:orphan:

.. include:: /_templates/include-file/page-prefix.rst

.. meta::
   :description: An actuarial waiting-time forecast for accidental nuclear winter: a three-state first-passage model calibrated on the Cold-War near-miss record, reporting the probability distribution over time-to-onset and individual mortality against the road-death baseline.
   :keywords: waiting time, actuarial forecast, accidental nuclear winter, first passage, absorbing Markov chain, hypoexponential, Michaelis-Menten, crisis rate, near-miss record, Baum, Hellman, Lewis, Tertrais, New START, TPNW, super wicked problem, uninsurable, road-death baseline, MAD, MAP, RiskyMAD, existential risk, AuditTheMath
   :author: Laurence Loewe of Laodicea, Everyone (as in https://balospe.com/en/about/authorship/)
   :og:card:title: Forecasting Actuarial Waiting Times<br>for Accidental Nuclear Winter
   :og:card:description: Half of all runs of world history reach accidental nuclear winter within 21 years. For most people it is likelier than a car crash. Offered not to be believed, but to be checked. #AuditTheMath

.. only:: latex

   .. raw:: latex

      % --- Per-paper header / footer values (see conf.py preamble) -----------
      \renewcommand{\paperheaderleft}{\scriptsize Balospe.com/study}
      \renewcommand{\paperheadercenter}{\scriptsize Matheo-b16}
      \renewcommand{\paperheaderright}{\scriptsize Variant OOv2r0p0\ $|$\ 2026m07d16}
      \renewcommand{\paperfooterleft}{\scriptsize Waiting times for accidental nuclear winter}
      \renewcommand{\paperfooterright}{\scriptsize Jonah License, CC-BY 4.0}
      % -----------------------------------------------------------------------
      \begin{titlepage}
      \thispagestyle{normal}
      \begin{center}
      {\LARGE\bfseries
      Forecasting Actuarial Waiting Times\\
      for Accidental Nuclear Winter\par}
      \vspace{8mm}
      {\large Laurence Loewe of Laodicea\textsuperscript{1,2,3,4,5,6,7}\par}
      \vspace{2mm}
      {\small Study b16 in the Matheo Study Series\par}
      \end{center}

      \vspace{3mm}
      \begin{flushleft}\scriptsize
      \textsuperscript{1}\,Balospe and Evolvix Research (Balospe.com)\\[1pt]
      \textsuperscript{2}\,Formerly Laboratory of Genetics and Wisconsin Institute for Discovery, UW-Madison\\[1pt]
      \textsuperscript{3}\,Email: \href{mailto:LLoL@balospe.org}{LLoL@balospe.org}\ $|$\ ORCID: \href{https://orcid.org/0000-0002-6253-9269}{0000-0002-6253-9269}\ $|$\ \href{https://scholar.google.com/citations?user=lBchRzQAAAAJ}{Google\,Scholar\,(lBchRzQAAAAJ)}\\[1pt]
      \textsuperscript{4-7}\,See \textit{Declarations} below for more essential background.\\
      \end{flushleft}

      \vspace{3mm}
      \begin{center}\bfseries Broader Significance\end{center}
      \begin{quote}\footnotesize
           Nuclear war is usually argued in words. This study argues it in numbers, using the
           oldest quantitative discipline built for questions of this shape: actuarial
           science. An actuary cannot say when a particular person will die. Given a
           population, a set of risk factors, and a claims history, an actuary can still
           price the risk, and be wrong in ways that show. This study treats the system of
           nuclear-armed states as the life being priced, the Cold-War record of near-misses
           as the claims history, and accidental nuclear winter as the death.

           At the rate crises have actually arrived, half of all runs of world history reach
           accidental nuclear winter within {\bfseries twenty-one years}, and the chance it
           begins in any given year is about {\bfseries one in thirty-four}. Set beside a
           risk that societies accept without alarm --- dying in a road accident --- a person
           is roughly {\bfseries sixty times} more likely to die as a consequence of
           accidental nuclear winter than in a car crash, counted the same way: annual, per
           person, death against death. That comparison is this study's central claim, and it
           is built to be attacked rather than admired. It survives when the most sceptical
           published reading of the record, the lowest published death toll, and the
           road-death rate of the worst-affected country on record are applied {\itshape all
           at once}.

           This risk is not invisible because it is small. It is invisible because it has
           been removed from the places where risks are measured. Nuclear war is excluded by
           standard clause from essentially every insurance policy written: the profession
           that prices catastrophe for a living examined this one and declined it, on the
           correct grounds that it is uninsurable in principle --- there is no surviving
           counterparty to pay. It was priced at infinity, and then not spoken of. What
           follows is not alarm. It is arithmetic, from public data, repeatable in an
           afternoon.

           Readers concerned with nuclear policy, existential risk, actuarial practice, or
           the governance of problems that no single authority is empowered to correct will
           find the method and the failure modes relevant. Readers who suspect this of being
           alarmism should begin at Section 5.3: the most sceptical published critic of
           nuclear close-call analysis supplies this study's own optimistic scenario, and the
           conclusion holds there too. Readers who want the escape without the theology will
           find it in a companion written in entirely secular terms.

           The study is offered not to be believed, but to be checked. If it is wrong, the
           fastest way to find out is for someone to say so.
      \end{quote}

      \vspace{3mm}
      \begin{center}\bfseries Declarations\end{center}
      \begin{flushleft}\scriptsize
      \textsuperscript{4}\,"of Laodicea" indicates taking responsibility to undo personal complicity with disastrous Laodicean legacies like banning mathematicians from clergy (Canon 36, Council of Laodicea; two magisteria separations), enabling institutional lukewarmness, weapons of math-destruction, and slow-motion explosions of misinformation from pandemics to self-compounding interests.\\[3pt]
      \textsuperscript{5}\,LLoL stands for ridiculous luck in serendipitous discovery and a commitment to find ever more fun ways to help others uncover street-wise math that matters.\\[3pt]
      \textsuperscript{6}\,Loewe's traditional standards for co-authorship demand naming AI Claude Opus 4.8 Max (by Anthropic) as a co-author for many substantial contributions, as if a PhD-student. Yet, AI co-authorship is withheld here until Loewe's framework for AI co-authorship after the practical singularity (PraS) passes external human peer review (see Matheo-b21 study). Anthropic is not responsible for AI mistakes here. Loewe as senior corresponding author remains forward accountable for every number in this study, including those a machine computed.\\[3pt]
      \textsuperscript{7}\,\textit{Licensed under the Jonah License and CC-BY 4.0 for maximal flexibility (see \href{https://balospe.com/en/license/joli/}{https://balospe.com/en/license/joli/}).}\\
      \end{flushleft}

      \end{titlepage}
      \newpage


****************************************************************************************************
Forecasting Actuarial Waiting Times for Accidental Nuclear Winter
****************************************************************************************************

.. only:: html

   | **Laurence Loewe of Laodicea** :sup:`1,2,3,4,5,6,7`

   .. container:: titlepage-credentials

      | :sup:`1` Balospe and Evolvix Research (Balospe.com)
      | :sup:`2` Formerly Laboratory of Genetics and Wisconsin Institute for Discovery, UW-Madison
      | :sup:`3` Email: LLoL@balospe.org \| ORCID: https://orcid.org/0000-0002-6253-9269 \| `Google Scholar (lBchRzQAAAAJ) <https://scholar.google.com/citations?user=lBchRzQAAAAJ>`__
      | :sup:`4-7` See *Declarations* block below for more essential background.
      | This is Balospe.com/study **Matheo-b16**, variant ``dv_ClaOp48Max_OOv2r0p0_2026m07d16``
      | **Study b16** in the Matheo Study Series

   .. raw:: html

      <hr/>

   **Broader Significance**

   Nuclear war is usually argued in words. This study argues it in numbers, using the oldest
   quantitative discipline built for questions of this shape: actuarial science. An actuary
   cannot say when a particular person will die. Given a population, a set of risk factors,
   and a claims history, an actuary can still price the risk --- and be wrong in ways that
   show. This study treats the system of nuclear-armed states as the life being priced, the
   Cold-War record of near-misses as the claims history, and accidental nuclear winter as
   the death.

   At the rate crises have actually arrived, half of all runs of world history reach
   accidental nuclear winter within **twenty-one years**, and the chance it begins in any
   given year is about **one in thirty-four**. Set beside a risk that societies accept
   without alarm --- dying in a road accident --- a person is roughly **sixty times** more
   likely to die as a consequence of accidental nuclear winter than in a car crash, counted
   the same way: annual, per person, death against death. That comparison is this study's
   central claim, and it is built to be attacked rather than admired. It survives when the
   most sceptical published reading of the record, the lowest published death toll, and the
   road-death rate of the worst-affected country on record are applied *all at once*.

   This risk is not invisible because it is small. It is invisible because it has been
   removed from the places where risks are measured. Nuclear war is excluded by standard
   clause from essentially every insurance policy written: the profession that prices
   catastrophe for a living examined this one and declined it, on the correct grounds that
   it is uninsurable in principle --- there is no surviving counterparty to pay. It was
   priced at infinity, and then not spoken of. What follows is not alarm. It is arithmetic,
   from public data, repeatable in an afternoon.

   Readers concerned with nuclear policy, existential risk, actuarial practice, or the
   governance of problems that no single authority is empowered to correct will find the
   method and the failure modes relevant. Readers who suspect this of being alarmism should
   begin at :ref:`Section 5.3 <oov1-b16-sec5>`: the most sceptical published critic of
   nuclear close-call analysis supplies this study's own optimistic scenario, and the
   conclusion holds there too. Readers who want the escape without the theology will find it
   in :doc:`a companion written in entirely secular terms
   </study/matheo/overview-secular/index>`.

   The study is offered not to be believed, but to be checked. If it is wrong, the fastest
   way to find out is for someone to say so.

   .. raw:: html

      <hr/>

   **Declarations**

   .. container:: titlepage-identity-footnotes

      | :sup:`4` "of Laodicea" indicates taking responsibility to undo personal complicity with disastrous Laodicean legacies like banning mathematicians from clergy (Canon 36, Council of Laodicea; two magisteria separations), enabling institutional lukewarmness, weapons of math-destruction, and slow-motion explosions of misinformation from pandemics to self-compounding interests.
      | :sup:`5` LLoL stands for ridiculous luck in serendipitous discovery and a commitment to find ever more fun ways to help others uncover street-wise math that matters.
      | :sup:`6` Loewe's traditional standards for co-authorship demand naming AI Claude Opus 4.8 Max (by Anthropic) as a co-author for many substantial contributions, as if a PhD-student. Yet, AI co-authorship is withheld here until Loewe's framework for AI co-authorship after the practical singularity (PraS) passes external human peer review (see :doc:`Matheo-b21 </study/matheo/b21/index>` study). Anthropic is not responsible for AI mistakes here. Loewe as senior corresponding author remains forward accountable for every number in this study, including those a machine computed.
      | :sup:`7` *Licensed under the Jonah License and CC-BY 4.0 for maximal flexibility (see* https://balospe.com/en/license/joli/ *).*

   .. raw:: html

      <hr/>

.. note:: **Draft status: OOv2r0p0 (2026m07d16) --- not yet reviewed by LLoL.** Successor to the
   OOv1 draft, following an adversarial panel review. **If you have seen 3.24 percent quoted from
   this work, see Section 2.0a: it was too high, by about 12 percent, and in this study's own
   favour.** What changed between the MMv5 floor and this draft --- what was refined, what
   was corrected, and the one claim that was removed --- is set out in
   :doc:`What Changed Between MMv5 and OOv1 </study/matheo/b16/b16-changelog-mmv5-to-oov2>`,
   with links to the full audit trail. Prior versions ``mmv1/``--``mmv3/`` are retained
   unedited as the archive.


**Abstract**

**How long does a civilization survive with nuclear weapons and without periodic
recalibration?** This study answers that question the way an actuary prices a life: as a
probability distribution over time-to-failure, calibrated on a claims history, and
falsifiable against it.

**The model.** RiskyMAD is a three-state continuous-time Markov chain --- Risky (weapons
exist, no exchange), MAD (a crisis in which nuclear use is on the table), and Dead
(accidental nuclear winter, an absorbing state). Four transitions connect them. The chain is
small enough to solve exactly, and the exact first-passage law is derived here rather than
approximated: it is **hypoexponential**, the sum of two exponentials, because a crisis takes
time to resolve before onset is possible at all.

**The calibration.** The one parameter that must come from the world is the rate at which
civilization-threatening nuclear crises arise. It is counted here from the largest published
catalogue of such events --- the sixty incidents compiled by Baum, de Neufville and Barrett
(2018) --- under a criterion fixed **before** counting. Incidents are not excursions: six of
their sixty belong to the single Cuban missile crisis and contribute one entry. The
classification returns **four Cuba-grade entries in the forty Cold-War years**, a crisis rate
of **0.1 per year**. The probability that a crisis escalates rather than de-escalates is taken
as **1/3**, from a structural argument, bracketed by Kennedy's contemporaneous estimate of
"between one in three, and even" on one side and Laplace's rule of succession on the other.

**The results.** At the base rate, the mean time to onset is **30.3 years** and the median is
**21.1** --- half of all runs of world history are over within twenty-one years. The annual
probability that accidental nuclear winter *begins* is **2.90 percent, about 1 in 34**; over
forty years, one career, it is **73 percent**. Across a scenario range bracketing both
published poles of the near-miss literature, the annual probability spans roughly 1 to 8
percent. Forty stochastic simulations of world history agree with the closed form to within
sampling noise.

**The comparison.** Discounted by a death fraction taken from the nuclear-winter literature,
individual annual mortality from accidental nuclear winter is roughly **fifty-eight times**
the global road-death baseline, counted annual-per-person against annual-per-person. The
inequality holds in every scenario, and it holds by threefold when the most sceptical crisis
rate, the lowest published death toll, and the highest national road-death rate on record are
imposed simultaneously.

**The mechanism, and why eighty-one quiet years prove little.** The scheme is a saturating
two-step process of exactly the Michaelis--Menten form, and the world sits ninety times below
half-saturation: the system is in its lethal state about one percent of the time. A process
like that produces long calm stretches as a matter of course. Non-observation of nuclear war
since 1945 is what this model predicts most of the time, and is therefore weak evidence about
the rate.

