Critical Density

The problem you only see after it is too late Your AI estate grew the way every estate grows: one sensible deployment at a time. A copilot here, a fine-tuned assistant there, a vendor feature switched on by default. Every individual decision was reasonable. Nobody chose to cross a line, because there is no line you can see. The dependency builds quietly, the curve stays smooth, and the day it tips, no single event triggered an alarm. Then something goes wrong. A wrong answer gets acted on. A model decides what it should not have. And you discover the part that actually hurts: you cannot say which layer did it. The base model, the fine-tune, the corpus, the orchestration, the prompt, each owned by a different party, each able to change behaviour without telling the others. The logs sit in three systems on three clocks with no joinable timeline. You have a great deal of evidence and no account of what happened. That capacity, the ability to say who did it, is not recovered after the incident. It is a property you build in before, or it is absent forever. This book is how you build it in. The instrument: the Kessler Syndrome, used and then set down The book reasons about your AI estate through the Kessler Syndrome, the orbital-debris cascade where each collision makes the next more likely until a shell of orbit becomes unusable. It is a clean, emotionally neutral model of how dependency accumulates, how thresholds get crossed without an alarm, and how accountability dissolves once the harm is done. It lets you think clearly about your own systems without first picking a side in the tired argument over whether AI is salvation or catastrophe. It is an instrument, not a thesis. The orbit story leads the first third of the book and then recedes on purpose, paragraph by paragraph, until the governance substance carries the page on its own. By Part II you are reading audit practice, not space. This is deliberate, and it is enforced: the book is built so you remember the controls, not the metaphor. No predictions about how AI ends. No hype, no doom. An operating manual. What is inside The book — ten chapters, three beats each, no filler. Every chapter runs the same pattern. First the mechanism, stated as a general law. Then the translation, what that same behaviour looks like in your AI portfolio, named as an observable you can go and check. Then the move, one concrete artifact with an owner, a meeting, and a first action. The promise the book makes and keeps: every chapter ends with something to do on Monday. It opens on a 72-hour orbital scenario (fictional, no real names) that installs the mental model, then walks the ten governance problems that follow from it: invisible thresholds, rational actors arriving at a bad aggregate, attribution that was never installed, prevention economics, frameworks that predate the problem, audit in practice, who owns the model’s mistake, buying accountability, designing traceability before the incident, and the cadence that keeps it all from decaying. Ships as a print-ready PDF (A4) and a reflowable EPUB for any e-reader, plus a browser-readable HTML copy. The toolkit — five board-ready artifacts that assemble into one system. The Density Register — the join key. One scored row per AI touchpoint, with a Density score and a Dependency score. Every other artifact attaches to its rows. You cannot govern what you have not counted, and building it surfaces the touchpoints nobody knew were live. The Attribution-Readiness Checklist + Traceability Architecture Spec — 25 scored items opening with the Licence-Plate Test, plus the seven requirement statements that make the hard items cheap to answer. The instrument that tells you, before an incident, whether a system can be attributed at all. The RACI-for-AI — one named person in the Accountable cell per system, with lifecycle columns that close the six accountability seams, an Article 25 role-shift check, and an orphan check. The Audit Question Bank — around sixty evidence-scored questions across eight sections. The examiner’s lens, run formally by internal audit or as a self-assessment by the risk officer. The Governance-Cadence Control Spec — the meta-control. The review calendar, the assumptions register, the refresh matrix that schedules the other four, three metrics, and escalation rules. The discipline that keeps the toolkit a living system instead of a folder of decaying snapshots. Each artifact ships as a ready-to-print PDF, a browser-viewable HTML, and editable Markdown you drop into your own docs. Every chapter’s worked example matches the artifact, so you read the chapter to understand the control, then use the file to run it. Who this is for CIOs, CTOs, and platform leads who own the AI estate and answer for it Heads of internal audit, risk officers, and compliance leads who have to attest AI program owners standing up governance that survives contact with a real portfolio Anyone preparing for the EU AI Act who needs the controls, not another explainer The examples