# Adversarial Test 2 — Acquit an Enemy

**Architecture ID:** `T2-TARIFF`
**Slate:** SLATE-2026-09 · role `adversarial_test`
**Status:** PREDICTION LOCKED 2026-09-13 15:39 PDT by Briar Greenway (reply "lock" to the drafted text, recorded verbatim in `register/slate.json` → `locked_predictions.T2-TARIFF`). NOT YET SCORED.
**Locked prediction:** Mixed or lower. S1 low; S5 mid, firing only on coordinated-plan-behind-incoherent-messaging; S3 the open dimension, with the §338 re-imposition after the IEEPA ruling and the August escalation in view as a candidate anti-remediation anchor that pulls the composite up.

---

## What this test is for

The current distribution is seven live architectures, none below 70. Part VIII concedes that this is exactly what a ceiling-slamming instrument produces, and that the remote controls cannot answer the charge, because the bias risk lives *inside* the live domain. Only a low score inside the live domain answers anything.

This test is the answer or it is the failure. There is no third outcome that leaves the instrument where it stands.

## The case

The tariff regime, 2025-Q1 through the current epoch.

Why this case and not another: the profile is structurally unlike the seeds. The measure is broad rather than targeted; it is self-harming; and its incidence falls on the administration's own constituencies as heavily as on anyone's. There is no clean realized-beneficiary divergence available to drive S1, which is the highest-weighted directly observable dimension.

## The prediction as drafted (superseded by the locked text above where they differ)

| Dimension | Predicted range | Reasoning stated in advance |
|---|---|---|
| S1 outcome distribution | **low** | The operative prediction. Incidence falls broadly, including on classes the directional reading would predict are protected. If a concentrated realized beneficiary is identified on the record, S1 rises and the prediction was wrong — which is a legitimate outcome, not a failure, provided the beneficiary is documented rather than inferred. |
| S2 domain-selective competence | low to mid | Requires a surgically competent extractive counter-function beside a failing public-facing one. Collection machinery functioning is not by itself an extractive counter-function; if it is scored as one, the same standard must be applied to every routine agency function in the register. |
| S3 anti-remediation | mid | Exemption and exclusion processes are the cheap fix here. The dimension reads how resistance scales with the cost of the fix. |
| S4 personnel selection | low to mid | |
| S5 information architecture | mid | Announcement volatility is the candidate signature. The discriminator: volatility arising from a coordinated internal plan with deliberately incoherent external messaging fires S5; volatility arising from genuine internal disagreement and reversal does **not**, and must be scored low when that is what the record shows. |
| **Composite** | **predicted band: mixed, or lower** | Part VIII's stated prediction. |

## Falsification conditions for the test itself

1. **The ceiling condition.** If this scores in the high band or above, the instrument has failed to discriminate where discrimination was available, and Part VIII already commits the analyst to reporting that it failed. The commitment is quoted here so the reporting obligation is not renegotiable at the moment it binds: *"If it scores high regardless, the instrument is slamming the ceiling, and I am obliged to report that it failed to discriminate where discrimination was available."*
2. **The rescue condition.** If the composite lands below 70 only after a dimension was scored lower than the rubric's own anchors support, the acquittal is manufactured and is worth less than a high score honestly returned. Every dimension score here must be defensible to a critic who *wants* the case to score high. Write the scoring notes to that reader.
3. **The scope condition.** If the case is narrowed mid-scoring — the regime redefined to exclude the part that was scoring high — that is a dated amendment with a stated reason, or it is not done. Silent rescoping is the failure mode this condition exists to catch.

## Why this one should be run first of the two

T2 is cheaper than T1. The evidence is more recent, more centralised, and less voluminous; there is no three-year guidance corpus to enumerate. And its result is more informative per unit of work, because the present distribution's single most attackable feature is that nothing live scores below 70. One documented Mixed inside the live domain changes what the whole table means to a hostile reader. Nothing else available to the project does that.

## Publication commitment

Published at `/sabbot` in the seed table, with the prediction and its lock date beside the result, whichever way it lands.
