Two officers. Two keys. Too far apart for either one to cheat.
Beginning in the 1960s, the Air Force buried rooms like the one you just pulled back through under the Great Plains, one for every flight of ten Minuteman missiles. Two officers stood watch in each. Each held a launch key. The keyholes sat far enough apart that one officer could not reach both, and the keys had to turn together. The codes used to check a launch order were locked in a safe with two locks, and each officer could open only one of them.
That’s the two-person rule. It assumes something unflattering and wise: on some day, somebody in that room might be sick, compromised, confused, or evil. So the system is built so that one bad day in one head can’t end the world.
Now climb the chain of command to where the order comes from.
Under current U.S. procedures, the president has sole authority to order the use of nuclear weapons. Advisers can advise. Authentication codes confirm that the order really comes from the president. But no one else’s agreement is required.
There are real arguments for designing it that way, and we’ll get to them. For now, just notice the shape of it. We took the most dangerous action a human being can take, and we installed the two-person rule on the lieutenants, not at the top.
We already know how to build systems that survive one bad actor. We keep installing them at the bottom.
That asymmetry is the subject of this essay, because once you see it in a missile capsule, you start seeing it everywhere: in banks, in the power grid, in the search box, in the agencies that police all of them, and now in AI.
The billionaire-bunker post is 150 years old
You’ve probably seen some version of it with thousands of upvotes. Billionaires are buying islands and bunkers. They own the politicians. They don’t care what happens to the rest of us. And AI is the newest tool in their kit, maybe even the reason you’re being told to fear AI in the first place.
It’s tempting to wave it off as paranoia. It’s equally tempting to swallow it whole. Both are mistakes, and the reason why both are mistakes points to a surprisingly practical fix.
Start with the age of the complaint. In the late 1800s, railroads, steel, oil, and banking produced fortunes on a scale Americans had never seen: Rockefeller, Carnegie, Vanderbilt, Morgan. The vocabulary of the day will sound familiar. Monopoly. Corruption. Bought politicians. Robber barons.
The fear wasn’t that rich people existed. It was that economic power could quietly turn into political power. If one company controlled the railroad, the bank, and most of the jobs in a region, elections could keep happening on schedule while the real decisions moved somewhere else.
The country answered with machinery, not sermons. The Interstate Commerce Act in 1887 put railroads under federal regulation. The Sherman Antitrust Act followed in 1890. Muckrakers like Ida Tarbell, whose history of Standard Oil ran in McClure’s from 1902 to 1904, dragged the trusts into daylight. The Pure Food and Drug Act passed in 1906, and the Sixteenth Amendment made a federal income tax possible in 1913.
- 1880sRailroads
- 1900sOil trusts
- 1930sBanks
- 1950s+Mass media
- 2000sPlatforms
- 2020sAI
Who actually runs society when economic power gets extremely concentrated?
Every generation since has asked that question about its own new giant. AI isn’t a new argument. It’s the newest place to have an old one. What changed is how much the public trusts anybody to answer it.
How trust in the federal government fell from 77 percent to 17 percent
Three in four trusted Washington
When researchers first asked in 1958, 73% said they trusted the federal government to do what’s right always or most of the time. In 1964 it was 77%. That matters: deep cynicism isn’t some permanent American trait. People trust big institutions when those institutions look competent, fair, and visibly useful.
Vietnam, Watergate, inflation
By 1980, only about a quarter still trusted Washington. And an intellectual shift rode along with the drop. The old populist line was “government must protect us from private power.” A newer one said “government is one of the powers to distrust.” Both strands are still alive, which is why anti-elite politics shows up on the left and the right, pointed at different buildings.
The bailout looked terrible
Banks helped cause a systemic crisis, then governments rescued the system to prevent something worse. There were serious economic arguments for it. Politically, it read as “the people who broke it got saved.” Trust hit 17%. Occupy gave us “the 99% versus the 1%,” the Tea Party aimed at bailouts and Washington insiders. Different diagnosis, same feeling: the people running the system are not serving you.