lean toward EPC and energy because that is the seat the author operates from, but nothing is sector-locked. A bank examiner, a hospital’s risk officer, and an insurer’s model-risk lead all find their own register rows in these pages. It assumes you run real systems, sign real attestations, and own real budgets. What makes this different It hands you a governance system, not a framework. Five artifacts with a shared spine: the register is the data layer, the checklist is the audit lens, the RACI is the ownership layer, the cadence is the lifecycle layer. They reference each other by design. Most governance books stop at a list of principles. This one ships the executable controls and the meeting they run in. It solves the problem most books ignore: governance decays. The final artifact is a meta-control, a cadence that re-checks the other four on a schedule and measures whether the maintenance actually happened. Approval stops being a finish line and becomes a renewable licence. That is the difference between a control and a document that was true the day you wrote it. It is audit-grade about its own facts. Every volatile claim carries an as-of date. The EU AI Act dates, the standard versions, the debris counts, the live legal cases: all dated, all flagged, because they move. The book tells you where each one will age and how to keep your copy current. The metaphor earns its keep and then leaves. The Kessler Syndrome installs the model and recedes. The book is engineered so the orbit story does not crutch the governance content. You finish remembering the Density Register and the Licence-Plate Test, not the satellites. Pricing and updates $59 — the book in three formats and the full five-artifact toolkit. Free updates. The fastest-aging facts in this book are the EU AI Act dates, and they are still moving (the Digital Omnibus is provisional as of writing). When a load-bearing fact shifts, the updated files re-deliver to every buyer through Gumroad automatically. You do not repurchase. Team use included. Share with your platform, audit, and risk teams. No per-seat fees inside your org. The break-even math At $59: if this book gets one criticality-4 system named, attributed, and owned before it fails, instead of after, it has paid for itself many times over before your next governance review. The larger number is the one you avoid. An unattributable AI incident is a six-week forensic exercise that ends in “we cannot say,” in front of a regulator or a court. One Red caught at the deployment gate, one orphaned owner found by the quarterly check, one Article 25 role-shift assessed before it surfaces in litigation: any single one of those is worth more than the price of the book, and the toolkit is built to catch all three. Frequently asked questions Is this a book about space? No. The Kessler Syndrome is a thinking instrument, used to reason cleanly about dependency and thresholds, and it recedes after the first third. By Part II you are reading AI audit practice. There is no orbital-mechanics lecture beyond what the model needs. Is it tied to one company or sector? No. The opening scenario is fictional. The examples lean toward EPC and energy but nothing is sector-locked. Banks, hospitals, insurers, and manufacturers all map their own systems onto the register, the RACI, and the checklist without translation. Do I need to be technical to use it? It is written for the operating seat. The executive chapters (ownership, procurement, cadence) read cleanly for a CIO or an audit lead. The traceability chapter goes deep enough for a platform lead to write requirements from. Both audiences find their layer. How current is the EU AI Act content? Sourced and dated throughout. The high-risk dates, the Article 50 marking grace, and the Digital Omnibus status are all flagged as volatile with their as-of dates, because they are still provisional. Free updates re-deliver when they settle, and the AI at Work newsletter tracks the changes between updates. What format are the files? A ZIP with the book as a print-ready PDF (A4), a reflowable EPUB, and a browser HTML copy, plus the five toolkit artifacts each in three formats: a ready-to-print PDF, a browser-viewable HTML, and editable Markdown you can drop straight into your internal docs or wiki. Where do I start? Build the Density Register first, because you cannot govern what you have not counted. Then stand up the cadence so it stays current. The other three slot in as their triggers fire. The free Licence-Plate Test (store.kesslernity.com/l/licence-plate-test) is a ten-minute taste of the attribution checklist if you want to score one system before you buy. Licensed, not sold. Full License & Terms apply (ref KESS-LIC-2026-001). By purchasing you agree to the version in force on your purchase date.Kesslernity is an independent publisher. This material is practitioner guidance, not professional, legal, or financial advice.Questions before you buy, or support after? Contact mathieu@kesslernity.com.Terms of Service · Privacy Policy