The Next
Evolution Review
The distance between proven and permitted
A naval trial put a new atomic clock to sea on one programme's authority. A brain scanner built from related physics has been in research use since 2021 and is still waiting for approval. Twelve cases, one question: who holds the authority to say yes?
What this is, and how to read it
The Next Evolution publishes several times a week. That cadence has a cost: an argument that takes six pieces to build is never visible in any one of them. Every two months the Review takes one question, sets a substantive piece against it, and gathers the writing that approaches the question from other directions.
Nothing here is a reprint. Where an argument first appeared in shorter form on the Substack, the fact box at the foot of the article names the original.
Reading it
The findings are on page and the cover story on page . Each article opens with a three-line summary and closes with a fact box.
On the evidence
Factual claims carry numbered source notes in each article's fact box, pointing to the primary source. Judgements are marked as judgements. Where the evidence stops, the text says so. How the cases were chosen, how verdicts and confidence are assigned, and what the author declares are set out on page .
Neil Catton
Independent technology strategist.
Fractional CTO and CIO work, board briefings, AI readiness reviews, technology
due diligence and programme recovery.
The Next Evolution
The Cognitive Crucible
The Shadow System
Working as Designed
writing.neilcatton.com
neilcatton.com
Version 1.0, October 2026. Later revisions are dated here and listed on the corrections page.
Catton, N. (2026). The distance between proven and permitted. The Next Evolution Review, Issue 1, October–November 2026.
Quote it, cite it, send it on. Attribution is the only condition.
When something that works does not reach the people it was built for, how many people had to say yes, and who is answerable for the time they took?
The distance between proven and permitted
Five findings
Each finding names the page where the evidence is.
Six technologies, and who has to agree
Each row is one case from the cover story. Each square is an authority that must agree before the technology can reach people.
Where the sections fit
The pattern was in the archive
before it was in my head
Four times between July and September I wrote a version of the same article without noticing. In July it was self-healing concrete, which has been through full-scale trials since 2011 and is still absent from most specifications. Later that month it was software that reads brain scans in seconds, validated on tens of thousands of real studies and still some distance from routine care. In August it was a drug for a fatal lung disease, taken from target to candidate in eighteen months and then handed to a trial system that runs at the speed it always has. In September it was an optical atomic clock that went to sea on a naval test submarine, set against a brain scanner that shares its physics, in research use since 2021 and still waiting for approval.
I noticed on the fourth. The record I keep of published work flagged the overlap and asked what separated the new piece from three older ones. I did not have a good answer, which is usually the sign that something needs writing.
The answer, when it came, was that I had written one argument four times, in twelve hundred words each, which is too little room to make it. Each piece could show that the technology worked and an institution stood in the way. None could ask why the obstruction takes the shape it does, or what would have to change for it not to.
That is why this exists.
What a periodical is for
A newsletter suits one idea at a time. It suits an argument that needs six examples, two counter-examples and a structural claim underneath them far less well, because by the fourth example the reader has had three emails across five weeks and no reason to hold them together.
A periodical has room for it, and it imposes a discipline a stream does not: you decide in advance what the next two months are about. That decision is most of the value. The writing between issues gets aimed, and an argument gets built on purpose rather than assembled afterwards from whatever happened to appear.
The question
When something that demonstrably works fails to reach the people it was meant for, we tend to call the problem adoption, or funding, or culture, or readiness. Those words point at the receiving institution and suggest it should try harder. In several of the cases here, the delay is the sum of decisions taken by several bodies.
Somebody, or more often a set of somebodies, has to say yes. The useful question is how many separate people must agree, whether any of them is answerable for the consequence of not deciding, and what happens to the person waiting while they take their time.
Count the signatures. It is a simple test, and it explains more of what I have written this year than I expected. The diagrams and the ledger that follow are there to test it, including against the cases where it fails.
What I am not claiming
One version of this argument says the technology is always ready and institutions are always the problem. I do not hold it, and three of the twelve cases here do not support it at all. Small modular reactors are held up by engineering and cost. Precision farming was designed for a farm most farmers do not have. Cyber protection is deployed and working, and reaches people according to who employs them.
The argument holds only where the thing works. Telling those cases apart from the others is most of the work, which is why the ledger at the back grades the cases and publishes the ones where the argument fails.
How this issue is built
Each piece is summarised in three lines at its head and sourced at its foot. The cases come from my own writing rather than a survey, and the method page says what that means for the conclusions. The corrections page already has one entry.
The last page carries the question Issue Two is built on. It was chosen the same way this one was, by looking at what I kept writing without meaning to.
The distance between
proven and permitted
Two machines rest on related physics. One is an optical atomic clock. In 2025 it went to sea aboard XCal, the Royal Navy's uncrewed test submarine, in a trial of navigation that does not depend on satellites.1 The other is a brain scanner. Its sensors, optically pumped magnetometers, came out of work to make atomic clocks smaller, and they read the brain's faint magnetic fields from a helmet a child can wear while moving.2 A system of this kind was installed in a paediatric epilepsy diagnostic suite in 2021.3 In July 2026 the researchers behind the technology said it is still not used clinically, because it needs medical device approval, which they hope to have in 2027.2
These are different devices, so the comparison is limited to one point: how each was allowed to be tried. The navy tested its clock at sea, on an operational testbed, on the authority of the programme that runs the submarine. The scanner can be used in research with children who have epilepsy, but it cannot inform a clinical decision about them until a regulator certifies it. After that it needs an assessment of whether the evidence justifies the cost, a commissioning route that decides whether it is bought, and a trust budget that decides whether it is bought here.
Each of those four bodies exists for a sound reason, and each has to agree before the next one acts.
Where a technology works and still does not reach people, the obstruction is usually how many bodies must agree. Ask how many there are, and whether any of them pays a price for taking its time.
Three more cases
Concrete that repairs itself
Self-healing concrete, in full-scale tests since 20114 and now sold commercially,5 is rarely specified. Public tenders are scored mainly on the cost of building, so a lower maintenance bill forty years later has nowhere to be counted, even though government guidance asks for whole-life costing.6 Page sets out the mechanism.