Back to 17%
After a pandemic that taught everyone to ask who benefits, who controls the information, and who pays, Pew measured 22% in 2024 and 17% in 2025. It isn’t only American, either. Edelman’s 2025 global survey found 61% of people hold a moderate or high sense of grievance: a belief that government and business serve narrow interests and the wealthy benefit unfairly.
The bunkers are real. Read the next sentence carefully.
For years, reporters have documented wealthy tech executives and investors buying remote land, survival shelters, and escape plans. The New Yorker’s 2017 investigation of doomsday prep among the super-rich described people preparing for political instability, cyberattacks, economic breakdown, and civil disorder.
There are two ways to read that. The mundane one: I have enormous resources, so spending a sliver of them on insurance against a small risk of catastrophe is rational.
The dark one: The people with the most power think society is going to fail, and they’re protecting themselves instead of fixing it.
The viral post picks the dark one and then keeps walking, all the way to they intend to harm us. That last step is where documented social criticism turns into speculation. The trick to thinking clearly here is to notice that the post mixes three different kinds of claims. Try sorting them.
- Evidence Checkable, and true. Federal Reserve data for mid-2026: 32.5% for the top 1%, 2.3% for the entire bottom half.
- Evidence Checkable, and true. 17% said they trust it always or most of the time in 2025, down from 77% in 1964.
- Evidence Checkable, and documented. Reporting such as The New Yorker's 2017 investigation of tech-industry doomsday prep describes exactly this.
- Debatable Reasonable and debated. Serious scholars argue about how much, through which channels, and compared with what.
- Debatable An interpretation. You can marshal evidence for it and against it, and people of good faith land in different places.
- Unsupported A claim about hidden intent. Owning a bunker is evidence of a plan B, not of a plan to make you need one.
- Unsupported A claim about coordinated secret action. Distrust and inequality being real doesn't count as evidence for it.
That sorting keeps you out of two ditches at once. One ditch dismisses every worry about concentrated power as tinfoil. The other treats every suspicion as proven because inequality and distrust are real.
And here’s the part the viral version misses, which is also the part that should worry you more: you don’t need a villain for this to go wrong.
Exit beats repair when you can afford the exit
Picture two households deciding how much the country should spend making the power grid tougher.
Grid up. Both households have power.
Household A loses power for a week if the grid fails. Household B has a microgrid, a generator, a second home, and the budget to ride out almost anything. Ask them both how much public money should go to hardening the grid, and their honest answers will differ. Nobody has to be malicious. Their incentives have simply come apart.
Scale that up. A middle-class family can’t buy private security, backup energy, aircraft, legal teams, private medicine, and property in three countries. A billionaire can. The more of life you can buy a private exit from, the less the public version has to work for you personally.
The problem isn’t that the powerful are evil. It’s that they increasingly don’t need the repair.
Four gauges in the red at once
Each of these alone would be a policy debate. Read together, they describe a system under strain.
of U.S. household net worth held by the top 1%. The entire bottom half holds 2.3%.
Federal Reserve, Distributional Financial Accountstrust the federal government to do what’s right always or most of the time. It was 77% in 1964.
Pew Research Centerof Americans say AI companies haven’t done enough to prevent serious harm. Only 11% call AI a positive for society.
Reuters/Ipsos poll, September 2026The Supreme Court’s vote in Trump v. Slaughter, letting presidents fire FTC commissioners at will and overruling Humphrey’s Executor.
Supreme Court of the United StatesThere’s a fifth gauge that barely existed in the Gilded Age. Rockefeller could dominate oil, but he didn’t own McClure’s, the magazine that published Tarbell’s takedown of Standard Oil. Today, a small number of companies run search, social feeds, app stores, cloud platforms, and increasingly the AI systems people ask about everything else. Economic power and information power have started to overlap: the same firms can participate in the economy and in the channels society uses to argue about the economy.
