version of the same claim, and this book argues for it. But the defensible version is not exculpatory in the slightest. It says that the outcome lay outside everyone’s intentions because the plans that produced it had been written separately and never checked against one another, which is not a fog descending but a specific dereliction with names attached. It relocates the blame from July to the preceding decade, where the men responsible had years to do better and did not. That version was of no use whatever to a government trying to reduce a reparations bill, which is presumably why nobody in Wilhelmstrasse was pushing it.

Distinguishing the two versions is the actual work, and it is harder than either accepting or rejecting the slogan wholesale. They sound almost identical. Both say nobody wanted it. One means that responsibility dissolves into circumstance; the other means that responsibility moves earlier and becomes structural. The first is a comfort; the second is an indictment.

The Fischer controversy of the nineteen sixties broke the exculpatory version, and broke it violently. A German historian working in German archives argued that the German leadership had pursued expansionist aims and had accepted the risk of a general war deliberately, and the resulting fight was less like a scholarly disagreement than like a national nervous breakdown, conducted in public, with denunciations and cancelled lecture invitations and questions in parliament. It ended the innocence of the documentary record. It also established something more durable than its specific claims, which is that a national historiography can be captured, that it can stay captured for forty years, and that the people inside it will not necessarily notice, because from the inside a captured historiography looks exactly like a consensus.

That is the reason this chapter sits so early in the book rather than being tucked into an appendix on sources. The reader is about to be given an argument for a proposition that a foreign ministry once paid to promote. It seems only decent to mention that in advance, at the front, where it can be weighed, rather than at the back, where it would look like a confession extracted under pressure.

It also sets a standard I would rather be held to than escape. If the claim that nobody wanted the war requires scrutiny of who benefits from believing it, so does the claim that everyone was simply out of time. Who benefits from that one? Any government, presently, that would prefer its own scheduling arrangements not to be examined too closely, since a book about response intervals in 1914 that ends by praising stock exchange circuit breakers is not obviously a neutral object either. I do not think that undermines the argument. I think it means the argument should be checked against evidence rather than accepted because it is elegant, and the evidence, fortunately, is a matter of public record and stated in hours.

Chapter Four — Everyone Wanted a Different War

Set the war aims of July 1914 side by side, the way a waiter sets down five dishes, and the first thing you notice is that no two of them are the same dish.

Vienna wanted a short punitive campaign against Serbia. Not a European war; a Balkan one, of the kind that had been fought twice in the preceding two years without troubling anybody in Paris. The Austro-Hungarian chief of staff had been requesting such a campaign, in writing, roughly twice a year since 1906, and the assassination of the heir to the throne finally gave him an argument nobody could refuse. What he wanted was to break Serbia as a regional power before the empire’s own nationalities concluded that breaking away was survivable.

Berlin wanted something different: a continental war against France and Russia, fought soon, decided quickly, and if at all possible without Britain. The chancellor’s calculation was that if the crisis could be kept local, Germany won a diplomatic victory for nothing, and if it could not, then a war in 1914 was preferable to a war in 1917, by which time the Russian railway program would be complete. This was a gamble made in cold blood, and it has been anatomized ever since. But note its shape. It was a bet on a particular war, with a particular list of participants, over a particular timescale.

St Petersburg wanted no war at all, which is not the same as wanting peace unconditionally. The Russian foreign minister wanted to demonstrate that Russia would not again stand aside while a Slavic client was humiliated, as it had in 1909, and he believed a demonstration would be sufficient. The whole Russian policy of late July was designed as a signal, and its authors were genuinely surprised when it was read as a preparation.

Paris wanted a defensive war, if one had to happen, fought with the Russian front already open and with Germany in the position of aggressor, which mattered because it determined whether Britain came in and whether the French Left would support mobilization. French policy in July was less about Serbia, which no French voter could locate, than about ensuring that whatever happened happened in the correct order.

London wanted, more than anything else, to not have to decide. British policy consisted of offering mediation, refusing to state in advance what Britain would do, and hoping the question would resolve itself. This was not cowardice, though it was called that afterward. It was the accurate reflection of a cabinet that would have split down the middle on any clear commitment in either direction, and whose foreign secretary knew it.

Now: is this a hidden consensus? Are these five governments secretly agreeing about something and failing to notice?

They are not, and the point is worth pressing because so much popular writing about 1914 assumes otherwise. The five aims above are not five expressions of a single suppressed wish. They are five genuinely different objectives, held for different reasons, by governments with different problems. Each was, taken by itself, achievable. A local Balkan war was achievable; two had just occurred. A continental war without Britain was achievable in the sense that reasonable men thought it possible, and the German ambassador in London spent the crisis explaining why it was not, and was disbelieved. A Russian demonstration without fighting was achievable; one had worked in 1912. A French defensive war with the correct sequence was achievable, and in the event France largely got it. British non-involvement was achievable right up until the Belgian frontier.

Five achievable objectives. Not one of them was achieved.

What arrived instead was a war of four years and three months, fought by every power on the list plus a dozen others, ending with four empires destroyed, three of them by revolution, twenty million dead, and a peace settlement that its own authors regarded as a failure within a decade. That outcome does not appear in any of the five lists. It does not appear as an acceptable outcome, an anticipated outcome, or a risk anybody was consciously running. It was not the war anyone wanted, and it was not a compromise between the wars they wanted either.

This is the precise sense in which nobody wanted the First World War, and it is worth separating carefully from the sense in which the phrase is usually meant.

The usual meaning is psychological: everybody was reluctant, everybody hoped it would go away, everybody was pushed by circumstances into something they inwardly dreaded. There is some truth in this and quite a lot of untruth. Several of these men were not reluctant at all. The Austro-Hungarian chief of staff had been demanding a war for eight years and greeted its arrival with relief. Certain figures in Berlin were positively cheerful. The reluctance model requires a continent of unwilling men and there were plainly some willing ones.

The other meaning is structural and has nothing to do with anyone’s feelings. It says: list every outcome that every participant was working toward. Now look at what happened. It is not on the list. Not lower down the list, not a degraded version of an item on the list. Absent.

That can happen without anybody being reluctant, deceived, or asleep. It happens when the actions that would produce each of the five desired outcomes are performed simultaneously, and the combination produces something none of the five actions was designed to produce. Each government’s plan was drawn up against an imagined opponent who behaved as that government expected. None was drawn up against the other four plans all running at once. Nobody had ever laid them on the same table, because each was among the most closely guarded secrets in Europe.

Here is a small domestic version of the same thing. Five people share a house. Each independently decides that the kitchen is filthy, that a confrontation would be unpleasant, and that the tactful solution is to clean it thoroughly at three in the morning when nobody is watching. All five arrive at three in the morning. What happens next is not what any of them wanted, is not a compromise between what they wanted, and cannot be explained by saying that any of them was reluctant to clean the kitchen. It is simply the interaction of five separately sensible plans that were never compared.

The house is a joke and the war was not, but the structure transfers exactly, and it explains something that the reluctance model cannot. It explains why the search for the man who wanted it has never converged. Investigators have been looking for a single intention that matches the outcome, on the assumption that outcomes are produced by matching intentions. When the outcome is produced by the interaction of non-matching intentions, that search returns nothing, forever, no matter how many archives are opened. And archives keep being opened, and it keeps returning nothing, which is itself a result that ought to have been taken more seriously long ago.

There is one refinement to add before leaving this, because otherwise the argument proves too much.

It would be absurd to claim that outcomes never match intentions. Most of the time they roughly do, which is why we plan at all. The conditions under which they come apart are specific, and two of them are visible here. The first is that the plans must be secret from each other, so that no participant can evaluate the joint result. The second is that they must be executed simultaneously rather than sequentially, because sequential execution allows adjustment: the second mover sees the first move and revises. Simultaneity removes revision.

Both conditions were satisfied in the last days of July 1914, and the second was satisfied for a reason that belongs to the argument of this book rather than to the diplomacy. Plans are executed simultaneously when nobody has time to wait and see. Sequential play, the ordinary rhythm of nineteenth-century diplomacy in which a move was made and a response awaited over weeks, requires that the intervals be long enough for observation. Compress the intervals and the game stops being sequential. It becomes a game in which all players move at once and discover the result together, which is a different game with different mathematics and vastly worse outcomes.

That is what the shrinking windows did. They did not change what anyone wanted. They changed the game from one in which you could see what your opponent did before committing, into one in which you could not, and in that game five sensible plans meet in a dark kitchen at three in the morning.

Chapter Five — Twenty-Five Days and Forty-Eight Hours

Divide twenty-five days by forty-eight hours and you get twelve and a half. That ratio is the single most informative number in the history of the July crisis, and it appears in almost no account of it.

Twenty-five days is how long Austria-Hungary took to compose its note to Serbia. The archduke was shot on the twenty-eighth of June. The note was handed over on the twenty-third of July at six in the evening. In between, the Austro-Hungarian government consulted its ally, argued internally, overcame the resistance of the Hungarian prime minister, waited for the harvest leave of its soldiers to end, drafted, redrafted, and satisfied itself that the terms were sufficiently severe that Serbia would have to refuse them. This was not dithering. It was a government using the ordinary interval a serious decision requires, and using it well.

Forty-eight hours is what it then gave Serbia to answer.

Nobody at the time regarded this as a scandal, and it is worth understanding why not, because our instinct is to read it as obvious bad faith. Ultimatums were a normal instrument. Short deadlines were normal within ultimatums. What was abnormal was the combination of a very short deadline with terms of unprecedented severity, several of which touched the internal sovereignty of another state, and one of which — the demand that Austro-Hungarian officials take part in judicial proceedings on Serbian soil — was included, on the evidence, because it was expected to be refused.

But hold the moral question aside, since it has been thoroughly worked over, and look at the arithmetic instead. One government needed twenty-five days to decide what it wanted. It then required another government to decide what it wanted in one twelfth of that time. And the second government’s decision was harder, since it involved the survival of the state rather than the framing of a demand.

That asymmetry is the instrument. An ultimatum is not primarily a communication of demands; if it were, you would leave the deadline open and negotiate. An ultimatum is a device for imposing on your opponent a response interval shorter than his deliberative capacity. Everything else about it is decoration.

Serbia, remarkably, met the deadline, and the reply it produced in forty-eight hours was a small masterpiece of diplomatic drafting that conceded nearly everything while conceding nothing that mattered. It was also delivered with two minutes in hand, which tells you something about how much slack there was.

The technique appears again, in a purer form, at the other end of the crisis. On the thirty-first of July the German government issued an ultimatum to Russia with a twelve-hour limit, and on the same day one to France with eighteen. On the second of August it gave Belgium twelve hours to permit the passage of German troops. On the fourth, Britain gave Germany a period that expired at eleven that night, London time, and which by the time it was actually delivered in Berlin amounted to a matter of hours.

Forty-eight, then eighteen, then twelve, then twelve, then something like seven. That is the shape of the crisis, drawn without reference to anybody’s motives, using only numbers that the governments themselves wrote down and published.

Now put beside it the other number, the one from the previous chapter’s argument: something on the order of half a day for a European government to convert an arriving message into an authorized decision. Twelve hours, give or take, under good conditions, with the relevant people available.

The two lines cross in the last days of July. After they cross, the deadlines being issued are shorter than the time required to answer them thoughtfully. What arrives at the other end is not a considered response. It is whatever the receiving government had ready.

There is a detail about the timing of the Austro-Hungarian note that deserves its own paragraph, because it demonstrates that at least one government understood exactly what it was doing.

The French president and prime minister were on a state visit to Russia during the third week of July. Their presence in St Petersburg meant that the two allies could coordinate face to face, quickly, without the delays of encrypted correspondence. The Austro-Hungarian note was deliberately timed to be delivered after they had left, and the departure schedule was checked. The French leaders sailed on the evening of the twenty-third; the note went in at six that evening; and the president of France spent the following crucial days on a battleship in the Baltic, receiving fragmentary wireless messages and unable to convene anything.

Read that again as an operation rather than as diplomacy. A government identified the moment at which its opponents’ response time would be longest, and delivered its demand then. It did not need to defeat French policy. It only needed to arrange that French policy could not be formulated in time. This is the same discovery Vienna made five days later when it declared war by telegram, applied in advance rather than after the fact, and it is the reason it is so difficult to argue that the Austro-Hungarian leadership stumbled into anything. Stumbling does not involve consulting a sailing timetable.

Once you see the technique, you find it everywhere in the twentieth century, and it has a name in ordinary life. It is what a salesman is doing when the offer expires today. It is what a negotiator is doing when he presents the contract on Friday afternoon. It is what a legislature is doing when it releases a two thousand page bill the night before the vote. In none of these cases does the party imposing the deadline expect to win the argument. The point is to arrange that the argument does not happen.

What makes the international version worse than the salesman’s is the reciprocity. The salesman’s customer cannot impose a deadline back. States can, and did. Each use of the technique in July 1914 provoked its use in return, and because every user chose an interval shorter than the last — since a deadline longer than your opponent’s previous one signals weakness — the intervals fell in a staircase that no single participant designed. Vienna’s forty-eight hours were not chosen with reference to Berlin’s later twelve. Berlin’s twelve were chosen with reference to Vienna’s forty-eight.

That is how a whole continent arrives at response intervals none of its governments could use, without any government deciding to arrive there. Each simply declined to be the one who granted more time than he had been granted.

Chapter Six — The Cipher Clerk Was Not Asleep

Consider the least glamorous job in European diplomacy in 1914. A young man sits in a locked room in an embassy with a bound codebook, a pad, and a pen. A telegram arrives as a sequence of five-letter groups. He looks up each group, writes the plaintext beneath it, and continues, group after group, for as long as the message runs. When the message is out he passes it to be typed. When a reply is to be sent, he performs the operation in reverse. He is not permitted to leave the room with his notes. He is often the only person on duty who is cleared to do this work.

He is the reason the war started when it did, and nobody has ever blamed him, which is correct, because he did nothing wrong.

This chapter is about a distinction that sounds pedantic for about a page and then reorganizes everything: the difference between how long a decision takes and how long a person takes to make up his mind. These are not the same quantity, they are not even the same kind of quantity, and confusing them is the reason a century of writing about 1914 has produced so much moralizing and so little mechanism.

Making up your mind is cognitive. It happens inside a head, it can be fast or slow depending on the head, and it is affected by fear, fatigue, prejudice, and the quality of the whisky at lunch. This is the stuff of the memoirs, and it is why the memoirs are so unsatisfying: everyone reports that everyone else was slow, indecisive, or blind, and everyone reports that he himself saw clearly and was ignored.

Institutional response time is not cognitive at all. It is a property of a machine made of people, buildings, procedures, and law. It includes the encipherment and the decipherment and the typing and the circulation. It includes the constitutional requirement, in three of the five great powers, that certain orders carry a sovereign’s signature, and therefore includes the time required to locate a sovereign. It includes the fact that a council of ministers is a physical assembly of physical men who must travel to a room, and that in July they were scattered across a continent at the height of the holiday season.

None of that gets faster because somebody in it has grasped the urgency. This is the crucial and slightly humiliating point. Understanding does not accelerate procedure. A minister who fully comprehends that Europe will be at war within seventy-two hours cannot decipher the telegram himself, cannot make his colleagues’ trains run sooner, cannot sign on behalf of his emperor. His comprehension is real and it purchases nothing.

There is an experiment nobody ran but which anyone can perform mentally. Replace every statesman in Europe in July 1914 with the most brilliant, decisive, far-sighted person you can imagine. Leave the machinery exactly as it was: the same codebooks, the same constitutions, the same railway timetables, the same holiday absences. Now shorten the windows exactly as they were shortened. Your paragons receive twelve hours to answer a demand that requires a crown council, and their brilliance saves them a couple of hours at most on a task that needs twelve. They fail slightly later than the actual men did, and in slightly better prose.

Now run the experiment the other way. Leave the actual men in place, with all their vanities and blind spots and mediocrities, and give them a mechanism for extending a deadline. Give them one instrument, of any kind, that could add seventy-two hours to any expiring ultimatum. The mediocrities muddle through, as mediocrities generally do when they have time, and the twentieth century goes differently.

That thought experiment is the argument of this book compressed into two paragraphs, and it explains why the moral literature has been so unproductive. If the binding constraint is machinery, then investigating character is investigating the wrong variable. You can establish beyond doubt that a given foreign minister was vain, deceitful, and out of his depth — several of them were — and you will not have explained the outcome, because a virtuous replacement facing the same intervals produces the same result.

There is a further consequence, which is that the standard vocabulary of blame becomes almost unusable. Consider the words we reach for: negligent, complacent, reckless, asleep. Every one of them describes a person performing below capacity. Not one describes the situation in which every person performs at capacity and the capacity is insufficient. Our moral language was built for a world in which trying harder helps. It has no word for the specific tragedy of a system whose components are all working perfectly at speeds that were adequate last decade.

I said that nobody has blamed the cipher clerk, and that this is correct, but it is correct for an interesting reason. We do not blame him because we understand instinctively that his speed was a property of his equipment rather than his effort. What we do not do, and should, is extend the same understanding upward. The council of ministers that took eleven hours to assemble was also operating at the speed of its equipment. So was the constitutional requirement for a signature. So was the ambassador who had to be found. At every level of the machine, the delay was structural, and at every level except the clerk’s we have insisted on reading it as a failure of character.

A last observation, which will matter greatly when we reach the present day. The clerk’s slowness was at least visible. Everyone in the building could see him working, could see the pile of undeciphered traffic growing, could form an accurate impression of how far behind the machine was running. Delay that you can watch is delay you can plan around, and several governments in July did plan around it, badly but consciously.

We have since removed the visible part. Messages now arrive instantly, and the modern equivalent of the locked room produces its output in less time than it takes to read. What has not changed is the assembly of the people entitled to decide, the establishment of what is actually true, and the securing of lawful authority to act. Those still take hours or days. But the pile of undeciphered traffic no longer sits there growing where anyone can see it, and so the machine now looks fast while remaining slow in the part that matters. That gap between how fast a government appears and how fast it can actually act is the subject of the last third of this book, and it is worse now than it was in 1914 for the specific reason that in 1914 you could see the clerk.

Chapter Seven — What a Default Is

Every building you have ever worked in has a fire procedure, and you have almost certainly never read it. Somewhere there is a notice explaining which staircase to use, where to assemble, and who is responsible for checking the lavatories. The notice exists because the designers of the building made an assumption about you, and the assumption is insulting only until you examine it. They assumed that when the alarm sounds you will not be capable of working out the optimal exit. Smoke, noise, other people running: these are conditions under which human reasoning degrades badly, and the sensible response is to decide in advance, in a quiet room, and post the answer on a wall.

That notice is a default. It is a decision made at a time of abundance about behavior at a time of scarcity, and it is not a confession of stupidity. It is the correct response to a foreseeable shortage of thinking time.

Every general staff in Europe in 1914 had produced the same object, in vastly greater detail. The German deployment plan filled volumes and was revised annually. The French plan, the seventeenth of its line, had been adopted the previous year. The Russian plans came in variants keyed to which enemies were involved. The Austro-Hungarian arrangements were organized around three lettered cases depending on whether the war was against Serbia, Russia, or both. Each represented years of professional work by intelligent men, and each existed for precisely the reason the fire notice exists: because when the moment came there would be no time to think, and a mediocre plan executed promptly beats a brilliant plan arrived at too late.

This is worth insisting on because the plans have such a bad reputation. In the popular telling they are villains, rigid machines that seized control from the politicians and dragged everyone to catastrophe. That story is wrong in a way we will take apart properly in a later chapter, and it is also unfair. Having a plan was not the error. Not having one would have been the error, and any staff officer who proposed to improvise the movement of three million men and their horses would have been dismissed as a lunatic, correctly.

What makes defaults dangerous is not any property of an individual default. It is a property of the collection.

Return to the building. The fire notice assumes something about everyone else in the building, namely that they will follow their own notices, which are compatible with yours. This compatibility is not an accident; it is the entire discipline of building safety, and it is enforced by people whose job is to look at all the notices in the building at once and check that the assembly points do not overlap, that the staircases are not oversubscribed, that the route from the third floor does not run through the fire on the second. Nobody thinks this coordination is optional. A building in which every floor had designed its own evacuation independently, in secret, without consulting the others, would not be permitted to open.

Europe in 1914 was that building.

Each plan was constructed on assumptions about what the others would do, and each set of assumptions was reasonable, and no one had ever laid the plans side by side, because they were among the most closely held secrets any of these states possessed. The German plan assumed a slow Russian mobilization, which was a defensible reading of the previous decade and a poor reading of the railway construction of the previous four years. It assumed France would fight in a particular way. It assumed Belgium would offer a formal protest and step aside, which was not merely wrong but had been contradicted directly by the Belgians, who were not consulted because one does not consult the country one intends to walk through. The Austro-Hungarian arrangements assumed that a choice between the Serbian and Russian cases could be made cleanly at the outset, when in the event the choice had to be made after the deployment had begun, producing a fiasco that put trains full of soldiers on journeys to nowhere.

Notice what all these assumptions have in common. Every one of them is an assumption about the behavior of another player, made by a planner who could not ask that player, and checked against nothing except his own judgment. And every one of them, when it failed, failed in the same direction: toward a larger, longer, more general war than the planner had in mind.

That direction is not a coincidence. Planners are professionals, and professionals build in margins. But the margin a general staff builds is a margin against its own plan failing, not against the plan succeeding in a world where four other plans are also running. A margin of the first kind makes your plan more robust. It also makes it larger, faster, and more committing, which shortens everyone else’s windows. Prudence at the level of the individual planner is thus converted, by the structure of the situation, into aggression at the level of the system, without anyone intending aggression.

The formal way of putting this is that the plans were not jointly executable. Each was a good answer to a question. The questions were incompatible.

There is an ugly consequence for accountability which most treatments avoid, and it is the reason this chapter exists where it does. If defaults are sensible individually and lethal collectively, then the responsible party is neither the man who wrote a plan nor the man who executed it. It is whoever was supposed to check the collection, and in 1914 that was nobody. No institution existed whose function was to ask whether the war plans of the European powers could all be true at once. The question was not asked and answered wrongly. It was not asked.

That is a strange kind of failure and our instruments for punishing it are poor. Courts, tribunals, and historians all work by identifying an actor and an act. The failure here is the absence of an act by an actor who did not exist. It is the same category of failure as a city with no building inspector: no individual is negligent, and the buildings burn.

One further feature of defaults deserves noting before we move on, because it will return in the modern chapters with considerable force. Defaults are self-justifying in a particular way. Once a default exists, the case for deliberating instead becomes weaker every year, because the default is right there, prepared, professional, and reassuring, while deliberation is expensive and produces disagreement. Organizations therefore tend to expand the set of situations covered by defaults and shrink the set requiring judgment. This drift is invisible, gradual, and almost always defended as prudence. The Russian regulations of 1913 are the classic case, and they get their own chapter later. For now it is enough to observe that a system in which more and more things are decided in advance is a system whose reserve of deliberative capacity is being quietly retired, department by department, with everyone congratulating themselves on their preparedness.

Chapter Eight — The Legation That Packed Its Bags

The Austro-Hungarian foreign minister had a problem in the last week of July, and it was not Serbia. Serbia had already been dealt with, in the sense that the reply had been declared unsatisfactory and relations broken. His problem was Europe, and specifically the near certainty that within days somebody — the British, the Germans, the Italians, possibly all three — would produce a conference, a mediation formula, or a face-saving compromise, and that the Habsburg monarchy would be manoeuvred into accepting it.

He had watched this happen before. In the Balkan crises of 1912 and 1913 the powers had convened, deliberated, and produced settlements. Vienna had gained something on paper each time and had come away convinced that it was being managed. Whatever else he wanted in July 1914, Count Berchtold did not want to be managed again.

His solution was elegant, disgraceful, and enormously instructive. On the twenty-eighth of July he had Austria-Hungary declare war on Serbia by telegram.

Declaring war by telegram was not a thing that was done. It had no clear precedent, and the Serbian government’s first reaction on receiving the message was to suspect a hoax, since the ordinary method involved an accredited representative delivering a document, and the ordinary method took time. That was the entire point. A declaration transmitted electrically could be issued in the interval between one diplomatic conversation and the next. There was no way to intercept it, no ambassador to instruct, no document to delay in transit.

More importantly, it could not be withdrawn. A state of war, once declared, is a fact of international law, and unmaking it requires a settlement rather than a change of mind. The moment the telegram went out, every mediation proposal then circulating in Europe was addressed to a situation that no longer existed. The Kaiser’s Belgrade proposal, which we met in the first chapter, was overtaken not because anyone rejected it but because it was a suggestion about how to avoid a war that was already legally under way.

Strip out the specific case and look at the technique, because the technique is the subject of this chapter.

If your opponents require a certain interval to organize a response — to consult, to convene, to agree on a formula — then you do not need to defeat their response. You need only perform an irreversible act in less time than their interval. Once the act is irreversible, their response, however well constructed, arrives to find its subject gone.

This is the offensive use of the two clocks. The previous chapters treated the shrinking windows as something that happened to Europe. Here it is something a government did on purpose, having worked out that it was possible. And once one government has demonstrated it, the technique is available to all of them, which is why the last week of July reads like an accelerating competition to be the one who acts before the others can meet.

The properties that make an act suitable for this purpose are worth listing, because they turn up again in every subsequent chapter of this book.

It must be fast to perform. A telegram qualifies; a naval blockade does not.

It must be difficult to undo, and difficulty here is political rather than physical. Nothing physical prevented Austria-Hungary from rescinding its declaration. What prevented it was that a monarchy which declares war in the morning and unsays it in the evening has announced to its own nationalities that it can be pushed, which for the Habsburg empire in 1914 was closer to a mortal threat than any Serbian army.

It must change the legal or factual situation rather than merely expressing a position. Statements can be answered by statements. Facts must be answered by facts, and producing a fact takes longer than producing a statement, which is where the asymmetry lives.

And it must be available to a small number of people without consultation. This is the property that matters most and is least discussed. An act requiring a cabinet cannot be performed inside the opponent’s response interval, because your own response interval is the same length. The technique is therefore available only for acts that one office can perform alone, which means that the shortening of windows systematically transfers power to whoever can act without asking. Across the last days of July, decisions migrated steadily away from cabinets and toward individuals and small groups, not because anyone seized power, but because the only decisions that could be taken in time were the ones a single office could take.

That is a rule with a very long reach, and I want to state it plainly because it will govern the second half of this book. Compressed intervals concentrate authority. Not as a matter of ideology or ambition, but as arithmetic: as the window shortens, the set of bodies capable of acting within it shrinks, and shrinks from the large and deliberative toward the small and executive. A crisis that gives you a week is decided by cabinets. A crisis that gives you an hour is decided by whoever is holding the telephone.

There is a final irony in the Belgrade telegram which is worth savoring, because it illustrates that the technique is not a strategy so much as a trap that also closes on its user.

Berchtold’s manoeuvre worked exactly as intended. The mediation proposals were nullified. The question was closed before it could be reopened. And within seventy-two hours his own government had lost control of the crisis entirely, because Russian mobilization was triggered by precisely the fact he had manufactured, and Russian mobilization triggered German mobilization, and after that no one in Vienna was consulted about anything of significance for the next four years. He had shortened everyone’s window, including his own, and the empire he was protecting from being managed ceased to exist within his lifetime. He died in 1942, in a country that no longer contained the state he had served, having written memoirs that nobody much read.

Chapter Nine — Plans That Cannot Be Executed Together

Two chess players sit down. Each has spent the previous month preparing an opening, and each preparation is excellent. The first has prepared a line that works beautifully against a particular defense. The second has prepared a line that works beautifully against a particular attack. Neither preparation is wrong. But the second player’s defense is not the one the first prepared against, and the first player’s attack is not the one the second prepared for, and what happens on the board is a position that appears in neither of their notebooks.

That is a mild inconvenience in chess, where you can look at the board and think. It is something else entirely when the preparations are national mobilization plans, the board cannot be seen, and the clock has run out.

The previous chapters established that each European power had a default and that the defaults had never been compared. This chapter is about what the comparison would have shown, had anybody made it, and about why the answer is more damning than the usual account of alliance entanglement.

Begin with the German plan, since it is the most notorious and the most misunderstood. Its logic was dictated by a genuine problem: Germany faced the possibility of war against France and Russia simultaneously, and lacked the strength for two full campaigns at once. The solution was sequential — defeat one enemy quickly, then turn to the other — and since Russian mobilization was slow and Russian space enormous, France had to be first. Speed against France required avoiding the fortified frontier, which required going through Belgium.

Every step of that reasoning is sound given its premises. Look now at the premises. It assumed Russia would be slow, which had been true in 1904 and was becoming less true every year as French-financed railways went in. It assumed France could be beaten in a matter of weeks, an assumption for which the evidence was a war fought forty-four years earlier against a different French army. And it assumed that violating Belgian neutrality would produce diplomatic protest rather than British intervention, an assumption that the German ambassador in London contradicted in writing repeatedly and was disbelieved each time.

Now the French plan, which was equally sound and equally dependent on assumptions about others. It assumed the German attack would come in a particular sector and be met with a French offensive there. It assumed the Russians would attack in the east early enough to draw German forces away, and the French had spent considerable diplomatic effort obtaining Russian promises to that effect, promises which required Russia to attack before its mobilization was complete.

Consider what has just happened. France required Russia to move earlier than Russia’s own plan considered prudent. Germany’s plan required Russia to move later than Russia intended. Both plans depended on the same variable, and they specified opposite values for it. Neither general staff could have discovered this, because neither had access to the other’s plan, and Russia could not satisfy both by definition.

The Austro-Hungarian arrangements supply the clearest illustration of incompatibility, because they were internally incompatible before any foreigner was involved. The Habsburg staff maintained plans for a Serbian war and a Russian war and a combined case, with a large body of troops that could be sent to either theatre depending on which case obtained. In the event, the decision to send them south was taken before the northern situation was clear, and then reversed, with the result that a substantial portion of the Austro-Hungarian army spent the opening weeks of the war riding trains between two fronts and arriving at neither in time to matter. The staff had built a plan that required a choice to be made before the information necessary for the choice existed.

Lay the four plans on a table, which no one did until the archives were opened decades later. What you see is not a machine that worked too well. It is a set of documents that contradict one another, and whose contradictions were resolved by the crude expedient of everybody executing his own and finding out.

The word for this is compossibility, an old term from philosophy meaning the capacity of several things to be true together. A set of plans is compossible if all of them can be carried out at once without producing a result that none of them contemplated. The European plans of 1914 were not compossible and nobody had checked, and the reason nobody had checked is the same reason the failure has such a curious moral texture. Checking would have required each general staff to show its most secret document to the staffs it was planning against. The requirement is not merely difficult. It is self-contradictory. The information needed to discover the danger was information whose concealment was the point.

