Let Ideas Travel Farther Than Authority
Hatched by Tom Haus
Aug 17, 2026
10 min read
0 views
94%
What if the safest way to create new ideas and the safest way to deploy artificial intelligence depend on the same design principle: make connections easy in low risk spaces, but make consequences difficult to spread?
At first, these seem like unrelated concerns. One involves chief information security officers deciding where an AI model should run. The other involves a person opening a blank knowledge base and writing five notes without folders, importing old material, or imposing a rigid taxonomy.
Yet both problems revolve around the same question: What should be allowed to connect with what, and under what conditions?
A creative note system benefits from unexpected proximity. An AI system benefits from controlled separation. The apparent contradiction is the important part. If we treat every connection as either good or dangerous, we will design systems that are either sterile or reckless. The deeper skill is learning to distinguish productive adjacency from uncontrolled exposure.
That distinction may become one of the central design principles of the AI era.
The strange relationship between creativity and security
The best ideas often begin as accidents of proximity. A note about urban planning sits beside a note about memory. A passage on software architecture reminds you of how a jazz ensemble improvises. The connection is not obvious when either idea stands alone, but becomes visible when the two occupy the same mental workspace.
This is why a fresh, lightly structured note system can be so powerful. Instead of beginning with folders such as “work,” “books,” “health,” and “projects,” you begin with a handful of things that genuinely matter. You write a note, then ask: “This makes me think of what?” The structure emerges from attention rather than being imposed before attention has had a chance to work.
Nearness lowers the cost of association. When related or potentially related items are close together, the mind notices patterns it would otherwise miss. A strict filing system may keep information tidy, but it can also conceal relationships. If every idea is placed in a separate cabinet, the cabinets themselves become barriers to discovery.
AI systems create a similar abundance of proximity, but at a much greater scale. A model can connect language, code, customer behavior, internal documents, images, and operational data in seconds. It can discover relationships that no individual employee would have time to inspect.
That is the opportunity. The danger is that connection is not the same as understanding, and access is not the same as authorization.
A personal note linking an observation about economics to a memory from childhood has a small blast radius. If the connection is foolish, the cost is usually a bad idea. An enterprise AI system linking private health information to an employee evaluation, or confidential product plans to an external service, can produce legal, financial, and human harm.
The same property that generates insight, namely the ability to bring distant things together, can also erase boundaries that exist for good reasons.
Creativity needs surprising connections. Security needs meaningful boundaries. Good systems must support both without confusing one for the other.
The failure of the “open or closed” mindset
Organizations often approach AI security as if they have only two choices. They can lock the system down so tightly that it becomes nearly useless, or they can move quickly, accept uncertainty, and repair the damage later.
Neither approach is sufficient.
A completely closed AI environment may protect data, but it can also prevent experimentation. Employees will then find unofficial tools that are more convenient, creating an invisible and less governable system. A completely open environment may generate impressive demonstrations, but it turns the vendor, the model, and the user into a chain of trust that the organization may not actually understand.
The location of the model matters. Running a private model on an organization’s own infrastructure generally offers greater control over data, access, monitoring, and configuration. Using a provider’s public environment can be faster and cheaper, but it requires the organization to trust an external party with more of its information and more of its operational context.
This is not merely a technical procurement decision. It is a decision about which boundaries the organization is willing to outsource.
The same issue appears in personal knowledge management. Starting with an empty workspace and no folders can be liberating because it avoids premature categorization. But “no folders” does not mean “no structure.” The structure is carried by links, naming, context, and the user’s judgment. If a knowledge base grows without any later maintenance, it can become an undifferentiated mass in which everything is connected and nothing is useful.
In both cases, the mistake is to confuse the absence of visible structure with the absence of design. A good system may feel open to the user while relying on carefully designed constraints underneath.
Consider an airport. Passengers need freedom to move through public areas, find shops, change direction, and reach their gates. But the airport cannot treat every door, corridor, and restricted room as equally accessible. Its usability depends on openness in some zones and strict controls in others.
AI governance should work the same way. So should an individual’s knowledge system.
A model for designed adjacency
A useful framework is to divide a system into three zones: the discovery zone, the decision zone, and the consequence zone.
The discovery zone is where connections should be easy. This is where an individual can make rough notes, ask an AI system exploratory questions, compare ideas, and follow unexpected associations. The standard here is not certainty. It is generative value.
For example, a product team might let an AI assistant analyze anonymized customer feedback alongside public market research. The goal is to find themes, hypotheses, and questions. A researcher might place notes about behavioral economics beside notes about interface design. The system is deliberately permissive because the cost of being wrong is low and the benefit of noticing something new is high.
The decision zone is where suggestions are tested. Here, provenance matters. Which documents informed the output? Are the data current? Is the reasoning reproducible? Could a person challenge the recommendation? Has a relevant bias or conflict of interest been identified?
An AI generated hypothesis can enter the decision zone, but it should not arrive disguised as a fact. A note can suggest a connection, but the connection should not become a belief merely because it appears in a graph.
The consequence zone is where outputs affect people, money, rights, access, or reputation. Hiring, lending, medical triage, security controls, legal decisions, production deployments, and disclosure of confidential information belong here. In this zone, the system must become conservative. Human review, explicit authorization, audit trails, data minimization, and clear accountability are not obstacles to creativity. They are protections against the cost of being wrong.
