Austin VornhagenEssays
Close-up of a brass key hanging in a chrome key switch on a worn grey-green Cold War control console, a glowing amber lamp just above it, rows of black toggle switches to the left, and blurred red and amber indicator lights in the dark behind.
An engineer’s guide to concentrated power

America Has 13 Single Points of Failure. Here’s the 5-part fix that works even if the wrong person holds the key.

Scroll to pull back from the key. Watch the readout in the corner.

By Austin VornhagenSeptember 2026 · 21 min
Scroll to pull back

Two officers. Two keys. Too far apart for either one to cheat.

Beginning in the 1960s, the Air Force buried rooms like the one you just pulled back through under the Great Plains, one for every flight of ten Minuteman missiles. Two officers stood watch in each. Each held a launch key. The keyholes sat far enough apart that one officer could not reach both, and the keys had to turn together. The codes used to check a launch order were locked in a safe with two locks, and each officer could open only one of them.

That’s the two-person rule. It assumes something unflattering and wise: on some day, somebody in that room might be sick, compromised, confused, or evil. So the system is built so that one bad day in one head can’t end the world.

Now climb the chain of command to where the order comes from.

Under current U.S. procedures, the president has sole authority to order the use of nuclear weapons. Advisers can advise. Authentication codes confirm that the order really comes from the president. But no one else’s agreement is required.

There are real arguments for designing it that way, and we’ll get to them. For now, just notice the shape of it. We took the most dangerous action a human being can take, and we installed the two-person rule on the lieutenants, not at the top.

We already know how to build systems that survive one bad actor. We keep installing them at the bottom.

That asymmetry is the subject of this essay, because once you see it in a missile capsule, you start seeing it everywhere: in banks, in the power grid, in the search box, in the agencies that police all of them, and now in AI.

01 The post you’ve seen

The billionaire-bunker post is 150 years old

You’ve probably seen some version of it with thousands of upvotes. Billionaires are buying islands and bunkers. They own the politicians. They don’t care what happens to the rest of us. And AI is the newest tool in their kit, maybe even the reason you’re being told to fear AI in the first place.

It’s tempting to wave it off as paranoia. It’s equally tempting to swallow it whole. Both are mistakes, and the reason why both are mistakes points to a surprisingly practical fix.

Start with the age of the complaint. In the late 1800s, railroads, steel, oil, and banking produced fortunes on a scale Americans had never seen: Rockefeller, Carnegie, Vanderbilt, Morgan. The vocabulary of the day will sound familiar. Monopoly. Corruption. Bought politicians. Robber barons.

The fear wasn’t that rich people existed. It was that economic power could quietly turn into political power. If one company controlled the railroad, the bank, and most of the jobs in a region, elections could keep happening on schedule while the real decisions moved somewhere else.

The country answered with machinery, not sermons. The Interstate Commerce Act in 1887 put railroads under federal regulation. The Sherman Antitrust Act followed in 1890. Muckrakers like Ida Tarbell, whose history of Standard Oil ran in McClure’s from 1902 to 1904, dragged the trusts into daylight. The Pure Food and Drug Act passed in 1906, and the Sixteenth Amendment made a federal income tax possible in 1913.

  1. 1880sRailroads
  2. 1900sOil trusts
  3. 1930sBanks
  4. 1950s+Mass media
  5. 2000sPlatforms
  6. 2020sAI
Same question, stamped on every eraWho actually runs society when economic power gets extremely concentrated?

Every generation since has asked that question about its own new giant. AI isn’t a new argument. It’s the newest place to have an old one. What changed is how much the public trusts anybody to answer it.

How trust in the federal government fell from 77 percent to 17 percent

Trust the federal government “always” or “most of the time”73%
A line chart of trust in the federal government. It starts at 73 percent in 1958, peaks at 77 percent in 1964, falls to about 25 percent by 1980, reaches 17 percent in October 2008, sits at 22 percent in 2024, and returns to 17 percent in 2025.0%25%50%75%100%1960198020002020VIETNAM · WATERGATE200873%77%~25%17%22%17%
Selected readings from Pew Research Center’s compiled series (National Election Studies, Gallup, CBS/New York Times, Pew, and others). The line joins readings; it isn’t one continuous survey.
1958 to 1964 · The high-trust years

Three in four trusted Washington

When researchers first asked in 1958, 73% said they trusted the federal government to do what’s right always or most of the time. In 1964 it was 77%. That matters: deep cynicism isn’t some permanent American trait. People trust big institutions when those institutions look competent, fair, and visibly useful.

