6. Governance transfer, in two separated layers
The results so far are theorems about a linear feedback loop. What, if anything, do they say about governance? The honest answer separates into two layers with very different transfer conditions, and the discipline of the section is to never let the stronger borrow the first's authority.
Layer A — the allocation logic, which transfers without Bode. The imported law of Section 2 is a statement about any constrained optimizer facing a fixed harm profile; it uses no conservation law. To export it, one identifies five objects in the governance domain: a location variable along which a strategic actor chooses where to act, a harm profile over those locations, the actor's reachable set, its concentration bound, and its budget — together with the discovery capacity of Section 4. Given these, and provided harm is linear and additive in the allocated density with costless static reallocation, the claim transfers as a static benchmark: strategic actors realize not the average harm over what they can reach but its upper tail, scaled by how densely they can concentrate and only to the extent they can discover it. Real actors face nonlinearity, congestion, switching costs, and endogenous response, so this is a benchmark model rather than a verbatim theorem about strategic behaviour in general. This formalizes the adversarial branch of the Goodhart taxonomy specifically — the regime where an agent responds to the metric and exploits residual structure — and supplies what the verbal statements of that literature lack: a budget, a licensing checklist, and a quantitative worst case [IP]. It does not require, and does not assert, that reform created the harm; it says only that whatever reachable, discoverable heterogeneity exists will be exploited to its tail rather than its mean.
Layer B — the manufacture claim, which does not transfer without a conserved burden. The stronger and more commonly intended claim is that suppressing the monitored channel does not merely expose pre-existing harm but manufactures it — that reform forces compensating vulnerability into existence. This is the Bode half, and it is exactly here that borrowed formal authority threatens. Bode's integral guarantees manufacture because it is a conservation law with proven licensing conditions. A governance system inherits that guarantee only if one can exhibit, empirically, an analogous conserved or lower-bounded quantity — a total burden that suppression in one place provably forces up elsewhere — together with the domain over which it is conserved, the mechanism by which the burden relocates, and the boundary beyond which conservation fails. The control case supplies all four for free; a governance domain supplies none of them by default. Absent an argument for all four, Layer B is unlicensed: to assert it is to dress a heuristic in the integral's authority, the precise move this series exists to refuse. We therefore state Layer B conditionally. Where a domain supports a conserved-burden argument, the manufacture claim and the Section 5 trilemma — suppress the proxy hard, keep the system robust, avoid manufacturing exploitable exposure; one must give — transfer at [IP]. Where it does not, only Layer A transfers, and the honest sentence is the weaker "strategic actors exploit whatever reachable, discoverable heterogeneity exists," not "reform creates it." Paper XVIII's laundering mechanism is the closest the series has come to a domain instance of a Layer B burden, and even there the conservation is demonstrated in a model, not the field.
A licensed Layer B instance: public-service queues. Layer B is not merely a gate no case passes; at least one governance structure supplies a genuine conservation law of the required form. For a broad class of work-conserving multiclass single-server queues, Kleinrock's conservation law fixes a traffic-weighted sum of class waiting times, Σ ρᵢ E[Wᵢ] = C, with C independent of the scheduling discipline. Prioritising one class — lowering its mean wait — therefore forces weighted waiting onto the others; the burden is conserved and merely relocated. The mapping to governance is direct: the classes are urgent versus routine cases or permit types, the server is the shared judicial, clerical, inspection, or clinical capacity, the monitored proxy is the wait for a politically salient class, the conserved burden is traffic-weighted waiting time, the relocation mechanism is scheduling priority, and the model boundary is any change to capacity, arrivals, service requirements, admission, or the measurement clock. Courts have been modelled explicitly as resource-constrained case-management queues; and the documented gaming of English NHS waiting-time targets — holding patients in ambulances outside the emergency department, cancelling unmonitored procedures during measurement windows, reclassifying recorded times — is the relocation mechanism in the field, its most revealing move being not redistribution within the queue but export of patients outside the measured queue, the governance analogue of pushing amplification beyond the certified band [IP]. Audit and Stackelberg security allocation give a second family, combining both layers: a fixed inspection or protection budget lies in a resource simplex (Layer B), while an attacker chooses a reachable, discoverable, weakly-covered target (Layer A).
These instances also show what kind of claim Layer B is. It is a subclass result, not a general property of governance: it holds where a domain exhibits identifiable stock–flow, workload, material, or resource conservation, and it is an unlicensed heuristic everywhere else. The conserved objects differ by structure — traffic-weighted waiting time in a service queue, a coverage budget in audit allocation, a revenue identity in a fiscal system under fixed targets, physical mass in material-flow regulation — and each comes with its own escape boundary (added capacity, deterrence spillovers, growth, transformation or a shifted system boundary). The transfer discipline is to name the conserved quantity and its boundary before invoking manufacture, not after.
Two cautions close the section. First, high realized harm requires no strategic adversary at all. The premium G measures advantage over a uniform baseline; under a naturally colored environment — one whose disturbance incidence is already concentrated near the response peak — realized loss can be high while the strategic premium is modest, because the danger already lives in the base measure. Reading the model as "no adversary implies safety" inverts its content [IP]. Second, discovery is the governance-specific gate that most limits Layer A in practice, and it is itself a policy variable: a manufactured vulnerability is exploited only to the extent it is legible to the strategic population, so opacity can suppress exploitation of a peak that reach and concentration would otherwise find. This cuts both ways — legibility that helps a regulator can also arm an adversary — and neither direction is modeled here.