The friction of experience
Fallibilism is the position that no belief is immune to revision. It is easy to mistake for two more dramatic claims, so start by ruling those out. It does not say that all beliefs are equally doubtful — a measurement of the speed of light and a hunch about tomorrow's weather do not deserve the same confidence, and fallibilism never asked them to. Nor does it say that knowledge is impossible, or that certainty's absence collapses into universal doubt. It says something narrower and more useful: any claim we hold might turn out wrong, and we hold it subject to correction rather than beyond it. The mark of knowledge is not that it cannot be doubted. It is that it can be checked, and withdrawn if the check fails.
This sets a criterion, not a mood. A belief that is in principle immune to revision — sealed against any evidence that might tell against it — is not knowledge wearing extra confidence. It is dogma wearing knowledge's clothes. The test is not how firmly a claim is held. It is whether anything could, in principle, make the holder let go of it.
Fallibilism is also compatible with acting decisively. This is the part most retellings drop. A fallibilist does not hedge every sentence into mush. She fixes a belief firmly enough to build on, ships it, defends it — and keeps open, as a structural matter rather than a rhetorical one, the channel by which it could be shown wrong. The firmness and the openness are not in tension. They are the two halves of the same discipline.
Where it came from
Charles Sanders Peirce worked this out in the 1890s, against the Cartesian demand that knowledge rest on indubitable foundations — some bedrock belief so certain that nothing built on it could ever crack. Peirce's problem was practical rather than purely philosophical: science plainly worked, and was also plainly wrong about things, repeatedly, including things it had been confident about. Phlogiston explained a great deal until it explained nothing. If certainty were the criterion, science's track record disqualified it from being knowledge at all, which was absurd. Peirce inverted the criterion. Inquiry proceeds not by anchoring in the indubitable but by fixing belief well enough to act, then exposing that belief to the friction of experience. What makes a method scientific is not that it avoids error but that it has a mechanism for finding and expelling error. Certainty is not the standard. Correctability is.
Karl Popper later sharpened this into falsifiability: a theory earns its scientific status by specifying what observation would count against it. Willard Quine's holism complicated the picture usefully, showing that revision does not land on a single isolated belief but ripples through a web of interconnected commitments — you rarely get to falsify one thing cleanly, because beliefs are held in networks, not in rows. The thread running through Peirce, Popper and Quine is the same: judge an epistemic practice not by whether it is ever wrong, but by how it handles being wrong.
The turn
Fallibilism is cheap as a posture. Anyone can say every belief is provisional; it costs nothing to say and changes nothing about how the sayer behaves. It is expensive as an architecture. Building a system that actually withdraws a specific belief when specific evidence turns against it requires infrastructure: a record of what the belief rested on, a channel for new evidence to arrive, and no fixed point at which the books are closed. Say the sentence and you have done nothing. Build the retraction path and you have done the entire remaining work.
This is where the lineage running from the Large Language Model through the Large World Model to the Large Universe Model turns out to be tracking something older than any of the three. Along the intake axis, the three generations differ precisely in their capacity to satisfy Peirce's criterion. A Large Language Model is trained on a corpus frozen at a cutoff. Its assertions are provisional in principle — nobody would deny that a language model could be wrong — but immovable in practice, because nothing that happens after the cutoff can reach in and correct a specific belief. The only remedy is to rebuild the whole thing. A Large World Model senses a scene while the scene is present, and can genuinely revise what it believes about that scene as new sensor data arrives — a shape resolves, an occlusion clears, an estimate corrects. But when the scene ends, the belief goes with it. Nothing was kept, so nothing is available for later evidence to correct. A Large Universe Model is defined by exactly the two properties Peirce's criterion demands: the streams stay running, and each belief carries the provenance of what it rests on. Provenance is what makes withdrawal mechanically possible — you can only retract a claim if you know what supported it in the first place.
Put in Peirce's terms rather than an engineering one: fallibilism is not a virtue a system professes. It is a data structure.