1964 to 1980 · Something breaks

Vietnam, Watergate, inflation

By 1980, only about a quarter still trusted Washington. And an intellectual shift rode along with the drop. The old populist line was “government must protect us from private power.” A newer one said “government is one of the powers to distrust.” Both strands are still alive, which is why anti-elite politics shows up on the left and the right, pointed at different buildings.

October 2008 · The accelerant

The bailout looked terrible

Banks helped cause a systemic crisis, then governments rescued the system to prevent something worse. There were serious economic arguments for it. Politically, it read as “the people who broke it got saved.” Trust hit 17%. Occupy gave us “the 99% versus the 1%,” the Tea Party aimed at bailouts and Washington insiders. Different diagnosis, same feeling: the people running the system are not serving you.

2024 to 2025 · The floor

Back to 17%

After a pandemic that taught everyone to ask who benefits, who controls the information, and who pays, Pew measured 22% in 2024 and 17% in 2025. It isn’t only American, either. Edelman’s 2025 global survey found 61% of people hold a moderate or high sense of grievance: a belief that government and business serve narrow interests and the wealthy benefit unfairly.

02 Bunkers

The bunkers are real. Read the next sentence carefully.

For years, reporters have documented wealthy tech executives and investors buying remote land, survival shelters, and escape plans. The New Yorker’s 2017 investigation of doomsday prep among the super-rich described people preparing for political instability, cyberattacks, economic breakdown, and civil disorder.

There are two ways to read that. The mundane one: I have enormous resources, so spending a sliver of them on insurance against a small risk of catastrophe is rational. The dark one: The people with the most power think society is going to fail, and they’re protecting themselves instead of fixing it.

The viral post picks the dark one and then keeps walking, all the way to they intend to harm us. That last step is where documented social criticism turns into speculation. The trick to thinking clearly here is to notice that the post mixes three different kinds of claims. Try sorting them.

Tap each claim to check it0 of 7 checked
  • Evidence Checkable, and true. Federal Reserve data for mid-2026: 32.5% for the top 1%, 2.3% for the entire bottom half.
  • Evidence Checkable, and true. 17% said they trust it always or most of the time in 2025, down from 77% in 1964.
  • Evidence Checkable, and documented. Reporting such as The New Yorker's 2017 investigation of tech-industry doomsday prep describes exactly this.
  • Debatable Reasonable and debated. Serious scholars argue about how much, through which channels, and compared with what.
  • Debatable An interpretation. You can marshal evidence for it and against it, and people of good faith land in different places.
  • Unsupported A claim about hidden intent. Owning a bunker is evidence of a plan B, not of a plan to make you need one.
  • Unsupported A claim about coordinated secret action. Distrust and inequality being real doesn't count as evidence for it.

That sorting keeps you out of two ditches at once. One ditch dismisses every worry about concentrated power as tinfoil. The other treats every suspicion as proven because inequality and distrust are real.

And here’s the part the viral version misses, which is also the part that should worry you more: you don’t need a villain for this to go wrong.

03 No villain required

Exit beats repair when you can afford the exit

Picture two households deciding how much the country should spend making the power grid tougher.

Two houses beside a power line. When the grid fails, household A goes dark. Household B stays lit on its own generator, batteries, and solar panels.HOUSEHOLD AGENHOUSEHOLD B

Grid up. Both households have power.

Household A loses power for a week if the grid fails. Household B has a microgrid, a generator, a second home, and the budget to ride out almost anything. Ask them both how much public money should go to hardening the grid, and their honest answers will differ. Nobody has to be malicious. Their incentives have simply come apart.

Scale that up. A middle-class family can’t buy private security, backup energy, aircraft, legal teams, private medicine, and property in three countries. A billionaire can. The more of life you can buy a private exit from, the less the public version has to work for you personally.

The problem isn’t that the powerful are evil. It’s that they increasingly don’t need the repair.

04 The panel, September 2026

Four gauges in the red at once

Each of these alone would be a policy debate. Read together, they describe a system under strain.

Wealth · Q2 202632.5%

of U.S. household net worth held by the top 1%. The entire bottom half holds 2.3%.