**What the study does not claim.** The classification of Baum et al.'s incidents is this
study's own, and is the part a reader should attack first; two calls are named in advance as
weakest, and removing the most contested gives 1 in 46 rather than 1 in 34. The escalation
probability of 1/3 is **not measured**, and no revision closes that gap. The absorbing state
is not resolved to a warhead count.

**The escape, and its price.** Because the Dead state is absorbing, accidental nuclear winter
is a stochastic certainty under business as usual: the only open question is when. The study
derives a candidate escape --- MAP, Mutually Assured Progress --- in which a credible
first-mover converts the nuclear Prisoner's Dilemma into an Assurance Game. It then prices
that escape with the same model: a seven-to-eleven-year transition carries a **20 to 30
percent** chance of not finishing in time, against 73 percent over a career of doing nothing.

**Every input is public and every step is open to inspection.** The dataset is not this
study's own; the equations are in Section 2.4a; the classification is tabulated incident by
incident so that a reader who rejects a call can strike it and recompute. **Don't believe it
--- #AuditTheMath.**


.. contents:: Contents
   :depth: 2
   :local:


----


.. _oov1-b16-sec1:

1. The Question
=================

How long does a civilization survive with nuclear weapons and without
periodic recalibration?

This is not a philosophical question. It is a stochastic modeling
question --- the same kind of question an actuary asks when pricing a
life insurance policy. An actuary does not know when a particular person
will die. But given a population, a set of risk factors, and historical
data, the actuary can estimate a probability distribution over
time-to-death. The estimate is falsifiable: if the actual death rate
deviates significantly from the predicted distribution, the model is
wrong and must be revised.

This paper applies the same logic to nuclear civilization. The "patient"
is the global system of nuclear-armed states. The "risk factor" is the
rate at which crises arise that bring the system to the brink of nuclear
war. The "historical data" is the Cold War record of near-misses. The
"death" is accidental nuclear winter --- not a deliberate nuclear
strike, but the unintended initiation of nuclear exchange through
miscalculation, system failure, or escalation beyond the point of human
control, and the subsequent global catastrophe as nuclear winter kills
far more people than the initial exchange.

The question is not whether accidental nuclear winter is possible. The
Cuban Missile Crisis (1962), the Able Archer exercise (1983), Stanislav
Petrov's false alarm (1983), and Vasili Arkhipov's refusal to authorize
a nuclear torpedo (1962) have already answered that question. The
question is: **given the observed crisis rate, what is the probability
distribution over the time until accidental nuclear winter begins?**

This is not an idiosyncratic worry. In July 2025 the Nobel Laureate
Assembly for the Prevention of Nuclear War warned that nuclear war is
uniquely able to end civilization "in an afternoon" :cite:`NobelAssembly2025`;
a year later, convened at the Vatican, the Global Nobel Laureates Assembly
on Artificial Intelligence and Nuclear War warned that "AI built into
nuclear systems leaves little time for, or even replaces, human judgement
in a crisis" :cite:`DiazMaurin2026` --- the exact failure this model takes
as its absorbing state. Theirs is the qualitative alarm; this study
supplies the quantity behind it.

The answer is sobering. But this paper is not a prediction of doom. It
is a diagnosis with a proposed treatment. The treatment is called MAP
--- Mutually Assured Progress --- and it is formally derivable from the
upstream results of this series. The system is designed to be critiqued,
not believed. #AuditTheMath


----



**Prior work, in brief.** The quantitative literature on nuclear-war risk is small, and
Section 5 sets it out in full. Two facts from it are needed in advance, because without
them Section 2 reads wrongly.

*This forecast is not an outlier.* Hellman, whose 2008 fixed-rate model is the nearest
methodological ancestor to the one used here, revised his estimate in 2021 to **on the
order of 1 percent per year** --- reached by a different route, and within a factor of
three of the base case below. Older citations of Hellman's 2008 figure of
:math:`(2\times10^{-4},\, 5\times10^{-3})` per year misread him: that was his rate for a
**single** mechanism, and he states in the same paper that it "underestimates the threat".

*The strongest objection is already priced in.* Tertrais (2017) argues that the close
calls were not close, that safety mechanisms held, and that the rate is falling. His own
reading of the record implies roughly **0.029 per year** --- which is, to two significant
figures, the optimistic scenario of Section 2.5, chosen independently. The disagreement
between this paper and its most sceptical published critic is therefore not about whether
his corner is admissible. It is in the table. Section 5.3 takes his argument seriously,
and Section 2.6 shows that even at his rate the paper's central comparison holds by more
than an order of magnitude.

The incident data used to calibrate Section 2.3 are not this paper's own: they are the
sixty historical incidents compiled by Baum, de Neufville and Barrett (2018)
:cite:`Baum2018`, the largest such catalogue available. The classification of them is this paper's, and is the part a
reader should attack first.


.. _oov1-b16-sec2:

2. The RiskyMAD Model
========================


.. _oov1-b16-sec2-0:

2.0 How to Read the Numbers: BEST Names
-----------------------------------------

This paper has three parameters and one answer. Before any of them appear, here is what
each is called, in every register a reader might meet it. The table follows the **BEST
Names** convention --- **B**\ rief, **E**\ xplicit, **S**\ ummarizing, **T**\ echnical ---
developed for semantic reproducibility across code-to-brain interfaces
:cite:`Loewe2016BestNames`. The one-letter **Brief** forms exist because equations need
them. Everywhere else this paper uses the **Summarizing** name, and a reader who never
looks at an equation will lose nothing.

.. list-table:: Table 0. BEST Names for every quantity in this paper
   :header-rows: 1
   :widths: 8 20 30 42

   * - **B**\ rief
     - **E**\ xplicit (model code)
     - **S**\ ummarizing (used in prose)
     - **T**\ echnical --- synonyms and cross-paper identities
   * - :math:`\lambda`
     - ``rRiskyGoMAD``
     - **the crisis rate**
     - How often the world enters a nuclear crisis, per year. Hellman's
       :math:`\lambda_{IE}` (initiating-event rate) is the nearest published relative;
       his :math:`\lambda_{CMTC}` is *not* this quantity --- it is his end-to-end failure
       rate, comparable instead to this paper's **onset hazard** below (Section 5.2).
       Michaelis--Menten substrate :math:`S` (Section 2.7).
   * - :math:`b`
     - ``rMADescapes``
     - **the de-escalation rate**
     - How fast a crisis resolves *back to safety*, per year. Two of the three OSCR modes
       (Section 2.2).
   * - :math:`c`
     - ``rMADtoDEATH``
     - **the escalation rate**
     - How fast a crisis resolves *into nuclear exchange*, per year. One of the three OSCR
       modes. Michaelis--Menten :math:`V_{max}` --- **you cannot die faster than this.**
   * - :math:`p_{death}`
     - --- (derived: :math:`c/(b+c)`)
     - **the per-crisis death probability**
     - The fraction of crises that go all the way. Michaelis--Menten commitment to
       catalysis; specificity constant :math:`k_{cat}/K_m`. Kennedy's Cuban estimate
       (Section 2.2) is a reading of this quantity, not of the crisis rate.
   * - :math:`T_R`
     - --- (derived)
     - **the mean waiting time**
     - Expected years from now until onset. First-passage mean to absorption from state
       Risky. **Not** a half-life and **not** a deadline (Section 2.9).
   * - :math:`q`
     - --- (external)
     - **the death fraction**
     - Share of humanity that dies once nuclear winter begins. Not produced by this model;
       taken from the nuclear-winter literature (Section 2.6).
   * - :math:`r_1`
     - --- (derived)
     - **the onset hazard**
     - The slow rate at which the whole system reaches Dead, per year. This is the number
       comparable to Hellman's "1 percent per year" and to Tertrais's implied rate ---
       **not** the crisis rate (Section 2.4a).

.. container:: fineprint

   **Why two names for everything.** A symbol is unreadable and a phrase is unusable in an
   equation, so both are needed and the mapping must be explicit rather than inferred. That
   is the whole content of the BEST Names convention :cite:`Loewe2016BestNames`, and this
   paper is a small test of it: a reader should be able to follow the argument in
   Summarizing names alone, check it in Brief names, and connect it to the existing
   literature through the Technical column --- without ever guessing which
   :math:`\lambda` is whose.


.. _oov1-b16-sec2-0a:

2.0a Central Result: The Anchor
---------------------------------

All figures below come from the **exact first-passage distribution** of the model in
Section 2.1 --- not from the Poisson approximation, and not from an exponential fitted to
the mean. The distinction matters and is derived in Section 2.4a. De-escalation rate
:math:`b = 6`/yr, escalation rate :math:`c = 3`/yr, per-crisis death probability
:math:`p_{death} = c/(b+c) = 1/3`.

.. list-table:: Table 3. Waiting times to onset of accidental nuclear winter, by scenario
   :header-rows: 1
   :widths: 22 8 8 8 8 8 8 8 8 14

   * - Scenario
     - crisis rate /yr
     - mean
     - median
     - |leq| 1 yr
     - |leq| 10 yr
     - |leq| 20 yr
     - |leq| 40 yr
     - |leq| 80 yr
     - x car-crash [d]_
   * - optimistic *(= Tertrais)*
     - 0.03
     - 100.3 yr
     - 69.6 yr
     - 0.88%
     - 9.40%
     - 18.00%
     - 32.83%
     - 54.94%
     - **18x**
   * - **base (4-in-40)**
     - **0.10**
     - **30.3 yr**
     - **21.1 yr**
     - **2.90%**
     - **27.91%**
     - **48.22%**
     - **73.28%**
     - **92.89%**
     - **58x**
   * - *(= Lewis et al.)*
     - 0.15
     - 20.3 yr
     - 14.1 yr
     - 4.30%
     - 38.68%
     - 62.60%
     - 86.09%
     - 98.08%
     - 87x
   * - pessimistic
     - 0.30
     - 10.3 yr
     - 7.2 yr
     - 8.34%
     - 61.99%
     - 85.71%
     - 97.98%
     - 99.96%
     - 168x

.. [d] Individual annual mortality is :math:`P(\text{onset} \le 1\text{ yr}) \times q`,
   against the **global** road-death baseline of :math:`1.49\times10^{-4}` per person per
   year (WHO 2023: 1.19 million deaths, ~15 per 100,000) and :math:`q = 0.3`. Earlier
   drafts used the US rate, which is *lower* than the global rate and therefore inflated
   this column; the claim is about most people, so the baseline must be too. Section 2.6
   gives the full ladder, including the worst-affected country on record.

.. admonition:: The exported result

   **Death by accidental nuclear winter is more likely than death by a car crash, for most
   people --- annual, per person, mortality against mortality.** The comparison holds in
   **every** scenario in Table 3, including the most optimistic, which is the most
   sceptical published reading of the historical record (Section 5.3), and where it still
   stands at eighteen times the global road-death baseline.

   Section 2.6 pushes every soft input against this conclusion **simultaneously** --- the
   most sceptical crisis rate, the lowest published death fraction, and the road-death rate
   of the worst-affected country on record rather than the average. The inequality survives
   that too, by threefold.

   No figure in this table is offered as invariant. The claim that is invariant is the
   inequality.

.. danger:: **If you have seen 3.24 percent quoted from this work, it was too high, and it
   was too high in this paper's favour.** Earlier versions computed the |leq| 1 yr column as
   :math:`1 - \exp(-t/T_R)` --- an exponential fitted to the correct mean --- and called the
   result exact. The first-passage law of this model is **hypoexponential** (Section 2.4a),
   and the shortcut overstated every scenario by about 12 percent: the base case was 3.24%
   (1 in 31) and is **2.90% (1 in 34)**. No conclusion changes. It is flagged here, rather
   than only in the changelog, because a reader arriving with the old number needs to know
   why it moved --- and because an approximation labelled "exact", erring toward its own
   thesis, in the number most likely to be quoted, is precisely the failure this paper
   exists to name (Section 2.2, over-Simplify). Full provenance:
   :doc:`what changed between MMv5 and OOv1 </study/matheo/b16/b16-changelog-mmv5-to-oov2>`.

----


.. _oov1-b16-sec2-1:

2.1 Three States, Four Transitions
--------------------------------------

RiskyMAD is a continuous-time Markov chain with three states:

.. figure:: /_file/pdf/gnp/mmv3/supporting-doc/sd1/fig/model-risky-mad-or-madi-decision-overview-iv_llol_qqv2_2026m03d01-fig-white.webp
   :alt: RiskyMAD model overview --- three states (Risky, MAD, Dead) with four transitions
   :width: 100%
   :align: center

   **Figure 1:** The RiskyMAD/MADI decision overview. Three states, four
   transitions. The escape path (Risky |rarr| LifeMAP) is currently inactive
   (rate = 0). Source: :doc:`SD1 </good-news-pack/vv/mmv3/supporting-doc/sd1/index>`.

1. **Risky** --- the current state of global affairs. Nuclear weapons
   exist, are deployed, and are on various levels of alert. No nuclear
   exchange has occurred. The system is metastable: it appears stable
   but has a non-zero probability per unit time of transitioning to the
   next state.

2. **MAD** --- a crisis state in which nuclear exchange becomes
   imminent. This state is transient: the system either escalates to
   Dead or de-escalates back to Risky. The average crisis duration in
   the model is approximately 40 days (consistent with historical
   crises such as the Cuban Missile Crisis, which lasted 13 days).

3. **Dead** --- accidental nuclear winter has been initiated. This state
   is absorbing: once entered, it cannot be left. The consequences of
   even a "limited" nuclear exchange (100+ warheads) include global
   temperature drops of 5--10 |deg|\ C, agricultural collapse, and famine
   affecting billions. The state is named "Dead" not because every
   human dies, but because the civilization that produced nuclear
   weapons has entered irreversible collapse. Limited nuclear exchanges
   that do not trigger global winter are not modeled as "Dead" --- they
   register only as milestones on the path to normalizing nuclear
   weapons enough that a global exchange becomes thinkable enough to
   happen.

The four transitions are:

- **Risky |rarr| MAD** (rate: ``rRiskyGoMAD`` = 0.10/year): a crisis arises
  that brings the system to the nuclear brink.
- **MAD |rarr| Risky** (rate: ``rMADescapes`` = 6/year): the crisis
  de-escalates without nuclear exchange.
- **MAD |rarr| Dead** (rate: ``rMADtoDEATH`` = 3/year): the crisis
  escalates to nuclear exchange and accidental nuclear winter.
- **Risky |rarr| LifeMAP** (rate: ``rRiskyEscape`` = 0): the civilization
  transitions to Mutually Assured Progress. This transition is the
  escape --- but in the base model, the rate is zero (no escape
  mechanism is currently active).


