Learning from the unforeseen
From simulated constraint to a politics of margin
Complexity does not mechanically produce innovation. It opens a space of exploration by multiplying competences, resources, memories, connections and possible trajectories. But it also engenders costs of its own: divergent interests, coordination delays, conflicts of interpretation, cross-dependencies and difficulties in rapidly mobilising dispersed capacities.
Diversity therefore constitutes a potential, not a guarantee. It can enrich the solving of complex problems while slowing decision at the precise moment when a constraint demands a rapid response. A system may possess a great variety of competences without managing to coordinate them. It may hold substantial resources without knowing how to make them accessible. It may be complex without being genuinely adaptable.
The essential question is therefore not only how many possibilities a system contains, but under what conditions it can mobilise them before the disturbance has reduced the space in which they can still be explored.
From available complexity to mobilisable capacity
The mere presence of diversity or redundancy does not suffice. What makes the difference is the way that complexity is organised.
In a modular or nearly decomposable architecture, in the sense developed by Herbert Simon, interactions are generally stronger within subsystems than between them. The different parts retain a relative autonomy while remaining connected to the whole. This organisation allows local variations to be tested, corrected or abandoned without every modification propagating immediately to the entire system.
Modularity therefore does not abolish relations. It limits the uncontrolled propagation of their effects. It allows a department to modify its functioning without having to transform the whole organisation, a region to try a policy without imposing it immediately on the whole territory, or a production unit to test a new method without committing the entire industrial chain.
It thus turns diversity into mobilisable capacity.
But modularity is not sufficient in itself. An overly fragmented architecture may lose its capacity for coordination. The subsystems then risk becoming blind to one another, reproducing the same errors or developing incompatible responses. Autonomy makes exploration possible, but it produces collective learning only if the experiments can be compared, transmitted and reintegrated into a common memory.
What is at stake is therefore not a choice between centralisation and decentralisation. It is to distribute initiative without losing coherence, and to coordinate without stifling local capacity for experiment.
Real redundancy and apparent redundancy
Redundancy plays an essential role in resilience, since it allows several elements to ensure a similar function or to take over when one route becomes unavailable. Yet not all redundancies are genuinely protective.
Several suppliers may depend on the same energy network. Several data centres may be fed by the same regional infrastructure. Several companies may rest on the same invisible subcontractor or use the same logistical routes. Several institutions may appear autonomous while depending on the same digital system or the same decision centre.
Visible diversity can therefore mask a deep dependence. The system appears to have several solutions, while all of them share the same mode of failure.
True redundancy does not consist in multiplying components, but in diversifying sufficiently the conditions on which their functioning depends. Alternative solutions must be able to remain operational when the principal route disappears. This presupposes distinct infrastructures, distributed competences, partially autonomous decision capacities and supply chains that do not all converge on the same critical nodes.
This distinction obliges us to look beneath the surface of complexity. A system may count numerous actors and remain dependent on a single point of failure. It may appear diversified while resting on a common infrastructure. It may multiply administrative levels while requiring every decision to travel back to the same centre.
In that case, complexity becomes dead weight: the capacities exist, but they cannot be activated at the moment they become necessary.
A redundancy that depends on the same critical point is therefore not a genuine safeguard. It merely displaces or masks the fragility.
Constraint as a mechanism of activation
Constraint can play a role of activation. By breaking inertia, modifying priorities and forcing a reallocation of resources, it can make operative possibilities that were until then dormant.
But it does not directly create innovation.
It reveals, selects or recombines capacities already present: dispersed knowledge, under-used resources, latent competences, hitherto secondary relations, or solutions left without function because the environment did not yet require their mobilisation.
Constraint can make necessary what was previously optional. It can accelerate a long-postponed transition, reveal dependencies that stability allowed us to ignore, or push a system to explore trajectories it would never have chosen in a predictable environment.
This effect is nevertheless neither automatic nor always beneficial. A constraint can stimulate exploration, but it can also destroy its conditions.
When it becomes too strong or too rapid, resources are absorbed by immediate survival. Actors stop exploring in order to protect essential functions. Decisions become centralised, behaviours rigidify and the diversity of responses diminishes. The pressure that was to activate capacities ends up consuming the margins needed to mobilise them.