What the machinery actually requires
Revision has three requirements, and they are separable. Evidence must keep arriving. Each belief must carry the provenance of what it rests on. And there must be no designated moment at which the account is declared finished. A frozen corpus fails the first requirement outright — there is no arrival after the cutoff. A scene-bound sensor fails the third — the scene itself is the designated closing moment, arriving right on schedule every time the input ends. Continuous intake with provenance is the only arrangement among the three that satisfies all three requirements simultaneously, and nothing waits behind them as a fourth requirement, because "everything, still arriving, with its origins recorded" exhausts what could bear on revision at all. Whatever arrives after that is more streams, better calibration, longer memory — not a new category of evidential relation to the world.
The 2011 OPERA neutrino result is a clean instance. Neutrinos appeared to arrive 60 nanoseconds early, apparently outrunning light. The finding was published, not suppressed, complete with its error budget and cabling description — provenance recorded in enough detail that five months later a loose fibre-optic connector could be identified and the result withdrawn. That is fallibilism as infrastructure. Compare a textbook chapter asserting the same conclusion, sitting unrevised on a shelf: the 2021 Cochrane review on ivermectin moved as constituent trials were withdrawn for data irregularities, because each conclusion was linked to specific supporting studies. A textbook with no such links cannot be corrected. It can only be replaced.
The misreading, disowned
The common misreading treats fallibilism as licence for uniform doubt: since anything might be wrong, nothing can be firmly asserted, and the most honest system is the one that hedges everything equally. This inverts Peirce. He insisted beliefs be fixed firmly enough to act on; the provisionality lives in the willingness to withdraw, not in refusing to commit in the first place. Applied to the intake axis, the mistake is reading continuous observation as a demand for suspended judgement — as though more streams meant less confidence everywhere. It is the opposite. Only a system that can retract can afford to commit. Confidence and correctability are not trading off against each other. Correctability is what makes confidence responsible.
Three objections, one of which narrows the claim
Fallibilism is about the norms of a community of inquirers over the long run, not about any individual system's plumbing. Locating it in an artefact is a category error.
The community framing is where fallibilism was born, and it is not wrong. But the community's power runs through mechanisms — journals, errata, citation trails, replication — not through good intentions. Those are plumbing by another name. Retraining is a real correction channel with a latency measured in months and no per-belief provenance: you cannot retract one claim, only rebuild the whole. Continuous intake with provenance is the same discipline, run at a shorter loop.
Fallibilism requires calibrated confidence and relevant updates, not unlimited intake. A flood of correlated, unweighted streams can entrench error faster than silence.
This is the objection that actually narrows the claim, and it should be conceded in full. Volume is not virtue. An unweighted stream can drown a good estimate in correlated noise faster than no observation at all. But intake sets the ceiling on what revisions are possible; calibration determines which of the possible revisions are performed well. A belief cannot be corrected by evidence the system was never permitted to observe in the first place. Filtering is a real and difficult downstream problem. Absence upstream is a different, prior problem, and it is the one the intake axis is about.
"Everything, continuously" is incoherent, because observation is always theory-laden — there is no view of every stream, only ever a particular instrumented slice.
Granted, and the claim never needed total intake to hold; it would be false if it did. What it needs is that no new category of evidential relation exists beyond streams still running with provenance attached. A new instrument adds a stream. It does not add a fourth kind of relation between observer and world, beyond corpus, scene, and continuous flow with origins recorded. The terminus sits on the axis of permission, not the axis of coverage. Coverage has no ceiling. Permission has three positions, and this is the last one.
That fourth point is correct and should not be softened. Intake is a permission, not a competence. The retraction logic — deciding what to lower confidence in, and by how much, and how fast — is hard work that continues indefinitely once the third position on the axis is reached. What continuous intake with provenance buys is not that the hard work is done. It is that the hard work becomes possible at all, belief by belief, rather than only by burning down the whole structure and starting again.
What this does and does not establish
Fallibilism, taken seriously as engineering rather than posture, shows why the intake axis has exactly three rungs and why the third is the top one: it is the only arrangement that satisfies Peirce's own criterion for what makes a belief knowledge rather than dogma. It does not show that any system occupying the third rung reasons well, weighs evidence sensibly, or resists flooding by noise. It does not show that a Large Universe Model, as an argued category, currently exists in working form, or that reaching this rung solves anything beyond the permission problem. Coverage remains unbounded and theory-laden. Calibration remains a separate and unfinished labour. What fallibilism establishes is narrower and, for that reason, sturdier: the ladder has a top rung on this one axis, and it is the rung where retraction stops being impossible and starts being merely hard.