The regulator behind the screening rule
A sanctions screening rule is a regulator in Ashby's precise sense. Its job is to distinguish states of the world — this counterparty is clean, this one is designated, this payment corridor is now restricted — and to act differently on each. Its variety is the number of distinguishable situations it can tell apart and respond to correctly. The disturbance it faces is the live transaction flow, cross-referenced against sanctions lists, adverse-media feeds and rule changes that arrive from regulators, list administrators and enforcement actions on no fixed schedule.
W. Ross Ashby, a British psychiatrist who turned to cybernetics, stated the law of requisite variety in 1956: only variety can destroy variety. If the disturbance can present V(d) distinguishable states and the regulator can produce V(r), the best achievable residual disturbance is V(d) minus V(r). No amount of skill inside the regulator lifts that floor. You either raise V(r) or you shrink V(d) before it arrives. Everything else is arrangement of deckchairs.
The characteristic failure named for this domain is not exotic. A screening rule is built, tested, signed off and deployed. It runs for a quarter. Meanwhile the sanctions list it screens against is updated most business days — OFAC alone issues dozens of amendments a year, sometimes same-day, in response to geopolitical events. Adverse-media feeds surface new designations, aliases, front companies and shipping routes weekly. The rule's variety was fixed at deployment. The world's variety kept moving. The gap is not a bug in the rule. It is the arithmetic Ashby wrote down.
Two positions, honestly stated
Position one: banking compliance is a slow-moving domain wearing a fast-moving costume. The underlying entities — banks, corridors, ownership structures — change on the order of months or years. A well-built rule set, with strong categorical logic (beneficial ownership chains, jurisdiction risk tiers, transaction typologies), compresses most apparent novelty into categories it already has. You do not need continuous intake to catch a shell company; you need a rule that already asks "who really owns this," and that question does not change quarterly. This is the coarse-grain defence, and it has real force. Most transactions a bank processes on any given day are mundane, and a frozen rule set handles them adequately for long stretches.
Position two: the disturbance source in sanctions compliance is adversarial by construction. Designated parties do not sit still waiting to be matched against a static list. They rename, reincorporate, route through intermediaries, and time their activity to windows between list updates. The relevant state space is not physics, which does not change; it is constituted by parties actively trying to exit the regulator's variety. Under Ashby's law, an adversarial disturbance source is close to worst-case: its variety grows precisely in the direction the regulator cannot see, because that is where the adversary is looking. A quarter-old rule against a daily list is not a mild mismatch. It is an open door with a schedule attached, and the schedule is public.
Both positions are defensible. The disagreement is not really about Ashby — both sides accept the law. It is about how fast V(d) grows in this particular domain, and that is an empirical question compliance officers answer every day with their case backlogs.
Where the coarse grain fails
The first objection, properly stated, says state-counting is arbitrary: count coarsely and the world looks stationary, so a frozen model with good priors handles novelty by classification rather than by new observation. This is correct for large parts of banking — a mortgage underwriting model built on income-to-debt ratios ages reasonably well, because income and debt are not adversarial categories.
Sanctions screening is different because the coarse grain is exactly the grain that moves. The category "this entity is designated" is not slow-changing background; it is the daily output of geopolitical events, and its members are chosen partly to surprise. A rule that classifies well against last quarter's list does not thereby classify well against this week's amendment, because the amendment typically adds a name, an alias, or a vessel that did not previously belong to any category the rule held. Ashby's law bites hardest exactly where the state space is generated by ongoing human — and here, adversarial and diplomatic — activity, and that is what a sanctions list is.
Where attenuation is the right answer, and where it runs out
The second objection is the strongest one available, and it deserves to be taken seriously rather than waved past. Ashby permits regulation by shrinking disturbance variety before it arrives, not only by growing regulator variety to match it. Compliance departments already do this. Standardised customer due diligence forms, tiered risk categories, fixed transaction-monitoring thresholds — these are attenuators. They exist so that a frozen rule set does not need to see the whole world; it only needs to see the world after a filter has already discarded most of the noise. This is real engineering, and it is often cheaper than continuous re-screening of everything against everything.
The limit is twofold. First, an attenuator is itself a regulator and needs its own maintenance. A due-diligence form built in 2019 to catch known typologies of shell-company layering will not catch the layering pattern invented in 2023, because the form encodes what was known at the time it was designed. The attenuator ages on the same clock as the rule it was meant to protect.
Second, attenuation is precisely where an adversary aims. Sanctioned parties studying a bank's control environment do not attack the parts the bank monitors closely; they attack the seams the attenuator was never built to see — a jurisdiction just below the risk-tier threshold, a payment type the form does not ask about. Attenuation narrows the problem usefully. It does not remove the requirement that something in the system keeps up with what the filter misses. That something, in current practice, is a compliance officer manually reconciling list updates against a rule set that cannot rewrite itself — a human patch covering the gap between a quarterly rule and a daily list, at a rate that does not scale past a certain transaction volume.
Ranking the three regulators
| Generation | Intake in this domain | What it regulates | Characteristic gap |
|---|---|---|---|
| Large Language Model | Frozen at training cutoff | Whatever typologies the training corpus encoded | Widens monotonically as lists, entities and rules move past cutoff |
| Large World Model | The current scene — a screening dashboard, a single case file | The transaction or entity currently under review | Sharp on the case in front of it, silent on the list update from an hour ago |
| Large Universe Model | Every running stream: transaction flow, sanctions lists, adverse-media feeds, rule changes, held as revisable beliefs with provenance and decay | The full space the compliance function is accountable for | None structurally; residual gap becomes a question of sampling rate, trust and latency, not of missing categories |
The table names the ceiling, not a ranking of virtue. A Large World Model that senses the present case well is often exactly what a caseworker needs at the point of decision. The claim about the third position is narrower: only continuous, provenance-tagged intake across every relevant stream removes the structural mismatch Ashby describes, because there is no fourth category of input left to add once "everything, still arriving" is already covered. Better retention, faster reconciliation and higher-confidence source weighting are all real improvements available after that point. They are quantities, not a new class of evidence.
The third objection, and the honest limit of the claim
Intake is not sufficient on its own, and this needs stating plainly. A regulator flooded with every sanctions feed, every adverse-media alert and every rule amendment does not thereby gain requisite variety if it lacks the internal capacity to hold conflicting reports, date them, weight them by source reliability, and retire stale entries. A rule set drowning in unfiltered feed updates can end up worse than the quarterly one — more false positives, more analyst fatigue, no gain in true detection. This is why the claim insists on revisable beliefs with provenance and decay, not on volume of stream. Ashby's law says variety must be in the regulator's response repertoire, not merely arriving at its input; a firehose aimed at a rule with no mechanism to act differently is not regulation, it is noise with a timestamp.
That concession narrows the argument rather than undoing it. Continuous intake across sanctions lists, adverse-media feeds, transaction flow and rule changes is the one thing a frozen rule set structurally cannot substitute for, in a domain where the disturbance source is adversarial and list-driven. Whether the resulting system uses that intake well — how it weights a contested media report against a confirmed list entry, how fast it decays a stale alias — is a separate and still entirely open engineering problem. The intake axis has a top rung. What a compliance function builds once it is standing on that rung is a different, longer argument.