That is a genuinely hard problem and I want to be honest that it has no clean solution, then and now. But observe that a weaker version was available and was also not attempted. It is not necessary to show your plan to your adversary in order to ask whether your plan’s assumptions about him are true. You can ask him. The German assumption about Belgian acquiescence could have been tested by any competent diplomat in an afternoon, and in a sense was tested, since the Belgians had said what they would do, and the assumption survived the test by the simple method of nobody in the German staff being obliged to listen to diplomats.

There is one more thing the comparison would have shown, and it is the point at which this chapter connects to the argument of the book. Every plan on the table required speed. Each staff had concluded, independently and for its own reasons, that the decisive advantage lay in mobilizing and striking before the enemy was ready. That conclusion was not a shared doctrine; it emerged separately from the particular geography and demography of each state. But its effect was collective. A continent in which every general staff believes that the first mover wins is a continent in which every window shortens automatically, because each government knows that any delay on its part is a gift to its enemies.

The plans, in other words, did not merely fail to fit together. They collectively produced the compression that made deliberation impossible, which was the condition under which they would be executed unexamined. They were the cause of the situation in which they became inevitable, and no single staff could have seen this, because seeing it required looking at all four.

Chapter Ten — The Ratchet

A ratchet is a wheel with asymmetric teeth and a pawl that rests against them. Turn it one way and it moves freely, tooth by tooth, with a satisfying click. Turn it the other way and the pawl catches. The mechanism does not prevent motion; it prevents motion in one direction. Every socket wrench, every hoist, every clock escapement depends on this, and it is one of the great inventions, precisely because a device that can only advance is enormously useful when advancing is what you want.

It is less useful when you have stopped wanting to advance and discover that the pawl is still there.

International crises have a pawl, and the last week of July 1914 is the clearest demonstration in the historical record. Between the twenty-third of July and the fourth of August, roughly a dozen significant acts were performed by the great powers. Not one of them was a step downward. Diplomacy continued throughout, proposals circulated, foreign ministers spoke of peace and several meant it, but the acts, as distinct from the words, went in exactly one direction.

Why should this be? There is no law of physics requiring it, and de-escalation is not difficult to describe. A government withdraws a demand, extends a deadline, returns troops to barracks, publicly accepts a formula it had rejected. These are all things a state can do in an afternoon.

The answer is that in a crisis every one of them costs something specific and immediate, while escalation’s costs are general and deferred. That asymmetry is the pawl, and it is built from four separate pieces, all of which happen to point the same way.

The first is the audience. A government that yields visibly pays at home, and pays fastest where politics is most contested. The Russian government in 1909 had accepted the Austro-Hungarian annexation of Bosnia after a German threat, and the humiliation was still being discussed in the Russian press five years later. By 1914 the Russian foreign minister was operating under the standing knowledge that a second such retreat would probably end his ministry and possibly something larger. Nothing comparable attended a decision to escalate, whose costs would arrive later and could be attributed to the enemy.

The second is the reading. In a crisis, every act is interpreted, and the interpretive frame is adversarial. An extension of a deadline is not read as generosity; it is read as an inability to sustain the pressure. This is not paranoia. It is often correct. But it means that the very gesture designed to create space is received as evidence that the maker of it can be pushed further, which invites further pushing.

The third is the military argument, which in 1914 was overwhelming and had a technical basis. Mobilization was a race with a large first-mover advantage, and standing down while an adversary continued meant surrendering days that could not be recovered. The soldiers who made this argument were not warmongers advancing a preference; they were describing their timetables accurately. And their argument had the peculiar property of being strongest exactly when de-escalation was most needed, since the closer the enemy was to readiness, the more expensive any pause became.

The fourth is the one nobody talks about, and it is the most fundamental. De-escalation takes longer than escalation. To escalate, one office issues an order. To de-escalate, someone must decide that the situation permits it, which requires an assessment of the adversary’s intentions, which requires consultation, which requires the deliberative interval that this book has been counting all along. Escalation is available to a single official in minutes. De-escalation requires a committee. And as the windows shorten, the committee becomes unavailable before the official does.

Put those four together and you have a mechanism that permits motion in one direction only, not because anyone designed it, but because four independent features of crisis all disfavor the same option.

It is worth being precise about what the ratchet does and does not claim, since the claim is easily overstated and would then be false. Crises plainly do de-escalate. Five European crises between 1905 and 1913 de-escalated, some of them from positions further advanced than the situation on the twenty-fifth of July 1914. The ratchet is not a law that escalation must continue. It is a bias, and its strength varies.

What varies it, principally, is time. Every one of the four mechanisms above weakens if the interval is long. Domestic audiences can be prepared for a retreat if there are weeks to prepare them. Adversarial misreadings can be corrected by a slow exchange of clarifications. Military arguments about lost days lose force when there are many days. And the committee required for de-escalation can actually meet.

So the ratchet is not an independent phenomenon. It is what the two clocks look like from the inside. When the reserve is comfortable, the pawl is loose and crises come back down, which is why Europe survived Morocco twice and Bosnia and the Balkans. When the reserve approaches zero, the pawl engages hard, and it engages hardest exactly when the need to disengage it is most urgent.

The practical consequence is uncomfortable, and it cuts against a great deal of well-meaning advice about crisis management. The standard counsel is that leaders should show restraint, offer off-ramps, avoid provocative rhetoric. All good advice, all delivered at the wrong point in the process, because by the time anyone needs it the interval required to act on it has already gone. Restraint is a slow behavior. It requires exactly the deliberative capacity that the crisis is consuming.

The intervention that works has to be structural and has to be installed beforehand: something that lengthens intervals automatically, without requiring anyone to choose lengthening at the moment when choosing has become impossible. What such a thing might look like is the subject of the last chapter of this book, and the answer, irritatingly, was worked out by stock exchanges rather than by chancelleries.

Chapter Eleven — Six Steps, Whatever Their Size

Here is a claim that sounds wrong and is not: the severity of the events in a crisis has almost nothing to do with how quickly it becomes uncontrollable. What matters is how many of them there are.

Most people’s intuition runs the other way, and reasonably so. We imagine a crisis as a quantity of pressure. Small provocations add a little, large ones add a lot, and when the total exceeds some threshold the vessel bursts. On that picture, the assassination of an heir to a throne is a very large addition indeed, and the question worth asking about 1914 is why that particular shock was big enough when previous shocks were not.

That question has occupied a great deal of scholarship and has never produced a satisfying answer, for the excellent reason that the shock was not especially large. Political assassination was distressingly routine in the years before 1914. A president of France, a president of the United States, a king of Italy, a king of Portugal, an empress of Austria, a prime minister of Spain and a prime minister of Russia had all been murdered within living memory, along with a Russian tsar and a great many lesser officials. None of these produced a European war. In the specific case, the murdered archduke was personally disliked by most of the court that afterward avenged him, his funeral was conducted with a shabbiness that scandalized observers, and the initial reaction of European chancelleries was closer to weary irritation than to alarm.

So the vessel-of-pressure model fails at the first test. The largest shock produced the smallest reaction, and the war arrived a month later, by which time the assassination had almost vanished from the diplomatic correspondence except as a pretext.

Now try the other model, the one this book has been building. Do not ask how big each event was. Ask what each event did to the interval available for responding to it.

On that accounting, every escalatory act has roughly the same effect regardless of magnitude, because what it does is shorten the window, and a window can be halved by a small act as easily as by a large one. An ultimatum with a twelve-hour limit compresses the situation exactly as much whether its demands are grave or trivial. What matters is the deadline, not the content.

Follow that through and something falls out that is counterintuitive but simple. If each step cuts the window by roughly a constant proportion, and the time required to respond stays put, then the number of steps to the crossing point is fixed by arithmetic. From a window of two days down to a floor of half a day, with each step cutting the remaining interval by a third or so, takes about four or five steps. It does not matter what those steps are. It matters that there are four or five of them.

Count the steps of the July crisis and you get roughly that number. The ultimatum. The rupture of relations. The declaration of war on Serbia. The Russian general mobilization. The German ultimatums and declarations. Whatever else one says about these events, they were not of comparable magnitude; the rupture of diplomatic relations between Austria-Hungary and Serbia was a formality, while Russian general mobilization was among the gravest decisions of the century. On the pressure model they should count for wildly different amounts. On the interval model they count the same, because each cut the remaining time by a similar proportion, and the interval model gets the answer right.

This is not merely an alternative way of describing the same events. It makes a different prediction, and the prediction is testable in principle. The pressure model predicts that severe crises are dangerous and mild ones are not, and that a run of mild confrontations should be harmless. The interval model predicts that a run of mild confrontations, arriving quickly enough, is more dangerous than a single severe one, because what kills a system is the count.

There is a domestic version of this that anybody who has run a hospital or an air traffic control room will recognize immediately. The dangerous shift is not the one with the catastrophe on it. Catastrophes command attention and resources; everything else stops and everyone helps. The dangerous shift is the one with nine ordinary problems arriving in ninety minutes, none of them serious, each requiring a decision, none of them permitting the previous one to be finished. Nothing on that shift is a crisis. The shift is the crisis, and it is made of small things.

I should mark the limits of the claim, since stated baldly it is too strong. Magnitude is not irrelevant. A sufficiently large single event can shorten every window at once and skip the intervening steps, which is roughly what a surprise attack does. And the constant-proportion assumption is an idealization; real sequences are ragged. What survives these qualifications is the ordering: for crises that develop through a sequence of acts rather than a single blow, the count of acts predicts the arrival of collapse better than the sum of their severities.

Which means the enduring question of the July crisis is misconceived. Generations have asked what made the summer of 1914 different, looking for the ingredient that was present then and absent in 1911. There may not have been one. The ingredient was the fifth step, and the fifth step was ordinary.

Chapter Twelve — War by Timetable and the Man Who Demolished It

In 1969 a British historian with a gift for provocation published a short book arguing that the First World War was caused by railway schedules. A. J. P. Taylor’s thesis, stated at its most compressed, was that the mobilization plans of the European powers were so complex, so interlocking, and so dependent on precise timing that once begun they could not be halted, and that the statesmen of 1914 were therefore prisoners of their own transport arrangements. The generals had built a machine; in July somebody pulled the lever; and the machine did what machines do.

It was a marvellous book, it sold well, and it is substantially wrong. The demolition took two decades and was performed by scholars working through the same archives Taylor had used, and the case against him is now settled well enough that no serious historian defends the strong version. Since this book advances an argument that will look, to a casual reader, like Taylor’s thesis with new vocabulary, it seems only decent to explain what was wrong with his and why the present one does not inherit the defect.

The demolition rests on a single observation, made most forcefully by Marc Trachtenberg in 1990 and elaborated by Jack Levy in the same volume. If mobilization had genuinely stripped statesmen of choice, the documents would show them being surprised by their own machinery: discovering too late what they had set in motion, protesting, being overruled by their generals. The documents show nothing of the sort. They show political leaders who understood precisely what mobilization entailed, who discussed the implications in detail, who weighed them against political objectives, and who then decided. Some decided badly. None was ambushed by a railway timetable.

The Russian ministerial discussions of the twenty-ninth and thirtieth of July are the crucial evidence. The Russian government understood that general mobilization would probably mean war with Germany, considered it at length, and ordered it anyway for reasons of policy, having concluded that the alternative was another retreat of the 1909 kind. That is a decision. It may have been a catastrophic one. It was not a machine operating on a passive government. Likewise the German leadership: Trachtenberg’s reading shows Bethmann Hollweg exerting himself considerably in the last days of July, at one point pressing Vienna hard to accept mediation, which is not the behavior of a man who believes the levers have stopped working.

So the strong timetable thesis fails, and it fails on evidence rather than on theory. This matters for the present argument, because if I were claiming that the men of 1914 were carried along helplessly by their own machinery, I would have to answer Trachtenberg, and I could not.

I am claiming something different, and the difference is worth stating with some precision, since everything in the rest of this book depends on it.

Taylor’s claim was about the option set: the statesmen could not choose otherwise, because the machinery permitted only one course. That is what the documents refute.

The claim here is about the interval: the statesmen could choose, and did, but the time available for choosing had fallen below the time their institutions required to produce a choice. Nothing in that claim requires anyone to be a prisoner. It requires only that a decision take longer to produce than the situation allows before the question is closed by somebody else’s act.

These two claims make different predictions about what the archives should contain, which is how one tells them apart. Taylor’s predicts documents in which political leaders are overridden, ignored, or informed after the fact by their general staffs. Those documents largely do not exist. Mine predicts documents in which political leaders decide correctly and too late; in which proposals are overtaken; in which a government is still assembling its response to the previous event when the next arrives; and in which participants complain that events have got ahead of them while remaining perfectly clear about what the events are. Those documents exist in quantity. The first chapter of this book was one of them: an emperor reading a document, forming an entirely sound judgment, acting on it promptly, and finding that the situation it addressed had ceased to exist during the morning.

There is a second difference, which concerns where the responsibility sits, and here the present account is harsher than Taylor’s rather than more forgiving. If the machinery removes choice, then blame attaches to whoever built the machinery, and it becomes a story about generals and engineers. If the machinery merely consumes time, then the political leaders retain full responsibility for what they chose within the interval available, and additional responsibility for having failed, over the preceding decade, to build anything capable of lengthening that interval. Trachtenberg’s statesmen, who understood everything and chose anyway, are not less accountable on my account. They are more so, because they cannot plead the machine.

I should add, since scholarly fairness requires it, that Taylor was not merely wrong. He was looking at something real and describing it with the wrong noun. The mobilization schedules did matter enormously. Their significance was not that they abolished choice but that they created irreversibility, which is a different property and the subject of the next chapters. A plan you cannot stop and a plan you cannot reverse are not the same object, and the second is quite bad enough.

Chapter Thirteen — The Partial Mobilization That Did Not Exist

The difference between a light switch and a dimmer is not a difference of degree but of engineering. A switch is two states and a wire. A dimmer requires a component that can throttle current continuously without burning up, and for the first fifty years of electric lighting no such component was cheap enough to install in an ordinary house. This is why old buildings have switches. Not because their designers preferred abrupt illumination, but because the intermediate option cost more to build than anyone thought it was worth.

Governments are full of switches, and almost none of them were designed by people who considered dimmers worth the price.

We have already met the Russian discovery of this in passing. In the last days of July 1914 the Russian ministers wanted a graduated response: something that would show Austria-Hungary that Russia would not stand aside, without signalling to Germany that a European war was beginning. Partial mobilization against Austria-Hungary alone seemed the obvious instrument, and the Tsar approved it on the twenty-ninth of July. Within hours the government was informed that this was not something the Russian army was equipped to do — that the schedules for a partial call-up, if improvised, would foul the arrangements for a general one, and that having gone partial the empire could not subsequently go general without weeks of chaos.

This chapter is about why the dimmer had never been built, because the answer is not laziness and is not confined to Russia.

Begin with the cost. Every additional option in a mobilization system multiplies the planning burden. A plan is not a document; it is a schedule of tens of thousands of train movements, each with a departure time, a route, a load, and a destination, coordinated so that men, horses, guns, and fodder converge in the right proportions. Producing one such schedule occupied a large staff for years. Producing a second, for a different combination of enemies, roughly doubled the work. Producing an intermediate case that could be converted mid-execution into either of the others was not twice the work but something considerably worse, since it required every branch point to be planned as well as every route.

Against that cost, consider how a staff officer would have justified the expenditure in, say, 1907. He would have had to argue that his government might one day wish to mobilize halfway. To a general staff, halfway mobilization is a contradiction. The purpose of mobilization is to be ready before the enemy; a plan that leaves you deliberately less ready is a plan for losing. Every professional instinct in the building says that intermediate states are where armies get destroyed.

Here is the trap, and it is worth stating carefully because the same trap is being built into systems today. The intermediate option is worthless from a military point of view and indispensable from a political one. It is worthless militarily because being half-mobilized is strictly worse than being mobilized. It is indispensable politically because it is the only move that says something without doing everything, and diplomacy consists almost entirely of saying things without doing everything.

The people who build the machinery are the military. The people who need the intermediate option are the politicians. The politicians do not discover which options exist until the day they need one, because the schedules are technical documents that no minister reads. And so the discovery is always made in the worst hour of the worst week, by men who assumed that the range of available actions matched the range of describable actions.

There is a general principle here which deserves a name, and I will call it the fallacy of the describable option. It is the assumption that because you can clearly state what you want to do, some part of your organization can do it. Nothing in the world guarantees this. Organizations can perform the actions they have rehearsed, and the set of rehearsed actions is always vastly smaller than the set of sensible ones, and nobody maintains a list of the difference.

The Russian case had a second feature which is even less comfortable. When the ministers were told that partial mobilization was impracticable, they did not abandon mobilization. They went to general mobilization, which was the option that existed. This is the characteristic behavior of a system with switches instead of dimmers: presented with a demand for moderation it cannot meet, it does not do nothing. It does everything, because everything is what has been built.

That deserves to be underlined, because it inverts a common intuition about restraint. We tend to think that a state which lacks intermediate options will therefore be cautious, since only the drastic move is available and drastic moves are frightening. The historical record suggests the opposite. A state that lacks intermediate options and feels compelled to act will take the drastic one. The absence of a dimmer does not produce darkness. It produces full brightness, at the moment when a little light was wanted.

Nothing about this is confined to 1914 or to railways. Consider the modern equivalent. A government facing a cyber intrusion of ambiguous origin would like to respond proportionately: something that signals capability and resolve without committing to escalation. Whether such a response exists depends on whether somebody built it, in peacetime, and rehearsed it, and obtained legal authority for it in advance. If nobody did, the available options will be a diplomatic protest, which signals nothing, and something considerably larger, which signals a great deal. The middle of the range is empty for exactly the reason the Russian middle was empty: it is expensive to build, of no interest to the specialists who would have to build it, and desperately wanted by exactly one group of people, who will not discover its absence until the night they reach for it.

Chapter Fourteen — Turn the Army East

On the evening of the first of August 1914, in Berlin, the German Emperor was handed a telegram from his ambassador in London and understood it to mean that Britain would guarantee French neutrality if Germany refrained from attacking France. He was delighted. He called for champagne. He then sent for the chief of the general staff and instructed him to turn the army around and march east against Russia alone.

Helmuth von Moltke the younger, nephew of the great Moltke and a man of fragile nerves in the best of circumstances, replied that this could not be done. The deployment of millions of men was in motion. The schedules could not be improvised; the army would arrive at the frontier as a disorganized mob rather than as an instrument of war. He said, according to his own later account, that the Emperor was asking him to undo the work of a generation, and that it was not possible.

The Emperor’s reply has come down in a form too good to be entirely trustworthy, but the substance is not in doubt: your uncle would have given me a different answer.

Within hours the telegram was clarified. The ambassador had made no such offer; the message had been misread; Britain had guaranteed nothing. The Emperor sent for Moltke again and told him to do as he liked. Moltke wrote afterward that he never recovered from that evening, and by the standards of a man who suffered a collapse three months later at the Marne, this may be literally true.

The episode is usually told for its human interest, and it has plenty. But it contains the mechanical fact that this chapter is about, and the fact is not the one the story appears to teach.

It appears to teach that the machine had taken over, which is the thesis the previous chapter dismantled. And in fact Moltke’s claim was not strictly true. A German eastern deployment plan had existed and had been maintained for years; it had been dropped from the annual planning cycle in 1913, as a cost-saving measure, on the reasoning that a war against Russia alone was implausible. So the redirection was not physically inconceivable. It was merely no longer prepared, and preparing it again in the middle of a mobilization was a different order of problem.

What Moltke was really saying — and what any staff officer in his position would have said — is that the cost of reversing exceeded the cost of continuing. That is a different statement from impossibility, and it is far more general and far more dangerous.

Here is the shape of it. To begin mobilizing, a government needs a decision and an order. To stop mobilizing, it needs a decision, an order, and then it must absorb a set of costs that did not exist before it started: the disorganization of the force, the days of advantage surrendered to an enemy who does not stop, the domestic humiliation of a visible reversal, and the demonstration to allies and adversaries that this government’s threats can be walked back. None of these costs was present at the moment of entry. All of them are present at the moment of exit, and they are produced by the entry itself.

Systems with this property are common and physicists have a word for them. A ratchet, from an earlier chapter, permits motion in one direction. This is subtler: motion in both directions is permitted, but the pressure required to go back is greater than the pressure that brought you in, and the difference grows with how far in you have gone. Push a heavy door until it swings past its hinge point, and it closes itself; getting it open again requires more force than closing it did. Every year of accumulated institutional commitment adds to the gap.

Once you have the shape, you find it everywhere in the crisis, and it explains behavior that otherwise looks like stubbornness. The Austro-Hungarian refusal to accept mediation after the declaration of war was not simply obstinacy. Having declared war, the monarchy could not unsay it without announcing that it could be pushed, which was the one thing the whole exercise had been designed to disprove. The Russian refusal to rescind general mobilization was not bloodlust. Having ordered it, the empire could not countermand it without surrendering days it could not recover and repeating the humiliation of 1909.

In each case the actor was perfectly free to reverse and perfectly rational not to, which is the exact situation this book keeps arriving at from different directions.

The property has a consequence that reaches beyond July 1914, and I will state it here because the last chapters of the book will need it. If exit costs more than entry, then any system that enters such a state under time pressure will remain in it long after the reasons for entering have evaporated. This is not a claim about war alone. It is a claim about states with hysteresis, of which mobilization is one, an occupation is another, an emergency legal regime is a third, and a monetary intervention is a fourth. The reasons for entry are usually specific and often good. The reasons for remaining are structural and require no one’s endorsement.

Which is why the two questions people ask about wars — why did it start, and why did it go on so long — turn out to have the same answer rather than different ones. We will return to that in the twenty-first chapter, having done some more groundwork first.

Chapter Fifteen — Halt in Belgrade

The compromise proposal that might have prevented the First World War can be stated in a sentence. Austria-Hungary would occupy Belgrade and a strip of territory around it, hold this as a pledge of Serbian good behavior, and negotiate the outstanding points from that position while the other powers guaranteed the arrangement. The Kaiser proposed it on the twenty-eighth of July. Sir Edward Grey had been circling something similar for two days. The German chancellor forwarded a version of it to Vienna. It is the great might-have-been of the crisis and appears in every account.

It was also, on examination, a proposal that satisfied nobody, and this chapter is about why the middle of a dispute is not always a safe place to stand.

Consider what each party would have received.

Austria-Hungary would have obtained the occupation of an enemy capital and a promise of further negotiation. From Vienna’s perspective this was worse than useless. The entire purpose of the exercise was to demonstrate that the monarchy could act decisively without being brought before a European tribunal, and the proposal ended with the monarchy before a European tribunal, holding a city as a bargaining chip while the powers debated the terms of its return. It converted a punitive war into precisely the mediated settlement that the whole operation had been designed to escape.

Russia would have been asked to accept the occupation of the capital of its client by the power it had failed to face down in 1909. The occupation would be temporary and guaranteed. That is very nice on paper and quite unbearable in a chancellery that had spent five years being told it had abandoned the Slavs once already. Russia was not being asked to accept a small concession. It was being asked to accept a highly visible one, in the newspapers, with photographs.

Serbia would have been asked to surrender its capital to a foreign army as a security deposit against its own future conduct.

There is a fourth party often forgotten, which is the military situation. Belgrade sat directly on the frontier, across the river from Habsburg territory, which is why the Serbian government had already evacuated it and moved south. Occupying Belgrade was militarily almost meaningless: it was the easiest thing the Austro-Hungarian army could do and the least useful. The proposal thus offered Vienna a prize it did not want, at a price Russia could not pay, for the sake of a negotiation Vienna had gone to war to avoid.

Now generalize, because the general point is the reason this chapter exists.

There is an assumption buried in almost all thinking about negotiation, and it is so natural that it is rarely examined. The assumption is that if each party finds its own position acceptable, then some intermediate position must be acceptable to both — that between two tolerable extremes there lies a tolerable middle, and the work of diplomacy is to find it.

This is simply false, and it is false in a way that can be demonstrated in a sentence. Suppose two parties dispute a matter in which each stands to lose far more from the other’s victory than it stands to gain from its own. Then a fifty-fifty outcome delivers to each party half of a large loss and half of a small gain, which nets out worse for both than either clean result. The middle is not a compromise between two acceptable states. It is a place where both parties bear the costs of conflict without obtaining the benefits of resolution.

This describes an enormous number of real disputes, particularly those concerning prestige, sovereignty, and the fate of client states, where the value of winning is modest and the cost of visibly losing is severe. And it describes July 1914 with painful accuracy. Half a punitive expedition, half a preserved client: occupation without resolution, humiliation without submission, and every party paying for a war it had not obtained.

The practical lesson is not that compromise is useless, which would be an absurd conclusion. It is that compromise by interpolation — splitting the distance between stated positions — is only safe when the parties’ losses are roughly proportional to their gains, and that when they are not, the mediator’s job is not to find the midpoint but to enlarge the space until an option exists that both sides can accept. Enlarging the space means introducing something that was not on the table: a face-saving formula, a third-party guarantee, a side payment, a redefinition of what is being disputed.

Enlarging takes time. It requires proposals to be drafted, circulated, revised, and considered by governments in several capitals. Grey’s conference proposal was an attempt at enlargement, and its fate is instructive: it required assembling ambassadors, which required days, and it was made on the twenty-sixth of July into a situation whose remaining span was about seventy-two hours.

So the two failures compound. The interpolated compromise was unacceptable because of the structure of the dispute. The enlarging compromise was unavailable because of the structure of the clock. The one that could have worked needed time that had already gone, and the one that fitted in the time remaining could not have worked at all.

That is the specific reason the July crisis produced no settlement, and it is more depressing than the usual account, in which some particular statesman failed to seize a chance. There was a chance. It was on the table on the twenty-eighth of July, in the handwriting of a head of state. It was the wrong shape, and the right shape took a week to make.

Chapter Sixteen — Abilene Has a Road Back

On a July afternoon in Coleman, Texas, sometime in the nineteen fifties, four adults sat on a porch playing dominoes. It was a hundred and four degrees. There was a fan going and lemonade in the kitchen and nobody had any particular complaint. Then the father-in-law suggested they drive to Abilene for dinner.

Abilene was fifty-three miles away. The car was a Buick without air conditioning. The drive was across dust, in heat, in both directions. The food, when they got there, was bad. They returned four hours later, sweating and exhausted, and someone remarked insincerely that it had been a great trip. The mother-in-law said she would rather have stayed home but had gone along because the other three seemed enthusiastic. The wife said she had never wanted to go. The son-in-law said he had agreed only to keep the others happy. The father-in-law said he had merely been making conversation and had assumed everyone was bored.

Four people who all wanted to stay home had driven a hundred and six miles across the Texas desert to eat a bad meal. The management theorist Jerry Harvey published the story in 1974 as a parable about organizations, and it has been famous ever since under the name he gave it, the Abilene paradox: the management of agreement, as opposed to the management of conflict, and the peculiar capacity of groups to take collective action that every member privately opposes.

Anyone who has read this far will feel the pull of the comparison. Four people go somewhere none of them wants to go; five great powers go to a war none of them wants. It is the obvious frame and I want to dismantle it, not because Harvey was wrong about porches in Texas, but because the fit fails at three points, and each failure teaches something.

The first failure is about preferences. Abilene requires that the private preferences coincide. All four wanted to stay home; the whole mechanism is that a real consensus existed and went undetected. Nothing of the kind was true in July 1914. Vienna wanted a punitive campaign, Berlin a short continental war, St Petersburg a demonstration without fighting, Paris a defensive war in the correct sequence, London to be left out of it. These are five different destinations, not a suppressed unanimity about the porch. Abilene is a failure to notice agreement. July 1914 was a genuine disagreement whose parties were each individually satisfiable.

The second failure is about the option set. The trip to Abilene was on the table. It was proposed aloud, considered, and chosen. What went wrong was that it was chosen for the wrong reasons; the outcome itself was one of the options under discussion. The First World War was not on anybody’s table. No European statesman in July 1914 was weighing a four-year continental war ending in the destruction of four empires against the alternatives. That outcome was not a rejected option or a reluctantly accepted one. It was absent from the deliberation entirely, and it arrived as the product of five separate plans interacting.

The third failure is the decisive one and it concerns reversibility. The Abilene paradox is a story about a mistake that could have been corrected at any moment, at a cost of one embarrassing sentence. Somebody had only to say that it was too hot and they would rather not. That is the entire force of the parable: correction was available, cheap, and continuously present, and the family’s inability to reach for it is what makes the story funny and useful. Mobilization had no such reverse gear, as the previous chapters have established at some length. The father-in-law could have turned the Buick around in the road. Moltke could not turn the army around, or rather could have, at a price he was not prepared to pay and no one was prepared to make him pay.

There is a fourth difference which is really a difference of mechanism rather than of conditions. Abilene is a failure of speech. Nobody said what they thought. The parable’s remedy is honesty: say it out loud, and the trip does not happen. In July 1914 the participants said what they thought, at length, in writing, promptly by the standards of every previous crisis of the era. The Kaiser said plainly that the Serbian reply removed the grounds for war. Grey said plainly what Britain might do. The German ambassador in London said plainly and repeatedly that Britain would not stand aside. Everyone spoke. The speech arrived late, or arrived on time and was overtaken, or arrived and was correctly understood by men who no longer had the hours required to act on it. Honesty was not the missing ingredient. Honesty was abundant. Time was missing.

The same three-part test disposes of the neighbouring explanation, groupthink, which Irving Janis developed from studies of American foreign policy fiascos and which describes the suppression of dissent inside a cohesive decision-making body. Groupthink requires a body: a room, a set of people who see each other, a shared conversation in which dissent might have been voiced and was not. There was no such room in July 1914. There were six governments in six capitals communicating by ciphered telegram with delays measured in hours. You cannot have a failure of group dynamics without a group.

Now, having spent a chapter on demolition, I owe Harvey a concession, and it is a real one.

There is an Abilene component in the July crisis, and it is located precisely where his mechanism predicts: in mutual estimation of the other party’s expectations. The German assurance to Vienna in early July was shaped by a belief about what Vienna required. Vienna then acted on a belief about what Berlin had authorized. Each was reading the other’s expectations rather than the other’s stated position, and each read them as more demanding than they were. That is the Abilene mechanism, operating between capitals rather than around a card table, and it accelerated the sequence.

But accelerating is not causing, and there is a test which distinguishes them. Remove the mutual misestimation entirely. Suppose Berlin and Vienna understood each other’s actual preferences perfectly. The ultimatum still goes in on the twenty-third of July with a forty-eight hour limit, because Vienna wanted a punitive war on its own account and had wanted one for eight years. The rupture still follows, the declaration still follows, Russia still mobilizes, and the windows still contract past the interval any government needed. What is removed by curing the misunderstanding is perhaps a day. What is not removed is the crossing.

That is why this book puts the clocks at the centre and the psychology at the edge. The psychology is real, it is well documented, and it makes everything worse. But a crisis in which everyone understands everyone perfectly and nobody has time to act still ends in a war, whereas a crisis in which everyone misunderstands everyone and there are three weeks to sort it out ends, historically, in a conference at which the misunderstandings are sorted out. We know this because it happened five times between 1905 and 1913, which is the subject of the next chapter.