.. _oov1-b16-sec2-2:

2.2 The Death-Trifecta Parameter: Why 1/3
---------------------------------------------

When the system enters a crisis (MAD state), two competing processes
race: de-escalation (rate 6) and escalation to nuclear exchange (rate
3). The probability of death per crisis is therefore 3/(6+3) = **1/3**.

This parameter is not arbitrary. It is grounded in the OSCR mechanism
--- a systems-failure pattern formally derived in :doc:`Matheo-b12 </study/matheo/b12/index>`
(BABL definition and m6.th1, the OSCR Collapse theorem).

**BABL** (Blindly Assuming Blind Leveraging) is a systems-failure
pattern that operates through three modes called the OSCR mechanism:
over-Simplifying (reducing a complex problem to a false narrative),
over-Complicating (burying the problem under layers of work-arounds),
and over-Reaching (extending beyond the point of no return). This
death-trifecta can be shown to invade any complex system, functioning
like a zero-day exploit: it produces the same failure modes regardless
of the system's specific domain. For the formal derivation, see
:doc:`Matheo-b12 </study/matheo/b12/index>`.

Under BABL, a crisis resolves through one of three OSCR modes:

1. **Over-Simplifying** --- the crisis is reduced to a manageable
   narrative ("it was just a misunderstanding"), and the system returns
   to Risky. The underlying tensions are unresolved, merely deferred.

2. **Over-Complicating** --- the crisis generates layers of diplomatic
   work-arounds, and the system returns to Risky. The underlying
   tensions are buried under complexity, merely deferred.

3. **Over-Reaching** --- someone, either by accident, by deliberate
   action, or by not realizing the implications of their orders,
   reaches beyond the point of no return. The RED button is pressed.
   Nuclear exchange begins.

Two out of three OSCR modes produce temporary escape (back to Risky).
One out of three produces death. Hence: ``rMADescapes`` = 6 (two
escape modes, each at rate 3) and ``rMADtoDEATH`` = 3 (one death mode
at rate 3). The factor of 3 sets the crisis time scale.

**The equiprobability of the three OSCR modes is a modeling assumption,
not a derived result.** The three-mode structure is a structural
property of BABL systems (formally derived in :doc:`Matheo-b12 </study/matheo/b12/index>`, BABL
definition and m6.th1); the equal weighting of the three modes is a
simplifying choice. The sensitivity analysis in Section 2.5a shows that
the qualitative conclusion does not depend on this choice.

**The only empirical anchor, and it is a weak one.** President Kennedy, in a private
assessment to his Special Counsel Theodore Sorensen during the Cuban Missile Crisis,
estimated the probability of nuclear war "somewhere between one in three, and even"
(Sorensen, *Kennedy*, Harper & Row, 1965; confirmed in Sorensen's 1986 WGBH interview for
*War and Peace in the Nuclear Age*; widely cited via Allison and Zelikow, *Essence of
Decision*, 2nd ed., Longman, 1999). This is the closest thing to a measurement of
:math:`p_{death}` that exists: one crisis participant's subjective estimate, from inside
one crisis, recorded second-hand. It is a single data point and it does not corroborate the
parameter. It brackets it.

**And the bracket runs both ways, which is the honest way to state this.** Against
Kennedy's range of 1/3 to 1/2, the model's 1/3 is the **low** end --- his midpoint would be
roughly 5/12, and using it would raise every figure in this paper by a quarter. Against the
historical record read through Laplace's rule (Section 2.8), the model's 1/3 is roughly
**3.7x too high** at :math:`n = 4`. So the two available anchors pull in opposite
directions and the chosen value sits between them, closer to the one that produces the
lower forecast of the two. The parameter is not measured. It is bracketed by a subjective
recollection on one side and an estimator with known defects on the other, and the paper
says so rather than picking the flattering anchor and calling it support.

**The precise value does not determine the conclusion.** The model's
parameters can be tuned by adjusting the thresholds: what qualifies as
a "nuclear MAD crisis" and what qualifies as "Dead." The qualitative
conclusion --- stochastic certainty of accidental nuclear winter in
the absence of structural change --- holds across a wide range of
parameter values (see Sections 2.5 and 2.5a).


.. _oov1-b16-sec2-3:

2.3 Calibrating the Crisis Rate
----------------------------------

The critical parameter is :math:`\lambda` (``rRiskyGoMAD``) --- the rate at which
civilization-threatening nuclear crises arise. Everything else in the forecast is either
structural (Section 2.2) or algebra (Section 2.4a); this is the one number that must come
from the world.

**The criterion.** A *civilization-threatening nuclear crisis* --- an entry into the MAD
state --- is any incident in which at least one nuclear-armed party's command authority
was confronted with a launch/no-launch decision, or in which nuclear weapons were
physically brought to the brink of detonation. This criterion was fixed **before**
counting and is applied unchanged below. That order matters: a criterion adjusted after
seeing the count is not a measurement.

**The source.** Rather than assemble a private list, this paper calibrates against the
largest published catalogue: the 60 historical incidents compiled by Baum, de Neufville
and Barrett (2018) :cite:`Baum2018`. Using someone else's data removes one degree of freedom from an
exercise that has too many. The classification below is this paper's own and is the part
a reader should attack first; the underlying incidents are not.

**Incidents are not excursions.** This distinction does most of the work and is easy to
miss. Six of Baum et al.'s sixty entries belong to the *same* Cuban missile crisis: the
crisis itself, the Duluth--Volk bear incident, the B-59 submarine, the Okinawa missile
order, the Florida satellite false alarm, and the Penkovsky false warning. The parameter
:math:`\lambda` counts **entries into the MAD state**, not incidents, so those six
contribute **one**. Lewis et al. (2014) :cite:`Lewis2014` independently list four separate Cuban-crisis
entries, which corroborates the distinction from outside this paper. A catalogue of sixty
incidents therefore does not imply sixty crises, and any calibration that treats it as
one will overstate :math:`\lambda` by roughly an order of magnitude.

**What the classification returns.** Of the sixty incidents, **twenty-seven are excluded
as peripheral** --- nuclear threat rhetoric, contingency studies, failed acquisition
attempts by non-state actors, and weapons accidents with no live launch pathway. A
further **twenty-three are serious but were caught by procedure** rather than by human
judgment or luck; these are the subject of Table 2. The remainder, after collapsing the
Cuban-crisis entries, are the five excursions of Table 1 --- of which **four fall inside
the forty Cold-War years**, giving

.. math::

   \lambda \;\approx\; \frac{4}{40} \;=\; 0.1 \text{ per year}

**On the composition of "the four".** Published and popular lists of the most widely
acknowledged near-misses do not agree on membership: this paper's reconstruction, the
lists circulating in popular accounts, and Lewis et al.'s Table 1 select different events.
That disagreement is real and is the subject of Table 2. It does not make the count
worthless. Four Cuba-grade excursions in the forty Cold-War years is what this
reconstruction returns from someone else's dataset, under a criterion fixed in advance ---
and an independent expert count, obtained by personal communication and by a different
route, returns the same number.




.. list-table:: Table 1. Historical entries into the MAD state, 1945--2026
   :header-rows: 1
   :widths: 5 7 18 38 20 12

   * - #
     - Year
     - Event
     - Explanation --- what actually happened
     - Why it qualifies
     - Cold War?
   * - 1
     - 1961
     - Berlin Crisis [c]_
     - The USSR demanded Western forces leave West Berlin. In October, Kennedy considered a
       first strike: a White House/Pentagon group produced a detailed plan to destroy Soviet
       second-strike capability by attacking 1,077 targets, after intelligence showed a much
       larger US arsenal than believed. He gave a speech instead.
     - a disarming first-strike plan reached the President's desk
     - yes
   * - 2
     - 1962
     - **Cuban Missile Crisis**
     - The reference event. Thirteen days. Internally it contains at least five further
       incidents (see note below), including the B-59 submarine, whose captain ordered the
       nuclear torpedo prepared and was overruled by Vasili Arkhipov.
     - launch decisions reached officers with authority; refusal, not procedure, stopped them
     - yes
   * - 3
     - 1983
     - Petrov (Serpukhov-15) [a]_
     - Soviet satellites indicated an incoming US missile launch. Duty officer Stanislav
       Petrov judged it a false alarm and declined to report it. He was right: sunlight on
       high cloud.
     - a launch indication reached a human whose judgment was the filter
     - yes
   * - 4
     - 1983
     - Able Archer
     - A realistic NATO command exercise simulating nuclear release, during a period when
       Soviet leadership feared a genuine first strike. Soviet leadership moved to bunkers;
       nuclear bombers went to runway alert.
     - Baum: "how close they were to launching their own attack is unclear"
     - yes
   * - 5
     - 1995
     - Norwegian Rocket
     - A Norwegian scientific rocket matched the flight profile of a submarine-launched
       missile intended to blind Russian radar by EMP. Russian forces went to full alert and
       Yeltsin activated the nuclear command suitcase --- the only confirmed activation.
     - launch authority was physically engaged by a head of state
     - no
   * - --
     - 1945
     - World War II [b]_
     - The atomic bombings of Hiroshima and Nagasaki: the only historical instance of nuclear
       war.
     - **excluded from the rate** --- see [b]_
     - --

.. [a] **Petrov --- retained, with the reservation recorded.** On Baum's text alone, roughly
   five missiles were indicated, which is implausible for a first strike, and downstream
   corroboration would very likely have failed; on a strict reading the decision never
   reached release authority. He is retained because he is among the most widely
   acknowledged near-misses and because Lewis et al. (2014) independently include him
   (Serpukhov-15, Table 1). **The forecast does not depend on him:** excluding Petrov gives
   three Cold-War excursions, a crisis rate of 0.075/yr, and an annual onset probability of
   2.19 percent --- 1 in 46.

.. [b] **World War II --- excluded from the rate, and why it is nonetheless in the table.**
   It was a one-sided use, not an entry into the two-sided crisis state this model tracks,
   so it is not an observation of :math:`\lambda`. What it establishes is not a probability
   but a **capability**: that these weapons were in fact deployed against whatever
   objections stood in the way at the time. The model assumes :math:`c > 0`. World War II is
   the observation that :math:`c > 0` is not a hypothesis.

.. [c] **Berlin 1961 is this paper's own addition** and is not in Lewis et al.'s list. It is
   included because a live disarming-first-strike plan reaching a head of state meets the
   criterion in Section 2.3 more directly than several incidents that are conventionally
   listed. A reader who rejects it should use the three-excursion row above.

----



How many incidents count as near nuclear use is contested in the published literature, and
Baum names the dispute: *"analysts disagree on how close they were to nuclear war --- for
example, Lewis et al. (2014) consider them to have come pretty close, while Tertrais (2017)
disagrees."* Rather than adjudicate it, this paper reports both poles and shows what each
implies.

.. list-table:: Table 2. What the two published poles imply for :math:`\lambda`
   :header-rows: 1
   :widths: 20 10 34 24 12

   * - Position
     - Count
     - Explanation --- what they counted
     - :math:`\lambda` (/yr)
     - P(onset |leq| 1 yr)
   * - **Tertrais (2017)**, skeptical
     - 1
     - 37 episodes reviewed; concludes safety mechanisms held throughout, and that only one
       significant incident has occurred in ~34 years (Black Brant, 1995). Excludes
       accidents, unauthorized launch, and terrorism by stated scope.
     - **0.029**
     - 0.85% (1 in 117)
   * - **This paper**, Table 1
     - 4 (Cold War)
     - Berlin 1961, Cuba 1962, Petrov 1983, Able Archer 1983; criteria fixed before counting;
       Norwegian Rocket 1995 falls outside the Cold-War window.
     - **0.100**
     - 2.90% (1 in 34)
   * - **Lewis et al. (2014)**, inclusive
     - 6 (Cold War)
     - Their Table 1 lists 13 cases of near nuclear use; collapsed to excursions (four of the
       thirteen are Cuban-crisis entries) this gives six Cold-War excursions: Cuba 1962, the
       1973 Arab--Israeli war, NORAD 1979, NORAD 1980, Serpukhov-15 1983, Able Archer 1983.
     - **0.150**
     - 4.30% (1 in 23)
   * - **Lewis et al.**, whole era
     - 10 / 77 yr
     - Adds the 1991 Soviet coup, Black Brant 1995, Kargil 1999, and the 2001--02 Kashmir
       standoff.
     - **0.130**
     - 3.75% (1 in 27)

Three things follow, and the second is the one that matters.

**The scenario range of Section 2.5 contains both published poles.** The optimistic corner
(0.03/yr) is Tertrais's implied rate. The pessimistic corner (0.3/yr) lies above Lewis et
al.'s --- it is not supported by either pole and rests instead on the non-stationarity
argument of Section 2.10, where it is argued rather than cited.

**This paper's base case is more conservative than Chatham House.** Lewis et al.'s reading
implies 1 in 23 per year; the base case used here is 1 in 34. A paper that adopted the most
inclusive published position wholesale would forecast a *higher* risk than this one does.
Whatever else this forecast is, it is not the most alarming reading available in the
literature.

**The disagreement is narrower than it looks.** The two poles are separated by a factor of
about five in :math:`\lambda` --- and, because the anchor of Section 2.0a is robust across
that whole span, they are not separated at all on the question the paper actually asks. See
Table 3.


----


.. _oov1-b16-sec2-4:

2.4 The Model Code and Simulation Results
---------------------------------------------

The RiskyMAD model was implemented in the Evolvix prototype compiler
(MMv0r3p1-RC1) and run as a stochastic simulation using the Gillespie
algorithm (Gillespie, 1977) --- the standard method for exact stochastic
simulation of continuous-time Markov chains.

**The complete model code** (as published on the
:doc:`SD1 poster </good-news-pack/vv/mmv3/supporting-doc/sd1/index>`):

.. code-block:: text

   Evolvix Quest RiskyMADdead
   (Question: "How many years until humanity self-destructs
               in a nuclear roulette accident?")