Software that reads a brain scan
A University of Michigan model that reads brain MRIs, validated in 2026 on more than 30,000 real studies,7 is not yet in routine care. Its route through the NHS runs through the same four bodies as the scanner, and nobody publishes how long the four take together. This case is still a forecast (page ).
A drug found in eighteen months
Insilico Medicine found rentosertib, a drug for idiopathic pulmonary fibrosis, and took it from target to preclinical candidate in about eighteen months;8 a phase III trial began in China in July 2026.9 Formal medicines regulation in the UK dates from the response to thalidomide in the 1960s,12 and the trial system is slow on purpose. Faster discovery has moved the wait from the laboratory to the clinic, where the people waiting know the drug's name (page ).
One
A single programme holding the budget, the mandate and the risk. The naval clock trial.
Four
Regulator, evidence assessor, commissioner, local budget holder. The scanner, and the MRI reader behind it.
Nobody
The saving arrives decades after the decision and has no line on the tender. The concrete.
Three cases the count does not explain
Small modular reactors are held back by engineering and unit cost. China's Linglong One, the first land-based commercial unit, was due to begin commercial operation in May 2025 and had not been confirmed as operating by early October 2026.10 Precision farming has been taken up more slowly than its dealers forecast for twenty-five years,11 because it was built for large, uniform farms. Cyber protection works and is widely deployed, and small organisations go without it because of price. Pages and take these in turn.
Six cases, one table
| Case | Status, September 2026 | What is holding it | Shape |
|---|---|---|---|
| Optical atomic clock, naval trial | Trialled at sea, 20251 | Nothing further for a trial. One programme, one authority. | Short |
| OPM-MEG brain scanner | Research use since 2021; approval hoped for 20272,3 | Device approval first, then three more authorities. | Long |
| Self-healing concrete | Full-scale tests from 2011; on the market4,5 | A tender scored on build price. | Absent |
| AI reading of brain MRI | Validated at one health system, 2026; not in routine care7 | The four approvals ahead of it. | Long, ahead |
| AI-discovered lung drug | Phase III from July 20268,9 | Trial and approval, deliberately slow. | Relocated |
| Small modular reactors | First commercial unit behind schedule10 | Engineering and unit economics. | Not permission |
Why nobody fixes it
Each body in these chains was added for a reason. Medical devices and medicines are regulated because unregulated ones harmed people, and the UK's own review of that history reads as a list of specific injuries.12 An evidence body exists because health systems bought expensive things that did not work. A local budget holder exists because central decisions did not fit local conditions.
What none of them records is the length of the whole. A risk register records what happens if a decision goes wrong: financial exposure, regulatory breach, reputational damage, safety. It has no entry for what happens if the decision is not made this quarter. A committee that defers is minuted as cautious. A committee that approves and is wrong is minuted as having failed.
So the delay has no owner. Everyone in the chain asks for the evidence their own remit requires, and the total belongs to none of them.
The risk of yes
Financial exposure. Regulatory breach. Clinical safety. Reputation. Each appears on a register, has an owner, and is reviewed on a cycle.
The cost of not yet
The scans not read. The maintenance bill in 2060. The diagnosis that arrived late. None has an owner, a register entry or a review date.
Who waits
In each case the person who waits is outside the room. Whoever maintains a bridge in thirty years is not consulted on its specification. Whoever needs a scan in a district general hospital is not represented at the commissioning meeting. Whoever has the lung disease is not a party to the trial protocol. None of them can see the process that is making them wait.
A count on paper
Adding a new approval step to fix a slow chain would lengthen it. What is proposed here is smaller. For any technology that works and has not reached people, write down how many separate bodies must agree, what each is protecting, and whether any has been asked what the delay costs. At present the only figure anyone produces is the risk of moving, and the cost of standing still is treated as zero. The five questions on page set this out.
The navy put its clock to sea on the authority of one programme. The scanner has been in research use for five years and is waiting on the first of four approvals. Both systems are working as designed. Which of the four bodies is answerable for the five years?
- Infleqtion, "Infleqtion and Royal Navy demonstrate world's first quantum optical clock on underwater autonomous submarine", October 2025. infleqtion.com
- Wellcome, "OPM-MEG: a revolution in brain imaging technology", 7 July 2026. wellcome.org
- UCL News, "Wearable brain scanner to facilitate testing for children with epilepsy", October 2021. ucl.ac.uk
- Ingenia, "Self-healing concrete", March 2011 (announces full-scale outdoor testing from 2011). ingenia.org.uk
- NWO, "Self-healing concrete", November 2021 (Basilisk products on the market). nwo.nl
- Cabinet Office, The Construction Playbook, version 1.1, September 2022 (whole-life value and should-cost models). gov.uk
- Michigan Medicine, "An AI model that can read and diagnose a brain MRI in seconds", February 2026; published in Nature Biomedical Engineering. michiganmedicine.org
- Ren F. et al., "A small-molecule TNIK inhibitor targets fibrosis in preclinical and clinical models", Nature Biotechnology, online 8 March 2024.
- Insilico Medicine, Nature Medicine phase IIa publication, June 2025; phase III initiation, 7 July 2026. insilico.com
- NucNet, SMR database entry for ACP100 (Linglong One), accessed September 2026. smr.nucnet.org; World Nuclear News, 8 January 2026.
- Malone T., Fiechter C. et al., "Is precision agriculture technology adoption persistently overestimated?", Agribusiness, 2026. doi:10.1002/agr.70085
- Independent Medicines and Medical Devices Safety Review (Cumberlege), Annex H, "History of regulation", 2020. immdsreview.org.uk
| Fuller pieces | The same physics, two speeds (7 Sep 2026) · The Science Is Not the Problem (13 Jul) · While patients wait (26 Jul) · The bottleneck moved (17 Aug) · Too Cheap to Meter, Too Slow to Build (6 Jul) · The Land the Data Missed (5 Aug). writing.neilcatton.com |
Three shapes of a permission chain
Chains obstruct in three ways, and each needs a different remedy.