There is therefore an intermediate zone in which constraint can become fruitful. It must be strong enough to render the old responses insufficient, but not so brutal as to exhaust reserves or suppress the means of invention.
When pressure is too weak, inertia dominates. Habits remain less costly than change, established interests delay transformation, and the resources available sustain the idea that no urgent adaptation is necessary.
When pressure becomes excessive, the system shortens its horizon. It favours immediate responses, concentrates its resources on maintaining vital functions and sometimes sacrifices its future capacities to preserve its present functioning. Regulatory mechanisms may saturate, conflicts intensify and errors propagate more rapidly.
Between these two extremes lies a window of adaptation: enough constraint to make change necessary, but still enough diversity, reserves, internal freedom and time to explore other responses.
Constraint becomes creative only as long as the system retains the means of answering it otherwise than by closure.
Tempo as the core of resilience
Tempo is probably one of the most underestimated elements of resilience.
One and the same disturbance can produce innovation, rigidification or rupture depending on the time the system has to understand what is happening, decide on a response, mobilise its resources and modify its organisation.
An energy shock, a logistical breakdown, a financial crisis or a technological transformation therefore does not produce the same effects in all systems. The outcome depends on the ratio between the speed of degradation and the speed of reorganisation.
This dynamic can be represented conceptually:
[ T_{}
T_{}
T_{}
T_{} < T_{} ]
This relation is not a predictive equation. It serves as an instrument of diagnosis.
A system can fail at each of these levels.
It may detect too late because weak signals are not recognised, because information circulates slowly, or because local actors lack the means to pass their observations upward.
It may recognise the threat correctly but remain paralysed at the moment of decision. Interests diverge, responsibilities are ill-defined, institutions pass competence back and forth, or procedures become too slow for a rapidly evolving situation.
It may also decide without managing to mobilise the available capacities. The resources exist, but they are dispersed, inaccessible, dependent on too many authorisations or impossible to convert rapidly into action.
Finally, it may intervene without managing to reorganise. The system temporarily compensates for the disturbance but does not transform the dependencies that made it vulnerable. It maintains its immediate functioning while progressively consuming its future capacities.
This decomposition makes it possible to localise vulnerabilities instead of reducing resilience to a vague notion of speed. A system may have abundant reserves but detect too slowly. It may possess excellent means of intervention while remaining unable to decide. It may act quickly without learning.
Useful speed is therefore not mere acceleration. It depends on the capacity to distribute observation, shorten certain decision chains, make resources accessible and correct errors rapidly.
Modularity as a protection of time
A distributed architecture can profoundly modify this sequencing.
In a strongly centralised system, information must travel up to the centre, be interpreted, validated, turned into decisions and then travel back down to the actors charged with implementing them. The delays add up.
In a modular architecture, some stages can unfold simultaneously. Local actors can detect a disturbance, interpret it and test a limited response without waiting for a uniform solution to be worked out for the whole system.
Modularity therefore protects not only space, by containing the propagation of damage. It also protects time, by authorising a local response before the whole organisation has understood the situation.
But this rapidity carries a risk of its own. An immediate reaction founded on a mistaken interpretation can accelerate the deterioration. The aim is not to reduce every delay to a minimum, but to preserve a viable ratio between observation, reflection and action.
The system must be able to intervene quickly enough not to undergo the disturbance entirely, while retaining enough prudence not to turn every uncertain signal into an irreversible decision.
Temporal resilience therefore rests on a balance: distributing initiative without losing the capacity to correct.
Reserves as stocks, options and available time
Reserves are not only stocks.
They comprise the financial, energetic or material resources available, but also latent capacities, flexible contracts, versatile competences, convertible infrastructures, alternative standards and means of production liable to be rapidly reactivated or scaled up.
A strategic stock makes it possible to absorb a rupture temporarily. A latent capacity makes it possible to rebuild a flow.
This distinction is essential.
A society may hold substantial material reserves while having lost the capacity to produce what it depends on. Conversely, it may retain a minimal industrial base, technical competences, adaptable infrastructures and networks able to scale up quickly.
These capacities represent options still open.
They sometimes have a cost in periods of stability. They may seem less efficient than a fully optimised system. They require maintaining little-used equipment, rarely mobilised competences or more costly alternative routes.