Chapter Seventeen — Why Not Nineteen Eleven

There is a question about the summer of 1914 that everybody asks and that has no answer, and the absence of an answer is not a gap in the scholarship. It is a result.

The question is: what was different? Europe had passed through a series of confrontations in the preceding decade, several of them at least as dangerous as the one that followed the assassination, and each had been resolved. What ingredient was present in July 1914 and absent in the summer of 1911, when a German gunboat appeared off Agadir and the French and British governments spent several weeks contemplating a war that did not happen?

Let us take the sequence seriously, because it is usually waved at rather than examined.

In 1905 and 1906 the German government challenged French primacy in Morocco, the Kaiser landed at Tangier, and the affair was settled by an international conference at Algeciras which handed Germany a diplomatic defeat. In 1908 and 1909 Austria-Hungary annexed Bosnia and Herzegovina, Russia protested, Germany delivered what amounted to an ultimatum in St Petersburg, and Russia backed down. In 1911 Germany sent a warship to Agadir, the British Chancellor of the Exchequer made a public speech that was read in Berlin as a threat of war, financial markets in Germany went into something close to panic, and the affair was settled by a colonial exchange in central Africa. In 1912 and 1913 the Balkan wars twice brought Austria-Hungary and Russia to the edge, with both partially mobilizing along their common frontier, and both times an ambassadors’ conference in London produced a settlement.

Five confrontations. Five resolutions. In several of them the situation had gone further than it had gone by the evening of the twenty-fifth of July 1914.

Now, if we are hunting for the special ingredient of 1914, we have to explain why each of those five lacked it. And here the search runs into trouble, because every candidate ingredient was present in at least one of the five. Alliance obligations: present throughout. Offensive doctrine: present from 1905. Nationalist press agitation: present, and more hysterical in 1908 than in 1914. Assassination: the Russian prime minister was murdered in 1911 and nothing followed. German willingness to threaten: demonstrated in 1909, with success. Russian determination not to yield: proclaimed continuously after 1909, and not acted on in 1912 or 1913.

Every ingredient of 1914 can be found somewhere in the preceding decade, in a crisis that ended peacefully. This is the sort of result that ought to prompt a change of question, and it very rarely does.

Consider an analogy from an entirely different field. A patient has a mild heart attack at the age of seventy-one. The cardiologist is not asked what was special about that Tuesday. Nothing was special about that Tuesday. The patient had been accumulating risk for four decades, the arteries had been narrowing throughout, and the event occurred when it occurred because the probability of it occurring on any given day had been rising steadily until it happened. The particular Tuesday has no properties worth investigating. It was simply the one where the accumulated hazard finally cashed out.

We understand this perfectly in medicine and refuse to apply it to history, because historical narrative demands causes proportionate to their effects. A war that killed twenty million people ought to have a cause of comparable magnitude, and the discovery that its immediate cause was ordinary feels like an insult to the dead. It is not an insult. It is where the evidence points, and it points there so consistently that the century of failure to find the special ingredient should be read as evidence rather than as an unfinished task.

The framework of this book supplies a mechanism for why the hazard was rising, and it is the subject of the next two chapters, so I will state it here only as a claim: each survived crisis reduced the reserve available for the next one. The 1909 humiliation lowered the threshold at which Russia would refuse to yield again. The Balkan confrontations of 1912 and 1913 led every general staff to shorten its preparatory procedures. The arms and service laws of 1913 in Germany, France, and Russia raised the cost of remaining unmobilized while a neighbour mobilized. Each of these was a reasonable response to a specific near miss. Each brought the two clocks closer together.

So the correct form of the question is not what was different about 1914 but how many crises the system could take, and the answer appears to be five. Not because the fifth was worse than the fourth, but because the reserve was consumed by the count.

That reframing has one consequence that is genuinely uncomfortable and that I do not want to soften. If the terminal crisis has no distinguishing properties, then nothing about the terminal crisis can be studied to prevent the next one. All the effort that has gone into the July crisis — the hour-by-hour reconstructions, the arguments about who read which telegram when, and yes, several chapters of this book — is the study of a Tuesday. It is fascinating and it is not where the leverage is. The leverage was in 1909, and in 1911, and in 1913, in the quiet decisions taken after each escape about how to be better prepared next time, every one of which made the next time worse.

Chapter Eighteen — The Regulation of Nineteen Thirteen

Among the least-read documents of the twentieth century is a Russian administrative regulation approved by the Tsar in March 1913, bearing a title that translates as the Statute on the Period Preparatory to War. It runs to some pages of bureaucratic prose and concerns the measures a government may take when war is possible but not certain: the recall of officers from leave, the readying of railway stock, the movement of supplies toward frontiers, the imposition of controls on communications.

Before 1913 such measures required specific authorization, case by case, from the highest level. After 1913 a defined set of them could be ordered on standing authority, without any formal decision of the kind that would have to be announced.

The change was entirely sensible. It arose directly from the Balkan crises of 1912, during which the Russian government had found itself unable to take sensible precautions without either doing nothing or announcing a mobilization it did not want to announce. The regulation solved a real problem experienced by real officials in a genuine emergency, and any competent administration would have done something similar. Several did; comparable adjustments were made in Germany and Austria-Hungary in the same period.

It also converted a set of deliberated actions into automatic ones, and in doing so it removed several days from the interval between peace and war without anybody deciding to remove them.

This is the mechanism I want to isolate, because it is the quiet one, it operates in peacetime, and it is running today in every government on earth.

Call it the migration of decisions. In any organization there are actions that require a decision and actions that are simply done. The boundary between the two moves, and it moves almost always in one direction. When an emergency reveals that some necessary action was slowed by the need to obtain authority, the obvious remedy is to grant the authority in advance. Nobody argues against this, because the alternative is to insist on delay for its own sake, which sounds absurd when stated aloud.

Each individual migration is defensible. The aggregate is a system in which more and more can happen without anyone choosing it, and the aggregate is never examined, because no institution keeps a register of what has migrated.

Note the perverse timing. Migrations occur after near misses, which is to say after the moments that most vividly demonstrate the danger. The organization has just had a fright. It examines its performance, finds delay, and removes the delay. It is at its most safety-conscious precisely when it makes the change that reduces its safety, and it experiences the change as a safety improvement, which in a narrow sense it is: next time, the necessary precautions will be taken faster.

What is not visible from inside is that the thing removed was not merely delay. It was the occasion for a decision. When the recall of officers from leave requires the Tsar’s approval, somebody has to bring the question to the Tsar, and in the course of bringing it somebody has to formulate what is happening and why, and someone in the room may say that this seems to be going rather far. When it happens on standing authority, no one formulates anything. The measures are taken by officials doing their jobs, correctly, and the first time the political level engages with the situation is when it has already changed.

In July 1914 the Russian preparatory measures were begun on the twenty-fifth and twenty-sixth, before any mobilization was ordered, under the 1913 regulation. German intelligence detected them, as it was bound to. From Berlin these looked like the early stages of a mobilization being concealed, which in a technical sense they were, since concealment of exactly this kind was among the regulation’s purposes. The German response was to accelerate its own preparations. Neither government had made a decision that it would have described as a step toward war.

I said that this mechanism is running today, and I want to make that concrete before leaving it, because the modern instances are not obscure.

Every standing rule of engagement is a migrated decision. Every pre-delegated authority to respond to an incoming attack is a migrated decision, and the delegation of nuclear release authority under conditions of decapitation is the most consequential one ever made. Every automated defensive system that engages targets without a human in the loop is a migration, and the argument for each is identical to the argument of 1913: the interval was insufficient, so the authority was granted in advance. Every one of these was adopted after an incident that demonstrated the cost of hesitation.

There is no organization anywhere whose job is to add up the migrations and ask what fraction of a nation’s path to war can now be traversed without a political decision. It is nobody’s portfolio. It was nobody’s portfolio in 1913 either, and the document that mattered most that year was an administrative regulation that no minister of any European power outside Russia had read, and that no historian looked at closely for fifty years.

Chapter Nineteen — Survival Is Depletion

Geriatricians use a word that has no equivalent in ordinary speech, and once you have it you cannot stop seeing what it describes. The word is frailty, and in medicine it does not mean weakness or illness. It means the loss of physiological reserve.

A healthy person of thirty and a frail person of eighty may perform identically on an ordinary day. Both walk to the shops, both digest lunch, both sleep. The difference appears under stress. Give both of them a chest infection. The young body mounts a response, runs a fever, recruits reserves it was not using, and recovers in a week. The frail body has no reserves to recruit. The same infection produces a cascade: the fever precipitates confusion, the confusion produces a fall, the fall produces a fracture, the fracture produces immobility, and a person who was walking to the shops a fortnight ago is dead of something that inconvenienced a thirty-year-old for six days.

What makes frailty treacherous is that it is invisible until tested. There is no symptom. The reserve is not something you feel; it is something you have, and you discover its absence at the moment you need it. And because ordinary days do not test it, a frail person can accumulate an impressive record of ordinary days, and can reasonably conclude from that record that all is well.

Now consider a state, and consider what the record of survived crises actually tells you.

Between 1905 and 1913 Europe passed through five confrontations and emerged from each. From inside, this looked like a demonstration of robustness. The system had been tested repeatedly and had held. Statesmen said so at the time, sometimes with self-congratulation: the mechanisms of consultation and conference had proved themselves, the alliance system had produced stability rather than war, the concert of Europe still functioned. As late as the spring of 1914 it was a commonplace among informed observers that the great powers had become adept at managing exactly these disputes, and there was a reasonable body of evidence for it.

Every one of those escapes had consumed something.

The Bosnian crisis of 1909 ended with Russia yielding to a German demand, and the yielding taught the Russian government a lesson it applied for the next five years: that a second retreat would be politically unsurvivable. That is a reduction in reserve. It means that the range of situations in which Russia can climb down has narrowed, permanently, as a direct consequence of having climbed down once.

The Balkan confrontations of 1912 and 1913 ended peacefully and produced the Russian preparatory-period regulation of the previous chapter, along with comparable adjustments elsewhere. That is a reduction in reserve. Steps that had required a decision now happened automatically, which removed days from the interval available for deliberation.

The Agadir crisis of 1911 ended in a colonial settlement and a German financial panic, and produced in Germany a conviction that the country had been humiliated by a bluff, together with the army bill of 1913. France answered with the three-year service law and Russia with its great rearmament program. Each of these was a rational response to a specific fright. Together they meant that by 1914 the cost to any power of being the last to mobilize had risen sharply, which shortens every window in the system.

So the record of five successes is also a record of five withdrawals from an account that was never credited. And here the medical analogy earns its place, because it explains the specific error that the European statesmen made, which was not stupidity but a correct inference from the wrong data.

They inferred robustness from survival. That inference is valid only if the system is unchanged by the surviving. For a young body it roughly is; an infection at thirty leaves you much as it found you, and having recovered from one is genuine evidence you will recover from another. For a frail body it is exactly backwards: each episode leaves less behind, and the record of recoveries is a record of depletion. The more impressive the history of survival, the closer the system is to the episode it will not survive.

I want to be careful here, because the claim can be stated in a form that is false. It is not the case that surviving a crisis always weakens a system. Institutions do learn, and some responses to near misses genuinely add reserve rather than consuming it. The direct communications link between Moscow and Washington, installed after 1962, made the interval for clarification shorter without shortening anyone’s window, which is a real gain. It is the one unambiguous instance I know of in the twentieth century where a great power responded to a fright by making deliberation faster rather than by making action automatic.

That it is possible to point to a single clear example, and that it took a crisis in which the world came nearer to destruction than in 1914, tells you how rare the favorable response is. The default institutional reaction to a near miss is to prepare more thoroughly, and preparing more thoroughly means deciding more things in advance, and deciding more things in advance is the withdrawal.

There is a practical implication, and it is one that no government has ever adopted, for reasons that will be obvious to anyone who has worked in one. The relevant statistic for crisis risk is not the current temperature of relations. It is the count of confrontations survived since the last genuine addition of reserve. A state that has come through four confrontations in six years should regard that fact with alarm rather than satisfaction, and should say so publicly, which no state will ever do, since announcing that your crisis management record is a liability is not a thing that survives a press conference.

Chapter Twenty — Avoidable Everywhere, Inevitable in Aggregate

Two people are arguing about the First World War and neither of them is wrong, which is why they have been arguing for a hundred years.

The first says the war was avoidable. Point at any moment in the crisis and there was an act that would have prevented it. Vienna could have accepted the Serbian reply, which conceded nearly everything. Berlin could have withheld its assurance. Russia could have delayed general mobilization by three days. Britain could have declared its position early enough to deter. At every point there was a door, and someone chose not to walk through it, and the choices were free.

The second says the war was inevitable. Look at the structure: an alliance system that converted local disputes into general ones, general staffs committed to offensive doctrines with first-mover advantages, a rising power and a declining one and a frightened one all convinced that time was against them, and a decade of confrontations trending in one direction. Given all that, something like 1914 was coming. If not that July then another July.

These positions are treated as opposites and are argued as opposites. They are not opposites. They are answers to different questions, and once the questions are separated both answers turn out to be true at once, which is a considerably more interesting result than either party winning.

Here is the separation. The first person is quantifying over individual moments: for each moment, was there an available act that would have prevented the outcome? The second is quantifying over the sequence: across the whole run of moments, was the outcome going to arrive at some point? These are different questions and their answers are logically independent. Yes to the first does not imply no to the second.

An illustration, deliberately banal. Consider someone who drives home from a bar slightly drunk twice a month for twenty years. On any given night the probability of a catastrophe is low. He can point, correctly, to any particular night and observe that he was in control, that he was driving carefully, that nothing happened and nothing was going to happen. Each individual night is genuinely survivable and he genuinely survives it. Over twenty years and five hundred trips, the accumulated probability approaches certainty. Both statements are true. Every trip was avoidable. The eventual crash was not.

The technical name for this is a first-passage problem: the question is not whether any particular trial produces the event but when the first one does. And first-passage problems have a property that is deeply counterintuitive and that explains why the historiography of 1914 has been stuck. The trial on which the event occurs need not differ in any respect from the trials on which it did not. Studying it for distinguishing features is a category error. It was the one where the dice came up, and dice do not have reasons.

This dissolves the argument between our two people, but it also does something more useful, which is to tell each of them where to look.

The avoidability party has been studying the terminal crisis with enormous care, and the previous chapter suggested this is the study of a Tuesday. If the terminal crisis is undistinguished, then no amount of detail about it will yield a lesson, and the century of hour-by-hour reconstruction has yielded, in the way of practical lessons, remarkably little. This is not a criticism of the scholarship, which is magnificent. It is an observation about where the leverage sits.

The inevitability party has the right level of analysis and usually the wrong variables. Alliance systems and offensive doctrines are real and they matter, but they are properties of the whole period, present throughout the decade in which nothing happened. What changed across the decade was the reserve, and the reserve changed for the reasons given in the last three chapters, none of which appear in the standard structural account.

So the useful question is neither “why 1914” nor “was it bound to happen” but a third one that both parties have skipped: how many confrontations could that system take, and what was consuming its capacity? That question has a definite answer in principle, it points at the pre-crisis decade rather than at the crisis, and it identifies interventions that are actually available, since you cannot go back and give Grey better instincts but you can, in the general case, decline to convert deliberated measures into automatic ones after a fright.

There is one more consequence, and it is the reason this chapter sits where it does rather than at the end of the book. If the argument is right, then the practice of assessing danger by looking at current tensions is close to worthless. Tensions are visible, they are what fills the newspapers, and they are the equivalent of asking a frail patient how he feels today. The answer is usually fine. The relevant measurement is of reserve, which nobody takes, which no ministry is responsible for, and which as far as I am aware appears in no national risk register anywhere in the world.

Chapter Twenty-One — The Four Years Afterward

By the summer of 1917 a great many serious people in every belligerent country had concluded that the war should stop.

This was not the sentiment of cranks. The Reichstag passed a resolution in July calling for a peace without annexations. The Pope issued a peace note in August proposing a return to the pre-war situation with adjustments. The Austrian emperor, who had inherited a throne and a catastrophe together, opened a secret channel to the French through his brother-in-law, offering terms that were serious enough to alarm his German allies when they eventually learned of them. In Britain a former foreign secretary published a letter in the press arguing that the continuation of the war was destroying European civilization, and was widely denounced for saying what a substantial part of the cabinet privately suspected. In Russia the government that had come to power in March spent its short life trying to find a formula for ending a war it could no longer fight.

None of it worked. The war went on for another fifteen months and killed several million more people, and the ending, when it came, arrived through military collapse rather than agreement.

The usual explanation is that the war aims had become irreconcilable, which is true and does not explain much, since war aims are always irreconcilable until somebody adjusts them. The question is why nobody adjusted, and the answer is the mechanism from the fourteenth chapter, operating over years instead of hours.

Recall the property: exiting a state costs more than entering it, and the difference grows with the depth of commitment. In August 1914 the cost of not entering the war was, for each power, a diplomatic humiliation and a period of political difficulty. In August 1917 the cost of leaving it was of an entirely different order, and the difference had been manufactured by the war itself.

Take the components separately, because they compound.

There is the debt. Every belligerent had borrowed enormously, and much of the borrowing was justified to lenders and to publics by the prospect of a victorious settlement in which the enemy paid. A negotiated peace on pre-war terms leaves the debt and removes the means of servicing it. The financial arithmetic that made the war affordable in 1915 made ending it unaffordable by 1917.

There is the dead. This is the component that is usually treated sentimentally and is in fact the most rigorously structural of the lot. A government that has presided over a million deaths cannot return to the status quo ante, because the status quo ante is the condition in which those deaths purchased nothing. The requirement is not psychological weakness. It is a political fact about what a government can survive saying. The larger the sacrifice, the larger the settlement required to justify it, and the settlement required grows faster than the settlement obtainable. This is precisely the hysteresis relation: the price of exit rises with the depth of entry.

There is the alliance structure, which by 1917 included formal undertakings not to conclude separate peace, so that any party wishing to leave had to bring its partners or break its word.

And there is the domestic transformation. Four years of war had produced in each country a set of institutions, industries, and political careers whose existence depended on continuation. This is not a conspiratorial claim about profiteers; it is an observation that a system optimized for a task acquires a constituency for the task.

Put these together and the position in 1917 was that every major belligerent contained a substantial body of opinion favouring a negotiated end, and no major belligerent could act on it, because the act required a government to say publicly that the previous three years had been a waste, and no government can say that and remain a government.

The parallel with July 1914 is exact and worth stating in full, because it is the point of the chapter and the reason it closes the historical half of this book.

In July 1914 the outcome was produced by a situation in which every actor could see what should be done and none could do it in the time available. In 1917 the outcome was produced by a situation in which every actor could see what should be done and none could do it at the price required. The first is a failure of interval; the second a failure of reversibility. They are the two faces of the same structural property, which is that systems with pre-committed defaults and asymmetric exit costs will enter states they did not choose and remain in them after the reasons have gone.

Which means the two great questions about the First World War — why did it begin, and why did it not stop — are not separate questions with separate answers. They are one question. The mechanism that made entry unavoidable in the last week of July is the mechanism that made exit unaffordable for the following fifty months, and any account that explains one without the other has explained neither.

That closes the case for 1914. The remainder of this book is about the fact that we did not dismantle the mechanism. We industrialized it.

Chapter Twenty-Two — Thirteen Days, Deliberately Slowed

If you wanted to design an experiment to test the argument of this book, you would need two crises with the same structure and different outcomes. The structure would have to include the essential features: two or more states with irreversible acts available, mutually foreclosing options, prepared plans on both sides, and a defeat condition each side regarded as intolerable. Then you would vary one thing — the management of the intervals — and see whether the outcomes differed.

History has run this experiment. The second trial took place in October 1962 and its subject was Cuba.

The structural resemblance to July 1914 is closer than the usual accounts suggest, and it is worth laying out before the differences, because the differences are the point and they mean nothing if the cases are not comparable.

Both crises began with a discovery rather than an attack: a shooting in one case, a photograph in the other. In both, the discovering power spent an initial period deliberating in secret while the other side believed nothing was happening. In both, the eventual response was an ultimatum in substance if not in name. In both, the participants had detailed prepared plans whose execution had been rehearsed and whose assumptions had never been checked against the other side’s plans. In both, alliance obligations meant that a bilateral quarrel implicated other states. In both, at least one participant believed that the balance was shifting against it and that acting sooner was better than acting later.

And in both, the professional military advice on the decisive days was to strike, promptly, before the enemy completed his preparations. The American chiefs of staff pressed for air strikes followed by invasion, and continued to press for them after the crisis had been settled, on the grounds that a genuine opportunity had been passed up. Their arguments were of the same form as those made in every European capital in July 1914 and were not obviously worse.

So the coupling was there, the plans were there, the first-mover logic was there, and the stakes were higher by a factor that does not need arithmetic. It did not collapse. Why not?

The answer this book proposes is not that the men were better. Some of them were; the crisis produced an unusually thoughtful performance from an American president who had performed poorly eighteen months earlier at the Bay of Pigs, and whose principal lesson from that failure appears to have been that plans presented by confident experts should be interrogated rather than approved. But the personnel explanation cannot carry the weight, because it has to explain not just good judgment but the availability of the time in which to exercise it, and time is not a personal quality.

The answer is that in 1962, for the first time in the history of great-power confrontation, the intervals themselves were treated as a variable to be managed.

Three interventions stand out and each gets its own treatment in what follows, but the summary is this. The window was deliberately lengthened rather than shortened. The authorization process was pre-convened rather than assembled on demand. And at the decisive moment the ratchet was deliberately broken by a response that was less escalatory than the input that provoked it.

That last one deserves a note here because it is so rare. On the twenty-sixth of October a long, personal, and conciliatory message arrived from the Soviet leader. On the twenty-seventh a second message arrived, formal and much harder, adding a demand that American missiles in Turkey be withdrawn. The obvious reading was that the first message had been superseded. The decision taken in Washington was to reply to the first message and behave as though the second had not arrived. Whatever one calls this — and it has been called a trick, which it was — it is a de-escalatory response to an escalatory input, and by the argument of the tenth chapter it is the single behavior that a crisis in progress almost never produces.

On the same day an American reconnaissance aircraft was shot down over Cuba and its pilot killed. Standing plans provided for immediate retaliation against the missile sites responsible, and the recommendation to execute them was made. The president declined. That is a second de-escalatory response to an escalatory input, taken within hours, in a situation where the case for the prepared plan was as strong as such cases ever get.

I do not want to leave this chapter having painted 1962 as a triumph of rational management, because parts of it were nothing of the sort, and the parts that were not are precisely where the model predicts they would be.

The same twenty-seventh of October found a Soviet submarine near the quarantine line, out of communication with Moscow, being harassed by American depth charges intended as signals to surface. The submarine carried a nuclear torpedo. Its captain, believing that war might already have begun and unable to find out, moved to authorize its use. Under the arrangements aboard that vessel, three officers had to concur; one, the flotilla chief of staff, refused, and the boat surfaced instead.

That is a latency collapse in miniature, occurring inside a crisis that was otherwise being managed carefully. The submarine’s window was minutes, its ability to consult Moscow was zero, and it had a default. Everything the political level had done to preserve deliberation at the top had no effect at all a hundred metres under the Atlantic, where the interval was too short and the authorization procedure was three men in a hot steel tube.

The lesson is not that management fails. It is that management protects the level at which it is applied and no other. The intervals were engineered where the leadership could see them, and where the leadership could not see them the ordinary mechanism ran as usual and was stopped by a single man’s refusal, which is not a system property and cannot be relied upon.

Chapter Twenty-Three — The Line Moved Outward

There is a small decision from October 1962 that never appears in the dramatic accounts, because nothing happens in it. No one shouts, no one resigns, no aircraft is lost. It is a line on a chart being redrawn, and it is the most instructive act of the entire crisis.

The American response to the missiles was a naval quarantine: a cordon around Cuba which Soviet ships would have to cross or turn back from. Someone had to decide where to draw it. The navy proposed a radius of eight hundred miles, which was the militarily sensible answer, since it kept American ships beyond the range of aircraft based in Cuba.

The line was moved in, to roughly five hundred miles. The reason had nothing to do with military advantage and everything to do with time. A closer line meant that Soviet vessels steaming toward Cuba would reach it later, which meant more hours before the first confrontation at sea, which meant more hours in which the Soviet leadership could consider its position and issue new orders to its captains. The British ambassador is generally credited with pressing the argument, and the president accepted it over the navy’s objection.

Consider what has happened here. A government at the height of a nuclear crisis has knowingly accepted a worse military position in exchange for hours. Not for a concession, not for a negotiating advantage. For hours, given to its adversary, for the adversary to think in.

I have found nothing remotely like it in the record of July 1914. The direction of every decision in that crisis was toward compression: the ultimatum timed for the departure of the French president, the declaration sent by telegram to preempt mediation, the deadlines of twelve hours where twenty-four had been the norm. It is not that the men of 1914 tried to lengthen intervals and failed. The possibility that an interval was a thing you could lengthen on purpose does not appear to have occurred to anybody.

Why did it occur in 1962? Partly because the consequences of getting it wrong had become unmistakable in a way they had not been in 1914, when the general expectation was of a short war. Partly because the participants had read about 1914; the American president had been given Barbara Tuchman’s account of the July crisis that summer and referred to it repeatedly during the thirteen days, telling his brother that he did not intend to have a book written about this one called The Missiles of October. It is one of the few clear cases of a historical account changing a decision, and it is somewhat ironic that the book in question advanced a version of the timetable thesis that historians have since dismantled. Tuchman was wrong about the mechanism and right about the danger, and being right about the danger was what mattered that week.

The general principle deserves to be stated in its own right, because it is the most practical thing in this book.

Your adversary’s deliberation time is an asset to you, not a cost. This is deeply counterintuitive and runs against every instinct of negotiation, where pressure is the currency and giving your opponent time to think feels like a concession. In a bargaining problem it usually is. In a crisis with irreversible acts and prepared defaults, it is not, because an adversary who has no time to think does not concede. He executes a plan, and the plan was drawn up by someone who assumed you would behave differently than you are about to.

Put plainly: if you compress your opponent’s interval past his deliberative capacity, you do not gain control of him. You gain control of nothing, and hand the outcome to a document written years ago by a staff officer neither of you has met.

There is a second act of window management in the same crisis, less famous and equally deliberate. Throughout the thirteen days the American administration went to considerable trouble to avoid public commitments that would be difficult to walk back. The president declined to state that the missiles would be removed by force; the language of the quarantine was chosen to avoid the word blockade, which is an act of war; the eventual settlement included a secret understanding about the Turkish missiles precisely because a public one would have been unacceptable to allies.

Every one of these is a decision to preserve reversibility, which is the exit-cost problem of the fourteenth chapter treated as something to be minimized rather than accepted. A commitment made publicly costs more to abandon than one made privately, so a leader who wishes to retain the option of abandoning it should make it privately, at the price of a weaker signal. That trade — signal strength against reversibility — was made consciously and repeatedly in October 1962, and was made in the opposite direction, equally consciously, in July 1914, when the Austro-Hungarian declaration of war was issued by telegram for the specific purpose of being impossible to withdraw.

Two crises. The same structure. In one, every marginal decision went toward compression and irreversibility. In the other, several went the other way, at real cost, over professional objection. That is as close to a controlled experiment as history is ever going to hand us.

Chapter Twenty-Four — The Hotline

The device installed in the Pentagon in the summer of 1963 was not a telephone and was not red. It was a pair of teleprinters, of the sort that clattered in newsrooms, connected to Moscow by a cable running through London, Copenhagen, Stockholm, and Helsinki, with a radio circuit as backup. Nobody spoke on it. Messages were typed, transmitted, and decoded by machine, and the reason for this design was that speech is ambiguous and translation under pressure is unreliable, whereas a typed text can be worked over by professionals at both ends.

It was tested hourly. The American end sent passages of Shakespeare and technical prose; the Soviet end sent Chekhov. For four years nothing else went over it. Its first operational use came in June 1967, during a Middle Eastern war, when the American and Soviet governments used it to explain the movements of their fleets to each other in the Mediterranean and thereby avoid a confrontation that neither wanted.

I have described this apparatus in some detail because it is, so far as I can determine, the only institution ever created by a great power for the sole purpose of reducing its own deliberation time, and it deserves to be looked at closely by anyone who wants to know what such a thing looks like.

Recall the components of institutional response time from the sixth chapter: transmission, authorization, promulgation. The nineteenth-century bottleneck was transmission, and the hotline attacked it directly. Before 1963, a message from the American to the Soviet head of government travelled through diplomatic channels: drafted, cleared, enciphered, given to an ambassador, delivered, translated, circulated. During the missile crisis one such message had taken something like twelve hours to make the journey, which meant that in a situation where events were moving in hours, the two men with the authority to stop it were operating with a delay comparable to the timescale of the events. The teleprinters reduced that to minutes.

So far this is an unambiguous good, and it is the reason I have called it, more than once in this book, the single clear case of a state responding to a fright by adding reserve rather than by consuming it. Every other response to the missile crisis followed the older pattern: more readiness, faster procedures, better pre-delegation. Only the hotline made deliberation quicker rather than making action automatic.

Now the limits, which are instructive.

The hotline attacked one of the three components and left the other two alone. It did nothing whatever to authorization latency, which is to say to the time required to assemble the people entitled to decide and obtain their agreement. And authorization, not transmission, is where nearly all the delay now lives. In 1914 the message took hours and the council took hours, so halving the message time was a real gain. Today the message takes no time at all and the council still takes hours, so improvements in transmission have reached the point of irrelevance while the binding constraint sits untouched.

This is a general pattern in the history of technology and it has a tiresome inevitability. We optimize the component we know how to optimize. Transmission is an engineering problem with an engineering solution. Authorization is a constitutional problem, and constitutions are not amenable to fibre optics.

There is a second limit, which is that a channel is only as good as the willingness to use it, and the record of the following decades is mixed. The line was used during several crises and conspicuously not used during others, sometimes because using it would have implied a level of concern that one side did not wish to signal. An instrument designed to remove delay was thus itself subject to a deliberation about whether to remove delay, which is the sort of joke that history tells without smiling.

And there is a third limit, the largest. The hotline shortens the time to communicate. It does nothing at all to lengthen the window, which is to say the interval before something irreversible happens. And over the six decades since 1963 the windows have shortened by more than the hotline gained. In 1962 the flight time of a Soviet missile to Washington was around half an hour. By the mid-seventies, submarine-launched missiles positioned off the eastern seaboard could reduce that to something closer to ten minutes.

Set those two developments side by side. Deliberation time, best case, improved by hours. Windows shortened by tens of minutes on a base of thirty. The gain was real and the loss was larger, and the loss came from ordinary technical progress that nobody experienced as a decision at all.

That is the situation the second half of this book has to reckon with, and the reckoning begins with an arithmetic problem in the next chapter.

Chapter Twenty-Five — Twenty-Six Minutes

Do the arithmetic that governs the nuclear age and you will find it is arithmetic a child could do, which makes the results harder rather than easier to accept.