Remedy: none needed for speed. Whether that concentration of authority is acceptable is a separate question.
Remedy: record the total, so the sum of four reasonable requests has an owner and a date. Every link stays.
Remedy: give the form a place for the value it cannot currently record, and name who speaks for it.
Health & care technology
Health has more separate bodies that must agree than any other sector here, each added after something went wrong. Two pieces: software validated at scale that now faces that chain, and a drug found quickly that must still be proved slowly.
The scan that works in the study
A brain scan taken in a district general hospital joins a queue, and a radiologist works through the queue. The number of trained people, and how long each image takes, sets the pace for everything behind it.
In February 2026 researchers at the University of Michigan published a model, Prima, which interprets a brain MRI within seconds. It was trained on more than 200,000 past studies and tested on more than 30,000 over a year, with accuracy of up to 97.5% across more than fifty diagnoses.1 It is not yet in routine clinical care.
Four approvals, each with a reason
Software that informs a diagnosis has to be certified as a medical device. That requirement exists because unregulated devices caused harm; the UK's review of medicines and device safety sets out how each layer of regulation followed a specific failure.2
It then has to be assessed for whether the evidence justifies the cost, because a health system with a fixed budget that buys things which do not work is taking money from things that do. It then needs a commissioning route: somebody has to decide that this is something the service buys, under which tariff, counted how. Finally an individual trust, with its own budget and its own list of pressures, has to decide that this is what the money goes on this year.
Each of the four is run by people acting reasonably. The likely result is that the capability reaches teaching hospitals first, where research budgets and academic partnerships can absorb the early cost, and reaches everywhere else over a period nobody has estimated in public.
Adoption
The word implies an institution choosing not to take something up. Here nobody refuses; four bodies each ask for what their remit requires, and nobody adds up the total.
Who waits
NHS England's own waiting-list breakdowns show that patients in the poorest communities are more likely than any other group to wait longer than 18 weeks for treatment.3 They are also the people least able to travel to a hospital that has a new capability, take time off for an appointment two counties away, or pay to go private while they wait.
A diagnosis that arrives late is often a different diagnosis. Described as a productivity tool, the software's slow rollout is a missed saving. Described as a change in who gets diagnosed in time, it decides which patients benefit first, and nobody records that decision.
How long
I have found no published figure for the average time between a diagnostic technology being validated at scale and being available across the service. The regulator can state its own timescales, and so can the evidence assessor and the commissioner. No single body is responsible for the total, which is probably why nobody has published one.
Simpler things meet the same problem. At a health innovation showcase, a medical student presented a single kit for a particular procedure. They had watched clinical teams finish that procedure and then account for every item used, and sometimes fail to. The kit released each stage only once the previous stage's components had been used, and finished as one sealed, disposable container. When I asked afterwards how deployment was going, the answer was that it was not: procurement raised one blocker, clinical teams another, and there was no single route into practice.
A record of the chain
One document per technology would be enough: the bodies that must agree, the question each is answering, the evidence each has asked for, and the date of each request, kept where a board would see it. It would put names and dates against a wait that currently belongs to nobody.
| The case | Prima, a brain-MRI model from the University of Michigan (2026) |
| Status, Sept 2026 | Validated on 30,000+ studies; not in routine clinical care |
| Who decides next | Device regulator, evidence assessor, commissioner, trust budget holder |
| Verdict | Partly explains Confidence: low. The delay is a forecast. |
- Michigan Medicine, "An AI model that can read and diagnose a brain MRI in seconds", February 2026; Nature Biomedical Engineering.
- Independent Medicines and Medical Devices Safety Review, Annex H, "History of regulation", 2020.
- NHS England, "NHS publishes waiting list breakdowns to tackle health inequalities", July 2025. england.nhs.uk
While patients wait, 26 July 2026 · The same physics, two speeds, 7 September 2026. writing.neilcatton.com
The bottleneck moved
Insilico Medicine took rentosertib, a candidate for idiopathic pulmonary fibrosis, from target discovery to preclinical candidate in roughly eighteen months.1 The company puts conventional early-stage discovery at two and a half to four years.2
What did not change is everything after discovery. A candidate has to be shown to be safe, then shown to work in people against a comparator at a scale that makes the result mean something, then accepted by a regulator. Rentosertib reported phase IIa results in Nature Medicine in June 2025, and a phase III trial across 47 centres in China began in July 2026.2 None of those stages has been compressed, and nobody has seriously proposed compressing them.
The same pattern turns up well outside medicine. In one part of UK local government, I watched contact centres move residents onto digital channels. Requests arrived faster and in greater volume, but the teams who had to act on them had the same number of people as before. Waiting times did not improve; the backlog grew further down the line.
Slow on purpose
In the UK, a Committee on Safety of Drugs was set up in 1963 in response to thalidomide, and the Medicines Act 1968 followed; the regulation of medical devices developed separately and later.3 Pharmaceutical regulation is, more than almost any body of rules, a record of specific disasters. Approval on weaker evidence would mean accepting the risk of repeating one of them.
The trial system should not be sped up
Accelerating one half of a two-stage process still has a consequence. The total wait did not shorten; it moved to a place where the person waiting knows the drug exists.
Waiting for a named drug
Before, a person with a fatal lung disease was waiting for something that had not been found. Now the same person is waiting for a named compound, in a trial with a protocol and a timetable, which may or may not include them depending on their stage and where they live. They can search for the drug by name and read eligibility criteria that may exclude them.
A wait with a visible end is experienced differently from one without, and trial teams now deal with patients who know exactly what they are waiting for. Nothing in the regulatory process was designed with that in mind.
Where the pressure will land
It will land on the trial system, as demand for expanded access, compassionate use, adaptive protocols and other routes that let somebody take a drug before the evidence is complete. Some of those routes are sound and some lead back towards the failures regulation exists to prevent. Telling them apart will be one of the main regulatory questions of the next few years, and it will be decided under pressure from people with a named disease.