Federal Reserve, Distributional Financial Accounts
Trust · 202517%

trust the federal government to do what’s right always or most of the time. It was 77% in 1964.

Pew Research Center
AI legitimacy · Sept 202673%

of Americans say AI companies haven’t done enough to prevent serious harm. Only 11% call AI a positive for society.

Reuters/Ipsos poll, September 2026
Insulation · June 20266-3

The Supreme Court’s vote in Trump v. Slaughter, letting presidents fire FTC commissioners at will and overruling Humphrey’s Executor.

Supreme Court of the United States

There’s a fifth gauge that barely existed in the Gilded Age. Rockefeller could dominate oil, but he didn’t own McClure’s, the magazine that published Tarbell’s takedown of Standard Oil. Today, a small number of companies run search, social feeds, app stores, cloud platforms, and increasingly the AI systems people ask about everything else. Economic power and information power have started to overlap: the same firms can participate in the economy and in the channels society uses to argue about the economy.

That makes suspicion cheap to generate even where there’s no conspiracy at all. And it feeds a loop:

  1. Power concentrates
  2. Distrust grows
  3. Politics freezes
  4. Problems go unsolved
  5. Distrust grows more
  6. Voters demand outsiders and radical fixes
  7. Institutions lose legitimacy
and around again

So here is the question worth replacing the viral post with. Not “are the billionaires secretly plotting?” but this:

Can we build a country where, even if powerful people are selfish, incompetent, short-sighted, or hostile, none of them holds enough unilateral power to decide everyone else’s future?

05 The turn

Design for adversaries, not saints

Engineers stopped relying on good behavior a long time ago. When we build airplanes, nobody says “hopefully the pilot never makes a mistake.” We build redundant flight computers, checklists, alarms, independent instruments, and accident investigations. When we build databases, nobody says “hopefully no disk ever fails.” We copy the data to several machines.

Then we build institutions and quietly say:

Hopefully the president is responsible.

Hopefully the billionaire behaves ethically.

Hopefully the CEO doesn’t abuse the monopoly.

Hopefully the AI company puts humanity first.

That’s hope-based design, and an engineer would flag every line of it. The engineering question is blunter:

Assume somebody eventually behaves badly. What can they actually do?

If the honest answer is “ruin everything,” you have a single point of failure. If the answer is “cause damage, which other independent systems contain, expose, reverse, and replace,” you have something close to a fault-tolerant society.

Notice what this does to the argument. You no longer have to decide in advance who the threat is: a president of either party, a tech founder, a bank, an intelligence agency, a union, a billionaire nobody has heard of yet, or an AI system that doesn’t exist yet. You design so that the identity of the bad actor matters less. It’s about as close to ideology-neutral as political design gets.

The first place to apply it is the one the viral post points at, and it’s subtler than “rich people exist.”

How separate kinds of power convert into a master key, and how friction stops it

Six kinds of power arranged in a ring: political, economic, information, technology, coercive, and infrastructure. One actor sits in the center. As conversions appear between them, the actor gains control of more of the ring until it holds all six, a master key. In the final state, friction gates break the conversions and the actor is confined to one.ONEACTORPOLITICALECONOMICINFORMATIONTECHNOLOGYCOERCIVEINFRASTRUCTURE
State 1 · Six separate locks

Power comes in kinds

Political, economic, information, technological, coercive, infrastructure. Picture each as its own lock with its own keyholders. Someone who becomes enormously successful in one, say economics, holds one key. That’s the healthy version: one kind of success, one kind of power.

State 2 · The first conversion

Wealth becomes political control

Campaign money, lobbying, and legal firepower let economic power flow into political power. This is exactly what the Gilded Age feared, and it’s a conversion, not a crime.

State 3 · The modern one

Market dominance becomes information control

Own the search box, the feed, or the chatbot, and your market position becomes influence over what people see, which businesses get found, and which arguments spread.

State 4 · The loop closes

Information shapes the regulators

Influence over the public conversation feeds back into the political process that is supposed to oversee the influencer. Now the conversions reinforce each other.

State 5 · AI’s contribution

Capital buys compute; compute reaches everything

Frontier AI rewards whoever can afford the chips, the data centers, and the energy. And software that can act can reach infrastructure and, eventually, force. Every lock in the ring is now wired to the same hand.

