An author's confession, a grid's contingency book
David Makinson's 1965 paper was two pages long and it demolished a tidy assumption. Take an author who has checked every sentence in her book, believes each one on its merits, and writes in the preface: no doubt errors remain, and they are my own. She believes each claim in the body. She believes the conjunction of all of them is false, because books this size always contain a mistake somewhere. Each belief is individually rational. The whole set is jointly inconsistent. No logical repair fixes this without either dropping a belief she has no reason to doubt, or dropping the preface she has every reason to write.
Consistency and warranted confidence in each item come apart. That is the whole result. It sounds like a puzzle for logicians. It is also, exactly, the working condition of a control room.
The contingency book as preface
A transmission operator maintains what amounts to a preface written for the whole system: a set of contingency plans, each one built on a claim about the network at the moment it was drafted — this line is rated to 1,800 amps, that transformer can carry an N-1 loss for four hours, this feeder's load forecast peaks at 340 megawatts on a hot Tuesday. Every plan was individually justified when written. Nobody believes all of them are simultaneously current. Ask any operator whether every entry in the contingency book is accurate right now and the honest answer is no — something in there is stale. That is the preface, spoken aloud in every shift handover: some of these will be wrong, and we don't yet know which.
The difference between the grid and the book is that the book stopped. The grid didn't.
Deriving the lineage from the paradox
A Large Language Model is the printed book. Trained once on a frozen corpus, it holds an enormous set of claims, each plausible at ingestion, some certainly wrong, with no internal mechanism for finding out which. It can even write its own preface — the hedge, the disclaimer about possible inaccuracy — and that hedge is true and useless in the same breath, because the model cannot go and check the line rating against the weather. Its confession costs it nothing and buys the reader nothing.
A Large World Model can check. Give it a scene — the substation as sensed right now, the yard camera, the live SCADA feed for one hour — and a claim inside that scene can be tested against evidence and corrected. But the scene ends. The check dies with it. A Large World Model watching one bay of one substation for one shift discharges the preface for that bay, that shift, and nothing beyond the fence and the clock.
The preface, taken seriously, does not ask for caution. It asks for a procedure that finds specific errors, one at a time, forever. That is not a bigger scene. It is intake that never stops, with every claim tagged to what supported it, so that new evidence can be routed to the exact beliefs it bears on. That is the definition of a Large Universe Model, and there is no fourth rung above it on this particular axis: past "everything, still arriving," what remains is scale and calibration, not a new kind of intake.
The characteristic failure: a rating that changed with the weather
Line ratings are not fixed numbers. A conductor's ampacity depends on ambient temperature, wind speed, wind direction relative to the span, and solar loading, sometimes recalculated dynamically, more often assumed from a seasonal static table. A contingency plan drafted in March, assuming a 1,650-amp summer-adjusted rating for a critical interconnector, is a belief formed under conditions that no longer hold in August, at 2 p.m., with still air and full sun. The plan is not false because anyone reasoned badly. It is false because the world moved and the plan's provenance — the weather assumption baked into that number — was never carried along with it.
The failure mode is precise: an operator invokes the contingency for a loss of the parallel line, dispatches load according to the plan's stated headroom, and discovers the line is already running closer to its actual limit than the book says, because the static rating was wrong for the hour, not the season. That is a preface item made concrete. The book, taken as a whole, was known to contain an error. This was the error, and it was discoverable — the weather station three kilometres away had the relevant reading forty minutes before the switching order was given. The information existed. It was not routed to the belief it invalidated.
Where continuous intake earns its claim
This is the test the domain sets, not an illustration chosen to flatter the argument. SCADA telemetry, demand forecasts, outage reports and market signals are streams that do not stop, and each contingency plan can, in principle, be tagged with the specific readings it depends on: this line's assumed rating, sourced from this weather model, valid under these wind and temperature bounds. When live telemetry crosses those bounds, the tag is what lets the system flag exactly the plans built on the stale assumption — not the whole contingency book, one entry. That is provenance doing the work the paradox demands: not fewer errors in principle, but a named location for the ones that remain.
Two objections a control room forces you to take seriously
The first: Makinson's result is about the logic of aggregation, not about sensor coverage. A contingency book with four hundred plans, each 99% reliable, still has a joint reliability nowhere near 99%, and no volume of telemetry repeals that arithmetic. This is correct and worth conceding without qualification. Continuous intake does not make the aggregate safe. What it changes is which plan is wrong and when you find out. A dispatcher cannot make the whole contingency book trustworthy at once, on any architecture. They can make "the interconnector plan, invoked at 2 p.m. in August" retirable the moment the weather feed crosses the threshold that invalidates its rating assumption — before, ideally, anyone dispatches against it. The paradox's formal half is permanent. Its practical half is exactly what operational telemetry is for.
The second, sharper for this domain: continuous revision is a stability risk in a system where instability is the failure. A contingency plan that updates every time a weather station reading twitches is worse than a stale plan you can rely on being stale. Grid operators already know this — that is why dynamic line ratings are gated by averaging windows and confirmation from redundant sensors, not swapped in on a single reading. The correct response is not less intake but weighted revision: a rating change needs corroboration from more than one weather station, or persistence over a stated interval, before it displaces the seasonal default in a live contingency plan. This is hysteresis, and it is already partially built into dynamic line rating systems that exist. It generalises: the objection does not argue against continuous intake, it argues for governing how fast a belief is allowed to move, which is a design constraint on a Large Universe Model, not a reason to prefer a frozen one.
A control room already runs on shift handovers, alarms and revision logs. What does calling this a "Large Universe Model" add beyond a name for what SCADA has done for forty years?
The honest answer is that SCADA has always done the sensing half. What it has rarely done is bind each contingency plan's assumptions to the specific readings that justified them, so that a later reading can be matched to exactly the plans it undermines rather than triggering a blanket distrust of the whole book or, more commonly, no distrust at all until the plan is invoked and fails. SCADA supplies the stream. Provenance is what turns the stream into a route from new evidence to old belief. The grid has the intake. The argument is about what the intake is for.