But their value appears when the environment changes.
Optimisation reduces costs in a predictable world. Options preserve the capacity to change trajectory in an uncertain one.
Reserves are therefore also reserves of time. They slow the transformation of a difficulty into an absolute emergency. They make it possible to observe before deciding, to compare several responses and to prevent a single solution from being imposed too early.
Financial resources can prevent a crisis from immediately absorbing all investment capacity. Social cohesion can preserve the trust necessary for collective action. Versatile competences can reduce the time needed to reassign functions. Convertible infrastructures can facilitate the modification of flows. Political time can maintain a space for debate and experiment.
Reserves therefore do not serve only to resist. They preserve the time to learn.
From analysis to simulated constraint
A resilient society should not wait for a crisis to discover its capacities for adaptation.
It should be able to introduce deliberately limited, progressive and reversible constraints in order to activate its dormant resources, reveal its dependencies and exercise its capacity for reorganisation.
But this constraint becomes fruitful only if the architecture limits its propagation, if the redundancies do not share the same modes of failure, if reserves preserve the time to learn, and if the rhythm of experimentation remains slower than that of deterioration.
Simulating constraint does not mean deliberately provoking a crisis. It means creating learning situations realistic enough to reveal fragilities without immediately exposing the viability of the whole.
An organisation can simulate the unavailability of a supplier, the interruption of a service, the temporary loss of an infrastructure or the absence of a decision centre. A society can test the continuity of certain essential functions when the usual flows are disturbed.
The aim is not only to demonstrate that the system holds. It is to observe what actually happens.
Which dependencies appear? Which actors detect the problem first? Which functions slow down? Which resources are available but impossible to mobilise? Which delays block adaptation? Which local capacities emerge spontaneously?
To be useful, the experimental constraint must remain circumscribed. It must be progressive so as to make thresholds observable, reversible so that it can be interrupted before the damage becomes irreparable, and realistic enough to produce genuine adaptations.
It must also be followed by a time of analysis, recovery and transformation.
The cycle should therefore not be:
[ ]
but:
[ ]
The aim is no longer only to verify whether the system withstands a shock. It is to increase its capacity to detect, combine and mobilise new responses.
The limit of simulation
One difficulty remains: a simulated constraint is necessarily chosen, prepared and, to some extent, anticipated.
It tests what the system has already recognised as possible.
Yet the power of real crises often lies in their reaching neglected dependencies, combining events no one had envisaged, or suddenly rendering inoperative assumptions regarded as stable.
A system may therefore pass every exercise it has itself designed and remain vulnerable to what it has never imagined.
It may become highly effective against known scenarios while remaining blind to fragilities lying outside its model. Simulation then risks producing an illusion of mastery: the organisation verifies that it knows how to respond to what it had foreseen and confuses that success with a general capacity for adaptation.
Radical unforeseeability cannot, however, be simulated without contradiction. As soon as an event is defined, scripted and prepared, it ceases to be entirely unforeseen.
One cannot reproduce in advance what one is incapable of imagining.
It is nevertheless possible to design conditions that increase the probability of encountering unexpected behaviours. The aim would no longer be to foresee exactly the next crisis, but to exercise the system's capacity to preserve its observation, its autonomy and its learning when it meets a situation it had not anticipated.
One does not simulate the unknown itself. One exercises the capacity to be surprised without losing the possibility of acting.
Introducing surprise without provoking catastrophe
A simulation should therefore not be limited to applying a scenario written entirely in advance.
An exercise designed solely to verify compliance with a protocol often measures conformity to an expected response rather than the real capacity for adaptation.
It can be useful to preserve a share of uncertainty: introducing random perturbations, combining several failures, keeping some information incomplete or modifying the conditions during the exercise.
The participants then know the safety limits, but not necessarily the exact nature of the difficulties they will have to resolve.
The constraint remains contained. The response, however, is not entirely prescribed.
It is also useful that the scenarios not be designed solely by those who will have to respond to them. An organisation that defines its own vulnerabilities, its own criteria of success and the expected solutions risks testing its own model of the world rather than the real system.