State 6 · The failure mode

A master key

Capture this one actor, or let it go bad, and you’ve captured the country. That is the real danger in the viral post, stated without any villains: one kind of success becoming a key to everything else.

State 7 · The fix

Tax the conversion, not the success

You don’t have to make everyone equal. You raise the friction at each gate: disclosure, separation rules, interoperability, broad ownership. Someone can still get very rich. They just can’t cash that in, without friction, for control of campaigns, newsrooms, regulators, and the grid.

06 The toolkit

Five engineering primitives do almost all the work

If you go through every place in American life where one actor holds unusual power, the fixes keep collapsing into the same five moves. You already know most of them from software, aviation, or finance. They just haven’t been applied to power on purpose.

1Multi-key authorization

Some actions are too consequential for one key. The rule that scales: as consequence and irreversibility rise, the number and independence of the people who must agree should rise too. It’s the missile capsule’s rule, or a crypto wallet that needs three signatures out of five.

The independence part is where most real-world versions cheat. A president plus three advisers the president can fire this afternoon isn’t four keys. It’s one key with extra steps.

Try weighing some real decisions. The scores are my judgment calls, not official ratings; the point is the shape of the rule.

Impact × irreversibility × uncertainty100

Several independent keys, a waiting period, and a supermajority.

Nobody has ever found the rollback for this one.

The same rule tells you how to handle AI. An AI system might become far better than any human at medicine, logistics, or running a power grid. That doesn’t mean it needs authority. You can split the ability to propose from the ability to execute. Instead of telling a system “do whatever it takes to optimize the grid,” you only let it emit something like:

// the model can only say this; it cannot do it
ProposedGridAdjustment(substation=47, load=-3%, duration=12min)
// an independent policy engine checks it; big ones need more keys

NIST’s AI Risk Management Framework already treats governance, accountability, and clearly defined human roles as core to deploying AI. The trap to avoid is what you might call the ceremonial human: a person “in the loop” who lacks the authority, expertise, or incentive to say no. You don’t want powerful AI plus a rubber stamp. You want powerful AI plus enforced boundaries, independent sign-off, logs, and a working off switch.

2Automatic failover

This is where society lags furthest behind engineering. If a cloud provider disappeared tomorrow, a well-built critical service would say traffic is moving to provider B. If a bank failed: deposits are moving to the bridge institution. If a platform turned hostile: you keep your identity, audience, and data elsewhere.

Sometimes the best defense against a monopoly isn’t stopping it from getting big. It’s making your dependence on it non-exclusive. If leaving costs you your identity, your network, your data, and your customers, you don’t really have a choice. If leaving is easy, even a giant has to behave, and nobody had to prove it was evil first.

3Blast-radius limits

This might be the single most useful idea in the whole kit. Ask of every institution: if this actor went bad tomorrow, how many people could it hurt before someone stopped it? You don’t have to prevent every failure. You make failure local.

The same fault in a monolithic system and in a cellular one

One shared hub0 of 96 down
A grid of 96 small squares, each a service or region. In the first layout they all hang off one hub, so one fault takes all 96 down. In the cellular layout they are split into six independent cells, and the same fault takes down only 16. With failover, neighboring cells pick up the load and nothing is fully down.HUB
Picks a random spot. Same rules.
Layout 1 · Everyone on one hub

Efficient, until it isn’t

Ninety-six services, one shared dependency: a single cloud region, a single payment processor, a single identity provider, a single regulator. It’s cheaper and simpler. Scroll on and watch one fault.

Layout 1 · The fault

Everything falls together

The hub fails, or is captured, and the failure races outward to all 96. Nothing went wrong in any of the services. They simply shared a fate. Engineers call this correlated failure.

Layout 2 · Cells with walls

Same fault, one-sixth the damage

Split the system into six independent cells with walls between them. The identical fault now stops at the wall: 16 down, 80 fine. A utility outage hits a region, not the continent. A corrupt mayor damages a city, not the federal government.

Layout 2 · Plus failover

Degraded, not down

Now let neighboring cells pick up the failed cell’s load. Service gets slower in one area; nobody goes dark. Federalism, competition, modular software, and sandboxing are all versions of this one idea: limit the blast radius.

4Reversibility

Here’s a surprisingly underrated point. The most dangerous kind of power isn’t the power to decide. It’s the power to decide things nobody else can undo. A healthy system keeps this loop open: decision, observation, challenge, correction. Sunset clauses, appeals, judicial review, rollbacks, bankruptcy, and interoperable platforms all exist to keep it open.