   Simulate stochastically until 200 :["years"]

   Initial Amount of Risky       = 1
   Initial Amount of MAD         = 0
   Initial Amount of Dead        = 0
   Initial Amount of rRiskyGoMAD = 0.10
   Initial Amount of rMADescapes = 6
   Initial Amount of rMADtoDEATH = 3

   Action 1 ( Risky ---[ Rate = 0.10 ]---> MAD     )
   Action 2 ( MAD   ---[ Rate = 6    ]---> Risky   )
   Action 3 ( MAD   ---[ Rate = 3    ]---> Dead    )
   Action 4 ( Risky ---[ Rate = 0    ]---> LifeMAP )

This is the entire model. In other simulation frameworks, implementing
a continuous-time Markov chain with Gillespie dynamics requires hundreds
of lines of code. In Evolvix, the model fits on a poster. Anyone who
can read the code can check the math. The Evolvix prototype compiler is
available for download at
:doc:`/good-news-pack/vv/mmv3/supporting-doc/evx-compiler/index`.

**Simulation results** (40 independent stochastic runs per scenario):

.. figure:: /_file/pdf/gnp/mmv3/supporting-doc/sd1/fig/forecast-mad-nuke-winter-stochastic-inevitability-michaelis-menten-iv_llol_qqv2_2026m03d02-fig.webp
   :alt: Stochastic inevitability of accidental nuclear winter --- simulation results across parameter range
   :width: 100%
   :align: center

   **Figure 2:** Stochastic inevitability of accidental nuclear winter.
   Forty simulation runs for each parameter scenario. In the most
   optimistic scenario, the luckiest runs reach ~329 years. In the most
   pessimistic, the fastest runs produce accidental nuclear winter
   within days. The argument holds equally whether the waiting time is
   4 days or 3 centuries. Source:
   :doc:`SD1 </good-news-pack/vv/mmv3/supporting-doc/sd1/index>`.

.. list-table:: Simulation Results Summary (40 runs per scenario)
   :header-rows: 1
   :widths: 15 15 12 12 12 12 22

   * - Scenario
     - ``rRiskyGoMAD``
     - Median
     - Mean
     - Min
     - Max
     - Key finding
   * - Pessimistic
     - 0.3/year
     - ~6.4 yr
     - ~10 yr
     - 0.01 yr
     - 36 yr
     - Fastest runs: accidental nuclear winter within days
   * - **Base**
     - **0.1/year**
     - **~19 yr**
     - **~33 yr**
     - **0.37 yr**
     - **127 yr**
     - **Accidental nuclear winter within a generation**
   * - Optimistic
     - 0.03/year
     - ~51 yr
     - ~96 yr
     - 0.57 yr
     - 329 yr
     - Luckiest runs reach ~329 years; median still within a lifetime


.. _oov1-b16-sec2-4a:

2.4a Analytic Solution: Mean Time to Absorption
-------------------------------------------------

The simulation is not the only handle on this model. The chain is small enough to solve
exactly, and doing so both supplies the waiting times this paper reports and retires a
standing objection.

Let :math:`T_R` and :math:`T_M` be the expected times to reach Dead from Risky and from
MAD. Conditioning on the next transition:

.. math::

   T_M &= \frac{1}{b+c} + \frac{b}{b+c}\, T_R \\
   T_R &= \frac{1}{\lambda} + T_M

Solving the pair:

.. math::

   \boxed{\; T_R \;=\; \frac{b+c}{\lambda\, c} \;+\; \frac{1}{c} \;}

At the base crisis rate of 0.1/yr, with :math:`b = 6` and :math:`c = 3`:
:math:`T_R = 9/0.3 + 1/3 = 30.3` years.

**But the mean is not the distribution, and the difference matters at short horizons.**
Reporting :math:`P(\text{onset} \le t)` requires the whole first-passage law, not
its average. Taking the Laplace transform of the same conditioning argument, with
:math:`f_R(s) = \mathbb{E}[e^{-sT_R}]`:

.. math::

   f_R(s) \;=\; \frac{\lambda}{\lambda+s}\cdot\frac{b\,f_R(s)+c}{b+c+s}
   \qquad\Longrightarrow\qquad
   \boxed{\; f_R(s) \;=\; \frac{\lambda c}{s^{2} + s(\lambda+b+c) + \lambda c} \;}

The denominator factorises as :math:`(s+r_1)(s+r_2)` with :math:`r_1 r_2 = \lambda c` and
:math:`r_1 + r_2 = \lambda + b + c`. Since the transform is exactly
:math:`r_1 r_2 / [(s+r_1)(s+r_2)]`, the waiting time is **hypoexponential** --- the sum of
two independent exponentials, not one:

.. math::

   T_R \;\sim\; \mathrm{Exp}(r_1) + \mathrm{Exp}(r_2),
   \qquad
   P(T_R \le t) \;=\; 1 - \frac{r_2 e^{-r_1 t} - r_1 e^{-r_2 t}}{r_2 - r_1}

At the base rate: :math:`r_1 = 0.0331`/yr (**the onset hazard** --- the slow stage, the
wait for a crisis to arrive and escalate) and :math:`r_2 = 9.067`/yr (the fast stage, the
crisis itself, mean duration 40 days). Every figure in Table 3 comes from this expression.

.. container:: fineprint

   **Why this matters only at one year, and why it matters there.** The fast stage
   contributes a mean delay of about forty days before onset is even possible, which
   suppresses the distribution near the origin. Over ten years or more the suppression is
   negligible and an exponential fitted to :math:`T_R` agrees to within 0.2 percentage
   points --- which is why the longer columns of Table 3 barely moved. At **one year** the
   forty days are 11 percent of the window, and the exponential shortcut overstates the
   answer by ~12 percent in every scenario: 3.24% against the true 2.90% at base. The
   one-year figure is the one everybody quotes. The shortcut erred there, and it erred
   upward.

**The structure answers the "loop" objection.** It is sometimes put to this model that the
de-escalation path MAD :math:`\rightarrow` Risky :math:`\rightarrow` MAD gives the world
repeated chances to survive, and that a forecast ignoring those chances must overstate the
risk. The objection is reasonable and the mathematics has already answered it. The factor

**The structure is interpretable, and it answers the "loop" objection.** It is sometimes
put to this model that the de-escalation path MAD :math:`\rightarrow` Risky
:math:`\rightarrow` MAD gives the world repeated chances to survive, and that a forecast
which ignores those chances must overstate the risk. The objection is reasonable and the
mathematics has already answered it. The factor

.. math::

   \frac{b+c}{c} \;=\; \frac{1}{p_{death}} \;=\; 3

is exactly the expected number of excursions into MAD before one escalates --- a
geometric process with per-crisis death probability :math:`p_{death} = c/(b+c) = 1/3`,
hence a mean of three attempts. Each attempt is preceded by an average wait of
:math:`1/\lambda = 10` years in Risky. So :math:`T_R \approx 3 \times 10` years. **The
de-escalation loop is not omitted from the mathematics: it is the factor of three.** The
world does get another chance, and the model counts every one of them.

**The Poisson form is checked, and it holds --- as a rate.** The onset hazard from the exact
solution is :math:`r_1 = 0.0331`/yr; the Poisson rate :math:`\lambda \cdot p_{death} =
0.0333`/yr. They agree to within 1 percent, because time spent inside a crisis slightly
delays the onset of the next one. **What does not follow is that either rate may be fed
into** :math:`1 - \exp(-rt)` **to obtain a one-year probability.** That is the step the
hypoexponential form above forbids: a rate is not a distribution when the process has two
stages and the horizon is comparable to the short one. The agreement of the rates is real;
the shortcut it appears to license is not.


.. _oov1-b16-sec2-5:

2.5 Worst, Mid and Best: Running World History Forward
------------------------------------------------------

.. admonition:: Central Result
   :class: important

   **At the base crisis rate, half of all runs of world history reach accidental nuclear
   winter within 21 years.** The annual probability that it *begins* is **2.90 percent ---
   about 1 in 34** --- and across the full scenario range it lies between roughly 1 percent
   and 8 percent. That range is a bound, and the bound is the result.

   **The simulation findings hold. The arithmetic sharpens them.** Forty independent runs of
   world history returned a median near 19 years, and roughly one run in forty reached
   catastrophe inside the first year. Solving the model exactly (Section 2.4a) puts the
   median at **21.1 years** and predicts **1.16** blow-ups per forty runs. Both simulated
   figures sit within ordinary sampling noise of the exact ones. Nothing here overturns what
   the simulations showed; it measures the same thing with a finer instrument, and the
   finer instrument reads **slightly worse**, not better.

   **The paper's earlier "at least 1 in 40" formulation was close, and errs in one place
   only.** As a floor on the annual probability it holds at the base rate (2.90 percent) and
   in the pessimistic scenario (8.34 percent). It **over-states** the risk at the optimistic
   corner, where the exact value is 0.88 percent --- 1 in 113. That is the honest correction:
   the formulation was right where it mattered and too pessimistic at the best-case end.

   **One claim does not survive, and it should never have been made:** that 1-in-40 held
   *regardless of scenario*. It does not. The expected number of blow-ups per forty runs is
   0.35 optimistic, 1.16 base, 3.34 pessimistic --- a spread of nearly ten. **A uniform
   1-in-40 was never a result of this model**; it was a tidy-looking summary that a hedged
   statement collapsed into somewhere between the simulations and the prose, and it is
   removed here rather than defended.

**Two instruments, two jobs.** This section reports simulations and arithmetic, and they
are not doing the same work, and keeping them apart is what makes each of them useful.

- The **simulations** run world history forward and return *waiting times*. They are the
  right instrument for the shape of the distribution --- the medians, the long tails, the
  fact that some runs last a century. That shape is what Section 2.7 rests on.
- The **arithmetic** returns the *annual probability*. It is exact and closed-form. Forty
  runs cannot resolve a 3 percent probability --- the standard error on such an estimate at
  :math:`n = 40` is about 2.5 percent, which is nearly the estimate itself --- so the
  simulations are simply the wrong tool for that number, and no re-run would change this.

They agree, and the agreement is now reportable rather than hedged: see below.


**What was simulated.** Forty independent runs of world history per scenario, generated
with the Evolvix prototype compiler
(:doc:`download </good-news-pack/vv/mmv3/supporting-doc/evx-compiler/index>`), which
implements the stochastic simulation algorithm exactly (Gillespie, 1977; Ehlert & Loewe,
2014, "Lazy Updating," *J Chem Phys* 141(20): 204109). Each run produces one random
waiting time until accidental nuclear winter.

.. figure:: /_file/pdf/gnp/mmv3/supporting-doc/sd1/fig/forecast-mad-nuke-winter-stochastic-inevitability-michaelis-menten-iv_llol_qqv2_2026m03d02-fig.webp
   :alt: Stochastic inevitability of accidental nuclear winter --- forty simulation runs for each of the three scenarios
   :width: 100%
   :align: center

   **Figure 2:** Forty runs of world history for each scenario --- optimistic, base, and
   pessimistic. In the most optimistic, the luckiest run reaches ~329 years. In the most
   pessimistic, the fastest runs produce accidental nuclear winter within days. **The
   argument holds equally whether the waiting time is four days or three centuries** ---
   which is the point of showing all three. Source:
   :doc:`SD1 </good-news-pack/vv/mmv3/supporting-doc/sd1/index>`.

.. list-table:: Table 4. What the simulations returned (40 runs per scenario)
   :header-rows: 1
   :widths: 18 14 12 12 12 12 20

   * - Scenario
     - crisis rate
     - median
     - mean
     - fastest run
     - slowest run
     - What the runs show
   * - Optimistic
     - 0.03/yr
     - ~51 yr
     - ~96 yr
     - 0.57 yr
     - 329 yr
     - Luckiest run reaches three centuries; median still inside one lifetime
   * - **Base**
     - **0.10/yr**
     - **~19 yr**
     - **~33 yr**
     - **0.37 yr**
     - **127 yr**
     - **Onset within a generation, with a century-long tail**
   * - Pessimistic
     - 0.30/yr
     - ~6.4 yr
     - ~10 yr
     - 0.01 yr
     - 36 yr
     - Fastest runs produce accidental nuclear winter within days

.. list-table:: Table 5. What the arithmetic returns (exact, Section 2.4a)
   :header-rows: 1
   :widths: 20 10 10 10 10 10 10 10

   * - Scenario
     - crisis rate
     - mean
     - median
     - |leq| 1 yr
     - |leq| 10 yr
     - |leq| 20 yr
     - |leq| 40 yr
   * - optimistic *(= Tertrais)*
     - 0.03
     - 100.3 yr
     - 69.6 yr
     - 0.88%
     - 9.40%
     - 18.00%
     - 32.83%
   * - **base**
     - **0.10**
     - **30.3 yr**
     - **21.1 yr**
     - **2.90%**
     - **27.91%**
     - **48.22%**
     - **73.28%**
   * - *(= Lewis et al.)*
     - 0.15
     - 20.3 yr
     - 14.1 yr
     - 4.30%
     - 38.68%
     - 62.60%
     - 86.09%
   * - Petrov removed *(§7.1b)*
     - 0.075
     - 40.3 yr
     - 28.0 yr
     - 2.19%
     - 21.8%
     - 39.0%
     - 62.9%
   * - pessimistic
     - 0.30
     - 10.3 yr
     - 7.2 yr
     - 8.34%
     - 61.99%
     - 85.71%
     - 97.98%

**The two tables agree, and the agreement is checkable.** At the base rate the exact
one-year probability is 2.90 percent, so the expected number of the forty runs that blow up
inside the first year is :math:`40 \times 0.0290 = 1.16`. Observing one or two such runs is
the ordinary outcome --- :math:`P(X \ge 2) = 32` percent. The simulated medians sit below
the exact ones (~19 against 21.1 at base) by an amount that is unremarkable at :math:`n=40`.
**There is no tension between the two instruments, and the appearance of one in earlier
drafts was manufactured by the exponential shortcut** the previous section retired: it
inflated the arithmetic to 3.24 percent and left the simulations looking as though they
disagreed. They never did.

.. container:: fineprint

   **On the 127-year run.** The slowest of the forty base-case runs reached 127 years. That
   is an observed sample maximum, not a probability: the exact chance of exceeding 127 years
   at the base rate is 1.50 percent, or about 1 in 67, and the *expected* maximum of forty
   draws falls near 112 years. "Roughly one run in forty survives past 127 years" would read
   as a distributional claim and is not one. The run is quoted here only for what it shows: that this model produces century-long quiet stretches as a matter
   of course (Section 2.7).