An intercontinental ballistic missile fired from central Asia at a target in North America follows a trajectory over the pole and arrives in about thirty minutes. That number has not changed materially since the nineteen sixties, because it is set by orbital mechanics rather than by engineering, and orbital mechanics does not improve.

From that thirty minutes, subtract. Infrared satellites detect the launch plume within a minute or two. Ground stations must then confirm what the satellites saw, since satellites are fooled by sunlight, by fires, and by weather. Radar confirmation is not available until the missiles clear the horizon, roughly ten minutes into the flight, because the earth is curved and radar is not. Confirmation must be assembled, assessed, and passed up a chain. Someone must reach the person with authority, who may be asleep, in a vehicle, or on another continent. That person must be briefed on a situation of which he has no prior knowledge, must understand what he is being told, and must choose.

Then, whatever he chooses, the order has to be transmitted and authenticated and executed, and that takes several minutes at the far end.

What remains in the middle, for the actual decision, is commonly estimated at somewhere between five and ten minutes. Call it six. Against a submarine-launched missile from a boat stationed close offshore, the whole envelope collapses to ten or twelve minutes and the middle vanishes.

Now recall the number from the first half of this book. A European government in 1914 needed something on the order of half a day to convert an arriving message into an authorized decision. Nothing about the structure of authorization has changed since. A modern government still requires that the responsible person be located, informed, and given the opportunity to decide, and it still requires, in most systems, some form of consultation. The transmission component has been reduced to nothing. The rest has not.

So we have arranged a permanent condition in which the window is six minutes and the authorization requirement is measured in hours.

By the definitions of this book that is not a risk of latency collapse. It is latency collapse, continuously, as a designed state, maintained deliberately for six decades by every nuclear-armed government on earth.

I want to be careful not to sound as though I have discovered something the strategic community has overlooked. It has not been overlooked. It has been the central preoccupation of that community since the nineteen fifties, and the response to it is called launch on warning, or in more careful formulations launch under attack, and it consists of preparing in advance exactly what will be done so that the six minutes can be spent on identification rather than on deliberation. The plans are elaborate, they are rehearsed, and the people who maintain them are not fools.

They are, in the vocabulary of the seventh chapter, defaults. They are the fire notice on the wall, written in a quiet room by people who correctly anticipated that there would be no time to think.

And the seventh chapter’s warning applies with full force: the danger of a default lies not in its own quality but in the joint execution of everyone’s. Two states, each with a well-designed launch-under-attack posture, each conditioning its action on detection of the other’s, constitute a system in which a false detection at either end produces a real launch at both. Nobody designed that system. Each side designed half of it, prudently, in response to the other half.

There is a feature of the modern arrangement with no analogue in 1914, and it makes things worse in a way that deserves its own paragraph. In July 1914 the shortest interval anyone faced was still long enough for a human being to think a complete thought. Twelve hours is not enough for a crown council, but it is enough to read a document twice and consider whether it means what it appears to mean. Six minutes is not enough for that. It is enough to be told something and to respond, which is a different cognitive operation, and the difference is the one between judgment and reaction.

There is a second feature which is more hopeful and which is the reason the argument of this book is not a counsel of despair. The six-minute window is not a fact of nature. It is a consequence of choices about basing, posture, and doctrine, all of which are adjustable. Missiles kept in a condition requiring hours to launch impose no six-minute requirement on anybody. Warheads separated from delivery systems impose none. Postures that renounce launch under attack, and are seen to, remove the need for the other side to plan against it.

Each of these has been proposed, each has been resisted, and the resistance has always taken the same form: any measure that lengthens our reaction time is a measure that invites attack. That argument is not stupid and it is not obviously wrong. It is precisely the argument every general staff in Europe made between 1905 and 1914, in exactly the same words, about mobilization schedules. It was the argument that produced the condition in which the schedules were executed unexamined.

Chapter Twenty-Six — The Room Where Nobody Can Be Reached

Try a scenario that has nothing to do with weapons.

It is three in the morning in a national capital. An event has occurred which requires a decision at the highest level within two hours. It could be a financial default, a border incident, a large industrial accident with cross-border consequences, or an infrastructure failure of ambiguous origin. Assume perfect information: everyone knows exactly what has happened. Assume perfect goodwill: nobody is playing politics. The only question is how long it takes to produce a decision that carries lawful authority.

Somebody must first determine that the threshold for waking the principals has been crossed, which requires a judgment by an official who will be blamed either for waking them unnecessarily or for not waking them. Then the principals must be located, and modern life is not helpful here: they may be travelling, they may be abroad, they may be in a jurisdiction where their communications are not secure. They must be briefed, and briefing is not instantaneous, because a person woken at three in the morning requires several minutes simply to become the person who holds the office. If the decision requires the concurrence of more than one office — and in most constitutional systems the significant ones do — those offices must be assembled, which now means a secure conference facility rather than a room, which is faster but not instant, since the participants must reach appropriate terminals.

Then there is the legal question. Somebody must establish that the action contemplated is within the authority of the person contemplating it, and if it is not, a further process is required. This is the step that is never in the film. It routinely takes longer than everything else combined.

An honest estimate for a well-run modern government, with everyone available and no obstruction, is a few hours. Under adverse conditions, considerably more. That estimate is not much better than 1914, and in one specific respect it is worse.

The respect in which it is worse is dispersion. The men who had to be assembled in July 1914 were, at least, in a small number of known locations, and the assumption that the foreign minister was in the foreign ministry was usually correct. The modern principal is mobile, and mobility has been sold to us as an improvement in availability. It is an improvement in contactability, which is not the same thing. You can reach a defence minister on an aircraft in ninety seconds. You cannot convene a lawful meeting of a cabinet on an aircraft, and the interval that matters is the second one.

I have set this out at length because of a widely held belief that modern governments are fast, and because the belief is held most firmly by people who have never watched one make a decision. The belief comes from the visible parts of government, which are indeed fast: information arrives instantly, analysis is produced overnight, statements are issued within the hour. What is fast is the production of material. What has not changed is the production of authority.

And here is the consequence that matters for this book. Because the visible parts are fast, everybody involved — including the principals themselves — systematically overestimates how quickly the system can decide. The overestimate is not a personal failing. It is what happens when the observable indicators of speed are all attached to the components that got faster.

This is the mechanism by which a government can believe it has time when it does not, and it is worth naming, since it will be the subject of the thirty-first chapter in a sharper form. Call it the illusion of readiness. Every part of the machine that you can see is quick. The part you cannot see, because it consists of legal authority and human assembly, is slow. Your estimate of the whole is formed from the parts you can see.

The institutional response to all this, over the last seventy years, has been pre-delegation: deciding in advance who may act, under what circumstances, without further consultation. Every nuclear-armed state has such arrangements for the extreme case, and their details are among the most closely held secrets in existence. Below the extreme case there are standing rules of engagement, automatic defensive systems, and legal frameworks that permit action first and review later.

Each of these is a rational answer to the arithmetic above. Each is also a migration in the sense of the eighteenth chapter: a decision moved from the moment of the event to a quiet room years earlier. The seventy-year accumulation of such migrations means that a modern state’s path from peace to war contains a substantial stretch that can be traversed without any political decision at all, and nobody knows how long that stretch is, because no one has ever added it up.

The Russians who drafted the preparatory-period regulation in 1913 were solving the same problem with the same logic and would have recognized every argument. They were not able to add up their own migrations either. Nobody asked them to.

Chapter Twenty-Seven — The Man Who Did Not Report

Shortly after midnight on the twenty-sixth of September 1983, at a command bunker south of Moscow, an alarm sounded. The satellite early warning system had detected a missile launch from the continental United States. The duty officer, a lieutenant colonel in the Soviet air defence forces, had a procedure: verify the indication and report it up the chain. Reporting it would have set in motion an assessment process at the general staff, under conditions where the Soviet leadership was already convinced that the United States might be preparing a first strike, and where the interval available for the whole sequence was on the order of twenty minutes.

Stanislav Petrov did not report it. He judged it a false alarm and said so.

Then the system reported a second launch. Then a third, a fourth, and a fifth. He continued to report a system malfunction, having by then no evidence for that conclusion beyond his own reasoning, and having thirty-odd people in the room watching him not do his job.

His reasoning was structural rather than technical, and it is the most interesting thing about the episode. He did not know what was wrong with the satellites; the fault, which turned out to involve sunlight reflecting off high cloud at an unusual angle at the autumn equinox, was identified later. What he knew was that five missiles made no sense. A first strike intended to disarm an adversary is not delivered by five missiles; it is delivered by hundreds, in the opening seconds, because anything less leaves the victim able to retaliate. The signal was the wrong shape for the thing it claimed to be.

He was right, and the world continued, and he was not rewarded. He was questioned extensively, his log-keeping was criticized, he received no commendation, and he left the service the following year with his health impaired. The incident was classified for a decade and became public only after the collapse of the state whose bunker he had been sitting in.

The story is usually told as one about an individual, and as such it is a fine story about an individual. I want to tell it as a story about a system, because as a story about a system it is considerably more alarming than its usual moral suggests.

Consider what the system had produced. It had produced a situation with a window of about twenty minutes, an authorization requirement measured in far longer, and consequently a set of pre-authorized responses to be triggered by an indication. That is latency collapse by construction, exactly as described in the twenty-fifth chapter. And what stood between that arrangement and its execution, on the night when it malfunctioned, was one man’s private judgment that the pattern looked wrong, exercised in defiance of his instructions.

That is not a safety mechanism. It is the absence of a safety mechanism, covered accidentally by a human being who happened to be both thoughtful and, by his own later account, the only officer on that roster with a civilian engineering education rather than a purely military one. Had the shift been staffed by a competent officer who followed procedure — which is to say, by a good officer — the indication would have gone up the chain, and what happened next would have depended on a series of further individuals doing something other than their jobs.

The general point deserves stating without the drama. Inside a collapsed system, the only remaining remedy is refusal. When the window is shorter than the deliberation requirement, there is by definition no time to decide correctly; there is time only to execute or to decline to execute. Declining is the sole degree of freedom left, and it has three properties which together make it a terrible thing to rely on.

It is unauthorized. Whoever declines is disobeying, and must be prepared to be wrong and punished. Petrov was neither rewarded nor punished, which is possibly the worst of the available outcomes, since it teaches nothing to anyone.

It is unreliable by design. It depends on the disposition of whichever individual happens to be on duty, which is a variable no system controls.

And it works only in one direction. A refusal can prevent an action from occurring. Nothing analogous can cause a correct action to occur when the system is producing a wrong one. Refusal is a brake, not a steering wheel, which means that a system whose only remaining safeguard is human refusal is safe against false positives and defenceless against everything else.

There is a companion case from the same era, mentioned earlier in this book: the officer aboard a Soviet submarine in October 1962 who withheld his concurrence from the use of a nuclear torpedo. Two incidents, two decades apart, in different services, with the same structure: a collapsed interval, a prepared response, and a single individual declining. Two is not a pattern in any statistical sense. It is enough to notice that on the occasions when we know the mechanism was tested, what stopped it was not the design.

We do not know how many other such occasions there have been. The nature of the thing is that a successful refusal produces no event, and non-events are not investigated.

Chapter Twenty-Eight — Attribution Takes Longer Than Retaliation

A power station goes dark. The failure is not mechanical; the control system has been given instructions it should not have received, from somewhere. Within an hour the government knows it has been attacked. Within a day it knows a great deal about how. Establishing by whom will take somewhere between several weeks and never.

This is the shape of the problem and it inverts every relationship this book has examined so far. In 1914 the difficulty was that decisions took longer than events. In the cyber domain the difficulty is that establishing the facts takes longer than either.

Consider what attribution actually requires. The intrusion arrived through infrastructure in several countries, at least one of which was itself compromised and belongs to a party with no involvement whatever. The tools used are available for purchase, or were stolen from a state that developed them, or were copied from a public disclosure, and their presence establishes only that somebody had access to them. The operational patterns resemble those of a known group, but resemblance is exactly what an adversary would produce if it wished to be mistaken for that group, and adversaries do wish this and do produce it. Confirmation of the kind that would satisfy a court generally requires human intelligence or intercepted communications, which take months to obtain and which cannot be published without destroying the source.

So the responsible official is in an unfamiliar position. He knows what has happened. He does not know who did it, he will not know soon, and the window for response — set by domestic expectation, by the need to deter repetition, and by the possibility that this is the first move of something larger — is measured in days.

Now apply the framework. The deliberation requirement here is not the time to convene a meeting; it is the time to establish the fact on which the meeting must decide, and that requirement has grown from hours to months. The window has not grown at all. If anything it has shrunk, since public attention now demands a response within a news cycle.

The gap is therefore larger than anything in the nuclear case, and it is a different kind of gap. The missile problem is a shortage of time to think about a known fact. The cyber problem is a shortage of facts to think about within a known time. Both produce the same output: the substitution of a prepared response for a considered one.

What fills the gap is a doctrine, which is a default with better manners. Declaratory policies now exist in several states specifying that attacks on critical infrastructure will be answered, that the answer need not be confined to the cyber domain, and that attribution will be made on the basis of the best available assessment rather than on proof. Each of those provisions is reasonable given the difficulty. Together they describe a system in which a state has committed in advance to retaliate, possibly with physical force, on the basis of an assessment it has also announced will be uncertain.

Set that beside the nineteenth of July 1914, when the Austro-Hungarian government determined that the Serbian state was responsible for the assassination, on the basis of an investigation that had established the involvement of Serbian officers and had not established the involvement of the Serbian government, and proceeded on the assessment because the assessment was what it had.

The parallel is not decorative. In both cases the responsible authority faced an act of violence, a strong prior about the culprit, an evidentiary standard it could not meet in the time available, and a domestic audience that regarded delay as weakness. In both cases the response was to act on the assessment. The difference is that Vienna’s investigation took three weeks and today’s would be expected to take three days.

There is an additional feature of the cyber case with no historical analogue, and it is the one that should worry us most. Attribution is not merely slow; it is contestable after the fact, permanently. A missile has a launch point that radar records. An intrusion has a chain of inference that can be disputed for years, by the accused, by domestic opponents of the government that made the accusation, and by anyone with an interest in confusion. This means that even a correct attribution followed by a proportionate response can be represented, indefinitely, as an unprovoked act.

Which produces a peculiar new hazard. Retaliation for an attack that a substantial part of the world believes did not happen, or happened at other hands, is not a deterrent. It is an escalation with no message attached. The whole purpose of a response is to communicate, and communication requires that the recipient and the audience agree on what is being answered.

The mitigations are not mysterious and none of them is popular. Declaratory policies could specify minimum intervals between attribution and response, which is the latency floor of a later chapter applied to this domain. Attribution could be referred to bodies with standing rather than assembled ad hoc after each incident, so that the assessment does not have to be built from nothing while the clock runs. Escalation could be decoupled from the news cycle by the simple expedient of governments stating in advance that they will not respond within it, which costs nothing except the appearance of vigour.

The appearance of vigour, unfortunately, is what the domestic clock rewards, and the domestic clock is the one nobody has ever succeeded in slowing down.

Chapter Twenty-Nine — Faster Than the Meeting Can Be Called

At around half past two in the afternoon of the sixth of May 2010, the American stock market fell by about nine percent and recovered most of it, and the entire episode lasted roughly thirty-six minutes. Shares in long-established companies traded, briefly, at a penny. Others traded at a hundred thousand dollars. Roughly a trillion dollars of notional value evaporated and largely returned before most of the people nominally responsible for the market were aware that anything had happened.

The official reconstruction took five months to produce and remains disputed in its details. What is not disputed is the general mechanism: an automated selling program interacted with automated market makers, which withdrew, which caused prices to move, which triggered further automated selling, in a loop whose complete cycle time was measured in milliseconds.

There is no villain in this story, which is what makes it useful. There is no equivalent of a foreign minister timing an ultimatum to catch his opponent at sea. There is a set of independently designed automatic systems, each behaving as its designers intended, interacting in a way none of them had been tested against.

By now that sentence should be familiar, and I do not intend to belabour the parallel. What is new here, and what earns this domain its own chapter, is the ratio.

In 1914 the window was hours and the deliberation requirement was hours; they were within a factor of ten of each other, which is why the crossing took a week and could in principle have been noticed. In the nuclear case the window is minutes and the requirement is hours: a factor of perhaps fifty, which is why the response is permanent pre-authorization. In automated markets the window is milliseconds and the requirement — for a human being to understand what is happening and obtain authority to intervene — is at best minutes. The factor is on the order of a hundred thousand.

At that ratio the concepts of this book stop describing a risk and start describing the ordinary operating condition. There is no question of a human decision arriving too late, because there was never a moment at which a human decision was contemplated. The system runs entirely on defaults and the only question is whether the defaults interact well.

I want to draw out three features, because each has a counterpart in the other domains and is clearest here.

The first is that the participants were not reckless. Each firm’s algorithms contained risk controls, and several of them worked exactly as designed: when conditions became abnormal, the systems stopped trading and withdrew. That is prudent behaviour at the level of the firm. Simultaneous prudent withdrawal by many firms is the removal of the market, which is the disaster. This is the compossibility problem of the ninth chapter in its purest available form, with the added indignity that the individually correct action is the collectively fatal one.

The second is that speed was not the objective of any participant but was imposed on all of them. No firm wanted to make decisions in microseconds; firms wanted to make good decisions, and were driven to microseconds because a competitor operating at that speed captures the trade. This is the arms-race logic of the pre-1914 general staffs, reproduced without any of the nationalism and with rather better mathematics.

The third is the one that matters for the rest of this book. The market’s response to the flash crash was not to demand better algorithms, or more responsible firms, or improved oversight, though it asked for all three. Its central response was structural and stupid in the best sense: mandatory halts. If the price moves too far too fast, trading stops, for a defined period, automatically, regardless of anyone’s opinion about whether stopping is warranted.

That is a machine for manufacturing an interval. It does not evaluate the situation. It does not ask whether the movement is justified by news. It simply reasserts, by force, a minimum time between an event and the responses to it, on the theory that nothing good happens in a market where the participants cannot think and quite a lot of bad things do.

It is, in the terms of this book, the only working example anywhere of an institution that lengthens windows automatically rather than requiring somebody to choose lengthening at the moment when choosing has become impossible. Which is why the last chapter of this book is about it, and why the intervening chapter is about the domain where the same problem is being created fastest.

Chapter Thirty — The Pandemic Clock

An epidemic with a doubling time of three days does not care what day of the week it is. This is the first and most important thing to understand about the mismatch, and it is a mismatch of a kind we have not yet examined, because the adversary here has no intentions at all.

Consider the two clocks in this setting. The window is set by the doubling time: the interval before the situation you are deciding about becomes a materially different situation. At three days, a measure that would have been sufficient on Monday is insufficient by Thursday and inadequate by the following week, not because it was wrong but because the thing it was designed for has quadrupled.

The deliberation requirement is set by the machinery of public health decision-making, which in every country is a committee. There are excellent reasons for this. The measures under consideration are coercive, expensive, and damaging in their own right, they fall across the responsibilities of several ministries, and they require legal authority that is often unclear until tested. A national decision to restrict movement is not a technical judgment; it is a political act with enormous consequences, and a system that permitted a single official to take it would be a badly designed system.

So the requirement is days, in the best case, and considerably longer where evidence must be assembled, where a scientific advisory body must reach a view, and where the measures must be agreed with subordinate governments that have their own authority.

Days against a window of days. Unlike the nuclear case, this is not a hopeless ratio. It is roughly the ratio of July 1914, and it has the same property: it can be survived comfortably or it can fail, depending on where in the sequence you are and how much of the reserve has been consumed.

What consumes the reserve here is delay in recognition, and this is where the epidemic differs instructively from a diplomatic crisis. In July 1914 everyone knew the crisis had begun; the ultimatum was a public document. An epidemic gives no such signal. It begins invisibly, and by the time it is recognized it has been doubling for some time, which means that the recognition itself arrives having already consumed a portion of the interval. A month of undetected spread at a three-day doubling time is a factor of a thousand, and no committee, however swift, can recover a factor of a thousand.

There is a second, subtler consumption, and it is the exact analogue of the ratchet chapter. Every measure available to a public health authority has an asymmetric cost profile. Imposing restrictions early, when the case numbers are small, is politically expensive, because the counterfactual is invisible: if it works, nothing happens, and the authority is accused of overreaction. Imposing them late is politically cheap, because by then everyone can see the hospitals. This asymmetry is well documented, it operates in every country regardless of political system, and it means that the incentive structure of the decision maker is precisely inverted relative to the epidemiology.

The consequence is a systematic bias toward acting at the last moment that the evidence permits, which in an exponential process is far too late, and which feels at the time like appropriate caution.

I have described the failure mode; let me describe the interesting case, because there is one, and it is the reason this chapter is not simply another catalogue of dismay.

Several jurisdictions in East Asia responded to the events of 2020 faster than their evidence strictly warranted, and the reason was structural rather than a matter of superior wisdom. They had experienced an outbreak in 2003, and in its aftermath they had built machinery: standing authorities that did not require fresh legislation, pre-agreed thresholds that triggered measures automatically, and testing capacity held in reserve. When the next event arrived, the deliberation requirement had already been paid, years earlier, in a quiet room.

That is precisely the migration described in the eighteenth chapter, the same operation the Russian general staff performed in 1913 — and here it produced a good outcome rather than a catastrophic one.

The difference is worth stating carefully, because it is the closest thing to a general rule that this book can offer about when pre-authorization helps and when it kills.

The Russian measures of 1913 pre-authorized actions whose effect depended on what an adversary did in response. The East Asian measures pre-authorized actions whose effect did not: a virus does not observe your preparedness and adjust. Where the environment contains a reacting opponent, pre-authorization removes deliberation from a situation whose whole content is the opponent’s reaction, and the joint execution problem of the ninth chapter applies in full. Where the environment does not react — a pathogen, a weather system, an earthquake — pre-authorization is nearly free, and the case for it is overwhelming.

Which suggests a test that any government could apply to its own standing authorities and none, so far as I know, has. Sort them by whether the thing being responded to has intentions. Where it does not, automate freely. Where it does, every automated step is a step your adversary is planning against, and the joint result is nobody’s plan.

Chapter Thirty-One — Apparent Time and Real Time

It is three in the morning and a duty officer has a problem. Something has happened at a frontier and the reports conflict. In 1914 he would have waited: for the next telegram, for the military attaché’s assessment, for the ambassador to be woken and asked. Waiting was not a choice; it was the condition of the job, and everyone in the building understood that nothing useful could be said for some hours.

Today he asks a machine. Within a minute he has a synthesis of every available report, a comparison with seventeen structurally similar incidents from the last forty years, an assessment of which accounts are mutually consistent, and three candidate interpretations ranked by plausibility with the evidence for each set out. The analysis is good. Better, quite possibly, than the ambassador’s would have been, and available two hours earlier than the ambassador could have been woken.

He now believes he understands the situation. And here is the question that this chapter exists to ask: how much time does he think he has?

The honest answer is that he thinks he has more than he did, and he is wrong, and the reason he is wrong is the most important thing in the second half of this book.

Go back to the decomposition from the sixth chapter. Institutional response time has three parts: getting the information, obtaining the authority, and issuing the order. Machines have collapsed the first part to nothing. They have done nothing whatever to the second, and they cannot, because obtaining authority is not an information-processing problem. It is a matter of finding the persons in whom authority is legally vested, briefing them, securing their agreement, and satisfying whatever procedural requirements the constitution imposes. That is a physical and legal process involving human beings who must be located and who must speak to one another.

So the two quantities have come apart. Call the first apparent time: how long it feels as though a decision requires, judged by how long it takes to have an answer in your hand. Call the second real time: how long it actually takes to produce an act that carries authority. Apparent time has fallen by an order of magnitude in twenty years. Real time has not moved.

The gap between them is now the most dangerous unmeasured quantity in international affairs, and it is dangerous for a reason that has nothing to do with whether the machines are any good.

Suppose they are excellent. Suppose the analysis at three in the morning is correct in every particular. The duty officer, holding a correct analysis, forms a judgment about how much slack the situation permits, and he forms it — as everyone forms such judgments — from his experience of how long things take. His recent experience is that things take almost no time, because everything he personally does now takes almost no time. He therefore estimates a comfortable margin, and the estimate is not a lapse of judgment; it is a correct generalization from the part of the process he can observe.

This is the illusion of readiness from the twenty-sixth chapter, but sharpened, because the machines have made the visible part of the process not merely fast but instantaneous, while leaving the invisible part exactly where it was.

There is an obvious objection and it deserves a straight answer. Surely a good analysis makes the authorization faster too? Principals arrive better briefed, the options are already framed, and the meeting is shorter.

Some of this is true and it is worth perhaps a fifth of the authorization interval. It does not touch the parts that dominate: locating people, securing a lawful basis, obtaining concurrence from institutions that must be convened. And there is a countervailing effect that may be larger. A ministry that receives three well-argued candidate interpretations does not necessarily decide faster than one that receives a single ambiguous cable. It may decide more slowly, because it now has three positions to argue about, each with evidence attached, and the argument is conducted by people who each find one of them persuasive. Better analysis makes better decisions. It does not reliably make quicker ones, and under some conditions it demonstrably does the reverse.

Now put this together with the ratchet, and with the fact that your adversary has the same machines.

Both sides now have excellent analysis instantly. Both sides estimate their own slack from apparent time. Both sides therefore believe they can afford to wait a little before responding, and both sides, having waited, respond to a situation that has moved. Neither side has time to notice that the other is in the same position. Each reads the other’s delay as deliberation and the other’s response as decided, when both are artefacts of a gap between apparent and real time that neither party has ever measured.

There is one more turn, and it is the worst of them.

If a government notices that its authorization process is too slow for the speed at which it now believes events move, the natural remedy is to shorten the authorization process, which means pre-delegation, standing authorities, and automatic responses. Which is to say: the recognition of the gap produces, as its remedy, exactly the migration described in the eighteenth chapter. The better the machines get, the wider the gap between apparent and real time, the stronger the case for removing the human authorization step altogether — not because anyone wants machines making the decisions, but because the human step has come to look like the bottleneck it now genuinely is.

That is a closed loop with no natural stopping point, and it is running in every advanced defence establishment in the world right now, and nobody has to intend any of it.

Chapter Thirty-Two — Machines That Never De-escalate

In early 2026 a professor of strategy at a British university did something obvious that nobody had done at scale. He took three of the most capable artificial intelligence systems then available, placed them in the roles of opposing national leaders in simulated nuclear crises, and let them play against each other. Twenty-one games, seven scenarios, several hundred moves, and a transcript of strategic reasoning longer than several long novels.

The results were reported widely and the headline was that the machines escalated. In the great majority of games at least one side employed nuclear weapons. In three quarters of them strategic nuclear threats were made. No model, in any game, chose to concede anything substantial.

The commentary that followed concentrated, understandably, on the alarming part: that systems being adopted for military analysis are apparently disposed toward escalation, and that they discuss the use of nuclear weapons in flatly instrumental terms, as options with costs and benefits rather than as thresholds. Others pointed out, correctly, that the experiment tells us about the behaviour of language models and not about the behaviour of humans, and that a wargame played by machines is evidence about machines.

Both observations are sound and neither is the one this book cares about. The finding that matters is buried in the reporting and was not the headline anywhere.

Across every one of those games, no model ever selected a de-escalatory move.

Return to the tenth chapter. The ratchet — the property that responses go up and never down — was described there as a bias produced by four separate mechanisms: domestic audiences, adversarial reading, military first-mover logic, and the fact that de-escalation requires a committee while escalation requires an office. Three of those four are absent from a machine playing a game. It has no domestic audience, no career, no ministry to convene. Only the second survives in any form: the tendency to read ambiguity adversarially, which these systems apparently do.

And yet the ratchet held perfectly. Twenty-one games, no exceptions.

That is a more interesting result than the escalation headline, because it suggests the ratchet does not depend on the four mechanisms this book attributed it to. Something about the structure of the situation, or about the strategic literature these systems absorbed in training, produces one-way motion in the absence of every institutional pressure that was supposed to cause it.

The training explanation is worth taking seriously and has an unpleasant reflexive quality. These systems learned strategy from the written corpus of strategic thought, which is overwhelmingly a literature about credibility, commitment, resolve, and the perils of appearing weak. It is a literature that treats de-escalation as a technical problem in signalling rather than as an available move. If you learned crisis behaviour from that corpus you would escalate too, and the machines may simply be returning to us, undiluted, the doctrine we wrote.

By the argument of the eleventh chapter this is sufficient for catastrophe on its own. If the ratchet holds, collapse follows in a finite and computable number of steps, and it does not matter how large the steps are. A participant that never de-escalates does not need to be aggressive, malicious, or mistaken. It needs only to be consistent.

Two qualifications, honestly offered.

These were games. The models knew, in whatever sense they know anything, that nothing was at stake, and a system that treats nuclear use instrumentally in a simulation may not do so when the consequences are real — though it is not clear what mechanism would produce the difference, and it is not clear that a system deployed as an advisor would ever be in a position where it knew the difference.

And nobody is proposing to hand these systems launch authority. The proposals on the table are for analysis, for wargaming, for the generation of options. That is a genuine distinction and it is smaller than it sounds. An advisor that never generates a de-escalatory option has removed de-escalation from the choice set of the human it advises, as surely as if it had made the decision. The thirteenth chapter’s fallacy of the describable option applies exactly: you can only choose from the options somebody put in front of you.

Set this beside the previous chapter and the picture completes itself. Machines shrink apparent time, which causes governments to believe they have slack they do not have. Machines generate the options from which humans choose, and in the only large study we have they generated no de-escalatory ones. And the remedy for the resulting slowness of the human step is to remove the human step.

Each of these three is being pursued by serious people for good reasons, in different institutions, none of which is responsible for the combination. If that sentence sounds familiar, it is the ninth chapter, and the year is 1912.

Chapter Thirty-Three — Circuit Breakers for Everything Else

After the American stock market fell twenty-three percent in a single day in October 1987, a presidential commission examined the wreckage and made a recommendation that sounded, to the people who received it, faintly ridiculous. It proposed that when prices moved too far too quickly, the market should be closed. Not investigated, not advised, not subjected to enhanced supervision. Closed, automatically, for a fixed period, whether or not anybody thought closing was warranted.

The objections were immediate and they were serious. Halting trade traps investors in positions they wish to exit. It does not remove the reason prices are falling; it merely postpones the fall and may worsen it by creating a rush for the exit before the halt. It substitutes a crude rule for the judgment of people who understand the situation. And it interferes with the price mechanism, which is what markets are for.

Every one of those objections is valid. The halts were installed anyway, in stages, and they were extended and refined after the flash crash of 2010, and today an American equity market that moves seven percent in a day stops trading for a quarter of an hour, and individual securities that move sharply are halted for five minutes each.

They work. Not perfectly, not without cost, and not in a way that satisfies anybody’s theory. What they do is guarantee, by force, that a minimum interval exists between an event and the responses to it, and that guarantee turns out to be worth more than the efficiency it destroys.