This produces a simple rule:
Lower the friction of exploration, raise the friction of irreversible action.
Many organizations do the opposite. They make experimentation painful by requiring approval for every harmless trial, then allow an experimental model to influence real operations without adequate review. The result is both bureaucratic and unsafe.
A well designed system creates a gradient of trust. A rough association deserves less trust than a verified claim. A verified claim deserves less trust than a recommendation evaluated against policy. A recommendation deserves less trust than an action that has been reviewed and authorized.
The system should make these differences visible.
Why “security by design” resembles good note taking
Security by design means that protection is considered while a system is being created, rather than added after the system has already become difficult to change. Privacy by design applies the same logic to personal information. Anti discrimination principles require designers to consider how systems may produce unequal outcomes before those outcomes become embedded in operations.
This is more than a compliance checklist. It is a way of thinking about architecture.
When someone begins a personal knowledge system with five notes and the prompt “This makes me think of,” they are practicing a form of design by emergence. They are not pretending to know the final shape of their thinking in advance. They are creating conditions in which useful structure can reveal itself.
But emergence works best when the early materials are chosen deliberately. The five notes are not an indiscriminate data dump. They are a small, meaningful starting set. The person is reducing inherited clutter, avoiding categories that no longer fit, and giving attention a manageable field in which to operate.
That is a surprisingly good analogy for responsible AI deployment. An organization does not need to solve every possible use case before learning anything. It can begin with a bounded set of valuable experiments, using data that is appropriate for the purpose, in an environment whose risks are understood.
The goal is not to design every outcome in advance. The goal is to design the conditions under which outcomes can be explored safely.
This also explains why importing every old note can be counterproductive. Legacy information contains value, but it also contains stale assumptions, duplicated material, forgotten sensitivities, and categories created for purposes that no longer exist. Bringing all of it into a new system can reproduce old confusion under the appearance of modernization.
Organizations face the same temptation with AI. They want to connect the model to every repository immediately because more data appears to promise more intelligence. In practice, indiscriminate access often creates noise, increases exposure, and makes it impossible to determine why the system produced a particular answer.
More context is not always better context. The right context is relevant, authorized, current, and proportionate to the task.
The connection budget
One practical way to apply this framework is to think in terms of a connection budget.
Every new connection in a system creates potential value and potential risk. Linking two ideas may produce insight. Linking two databases may create a powerful capability. It may also create a new pathway for sensitive information to move, a new source of bias, or a new ambiguity about responsibility.
A connection budget asks four questions before expanding access or integration:
- What new insight or capability does this connection make possible?
- What is the worst plausible consequence if the connection is misused or misunderstood?
- Can the same value be achieved with less sensitive data, narrower permissions, or a private environment?
- What evidence would tell us that the connection is producing value rather than merely generating activity?
Imagine a customer service assistant. In its discovery zone, it may use anonymized conversation patterns and product documentation to propose improvements to frequently asked questions. In its decision zone, a support manager reviews the proposed changes and checks whether they are accurate. In its consequence zone, the assistant can draft a response, but it cannot issue a refund, alter an account, or reveal internal information without explicit authorization.
Now imagine a personal knowledge system. You may freely link a note about a book to one about a project idea. But before allowing an AI tool to summarize private journal entries, work documents, and health records together, you should ask whether the connection is necessary, whether the data remains private, and whether the resulting inference could surprise or harm you.
The budget is not a demand to avoid connections. It is a demand to spend them consciously.
Key Takeaways
-
Separate discovery from consequence. Use open, flexible environments for brainstorming and pattern finding, but introduce stronger controls before an output informs a consequential decision or takes an external action.
-
Start with a small, meaningful data set. Five carefully chosen notes are often more useful than importing an entire archive. In AI projects, begin with bounded data and a clear purpose rather than granting universal access.
-
Treat proximity as a design resource. Put potentially related ideas, documents, and signals close enough to be compared. Then preserve boundaries around information that should not be combined.
-
Assign trust in stages. An idea, a generated answer, a verified claim, a recommendation, and an authorized action are not equivalent. Label them differently and require increasing evidence as consequences rise.
-
Make the costly step deliberate. Privacy review, security review, human approval, and auditability should be concentrated at the point where an exploratory connection could become an irreversible action.
The future of intelligent systems will not be determined by whether we choose openness or control. It will be determined by whether we can place each kind of openness in the right location.
A mind needs room to associate. An organization needs boundaries that survive association. The answer is not to prevent systems from connecting things, because connection is where learning and innovation begin. The answer is to build systems in which connections can be explored without automatically becoming permissions, decisions, or actions.
The most mature design principle may therefore be this: let ideas travel farther than authority.
A thought should be allowed to cross boundaries while it is still a question. A fact should cross only when its source and purpose are clear. An action should cross only when someone can explain who authorized it, who bears responsibility, and what happens if it is wrong.
When we design for that progression, security stops being the enemy of creativity. It becomes the architecture that allows creativity to move freely without taking everything else with it.
Sources
Hatch New Ideas with Glasp AI 🐣
Glasp AI allows you to hatch new ideas based on your curated content. Let's curate and create with Glasp AI :)
Start Hatching 🐣