That makes suspicion cheap to generate even where there’s no conspiracy at all. And it feeds a loop:
- Power concentrates
- Distrust grows
- Politics freezes
- Problems go unsolved
- Distrust grows more
- Voters demand outsiders and radical fixes
- Institutions lose legitimacy
So here is the question worth replacing the viral post with. Not “are the billionaires secretly plotting?” but this:
Can we build a country where, even if powerful people are selfish, incompetent, short-sighted, or hostile, none of them holds enough unilateral power to decide everyone else’s future?
Design for adversaries, not saints
Engineers stopped relying on good behavior a long time ago. When we build airplanes, nobody says “hopefully the pilot never makes a mistake.” We build redundant flight computers, checklists, alarms, independent instruments, and accident investigations. When we build databases, nobody says “hopefully no disk ever fails.” We copy the data to several machines.
Then we build institutions and quietly say:
Hopefully the president is responsible.
Hopefully the billionaire behaves ethically.
Hopefully the CEO doesn’t abuse the monopoly.
Hopefully the AI company puts humanity first.
That’s hope-based design, and an engineer would flag every line of it. The engineering question is blunter:
Assume somebody eventually behaves badly. What can they actually do?
If the honest answer is “ruin everything,” you have a single point of failure. If the answer is “cause damage, which other independent systems contain, expose, reverse, and replace,” you have something close to a fault-tolerant society.
Notice what this does to the argument. You no longer have to decide in advance who the threat is: a president of either party, a tech founder, a bank, an intelligence agency, a union, a billionaire nobody has heard of yet, or an AI system that doesn’t exist yet. You design so that the identity of the bad actor matters less. It’s about as close to ideology-neutral as political design gets.
The first place to apply it is the one the viral post points at, and it’s subtler than “rich people exist.”
How separate kinds of power convert into a master key, and how friction stops it
Power comes in kinds
Political, economic, information, technological, coercive, infrastructure. Picture each as its own lock with its own keyholders. Someone who becomes enormously successful in one, say economics, holds one key. That’s the healthy version: one kind of success, one kind of power.
Wealth becomes political control
Campaign money, lobbying, and legal firepower let economic power flow into political power. This is exactly what the Gilded Age feared, and it’s a conversion, not a crime.
Market dominance becomes information control
Own the search box, the feed, or the chatbot, and your market position becomes influence over what people see, which businesses get found, and which arguments spread.
Information shapes the regulators
Influence over the public conversation feeds back into the political process that is supposed to oversee the influencer. Now the conversions reinforce each other.
Capital buys compute; compute reaches everything
Frontier AI rewards whoever can afford the chips, the data centers, and the energy. And software that can act can reach infrastructure and, eventually, force. Every lock in the ring is now wired to the same hand.
A master key
Capture this one actor, or let it go bad, and you’ve captured the country. That is the real danger in the viral post, stated without any villains: one kind of success becoming a key to everything else.
Tax the conversion, not the success
You don’t have to make everyone equal. You raise the friction at each gate: disclosure, separation rules, interoperability, broad ownership. Someone can still get very rich. They just can’t cash that in, without friction, for control of campaigns, newsrooms, regulators, and the grid.
Five engineering primitives do almost all the work
If you go through every place in American life where one actor holds unusual power, the fixes keep collapsing into the same five moves. You already know most of them from software, aviation, or finance. They just haven’t been applied to power on purpose.
1Multi-key authorization
Some actions are too consequential for one key. The rule that scales: as consequence and irreversibility rise, the number and independence of the people who must agree should rise too. It’s the missile capsule’s rule, or a crypto wallet that needs three signatures out of five.
The independence part is where most real-world versions cheat. A president plus three advisers the president can fire this afternoon isn’t four keys. It’s one key with extra steps.
Try weighing some real decisions. The scores are my judgment calls, not official ratings; the point is the shape of the rule.