Outside perspectives, adversarial approaches or teams charged with contesting the dominant assumptions can reveal forgotten dependencies and vulnerabilities that have become invisible because the organisation has grown accustomed to its own functioning.
But no simulation, however complex, will be able to explore the whole set of possible disturbances.
Resilience therefore cannot rest on occasional exercises alone. It also requires a permanent capacity for real experimentation.
From simulation to a politics of margin
Modularity acquires a further function here.
It no longer serves only to prevent a local disturbance from becoming systemic. It allows different subsystems to explore distinct responses, to meet real constraints at their own scale and to produce variations that the centre would not necessarily have imagined.
Territories, institutions, companies or communities can experiment with different forms of organisation, production, regulation or cooperation.
These experiments are not entirely simulated. They meet the real, produce consequences and reveal unexpected behaviours. But their limited scale makes it possible to prevent a local error from immediately threatening the whole system.
True simulation might then become less an occasional exercise than a politics of margin.
It would mean preserving spaces where several responses can coexist, where actors have enough autonomy to experiment, where certain deviations are tolerated and where error can remain local.
Diversity then becomes a continuous production of hypotheses.
Modularity makes it possible to test them.
Redundancy limits the cost of failures.
Reserves give the time to observe their effects.
Collective memory turns local experiments into shared capacities.
This politics of margin does not presuppose the abandonment of all coordination. On the contrary, it requires a capacity for collective observation.
A local innovation can disappear if no one documents it. An error can be repeated in several territories if its lessons do not circulate. A solution may seem effective in a particular context and fail when transposed elsewhere.
Autonomy must therefore be paired with mechanisms of comparison, transmission and capitalisation.
An adaptive society must be able to observe what appears at its margins without immediately seeking to standardise it. It must distinguish what deserves to be amplified, what should remain local, what should be corrected and what reveals a common vulnerability.
Learning does not lie only in the diversity of experiments. It depends on the capacity to circulate their lessons without abolishing the differences that made them possible.
Learning from error without abolishing responsibility
Learning also presupposes a particular relation to failure.
When an incident immediately triggers a search for a culprit, actors often learn to protect their reputation rather than to make the fragilities of the system visible.
Errors are concealed, weak signals travel upward less readily, and failures are attributed to individuals when they sometimes result from interactions, procedures, incentives or structural dependencies.
This does not mean abolishing responsibility.
Deliberate negligence, concealment or conscious transgression cannot be treated as mere accidents. But the analysis must distinguish individual fault from the conditions that made the error possible, probable or hard to detect.
The aim is not to erase responsibility. It is to prevent it from obstructing understanding.
A local disturbance becomes a future capacity only if the system agrees to examine what it reveals about its architecture.
From error of execution to error of representation
Learning from the unforeseen requires a still deeper transformation.
Some events do not merely reveal poor execution. They call into question the representation the system has of itself.
An organisation can correct a protocol without questioning the assumptions that produced it. It can add a new rule after each incident, strengthen controls and multiply procedures.
It then becomes more complex without becoming more adaptable.
By answering every failure with an additional layer of control, it even risks increasing the delays, dependencies and rigidity that contributed to the problem.
True learning therefore does not consist only in improving the response. It must sometimes modify the way the system defines the problem.
Which dependencies does it regard as normal? Which assumptions are never questioned? Which signals go unrecognised? Which alternatives are excluded before even being studied?
Surprise then becomes more than a disturbance to eliminate. It becomes information about the limits of the model the system holds of itself.
An adaptive system therefore does not seek only to correct its errors. It develops the capacity to discover that its own way of understanding the situation was itself incomplete.
Robustness, resilience and antifragility
This reflection makes it possible to distinguish several properties often confused.
Robustness is the capacity to maintain a function despite a disturbance. A robust system resists and absorbs a variation without having to modify its organisation profoundly.
Resilience denotes the capacity to absorb a shock, to reorganise and to recover a viable trajectory. The system does not necessarily return to its initial state. It may transform its relations, its priorities or its structures in order to keep functioning in a modified environment.
Antifragility denotes a more demanding property: certain disturbances can improve the system's future capacities. Local errors can reveal hidden dependencies, moderate competition can stimulate innovation, and controlled experimentation can enrich collective memory.
