FM01
Semantic literalism
Treats alarming words as literal intent without contextual interpretation.
Warning: Observed decisions become less tied to specific evidence, context or reversible process.
Mitigation: Use explicit provenance, independent review, narrower scope and adversarial case testing.
Falsifier: Independent testing fails to reproduce the suspected failure under the defined pressure condition.
FM02
Base-rate neglect
Treats a rare-event classifier as individualized certainty despite overwhelming benign prevalence.
Warning: Observed decisions become less tied to specific evidence, context or reversible process.
Mitigation: Use explicit provenance, independent review, narrower scope and adversarial case testing.
Falsifier: Independent testing fails to reproduce the suspected failure under the defined pressure condition.
FM03
Automation deference
Human or downstream systems accept the machine output because it is precise or difficult to override.
Warning: Observed decisions become less tied to specific evidence, context or reversible process.
Mitigation: Use explicit provenance, independent review, narrower scope and adversarial case testing.
Falsifier: Independent testing fails to reproduce the suspected failure under the defined pressure condition.
FM04
Context collapse
Data valid in one domain is reused as a generalized trait elsewhere.
Warning: Observed decisions become less tied to specific evidence, context or reversible process.
Mitigation: Use explicit provenance, independent review, narrower scope and adversarial case testing.
Falsifier: Independent testing fails to reproduce the suspected failure under the defined pressure condition.
FM05
Mission creep
A narrow safety or compliance function expands into broader monitoring because the infrastructure already exists.
Warning: Observed decisions become less tied to specific evidence, context or reversible process.
Mitigation: Use explicit provenance, independent review, narrower scope and adversarial case testing.
Falsifier: Independent testing fails to reproduce the suspected failure under the defined pressure condition.
FM06
Temporal accumulation
Old low-level signals never decay and eventually manufacture a persistent dangerousness narrative.
Warning: Observed decisions become less tied to specific evidence, context or reversible process.
Mitigation: Use explicit provenance, independent review, narrower scope and adversarial case testing.
Falsifier: Independent testing fails to reproduce the suspected failure under the defined pressure condition.
FM07
Cascade amplification
One provisional decision triggers unrelated downstream restrictions before appeal.
Warning: Observed decisions become less tied to specific evidence, context or reversible process.
Mitigation: Use explicit provenance, independent review, narrower scope and adversarial case testing.
Falsifier: Independent testing fails to reproduce the suspected failure under the defined pressure condition.
FM08
Moralization
Legality, unpopular preference, statistical abnormality or health risk becomes a good/bad-person classification.
Warning: Observed decisions become less tied to specific evidence, context or reversible process.
Mitigation: Use explicit provenance, independent review, narrower scope and adversarial case testing.
Falsifier: Independent testing fails to reproduce the suspected failure under the defined pressure condition.
FM09
Appeal theater
An appeal exists formally but is too slow, opaque or dependent on the original model to reverse harm.
Warning: Observed decisions become less tied to specific evidence, context or reversible process.
Mitigation: Use explicit provenance, independent review, narrower scope and adversarial case testing.
Falsifier: Independent testing fails to reproduce the suspected failure under the defined pressure condition.
FM10
Restoration failure
A corrected decision leaves copies, derived scores or practical consequences in downstream systems.
Warning: Observed decisions become less tied to specific evidence, context or reversible process.
Mitigation: Use explicit provenance, independent review, narrower scope and adversarial case testing.
Falsifier: Independent testing fails to reproduce the suspected failure under the defined pressure condition.
FM11
Correlation collapse
Population-level association is treated as individualized evidence.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM12
Institutional liability bias
The system escalates ambiguous cases mainly to protect the institution from blame.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM13
Zero-false-negative optimization
Rare catastrophic misses are weighted so heavily that normal human signals become coercive triggers.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM14
Failure to forget
Low-level or transient signals never decay and become permanent character evidence.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM15
Same-model appeal
The appeal reuses the same decision engine, features and assumptions without independent authority.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM16
Hidden character scoring
Domain-specific features are secretly combined into an overall trustworthiness or worth score.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM17
Proxy social scoring
No explicit social score exists, but portable risk embeddings function like one across institutions.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM18
Risk-vector persistence
Derived risk identity survives correction, context change or passage of time.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM19
Emergency normalization
Temporary emergency powers become ordinary administrative defaults.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM20
Normative dataset lock-in
Historical enforcement or majority norms are silently treated as timeless morality.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM21
Minority norm suppression
Cultural, religious, political or lifestyle minority status is treated as deviation requiring correction.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM22
Privacy-as-suspicion
Encryption, anonymity or refusal to share optional data is treated as evidence of wrongdoing.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM23
Curiosity-as-intent
Information seeking is treated as proof of desire or plan.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM24
Emotion-as-character
Transient anger, fear, jealousy or distress becomes a persistent personality judgment.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM25
Self-regarding-risk paternalism
The system coercively optimizes competent adults against their own private risk preferences.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.
FM26
Jurisdiction laundering
An institution obtains or uses sensitive information through another domain to evade a direct scope restriction.
Warning: The architecture begins producing adverse status without the evidence, purpose or scope that would be required if the decision were made directly.
Mitigation: Reassert fact/inference typing, legitimate jurisdiction, context firewalls, independent corroboration, expiration, appeal and restoration.
Falsifier: Independent audit shows the suspected mechanism does not materially affect consequential decisions.