**What a 1-in-34 annual probability means.** No regulator, no underwriter, and no
operator of any other system accepts a 3 percent annual chance of catastrophic,
irreversible failure. This one is accepted --- not through informed consent, and not
because anyone weighed it and judged it tolerable, but because almost nobody has been shown
the number. Section 2.6 puts it beside a risk that societies *have* weighed and do accept.
.. _oov1-b16-sec2-5a:

2.5a Sensitivity Analysis: Death Probability
-------------------------------------------------

The base model uses a per-crisis death probability of 1/3, grounded in the OSCR three-mode
structure (Section 2.2). The equiprobability of the three modes is a modelling assumption,
and Section 7.3 states plainly that it is the weakest joint in this paper. This table shows
what happens when it is varied, holding the crisis rate at its base value of 0.1/yr.

.. list-table:: Table 9. Sensitivity to the per-crisis death probability
   :header-rows: 1
   :widths: 16 22 14 14 16 18

   * - per-crisis death prob.
     - implied rates
     - mean
     - median
     - P(onset |leq| 1 yr)
     - x car-crash
   * - 1/10
     - ``rMADescapes`` = 27, ``rMADtoDEATH`` = 3
     - 100.3 yr
     - 69.6 yr
     - 0.96%
     - 19x
   * - 1/5
     - ``rMADescapes`` = 12, ``rMADtoDEATH`` = 3
     - 50.3 yr
     - 34.9 yr
     - 1.84%
     - 37x
   * - **1/3 (base case)**
     - ``rMADescapes`` **= 6,** ``rMADtoDEATH`` **= 3**
     - **30.3 yr**
     - **21.1 yr**
     - **2.90%**
     - **58x**
   * - 1/2 *(= Kennedy's upper end)*
     - ``rMADescapes`` = 3, ``rMADtoDEATH`` = 3
     - 20.3 yr
     - 14.1 yr
     - 4.05%
     - 82x

.. container:: fineprint

   **These are exact values.** A 40-run sample would put the base-case median near 19 years
   against the exact 21.1, and the 1/10 row near 57 against 69.6 --- ordinary noise, but
   there is no reason to quote a noisy sample when a closed form exists (Section 2.5). Every
   figure above comes from the first-passage law of Section 2.4a. The car-crash column uses
   the global baseline and :math:`q = 0.3` (Section 2.6).

**The parameter moves the waiting time, not the direction.** Across the whole range ---
from a tenth to a half, which spans every value anyone has proposed, including both ends of
Kennedy's estimate --- the mean wait moves by a factor of five and the car-crash comparison
never falls below **19x**. Even at 1/10, a value **below** anything this paper's structure
or its anecdotal anchor suggests, an individual remains an order of magnitude more likely to
die of accidental nuclear winter than in a car crash.

**And stochastic certainty holds for any death probability above zero.** Whether the value
is 1/10 or 1/2, the absorbing state is reached with probability 1 given sufficient time
(Section 2.9). The parameter sets the schedule. It does not set the outcome.


.. _oov1-b16-sec2-6:

2.6 Contextualizing the Risk: The Car-Crash Baseline
-------------------------------------------------------

To make the forecast tangible, it is compared against a mortality risk that societies
accept without alarm: dying in a motor-vehicle crash. The comparison must be like-for-like
--- **annual probability, per person, death against death** --- or it is meaningless. Three
quantities are therefore kept distinct throughout.

**The baseline.** Worldwide, road traffic kills about **1.19 million people a year**, a
rate of roughly **15 per 100,000 population**, or :math:`1.49\times10^{-4}` per person per
year --- about 1 in 6,700 :cite:`WHO2023RoadSafety`. This paper uses the **global** figure,
because its claim is about most people. The United States rate
(:math:`1.22\times10^{-4}`; 40,901 deaths at 12.21 per 100,000 in 2023 :cite:`NHTSA2024`)
is *lower* than the global average, so using it would inflate every multiplier below ---
which is the direction a reader should expect a motivated author to choose, and the reason
not to.

**The model's output is not a mortality.** RiskyMAD forecasts the annual probability that
accidental nuclear winter *begins* --- not the probability that any given individual dies.
The two differ by the death fraction

.. math::

   q \;=\; P(\text{individual dies} \mid \text{nuclear winter begins})

driven by global cooling, agricultural collapse, and famine. Individual annual mortality
is therefore :math:`P(\text{onset}) \times q`, and it is this product --- not
:math:`P(\text{onset})` --- that may be set beside the road-death figure. Conflating the
two would overstate the comparison by a factor of :math:`1/q`.

**Where** :math:`q` **comes from.** It is not this model's output and is not invented here.
Xia et al. (2022) estimate that even a *small* regional exchange --- roughly 100 warheads,
5 Tg of soot --- causes about **2 billion** deaths from famine within two years, while a
full US--Russia exchange (150 Tg) causes **over 5 billion** :cite:`Xia2022`. Against a
world population near 8 billion those are :math:`q \approx 0.25` and :math:`q \approx 0.63`.
This paper uses :math:`q = 0.3`, near the **low** end of that published range and
corresponding to the smallest exchange anyone models.

.. list-table:: Table 6. Individual annual mortality against the global road-death baseline
   :header-rows: 1
   :widths: 30 16 24 30

   * - Scenario
     - P(onset |leq| 1 yr)
     - Individual mortality
     - Relative to road deaths
   * - optimistic (= Tertrais's implied rate)
     - 0.88%
     - :math:`2.6 \times 10^{-3}`
     - **18x**
   * - **base**
     - **2.90%**
     - :math:`8.7 \times 10^{-3}`
     - **58x**
   * - Lewis et al.'s implied rate
     - 4.30%
     - :math:`1.3 \times 10^{-2}`
     - 87x
   * - pessimistic
     - 8.34%
     - :math:`2.5 \times 10^{-2}`
     - 168x

**The stress test.** Three inputs to that table are chosen rather than measured: the crisis
rate, the death fraction, and the baseline. A reader is entitled to suspect that three
choices all landing in the paper's favour is not a coincidence. So each is pushed to its
least favourable defensible value **at the same time**:

.. list-table:: Table 7. Every soft input pushed against the conclusion, simultaneously
   :header-rows: 1
   :widths: 26 30 44

   * - Input
     - Least favourable defensible value
     - Why that value is admissible
   * - crisis rate
     - **0.03/yr** (P = 0.88%)
     - Tertrais's own reading of the record --- the most sceptical published position
       (Section 5.3)
   * - death fraction :math:`q`
     - **0.25**
     - Xia et al.'s *smallest* modelled exchange, 100 warheads :cite:`Xia2022`
   * - baseline
     - **7.3e-4/yr**
     - Libya, ~73.4 per 100,000 (2013) --- **the highest national rate on record**, nearly
       five times the global average :cite:`WHO2015RoadSafety` :cite:`GuinnessRoadDeath`

.. admonition:: What survives the stress test

   Against the **global** baseline, with the most sceptical crisis rate and the lowest
   published death fraction: **15x**.

   Against the road-death rate of **the worst-affected country on record** --- Libya, at
   nearly five times the global average --- with those same two concessions: **3x**.

   **The inequality holds at every corner, including all three corners at once.** It is not
   rescued by any single input, and it cannot be attacked by disputing any single input.
   That is the claim this paper defends. The multiplier is a range --- roughly threefold at
   the most punishing corner constructible, sixtyfold at the base case, a few hundredfold
   at the pessimistic one. The *direction* does not move.

.. container:: fineprint

   **On the worst-country figure.** The baseline used here is the highest national
   road-death rate on record --- Libya at **73.4 per 100,000** in 2013, reported in WHO's
   *Global status report on road safety 2015* :cite:`WHO2015RoadSafety` and recorded by
   Guinness World Records as the world's deadliest place to travel by road
   :cite:`GuinnessRoadDeath`. It is chosen deliberately as the most demanding baseline the
   record supports: a *higher* road-death rate makes the car-crash comparison *harder*, so
   surviving against it is the strongest form of the claim. Libya's more recent WHO figure
   is lower (~34 per 100,000, 2021 :cite:`WHOLibya`), and national rankings shift year to
   year --- nothing here turns on Libya being worst *today*, only on 73.4 being a real,
   documented maximum. At the current ~34 the multiplier would be *larger* (about 6.5x
   rather than 3x), so this choice is the conservative one.

**The scope switch, and why the number of billions does not matter.** Individual annual
mortality is the **only axis on which these two risks are commensurable**, which is why the
comparison runs there. On every other axis they differ, and every difference runs the same
way. A car crash is **idiosyncratic**: it kills you and perhaps a few others; the world
continues; an insurer pays; your family is compensated; the institutions that investigate
the crash still exist the next morning. Nuclear winter is **systemic**: it kills you, and
everyone you know, and the institutions, and the counterparty, and the investigator.

This is why nothing in the argument depends on whether the toll is one billion or eight.
At :math:`q = 0.25` the inequality holds; at :math:`q = 1` it holds; only the multiplier
moves. And the *character* of the risk --- perfectly correlated across the whole
population, with no surviving counterparty --- is identical at every :math:`q > 0`. A
reader who wants to argue about the billions is arguing about a number the conclusion does
not use.

.. admonition:: The risk is not unpriced. It was priced, and the price was "uninsurable."

   It is tempting to call this risk "uninsured, unregulated, unpriced", as though through
   oversight. That would be wrong, and the truth is stronger.

   Nuclear war is excluded from essentially every insurance policy written --- property,
   casualty, life --- by a standard **nuclear exclusion clause** :cite:`GAO2008NBCR`.
   Not because the risk is small. Because it is **uninsurable in principle**: insurance
   requires risks that are independent, so that a pool can absorb them, and a solvent
   counterparty who survives to pay. Nuclear winter violates both, by construction. The
   United States Treasury told Congress as much: war insurance "is not a feasible means for
   handling war losses of the magnitude which might be expected in a nuclear conflict."

   **So the profession that prices catastrophic risk for a living has already examined this
   one and declined it.** That is not ignorance --- it is a decision, taken decades ago, and
   documented in the fine print of nearly every policy on Earth. The risk is not unpriced.
   It is priced at infinity, and then not spoken of again.

   The inequality in Table 6 is therefore not a claim that actuaries have missed something.
   It is a claim about what happens when a risk is *removed from the domain where risk
   expertise operates*: it stops being measured, and then it stops being mentioned, and
   then people conclude from the silence that it is small.

   The pattern is visible in the government's own record. When the United States asked
   whether nuclear, biological, chemical and radiological attacks were insurable, the
   resulting review :cite:`GAO2008NBCR` catalogued the exclusions and the potential for
   catastrophic loss --- the *severity* side --- but did not estimate how *likely* such an
   event is; frequency was treated as outside the question. Set that beside an age that
   funds sky-surveys to put numbers on asteroid-impact probabilities: for nuclear war the
   risk apparatus returns a severity verdict, "uninsurable," and leaves the likelihood
   unasked. That unasked question --- how often --- is the one this study answers.

.. note:: **On the distinction between the exchange and the winter.** A nuclear exchange
   between two states might kill millions directly. The subsequent nuclear winter ---
   global cooling, agricultural collapse, famine --- is what kills billions. The winter,
   not the exchange, is the mass killer, which is why the model treats nuclear winter as
   the absorbing state rather than weapon launch. This also means the estimate here is
   **not** comparable to forecasts whose terminal event is a launch (Section 5.2): the
   states being forecast are different, and the difference runs in the direction of a
   broader, later, and more consequential threshold.

.. caution:: **:math:`q` is the softest number in this paper, and it is doing real work.**
   Every figure in Table 6 scales linearly with it. It is anchored to Xia et al.
   :cite:`Xia2022` rather than derived here, and the anchoring is coarse: their scenarios
   are specific exchanges, and this model's absorbing state is not resolved to a warhead
   count. A reader who prefers a different :math:`q` may rescale Table 6's final column
   directly. The inequality against the global baseline survives for any
   :math:`q > 0.017` --- computed at the **optimistic** corner, which is the one this paper
   leans on, and roughly fifteen times below the lowest published estimate. Note that the
   threshold must be computed at that corner: taken at the base case it would read
   :math:`q > 0.004`, which does not hold where the paper actually leans.


.. _oov1-b16-sec2-7:

2.7 The Mechanism: Michaelis--Menten Kinetics
-----------------------------------------------

The preceding sections produce a number. This section gives the reason the number has
the shape it does. It earns its space because the mechanism answers an objection that
no amount of arithmetic can reach: *nothing has happened in eighty years, so how bad
can it be?*

**The claim, stated precisely.** The scheme Risky :math:`\rightleftharpoons` MAD
:math:`\rightarrow` Dead is not merely *reminiscent* of enzyme kinetics. Solving its own
first-passage equations (Section 2.4a) for the rate at which the chain reaches Dead
gives

.. math::

   v(\lambda) \;=\; \frac{1}{T_R} \;=\; \frac{\lambda\, c}{\lambda + b + c}

which is **identical, at every point**, to the Michaelis--Menten rate law

.. math::

   v \;=\; \frac{V_{max}\, S}{K_m + S}

under the reading below. This is not an analogy that holds approximately in a limit. It
is the same function.

.. list-table:: The dictionary
   :header-rows: 1
   :widths: 26 40 14 20

   * - Michaelis--Menten
     - RiskyMAD
     - Value
     - Meaning here
   * - substrate :math:`S`
     - crisis rate :math:`\lambda`
     - 0.1/yr
     - how often the world enters a nuclear crisis
   * - :math:`K_m`
     - :math:`b + c`
     - 9/yr
     - how fast a crisis resolves, either way
   * - :math:`V_{max}`
     - :math:`c`
     - 3/yr
     - the escalation step --- **you cannot die faster than this**
   * - :math:`k_{cat}/K_m`
     - :math:`V_{max}/K_m = c/(b+c)`
     - 1/3
     - the specificity constant
   * - commitment to catalysis
     - :math:`p_{death} = c/(b+c)`
     - 1/3
     - the fraction of crises that go all the way

The defining property of Michaelis--Menten kinetics holds **exactly**: the rate is
half-maximal when :math:`S = K_m`. Here :math:`v(9) = 1.5 = V_{max}/2`. And the system
saturates: as :math:`\lambda \rightarrow \infty`, :math:`v \rightarrow c`. That ceiling
is not a mathematical curiosity --- it says that however often crises arrive, the world
cannot be destroyed faster than the escalation step permits.

**Why "but the master equations are linear" is not an objection.** It has been put to
the authors that this model cannot be Michaelis--Menten because there is no substrate
concentration, no conserved catalyst, and because the governing master equations are
linear. The premise is true and the conclusion does not follow.