But this property is rare, asymmetric and contextual.
A system may benefit from certain disturbances while remaining vulnerable to others. An organisation may learn from local errors and remain fragile in the face of a sudden loss of trust. A society may adapt to a gradual crisis and be disorganised by a rapid systemic shock.
Antifragility is therefore not a global property. It depends on the nature of the disturbance, its intensity, its duration, the function observed and the scale considered.
The right question is not whether a system is antifragile, but in the face of which disturbances, in which dimensions and for how long it can turn variability into learning.
One and the same system may be antifragile in one dimension, resilient in another and fragile in a third.
Applications in organisations, in the living and in societies
Companies entirely optimised for immediate efficiency can become vulnerable when the environment changes.
Just-in-time reduces stocks. Centralisation simplifies coordination. Specialisation increases productivity. Standardisation lowers costs.
But when these mechanisms are pushed to the extreme, they can remove the margins necessary for adaptation.
A supply chain without reserve can function perfectly in a stable environment and break down rapidly when a supplier disappears. A strongly centralised organisation can take coherent decisions in normal times but become slow when several disturbances appear at once.
Conversely, some companies deliberately keep margins: relatively autonomous units, versatile competences, rotation of functions, failure exercises, resources not entirely committed, or spaces devoted to experiment.
These margins may seem inefficient in periods of stability. They nevertheless sometimes constitute the very conditions of adaptation.
In the living, evolution does not advance through a linear accumulation of complexity.
Complexity can create new possibilities, but it can also increase dependencies and energy costs. Adaptation rests on variation, selection, duplication, recombination and the progressive transformation of the relations between elements.
Gene duplication can allow one copy to retain a function while another explores new variations. The modularity of regulatory networks can limit the propagation of certain modifications. Phenotypic plasticity can allow an organism to modify its response without waiting for a genetic transformation.
Over-specialised organisms can be extremely effective in a stable niche and become vulnerable when conditions change.
Adaptation therefore depends not only on the level of complexity, but on the capacity to produce variations without immediately losing viability.
In societies, institutional diversity, decentralisation and the existence of alternative routes can prevent a disturbance from propagating immediately to the whole.
But decentralisation does not automatically produce learning. It can also generate incoherences, inequalities or difficulties of coordination.
It becomes genuinely adaptive when the experiments are observable, comparable, reversible and transmissible.
Cities, regions or sectors can test different approaches within a common framework. Energy, educational or administrative policies can be tried at several scales without being immediately generalised.
The system then learns from the differences instead of seeking to abolish them too early.
Conclusion
Complexity opens possibilities, but it does not guarantee their mobilisation.
Diversity increases the number of conceivable responses. Modularity makes it possible to explore them locally. Redundancy preserves alternative routes. Independence prevents them all from disappearing in a single disturbance.
Reserves give the time to mobilise them. Options keep several trajectories open. Constraint makes their exploration necessary. Simulation makes it possible to rehearse certain responses before the crisis. The politics of margin lets solutions appear that no one had programmed. Collective memory turns local experiments into durable capacities.
And tempo decides whether reorganisation can still outpace deterioration.
What finally distinguishes mere complexity from resilience is not the number of possibilities present, but the capacity to detect them, mobilise them, test them, coordinate them and recombine them before the constraint has consumed the time needed to do so.
A capacity that cannot be activated in time is only a theoretical possibility.
A redundancy that depends on the same critical point is only an apparent safeguard.
A reserve that cannot be converted into action merely delays the rupture.
An experiment whose lessons do not circulate produces only a local adaptation.
A resilient society therefore does not seek to foresee every crisis. It builds an architecture capable of discovering quickly that it was wrong, of containing the consequences of that error and of preserving enough diversity, autonomy and time to explore other responses.
It does not claim to abolish uncertainty. It prevents uncertainty from becoming immediately irreversible.
Simulating constraint therefore does not suffice. One must also protect the spaces in which the real can produce variations that no one had programmed, where error can remain local and where learning remains continuous.
To give a system the possibility of learning before urgency takes away its time to invent is not merely to organise tests. It is to preserve the margins in which the unexpected can appear without immediately becoming a catastrophe, and where surprise can still be transformed into knowledge, reorganisation and future capacity.