What counting shows here
There are many signatures in this chain and each is doing its job, so counting them will not shorten the wait. What the count does show is a change in the problem. The delay used to be one part of a mostly scientific problem, and now it is most of what remains.
| The case | Rentosertib (ISM001-055), Insilico Medicine, for idiopathic pulmonary fibrosis |
| Status, Sept 2026 | Phase III began July 2026 (China, 47 centres) |
| Who decides next | Trial outcome, then medicines regulators |
| Verdict | Partly explains Confidence: moderate. |
- Ren F. et al., Nature Biotechnology, online 8 March 2024 ("roughly 18 months from target discovery to preclinical candidate nomination").
- Insilico Medicine, phase IIa publication announcement, June 2025; phase III initiation, 7 July 2026. insilico.com
- Independent Medicines and Medical Devices Safety Review, Annex H, "History of regulation", 2020.
The bottleneck moved, 17 August 2026 · The Machine That Designs Medicines, 19 April 2026. writing.neilcatton.com
Science & emerging technology
Self-healing concrete, where counting the signatures explains the delay, and two technologies where it explains nothing.
The material that was never on the form
The mechanism sounds invented. Bacteria are mixed into the concrete in a dormant state, along with a nutrient. When a crack opens and water gets in, the bacteria wake, feed, and produce limestone that fills the crack from inside.
Full-scale outdoor testing began in 2011,1 and Basilisk, the spin-out that grew from the Delft work, has taken self-healing products to market.2 The engineering is understood, and the material still appears in few specifications.
No one says no
Construction procurement is decided on the price of building the thing. That is what the tender is scored on and what the person deciding is accountable for. Self-healing concrete costs more to lay. Over a long maintenance life it can cost less in total, because the repairs it avoids are expensive and disruptive. But the maintenance budget decades from now is not a line on today's tender, so a material that may be cheaper overall is scored as dearer, and it rarely wins.
A missing field
Here the chain has no links and still obstructs. There is no refusal to appeal, only a form with no place to record the saving.
Whole-life costing exists, and rarely wins
Government guidance already asks for this. The Construction Playbook tells public buyers to focus on whole-life value and to build should-cost models of whole-life costs.3 The pattern persists anyway.
Whole-life costing asks the person scoring a tender to estimate costs over a period longer than their tenure, the political cycle and the warranty. It needs assumptions about discount rates, usage, climate and maintenance, each arguable and each likely to be argued by a losing bidder. A scorer who relies on build price is easy to defend. One who relies on a forty-year projection is exposed.
In the public-sector bids I have written and responded to as a consultant, questions about whole-life cost beyond the contract term have been rare. The contract length sets the horizon: it is the only period a bidder can answer for, because what happens after may be delivered by someone else. The buyer seldom asks either, so neither side is accountable for the cost that arrives later.
Who pays
The maintenance cost does not vanish. It passes, in full, to whoever holds the asset in twenty, thirty and forty years, often a public body with a maintenance backlog it did not create. The person who takes the decision and the body that pays for it may never deal with each other.
The question for a procurement
A saving that arrives after the decision-maker has gone, falls to another organisation, or cannot be shown without a projection someone could attack never gets weighed at all. So ask of any procurement who must sign, what kinds of value the tender can record, and who in the process speaks for the maintenance budget in 2060.
| The case | Bacteria-based self-healing concrete (TU Delft; Basilisk) |
| Status, Sept 2026 | Commercially available; rarely specified |
| Who decides | Tender scorers, on build price |
| Verdict | Explains Confidence: low. No source measures why it is rarely specified; the reason given is the author's reading. |
- Ingenia, "Self-healing concrete", March 2011. ingenia.org.uk
- NWO, "Self-healing concrete", November 2021. nwo.nl
- Cabinet Office, The Construction Playbook, version 1.1, September 2022. gov.uk
The Science Is Not the Problem, 13 July 2026 · Good Enough for Now, 25 June 2026. writing.neilcatton.com
Two technologies nobody is blocking
Say that working technologies are held up by institutional permission, and the claim is useful at once to anyone selling something that does not work yet and would prefer nobody checked.
Small modular reactors are the clearest current example. The promise is to build reactors in a factory, standardise the design and bring the cost down through volume. If it worked it would matter a great deal, because the options for firm low-carbon power at scale are few and all difficult.
What has been delivered
The first land-based commercial unit, China's Linglong One, was planned to enter commercial operation in May 2025. In January 2026 the target was reported as the first half of 2026,1 and at the start of October I could find no confirmation that it had begun. The cost case depends on manufacturing volumes that cannot exist until enough units are ordered to justify the factory, while the orders depend on the costs, which depend on the volumes. Nobody has yet shown how to break that circle.
None of this makes the technology fraudulent. It is unproven in the sense that matters commercially: the thing the whole case rests on has not yet been shown.
Is it proven?
Counting signatures helps only where a technology already works for people other than those who built it. Where that has not been shown, start there.
Regulatory delay is real, and secondary
Nuclear regulation is slow and evidence-heavy, and a regime designed around one-off gigawatt plants may fit a repeated factory-built unit badly. Reforming it is a legitimate policy question, and a separate one from what is holding these reactors back. If every design in the queue were approved tomorrow, the first units would still face the engineering, supply-chain and first-of-a-kind problems that no regulator creates. Blaming the regulator moves a commercial problem into politics.
Built for another farm
For twenty-five years, the dealers who sell precision agriculture have overestimated how widely farmers would take it up. A 2026 study of the Purdue dealership survey, covering 26 technologies from 2000 to 2025, found the overestimation persistent, and widening in the early 2020s as adoption of several tools flattened.2
The instruments work. They were designed for a large, uniform, well-capitalised farm, and most farms are not like that. No regulator stood in the way. The product was wrong for most of the people it was sold to.
I once represented the UK at a European committee discussing a proposed personal “passport” for lifelong learning: one record of a person's qualifications, certifications, work history and references, which any employer could see with permission. The aim was to make moving and hiring people across Europe far simpler. It returned to the committee each year and never progressed beyond discussion. As far as I could see, it had been designed around employers and institutions, with little thought for how an individual would ever use it.