So every major decision should face one engineering question before it happens: if this turns out to be catastrophically wrong, how fast can we get back to where we were? A one-year tax change: easily. A war: never. That’s why the key ladder above multiplies by irreversibility. Treating every government decision as if it deserves the same process is incoherent. The burden should rise with impact × irreversibility × uncertainty.

5Observability

Distributed systems turn dangerous when nobody can see what they’re doing. So every important exercise of power should leave a trace, the institutional equivalent of a log file:

power.log
  1. authorized_by Who signed it?
  2. authority Under what law or rule?
  3. evidence What did they rely on?
  4. beneficiaries Who gained financially?
  5. alternatives What else was considered?
  6. expires When does it lapse?
  7. reversible_by Who can undo it?

That doesn’t mean publishing military secrets or medical records. It means that contracts, major regulatory decisions, disclosed lobbying contacts, conflicts of interest, emergency actions, and waivers live in one searchable public record, linked by common identifiers. Then any journalist can ask a question like show me every company that won a contract within two years of hiring an official involved in awarding it, or show me every emergency power still active after two years. AI, which is part of the problem, becomes part of the audit.

07 The audit

Thirteen warning lamps on America’s panel

Here’s what it looks like to walk the United States, as of September 2026, and flag the places where one person or a small group holds unusually consequential power. Each lamp shows what is true today, then a design sketch for the redundancy. The fixes are proposals for argument, not predictions. Tap a lamp.

Lamp 01 of 13

Presidential nuclear authority

Today

The president has sole authority to order the use of U.S. nuclear weapons. Advisers advise and authentication confirms the order is genuine, but nobody else’s agreement is required.

Redundancy

Split first use into independent keys held by people the president cannot instantly fire. Keep an expedited path for a verified incoming attack, so the redundancy never weakens deterrence.

KeysReversibility

Look at the tags. Thirteen very different institutions, and the same five primitives keep showing up. That’s the whole point: this isn’t thirteen unrelated reforms. It’s one design discipline applied thirteen times.

08 The catch

More keys can also break the machine

If you’ve been nodding along, here’s where your intuition needs one correction. The instinct “add more checks” is only half right, because distributed systems have two classic ways to fail.

One is capture: a single actor takes over and nobody can stop it. The other is deadlock: so many parties can veto that nothing happens at all, even when something urgently must. Plenty of Americans who distrust institutions aren’t angry about tyranny. They’re angry that housing, health costs, and infrastructure seem permanently stuck.

That’s why the burden has to scale rather than max out everywhere, and why lamp 04 in the audit, Congress, gets fewer veto points, not more. It’s also why the nuclear fix keeps a fast path for a verified incoming attack. Speed is a legitimate requirement. The goal is to spend friction where irreversible harm lives and nowhere else.

A good system isn’t hard to use. It’s hard to abuse.

09 Back in the capsule

The goal was never to find better people

Go back to those two officers and their keys. Nobody designed that room because they believed Air Force officers were bad people. They designed it because they understood that over enough years, with enough officers, some day would be a bad day, and the stakes were too high to bet on it never coming.

That’s the whole philosophy in one room. You don’t fix concentrated power by finding saints, and you don’t fix it by hunting villains. You fix it by asking every powerful institution one question, on a schedule, the way aviation inspects a part whose failure could crash a plane:

If the leadership here became malicious, incompetent, compromised, or incapacitated today, what is the worst thing it could do before someone independent could stop it?

Anything with a catastrophic answer is a design defect. Not necessarily illegal. Not necessarily anyone’s fault. Just unacceptable until there’s another independent layer between one bad day and everyone else.

The viral post gets the feeling right and the diagnosis wrong. It thinks the problem is who holds power. The problem is how power is held.

The goal isn’t to eliminate powerful people. It’s to eliminate irreversible, unaccountable, single-point-of-failure power.

We already built that rule into concrete rooms under the Great Plains. It’s time to install it at the top.

Run the audit on your own business

Is one platform your single point of failure?

The same question works at small scale. If every customer finds you through one marketplace, one social account, or one directory listing, somebody else holds your key. I build websites for service businesses at Content Pilots, with scheduling and payments built in, so your customers can find and book you on a site you own. And if you think one of my thirteen lamps is wrong, tell me.