Several independent keys, a waiting period, and a supermajority.
Nobody has ever found the rollback for this one.
The same rule tells you how to handle AI. An AI system might become far better than any human at medicine, logistics, or running a power grid. That doesn’t mean it needs authority. You can split the ability to propose from the ability to execute. Instead of telling a system “do whatever it takes to optimize the grid,” you only let it emit something like:
// the model can only say this; it cannot do it
ProposedGridAdjustment(substation=47, load=-3%, duration=12min)
// an independent policy engine checks it; big ones need more keysNIST’s AI Risk Management Framework already treats governance, accountability, and clearly defined human roles as core to deploying AI. The trap to avoid is what you might call the ceremonial human: a person “in the loop” who lacks the authority, expertise, or incentive to say no. You don’t want powerful AI plus a rubber stamp. You want powerful AI plus enforced boundaries, independent sign-off, logs, and a working off switch.
2Automatic failover
This is where society lags furthest behind engineering. If a cloud provider disappeared tomorrow, a well-built critical service would say traffic is moving to provider B.
If a bank failed: deposits are moving to the bridge institution.
If a platform turned hostile: you keep your identity, audience, and data elsewhere.
Sometimes the best defense against a monopoly isn’t stopping it from getting big. It’s making your dependence on it non-exclusive. If leaving costs you your identity, your network, your data, and your customers, you don’t really have a choice. If leaving is easy, even a giant has to behave, and nobody had to prove it was evil first.
3Blast-radius limits
This might be the single most useful idea in the whole kit. Ask of every institution: if this actor went bad tomorrow, how many people could it hurt before someone stopped it? You don’t have to prevent every failure. You make failure local.
The same fault in a monolithic system and in a cellular one
Efficient, until it isn’t
Ninety-six services, one shared dependency: a single cloud region, a single payment processor, a single identity provider, a single regulator. It’s cheaper and simpler. Scroll on and watch one fault.
Everything falls together
The hub fails, or is captured, and the failure races outward to all 96. Nothing went wrong in any of the services. They simply shared a fate. Engineers call this correlated failure.
Same fault, one-sixth the damage
Split the system into six independent cells with walls between them. The identical fault now stops at the wall: 16 down, 80 fine. A utility outage hits a region, not the continent. A corrupt mayor damages a city, not the federal government.
Degraded, not down
Now let neighboring cells pick up the failed cell’s load. Service gets slower in one area; nobody goes dark. Federalism, competition, modular software, and sandboxing are all versions of this one idea: limit the blast radius.
4Reversibility
Here’s a surprisingly underrated point. The most dangerous kind of power isn’t the power to decide. It’s the power to decide things nobody else can undo. A healthy system keeps this loop open: decision, observation, challenge, correction. Sunset clauses, appeals, judicial review, rollbacks, bankruptcy, and interoperable platforms all exist to keep it open.
So every major decision should face one engineering question before it happens: if this turns out to be catastrophically wrong, how fast can we get back to where we were? A one-year tax change: easily. A war: never. That’s why the key ladder above multiplies by irreversibility. Treating every government decision as if it deserves the same process is incoherent. The burden should rise with impact × irreversibility × uncertainty.
5Observability
Distributed systems turn dangerous when nobody can see what they’re doing. So every important exercise of power should leave a trace, the institutional equivalent of a log file:
- authorized_by Who signed it?
- authority Under what law or rule?
- evidence What did they rely on?
- beneficiaries Who gained financially?
- alternatives What else was considered?
- expires When does it lapse?
- reversible_by Who can undo it?
That doesn’t mean publishing military secrets or medical records. It means that contracts, major regulatory decisions, disclosed lobbying contacts, conflicts of interest, emergency actions, and waivers live in one searchable public record, linked by common identifiers. Then any journalist can ask a question like show me every company that won a contract within two years of hiring an official involved in awarding it,
or show me every emergency power still active after two years.
AI, which is part of the problem, becomes part of the audit.