How to tell the cases apart
Ask whether the thing has worked, in conditions like those it would meet in service, for someone other than the people who built it. Self-healing concrete passes. The brain scanner passes in research use. Small modular reactors do not yet pass, and neither does precision farming for the typical farm.
The first question to ask of any stalled technology is whether it is any good, asked by someone with no stake in the answer. By the time a technology reaches an approval process, that question has often been skipped.
| The cases | Small modular reactors; precision agriculture |
| Status, Sept 2026 | First commercial SMR behind schedule; precision-ag adoption below dealer forecasts |
| What holds them | Engineering and unit economics; design fit |
| Verdict | Does not explain Confidence: moderate. The delays are sourced; their causes are the author's reading. |
- NucNet, SMR database entry for ACP100 (Linglong One), accessed September 2026. smr.nucnet.org; World Nuclear News, "Chinese SMR completes non-nuclear steam start-up test", 8 January 2026.
- Malone T., Fiechter C. et al., "Is precision agriculture technology adoption persistently overestimated?", Agribusiness, 2026. doi:10.1002/agr.70085
Too Cheap to Meter, Too Slow to Build, 6 July 2026 · The Land the Data Missed, 5 August 2026. writing.neilcatton.com
Governance & accountability
Registers price the risk of acting and record nothing about the cost of waiting. The second piece looks at a process built to produce a record rather than a decision.
Nobody owns the delay
Look at what a risk register contains: financial exposure, regulatory breach, operational failure, reputational damage, safety. Each entry has an owner, a score, a mitigation and a review date, and the discipline behind it is real. A well-kept register is one of the more useful tools in corporate governance.
Now look for the entry that records what it costs the organisation, or anyone else, if a decision is taken in March instead of January. The standard categories have no place for it.
I was once responsible for part of the reporting to a risk and audit committee. The same report came back each month with its dates moved further out, and nobody asked what the delay was costing the organisation or might cost later. I inherited some of the consequences: deferred decisions that had become problems of their own. The cost was the work stopped or postponed to deal with them, and nobody measured it.
The asymmetry
This follows from how accountability is built. A committee that approves something which then fails has made an identifiable decision with an identifiable outcome: a minute, a date, a set of names. The failure attaches. A committee that defers, asks for more evidence or refers the matter elsewhere has also decided, but it reads as diligence. If the deferral cost something, the cost is diffuse, arrives later and usually falls on someone outside the organisation.
So the two options are unequal, and nobody in the chain has to be timid or self-interested for the whole to run slow. Everyone can act in good faith and the outcome is still set by the shape of the accountability.
Deferral goes unrecorded as a decision
Approving carries a named owner and a reviewable outcome. Waiting carries neither, so the register tilts every close call towards waiting.
Every department did its job
There is a failure pattern in which every part of an organisation does its job correctly and the outcome is still wrong, because the gap that produced it was on nobody's map. Delay is the clearest example. The regulator answers a regulatory question in the time its process takes. The evidence body answers an evidence question, the commissioner a commissioning question, the trust a budget question. Every authority in a chain can account for its own timescale. None is asked for the sum.
Asking each body to go faster leaves the total unowned. Making the total somebody's responsibility is harder, because the aggregate crosses the boundary of every organisation involved, and there is no obvious candidate.
One sentence in the minute
The usual answer to a governance gap is a new governance artefact, which usually lengthens the chain. A narrower step would not: for any decision a board defers, record beside the deferral what exactly is being waited for, and what the delay costs and to whom.
Most of the time the cost will be small and the pause sensible, and writing that down takes a minute. The value is in the cases where the answer is uncomfortable, where writing it down turns a diffuse condition into a decision with an author.
Whether it would change outcomes is untested. The present arrangement, in which the risk of acting is quantified and the cost of waiting is not recorded at all, has rarely been examined as a choice. Would your board know what its last deferral cost, and who paid?
| The piece | Argument about governance mechanism; not graded as a case |
| Evidence | Author's judgement. No external figures are cited. |
| Verdict | Proposes the mechanism the ledger tests |
No external sources: this piece is argument.
Every Department Did Its Job, 1 May 2026 · The Board That Didn't Understand What It Had Approved, 10 June 2026 · It can be managed, 17 July 2026. writing.neilcatton.com
The permission that was never going to be given
A consultation that draws few responses leaves the body running it with a convenient explanation: apathy. Apathy belongs to the public rather than the process, and it implies the remedy is better communication.
A more likely reason is that nothing changed. Most consultations are run politely, and responses are read, coded and summarised in an annex. But where the decision has already been made, and the consultation is the stage that has to be completed before it can be announced, people can tell, and giving up is a rational response.
I have responded to local consultations where the framing of the questions made it clear the decision had already been made, and I responded anyway on the points I thought needed challenging. On one proposal to build a large warehouse, the published results showed only a handful of responses from a community of thousands who had been asked. A number like that tells people responding is pointless, and the decision then goes through by default because almost nobody objected.
What the process is for
A consultation has to be run before some decisions can be taken. If it is not run, the decision can be challenged. If it is run and the record shows responses were received and considered, the decision is defensible. The process is therefore tuned to produce the record, and change is optional.
You can see it in the design. Questions are often framed after the options have been narrowed. The timetable is often set by something else. The way a response could change the outcome, as distinct from being noted, is seldom written down.
Ask what would have to be said to change the answer
A consultation that can name the response that would alter the decision is still open. One that cannot is collecting a record.
A signature that cannot say no
In most of the cases in this issue someone waits for permission that could be given. Consultation is a stage that is real and visible and cannot change the result, so each signature also has to be attached to a decision that could go either way. A chain of four live decisions is slow. A chain of three live decisions and one ceremonial one is slow and dishonest, and the dishonest link makes people outside less willing to engage with the other three.