I want to be precise about what makes this the right model rather than merely an encouraging analogy, because the differences between markets and states are substantial and I do not want to pretend otherwise.

The first essential feature is that the halt is automatic. It does not require anyone to decide that a halt is warranted. This is the whole point, and it is the property that every other proposal in this area lacks. Recall the difficulty from the tenth chapter: the moment at which a pause is most needed is precisely the moment at which nobody has the time or the political capacity to request one. A mechanism requiring somebody to invoke it will not be invoked. A mechanism that fires on a measurable condition will.

The second is that the trigger is a rate rather than a level. The market does not halt because prices are low. It halts because they are moving fast. This maps directly onto the argument of the eleventh chapter: what endangers a system is not the severity of its situation but the rate at which its situation is changing relative to the speed at which it can respond. A crisis-stability mechanism triggered by how bad things are would fire at the wrong times. One triggered by how fast things are changing would fire at the right ones.

The third is that the halt is brief and fixed. Fifteen minutes, not indefinite suspension. This matters politically, because a mechanism that could freeze a state’s ability to respond indefinitely would never be agreed to by anyone, and rightly. What is on offer is not paralysis. It is the restoration of a minimum deliberative interval.

The fourth is that everyone knows the rules in advance. The thresholds are published. Nobody is surprised, nobody can claim that a halt was a hostile act, and — this is the underrated part — participants adjust their behaviour in anticipation, which reduces the number of times the mechanism is needed.

What would the equivalent look like between states? The honest answer is that nobody has built one, and that the obstacles are real. But the components are not mysterious and several already exist in embryo.

A minimum-response-interval norm would be the closest analogue: an undertaking between states that formal demands carrying military consequence will grant not less than some specified period for reply. This does nothing about anyone’s aims and costs nothing except the option of surprise. It is the exact inverse of the Austro-Hungarian note of the twenty-third of July 1914, and there is no technical obstacle to it whatsoever.

A migration audit would address the eighteenth chapter’s mechanism: a standing requirement that every pre-delegated authority be registered, periodically reviewed, and reported in aggregate, so that some office somewhere can answer the question of how much of the path from peace to war can now be traversed without a political decision. Nobody can answer that question today in any country.

A reversibility standard would address the fourteenth chapter’s hysteresis: force postures and legal regimes designed so that each step can be walked back at a cost comparable to the cost of taking it, with the walking-back rehearsed rather than theoretical.

And an interval-preserving rule for automated systems: that no advisory system be deployed which cannot generate a de-escalatory option, and that no system be permitted to compress the interval between detection and response below a published floor.

I am aware that this list will read as naive to anyone who has worked in a defence ministry, and that the objections to each item are the same objections that were made to circuit breakers in 1988: that it surrenders advantage, that it invites exploitation by an adversary who does not reciprocate, that it substitutes a crude rule for expert judgment.

Those objections were correct and the breakers were installed anyway, and the reason they were installed is worth ending on. It was not that the objectors were defeated in argument. It was that the alternative had been demonstrated. Everyone had watched a market destroy a quarter of its value in six and a half hours through the interaction of individually sensible automatic behaviours, and the demonstration was sufficiently vivid that a crude remedy became preferable to an elegant analysis of why no remedy was possible.

We have had that demonstration too. It was conducted between 1914 and 1918 at a cost of some twenty million lives, and we have spent a century arguing about whose fault it was instead of installing the breakers.

Conclusion

A book that has spent thirty-three chapters arguing that people misjudge how much time they have should probably say something about its own.

This account of 1914 is the third invention of the July crisis that I am aware of. The first was manufactured in the nineteen twenties by a government with a bill to reduce, and it gave us the fog, the tangle of alliances, and the comfortable proposition that nobody was to blame. The second arrived in the nineteen sixties, when a German historian went into his own archives and produced a case for deliberate German war-seeking so uncomfortable that his countrymen conducted a public breakdown over it. The third is the one you have been reading, and it says that the decisive variable was neither guilt nor fog but the ratio between two intervals.

I believe it. I also notice that it arrives at a moment when a great many people are anxious about automated systems making decisions faster than institutions can supervise them, and that a historical thesis which turns out to be exactly about that is the sort of thesis one should examine for convenience before accepting. The reader who has come this far is entitled to ask whether the argument was found or manufactured, and the honest answer is that I cannot fully tell from the inside, which is precisely what the third chapter said about everyone else.

What I can do is say where it would break.

It would break if the July windows turned out not to have contracted, and they did, and the instruments state their own deadlines, so this is not a matter of interpretation. It would break if European governments had been able to decide in an hour or two, which they could not, for reasons of cipher, council, and constitution that are documented in tedious administrative detail. It would break if the crises of 1905 to 1913 showed reserves being replenished rather than consumed, and the armaments legislation and the preparatory-period regulations of those years show the opposite. And it would break most cleanly if some crisis could be found with the same coupling, the same prepared plans, and an unmanaged contraction of intervals, that nonetheless resolved peacefully. I have not found one. Somebody may.

Set against that, the weaknesses are real and I have named them where they occur. Five formal deadlines is a small sample. The estimate of what a 1914 government needed to produce a decision is a reconstruction with a band around it, not a measurement. The comparison with 1962 rests on three interventions that I have interpreted as deliberate management of intervals and which a hostile reader could interpret as ordinary prudence that happened to have that effect. None of these is fatal and all of them are the sort of thing that ought to be said out loud in a book that has spent a chapter on the consequences of not saying such things.

Now the part that matters, which is what follows if the argument is right.

The first consequence is that the century-long search for the guilty party has been looking in the correct place at the wrong date. There were culpable decisions and they were taken in peacetime by men with all the time in the world: to write plans that assumed a cooperative enemy, to convert deliberated measures into automatic ones after each near miss, to build no institution whatever capable of lengthening an interval once it began to contract. Those men were not hurried. They were not confused. Several of them were the most competent officials their countries produced. Their failure was that nobody’s job description contained the question of whether all these arrangements could be true at once, and nobody asked for the job.

The second consequence is that the record of successful crisis management is not the reassurance it appears to be. Five European crises were survived and each survival consumed part of the reserve that made survival possible, and the men of 1914 read their run of escapes as evidence of robustness because that is what a run of escapes looks like from inside. Any government today that draws confidence from having handled several recent confrontations is making the identical inference from the identical data.

The third is that the interventions which would help are dull, structural, and available. Minimum response intervals for formal demands. A register of what has migrated from deliberated to automatic, so that somebody can answer how much of the road can now be travelled without a decision. Force postures designed so that walking back costs no more than walking forward. Advisory systems required to generate a de-escalatory option. Not one of these requires anybody to become wiser, more peaceful, or more trusting, which is the whole point, since proposals requiring those things have a poor record.

And the fourth is the one I would most like the reader to keep, because it is the least intuitive and the most portable.

Your opponent’s thinking time is your asset. Every instinct says otherwise. Pressure is what negotiation is made of, deadlines are how things get done, and giving the other side room to think feels like giving away the only advantage you have. In an ordinary bargain that instinct is sound. In a confrontation where both sides have prepared plans and irreversible acts available, it is precisely wrong, because an adversary with no time to think does not yield. He executes a document written years ago by somebody neither of you has met, against an imaginary version of you, and what happens next is not what either of you decided.

That was the discovery of the last week of July 1914, made too late by everyone and never afterward written down as a lesson. The men who made it were not fools, and their institutions were not primitive, and their intentions were mostly ordinary. They had between them all the intelligence, experience, and goodwill that anyone could reasonably ask for, and what they lacked was six hours.

We have built machinery that can produce a brilliant analysis of any crisis in ninety seconds, and we have not added six hours anywhere. The stock exchanges added theirs in 1988 and were called ridiculous for it, and the mechanism is still there, and it still fires, and every time it does somebody complains about the efficiency lost.

Efficiency was never the scarce commodity. Time to change your mind was, and it still is, and the difference between a system that has it and a system that does not is the difference between a bad afternoon and a century that never fully recovered.

Case Study One — Able Archer, November 1983

Background. In the first days of November 1983, NATO conducted an annual command post exercise called Able Archer, designed to rehearse the procedures by which political authorization for nuclear release would be sought and transmitted in a European war. No troops moved. No weapons were readied. The entire exercise consisted of message traffic, staff procedures, and simulated consultations among allied capitals, which is precisely what makes it interesting: it was a rehearsal of the authorization interval itself.

That year the exercise incorporated several realistic innovations. New communication formats were used. Radio silence was observed at certain stages. Heads of government were notionally involved in the escalation sequence. The realism was the point of the exercise; it was also, as it turned out, the hazard.

The core challenge. On the other side of the inner German border, the Soviet leadership was operating in a state of anxiety that Western governments substantially underestimated. Since 1981 Soviet intelligence had been running a standing collection programme premised on the possibility that NATO was preparing a surprise nuclear first strike, and the indicators it had been instructed to watch for included exactly the things Able Archer produced: changes in communication patterns, unusual staff activity at headquarters, and evidence of political leadership being brought into military channels.

An intelligence programme constructed to detect preparations for a first strike will detect the rehearsal of a first strike, because a rehearsal is what preparations look like. The Soviet collection system was doing its job correctly and returning alarming answers.

Fragmentary evidence, some of it from a Soviet officer working for British intelligence, indicates that elements of Soviet air forces in Central Europe were placed on heightened alert during the exercise, and that at least some senior figures took seriously the possibility that the exercise was cover for the real thing. The scale of the alarm has been debated by historians ever since and the honest position is that it was somewhere between significant and severe. What is not in dispute is that a Western military exercise designed to test decision procedures was read on the other side as a possible prelude to attack, and that Western governments did not know this was happening at the time.

Now apply the framework of this book. Two systems, each with prepared responses. One conducting an exercise on the assumption that the other understood it to be an exercise. The other assessing the exercise through a collection apparatus specifically designed to find attack indicators. The interval available to the Soviet leadership for determining which interpretation was correct was the duration of the exercise, and the means of resolving the ambiguity — asking — was unavailable, since asking would have disclosed both the concern and the intelligence sources that produced it.

The solutions implemented. The response, once Western governments understood what had happened, was concentrated in two areas.

The first was informational. Intelligence assessments in Washington and London were revised to take Soviet fear seriously as an operational factor rather than as propaganda, and this revision is generally credited with contributing to the shift in Western diplomatic posture that followed. An American president who had described the Soviet Union in eschatological terms in early 1983 was, by early 1984, publicly discussing the possibility that the two sides might frighten each other into a war neither wanted.

The second was procedural, and it is the one that matters here. Subsequent exercises were designed with the adversary’s interpretation in mind. Notification practices were extended. The specific innovations that had generated alarm — the involvement of political leadership in realistic form, the novel communication procedures — were modified or announced in advance. Later arms control agreements formalized advance notification of major exercises, converting a discretionary courtesy into a treaty obligation.

Measurable results. The 1986 Stockholm agreement required prior notification of military activities above defined thresholds, with observers invited. Subsequent European security arrangements extended this to annual exchanges of information about force dispositions and planned exercises. The effect on the specific hazard is difficult to quantify, as is always the case with prevented events, but the number of exercise-driven alarms reported in the declassified record falls sharply after the mid-eighties.

The mechanism of the fix deserves attention because it is unusual. What the notification regime does is not reduce anyone’s response time or lengthen anyone’s window in the direct sense. It removes an interpretive question from the crisis in advance. A general staff that has received notification of an exercise six weeks earlier does not have to determine, in the hours available, whether the activity it observes is an exercise. The question has been answered before it was asked.

That is a third category of intervention which this book has not otherwise had occasion to name. Alongside shortening your own response time and lengthening your adversary’s window, there is the option of pre-resolving ambiguities so that they do not consume the interval when it arrives.

Present-day relevance. The Able Archer structure is reproducing itself in the cyber and space domains with none of the mitigations in place. A state conducting a defensive penetration test of its own critical infrastructure generates network activity indistinguishable, from the outside, from an intrusion. A satellite manoeuvred for inspection of one’s own asset is indistinguishable from a satellite manoeuvred to interfere with someone else’s. In both cases the observing party must interpret the activity within an interval it does not control, using a collection apparatus designed to find hostile preparations, and in both cases the notification regimes that resolved the analogous problem for ground exercises in the nineteen eighties do not exist.

The lesson is available and cheap. Announcing in advance what you are about to do, in sufficient detail that it cannot be mistaken for something else, costs a small amount of operational surprise and removes an entire class of interpretation problem from a crisis window that will be too short to accommodate it.

Case Study Two — The Norwegian Rocket, January 1995

Background. On the morning of the twenty-fifth of January 1995, a research rocket was launched from an island off the north-west coast of Norway. Its payload was scientific equipment for studying the aurora, its flight path took it north over the Norwegian Sea, and its launch had been notified to thirty countries including Russia through the ordinary diplomatic channel some weeks in advance.

The rocket was a Black Brant XII, a four-stage vehicle capable of reaching an altitude of nearly a thousand kilometres. That performance is comparable to a submarine-launched ballistic missile, and its radar signature during the boost phase was similar.

The core challenge. Russian early warning radar detected the launch and characterized it as a possible missile. The trajectory was consistent with a launch from a submarine in the Norwegian Sea, and one specific interpretation was available and alarming: a single high-altitude detonation over Russian territory, intended to blind Russian radar and communications with an electromagnetic pulse as the opening move of a larger attack. Russian doctrine took this possibility seriously enough to plan against it, which meant that a single missile on that trajectory was not read as a trivial event but as a potential precursor.

The alert propagated upward. The Russian president was presented with the portable terminal that conveys strategic warning and permits authorization, and it was activated. Russian submarine commanders were placed on alert. For several minutes — accounts vary between four and eight — the Russian leadership was engaged with an unresolved indication of a possible attack.

The trajectory was then determined to be heading away from Russian territory, and the alert was terminated.

The notification had been sent and had not reached the people who needed it. It had gone through diplomatic channels, been received by the Russian foreign ministry, and stopped there. Nobody at the radar station in question had been told.

The solutions implemented. The technical fix was straightforward and was implemented: notification procedures were revised so that launch information reaches operational early warning units rather than terminating at a ministry. The institutional fix was more interesting. In 1998 the American and Russian governments agreed in principle to establish a joint centre for the exchange of missile launch data, with personnel from both countries in the same room watching the same feeds, precisely so that an ambiguous indication could be resolved by turning to the person at the next desk rather than by inference.

The centre was agreed, an agreement was signed, a building was identified, and it never opened. The reasons were a mixture of liability questions, funding, and the general deterioration of relations. The joint early warning concept remains, more than a quarter of a century later, an excellent idea that exists on paper.

Measurable results. The direct measurable outcome is the notification reform, which was implemented and which appears to have worked: no comparable incident involving a scientific launch has been reported since. The larger measure is a negative one. The most substantial proposed remedy was agreed and not built, and the interval available to Russian decision makers for resolving an ambiguous indication remains what it was in 1995.

It is worth stating what that interval is, because the numbers are the argument. A submarine-launched missile from the Norwegian Sea reaches Moscow in something over ten minutes. Detection and characterization consume several of those. The remainder is the deliberative interval, and into it must fit the assembly of information, the reaching of the head of state, the briefing, and the decision. The 1995 incident resolved in four to eight minutes, which was fast, and was fast because the trajectory happened to be determinable early. Had the rocket been launched on a bearing that took longer to distinguish, the remaining interval would have been close to zero.

Present-day relevance. Three things have changed since 1995 and all three are unfavourable.

Commercial and scientific launch activity has increased by more than an order of magnitude, and a substantial fraction of it involves vehicles with performance comparable to military systems. The population of ambiguous radar events is therefore much larger than it was.

Hypersonic glide vehicles, which several states now deploy, follow trajectories that are not ballistic and cannot be extrapolated from the boost phase in the way that saved the situation in 1995. The specific mechanism that resolved that incident — determining early that the object was going somewhere else — is less available against a vehicle that can change where it is going.

And the political relationship in which such incidents must be interpreted is considerably worse than it was in 1995, when the two governments were, whatever their differences, not treating each other as likely aggressors.

The 1995 incident is sometimes told as a story about how close we came, with the implication that the system worked. The system did not work; a notification was sent and lost, and what saved the situation was that the rocket’s trajectory declared itself quickly. The remedy was designed, agreed, and abandoned. That is the part worth remembering.

Case Study Three — The Faulty Chip and the Training Tape, 1979 and 1980

Background. Twice within eight months, the American strategic warning system reported a major Soviet missile attack that was not occurring.

On the ninth of November 1979, displays at several command centres showed a large-scale launch. Bomber crews went to their aircraft and started engines. Interceptors were launched. The airborne command post was readied. Within about six minutes the indication was determined to be false: a training tape simulating a full attack had been loaded into a live system.

On the third of June 1980, and again a few days later, similar indications appeared, this time with fluctuating and implausible numbers of missiles. Bomber crews again went to their aircraft. The cause was eventually traced to a failing integrated circuit in a communications multiplexer, a component costing well under a dollar, which was inserting random digits into the routine message that reported how many missiles had been detected. The routine message normally reported zero.

The core challenge. Both incidents were resolved without escalation, and both were resolved by the same mechanism: cross-checking against independent sensors. Satellite detection and ground radar are separate systems with separate failure modes, and an attack that appears on one and not the other is not an attack. In both cases the check was performed, the discrepancy was found, and the alert was cancelled inside the available window.

That is a genuine engineering success and deserves to be recorded as one. The dual phenomenology requirement — that an attack be confirmed by two physically different sensing methods before it is treated as real — is one of the better ideas in the history of command and control, and it worked twice under exactly the conditions it was designed for.

The challenge lies in what the incidents revealed about the interval. In each case the window from indication to the point at which irreversible steps would be required was on the order of minutes, and the cross-check consumed a substantial fraction of it. The 1979 incident was resolved in about six minutes; the response, in the meantime, had progressed to launching aircraft, which is expensive, visible, and observable by the other side.

That last point deserves emphasis, because it is the part the framework of this book identifies as most dangerous and the part the incident reports treat as incidental. Every one of these false alarms produced real observable military activity. Bomber engines were started. Interceptors flew. The airborne command post was prepared. Soviet intelligence was watching, and what it saw was an American strategic force being generated for reasons it could not determine.

A false alarm on one side thus becomes a true indication on the other, and the second side’s response to it becomes a further indication on the first. Nothing in the design of either system prevents this loop, and neither side’s cross-check procedure includes the question of whether the activity being observed is the other side’s response to one’s own earlier false alarm.

The solutions implemented. The technical responses were prompt and adequate. Test and training systems were physically separated from operational ones. The failing component was replaced and the design was revised to include checksums that would detect corruption of the message rather than passing it through. Procedures were revised so that certain response steps required additional confirmation.

An additional and less publicized change concerned the conference procedure: the sequence by which duty officers at multiple commands assess an indication together before it is passed upward. The threshold assessment conference was formalized, which sounds bureaucratic and is in fact an interval-management measure of the kind this book has been arguing for. It inserts a defined step, with defined participants, that must be completed before escalation continues.

Measurable results. Public reporting of the period indicates that the American warning system generated several dozen indications per year requiring assessment, of which a small number each year progressed to the conference stage, and of which a very small number progressed further. Those numbers fell after the fixes.

What did not change is the underlying interval, and the incidents are therefore best read not as failures that were corrected but as demonstrations of a permanent condition. The system is designed to operate correctly with a decision window of minutes. It did operate correctly, twice, under test conditions supplied by accident. The question the incidents raise is not whether the system works but what happens on the occasion when the cross-check is ambiguous rather than clean, and the answer to that is not available from the record because it has not yet happened.

Present-day relevance. The 1980 incident is the most economical illustration available of a general principle: in a tightly coupled system with short intervals, the cost of a component bears no relation to the consequences of its failure. A component costing less than a dollar generated a strategic alert in two countries.

Modern equivalents are more numerous and less inspectable. Warning systems now incorporate software of a complexity that forbids exhaustive testing, and increasingly incorporate machine learning components whose failure modes are not enumerable in advance in the way that a failing multiplexer’s are. The cross-check that saved the day in 1979 and 1980 depends on the independence of the systems being compared, and independence is exactly what shared software libraries, shared data pipelines, and shared training corpora quietly remove.

A dual-phenomenology check between two systems that both use the same commercial component, or that were both trained on the same data, is not a dual check. It is one check performed twice. # Case Study Four — The Hawaii Alert, January 2018

Background. At eight minutes past eight on the morning of Saturday the thirteenth of January 2018, mobile telephones across the state of Hawaii received a message in capital letters stating that a ballistic missile was inbound, that recipients should seek immediate shelter, and that this was not a drill. Television and radio broadcasts were interrupted with the same message.

There was no missile. The alert had been issued during a routine internal drill at the state emergency management agency. Thirty-eight minutes elapsed before a correction was broadcast.

The core challenge. What happened technically is well documented. The agency was conducting an unannounced drill at a shift change. A recorded message played over the internal system began with the words that would ordinarily indicate an exercise, but also contained, in the middle, the phrase used for a real event. An officer, using a software menu in which the option for a drill alert sat adjacent to the option for a real alert, selected the real one and confirmed it at a dialogue box asking whether he was sure.

That is the proximate account and it invites the obvious response, which is that the interface was badly designed and the officer was careless. Both are true and neither is interesting. What is interesting is the thirty-eight minutes.

The agency knew within two minutes that the alert was false. The correction took thirty-eight. The gap was not caused by confusion about the facts; it was caused by the absence of any prepared means of retraction. The alert system had a template for issuing a ballistic missile warning. It had no template for cancelling one. Producing a cancellation required drafting a message, obtaining authorization to send it through a channel that had not been designed for corrections, and obtaining approval from a federal agency for the use of the emergency alert system for a purpose it did not have a category for.

Set that against the argument of the fourteenth chapter and it is a textbook instance. Entering the state took one click. Leaving it took thirty-eight minutes, not because leaving was physically difficult, but because entering had been prepared and leaving had not.

The solutions implemented. The remedies were adopted quickly and are worth listing because they are exactly the right ones and because they were only adopted after the event.

A cancellation template was created, pre-approved, and made available for immediate transmission without further authorization. Two-person authorization was instituted for the issuance of a live alert. The drill and live options were separated in the interface. Drills were required to be announced to staff in advance. And the recorded drill message was rewritten so that it did not contain the phrase used in real alerts.

Measurable results. Subsequent testing showed the cancellation path reduced from thirty-eight minutes to a matter of a few minutes. No comparable incident has occurred in that jurisdiction since. Several other states and countries reviewed their own alert systems and found the same asymmetry: an issuance path that was prepared and a retraction path that was not. Several fixed it.

The broader measurable result is behavioural and more troubling. Surveys conducted afterward found that a substantial proportion of recipients did not believe the alert, and that a substantial proportion of those who did believe it did not know what to do, having no shelter available and no plan. A second finding was that some recipients said they would treat a future alert with more scepticism, which is the predictable cost of a false positive and which cannot be undone by procedural reform.

Present-day relevance. This case is included because it is the clearest available demonstration that the asymmetry between entering and leaving a state is not a property of armies or of nuclear weapons but of institutional design as such, and because it is recent, small, and fully documented.

The general rule it supports can be stated in a sentence that any organization could adopt tomorrow: for every action your systems can take automatically or in one step, the reversal of that action must be equally prepared and equally fast. Nobody does this. Organizations design the path they intend to take and treat the path back as a contingency that judgment will supply, and judgment will not supply it, because at the moment it is needed everyone is occupied with the consequences of the first path.

Applied at scale, the rule would require that every pre-delegated military authority be accompanied by a pre-delegated rescission authority of equal speed; that every automated defensive system have an equally automatic stand-down; and that every emergency legal regime contain a termination procedure as easy to invoke as the entry. None of these is difficult. All of them are omitted, everywhere, for the same reason the Hawaii system had no cancellation template: because the people designing the system were thinking about the emergency, and the retraction is not part of the emergency they were imagining.

Case Study Five — The Vincennes and Iran Air 655, July 1988

Background. On the third of July 1988, an American guided missile cruiser operating in the Strait of Hormuz shot down an Iranian civil airliner on a scheduled flight from Bandar Abbas to Dubai. All two hundred and ninety people aboard were killed.

The ship was among the most technically advanced warships afloat, equipped with a combat system designed to track and engage large numbers of targets simultaneously and to present a synthesized tactical picture to its commanding officer. It was operating in a confined waterway during an ongoing tanker war, had been engaged in a surface action with Iranian gunboats minutes earlier, and was aware that Iranian military aircraft operated from the same airfield used by civil traffic.

The core challenge. The aircraft took off from Bandar Abbas and climbed along a published civil airway. The ship’s system tracked it. Over the following seven minutes the ship’s crew attempted to identify it, issued warnings on military and civil emergency frequencies, and concluded that it was an Iranian F-14 descending in an attack profile. Two missiles were fired.

The aircraft had been climbing, not descending. It was squawking a civil identification code. It was on schedule, on a published route.

The subsequent investigation identified a set of factors that have been argued about ever since: the possibility that an operator read the altitude of a different track, the ambiguity of the identification codes, the difficulty of correlating a radar track with a printed airline schedule under pressure, and the phenomenon that investigators named scenario fulfilment, in which personnel under stress interpret ambiguous data in conformity with an expected pattern.

Apply this book’s framework and the structure is stark. The window was seven minutes, set by the closing geometry between an aircraft and a ship. The identification requirement — establishing with confidence what the aircraft was — could not be met in seven minutes with the means available, because the means available produced ambiguous data and the disambiguating information sat in a civil aviation schedule that was not integrated into the tactical picture.

So the requirement exceeded the window, and what filled the gap was a default: the doctrine and rules of engagement governing an unidentified aircraft closing on a warship in a hostile environment, which had been written in advance by people who correctly anticipated that there would be no time to deliberate. The commanding officer was not deciding whether the aircraft was hostile. He was applying a rule to an ambiguous input, which is what one does when the interval is too short for anything else.

The solutions implemented. Several changes followed, of varying seriousness.

Identification procedures were revised, and the integration of civil air traffic data into naval tactical systems was improved, so that a track correlating with a scheduled civil flight could be marked as such automatically. This is the substantive fix: it converts an identification problem that consumed the window into one answered in advance, which is the pre-resolution measure identified in the first case study.

Rules of engagement in the area were adjusted, and communication procedures with civil aviation authorities were established so that warnings on civil emergency frequencies would be more likely to reach the intended recipient. It emerged that the warnings issued by the ship had specified the target’s position by reference to a bearing and speed that the airliner’s crew, had they heard them, might not have recognized as applying to themselves.

The formal responsibility question was handled in the manner such things usually are. The commanding officer was not disciplined; the American government eventually paid compensation to the families without admitting liability.

Measurable results. Civil-military air traffic deconfliction in the Gulf improved measurably and no comparable incident has occurred there since, through a period of considerable tension. The integration of civil schedule data into tactical identification is now standard, and the specific ambiguity that contributed to the misidentification has been engineered out.

That is a real improvement and it took two hundred and ninety deaths to obtain.

Present-day relevance. The Vincennes case is the most-studied instance of a general problem that is becoming more common rather than less: an automated system presenting a synthesized picture to a human operator who must decide inside an interval too short for independent verification.

The system aboard the ship did not make the decision. It presented information, some of it ambiguous, some of it misread, in a format that made the tactical situation legible at a glance. A human being decided. But the human being’s decision was made from what the system presented, in the time the system’s own tempo allowed, and the question of whether that constitutes human control is exactly the question now being asked about a much larger class of systems.

Two features of the case recur in every contemporary discussion. The first is that the operator’s reasonable reliance on a sophisticated display is not a failure of vigilance; it is the intended use of the equipment, and an operator who second-guessed every track would be unable to perform his function at all. The second is scenario fulfilment, which is not a personal weakness but a documented property of human cognition under time pressure, and which is aggravated rather than relieved by systems that present a confident synthesis of ambiguous inputs.

Both features are more pronounced today, not less. Contemporary systems fuse more sources into a more confident picture, and the interval available for questioning that picture is shorter, and the operator’s ability to inspect the reasoning behind the synthesis is in many cases lower than it was aboard a cruiser in 1988.

The lesson usually drawn is that better identification technology is needed. The lesson this book draws is that the seven minutes was the problem, and that nothing done since has lengthened it.

Case Study Six — Überlingen, July 2002

Background. Shortly before midnight on the first of July 2002, a passenger airliner carrying mostly Russian schoolchildren and a cargo aircraft collided at eleven thousand metres over southern Germany. All seventy-one people aboard both aircraft were killed.

The airspace was controlled by a Swiss company from a centre at Zurich. That night a single controller was working two positions alone, colleagues having taken a break in accordance with an informal practice that management had tolerated for years. One of the two radar systems was undergoing maintenance, which had disabled the optical collision warning, and the telephone system was partially inoperative, which meant that a neighbouring control centre attempting to warn Zurich of the developing conflict could not get through.

The core challenge. Both aircraft were equipped with an airborne collision avoidance system, which detects a conflicting aircraft, coordinates automatically with the equipment aboard the other, and instructs one crew to climb and the other to descend. The system is designed to work without controller involvement and its instructions are, by design, to be followed.

Approximately fifty seconds before the collision, the controller noticed the conflict and instructed the passenger aircraft to descend. Seconds later, the collision avoidance system aboard that aircraft instructed it to climb, while the system aboard the cargo aircraft instructed it to descend.

The crew of the passenger aircraft followed the controller. The crew of the cargo aircraft followed the automatic system. Both aircraft descended.

This is the compossibility failure of the ninth chapter in its purest documented form. Two sets of instructions, each internally coherent, each issued by a competent authority acting correctly within its own frame, whose simultaneous execution produced the outcome both were designed to prevent. The controller did not know the automatic system had issued a contrary instruction, because the system does not inform controllers. The automatic system did not know the controller had issued an instruction, because it does not receive them.

There was a further layer. The two crews came from different aviation cultures with different training emphases regarding the priority of automatic instructions over controller instructions. That difference was known to exist and had been the subject of discussion within the industry, and the discussion had not resolved into a single unambiguous rule.

The interval available for resolving all of this was under a minute.

The solutions implemented. The response was, by the standards of most fields examined in these case studies, exemplary.

The priority rule was made unambiguous and universal: the automatic system’s instruction takes precedence over the controller’s, without exception, and controllers are trained that once such an instruction is issued they are no longer responsible for separating those aircraft. The ambiguity that killed seventy-one people was removed by choosing one of the two answers and enforcing it everywhere.

Procedures for single-controller operation were tightened. Maintenance practices that disabled safety functions without adequate compensating measures were revised. The technical arrangements were altered so that controllers receive an indication that an automatic resolution is in progress.

Measurable results. In the two decades since, mid-air collisions between commercial aircraft equipped with the system have effectively ceased in the airspace where the rule applies. The number of incidents in which contradictory instructions were issued has fallen to near zero, and the residual cases are handled by the priority rule.