Thirteen warning lamps on America’s panel
Here’s what it looks like to walk the United States, as of September 2026, and flag the places where one person or a small group holds unusually consequential power. Each lamp shows what is true today, then a design sketch for the redundancy. The fixes are proposals for argument, not predictions. Tap a lamp.
Presidential nuclear authority
The president has sole authority to order the use of U.S. nuclear weapons. Advisers advise and authentication confirms the order is genuine, but nobody else’s agreement is required.
Split first use into independent keys held by people the president cannot instantly fire. Keep an expedited path for a verified incoming attack, so the redundancy never weakens deterrence.
Declared national emergencies
Under the National Emergencies Act of 1976, a declaration unlocks a long list of statutory powers. Congress can end one only by passing a joint resolution, which the president can veto.
Every emergency authority expires automatically after 30 to 60 days unless Congress affirmatively renews it. Each action is published in machine-readable form and gets fast judicial review.
Control of the federal executive branch
In Trump v. Slaughter (June 29, 2026), the Supreme Court ruled 6 to 3 that presidents may remove FTC commissioners at will, overruling a 1935 precedent, while treating the Federal Reserve differently.
Separate policy direction from case-by-case enforcement. Presidents set priorities; individual prosecutions, licenses, merger reviews, and audits carry published reasons, tamper-proof logs, and appeal to bodies whose members can’t all be replaced at once.
Congressional leadership as a chokepoint
A few leaders and committee chairs can keep a bill from ever getting a vote. The House’s escape hatch, the discharge petition, needs a majority of the whole chamber to sign.
An automatic discharge rule: when a large, geographically broad coalition backs a bill, leadership cannot block a vote indefinitely. This is the one lamp where the fix is fewer veto points, not more.
Supreme Court interpretation
Nine justices with life tenure can set nationwide constitutional rules that ordinary legislation cannot reverse.
Keep judicial independence and add redundancy around it: staggered terms for future appointments, enforceable ethics rules, transparent recusal. Give no political actor a veto over individual cases.
Frontier AI and cloud infrastructure
Building frontier AI takes enormous capital, chips, data centers, and energy, so a small number of developers and cloud providers hold unusual leverage. The FTC has studied how cloud and AI partnerships affect access to compute and switching costs.
Compute portability: standard model packaging, data export, interoperable inference. Critical public services must run on at least two independently controlled providers and never depend on a single model family.
AI systems that can act in the world
The danger isn’t an AI producing words. It is software that can initiate payments, switch infrastructure, or issue administrative decisions on its own.
Separate proposing from executing. The AI emits typed proposals, an independent policy engine decides what’s allowed, high-consequence actions need multiple cryptographic sign-offs, and every step lands in an append-only log.
Information gateways
Federal courts found Google liable for illegal monopolization twice: in search in 2024 and in advertising technology in 2025. A handful of firms run the feeds, app stores, and search boxes where the public forms its picture of the world.
Make gateways easy to leave: you own your identity, audience, subscriptions, and history in standard formats. Ranking changes that affect civic information get auditable records, without handing editorial control to the government.
Payment infrastructure
Already more redundant than most sectors. The Fed’s FedNow service, launched in 2023, runs alongside private instant rails, ACH, card networks, and wallets.
Every regulated bank reachable on at least two independent rails. Large merchants and agencies fail over automatically. Account numbers become portable, so switching banks doesn’t mean rebuilding every payment relationship.
Banking and financial custody
Very large intermediaries become systemically important because millions of people depend on them at once. 2008 showed how one failure propagates.
Continuous resolution readiness: rehearsed plans to move deposits, securities, and basic transactions to a bridge institution fast, with customer data in standard schemas so a bank’s software failure can’t trap its customers.
Electrical grid control
Grid operators, utilities, and very large power users can become regional chokepoints. AI data centers are turning into some of the biggest loads the grid has ever served.