Single-molecule Michaelis--Menten kinetics --- one enzyme, one substrate, first passage
to one product --- *also* has linear master equations. That is what makes it tractable,
and it is a developed field in its own right. The linearity is in the state
probabilities; the saturation is in the :math:`\lambda`-dependence of the first-passage
rate. Both are true at once, in this model and in real enzymology, and neither implies
the other. There is likewise no requirement for a concentration: in the count-based
reading, :math:`S` is an **encounter rate**, not a concentration, and the dimensionless
ratio :math:`\lambda/(b+c)` does the work that :math:`[S]/K_m` does in the textbook
treatment. This model has one Earth and one doomsday system, and that is exactly the
regime single-molecule kinetics was built for.

**Why the analogy earns its keep.** The value of Michaelis--Menten kinetics has never
been that enzymes are simple. They are not: an enzyme is a large machine that wanders
through an enormous configuration space, and the details of how it finds and binds its
substrate are, in the general case, hopeless to model. The achievement of the
Michaelis--Menten treatment is that **you do not need them.** All of that unmodellable
complexity is absorbed into an effective encounter rate, and the waiting time to product
follows from that rate and two others.

The same structure holds here, and it is the reason this paper can exist. The
"configuration space" is the space of historical causal chains --- every way the world
can arrange itself into a nuclear crisis. No one can model that. But it is not
necessary to model it, because the encounter rate can be **measured** instead, from the
record of times the world did in fact enter such a state. That measurement is Section
2.3, and Tables 1 and 2 are what it returns. The near-miss record plays exactly the
role that a measured :math:`k_{on}[S]` plays in enzymology: it is the empirical stand-in
for a mechanism too complex to derive.

**Where this system actually sits.** With :math:`\lambda = 0.1`/yr and :math:`K_m = 9`/yr,
the ratio is

.. math::

   \frac{S}{K_m} \;=\; \frac{\lambda}{b+c} \;=\; 0.011

--- ninety times below half-saturation. The system is deep in the first-order regime,
and this is *why* the simple product :math:`\lambda \cdot p_{death}` works at all: it is
the low-substrate limit of a saturating law, and it agrees with the exact solution to
1.1 percent. Saturation would require a crisis roughly every six weeks. The model is
therefore operating in the regime where the analogy is not merely valid but linear ---
which is the easy case, and the one most favourable to a sceptical reader.

**A consistency check that was not fitted.** The parameters :math:`b` and :math:`c` were
set from the OSCR structure (Section 2.2), with no reference to crisis durations. Yet
they imply that a crisis, once entered, resolves in a mean time of
:math:`1/(b+c) \approx 40` days. The Cuban missile crisis lasted thirteen days. Those
agree to well within an order of magnitude, from a parameter fixed for entirely
independent reasons. This is offered not as confirmation but as the absence of a
contradiction that could easily have appeared.

**What the quiet years prove.** The system spends about **one percent of its time** in
the bound state: :math:`\lambda/(\lambda+b+c) \approx 0.011`. The rest of the time the
doomsday substrate is elsewhere, and the world looks safe --- because it *is* safe, most
of the time. When binding occurs, the resolution is fast and the outcome is decided in
weeks.

This is the shape of the risk, and it is why the intuition "nothing has happened, so
the rate must be low" fails. A process that is quiescent 99 percent of the time and
lethal 1/3 of the time it is not will produce long, calm stretches as a matter of
course. In the base scenario the median wait to absorption is 21 years, yet roughly one
run in forty survives past 127 years. **Both are the same model.** An observer inside
the long run would conclude the risk was small; an observer inside the short one would
not; and neither observation moves the underlying rate. The non-observation of nuclear
war since 1945 is precisely what this model predicts most of the time, and it is
therefore weak evidence about the parameters. That is not a rhetorical point. It is a
property of the variance of first-passage times in a saturating two-step scheme, and it
can be checked by running the model.


.. _oov1-b16-sec2-8:

2.8 Alternative Re-weightings
--------------------------------

The scenario range of Section 2.5 takes :math:`p_{death} = 1/3` from the OSCR structure
and calibrates :math:`\lambda` from the record. A reader may reasonably ask what happens
if :math:`p_{death}` is calibrated from the record too. This section reports that
calculation, because a reviewer will perform it in ten minutes and it is better answered
than ignored. It is presented as one analysis among several, and it is **not** the
paper's headline.

**The calculation.** Suppose :math:`n` crises met the MAD criterion and none escalated.
Under a uniform prior, the posterior mean of :math:`p` is Laplace's rule of succession,
:math:`\mathbb{E}[p \mid 0 \text{ in } n] = 1/(n+2)`. Estimating :math:`\lambda = n/T`
from the *same* count over :math:`T = 77` years gives an effective hazard

.. math::

   h_{\mathrm{eff}} \;=\; \frac{n}{T} \cdot \frac{1}{n+2}
   \;=\; \frac{n}{T\,(n+2)} \;\xrightarrow[n \to \infty]{}\; \frac{1}{T}

Counting more crises raises :math:`\lambda` and lowers :math:`p`, and the two effects
very nearly cancel: 0.86 percent per year at :math:`n=4`, 1.08 percent at :math:`n=10`,
approaching 1.30 percent as :math:`n` grows without bound. The limit :math:`1/T` is what
one obtains by discarding the crisis decomposition entirely and applying Laplace directly
to the time axis. Notably, this converges on Hellman's independently derived ~1 percent
per year (Section 5.2) --- two different routes, two different decades, the same order
of magnitude.

**Why this is reported and not adopted.** Four reasons, and the first is the one that
matters.

#. **It is a re-weighting, not a measurement.** Trading a rising :math:`\lambda` against
   a falling :math:`p` so that they cancel does not add information; it redistributes an
   assumption. The apparent stability of :math:`h_{\mathrm{eff}}` across :math:`n` is an
   artifact of the estimator's construction, not a discovered invariance of the world.
#. :math:`1/T` **is a posterior mean under a flat prior, not a ceiling.** It is
   frequently mistaken for one. The posterior on the hazard is wide, and it assigns
   non-negligible probability to values well above its own mean. Summarising an
   existential risk by the mean of a wide posterior is a false security illusion: it
   converts an unresolved question into a reassuring point estimate, which is precisely
   the failure mode this paper exists to name.
#. **The record is weak evidence at** :math:`n=4`. Surviving four crises each carrying
   :math:`p = 1/3` has probability :math:`(2/3)^4 = 19.8` percent --- unremarkable luck.
   The likelihood ratio between :math:`p = 1/3` and :math:`p = 0.1` is only about 3.3 to
   1. A value derived from structure (Section 2.2) is not displaced by evidence that
   weak. The trade only bites for large :math:`n`, and Section 2.3 returns :math:`n = 4`.
#. **At** :math:`n = 1` **the rule returns** :math:`p = 1/3` **exactly.** If the Cuban
   missile crisis is treated as singular --- which is what Hellman independently concludes
   when he reports that its thirteen days may carry more than a tenth of the era's total
   risk --- then Laplace and Kennedy agree to the digit. The disagreement between this
   section and Section 2.2 is therefore not about arithmetic. It is about whether Cuba
   was one of several comparable events or one of a kind.

The honest summary is that this re-weighting is an interesting convergence with the
existing literature and a poor basis for a forecast. It is included so that a reader
who reaches for it finds it already here, with its weaknesses stated.


.. _oov1-b16-sec2-9:

2.9 Stochastic Certainty
------------------------

.. note:: **This result is qualitative, and is not the forecast.** The certainty
   result below is parameter-independent: it holds for *any* positive rates, and says
   only that an absorbing state is reached eventually. The *quantitative* annual
   probability is bounded in Section 2.5, and the waiting times in Section 2.4a. The
   two must not be read as one claim --- certainty about the limit is not urgency about
   the year, and this paper's case rests on Section 2.5, not on this section.

The most important structural insight is not the median (21 years) or
the annual probability, but the mathematical certainty of the outcome:

**As long as** ``rRiskyGoMAD`` **> 0 and** ``rMADtoDEATH`` **> 0,
accidental nuclear winter is a stochastic certainty.** The absorbing
state (Dead) is reached with probability 1. Not probability 0.95.
Not probability 0.99. Probability 1. The only question is when.

The only way to change this conclusion is to make one of these
parameters exactly zero --- which means either eliminating nuclear
crises entirely or ensuring that no crisis ever escalates to exchange.
Neither is achievable without structural change to the system.

This is not a rhetorical claim. It is a theorem of absorbing Markov
chains: any state that can be reached from any other state and that has
no outgoing transitions will be reached with probability 1, given
sufficient time. The Dead state is absorbing. It is reachable from
Risky (via MAD). Therefore it will be reached. The parameters determine
the waiting time, not the outcome.

**The stochastic certainty result is timeline-independent.** Whether
the median waiting time is 4 days or 3 centuries, the conclusion is
the same. The argument holds equally at every point in the full
simulation range --- from the fastest pessimistic runs (accidental
nuclear winter within days) to the luckiest optimistic runs (~329
years). Those who claim the risk is manageable must demonstrate that
the crisis rate reaches *exactly zero* --- that no nuclear crisis will
*ever* occur again. No credible analyst makes this claim.


.. _oov1-b16-sec2-10:

2.10 Why the Crisis Rate Increases Over Time
--------------------------------------------

The base model assumes a constant crisis rate. This is a conservative
simplification. The upstream papers provide formal reasons to expect the
crisis rate to *increase* over time:

**The OSCR mechanism** (the collapse mechanism of BABL, formally
derived in :doc:`Matheo-b12 </study/matheo/b12/index>`, BABL definition and m6.th1): The
Over-Simplify, over-Complicate, over-Reach cascade predicts that any
self-assessing system that declares itself "OK" enters a
self-reinforcing degradation cycle. Applied to nuclear-armed
civilizations:

- **Over-Simplify (Stage 1):** Complex geopolitical tensions reduced to
  "us vs. them" binaries. Truth channels degraded by noise (the
  Unimportant Message Problem, :doc:`Matheo-b12 </study/matheo/b12/index>`, m5.ax2).

- **Over-Complicate (Stage 2):** Layers of work-arounds --- arms
  control treaties with loopholes, verification regimes with exceptions.
  Each work-around adds complexity without restoring the truth channel.

- **Over-Reach (Stage 3):** The system extends beyond its resources.
  A crisis that would have been manageable in an earlier era becomes
  unmanageable because the correction mechanisms have been eroded.

**The Binary Attractor theorem** (:doc:`Matheo-b14 </study/matheo/b14/index>`, th8): There is no
stable middle ground between BABL (self-reinforcing degradation) and
the active self-correction cycle called ZION (Zoning, Investigating,
Organizing, Navigating). ZION is the perpetual cycle that counteracts
BABL: scope a problem (Zoning), examine it honestly (Investigating),
structure a response (Organizing), and steer through implementation
(Navigating). Then repeat. The cycle is perpetual --- stopping it
restarts BABL. A civilization that is not actively engaged in this
self-correction cycle is converging toward BABL. Delay is not
neutral; it is convergence toward the attractor from which escape
becomes harder.

**Implication:** If OSCR is active, then ``rRiskyGoMAD`` is not
constant at 0.1/year --- it is increasing. The base-case median of
~19 years is therefore an *upper bound*. The model is optimistic.


----



**A note on direction, and on the disagreement this section is answering.** Section
5.3 sets out Tertrais's argument that the rate is *falling*: fail-safes have been
perfected, lessons learned, and known incidents have become rare since 1983. That
argument is serious and its conclusion is in this paper's optimistic column. This section
gives the reasons for thinking the forward rate is nonetheless rising, and it is the only
support this paper offers for its pessimistic corner --- which, unlike the optimistic and
base cases, is **not** bracketed by any published reading of the record (Table 2). It is
argued here rather than cited, and a reader who rejects the argument should discard that
column.

**Some holes closed; others opened.** Tertrais's evidence establishes that specific
failure modes were fixed. It does not establish that the total is falling, because it
counts only the closings. Since the fail-safes he credits were designed, the failure
surface has changed in kind: command-and-control systems have acquired network
attack surfaces that did not exist; hypersonic delivery compresses the decision window
that dual phenomenology needs in order to work; and automated decision support inserts
a class of error whose failure modes are, by construction, unlike the human ones the
existing procedures were built to catch. Whether the sum of these exceeds the
improvements is not known. The claim here is only that the sum is not obviously
negative, and that a forecast which assumes it is negative is making the stronger
assumption.

**Pathway growth is quadratic.** The number of nuclear-armed states has grown from five
to nine. Bilateral crisis pathways grow as :math:`\binom{k}{2}`, so nine states carry
thirty-six pathways where five carried ten --- a factor of 3.6 in the number of
dyads that can produce a crisis, before any account is taken of how much less
practised the newer dyads are at managing one. Today there are **nine** nuclear-armed
states; a tenth is plausible on the current trajectory of intent, though it has not
happened and this paper does not forecast it.

**Normalization works against disarmament, not for it.** Each new entrant makes the
possession of these weapons more ordinary. A horror that is routine is harder to
abolish than one that is shocking, and every accession supplies a further argument that
possession is normal statecraft rather than an emergency to be ended. This is a
mechanism by which the crisis rate and the difficulty of reducing it move together ---
in the wrong direction, and for reasons that have nothing to do with anyone's malice.

**The last cap came off in February 2026, and this is not an interpretation.** New START ---
the final treaty limiting the deployed strategic arsenals of the two states holding roughly
90 percent of the world's warheads --- **expired on 5 February 2026**. It had been extended
once, in 2021, for the five years its own text permits; no further extension was legally
available. No successor exists, and no negotiations toward one are under way
:cite:`FAS2026NewSTART` :cite:`ICAN2026NewSTART`. Russia's verification cooperation had
already lapsed in 2023. **For the first time since 1972, there is no agreed ceiling on
US and Russian strategic nuclear forces, and no inspection regime attached to one.**

This matters to Section 2.10's argument in a way the rest of it does not. Everything else
here is inference about mechanisms; this is a dated fact with a citation, and it is the
kind of evidence the pessimistic column has otherwise lacked. It does not by itself raise
the crisis rate --- treaties constrain arsenals rather than crises, and the model's
parameter counts crises. What it removes is the transparency and predictability that made
crises *legible* to the other side, which is the input on which every de-escalation in
Table 1 depended. The analysts who track this describe the consequence as "a world of
heightened nuclear competition fueled by worst-case planning and nuclear expansion, fewer
transparency mechanisms, and deepening mistrust" :cite:`FAS2026NewSTART`.