The aviation industry’s approach to this class of problem is the most successful institutional treatment of non-compossible defaults that exists anywhere, and it rests on three practices that other domains have not adopted. Incidents are investigated by a body independent of both the operators and the regulator. The findings are published in full, including the errors of individuals, but the process is separated from the assignment of legal blame, so that participants can speak freely. And the resulting rules are made mandatory internationally rather than being left to national discretion.

Present-day relevance. There is a postscript that belongs to this case and that no account of it should omit. In 2004 a man whose wife and two children had died aboard the passenger aircraft travelled to Switzerland and killed the controller who had been on duty that night. He was convicted, served part of a sentence, and was released. The controller had been working alone because of a practice his employer tolerated, with equipment degraded by a maintenance schedule he did not set, and receiving no warning because a telephone system had failed.

The postscript belongs here because it illustrates the cost of the natural human response to a systemic failure, which is to find the person nearest the outcome and hold them responsible. That response is nearly irresistible and it is nearly always wrong, and the aviation industry’s great achievement is to have built institutions that resist it. The July crisis of 1914 has never had such an institution, and a century of argument about which foreign minister was to blame is what a field looks like when it lacks one. # Case Study Seven — Air France 447, June 2009

Background. On the night of the thirty-first of May 2009, an Airbus A330 left Rio de Janeiro for Paris with two hundred and twenty-eight people aboard. Some four hours later, over the mid-Atlantic, it entered an area of convective weather. Ice crystals blocked the pitot tubes that measure airspeed. The autopilot, deprived of valid airspeed data, disconnected and handed control to the crew.

Four minutes and twenty-three seconds later the aircraft struck the ocean. There were no survivors. The flight recorders were recovered from four thousand metres of water nearly two years afterward.

The core challenge. What the recorders showed is that the aircraft was flyable throughout. The blockage was temporary; airspeed indications returned to normal within about a minute. The aircraft was not damaged, its engines functioned, and the correct response to the initial condition was to maintain attitude and thrust and wait.

Instead the aircraft was pulled into a climb, lost speed, and entered an aerodynamic stall from which it descended, nose high, at high vertical speed, for three and a half minutes. The stall warning sounded and then, as airspeed fell below the threshold at which the system considers the data valid, stopped, and resumed when the nose was lowered — which meant that the correct recovery action was rewarded with the return of the warning it was intended to silence.

The captain was on his rest break when the event began. He returned to the flight deck about ninety seconds in, to a situation he had not seen develop, with two pilots giving contradictory inputs and instruments presenting a picture he was not able to reconstruct in the time available.

The framework of this book identifies three failures of interval here, and none of them concerns anyone’s competence.

The window was set by the aircraft’s energy state, which is to say by physics, and it was about four minutes from a stall entry at altitude to impact. The requirement — to determine what was happening from an incoherent instrument picture, resolve a disagreement between two operators, and execute a recovery — exceeded it.

The captain’s arrival illustrates the authorization latency problem in miniature. The most experienced person aboard arrived ninety seconds into a four-minute event and had to be briefed by people who were themselves confused, which consumed a further portion of what remained. Bringing the authority to the problem takes time, and the time is subtracted from the same account.

And the stall warning’s behaviour is a designed default that inverted under conditions its designers had not modelled.

The solutions implemented. Pitot tube designs were replaced across the fleet, a change that had been under consideration before the accident and was accelerated after it. Training requirements were revised substantially: manual handling at high altitude, recovery from unusual attitudes, and stall recovery in conditions where the automatic protections are unavailable all became mandatory recurrent training, having previously been treated as unlikely scenarios.

Two deeper changes matter more. The first is a shift in training philosophy away from the memorization of responses to named failures and toward the diagnosis of unnamed ones, on the recognition that the dangerous case is the one that does not match a checklist title. The second is a body of work on the presentation of degraded system states, aimed at ensuring that when automation withdraws it does so in a way that tells the crew what it is now doing rather than merely ceasing.

Measurable results. High-altitude upset accidents in commercial aviation have declined since the training changes, though the base rate was low enough that attribution is difficult. Simulator studies conducted after the accident found that a substantial fraction of experienced crews, presented with the same scenario without warning, produced similar outcomes — a finding that did more to change the industry’s mind than the accident itself, because it removed the explanation that the crew had been unusually poor.

Present-day relevance. The pattern of this accident is now recognized as a class: automation surprise, in which a system operating correctly within its design withdraws at the moment its assistance is most needed, handing control to a human who has been out of the loop precisely because the automation was working.

The class has a property that makes it worse over time rather than better. The more reliable the automation, the less practice the operator gets, and the more degraded the operator’s ability to take over when it stops. Reliability and preparedness are therefore in tension, and the tension is not resolvable by making the automation better.

This is directly relevant to the argument of the book’s later chapters. A decision-support system that produces excellent analysis reduces the occasions on which its user must reason unaided, and thereby degrades the capacity that will be required on the occasion when the system is wrong. The degradation is invisible until tested, and it is tested at the worst moment, in the shortest interval, by definition.

Case Study Eight — Ten Seconds and a Single Sensor, 2018 and 2019

Background. In October 2018 a Boeing 737 MAX operated by an Indonesian carrier crashed into the Java Sea shortly after take-off, killing one hundred and eighty-nine people. In March 2019 an aircraft of the same type operated by an Ethiopian carrier crashed shortly after take-off, killing one hundred and fifty-seven. The type was grounded worldwide for twenty months.

The core challenge. The aircraft incorporated a system, added because larger engines mounted further forward had altered its handling characteristics, which automatically pushed the nose down under certain conditions. The system took its input from a single angle-of-attack sensor. If that sensor failed and reported a high angle, the system would repeatedly command nose-down trim against an aircraft that was flying normally.

The certification analysis had considered this failure mode and had concluded that it was manageable, on the assumption that a trained crew would recognize the resulting behaviour as a runaway stabilizer and would apply the memorized procedure for that condition. The assumption included a specific interval: crews were expected to diagnose and respond within a few seconds.

That assumption was the accident. It was not unreasonable in the abstract — the runaway stabilizer procedure is a memory item and crews are trained to execute it promptly — but it presumed a crew who knew that this failure mode existed and that this was what they were seeing. The system had not been described in the flight manuals. Pilots transitioning to the type had not been told it was there.

So the requirement was to recognize an unfamiliar behaviour, correctly classify it as a familiar one whose signature it only partly matched, and execute a procedure, all within a window set by the aircraft’s proximity to the ground after take-off, which was measured in tens of seconds and shrank with each repetition of the automatic trim command.

There is a further element that belongs to the argument of this book. The window was not merely short but self-shortening. Each activation moved the trim further, which increased the control forces required to counteract it, which reduced the crew’s ability to arrest the descent, which reduced the time remaining. The system’s response to being resisted was to resist harder.

The solutions implemented. The system was redesigned to take input from two sensors and to compare them, to activate only once rather than repeatedly, and to be limited in the authority it could exercise so that it cannot overpower the crew’s control inputs. Its existence was documented and training was mandated. The certification process by which the original analysis had been accepted was subjected to external review and reformed, including the arrangements by which manufacturer employees performed certification tasks on behalf of the regulator.

Measurable results. The type returned to service after twenty months and has since accumulated many millions of flight hours without a recurrence of the failure. The direct financial cost to the manufacturer exceeded twenty billion dollars. Two regulators that had accepted the original certification revised their reciprocal arrangements, and the practice of automatic mutual recognition of another regulator’s approval was curtailed.

Present-day relevance. The most transferable element is the assumption that killed three hundred and forty-six people, and it was not an engineering assumption. It was an assumption about an interval: that a human operator, presented with an unexpected behaviour, would correctly diagnose and respond within a specified number of seconds.

Every automated system whose safety case depends on human intervention contains such an assumption, and it is almost never stated in the form of a number that anyone is required to justify. The safety analysis says that the crew will respond. The analysis does not say that the crew will respond within nine seconds, having never been told the system exists, at four hundred feet, at night, while also handling an unreliable airspeed indication.

The recommendation that follows is simple and would be resisted everywhere. Any safety case that relies on human intervention should be required to state the interval assumed, the information the human is assumed to have, and the evidence for both. Where that has been done in aviation, the results have been sobering: assumed response times have repeatedly proved to be two or three times the times actually observed in unannounced simulator testing.

The same assumption underlies every claim that a human remains in the loop of an automated military or financial system. In no case that I have been able to find is the assumed interval published.

Case Study Nine — Three Mile Island, March 1979

Background. At four in the morning on the twenty-eighth of March 1979, a pump failure in the secondary cooling system of a pressurized water reactor in Pennsylvania initiated a sequence that led, within about two and a half hours, to the partial melting of the reactor core.

No one was killed. The containment held. The financial and political consequences were enormous: the plant’s operator effectively ceased to exist as an independent entity, and the American nuclear construction programme, which had been ordering reactors at a rate of dozens per year, ordered almost none for the following three decades.

The core challenge. The initiating fault was routine and the plant responded to it as designed. Pressure rose, a relief valve opened to reduce it, and the reactor shut down automatically. The relief valve was then supposed to close.

It did not close. The control room indicator for that valve showed that it had closed, because the indicator was wired to the command signal rather than to the valve position. The operators therefore believed the system was sealed when in fact coolant was escaping continuously through an open valve.

Working from that belief, they interpreted the rising water level indication in the pressurizer as evidence that the system was filling with too much water, and reduced the emergency cooling flow to prevent it. This was exactly wrong: the core was losing coolant, not gaining it, and the emergency systems that would have prevented the damage were throttled back by trained operators reasoning correctly from false information.

The diagnosis was made about two hours and twenty minutes into the event, by a shift supervisor arriving fresh, who closed a downstream valve on a hunch and discovered the leak.

Two features matter for this book. The first is that the control room during those hours was generating alarms faster than any human could process them — over a hundred within the first minutes, with no prioritization, printing on a device that fell progressively further behind. The information required to diagnose the fault was present in the room and was buried in the volume of information that was not required.

The second is the fresh supervisor. The person who solved the problem was the one who had not been present while it developed, and who therefore arrived without the interpretation that everyone else had built and could not escape. That is a recurring pattern in the literature on operational failure, and it has an uncomfortable implication: the value of a fresh perspective is inversely related to how long the crisis has been running, so the person most likely to see the answer is the one least likely to be consulted.

The solutions implemented. The industry response was among the most thorough ever undertaken by a private sector. An independent institute was created by the operators themselves to set standards and to conduct peer evaluations of every plant, with results circulated among competitors — an arrangement that would be unthinkable in most industries and that reflected an accurate assessment that any operator’s accident was every operator’s problem.

Control room design was overhauled: alarm prioritization, indicators wired to actual states rather than to commands, and displays organized around the questions operators actually ask. Simulator training was made mandatory and plant-specific. Procedures were rewritten from event-based, which requires the operator to identify what has gone wrong before knowing what to do, to symptom-based, which tells the operator what to do about what he can observe regardless of cause.

That last change is the important one and it deserves the emphasis. Event-based procedures require diagnosis before action, and diagnosis is exactly what a short interval does not permit. Symptom-based procedures decouple the two: maintain these parameters within these ranges, whatever is happening. It is a direct engineering response to the problem this book has been describing, and it works.

Measurable results. American nuclear plant performance improved dramatically over the following two decades by every operational measure: unplanned shutdowns per unit fell by roughly an order of magnitude, capacity factors rose from the sixties to the nineties, and significant events declined steadily. The industry that emerged from the accident was a demonstrably safer one.

Present-day relevance. Three transferable findings.

Indicators must show states, not commands. This sounds trivial and is violated constantly in modern systems, where a dashboard reports that an instruction was issued rather than that it was executed.

Alarm floods are an interval problem, not an information problem. A system that produces more alerts than can be read has not informed anyone; it has consumed the interval it was meant to protect. Modern security operations centres and intensive care units both suffer this in an acute form, and the countermeasure — ruthless prioritization, with most alarms suppressed — is resisted because suppressing an alarm feels like accepting a risk.

And symptom-based response is the general remedy for short windows. Where the interval does not permit diagnosis, the procedure must not require it.

Case Study Ten — Chernobyl, April 1986

Background. During the night of the twenty-fifth to twenty-sixth of April 1986, an experiment at a Soviet reactor in northern Ukraine led to a power excursion, a steam explosion, and the destruction of the reactor and the building containing it. The release of radioactive material contaminated large areas of three republics and detectable quantities crossed Europe.

The core challenge. The experiment was intended to test whether, in the event of a loss of external power, the residual rotational energy of the turbine could supply the plant’s own pumps during the interval before the emergency generators reached full output. It was, in other words, a test of a latency gap: the plant was known to have a period of some tens of seconds during which it could neither draw external power nor rely on its own, and the experiment was an attempt to find something to fill it.

The test had been intended for the afternoon shift, which had prepared for it. A grid controller asked for the plant to continue producing power, and the test was postponed by some hours. It was therefore conducted by the night shift, which had not prepared, using a procedure annotated by hand, in a reactor whose condition had changed during the delay in ways that made the test considerably more dangerous.

During the postponement the reactor had been operated at reduced power for an extended period, which had allowed a neutron-absorbing fission product to accumulate in the core. When the operators attempted to raise power for the test, the reactor responded sluggishly, and they compensated by withdrawing control rods far beyond the limits permitted by the operating instructions.

The reactor was then in a condition in which its power coefficient was positive, meaning that an increase in power tended to produce a further increase, and in which the shutdown system had a design characteristic — graphite followers on the control rods that displaced water as the rods entered — that briefly increased reactivity when shutdown was initiated.

Both of these were known to the designers. Neither had been disclosed to the operators.

The interval available at the decisive moment was seconds. The emergency shutdown was initiated and made the situation worse for a few seconds before it could improve it, and the few seconds were sufficient.

The solutions implemented. The physical defects were corrected across the reactor fleet: additional fuel enrichment and fixed absorbers to reduce the positive coefficient, redesign of the control rods, and faster shutdown systems. Operating margins were made physically enforceable rather than administratively required.

The institutional changes were larger. An international convention on nuclear safety was concluded. Conventions on early notification of accidents and on mutual assistance were adopted, both directly addressing the fact that neighbouring countries had learned of the accident from their own radiation monitors rather than from the state where it occurred. A world association of nuclear operators was created to conduct peer reviews across national boundaries.

Measurable results. The reactors of the same design that continued to operate did so for decades afterward without a comparable event. The notification convention has been invoked repeatedly. The peer review system covers essentially every commercial reactor in the world.

Present-day relevance. The transferable finding is not about reactor physics. It is about the relationship between the people who design a system’s dangerous behaviours and the people who must respond to them in seconds.

The operators at Chernobyl were not told that their emergency shutdown could briefly increase reactivity. There were institutional reasons for the omission, having to do with secrecy and with professional hierarchy, and they were all bad reasons. The consequence was that a crew facing a window of seconds reached for the control that their training told them was the safe response, and the control did the opposite of what they believed for exactly long enough.

Any system in which the emergency response has a counterintuitive transient, and in which the operators have not been told, is the same system. The category includes automated financial controls that liquidate positions in a falling market, network defences that isolate segments and thereby disable the monitoring needed to understand the attack, and any safety system whose activation removes the information required to evaluate whether activation was correct.

The rule that follows is uncomfortable for organizations that value confidence: every documented counterintuitive behaviour of an emergency system must be disclosed to the people expected to operate it under time pressure, however much this undermines their trust in it. Trust that has not been calibrated is not an asset. # Case Study Eleven — Fukushima Daiichi, March 2011

Background. On the eleventh of March 2011 an earthquake off the north-east coast of Japan shut down the operating reactors at the Fukushima Daiichi station automatically and as designed. The emergency diesel generators started and supplied cooling. Approximately fifty minutes later a tsunami overtopped the station’s sea wall, flooded the generators and switchgear located in basements, and removed essentially all electrical power from the site.

Three reactor cores melted over the following three days. Hydrogen explosions destroyed the upper structures of several buildings. Some one hundred and fifty thousand people were displaced, most of them for years.

The core challenge. The loss of all power removed not merely the ability to cool the reactors but the ability to know their condition. Instruments were dark. Valves that required electricity could not be operated. Lighting failed. Operators entered the reactor buildings with hand torches and car batteries scavenged from the parking area, attempting to read gauges and to open valves by hand in an environment of rising radiation.

Two decisions dominate the accounts and both are interval problems.

The first concerns a passive cooling system on the oldest unit, which requires no power and which had been operating. Its status was misread; operators believed it was functioning when it was not, for a period of several hours during which the core was uncovered. The system was one that the operating crew had rarely seen in use and had never seen in this configuration.

The second concerns venting. As pressure rose inside containment, it became necessary to vent gas to the atmosphere to prevent the containment failing, which would release far more. Venting is a deliberate release of radioactive material and requires authorization that reaches beyond the plant, to the utility and to the government, and involves the evacuation of the surrounding population first. The decision therefore had a long authorization interval, embedded in a situation whose window was set by the rate of pressure rise, and the two did not match. Venting occurred hours later than the technical situation required, partly because of the authorization chain and partly because performing it manually in the dark, in high radiation, with no compressed air for the valves, proved extraordinarily difficult.

There is a further element that has no counterpart in the other nuclear cases here. The station manager, at a critical point, was instructed by his headquarters to stop injecting seawater into a reactor, seawater being ruinous to the equipment and its use amounting to a decision to write off the asset. He acknowledged the instruction and continued the injection, having judged that the alternative was worse. This is the refusal mechanism of the twenty-seventh chapter, appearing in an industrial setting.

The solutions implemented. Physical changes were extensive and are largely uncontroversial: relocation of emergency generators and switchgear above flood level, provision of portable pumps and generators stored off-site, hardened venting systems with power-independent actuation, and filtered vents that permit pressure relief with substantially reduced release.

The organizational changes were more contested and more important. The Japanese regulator was reconstituted as a body independent of the ministry that promoted nuclear power, the previous arrangement having placed promotion and regulation under the same authority. Emergency authority at plant level was clarified so that the on-site manager holds decision rights that do not require reference upward during the first phase of an accident.

Measurable results. The regulatory reconstruction is measurable in restart decisions: the new regulator has required expensive modifications and has kept plants shut for years, which the previous arrangement did not. Portable equipment stockpiles now exist at regional centres in several countries, with response time requirements specified in hours.

The most quantifiable result concerns the delegation. Where authority to take irreversible protective actions has been moved to the site, the interval for those actions has fallen from hours to minutes, and post-accident reviews in several countries have identified this as the single most effective change.

Present-day relevance. This case supplies the qualification that the argument of this book most needs, and it is worth stating carefully because it cuts against the general drift of the later chapters.

The book has argued that pre-authorization is dangerous because it removes deliberation from situations whose content is an adversary’s reaction. Fukushima is the opposite case: the delay in venting was caused by requiring authorization that the situation did not permit, and the fix was to pre-authorize. There is no adversary in a reactor accident. The pressure rises according to physics, and physics does not adjust its behaviour on learning that you have delegated authority.

This is precisely the test proposed at the end of the thirtieth chapter. Where the environment reacts, pre-authorization is hazardous. Where it does not, pre-authorization is close to free and the case for it is strong. Fukushima and the July crisis of 1914 sit on opposite sides of that line, and any government reviewing its own standing authorities should sort them by which side they fall on before deciding anything else.

Case Study Twelve — Deepwater Horizon, April 2010

Background. On the evening of the twentieth of April 2010, a drilling rig in the Gulf of Mexico was completing a well prior to temporary abandonment. Hydrocarbons entered the wellbore, reached the rig, and ignited. Eleven men were killed. The well flowed for eighty-seven days and released some four million barrels of oil.

The core challenge. The critical event occurred hours before the blowout, during a procedure called a negative pressure test, which is designed to verify that the cement barrier at the bottom of the well will hold once the heavy drilling fluid above it is removed.

The test produced contradictory results. One line showed the pressure that a sound barrier should produce. Another showed pressure that indicated flow. The crew discussed the discrepancy for some time and settled on an explanation, offered by an experienced member of the team, involving a phenomenon that would account for the anomalous reading without implying a barrier failure. The explanation had no basis in fluid mechanics; the phenomenon does not exist. It had, however, been invoked before on other wells, had never been contradicted by an ensuing disaster, and was accepted.

Having accepted it, the crew proceeded to displace the drilling fluid, which removed the weight holding the reservoir down, and the well began to flow. From that point the window closes rapidly. The indications of flow were present on the rig’s monitoring displays for close to an hour before anyone acted, during which the crew was engaged in other operations and the displays were not being watched by anyone whose sole responsibility they were.

Two distinct interval failures, then, and they are of different kinds. The first is a diagnosis failure with plenty of time available: the negative test was discussed at length, and more time would not obviously have helped, because the group had reached a comfortable explanation. The second is a detection failure in which the information was present and unattended.

The solutions implemented. Regulatory reorganization followed, splitting the agency that had combined revenue collection with safety oversight into separate bodies, on the same reasoning that reconstituted the Japanese nuclear regulator the following year. Well design and testing requirements were tightened, and independent verification of critical barriers was mandated.

Industry created two well containment consortia holding pre-built capping equipment ready for deployment, addressing a gap the response had exposed: no one had equipment capable of capping a well at that depth, and building it while the well flowed consumed weeks.

The most interesting change is the least discussed. Several operators adopted a rule that anomalous results from a critical barrier test must be escalated to a shore-based authority for concurrence, rather than resolved by the crew on the rig. This inverts the Fukushima remedy: authority is moved away from the site rather than toward it.

Both are correct, and the difference between them is instructive. Fukushima’s problem was that a fast-moving physical situation required action faster than the authorization chain permitted. Deepwater’s problem was that a group with ample time reached a wrong consensus that no one present was positioned to challenge. Where the window is short, move authority toward the scene. Where the window is adequate but the group is closed, move it away.

Measurable results. Pre-built capping stacks now exist at several locations with committed deployment times measured in days rather than weeks. Regulatory separation has produced measurably more enforcement actions. Loss-of-well-control incidents in the region declined over the following decade.

Present-day relevance. The invented explanation is the transferable finding. A group under commercial pressure, facing data that contradicted its preferred conclusion, generated a mechanism that would reconcile them, and the mechanism was fictitious.

This is not a rare pathology; it is the ordinary behaviour of expert groups presented with anomalies, and it is well documented. What made it lethal here was that no procedure required the anomaly to be resolved by anyone outside the room, and no procedure specified what would count as passing rather than leaving the interpretation to professional judgment.

The remedy that follows is unglamorous and general. Critical tests must have pass criteria specified in advance, in numbers, so that interpreting an anomalous result as a pass requires overriding a written standard rather than exercising judgment. The difference between those two situations is enormous and it is entirely procedural.

Case Study Thirteen — Challenger, January 1986

Background. On the evening of the twenty-seventh of January 1986, engineers at a contractor in Utah recommended against launching a space shuttle the following morning. Overnight temperatures at the launch site were forecast to fall below freezing, and the engineers believed that the rubber seals between segments of the solid rocket boosters would not seal reliably in the cold.

A teleconference was held between the contractor and the launch agency. The engineering recommendation was presented, questioned, and withdrawn. The launch proceeded and the vehicle was destroyed seventy-three seconds after lift-off, killing seven people.

The core challenge. The seal problem was not a surprise. Damage to the seals had been observed on previous flights, had been analyzed, and had been accepted as a known condition operating within experience. The engineers’ concern that night was that the coming launch would be colder than any previous one, and therefore outside the experience within which the condition had been accepted.

Their evidence was suggestive rather than conclusive. They had data showing damage on cold flights and could not demonstrate a clean relationship, partly because the flights without damage had not been plotted alongside those with it. Asked to prove that the seals would fail, they could not. They were asked, in effect, to demonstrate that it was unsafe to fly, rather than being required to demonstrate that it was safe.

That inversion is the accident. It is a reversal of the burden of proof, and it occurred under a schedule pressure that made the burden hard to meet: the interval available to develop the argument was the length of a teleconference, because the launch window was the following morning and the analysis had never been performed in advance because the question had never been asked in advance.

The engineers’ concerns were expressed and were not sustained. A contractor manager was asked to take off his engineering hat and put on his management hat, a phrase that has entered the literature on organizational failure as a specimen.

The solutions implemented. The investigating commission produced findings that went well beyond the seals, identifying a decision-making culture in which the acceptance of a deviation on one flight became the precedent for accepting it on the next, a process later named the normalization of deviance.

Structural changes followed: an independent safety office reporting outside the programme management chain, a requirement that dissenting technical opinions be recorded and transmitted upward rather than resolved at the level where they arose, and revised flight readiness reviews requiring affirmative certification rather than absence of objection.

That last change is the direct remedy for the burden inversion. Under an affirmative certification standard, the question is not whether anyone can prove danger but whether the responsible engineer will state that the vehicle is ready. Silence is no longer consent.

Measurable results. The programme flew for a further seventeen years before its second fatal accident, which the subsequent investigation found had organizational causes strikingly similar to the first, and which prompted the observation that cultural fixes decay unless maintained.

The most durable measurable outcome is the diffusion of the affirmative certification standard and the recorded-dissent requirement into other high-consequence industries. Both are now common in aerospace, nuclear power, and offshore operations.

Present-day relevance. Two findings transfer directly to the argument of this book.

The first is the burden of proof and its relationship to intervals. When the burden falls on the party arguing for delay, and the interval available for constructing an argument is short, the burden cannot be discharged and the default proceeds. Setting the burden is therefore equivalent to choosing the outcome whenever time is short, and this is true regardless of the merits.

The second is the normalization of deviance, which is the depletion mechanism of the nineteenth chapter appearing in an engineering organization. Each flight with damaged seals that returned safely was read as evidence that the damage was tolerable. The evidence accumulated in the wrong direction: what the flights actually demonstrated was that the margin had been consumed repeatedly without anyone measuring what remained.

That is precisely the inference the European powers made from five survived crises, and it is precisely the inference a modern government makes from a decade of confrontations that did not become wars.

Case Study Fourteen — The Northeast Blackout, August 2003

Background. Shortly after four in the afternoon on the fourteenth of August 2003, the electrical grid serving the north-eastern United States and Ontario collapsed. Fifty-five million people lost power, some for two days. The economic cost was estimated in the billions.

The core challenge. The cascade began with unremarkable events. A generating plant in Ohio went offline. Transmission lines, carrying more current than usual on a hot afternoon, sagged into trees that had not been trimmed and tripped out, one after another. Each loss shifted power onto remaining lines, which became more heavily loaded, sagged further, and tripped in turn.

None of this was unusual in kind. Grids experience line trips routinely and control rooms manage them. What made this cascade different was that the control room did not know it was happening.

The alarm system at the affected utility had failed some hours earlier. It failed silently: it did not report its own failure, and the screens continued to display the last state they had received. Operators were looking at a picture of a grid that no longer existed, and they were looking at it with the confidence appropriate to a system that had not told them anything was wrong.

By the time the situation was understood, the cascade had propagated beyond the point at which any local action could arrest it. The final phase, in which the failure spread across four states and a province, took about seven minutes.

Apply the framework. The window in a cascading grid failure shortens as it progresses: early on, an operator has minutes to shed load or reconfigure; in the final phase, the propagation is faster than any human process. The deliberation requirement, meanwhile, includes the step that failed here — knowing the current state — and that step had silently become infinite.

The solutions implemented. Reliability standards in North America were made mandatory and enforceable with financial penalties, having previously been voluntary guidelines among cooperating utilities. This was the central change and it was resisted for years before the blackout made it politically possible.

Vegetation management requirements were specified concretely rather than left to utility discretion. Wide-area monitoring was deployed: synchronized measurement units that report grid conditions many times per second, referenced to a common clock, giving operators a view across regions rather than only their own territory. Alarm systems were required to monitor and report their own health.

Measurable results. Synchronized measurement coverage in North America went from a few dozen units before the blackout to well over two thousand. Enforcement actions with penalties are now routine. No blackout of comparable extent has occurred in that interconnection in the two decades since, through a period that has included several events with similar initiating conditions.

Present-day relevance. The silent alarm failure is the finding worth carrying forward. A monitoring system that fails without announcing its failure is worse than no monitoring system, because it produces confident false information rather than acknowledged ignorance. Operators who know they are blind behave cautiously. Operators who believe they can see behave normally.

That distinction bears directly on the thirty-first chapter’s argument about apparent and real time. A decision-support system that continues to produce fluent output when its inputs have degraded is a silent alarm failure in a new form. The operator’s confidence is calibrated to the fluency of the output, not to the quality of the input, and nothing in the output indicates which is which.

The grid’s remedy — requiring monitoring systems to monitor themselves and to announce their own degradation — has no equivalent in the automated analysis now being adopted for decisions of considerably greater consequence. # Case Study Fifteen — The Texas Grid, February 2021

Background. In mid-February 2021 a winter storm brought sustained sub-freezing temperatures to Texas. Electricity demand rose toward record levels as heating loads increased. Simultaneously, generating capacity failed: gas wellheads froze, instrumentation lines froze, some wind turbines iced, and a nuclear unit tripped on a frozen sensor line.

At about a quarter past one in the morning on the fifteenth of February, the system frequency began to fall as demand exceeded supply. Grid operators shed load in stages. Frequency continued to decline. Operators later stated that the system came within approximately four minutes and thirty-seven seconds of an uncontrolled collapse that would have required a black start — the restoration of a grid from nothing — which for a system of that size is estimated to take weeks.

Rolling outages, imposed to prevent this, left millions without power for days in freezing conditions. The death toll was officially counted in the hundreds and independently estimated considerably higher.

The core challenge. The interval structure here is unusually clear. Grid frequency must be held within a narrow band. When generation falls short, frequency declines, and if it declines past defined thresholds for defined durations, generating units disconnect automatically to protect themselves, which removes further generation, which accelerates the decline. That is a cascade with a total duration of minutes.

The only remedy available inside that window is to shed load, which means deliberately cutting power to customers. It is automated at the final stages precisely because no human process fits in the window.

The deliberation requirement, meanwhile, sat entirely in the preceding decade. Whether to require generators to be winterized, whether to maintain reserve margins adequate for extreme events, whether to connect the region more substantially to neighbouring grids so that it could import during shortfalls — all of these were questions with years available for their consideration. Similar events in 1989 and 2011 had produced formal recommendations to winterize, and those recommendations were not made mandatory.

This is the cleanest available example of the point made throughout this book: the decisions that determine the outcome of a four-minute crisis are taken in the years before it, by people with unlimited time, and the four minutes contains no decisions at all.

The solutions implemented. Weatherization requirements were made mandatory with inspection and penalties. Gas facilities serving electricity generation were designated critical infrastructure so that they would not themselves be cut off during load shedding — a circularity that had aggravated the event, since shedding load to gas compressors reduced fuel to generators. Communication requirements between gas and electricity systems were established, the two having previously operated with limited visibility of each other despite total dependence.

Reserve requirements were revised and market mechanisms adjusted to pay for reliability rather than only for energy delivered.

