Chapter 3 made the population's felt experience sovereign. Be honest about what that buys the attacker: if the signal rules everything, the cheapest attack on everything is the signal's formation. Media capture, propaganda, preference falsification — people professing in public what they reject in private — and the subtlest weapon, manufactured apathy. In an engagement-weighted system, the checked-out cede their weight to whoever remains; a captured elite's cheapest strategy is not winning the argument but producing the disengagement. Protecting the environment in which citizens' judgments form is therefore not adjacent hygiene. It is the foundation. Every other chapter stands on this one.
One floor is non-negotiable before any of it: rights, courts, and the removal levers stay in force for everyone, participant or not. Participation is voluntary; the floor is not — because collapse is never well-targeted at the disengaged alone.
The system's default is radical transparency — power exercised in the open, resource flows visible, conflicts tracked. But transparency uniformly applied would hand coercers their target list, so privacy is stratified by role, deliberately, with each regime justified by what its layer must resist:
Secrecy where coercion attacks, permanence where reputation accrues, nakedness where power lives. The stratification is load-bearing; flatten it in either direction and either the sensors get squeezed or the powerful get masks. And note what kind of thing this three-regime scheme is: a setting, not a commandment. Privacy-versus-transparency is one of the dialectics of chapter 2 — the regimes described here are the current position of that lever, justified per layer, held in the meta-rules, and adjustable at constitutional viscosity as the search learns where each layer's protection actually needs to sit.
The constructive defense the design can offer is self-determination of the algorithm. The rule the whitepaper sets for AI assistance holds for the whole information layer: trained by the individual, never consumed from a provider. A feed you consume from a platform optimizes for the platform's objectives — engagement, outrage, whatever pays — and a population fed by three such platforms has outsourced its perception to three boardrooms. The counter is structural rather than heroic: citizens own and train their own filters, delegate attention to tools they control rather than tools that control them, and the removal levers point at any evaluator that would centralize the feed. This does not solve propaganda; nothing solves propaganda. It removes the single throat to squeeze.
AI enters this design on exactly one side of a line. As legibility infrastructure it is a gift: tracing causal chains from policy to outcome, surfacing what the salesman did not actually do, making the state auditable by anyone with a question — plausibly the technology that finally closes the gap between the best talker and the best doer. As verdict-issuer it is a new priesthood: whoever trains, audits, or prompts the evaluator holds the most valuable capture target in the system, and chapter 3's entire argument against expert-owned metrics applies with fresh force. The line: citizens use it to see; they never defer to it to judge. The removal levers point at the evaluator too. And even an honest evaluator meets the identification problem — the difficulty of showing that a policy, rather than everything else happening at the same time, caused the outcome. Social counterfactuals are confounded, not merely complicated, and a system that forgets this will laminate false precision onto genuine uncertainty.