.. caution:: **What this section does not claim, and why.** (1) No claim is made here about
   any state's doctrine, motives, theology, or intentions. The argument is about the number
   of dyads, the transparency of the channels between them, and the character of the failure
   surface --- all of which are observable without attributing anything to anyone. (2) Two
   illustrations that might be expected here are **deliberately absent**: an assertion about
   Russia's adjustment of its stated conditions for use, for which no primary source was
   located; and a characterization of the 2026 Iran--US--Israel escalation, which the authors
   cannot check to the standard the rest of this paper is held to. Neither is load-bearing,
   and an unsourced claim is worth less than the space it occupies. **Current events date quickly, and a
   forecast that rests on this year's headlines deserves the scepticism it will receive.**


.. _oov1-b16-sec3:

3. Why "Later" Is Not an Option
==================================

The most dangerous assumption in nuclear policy is: "We can deal with
this later." Two formal arguments establish that delay is not neutral.


.. _oov1-b16-sec3-1:

3.1 Stochastic Certainty Means No Safe Waiting Period
---------------------------------------------------------

In a system with an absorbing state reachable with positive probability
at each step, the probability of eventually reaching that state is
exactly 1. This is not a statistical estimate; it is a mathematical
theorem. There is no "safe" number of years to wait. Every year the
system continues in its current form, the roulette wheel spins again.

The base case (Section 2.5) makes this concrete: even in a single year,
the risk of catastrophic failure is not negligible. It is comparable to
loading a revolver with one round in 34 chambers, putting it to the head
of civilization, and pulling the trigger --- once per year, every year,
forever. The optimistic scenario widens the cylinder to 113 chambers.
It does not unload the gun, and no scenario in Table 3 does.


.. _oov1-b16-sec3-2:

3.2 No Stable Middle (Binary Attractors)
--------------------------------------------

The Binary Attractor theorem (:doc:`Matheo-b14 </study/matheo/b14/index>`, th8) provides the
formal reason why "dealing with it later" is not a neutral decision.
In a system with a self-assessment bifurcation (:doc:`Matheo-b12 </study/matheo/b12/index>`, th3),
there are exactly two stable states --- convergence toward BABL and
convergence toward the self-correction cycle ZION (Zoning,
Investigating, Organizing, Navigating). There is no stable middle.

A civilization that is not actively engaged in structural recalibration
--- the ZION cycle of scoping, investigating, organizing, and
navigating --- is, by default, converging toward BABL. This convergence
is invisible from the inside (because BABL disables the self-assessment
mechanisms that would detect it). The decision to "deal with it later"
*feels* neutral --- the system appears stable, deterrence appears to be
working. But apparent stability is itself a symptom of BABL: the system
has declared itself OK ("deterrence works") and stopped checking.


.. _oov1-b16-sec3-3:

3.3 The Adaptive Learning Objection
---------------------------------------

Some will argue that adaptive learning --- institutional responses
after each near-miss --- reduces the crisis rate over time. After the
Cuban Missile Crisis, the hotline was established. After Able Archer,
intelligence sharing was improved. This argument faces two structural
problems:

**First, the burden of proof is reversed.** The stochastic certainty
result holds for *any* positive crisis rate. Those who claim adaptive
learning resolves the problem must demonstrate that the crisis rate
reaches *exactly zero* --- that no nuclear crisis will ever occur
again. No credible advocate of adaptive learning makes this claim.

**Second, the adaptive learning argument must survive its own vested
interests test.** Those who argue that nuclear deterrence is adequately
managed are, overwhelmingly, professionals whose careers, institutions,
and funding depend on the continuation of nuclear deterrence
infrastructure. This is not an accusation, and it is emphatically not a
claim that any individual is arguing in bad faith --- most are not, and
the ones most likely to read this paper are among the least likely to be.
It is a structural observation about incentive alignment, of the kind
formal mechanism design routinely addresses, and it applies to this
paper's author with equal force (Section 4.0a).

It is also the second of the four features by which Lazarus
:cite:`Lazarus2009` and Levin et al. :cite:`Levin2012` define a **super
wicked problem**: *those who cause the problem also seek to provide the
solution*. The other three fit as exactly: *time is running out*
(Section 2.9); *the central authority needed to address it is weak or
non-existent* (Section 6); and *irrational discounting pushes responses
into the future* (this section). Nuclear risk is not merely a hard
problem. It is a member of a named class whose defining property is that
the ordinary machinery of correction does not engage with it --- which is
the phenomenon Section 6 reports from the inside.


----


.. _oov1-b16-sec4:

4. MAD |rarr| MAP
====================

.. _oov1-b16-sec4-0:

4.0 Why a Risk Paper Carries a Remedy Section
------------------------------------------------

A forecast does not require a solution to be correct, and a reader may reasonably ask why
this one comes with a proposed escape at all. The answer is not advocacy. It is that the
remedy and the measurement are causally connected, in a way Section 4.0a below and
Section 5.1 set out, and that connection is itself one of this paper's claims.

The argument has three steps, and each is checkable.

#. **Risks without visible remedies do not get measured** (Section 4.0a). An unbearable
   number with no exit attached is a number one finds reasons not to compute, or --- having
   computed it --- reasons to temper. Hellman recorded exactly this adjustment in his own
   text. The author of this paper did the same thing more completely, by not looking for
   years despite having every tool required.
#. **The field's bottleneck is uptake, not analysis.** This is not this paper's claim but
   Baum's, from the most recent survey of the literature: nuclear war policy decisions
   "have made little use of risk analysis", and "the limiting factor is mainly the use of
   risk analysis for decision-making." The analyses exist. They are not used.
#. **Therefore the two are the same problem.** If risks without remedies go unmeasured,
   and measurements without remedies go unused, then the shortage is not of arithmetic.
   **Uptake is limited for lack of a vision.** A decision-maker offered a number and no
   course of action is being offered a reason for despair, and will decline it --- not from
   stupidity, but because despair is not actionable and their attention is finite.

This is why the section exists, and it also bounds what the section may claim. What
follows is **a** candidate escape, not **the** solution; it is offered to be checked, not
believed; and if it is wrong, the forecast in Section 2 is unaffected. The forecast does
not depend on the remedy. But the *measuring* did, and the *use* will.

**Where the concrete form is set out, and in what terms.** What a candidate escape looks
like as an institution --- who checks the checking, how it is funded, what it would
actually do --- is not developed here, because a risk paper is the wrong place to develop
it, and because doing so is what makes such papers read as prospectuses. Two pointers
suffice, and both are self-contained:

- :doc:`ResearchCity </solution/researchcity/index>` --- the proposed institution that
  would carry out the checking at scale, described concretely rather than gestured at.
- :doc:`Staying Correctable --- A Secular Reading
  </study/matheo/overview-secular/index>` --- the same argument in **entirely secular terms**, from
  systems-engineering self-correction through scheduled institutional renewal to the
  urgency established above. No scripture is required to follow it or to check it. A reader
  who wants the framework without the theology should start there; a reader who suspects
  the theology is doing the argumentative work can use that page as the control.
- :doc:`Open Letter OL10 </good-news-pack/vv/mmv3/open-letter/ol10/index>` --- the ask in
  concrete, actionable form: *Put Earth in Escrow*, a proposal that the ten Nuclear Kings
  hold the line while ResearchCity is built (priced in Section 4.3a). It is included as a
  pointer rather than reproduced, and a reader should know what it is before clicking: it
  is a **letter to heads of state**, written in that register, not a section of this paper.
  It is also Exhibit A of Section 6.

The forecast in Section 2 stands or falls on its own arithmetic, and neither pointer is
load-bearing for it.


4.0a Why numbers like this go unmeasured
----------------------------------------

There is a pattern in the two preceding subsections worth naming, because it bears on how
much confidence the reader should place in the *absence* of forecasts like this one.

**Risk analysts under-report risks for which they can see no remedy.** An unbearable number
with no exit attached is a number one finds reasons not to compute --- or, having computed
it, reasons to temper. This is not an accusation of character. It is a structural feature of
doing risk analysis on a problem you cannot solve, and it predicts exactly what Hellman
recorded of himself in 2008.

The present author is the stronger case, and it cuts against him. He grew up as the Cold War
ended and understood what it had meant. He works on existential problems by profession. He
had every modelling tool this paper uses, and the model is, by the standards of problems he
had already solved, trivially simple: three states, four transitions, a closed-form answer
obtainable in an afternoon. **He still took years to even look.** What changed was not new
data or a new method. It was that a candidate escape --- Section 4 --- had been worked out
first, and only then did looking at the number become bearable.

That admission carries an obvious hazard, and it should be stated before a reader states it:
if envisioning a solution is what made the problem visible, perhaps the problem was
constructed to fit the solution. The reply is evidential, and the reader is invited to check
it rather than accept it.

- **The number does not depend on the escape.** Hellman, who has no MAP and no stake in one,
  reaches ~1 percent per year. This paper's base case is 3.2 percent. Those differ by a
  factor of three. If a preferred solution were driving the estimate, it would not land that
  close to a man who had no such solution.
- **The inputs are not this paper's.** The incident catalogue is Baum's. The classification
  criteria in Section 2.3 were fixed before counting, are stated in full, and every cell is
  recomputable by anyone who disagrees with a call.
- **The corner most favourable to critics is published here.** Tertrais's reading of the
  record and this paper's optimistic scenario are the same number, and it is in Table 3.

A candidate escape removed a disincentive to measure. It did not supply the measurement.

The consequence for policy is the point of stating any of this, and it requires a
distinction that is easy to collapse.

**The risk is not unknown. The arithmetic is.** That nuclear war would be catastrophic is
among the most widely known facts on Earth; it has been public for eighty-one years, and no
one needs this paper to learn it. The choice to live with it has been made, repeatedly and
knowingly, by everyone. What is absent is narrower and more specific: **a waiting-time
distribution.** Not "this could be very bad" but "here is the probability per year, here is
the median, here is what it costs to wait." Baum's survey of this literature finds that
nuclear war policy decisions "have made little use of risk analysis" --- not that they are
unaware of nuclear war.

The two claims must not be run together. It would be easy to conclude that "nobody told
them" --- but plainly many people have, for decades, with more standing than this author
has. The defensible claim is the smaller one:
if someone with the background, the motive, the tools, and a three-state model still took
years to *compute* it, it is not reasonable to assume that heads of state --- who have none
of those four --- have been shown a waiting-time forecast. **The likeliest explanation for
the absence of this particular calculation from nuclear policy is not that it was weighed
and rejected. It is that the number was never put in front of anyone in a form that could
be acted on, and Section 6 reports what happened when someone tried.**


----


.. _oov1-b16-sec4-1:

4.1 The Current Paradigm: Mutually Assured Destruction
---------------------------------------------------------

MAD (Mutually Assured Destruction) has been the dominant nuclear
strategy since the 1960s. Its logic: if both sides can destroy each
other even after absorbing a first strike, neither has an incentive to
strike first.

MAD has prevented nuclear war for 80 years. The model does not deny
this. But MAD has a structural weakness that the RiskyMAD model exposes:
**MAD is a metastable equilibrium, not a stable one.**

- A **stable** equilibrium returns to its original state after a
  perturbation. A ball at the bottom of a bowl.

- A **metastable** equilibrium appears stable until a sufficiently
  large perturbation pushes it past a threshold, after which it
  transitions irreversibly. A ball balanced on the rim of a bowl.

MAD is the ball on the rim. Small crises are resolved, and the system
returns to its apparent equilibrium. But the RiskyMAD model shows that
the threshold will eventually be exceeded --- stochastic certainty.
Moreover, the model *measures* the basin depth: a 1-in-34 annual
probability of crossing the threshold at the base rate, and no better
than 1 in 113 under the most sceptical published reading of the record.
The basin is shallow.

The characterization of MAD as metastable is consistent with the crisis
stability literature (Schelling, *The Strategy of Conflict*, 1960;
Jervis, "Cooperation Under the Security Dilemma," *World Politics*,
1978). Schelling's analysis of crisis stability identifies precisely the
dynamics that the RiskyMAD model formalizes: the tension between
stability at each decision point and instability over iterated
interactions. Jervis's security dilemma framework explains why
deterrence systems generate the very crises they are designed to
prevent. The RiskyMAD model adds the quantitative result that this
literature lacks: a probability distribution over time-to-failure.

The insight is not that MAD is wrong. The insight is that MAD is
*incomplete*. MAD prevents nuclear war on any given day; it does not
prevent nuclear war over any given century. A strategy that works
locally but fails globally is not a strategy. It is a delay mechanism.


.. _oov1-b16-sec4-2:

4.2 The Proposed Alternative: Mutually Assured Progress
-----------------------------------------------------------

MAP (Mutually Assured Progress) replaces the threat of mutual
destruction with a shared commitment to mutual progress. Instead of
"if you attack, we both die," MAP says: "if we both invest in
recalibration, we both thrive."

The formal basis comes from two upstream results:

**The Commitment Trichotomy** (:doc:`Matheo-b13 </study/matheo/b13/index>`, th6): In a Prisoner's
Dilemma (where defection is individually rational), cooperation cannot
emerge from rational self-interest alone. But the game structure can
be changed by a credible first-mover who demonstrates commitment to
cooperation at personal cost. This changes the game from Prisoner's
Dilemma to Assurance Game --- where cooperation is individually
rational *if* the other side also cooperates. The first-mover's
credibility resolves the "if."

**Qualitative payoff structure for the nuclear case:**

.. list-table:: Nuclear MAD/MAP Payoff Matrix (Qualitative)
   :header-rows: 1
   :widths: 25 35 35

   * -
     - **Side B: Cooperate (reduce)**
     - **Side B: Defect (maintain)**
   * - **Side A: Cooperate (reduce)**
     - Both reduce risk, save resources. High payoff for both.
       Mutual progress (MAP).
     - Cooperator vulnerable. Worst for cooperator, best for
       defector. Classic Prisoner's Dilemma outcome.
   * - **Side A: Defect (maintain)**
     - Defector gains temporary advantage. Best for defector,
       worst for cooperator.
     - Status quo continues. Stochastic certainty of death for
       both (Section 2.9). Both lose OLT but *feel* safe locally.
       Mutual destruction (MAD).

In the current game (Prisoner's Dilemma), Defect/Defect is the Nash
equilibrium: each side is individually rational to maintain its arsenal
regardless of the other's choice. The first-mover's credible commitment
changes this perception: once one side demonstrates verifiable
commitment at genuine personal cost, the game shifts from PD (where
D/D is the Nash equilibrium) to Assurance Game (where C/C is a Nash
equilibrium that dominates D/D *if* both sides recognize it). The
credibility of the first move is the mechanism.