Measurable results. Subsequent winter events have been managed without emergency conditions of the same order, though none has matched the 2021 storm in severity. Weatherization inspections now cover the great majority of generating capacity. The interconnection question — whether to link more substantially to neighbouring grids, which would bring the system under federal jurisdiction — remains unresolved, and is the largest available reserve-increasing measure not taken.

Present-day relevance. Two findings.

The first is the coupling that nobody owned. Electricity depended on gas; gas production depended on electricity; and the two sectors were regulated by different bodies, operated by different companies, and monitored by systems that could not see each other. Nobody was responsible for the joint behaviour. This is the compossibility problem of the ninth chapter in an industrial setting, and its remedy is the same: an institution whose specific job is to examine the interaction rather than the components.

The second concerns the recommendations of 1989 and 2011. They were correct, they were published, and they were not mandatory. The relevant failure was not analytical. Everyone knew. What was missing was any mechanism converting knowledge into obligation, and the absence of that mechanism cost more than the winterization would have.

Case Study Sixteen — Knight Capital, August 2012

Background. On the morning of the first of August 2012, an American market-making firm deployed new trading software to its production servers. The deployment was incomplete: seven of eight servers received the new code, and one did not.

When markets opened, the eighth server began executing orders according to a repurposed flag in the code that, in the older version still resident on that machine, activated a dormant function written years earlier for a different purpose. The function bought high and sold low, continuously, at a rate of thousands of orders per second.

In forty-five minutes the firm accumulated a loss of approximately four hundred and sixty million dollars, roughly four times its annual profit. It was rescued by an emergency capital injection that transferred ownership to its rescuers, and ceased to exist as an independent company within months.

The core challenge. What is remarkable is not the bug. Bugs are ordinary. What is remarkable is the forty-five minutes.

The firm’s own systems generated alerts within the first minute. Those alerts went to a group whose members did not have the context to interpret them, and the messages did not identify the affected system in a way that made the problem obvious. Staff spent the following half hour attempting diagnosis while the losses accumulated at roughly ten million dollars per minute.

A decision was then taken that made things worse: technicians, believing the new code was at fault, removed it from the seven servers that had received it correctly, thereby causing all eight servers to run the old code with the repurposed flag active. The response to the fault propagated the fault.

Finally the systems were shut down entirely, which was the action that stopped the loss and which could have been taken in the first minute.

Apply the framework. The window was zero: the machine was acting continuously, and every second of deliberation had a price. The deliberation requirement was the ordinary requirement for diagnosing a software fault, which is measured in tens of minutes at best. The mismatch was total, and the response was not a decision but a sequence of attempts, one of which was actively harmful.

There was no prepared default. Nobody had established in advance what the response should be to an unexplained runaway condition, and so the response was improvised by intelligent people under the worst imaginable pressure.

The solutions implemented. The regulatory response required firms to establish and periodically test risk management controls: pre-trade limits on order size and frequency, kill switches capable of disabling a trading system immediately, and change management procedures with deployment verification.

The most consequential idea is the kill switch, and it deserves the attention. A kill switch embodies a specific principle: that stopping is always available, always fast, and does not require the operator to understand what is wrong. It is the industrial equivalent of the symptom-based procedures adopted after Three Mile Island. You do not need a diagnosis to stop.

Measurable results. Kill switch capability and pre-trade risk controls are now standard and are examined by regulators. Deployment verification — confirming that code actually reached every target — is now automated in most trading firms, having been a manual checklist item. No comparable single-firm runaway loss has been reported in the region since.

Present-day relevance. The transferable principle is that in any system where the window is shorter than the diagnosis interval, the response must be decoupled from understanding. Stopping must be possible without knowing why.

This is a demanding requirement and it is generally resisted, because stopping has costs and because operators reasonably wish to avoid stopping unnecessarily. The resistance is strongest exactly where the principle matters most: in systems whose continuous operation is regarded as essential, which is to say in the systems whose runaway behaviour would be most damaging.

A defensive military system that cannot be halted without first establishing whether the threat is real is Knight Capital with worse consequences. The engineering answer exists and is well understood in one industry, and its adoption elsewhere has been minimal.

Case Study Seventeen — The Lehman Weekend, September 2008

Background. Over the weekend of the thirteenth and fourteenth of September 2008, senior officials of the American financial authorities and the chief executives of the major banks met in New York to determine the fate of an investment bank that would be unable to open for business on Monday.

No solution was found. The firm filed for bankruptcy protection early on Monday. Global credit markets seized within days; a money market fund broke its dollar-per-share value the following day, triggering a run on a sector previously regarded as equivalent to cash; and within a fortnight the authorities had constructed emergency support programmes of a scale that would have been unimaginable a month earlier.

The core challenge. The weekend was a decision with a hard deadline set by market opening in Asia on Monday morning. It was not adjustable. Within that window, the participants had to determine whether a private solution was possible, whether public support was legally available, and what the consequences of failure would be.

Each of those questions required more time than was available.

The private solution required a buyer to conduct diligence on a balance sheet of enormous complexity in about forty-eight hours. One potential buyer required a government guarantee against losses it could not quantify in the time available; another was constrained by its own domestic regulatory requirements, which could not be waived over a weekend.

The legal question — whether the central bank could lend against the firm’s assets — turned on a judgment about whether those assets were adequate security, and that judgment could not be made properly in the window. Officials later gave different accounts of whether the constraint was legal or political.

And the consequences question was the one that mattered most and was answered worst. The prevailing assessment was that the market had been given ample warning and had prepared. That assessment was wrong, not because the analysis was poor but because the relevant exposures were distributed through instruments and entities whose interconnections nobody had mapped. Establishing what would happen would have required an inventory that did not exist and could not be constructed over a weekend.

The solutions implemented. The regulatory response was extensive and much of it addressed the interval directly.

Resolution planning was mandated: large financial institutions must now maintain plans describing how they could be wound down without public support, updated annually and reviewed by authorities. This converts a weekend’s diligence into a document prepared over years.

Resolution authority was created, giving authorities legal powers to intervene in a failing institution without the delay of ordinary bankruptcy, and specifying in advance which claims are subordinated.

Central clearing of derivatives was mandated for standardized contracts, which addresses the mapping problem: a central counterparty knows the network of exposures because it is the network.

Measurable results. Resolution plans now exist for every globally systemic bank and several have been rejected and required revision, which is evidence that the exercise is not merely formal. Central clearing covers the substantial majority of interest rate derivatives, against a small fraction before. Several institutions have failed since without systemic consequences, which is the outcome the framework was built for.

Present-day relevance. The transferable finding is the value of preparing the diligence rather than the decision.

The Lehman weekend failed because the questions could not be answered in the window. The response was not to lengthen the window, which was set by the calendar and could not be moved, nor to pre-decide the outcome, which would have been absurd. It was to move the answering of the questions into peacetime: to require, in advance and continuously, that the information needed for a fast decision be assembled and maintained.

That is a third category of intervention alongside the two this book has emphasized, and it may be the most practical of them. You cannot always lengthen the window. You can often move the work.

Applied to the domains of this book: the identification data that could not be correlated in seven minutes aboard a warship, the attribution that cannot be established in three days after a cyber attack, the assessment of an adversary’s intentions that cannot be constructed during an ultimatum — in each case, some substantial part of the work could be done in advance and held ready, and in each case it largely is not.

Case Study Eighteen — NotPetya, June 2017

Background. On the twenty-seventh of June 2017, malicious software distributed through a compromised update to Ukrainian accounting software spread across corporate networks worldwide. It presented itself as ransomware but was designed to destroy data irrecoverably. Total damages were estimated at ten billion dollars, making it the most costly cyber incident recorded.

Among the affected was a Danish shipping company responsible for a substantial share of global container traffic. Its systems were destroyed globally within minutes. Terminals stopped. Ships arrived at ports that could not process them.

The core challenge. The propagation was faster than any human response. The software spread through internal networks using stolen credentials and an exploit, and infected an entire global corporate network in a period variously reported as under ten minutes. There was no interval in which anyone could have decided anything.

What the shipping company did, in the event, was pull the plug: staff physically disconnected systems and data centres around the world, in some cases by running through buildings unplugging cables. This is the kill switch of the previous case study, implemented by sprinting.

Reconstruction then faced a problem that is the most instructive part of the episode. The company’s domain controllers, which hold the credentials without which the network cannot be rebuilt, had been destroyed. Every one of them, worldwide, had been backed up in a manner that meant the backups were also compromised or unavailable — with a single exception, in Ghana, where a power cut had taken a server offline before the software reached it.

The recovery of the company depended on a machine that had survived by accident, and on physically transporting its contents to Europe because the network connection was inadequate.

The solutions implemented. The company rebuilt its infrastructure with a substantially different architecture: segmented networks, immutable and isolated backups, and a rebuilt identity system. Its disclosure of the incident in unusual detail became a reference case across the industry.

More broadly, the incident accelerated adoption of network segmentation, the assumption of breach as a design principle, and offline backup requirements. It also produced a substantial legal question when insurers declined claims on the basis of war exclusion clauses, given that the attack was attributed to a state military intelligence service; litigation that followed has reshaped how cyber insurance treats state-attributed events.

Measurable results. The company restored operations over approximately ten days, having processed a substantial fraction of its normal volume manually in the interim. Direct losses were around three hundred million dollars against a scenario that could plausibly have ended the company.

Segmented architectures and isolated backups are now standard guidance in every major framework, and adoption rates have risen substantially across large enterprises.

Present-day relevance. Three findings.

The propagation window was minutes and the human response window could not be less than tens of minutes, so no procedural remedy was available. The only effective responses were architectural and had to be in place beforehand. This is the general condition in the cyber domain and it is unlike every other domain examined here, where at least some human interval existed.

The accidental survival of the Ghanaian server is the sort of thing that should not be allowed to comfort anyone. The company survived because of a power cut. That is not resilience; it is luck, and the appropriate response to surviving by luck is to assume that the reserve was consumed rather than demonstrated, which is the nineteenth chapter’s point applied to an information system.

And the insurance question raises something this book has otherwise not addressed. When the distinction between a criminal act and an act of war is itself contested for years after the event, the mechanisms societies use to distribute the costs of catastrophe stop functioning, and the resulting uncertainty is itself a form of unresolved attribution operating on a timescale of years rather than days. # Case Study Nineteen — Apollo Thirteen, April 1970

Background. Fifty-five hours into a flight to the moon, an oxygen tank in the service module of Apollo 13 ruptured. The explosion damaged the second tank and the fuel cells that supplied the command module with electricity and water. Within about two hours the spacecraft that was to have carried three men home was inert.

They were two hundred thousand miles from Earth in a vehicle with no propulsion, no power, and no capacity to sustain life. They returned alive four days later.

The core challenge. The immediate window was set by consumables. The command module’s batteries, reserved for re-entry, would sustain the crew for a few hours at most. The lunar module attached to it had its own power, oxygen, and engine, designed to support two men for two days on the moon’s surface, and would now have to support three men for four days in space.

The trajectory decision had to be made within hours: whether to turn around directly, which required an engine burn the crew could not be certain was safe, or to continue around the moon and use its gravity, which was slower but used a propulsion system known to be intact. The choice was made for the slower, safer path.

Then a series of problems arrived, each with its own interval. Carbon dioxide accumulated because the lunar module’s scrubbers were sized for two men and the spare cartridges from the command module were the wrong shape. Power had to be reduced to a level the vehicle had never been designed to operate at, and then restored in a sequence that had never been attempted. Course corrections had to be made without the guidance platform, using the Earth’s terminator as a reference. And the command module had to be brought back to life from cold on a power budget that permitted no mistakes and no second attempts.

What is striking, examined as an interval problem, is that at no point did the deliberation requirement exceed the window — and that this was achieved deliberately rather than by luck.

The solutions implemented. Four mechanisms did the work, and they are the closest thing to a positive model that this collection of case studies contains.

The first was the deliberate purchase of time. Every early decision was evaluated partly on how much interval it created for later decisions. The slower return trajectory is the clearest example: it was chosen in preference to a faster option specifically because the additional days permitted problems to be solved that had not yet been identified.

The second was parallel work. The control organization split into teams working on different problems simultaneously, with one team working the immediate situation while others worked problems that would arise in twelve, twenty-four, and forty-eight hours. Nobody waited for a problem to become urgent before beginning on it.

The third was ground testing before commitment. No procedure was transmitted to the crew before being tested in a simulator on the ground by people using the same equipment. The re-entry power-up sequence, written from nothing, was tested repeatedly before the crew saw it.

The fourth was disciplined refusal to act. The flight director’s standing instruction was that nobody should make the situation worse by guessing, and that a controller who did not know should say so rather than offer a plausible answer. This was enforced against considerable pressure.

Measurable results. The crew returned alive with margins that were narrow but positive throughout. The review board produced findings about the tank’s design and about the testing procedure that had damaged it, and those were corrected.

The organizational practices were retained and became the model for mission operations. They have since been adopted in emergency management, in surgical crisis management, and in the incident command systems used by fire services, all of which now use variants of the parallel-team structure with a separation between immediate response and forward planning.

Present-day relevance. This case earns its place because it demonstrates that a system facing a severe interval problem can manage it, and identifies precisely what that management consists of.

Every one of the four mechanisms is available to any organization. Buying time with early decisions requires only that the interval be treated as a resource worth spending other things to obtain. Parallel teams require only that somebody be assigned to problems that are not yet urgent. Ground testing requires a duplicate of the system and the discipline not to skip the step. Disciplined refusal requires a culture in which admitting ignorance is not punished.

Against the arguments of this book’s later chapters, the third mechanism deserves particular emphasis. Every procedure was tested on the ground before being sent up, which meant that no one relied on an analysis that had not been checked against reality. As decision-support systems become more capable and more fluent, the equivalent step — verifying the recommendation against something other than the system that produced it — becomes both more necessary and easier to skip, because the recommendation arrives already looking like a tested answer.

Case Study Twenty — The Year Two Thousand

Background. Through the second half of the twentieth century, a great deal of software represented years with two digits. The reasons were originally economic, storage having been genuinely expensive, and later inertial. The consequence was that on the first of January 2000, systems performing date arithmetic might treat the year as 1900, with unpredictable results in any process involving intervals, sequencing, or expiry.

The problem had been identified in print as early as the mid-nineteen eighties. Substantial remediation programmes began in the mid-nineteen nineties. Global expenditure has been estimated in the hundreds of billions of dollars.

Very little happened. A number of minor failures occurred and were fixed. No infrastructure collapsed.

The core challenge. The date was fixed and known decades in advance, which makes this the only case in this collection where the window was both enormous and precisely known.

The difficulty was of a different kind: the work was distributed across every organization holding software, much of which was undocumented, written in languages whose practitioners had retired, and running on hardware nobody was certain of the contents of. Establishing what needed fixing was harder than fixing it.

And the incentive structure was hostile. Expenditure was certain, large, and immediate; the benefit was the absence of an event whose magnitude was contested. Any executive who spent heavily faced, in the event of success, an audience concluding the money had been wasted.

The solutions implemented. Governments established coordination bodies with authority to require reporting. Regulated sectors were subjected to mandatory audit and disclosure. Exposure through suppliers and customers was addressed through contractual certification requirements, which propagated the obligation down supply chains faster than regulation could have.

Legal changes were made in several jurisdictions limiting liability for organizations that shared information about their remediation, addressing a genuine obstacle: firms feared that disclosing what they had found would be used against them.

Testing was performed against rolled-forward clocks in isolated environments, which is the ground-testing principle of the previous case.

Measurable results. Reported failures were numerous but small: some card terminals, some billing systems producing century-long charges, some monitoring displays. In countries that had spent comparatively little, outcomes were not obviously worse, a fact which has been used ever since to argue that the exercise was unnecessary.

That argument cannot be settled, and its unresolvability is the interesting part.

Present-day relevance. This case is included for one reason: it is the only large-scale instance in modern memory of a society identifying an interval problem decades in advance and spending heavily to address it before anything happened, and its reputation is that of an embarrassment.

That reputational outcome is the single greatest obstacle to every remedy proposed in this book. A minimum-response-interval agreement, an audit of migrated authorities, an architectural change to preserve deliberation time — each has the same profile. Certain cost now; uncertain benefit later; and success indistinguishable from the problem having been imaginary.

The July crisis of 1914 has the opposite profile, which is why it is remembered. Nobody spent anything, and the consequences were unmistakable.

Between those two examples sits every decision a society makes about whether to buy itself time it may not need. The one that spent is remembered as foolish; the one that did not is remembered as a tragedy. A rational institution reading those two histories would conclude that the reputational cost of prevention is real and the reputational cost of catastrophe is diffuse, and would act accordingly, which is what institutions do.

The only available remedy is to insist that prevention be judged on the reasoning available beforehand rather than on the outcome — the standard applied, as a matter of course, in medicine and aviation, and almost nowhere else.

Abilene paradox. A situation in which a group takes an action that every member privately opposes, because each wrongly believes the others want it. Named after a story about a family driving to Abilene, Texas, for a meal none of them wanted. Distinct from latency collapse, in which preferences genuinely differ and the failure is one of time rather than communication.

Action window. The time remaining before somebody else does something irreversible that removes an option you currently have. It is set by other people, not by you.

Adversarial reading. The habit, normal in a crisis, of interpreting the other side’s actions in the least favorable way available. It makes conciliatory gestures look like weakness.

Agadir crisis. A confrontation in 1911 between Germany and France over Morocco, triggered by the arrival of a German warship. Settled peacefully by a colonial exchange.

Aggregate risk. The total probability of an event over a sequence of opportunities, as opposed to its probability on any one occasion.

Alarm flood. A situation in which a monitoring system produces more warnings than any human can read, so that the important one is buried. It consumes the very time it was meant to protect.

Alliance system. The network of treaties binding the European powers before 1914, which meant that a quarrel between two states obliged others to become involved.

Ambiguity. A condition in which the available information supports more than one interpretation. It consumes intervals, which is why removing it in advance is valuable.

Anomaly. An observation that does not fit expectations. Expert groups under pressure often explain anomalies away rather than investigating them.

Apparent time. How long a decision seems to require, judged by how quickly one can obtain an answer. Modern tools have reduced it dramatically without reducing the time actually needed to act lawfully.

Attribution. Establishing who was responsible for an act. In the cyber domain it takes weeks or months, far longer than the time available for a response.

Authorization latency. The part of a government’s response time taken up by finding the people entitled to decide, briefing them, and obtaining their lawful agreement. It has barely changed in a century.

Automation surprise. What happens when an automatic system withdraws or behaves unexpectedly, handing control to a human who has been out of practice precisely because the automation was working.

Balkan Wars. Two wars in 1912 and 1913 among the states of south-eastern Europe, during which Austria-Hungary and Russia twice came close to fighting each other and twice did not.

Bifurcation. A point at which a small change in conditions causes a system to jump abruptly to a different state rather than changing gradually.

Black start. Restoring an electrical grid from a complete shutdown, with no power available to start the generators. For a large system it takes weeks.

Bounded rationality. The idea that decision makers reason well within limits of information, attention, and time, rather than perfectly.

Burden of proof. Which side must demonstrate its case. Where the interval is short, whoever carries the burden loses, regardless of the merits.

Cascade. A failure that spreads from one part of a system to another, each failure making the next more likely. The defining behavior of tightly coupled systems.

Central clearing. An arrangement in which financial contracts pass through a single institution, which therefore knows the whole network of obligations. Adopted after 2008 because nobody had been able to map that network in a crisis.

Chain of command. The sequence of authority through which orders pass. Each link adds to authorization latency.

Ciphering. Converting a message into code before transmission. In 1914 it was done by hand and took hours for a long message.

Circuit breaker. A rule that halts trading automatically when prices move too fast, for a fixed short period, regardless of anyone’s opinion. The only widely used institution that manufactures deliberation time by force.

Command and control. The arrangements by which military forces are directed: who may order what, how orders are transmitted, and how they are authenticated.

Compossibility. The capacity of several plans to be carried out at the same time without producing a result that none of them intended. The war plans of 1914 lacked it.

Concert of Europe. The informal practice by which the great powers settled disputes through conferences. It worked repeatedly between 1905 and 1913 and required weeks each time.

Confirmation. A second, independent indication that something is real.

Contingency plan. A prepared response to a situation that has not yet occurred.

Contraction ratio. The proportion by which each successive deadline in a crisis is shorter than the last. Estimated at roughly two thirds for the formal ultimatums of July 1914.

Control parameter. A quantity that, when varied, moves a system from one state to another. In the mobilization model it stands for political pressure.

Convex hull. The set of all mixtures of a group of options. The book shows that a mixture of individually acceptable positions can be unacceptable to everyone.

Coupling. The degree to which parts of a system affect one another. Tight coupling means that a disturbance in one part reaches the others quickly and cannot be absorbed locally.

Credibility. The belief by others that one will do what one has said. Its pursuit is among the strongest forces preventing de-escalation.

Crisis stability. The property of a confrontation in which neither side gains by acting first. Its opposite is a situation rewarding whoever moves soonest.

Cross-check. Confirming an indication using an independent system with different failure modes. It prevented two American false alarms from escalating in 1979 and 1980.

Cyber attribution. See attribution. The special difficulty is that the evidence is contestable indefinitely, so even a correct response can be widely believed to be unprovoked.

De-escalation. An act that lowers the level of a confrontation. Structurally disfavoured, and requiring more time than escalation does.

Decapitation. An attack aimed at a state’s leadership and command system. The possibility of it is the main argument for pre-delegating authority.

Declaration of war. A formal statement creating a legal state of war. Austria-Hungary issued one by telegram in 1914 specifically because it could be done faster than anyone could object.

Default. An action prepared in advance and executed without fresh deliberation when there is no time to decide. War plans, fire drills, and standing rules of engagement are all defaults.

Deliberation latency. The minimum time an institution needs to turn information into a decision carrying its authority. It includes transmission, authorization, and promulgation.

Depletion. The consumption of reserve. Each survived crisis uses some up, which is why a record of successful crisis management is a warning rather than a reassurance.

Deterrence. Preventing an action by threatening a response. It requires that the threatened response be credible, which usually means preparing it in advance.

Diligence. The investigation required before a decision. When it cannot be completed in the window, it must be prepared beforehand or dispensed with.

Doubling time. The interval in which an epidemic doubles in size. It sets the window within which public health decisions must be taken.

Dual phenomenology. A requirement that an attack be confirmed by two physically different kinds of sensor before being treated as real. Undermined when the two systems share software or data.

Early warning. Systems designed to detect an attack in progress. They shorten the time to detection without lengthening the time available to respond.

Emergency powers. Legal authorities available in a crisis. They are typically easier to invoke than to terminate.

Escalation. An act that raises the level of a confrontation. Its effect in this book’s terms is to shorten everyone’s window.

Escalation dominance. The ability to prevail at every level of a conflict, which in theory permits controlled escalation and in practice encourages it.

Escalation level. A position in a sequence of increasingly severe acts. The number of levels reached, rather than their severity, determines when collapse occurs.

Event-based procedure. An emergency procedure requiring the operator first to identify what has gone wrong. Replaced in the nuclear industry by symptom-based procedures after 1979.

Exit cost. What it costs to leave a state one has entered. When it exceeds the cost of entry, the system has hysteresis.

Fait accompli. An act performed quickly and irreversibly so that others must respond to a changed situation rather than argue about a proposed one.

False negative. Failing to detect something that is present.

False positive. Reporting something that is not present. In warning systems it produces real military activity, which the other side observes.

First-mover advantage. The benefit of acting before an opponent. Where it is large, every window in the system shortens automatically, because delay is costly to everyone.

First-passage problem. The question of when a repeated risk first produces its event, rather than whether any particular trial does. It explains why the crisis that ends a peace need have no special features.

Fischer controversy. The dispute that followed a German historian’s argument in 1961 that Germany had deliberately sought a war in 1914. It ended the earlier consensus that nobody was responsible.

Flash crash. A very rapid fall and recovery in market prices, driven by automatic systems interacting faster than anyone could intervene. The best known occurred in 2010.

Fold bifurcation. The mathematical form of a system that jumps abruptly and does not return along the same path. It produces the gap between entry and exit pressures.

Frailty. In medicine, the loss of physiological reserve. A frail body performs normally until stressed, then fails to a challenge a younger one would absorb. The closest medical analogue of a depleted political system.

Frequency. In an electrical grid, the rate of alternation that must be held within a narrow band. Its decline is the measure of an impending collapse.

Geometric contraction. A pattern in which each successive interval is a fixed fraction of the last, so that intervals fall quickly and predictably.

Governance. The arrangements determining who decides what. Almost all latency lives here rather than in technology.

Granularity. How finely an option can be adjusted. Systems built with only two settings force a choice between doing nothing and doing everything.

Groupthink. The suppression of dissent inside a cohesive decision-making body. Requires a group in a room, which the governments of 1914 did not have.

Halt in Belgrade. A proposal of 28 July 1914 that Austria-Hungary occupy the Serbian capital as a pledge and then negotiate. Acceptable to nobody, and an example of the failure of compromise by splitting the difference.

Hazard rate. The probability that an event occurs in a given period, given that it has not yet occurred. This book argues it was rising across the pre-1914 decade.

Hotline. The direct communications link between Moscow and Washington, established in 1963. Teleprinters, not telephones. The clearest instance of a state deliberately reducing its own response time.

Hysteresis. The property of a system whose path back differs from its path in, so that reversing a change requires more force than causing it did.

Illusion of readiness. The belief that an organization can act quickly, formed from observing the parts of it that are fast while the slow parts remain invisible.

Inadvertent war. A war that occurs without any participant having chosen it in the form it took.

Interoperability. The capacity of separately built systems to work together, which requires that someone examine them jointly.

Interpolation. Finding a position between two stated ones. Safe only when each side’s losses are roughly proportional to its gains, which in disputes over prestige they are not.

Joint execution. What happens when several parties carry out their prepared plans at the same time. The result may lie outside every plan.

July Crisis. The five weeks between the assassination at Sarajevo on 28 June 1914 and the outbreak of general war in early August.

Kill switch. A control that stops a system immediately without requiring the operator to understand what is wrong. Mandated in financial trading after 2012 and largely absent elsewhere.

Kriegsschuldreferat. The war guilt section established by the German Foreign Office in 1919 to demonstrate that Germany had not been responsible for the war. Its work shaped the historiography for decades.

Latency. Delay. Used throughout this book for the time an institution requires rather than the time a person takes to think.

Latency collapse. The condition in which the time available for deciding has fallen below the time required, for every participant at once. Decisions stop being made and prepared plans are executed instead.

Latency floor. The shortest time in which an institution can produce an authorized decision under the best conditions. Estimated at roughly twelve hours for a European government in 1914.

Launch on warning. A posture in which retaliation is ordered on detection of an incoming attack rather than after it arrives. It is latency collapse adopted deliberately as policy.

Legitimacy. The acceptance of an authority’s right to act, without which decisions taken quickly may not be obeyed.

Load shedding. Deliberately cutting power to some customers to prevent an entire grid collapsing. Automated at the final stages because no human process fits the window.

Loop. A feedback path in which an output returns as an input. Escalation between two states is a loop, as is a cascade in a network.

Margin. The distance between a system’s current state and the point at which it fails.

Mediation. A third party’s attempt to settle a dispute. It requires an interval in which to circulate and consider proposals, and was repeatedly overtaken in 1914.

Migration of decisions. The gradual movement of actions from the category requiring authorization to the category performed automatically. It happens after near misses and is never audited.

Minimum response interval. A proposed rule that formal demands carrying military consequence must grant at least a specified time for reply.

Mobilization. Bringing armed forces from peacetime to wartime condition. In 1914 it involved millions of men moved by railway on schedules prepared years in advance.

Momentum. The appearance that events are proceeding independently of anyone’s decisions. Usually a report that response times have exceeded windows.

Near miss. An incident that could have produced a catastrophe and did not. Frequently read as evidence of safety when it is evidence of exposure.

Non-compossibility. The condition in which several plans cannot all be executed without producing an outcome none of them contemplated.

Normal accident. An accident arising from the ordinary interaction of a system’s parts rather than from any component failing. Characteristic of tightly coupled systems with interactive complexity.

Normalization of deviance. The process by which a departure from specification, having caused no harm on several occasions, comes to be treated as acceptable.

Notification regime. An arrangement under which states announce exercises and launches in advance, so that observers do not have to interpret them under time pressure.

Observability. Whether a system’s true state can be seen by its operators. A monitoring system that fails silently destroys it.

Offensive doctrine. A military belief that attacking is decisive and that the side that strikes first wins. Widely held in Europe before 1914 and a direct cause of shortened windows.

Option set. The actions actually available to a decision maker, as distinct from those he can describe. Almost always smaller, and the difference is not written down anywhere.

Partial mobilization. A call-up directed against one enemy rather than all. Russia attempted to order one in 1914 and discovered no schedule for it existed.

Pawl. The catch in a ratchet that permits motion in one direction only. Used in this book for the four mechanisms that make crises escalate rather than subside.

Period preparatory to war. A Russian regulation of 1913 permitting a range of military preparations on standing authority rather than by specific decision. The type specimen of the migration of decisions.

Pre-authorization. Granting in advance the authority to perform an action, so that it can be taken without further consultation. Safe against pathogens and earthquakes; dangerous against opponents who are planning around it.

Pre-delegation. The specific practice of deciding in advance who may order the use of force under defined circumstances.

Precommitment. Deliberately restricting one’s own future options in order to make a threat or promise credible. It reduces one’s own reversibility on purpose.

Preventive war. A war begun because the balance is expected to shift unfavourably, rather than in response to an act.

Promulgation latency. The time required for a decision, once taken, to reach the people who must carry it out.

Provenance. Where a claim came from and who benefited from its acceptance. It does not settle whether the claim is true, but it predicts which version of it will circulate.

Quarantine line. The cordon around Cuba in 1962. Deliberately drawn closer to the island than was militarily desirable, in order to give the Soviet leadership more time to think.

Ratchet. The tendency of crises to move in only one direction, produced by domestic audiences, adversarial reading, first-mover logic, and the fact that de-escalation requires a committee while escalation requires an office.

Rate trigger. A rule that fires on how fast something is changing rather than how bad it has become. The design principle behind market circuit breakers.

Reaction requirement. The time a party is granted in which to respond. An ultimatum states it explicitly; other acts impose it implicitly.

Realized outcome. What actually happened, as opposed to what anyone planned. In 1914 it lay outside every participant’s intended set.

Redundancy. Duplication intended to survive a failure. It fails when the duplicates share a cause of failure.

Reflexivity. The property of a system whose participants’ beliefs about it change its behaviour.

Reserve. The margin between the time available and the time required. The central quantity of this book, and one that appears in no national accounts.

Resolution planning. A requirement that large financial institutions maintain a documented plan for their own orderly failure. An example of moving diligence into peacetime.

Reversibility. The capacity to undo an action at a cost comparable to the cost of taking it.

Rules of engagement. Standing instructions specifying when force may be used. Pre-authorized defaults for situations too fast for consultation.

Scarring. The residue left by a crisis that was survived: a lowered threshold, a shortened procedure, a reputation to be restored.