A cellular grid: regions that can island themselves, more distributed generation and storage, black-start capacity, spare transformers, automatic load shedding. No single customer should be able to destabilize a region.
Internet and cloud concentration
Huge numbers of businesses lean on the same hyperscaler, identity provider, DNS service, or content network, so one outage takes thousands of them down together.
A resilience standard like a capital requirement: essential services prove they can recover on another provider. Public agencies run regular “lose our primary cloud for 72 hours” drills.
Local ownership of essentials
Consolidation can hand one owner the hospitals, housing, local news, or food processing in a region without it ever looking like a national monopoly.
Measure concentration where people live, not only nationally. Trigger tougher review when one owner controls an essential service across a region, and require continuity plans where switching is otherwise impossible.
Look at the tags. Thirteen very different institutions, and the same five primitives keep showing up. That’s the whole point: this isn’t thirteen unrelated reforms. It’s one design discipline applied thirteen times.
More keys can also break the machine
If you’ve been nodding along, here’s where your intuition needs one correction. The instinct “add more checks” is only half right, because distributed systems have two classic ways to fail.
One is capture: a single actor takes over and nobody can stop it. The other is deadlock: so many parties can veto that nothing happens at all, even when something urgently must. Plenty of Americans who distrust institutions aren’t angry about tyranny. They’re angry that housing, health costs, and infrastructure seem permanently stuck.
That’s why the burden has to scale rather than max out everywhere, and why lamp 04 in the audit, Congress, gets fewer veto points, not more. It’s also why the nuclear fix keeps a fast path for a verified incoming attack. Speed is a legitimate requirement. The goal is to spend friction where irreversible harm lives and nowhere else.
A good system isn’t hard to use. It’s hard to abuse.
The goal was never to find better people
Go back to those two officers and their keys. Nobody designed that room because they believed Air Force officers were bad people. They designed it because they understood that over enough years, with enough officers, some day would be a bad day, and the stakes were too high to bet on it never coming.
That’s the whole philosophy in one room. You don’t fix concentrated power by finding saints, and you don’t fix it by hunting villains. You fix it by asking every powerful institution one question, on a schedule, the way aviation inspects a part whose failure could crash a plane:
If the leadership here became malicious, incompetent, compromised, or incapacitated today, what is the worst thing it could do before someone independent could stop it?
Anything with a catastrophic answer is a design defect. Not necessarily illegal. Not necessarily anyone’s fault. Just unacceptable until there’s another independent layer between one bad day and everyone else.
The viral post gets the feeling right and the diagnosis wrong. It thinks the problem is who holds power. The problem is how power is held.
The goal isn’t to eliminate powerful people. It’s to eliminate irreversible, unaccountable, single-point-of-failure power.
We already built that rule into concrete rooms under the Great Plains. It’s time to install it at the top.
If “design for adversaries” stuck with you
Six Invisible Walls Stand Between You and a Plane Crash
The best real-world example of a fault-tolerant system: how aviation stacks independent layers so no single error can bring a plane down, and which walls are cracking.
Read the essay →Essay · Content PilotsNobody Will Ever Admit They Were Wrong
The reversibility primitive, in depth: how to build institutions that correct their own mistakes even when nobody inside them will concede.
Read the essay →Essay · Content PilotsThe Robot Dividend Could Hit $10 Million a Year
The ownership side of the master key: what it would take for ordinary people to hold a real stake in an automated economy instead of relying on whoever owns the machines.
Read the essay →Primary source · CRSCommand and control of nuclear forces
The Congressional Research Service’s short primer on who can order the use of U.S. nuclear weapons, and how the order travels.
Read the primer →Is one platform your single point of failure?
The same question works at small scale. If every customer finds you through one marketplace, one social account, or one directory listing, somebody else holds your key. I build websites for service businesses at Content Pilots, with scheduling and payments built in, so your customers can find and book you on a site you own. And if you think one of my thirteen lamps is wrong, tell me.