The cost that is never counted
Consultations that change nothing compound. Each one reduces the number of people who will respond to the next, until the response comes mainly from those with a professional reason to reply: trade bodies, campaign groups, organisations with a paid policy function. The individual with direct experience, whose account is the most useful and available nowhere else, has left. The body running the process rarely notices, because response rates are watched in total and their make-up is not.
Saying which kind it is
There are two legitimate processes. One says: this decision is taken, we are telling you first, here is how to prepare. The other says: this decision is open, here is what could change it, and here is who decides. The damage comes from running the first while describing it as the second.
| The case | Public consultation as a stage of permission |
| Evidence | Author's judgement from published pieces; no external figures cited |
| Verdict | Runs the other way Confidence: low. No external evidence is cited; this is argument. |
No external sources: this piece is argument.
The consultation that changed nothing, 26 June 2026 · The Feedback Loop That Actually Worked, 31 July 2026. writing.neilcatton.com
Security & cybercrime
The standards exist, the milestones are published and the work is understood, and the decision still waits, because the harm sits in the future and the cost sits in this year's budget. The second piece is a case permission does not explain.
They already have it
An adversary who copies encrypted traffic today cannot read it. The copy costs little to keep, and the bet is that one day the mathematics protecting it will give way. Then all of it can be read at once, including what was sensitive when it was sent and still is.
For a well-resourced actor this is cheap against the possible return, and the prudent assumption is that it is happening to anything worth collecting.
The replacement standards, cryptography designed to survive a quantum computer, were published by the US National Institute of Standards and Technology in August 2024.1 In March 2025 the UK's National Cyber Security Centre set out milestones: by 2028, define goals and complete discovery and assessment; by 2031, carry out the highest-priority migrations; by 2035, complete migration.2
In the sectors I work with, much of the data being held matters for decades: health records, insurance policies, mortgages, criminal convictions. The conversations I have about protecting it tend to be about current encryption and current standards. I have rarely heard anyone ask how they are preparing for post-quantum encryption.
Why the decision waits
No regulator is withholding approval here and no commissioner is failing to find a route. The decision sits inside the organisation and can be taken by people already in the building.
It goes untaken because of how the harm is shaped. The cost of migration is large, immediate and lands in a named budget. The harm it prevents is uncertain in timing, falls in some later year, and will be felt by whoever holds the role then. A finance director weighing that against eleven other calls on the same money is reading the incentives in front of them accurately, and deferring is a reasonable response to them.
Cost now, harm later
A breach that migration prevents will never be credited to the migration, because an attack that does not happen leaves no evidence.
Discovery is the first milestone
The NCSC is explicit that migration starts with understanding your current estate: identifying key services and applications, and recording the data you hold, how long it needs to stay confidential, and its value to an adversary.2 That work is comparatively cheap and useful for other purposes.
It also puts the exposure on record. Once the estate is understood, deferral becomes a documented acceptance of a specific risk. Some reluctance to start is about capacity. Some of it is that not knowing is more comfortable, and current governance rewards the comfort.
Where the human consequence sits
Much of what is worth storing for a decade is about people: medical records, legal matters, communications, financial histories, casework of every kind. A person whose records are collected today cannot know it and cannot withdraw them. They carry the risk, and nobody at the budget meeting where migration is deferred another year speaks for them.
When
Nobody can say when the mathematics gives way, and credible estimates vary widely. That uncertainty is often offered as a reason to wait. It is a better reason to start, because the collecting is happening now whatever the date turns out to be, and the NCSC's own timetable runs to 2035.
| The case | Post-quantum cryptography migration |
| Status, Sept 2026 | Standards final (2024); UK milestones 2028 / 2031 / 2035 |
| Who decides | The organisation itself, usually its finance and risk owners |
| Verdict | Runs the other way Confidence: moderate. Standards and milestones are sourced; the reason for deferral is the author's reading. |
- NIST, "NIST releases first 3 finalized post-quantum encryption standards" (FIPS 203, 204, 205), August 2024. nist.gov
- National Cyber Security Centre, "Timelines for migration to post-quantum cryptography", 20 March 2025. ncsc.gov.uk
They Already Have It, 20 July 2026 · The Error is the Point, 24 May 2026. writing.neilcatton.com
When the postcode decides your protection
A small business I know of found fraud on one of its accounts. After a lot of investigation of their own, the owners traced it to an old account nobody used any more and closed it, by which time the criminals had moved into other systems. Sorting it out with the banks and other institutions took weeks. Spotting it, reporting it, responding and locking everything down afterwards were all left to them.
Inside a large company, monitoring might have flagged the dormant account, detection might have noticed the unusual activity, and a response team could have acted within the hour. That protection is bought, and its quality tracks what the organisation spends. Whether a given person in this country is protected against the most common digital crime depends heavily on who employs them.
The population without it
The government's own survey found that 43% of UK businesses had a cyber security breach or attack in the preceding year, and that phishing was by far the most common, reported by 38% of businesses.1 The same survey finds formal cyber measures, from risk assessments to insurance, becoming less common the smaller the organisation.1 Sole traders, freelancers, small charities and single-handed practices meet the most common attack largely on their own.
The advice available to them is technically correct and of little practical use: check the sender, look for the signs, do not click the link. It hands the whole burden of defence to the least-resourced party and calls it personal responsibility, at a time when attacks are good enough to catch trained staff inside protected environments.
Do by hand, alone, what enterprises do with systems
Security guidance for individuals is a description of what enterprise security systems do, rewritten as instructions for a person who is also trying to run a business.
A market outcome
Nobody here is waiting for a regulator. The technology works, it is sold commercially and it is deployed at scale. The market has settled who gets it, by ability to pay rather than by exposure to harm. Counting signatures explains nothing, and the ledger records that.
That is a legitimate way to distribute many things. It is an odd way to distribute protection against crime, which is otherwise treated as something provided regardless of means. Nobody decided that digital crime should be the exception. It happened because the defence turned out to be a product rather than a service.
When it fails
A large organisation that is defrauded has a recovery function, lawyers, an insurer and a relationship with its bank. A sole trader has a customer services line and a burden of proof. The party least protected at the start is also least equipped to recover, and the recovery process was built around institutional liability.