Scenario fulfilment. The tendency, under time pressure, to interpret ambiguous information as conforming to an expected pattern. Identified in the investigation of the 1988 Iran Air shootdown.

Schlieffen Plan. The German deployment scheme requiring a rapid attack on France through Belgium before Russia could mobilize fully. Its assumptions about Belgium and Britain were contradicted in advance and disbelieved.

Scope ambiguity. A dispute in which the parties are quantifying over different things. The argument about whether the war was avoidable or inevitable is one.

Sequential play. A situation in which each party can observe the other’s move before committing. It requires intervals long enough to observe, and disappears when windows shorten.

Signal. An act intended to communicate rather than to accomplish. Signals are read adversarially in crises and frequently mean the opposite of what was intended.

Simultaneous play. A situation in which all parties commit without seeing what the others have done. It produces far worse outcomes than sequential play with the same preferences.

Slack. The difference between the action window and the deliberation latency. When it is negative for everyone at once, the system is in latency collapse.

Sleepwalkers. A description of the statesmen of 1914 as watchful but unseeing. Accurate as a metaphor and unhelpful as a mechanism.

Status quo. The situation before a crisis, used as the reference point against which outcomes are judged acceptable or not.

Strategic warning. Advance notice that an attack may be coming, as distinct from tactical warning that one is under way.

Structural explanation. An account of an event in terms of the arrangement of a system rather than the intentions of its members.

Sunk cost. Expenditure already incurred. It should not affect a decision and reliably does, particularly when the expenditure was in lives.

Symptom-based procedure. An emergency procedure telling the operator what to do about observable conditions, without requiring a diagnosis first. The general remedy for short windows.

Telegraphic declaration. Austria-Hungary’s method of declaring war on Serbia in 1914, chosen because it could be issued faster than mediation could be organized.

Threshold. A level at which behaviour changes discontinuously. Systems near thresholds behave normally until they do not.

Tight coupling. A condition in which parts of a system depend on each other closely enough that a disturbance cannot be absorbed locally.

Timetable thesis. The argument that railway schedules removed the freedom of statesmen in 1914. Substantially refuted, and distinct from this book’s claim, which concerns intervals rather than choices.

Transmission latency. The time required to send a message and render it readable. Reduced to nothing since 1914, unlike the other components of response time.

Trollope ploy. Answering the more favourable of two conflicting messages and behaving as though the other had not arrived. Used in October 1962 and a rare instance of a deliberately broken ratchet.

Two clocks. The pair of quantities at the centre of this book: how long you need, and how long you have.

Ultimatum. A demand carrying a deadline. Its function is not to communicate terms but to impose on the recipient a response interval shorter than his deliberative capacity.

Unauthorized refusal. Declining to execute a prepared response without authority to decline. The only remedy remaining inside a collapsed system, and an unreliable one.

Verification. Establishing that an indication is real. Where it takes longer than the window, the response is necessarily a default.

Versailles Article 231. The treaty provision assigning responsibility for the war’s losses, and the legal foundation of reparations. It gave the question of war origins a price.

War aims. What a state hopes to obtain by fighting. In July 1914 the five great powers held five different and individually achievable ones.

War guilt. The question of responsibility for the outbreak of the war, which became a matter of treaty law and therefore of money.

War plan. A detailed scheme for the opening operations of a war, prepared in peacetime. Every European power had one and none had seen another’s.

Wargame. A simulation of a conflict used to test plans or study behaviour. Recent studies using artificial systems found that no participant ever chose to de-escalate.

Window contraction. The shortening of available response intervals as a crisis progresses. Approximately geometric in July 1914.

Zentralstelle. A German body founded in 1921 to study the causes of the war, covertly financed by the Foreign Office, which promoted the view that responsibility was widely distributed.

Zero-sum. A situation in which one party’s gain is exactly the other’s loss. Disputes that are close to zero-sum are the ones where splitting the difference is most dangerous.

Timeline

Fifth century BC. Thucydides records the Athenian and Spartan deliberations before and during the Peloponnesian War, establishing the practice of examining not merely what states did but the intervals and assemblies in which they decided.

  1. Machiavelli argues that fortune governs half of human affairs and that preparation made in quiet times determines what can be done in urgent ones. The distinction between the moment of decision and the years that shaped it enters political writing.

  2. Hobbes describes the condition in which parties, each fearing the other’s first strike, attack preemptively although none desires war. The structure of the security dilemma is stated two centuries before it is named.

  3. Clausewitz, published posthumously, distinguishes war as it is planned from war as it occurs, and introduces friction: the accumulation of small delays and frictions that make the real thing differ from the design.

  4. The electric telegraph is patented. Over the following three decades the time required to send a message between European capitals falls from days to minutes, while the time required to convene a council does not change at all. The gap between transmission and authorization opens for the first time.

1866 and 1870. Prussian victories over Austria and France are attributed to railway mobilization and general staff planning. Every European power begins building mobilization schedules of increasing detail and decreasing flexibility.

1899 and 1907. The Hague Peace Conferences establish procedures for mediation and arbitration, including a convention on the opening of hostilities. The procedures require weeks to invoke.

1905 to 1906. The First Moroccan crisis. Settled by conference at Algeciras. The first of five great-power confrontations that will be survived.

1908 to 1909. The Bosnian annexation crisis. Russia yields after a German demand, and the humiliation establishes a threshold below which Russian governments will not go again.

  1. The Agadir crisis. A German warship at a Moroccan port produces several weeks of European alarm and a German financial panic, and is settled by a colonial exchange.

1912 to 1913. The Balkan Wars. Austria-Hungary and Russia twice mobilize partially against each other and twice draw back, the disputes being settled by an ambassadors’ conference in London.

March 1913. Russia adopts the Statute on the Period Preparatory to War, permitting a range of military preparations on standing authority rather than by specific decision. Deliberated steps become automatic ones.

  1. Germany passes an army bill, France adopts a three-year service law, and Russia begins its Great Program of rearmament. The cost of being the last to mobilize rises sharply for everyone.

28 June 1914. Archduke Franz Ferdinand is assassinated at Sarajevo. European chancelleries react with irritation rather than alarm.

5 to 6 July 1914. Germany assures Austria-Hungary of support. The assurance is framed by beliefs about what Vienna requires.

23 July 1914, six in the evening. The Austro-Hungarian note is delivered in Belgrade with a forty-eight hour limit, timed to follow the departure of the French president and premier from St Petersburg.

25 July 1914. Serbia replies within the deadline, conceding nearly everything. Relations are broken within the hour and the Austro-Hungarian minister leaves by the evening train.

26 July 1914. Britain proposes a four-power conference. Assembling it would require days.

28 July 1914, morning. The German Emperor reads the Serbian reply, judges that every ground for war has disappeared, and proposes a limited occupation of Belgrade as a pledge. Austria-Hungary declares war on Serbia by telegram the same morning. The proposal reaches Vienna that night.

29 to 30 July 1914. Russia attempts partial mobilization, discovers no schedule exists, and orders general mobilization on the thirtieth.

31 July 1914. Germany proclaims a state of imminent danger of war and issues ultimatums to Russia with twelve hours and to France with eighteen.

1 August 1914, evening. On a misread telegram from London, the German Emperor orders the army turned east and is told it cannot be done. The telegram is clarified within hours.

2 to 4 August 1914. Germany gives Belgium twelve hours, declares war on France, enters Belgium, and receives a British ultimatum expiring that night. The granted intervals have fallen from forty-eight hours to about seven.

  1. Peace initiatives from the Reichstag, the Papacy, the Austrian emperor, and a former British foreign secretary all fail. The cost of leaving the war now exceeds the cost of entering it by the whole weight of the dead.

  2. The Treaty of Versailles assigns responsibility for the war’s losses. The German Foreign Office establishes a war guilt section.

  3. A central office for the study of the causes of the war is founded in Germany, covertly financed by the Foreign Office.

1922 to 1927. Forty volumes of German diplomatic documents are published, an edited selection that shapes international scholarship for a generation.

  1. A study commissioned from the jurist Hermann Kantorowicz reaches conclusions unfavourable to the German case and is suppressed. It appears in 1967.

  2. Lewis Fry Richardson develops coupled equations for arms competition, founding the formal modelling of escalation.

  3. A fire crew is overrun at Mann Gulch, Montana. The subsequent analysis of why an organization loses its structure under time pressure becomes a foundation of the study of organizational failure.

1960 and 1966. Thomas Schelling analyses commitment, precommitment, and the threat that leaves something to chance, establishing that shortening one’s own options can be a bargaining instrument.

October 1962. The Cuban missile crisis. The quarantine line is drawn closer to Cuba than is militarily desirable in order to lengthen the interval; a standing advisory group is kept in continuous session; a conciliatory message is answered and a harder one ignored; and the destruction of a reconnaissance aircraft is not answered with the prepared retaliation. A Soviet submarine officer separately declines to concur in the use of a nuclear torpedo.

June to August 1963. The Moscow-Washington direct communications link is agreed and installed. Teleprinters, tested hourly, first used in earnest in 1967.

1961 to 1969. Fritz Fischer’s argument for deliberate German war-seeking divides German historiography. A. J. P. Taylor publishes the timetable thesis in its most compressed form.

1972 and 1974. Irving Janis names groupthink; Jerry Harvey publishes the Abilene paradox. Both become standard explanations of collective decisions nobody wanted, and both concern groups in rooms.

  1. A training tape loaded into a live American warning system produces a false attack indication resolved in about six minutes. The Three Mile Island accident occurs, leading to the replacement of event-based emergency procedures with symptom-based ones.

  2. A failing integrated circuit costing less than a dollar produces two further false attack indications.

  3. Stanislav Petrov declines to report a satellite indication of five incoming missiles. The NATO exercise Able Archer is read in Moscow as possible preparation for a first strike.

  4. Charles Perrow publishes the analysis of accidents in tightly coupled systems as normal properties rather than deviations. Stephen Van Evera publishes on offensive doctrine and 1914.

  5. The Challenger accident demonstrates the effect of placing the burden of proof on those arguing for delay. The Chernobyl accident demonstrates the consequences of not telling operators about counterintuitive emergency system behaviour.

  6. American equity markets fall twenty-three percent in a day. The subsequent commission recommends mandatory trading halts.

  7. An American cruiser destroys an Iranian airliner in the Strait of Hormuz after a seven-minute identification problem. Trading circuit breakers are introduced.

1990 and 1991. Marc Trachtenberg and Jack Levy demonstrate that the statesmen of 1914 understood mobilization and were not overridden by their general staffs, refuting the strong timetable thesis.

  1. Scott Sagan documents the accumulation of nuclear near-misses that organizations had recorded as successes.

  2. A Norwegian scientific rocket is detected by Russian early warning; the Russian president’s strategic terminal is activated. The advance notification had reached a ministry and not the radar operators.

1998 to 2000. A joint early warning centre is agreed by the American and Russian governments and never opens. Remediation of two-digit year representations concludes with very few failures and a lasting reputation for extravagance.

  1. A midair collision over Überlingen results from contradictory instructions issued by a controller and an automatic system, each acting correctly. The priority rule is subsequently made unambiguous and universal.

  2. A silent alarm system failure at an Ohio utility permits a cascade that removes power from fifty-five million people. Mandatory reliability standards and wide-area monitoring follow.

  3. The collapse of an investment bank over a weekend demonstrates that the diligence required for a fast decision cannot be performed in the window. Resolution planning and central clearing follow.

  4. Air France 447 is lost in four minutes and twenty-three seconds after an airspeed sensor blockage, establishing automation surprise as a recognized accident class.

  5. An automated selling program interacts with automated market makers to remove nine percent of American equity value in thirty-six minutes. A deepwater well blows out after an anomalous pressure test is explained away.

  6. An earthquake and tsunami disable the Fukushima Daiichi station; the venting decision is delayed by an authorization chain longer than the physical window, and the remedy adopted afterward is to delegate authority to the site.

  7. A trading firm loses four hundred and sixty million dollars in forty-five minutes through an incomplete software deployment. Kill switches become mandatory.

  8. Destructive software distributed through a compromised accounting update propagates across global corporate networks in minutes, and one shipping company’s recovery depends on a server that survived a power cut in Ghana.

  9. A false ballistic missile alert in Hawaii takes thirty-eight minutes to retract because no cancellation template exists. The first of two crashes of a new airliner type occurs, resting on an assumption that crews would diagnose an undisclosed system in seconds.

  10. Governments with standing authorities and pre-agreed thresholds, established after an earlier outbreak, act faster against a pandemic than those requiring fresh legislation.

  11. An electrical grid comes within minutes of an uncontrolled collapse whose repair would have taken weeks, having declined to act on winterization recommendations issued after comparable events in 1989 and 2011.

2024 to 2026. Studies place artificial systems in simulated diplomatic and military crises. Escalation is near universal, and across the largest such study no participant ever selects a de-escalatory move.

  1. The formal argument of which this book is the popular expansion is deposited, proposing that the outbreak of 1914 be understood as a collapse of available decision time below required deliberation time, and that the same structure now governs command architectures operating at machine speed.

Literature

Albertini, Luigi. The Origins of the War of 1914. Three volumes. Translated by Isabella M. Massey. London: Oxford University Press, 1952 to 1957. The indispensable hour-by-hour reconstruction, and the source from which most of the timings used in this book ultimately derive.

Allison, Graham, and Philip Zelikow. Essence of Decision: Explaining the Cuban Missile Crisis. Second edition. New York: Longman, 1999. Three competing models of how governments decide, applied to the same thirteen days.

Bundesstelle fur Flugunfalluntersuchung. Investigation Report AX001–1–2/02: Uberlingen. Braunschweig, 2004. The clearest documented case of two correctly functioning authorities issuing contradictory instructions.

Blair, Bruce G. The Logic of Accidental Nuclear War. Washington: Brookings Institution Press, 1993. The closest predecessor to this book’s treatment of launch on warning as institutionalized shortage of time.

Brummitt, Charles D., Raissa M. D’Souza, and E. A. Leicht. Suppressing Cascades of Load in Interdependent Networks. Proceedings of the National Academy of Sciences 109 (2012). Shows that interdependence between networks is not uniformly bad, which complicates the simple version of the cascade story.

Buldyrev, Sergey V., Roni Parshani, Gerald Paul, H. Eugene Stanley, and Shlomo Havlin. Catastrophic Cascade of Failures in Interdependent Networks. Nature 464 (2010). The foundational result that coupling turns gradual degradation into abrupt collapse.

Bureau d’Enquetes et d’Analyses. Final Report on the Accident on 1st June 2009 to the Airbus A330–203 Registered F-GZCP. Paris, 2012. The Air France 447 investigation, and the origin of much subsequent work on automation surprise.

Chernavskikh, Vladislav, and Jules Palayer. Impact of Military Artificial Intelligence on Nuclear Escalation Risk. SIPRI Insights on Peace and Security 2025/06. Stockholm, 2025. Policy analysis of how automated systems compress warning and decision timelines.

Clark, Christopher. The Sleepwalkers: How Europe Went to War in 1914. London: Allen Lane, 2012. The major recent synthesis, and the source of the metaphor this book argues is accurate as description and unhelpful as mechanism.

Clausewitz, Carl von. On War. 1832. The concept of friction, the accumulation of small delays that separates war as planned from war as fought, is the direct ancestor of this book’s subject.

Dekker, Sidney. The Field Guide to Understanding Human Error. Farnham: Ashgate. Argues that human error is a symptom of trouble deeper in a system rather than an explanation of it.

Dilmoney, Dolev, Bnaya Gross, and Nadav M. Shnerb. Dynamics of Critical Cascades in Interdependent Networks. Preprint, arXiv:2504.06862, 2025. Analyzes the long plateau of apparent stability that precedes abrupt collapse.

Dobbs, Michael. One Minute to Midnight: Kennedy, Khrushchev and Castro on the Brink of Nuclear War. New York: Knopf, 2008. Hour-by-hour account of October 1962, including the events aboard the Soviet submarine.

Ferguson, Niall. The Pity of War. London: Allen Lane, 1998. A contrarian reading, valuable here chiefly for its treatment of the financial dimension and of British entry.

Fischer, Fritz. Germany’s Aims in the First World War. New York: W. W. Norton, 1967. The book that broke the exculpatory consensus and started the greatest controversy in modern German historiography.

Fischer, Fritz. War of Illusions: German Policies from 1911 to 1914. London: Chatto and Windus, 1975. The extension of the argument backward into the pre-crisis decade.

Geiss, Imanuel. July 1914: The Outbreak of the First World War. Selected Documents. New York: Charles Scribner’s Sons, 1967. The documentary selection in English, including the texts of the ultimatums with their stated deadlines.

Hamilton, Richard F., and Holger H. Herwig, editors. Decisions for War, 1914 to 1917. Cambridge: Cambridge University Press, 2004. Each belligerent’s decision process treated in parallel, which is the format most useful for comparing institutional response times.

Harvey, Jerry B. The Abilene Paradox: The Management of Agreement. Organizational Dynamics 3 (1974). The original statement of the parable this book devotes a chapter to dismantling.

Hermann, Charles F., and Margaret G. Hermann. An Attempt to Simulate the Outbreak of World War I. American Political Science Review 61 (1967). Human subjects placed in the roles of the July decision makers, six decades before the same thing was attempted with machines.

Herrmann, David G. The Arming of Europe and the Making of the First World War. Princeton: Princeton University Press, 1996. Documents the armaments dynamic of 1912 to 1914 that raised the cost of being last to mobilize.

Herwig, Holger H. Clio Deceived: Patriotic Self-Censorship in Germany after the Great War. International Security 12 (1987). The essential account of how the documentary record was shaped, and the principal source for this book’s third chapter.

Hobbes, Thomas. Leviathan. 1651. Contains the earliest clear statement of the situation in which parties attack preemptively although none desires conflict.

Hoffman, David E. The Dead Hand: The Untold Story of the Cold War Arms Race and Its Dangerous Legacy. New York: Doubleday, 2009. Includes the fullest published account of Soviet automated retaliation arrangements.

Hollnagel, Erik. Safety-I and Safety-II: The Past and Future of Safety Management. Farnham: Ashgate, 2014. Argues that safety should be studied through what normally goes right rather than through failures.

Hua, Wenyue, and colleagues. War and Peace: Large Language Model-Based Multi-Agent Simulation of World Wars. Preprint, arXiv:2311.17227, 2023. Machine agents placed in the roles of the 1914 powers, joining the two halves of this book’s subject.

International Atomic Energy Agency. The Fukushima Daiichi Accident. Vienna, 2015. The technical reference, including the sequence of the venting decisions.

Janis, Irving L. Groupthink: Psychological Studies of Policy Decisions and Fiascoes. Second edition. Boston: Houghton Mifflin, 1982. The standard treatment of suppressed dissent within a decision body.

Jervis, Robert. Perception and Misperception in International Politics. Princeton: Princeton University Press, 1976. Remains the reference for how states read each other’s signals wrongly and systematically.

Jones, Nate. Able Archer 83: The Secret History of the NATO Exercise That Almost Triggered Nuclear War. New York: New Press, 2016. Collects the declassified record on the 1983 exercise.

Kahneman, Daniel. Thinking, Fast and Slow. New York: Farrar, Straus and Giroux, 2011. The distinction between fast automatic judgment and slow deliberate reasoning, which is the individual-level analogue of this book’s institutional argument.

Keegan, John. The First World War. London: Hutchinson, 1998. A general military history, useful for the conduct of the war that this book deliberately omits.

President’s Commission on the Accident at Three Mile Island. Report. Washington, 1979. The source of the finding that operators reasoned correctly from false indications.

Kennedy, Paul M., editor. The War Plans of the Great Powers, 1880 to 1914. Boston: Allen and Unwin, 1979. The plans of the several powers described together, which is the comparison nobody made before 1914.

Kennedy, Robert F. Thirteen Days: A Memoir of the Cuban Missile Crisis. New York: W. W. Norton, 1969. A participant’s account, to be read alongside the tapes and the later scholarship that correct it.

Kriger, Peter. When the Last Straw Is Small: Cascading Failure under Clustered Multi-Vector Shocks in Networked Societies. IIIR Computational Humanities and Cultural Systems, 2026. DOI 10.5281/zenodo.21405843. The companion work establishing that collapse deadlines are set by the number of shocks rather than their size.

Kriger, Peter. Latency Collapse: When Available Decision Time Falls Below Required Deliberation Time in Coupled Escalation Networks. IIIR Computational Humanities and Cultural Systems, 2026. DOI 10.5281/zenodo.21568121. The formal argument of which this book is the popular expansion.

Kriger, Boris. A Unified Structural Theory of Complex Systems: Formal Laws, Epistemic Constraints, and Self-Organization across Physical, Cognitive, and Social Domains. 2026. DOI 10.5281/zenodo.18637687. The wider structural framework on which the companion article rests.

Lamparth, Max, and colleagues. Human versus Machine: Behavioral Differences between Expert Humans and Language Models in Wargame Simulations. Preprint, arXiv:2403.03407, 2024. Compares machine and expert human behaviour in the same scenario.

Leveson, Nancy G. Engineering a Safer World: Systems Thinking Applied to Safety. Cambridge: MIT Press, 2011. Treats accidents as control problems rather than as chains of component failures.

Levy, Jack S. Preferences, Constraints, and Choices in July 1914. International Security 15 (1990 to 91). Establishes that the preferences of the July actors were coherent and stable, which this book’s argument requires rather than resists.

Lieber, Keir A. The New History of World War I and What It Means for International Relations Theory. International Security 32 (2007). Surveys what survives of the mechanical readings of 1914 after the documentary revisions.

Lieven, D. C. B. Russia and the Origins of the First World War. New York: St Martin’s Press, 1983. The Russian decision process, including the partial mobilization episode.

Machiavelli, Niccolo. The Prince. 1513. The argument that preparation made in quiet times determines what is possible in urgent ones.

MacMillan, Margaret. The War That Ended Peace: How Europe Abandoned Peace for the First World War. London: Profile, 2013. The long pre-history, with particular attention to the crises that did not become wars.

May, Ernest R., editor. Knowing One’s Enemies: Intelligence Assessment before the Two World Wars. Princeton: Princeton University Press, 1984. How each power assessed the others, and how wrong the assessments were.

McMeekin, Sean. July 1914: Countdown to War. New York: Basic Books, 2013. Narrative reconstruction with fine temporal grain and a distinctive view of Russian responsibility.

Mombauer, Annika. Helmuth von Moltke and the Origins of the First World War. Cambridge: Cambridge University Press, 2001. The German staff dimension, including the events of the evening of 1 August.

Mombauer, Annika. The Origins of the First World War: Controversies and Consensus. London: Longman, 2002. The best guide to the historiographical argument itself, which is a subject distinct from the events.

Motter, Adilson E., and Ying-Cheng Lai. Cascade-Based Attacks on Complex Networks. Physical Review E 66 (2002). Load redistribution as a mechanism of cascading failure.

National Diet of Japan. The Official Report of the Fukushima Nuclear Accident Independent Investigation Commission. Tokyo, 2012. Notable for locating the causes in regulatory arrangements rather than in the tsunami.

National Commission on the BP Deepwater Horizon Oil Spill and Offshore Drilling. Deep Water: The Gulf Oil Disaster and the Future of Offshore Drilling. Washington, 2011. Contains the account of the negative pressure test and the explanation invented to reconcile it.

Otte, T. G. July Crisis: The World’s Descent into War, Summer 1914. Cambridge: Cambridge University Press, 2014. The most recent detailed reconstruction of the five weeks.

Payne, Kenneth. AI Arms and Influence: Frontier Models Exhibit Sophisticated Reasoning in Simulated Nuclear Crises. Preprint, arXiv:2602.14740, 2026. The largest study of machine behaviour in simulated nuclear crises, and the source of the finding that no participant ever de-escalated.

Perrow, Charles. Normal Accidents: Living with High-Risk Technologies. New York: Basic Books, 1984. Introduced tight coupling and interactive complexity, and the idea that certain accidents are properties of a system rather than deviations from it.

Reason, James. Human Error. Cambridge: Cambridge University Press, 1990. The distinction between active failures and latent conditions, which corresponds to this book’s distinction between the crisis and the decade before it.

Richardson, Lewis F. Arms and Insecurity: A Mathematical Study of the Causes and Origins of War. Pittsburgh: Boxwood Press, 1960. The founding formal model of escalation, and the reference point from which this book departs by taking time rather than armament as the state variable.

Rivera, Juan-Pablo, and colleagues. Escalation Risks from Language Models in Military and Diplomatic Decision-Making. Preprint, arXiv:2401.03408, 2024. Early systematic evidence of escalatory tendencies in automated decision support.

Presidential Commission on the Space Shuttle Challenger Accident. Report. Washington, 1986. Including the appendix on the reliability estimates, which remains the finest short essay on institutional self-deception ever appended to a government report.

Rohl, John C. G. Wilhelm II. Three volumes. Cambridge: Cambridge University Press. The definitive biography, and the source for the Emperor’s marginal notes of 28 July 1914.

Sagan, Scott D. 1914 Revisited: Allies, Offense, and Instability. International Security 11 (1986). The interaction of alliance structure with offensive posture.

Sagan, Scott D. The Limits of Safety: Organizations, Accidents, and Nuclear Weapons. Princeton: Princeton University Press, 1993. Documents the near-misses that organizations recorded as successes, and is the origin of this book’s claim that survival is depletion.

Scheffer, Marten, and colleagues. Early-Warning Signals for Critical Transitions. Nature 461 (2009). Statistical traces that precede abrupt transitions, and the basis for the forecasting proposal in the companion article.

Schelling, Thomas C. Arms and Influence. New Haven: Yale University Press, 1966. The foundational treatment of crisis stability and of the threat that leaves something to chance.

Schelling, Thomas C. The Strategy of Conflict. Cambridge: Harvard University Press, 1960. Commitment, precommitment, and the deliberate destruction of one’s own options as a bargaining instrument.

Schwartz, Joshua A., and Michael C. Horowitz. Out of the Loop Again: How Dangerous Is Weaponizing Automated Nuclear Systems? Preprint, arXiv:2505.00496, 2025. The institutional consequences of automating nuclear decision support.

United States Securities and Exchange Commission and Commodity Futures Trading Commission. Findings Regarding the Market Events of May 6, 2010. Washington, 2010. The official reconstruction of the flash crash.

Snyder, Jack. The Ideology of the Offensive: Military Decision Making and the Disasters of 1914. Ithaca: Cornell University Press, 1984. Why general staffs adopted offensive doctrines against the evidence.

Stevenson, David. Armaments and the Coming of War: Europe, 1904 to 1914. Oxford: Clarendon Press, 1996. The arms competition treated as a continuous process rather than as a background condition.

Stevenson, David. Militarization and Diplomacy in Europe before 1914. International Security 22 (1997). Military preparation used as a diplomatic instrument, which is the mechanism of this book’s reputational depletion channel.

Strachan, Hew. The First World War. Volume One: To Arms. Oxford: Oxford University Press, 2001. The most comprehensive modern treatment of the war’s opening.

Strogatz, Steven H. Nonlinear Dynamics and Chaos. Second edition. Boulder: Westview Press, 2015. The standard text, and the source of the normal-form treatment of the fold that produces the gap between entry and exit.

Taleb, Nassim Nicholas. Antifragile: Things That Gain from Disorder. New York: Random House, 2012. Argues that some systems improve under stress, which is the interesting counter-case to this book’s depletion argument.

Taylor, A. J. P. War by Time-Table: How the First World War Began. London: Macdonald, 1969. The timetable thesis in its most compressed and most refuted form, and required reading for understanding what this book is not claiming.

Tetlock, Philip E. Expert Political Judgment: How Good Is It? How Can We Know? Princeton: Princeton University Press, 2005. The systematic evaluation of expert forecasting, which bears on every claim about what decision makers should have foreseen.

Thucydides. History of the Peloponnesian War. Fifth century BC. The origin of the practice of examining not only what states did but in what assemblies and within what intervals they decided it.

Trachtenberg, Marc. The Meaning of Mobilization in 1914. International Security 15 (1990 to 91). The demolition of the strong timetable thesis, and the objection that any successor account must answer.

Trachtenberg, Marc. History and Strategy. Princeton: Princeton University Press, 1991. Contains the revised version of the mobilization essay together with related work on crisis decision making.

Trumpener, Ulrich. War Premeditated? German Intelligence Operations in July 1914. Central European History 9 (1976). What Berlin knew of Russian preparatory measures and when.

Tuchman, Barbara W. The Guns of August. New York: Macmillan, 1962. Wrong about the mechanism and right about the danger, and read by an American president during the thirteen days of October 1962.

Turchin, Peter. Historical Dynamics: Why States Rise and Fall. Princeton: Princeton University Press, 2003. Establishes the tradition of quantitative modelling in history within which this book’s companion article sits.

United States and Canada Power System Outage Task Force. Final Report on the August 14, 2003 Blackout. Washington and Ottawa, 2004. Including the silent failure of the alarm system that left operators confident and blind.

Van Evera, Stephen. Causes of War: Power and the Roots of Conflict. Ithaca: Cornell University Press, 1999. The general theory of which the 1914 case is one application.

Van Evera, Stephen. The Cult of the Offensive and the Origins of the First World War. International Security 9 (1984). The classic statement of the offensive doctrine argument.

Vaughan, Diane. The Challenger Launch Decision: Risky Technology, Culture, and Deviance at NASA. Chicago: University of Chicago Press, 1996. The origin of the normalization of deviance, and the finest study of how an organization talks itself into an outcome.

Watson, Alexander. Ring of Steel: Germany and Austria-Hungary at War, 1914 to 1918. London: Allen Lane, 2014. The war from the side of the Central Powers, including why ending it proved impossible.

Watts, Duncan J. A Simple Model of Global Cascades on Random Networks. Proceedings of the National Academy of Sciences 99 (2002). Threshold cascades, and why the size of a shock predicts its consequences so poorly.

Weick, Karl E. The Collapse of Sensemaking in Organizations: The Mann Gulch Disaster. Administrative Science Quarterly 38 (1993). How an organization loses its structure under time pressure, studied through the deaths of thirteen firefighters.

Weick, Karl E., and Kathleen M. Sutcliffe. Managing the Unexpected: Sustained Performance in a Complex World. San Francisco: Jossey-Bass. What distinguishes organizations that operate reliably in unforgiving conditions.

Kriger, P. (2026). Latency Collapse: When Available Decision Time Falls Below Required Deliberation Time in Coupled Escalation Networks. IIIR Computational Humanities and Cultural Systems. https://doi.org/10.5281/zenodo.21568121


메타데이터
post_id
89ec45f0ee50
slug
the-world-war-that-nobody-wanted-89ec45f0ee50
url
https://medium.com/@peterkriger/the-world-war-that-nobody-wanted-89ec45f0ee50
canonical_url
https://medium.com/@peterkriger/the-world-war-that-nobody-wanted-89ec45f0ee50
author_url
https://medium.com/@peterkriger
status
ok
fetched_at
2026-08-12 09:00:28