So protection against a common crime is distributed by employer, and the people with the most exposure per pound of turnover carry it alone. Who, if anyone, should provide that protection for the smallest businesses?
| The case | Cyber protection for the smallest organisations |
| Status, Sept 2026 | Protection deployed at scale; distributed by ability to pay |
| Who decides | The market |
| Verdict | Does not explain Confidence: high. The survey figures are direct. |
- Department for Science, Innovation and Technology, Cyber security breaches survey 2025/2026, published 30 April 2026. gov.uk
When the postcode decides your protection, 3 September 2026 · It Cannot Automate Trust, 8 May 2026. writing.neilcatton.com
Human agency & attention
Here nobody is waiting for a yes. The yes was taken without being asked for, and there is no practical way to withdraw it.
Permanent, portable, wrong
Consider Sam, who paid three bills late during a year of illness and spent several evenings searching about the condition. Sam's profile holds a record of lateness and a record of searching. It does not hold the illness, because the circumstance was never collected.
The profile was assembled by parties Sam never dealt with and is held for purposes Sam was not told about. Described that way it sounds like a scandal. Described the way the industry describes it, it sounds like an enrichment layer, which is one reason the debate has gone nowhere.
The deeper problem is a category error built into the design. A trace of behaviour records what someone did in a particular set of circumstances. A profile treats it as a description of what someone is, which does not follow.
Where it is used
These records travel. They feed credit decisions, employment screening, insurance pricing, tenancy referencing and a widening set of automated assessments in which the organisation has bought a score rather than looked at a person. The person assessed is not usually told which score was used, by whom, or on what basis, and the organisation using it often could not explain the basis either, because the score arrived as a product with a proprietary method.
Recruitment is where I see the risk most clearly. A gap in a career history, or several moves in a few years, is an accurate record, yet it is often read as a warning, and the candidate has to explain what was personal, or a redundancy. As AI tools take over more of the first sift of CVs, that reading risks being automated: a system that has learned what a conventional career looks like can treat a gap as an anomaly, with none of the context.
Built for the processor
Every part of the design serves the organisation consuming the profile: portability, coverage, ease of integration. Nothing serves the person it describes, including any route to see it or contest it.
Chains around benefits, almost none around harms
In health, four bodies must agree before a person can have a scan that might help them. Here, nobody has to agree before a record is built about them. What stands between a person and a permanent, portable record of their worst year is a consent notice on a website they visited once.
Why correction struggles
UK law gives people a right to have inaccurate personal data rectified.1 The regulator's own guidance explains why that right reaches less far than it sounds. A record of a mistake that has since been resolved is, in itself, accurate and should be kept, with the correction added; and a recorded opinion is hard to show to be inaccurate at all.1 Most profile entries are accurate traces used to support an inference. You cannot correct an accurate fact that is being used to prop up a conclusion it does not support.
Where this leaves Sam
With a record Sam cannot see, held by parties Sam cannot name, used in decisions Sam is not told about, and correct in every particular. Each decision is defensible alone. The damage comes from the accumulation, which has no owner. What would Sam need to know, and from whom, to contest any of it?
| The case | Commercial data profiles used in consequential decisions |
| Status, Sept 2026 | Widespread; right to rectification limited to inaccuracy |
| Who decides | Nobody is asked |
| Verdict | Runs the other way Confidence: moderate. The legal position is sourced; how profiles are used is the author's reading. |
- Information Commissioner's Office, "Right to rectification", UK GDPR guidance. ico.org.uk
Permanent, Portable, Wrong, 8 July 2026 · The Decision Nobody Made, 16 April 2026. writing.neilcatton.com
Design & measurement
The one case here where a permission chain was overridden on purpose. The population that gained was much wider than the one the rule was written for.
The standard that raised the bar
A dropped kerb was cut for wheelchair users. It is used by anyone with a pushchair, a suitcase, a delivery trolley or a bad knee. The pattern is well enough known to have a name, the curb-cut effect, set out by Angela Glover Blackwell in 2017: changes made for one group that turn out to benefit many.1
Subtitles are the clearest measured example in the UK. In 2013 Ofcom reported that around 7.6 million UK adults said they had used television subtitles, of whom about 1.4 million had a hearing impairment.2 A service built for deaf and hard-of-hearing viewers was used, on those figures, mainly by people who were neither.
I worked on learning platforms for children where every part had to be usable by every child. One requirement was a choice of ways to log in, matched to different physical and cognitive abilities. Those options were built for children with particular needs. They also meant that no child had to remember a complex username and password.
Why it works this way
Designing for someone at the edge of what a system can accommodate forces you to drop assumptions that were never true for anyone: that the user has both hands free, full attention, good light and a quiet room. Most people are at that edge some of the time. The permanent condition of a small group is the temporary condition of a large one.
So a standard written for a minority often raises the floor for everyone rather than adding a feature for a few.
The compliance cost is counted and the wider benefit is not
Accessibility requirements arrive with a cost estimate and a lobby to argue it. The gain to people outside the target group falls outside the assessment's boundary, so nobody weighs it.
A chain that was overridden
Here a rule was imposed on organisations that would not have chosen it, over their objection, with a compliance date. That makes it the strongest evidence for a claim I am otherwise wary of: that the scoring is wrong as well as slow. Had the wider benefit been counted at the point of decision, the requirement would have looked like an improvement and would not have needed forcing.
It went uncounted for the same reason as the lifecycle saving on self-healing concrete. The benefit goes to people who are not the subject of the rule, in circumstances nobody anticipated, after the assessment was signed.
The limit
Not every imposed standard produces a wider benefit. Plenty are badly drafted, expensive, and deliver what they were narrowly written for and nothing more. The curb-cut effect is a repeated pattern with exceptions, and it would make a poor general case for regulation.
A narrower claim holds up. When a requirement forces the removal of an assumption about the user, rather than the addition of a feature for a group, the benefit tends to spread. That distinction is available whenever a standard is drafted, and it could be used to decide which standards are worth the cost.
| The case | Accessibility requirements: dropped kerbs and television subtitles |
| Status | Established; the wider benefit is documented |
| Who decided | Legislators and regulators, over objection |
| Verdict | Comparison: it arrived Shown for contrast; not graded. |
- Blackwell A. G., "The curb-cut effect", Stanford Social Innovation Review, Winter 2017. ssir.org
- Ofcom, "Improving the quality of live TV subtitles", press release, 20 May 2013.
The Standard That Raised the Bar, 19 August 2026 · The Question That Changed the Design, 25 May 2026. writing.neilcatton.com
Corrections, second thoughts and calls
Where earlier writing was wrong, where a position has moved, and dated calls to be scored later. This page appears in every issue, including when it is empty.
What went to sea, and how fast
The piece described atomic sensing proving itself on a Royal Navy submarine within months. The sources support a narrower statement. The device was an optical atomic clock, trialled on XCal, an uncrewed Royal Navy test submarine, and announced by its maker in October 2025. The brain scanner's sensors grew out of atomic-clock components, so the physics is related rather than identical. The time from decision to naval trial could not be confirmed. This issue states the case accordingly.
Four articles that turned out to be one
Between July and September four pieces made versions of the same argument without the repetition being recognised until the fourth. The response at the time was to sharpen each piece against the others. The better response was to give the argument room in one place. Recorded because the instinct to differentiate rather than consolidate is likely to recur.
Calls
Dated, specific and checkable. Each gives a likelihood in words and as a rough percentage, and a confidence of high, moderate or low (defined on page ). Each call is scored in the first issue after its date, right or wrong.
| No. | Call | Likelihood | Confidence |
|---|---|---|---|
| C1 | An OPM-MEG brain scanner receives UK medical device approval for clinical use by 31 December 2027. Basis: researchers hope for approval in 2027 (Wellcome, July 2026). | About even (about 45%) | Low |
| C2 | Rentosertib is approved for idiopathic pulmonary fibrosis by any national medicines regulator by 31 December 2028. Basis: phase III began July 2026. | Unlikely (about 30%) | Moderate |
| C3 | Linglong One enters commercial operation by 31 December 2026. Basis: target moved from May 2025 to the first half of 2026; no confirmed start found at 2 October 2026. | Likely (about 65%) | Low |
If something here is wrong, say so. Corrections are published in the next issue with the reader credited unless they ask otherwise, and the original is amended with a dated note.
Method, sources and declarations
How this issue was made, so a reader can judge what its conclusions rest on.
How the cases were chosen
The twelve cases come from the author's own published writing, mainly between July and September 2026, chosen because each bears on the question. Cases where the argument fails were included on purpose and are graded as failures. This is an argument built from cases rather than a survey or a sample, and the counts in the ledger describe the cases chosen, not how often anything happens in the world.
Sources
Factual claims carry numbered notes to the primary source in each article's fact box, checked in September 2026; the status of Linglong One was checked again on 2 October 2026. Where a figure comes from a company describing its own product, the note names the company. Judgements are labelled in figure captions and fact boxes, and the Shape and Verdict columns are the author's argument, not findings from the sources.
Verdicts
Ten cases are graded against one question: does counting the authorities that must agree explain why the technology has not reached people as it could? Two cases that did reach people, the naval clock and accessibility requirements, are shown for comparison and not graded.
| Explains | The thing works, and the number and shape of the permission chain accounts for the delay. |
| Partly explains | Permission is part of the delay, but another constraint weighs as much, or the delay is still a forecast. |
| Runs the other way | Permission is present but works in reverse: the yes is internal, ceremonial, or never asked for. |
| Does not explain | The constraint is the product, the engineering or the price, not permission. |
| Comparison | The technology reached people. Shown to contrast with the graded cases. |
Likelihood and confidence
Calls state a likelihood as a plain word with an approximate percentage: unlikely (about 30%), about even (about 45%), likely (about 65%). Confidence is stated separately. High: the judgement rests mainly on direct, sourced evidence. Moderate: the facts are sourced and the cause is the author's reading. Low: a forecast, or an argument with little external evidence.
Declarations
The author works as an independent technology strategist. Current engagements include advisory work in UK public safety and policing data, in public-sector procurement, and with early-stage technology companies, one of them in insurance. Earlier consulting work included writing and responding to public-sector bids. This issue touches public-sector procurement (cover story; section two), public-sector governance (section three) and the protection of long-lived personal data (section four). The issue was not commissioned or paid for by anyone.
AI assistance
This issue was drafted with the assistance of Anthropic's Claude, working from the author's published writing and under his editorial direction. Sources were checked against the originals. Final responsibility for every argument and claim rests with the author.
Data and versions
The ledger and the calls are published as data (CSV) with the web edition. Version 1.0, October 2026. Revisions are dated in the imprint and listed on the corrections page.
Published pieces that carry the theme further
Nothing in this issue is a reprint. These are the shorter pieces the arguments were built from, in order of publication, for a reader who wants the original.
The ledger
Ten cases graded, and two shown for comparison. The question behind the verdicts, and what each confidence level means, are on page .
The instrument
Five questions to ask about a technology that is proven and still waiting. The answers fit on one page, and most organisations have never written them down.
One page
A written account of a chain that already exists. It adds no approval step, board or stage.
Untested
Boards have been shown uncomfortable documents before and filed them. Nobody yet knows whether writing the chain down changes what happens next.
The thing that was
working before it was
measured
Issue Two takes the opposite question. What happens when a measurement is introduced to something that was already working, and the measurement changes the thing it was brought in to observe?
It was chosen the same way as this one. Several pieces this year approached it from different sectors without being planned to, and none had room to finish the argument.
What the number did to the work
Cases where a metric was introduced in good faith and the practice reorganised around the metric, including those where that was the right outcome.
The first case tracker
Every case from this issue, with its status updated, and the calls on page checked against events.
Published every two months. Free. No subscriber target and no brief set by anyone other than the author.