Three possible responses:

1. **Defect** (the BABL default): assume defection, defect yourself.
   Stable but suboptimal.

2. **Cooperate naively** (the BABL over-simplification): cooperate
   without checking commitment. Exploitable and unsustainable.

3. **Volunteer credibly** (the self-correction path): commit first, at
   genuine personal cost, visibly and in a way that can be checked.
   This changes the payoff matrix for all other players.

**The third option is not hypothetical. It has been taken twice, and both times it
worked.** In October 1962, aboard submarine B-59, Vasili Arkhipov refused to authorize the
nuclear torpedo his captain had ordered readied --- at obvious cost to himself, against the
judgment of his superior, with no way of knowing whether he was right. In the late 1980s
Mikhail Gorbachev made unilateral concessions of exactly the form option 3 describes:
visible, costly, checkable, and made first. **Each of them won a world war that never
happened, and neither got a parade.** The Commitment Trichotomy is not a proposal for a
move nobody has ever made. It is a description of the only two moves that have ever worked
on this problem, both made by Russians, and this paper is asking for a third.

**And the payoff for making it is larger than the paper needs to argue for.** Gorbachev
received the Nobel Peace Prize in 1990. That is worth stating plainly, not as an inducement
--- this paper has no standing to offer anything, and the concrete ask lives in
:doc:`OL10 </good-news-pack/vv/mmv3/open-letter/ol10/index>` rather than here --- but as an
observation about the board that Section 4.2 is describing. The first-mover payoff in this
game already includes the largest reputational prize the international system has, it has
already been paid out once for precisely this move, and it is currently unclaimed.

**The Jubilee System** (:doc:`Matheo-b14 </study/matheo/b14/index>`, ax25): The mechanism for MAP
is periodic recalibration. The Jubilee System is a periodic
recalibration mechanism: every 50 units (structured as 7 cycles of 7,
plus 1), accumulated imbalances are systematically reset. The modern
equivalent: arms advantages recalibrated, resource asymmetries
rebalanced, institutional structures reformed. Not utopian; an
engineering specification for a self-correcting civilization. The
economic modeling is developed in :doc:`Matheo-b14 </study/matheo/b14/index>`.


.. _oov1-b16-sec4-3:

4.3 What MAP Looks Like Concretely
--------------------------------------

1. **Staged, mutual, verifiable arms reduction.** Not unilateral
   disarmament but mutual reduction with checking at every step.
   The Jubilee System applied to arsenals: each cycle reduces the
   total, with checking that makes cheating detectable.

2. **Truth-channel restoration as a security measure.** Degraded
   information channels *increase the crisis rate* (OSCR Stage 1).
   Investing in reliable information infrastructure is a defense
   measure, not a diplomatic nicety.

3. **Jubilee System cycles applied to international resource allocation.**
   Periodically rebalancing the accumulated advantages that make arms
   races feel necessary. Not redistribution (which creates dependency)
   but removing the structural conditions that produce arms races.

4. **The Great Jubilee Race.** The transition from MAD to MAP in 7--8
   stages, with all ten Nuclear Kings participating. Each stage has
   milestones that can be checked. Each completed stage makes the next
   easier. Section 4.3a prices the window this would take.

5. **FiShFus (Fiduciaries Sharing Futures).** 288,000 paid long-term
   thinkers whose job is to maintain the NOT OK self-assessment that
   the self-correction cycle (ZION: Zoning, Investigating, Organizing,
   Navigating) requires. A civilizational immune system. Cost:
   approximately $8 per person per year (~2 cents per day).

.. admonition:: What "the 10 Nuclear Kings" means, and what it does not

   **The term is an abstraction for** *sovereign* --- for the holder of an unappealable
   decision, answerable to no authority above it. It is not a claim that any of them is
   literally a king, and the form of government is irrelevant to the argument: presidents,
   premiers, chairmen, supreme leaders and prime ministers all appear in the list. What they
   share is the property the model cares about, which is that each holds a decision no one
   can overrule.

   **The word "Nuclear" is never dropped.** "The Kings" alone means nothing here.

   **The ten are ten thrones, nine of them armed:** the United States, Russia, China, North
   Korea, India, Pakistan, Israel, France, and the United Kingdom hold weapons; **Iran** is
   included because its intention to join is declared clearly enough that a solution
   excluding it would not be a solution. The tenth king has no crown yet, and that is
   exactly why he is at the table --- **intent adds crisis pathways whether or not the
   warhead exists**, which is the quadratic-pathway argument of Section 2.10 and requires no
   claim whatever about anyone's motives, doctrine, or beliefs. This paper makes none.

   **The irony in the name is the point.** Ten sovereigns cannot all be sovereign at once
   over the same shared object, and the object here is the survival of everyone including
   themselves. Each is sovereign over his own arsenal and over nothing else in this model.
   The crisis rate is not theirs --- it is what the world does to them. The per-crisis death
   probability is not theirs --- it is what a crisis does once it has started. **The
   absorbing state does not check credentials.**

.. container:: fineprint

   **Canute, retold --- because the story is usually told backwards.** In the twelfth-century
   account by Henry of Huntingdon, King Cnut the Great had his throne carried to the seashore
   and commanded the incoming tide to halt and not wet his robes. The tide came in anyway.
   The story is remembered as an emblem of royal vanity, and that is the opposite of what
   Huntingdon reports. Cnut staged it **on purpose, in front of his courtiers, precisely so
   that they could watch him fail** --- because they had been flattering him that all things
   obeyed him. With his feet in the water he told them that the power of kings is empty
   beside the laws that heaven, earth and sea obey. Then he went to Winchester, hung his
   golden crown on a crucifix, and by Huntingdon's account never wore it again.

   That is this paper's invitation to the ten, and it is not a humiliation. **They are asked
   to get their feet wet on purpose, in front of witnesses, while it is still a
   demonstration rather than a drowning.** The tide here is Table 3. It does not negotiate,
   it cannot be deterred, it grants no exceptions for arsenal size, and it holds no opinion
   about anyone's sovereignty. Bowing to it is not defeat --- it is the only move on the
   board that a king can make and still be remembered as wise. Cnut is remembered that way
   for precisely this reason. The only open question is whether the bowing is early and
   voluntary, or late and arithmetic.

**The ten have a function, and it is not ceremonial.** ResearchCity (Section 4.0) cannot
scale without them, for two reasons that are structural rather than diplomatic.

#. **They must permit it, because any one of them could end it.** ResearchCity will not take
   up arms --- not as a tactic, and not conditionally. That makes it permanently destructible
   by any party who objects. This is not a weakness in the proposal; **it is the proposal.**
   Section 4.2's Commitment Trichotomy requires a first move that is credible *because* it is
   costly and cannot be reversed into a threat. An institution that cannot defend itself
   cannot become one of the things it was built to correct, and everyone can check that this
   is so. Permitting it therefore costs the ten nothing they would want to keep, which is
   what makes refusing it informative.
#. **They must stay at the table, because a solution that is not transparent to all ten binds
   none of them.** Whatever ResearchCity finds has to be checkable by every party who would
   have to act on it, or it is merely another proposal from an interested party. **The ten
   are hereby recruited as reviewers** --- which is the same request this paper makes of
   every reader, addressed to those who hold the classified data that would settle it.

**A note on actor heterogeneity.** The symmetric model (ten equivalent
Nuclear Kings) is a conservative simplification. In reality: the US
and Russia hold approximately 90% of all nuclear warheads; China
maintains a no-first-use doctrine with fundamentally different strategic
incentives; Israel does not officially acknowledge its arsenal; regional
dynamics (India-Pakistan, North Korea) are shaped by bilateral
relationships, not global cooperation norms. The asymmetric case has
*more* crisis pathways, not fewer. The formal model's symmetry
simplifies the analysis without weakening the conclusion.

**A note on verification.** "Verifiable" is itself a hard problem.
The history of arms control includes both successes (INF Treaty
on-site inspections) and failures (Iraq pre-1991, North Korea). The
MAP proposal does not claim that checking is easy; it claims that
staged checking with milestones is structurally possible and that
the alternative (no checking, stochastic certainty of death) is worse.
The detailed treatment of checking mechanisms is developed in b17
(:doc:`Matheo-b17 </study/matheo/b17/index>`) and b18 (:doc:`Matheo-b18 </study/matheo/b18/index>`).

**A note on transition risk.** The transition from MAD to MAP passes
through configurations with temporarily elevated uncertainty. This
transition risk is real and should not be minimized. However, the
choice is not between "safe status quo" and "risky transition." The
choice is between stochastic certainty of eventual death (the status
quo) and a transition period with temporarily elevated but *finite*
risk followed by structural escape. Any finite transition risk is
preferable to infinite-horizon certainty of death.


.. _oov1-b16-sec4-3a:

4.3a What the Escape Window Costs
-------------------------------------

A proposal that names a timeline can be priced by the same model that produced the problem,
and it should be. Scaling ResearchCity through its stages is estimated at **7 to 11 years**,
with a mid case near 9. The model says what that window costs.

.. list-table:: Table 8. Probability of onset **before** the escape is built
   :header-rows: 1
   :widths: 22 20 20 20

   * - Window
     - optimistic (0.03)
     - **base (0.10)**
     - pessimistic (0.30)
   * - 7 years
     - 6.6%
     - **20.4%**
     - 49.0%
   * - 9 years (mid case)
     - 8.5%
     - **25.5%**
     - 58.1%
   * - 11 years
     - 10.3%
     - **30.3%**
     - 65.5%

**This is the honest price, and it is not reassuring.** At the base rate, a plan that takes
nine years carries roughly a **one-in-four chance that it does not finish in time.** That
figure is not a reason to reject the plan; it is the figure any alternative must beat. The
comparison is not against zero. It is against 73 percent over the forty years of a single
career (Table 3) --- which is what continuing costs, on the same arithmetic, with no
transition risk at all and no escape at the end of it.

**A moratorium is not the solution, and calling it one would be a category error.** Nothing
in a treaty sets the crisis rate to zero; Section 2.9 shows that only an exactly-zero rate
changes the outcome, and no instrument achieves that. What the escrow window does is
different and more modest: it is **the interval during which the escape transition
(**\ ``rRiskyEscape``\ **, currently zero) can be made non-zero.** The model's fourth action
is inactive not because it is impossible but because nothing has been built. The window buys
the building time, and Table 8 says what the building time costs.

.. container:: fineprint

   **Why the window cannot simply be made shorter.** The stages are sequential because each
   one's checkability depends on the previous one having been checked --- that is what
   distinguishes staged verifiable reduction from a promise. Compressing the schedule does
   not reduce the risk in Table 8 so much as relocate it, by producing stages whose
   milestones cannot be confirmed before the next begins. The 7-to-11-year range is an
   estimate of the author's, offered to be checked like everything else here, and it is the
   softest number in Section 4.


----


.. _oov1-b16-sec5:

5. Related Work
===============

This section sets out the quantitative nuclear-risk literature against which the
forecast of Section 2 should be read. The two facts a reader needs in advance were
given in Section 1; what follows is the argument behind them.


5.1 The field
-----------------

Quantitative estimation of nuclear-war risk is a small literature. Barrett, Baum &
Hostetler (2013) :cite:`Barrett2013` :cite:`Barrett2013b` build the closest methodological ancestor to the model used here: a
mathematical framework of fault trees and Poisson processes for inadvertent US--Russia
nuclear war arising from misinterpreted early-warning false alarms, with an online appendix
giving the underlying incident frequencies. Baum, de Neufville & Barrett (2018) :cite:`Baum2018` extend the
scope to fourteen interrelated scenarios covering, in their words, "perhaps the entire
range of nuclear war scenarios", and --- decisively for this paper --- compile a dataset of
**60 historical incidents that might have threatened to turn into nuclear war**, the
largest such catalogue then available. Baum (2018) :cite:`Baum2018b` reviews the whole field.

Two features of that review shape what follows. First, Baum finds that the work needed here
has not been done: *"Further work is needed to assess how close each incident came to
nuclear war... Quantifying how close each incident came to nuclear war would be a subtly
challenging endeavor. The incidents are all prone to historical interpretation."* He lists
it explicitly as future research: *"Quantify historical incidents in terms of how far they
went in their respective nuclear war scenarios."* Section 2.3 does exactly that, and
inherits exactly that difficulty.

Second, Baum reports that the field's bottleneck is not analysis but **uptake**:
*"nuclear war policy decisions have made little use of risk analysis... the limiting factor
is mainly the use of risk analysis for decision-making, such that people working on nuclear
war risk should emphasize outreach to decision-makers."* This paper is written on that
premise.

5.2 Hellman: the nearest ancestor, and what he did with the number
----------------------------------------------------------------------

Hellman (2008) :cite:`Hellman2008` is the closest predecessor to the model in Section 2: a fixed-rate chain
built on the Cuban missile crisis, estimating the failure rate of deterrence via one
mechanism --- a Cuban-Missile-Type Crisis --- as :math:`\lambda_{CMTC} = \lambda_{IE} P_1
P_2 P_3`, yielding a range of :math:`(2\times10^{-4},\, 5\times10^{-3})` per year.

Three things must be said about that figure, because it is routinely misused.

**It is not a total-risk estimate.** Hellman states plainly that the analysis "neglects
other trigger mechanisms such as command-and-control malfunctions and nuclear terrorism"
and "therefore underestimates the threat" (p. 21). Citing its upper bound as Hellman's
ceiling on nuclear-war risk misreads him.

**He revised it upward, in print.** Hellman (2021) :cite:`Hellman2021` --- chapter 4 of Scouras's
*On Assessing the Risk of Nuclear War* --- concludes that "the risk of nuclear deterrence failing
currently appears to be on the order of **1 percent per year**", with an order-of-magnitude
range from a third of a percent to 3 percent, bounded above by 10 percent per year (sixty-
six years survived) and below by 0.1 percent (pp. 97--99). That is his current published
position, and it is the figure this paper's estimates should be compared against.

**He shaded two parameters downward for a stated non-epistemic reason.** In 2008 he
restricts :math:`\lambda_{IE}` to three initiating events, writing: *"To temper the
possibility of this article being seen as alarmist, it only considers the first three
possible initiating events"*; and of :math:`P_3`: *"Again to avoid being seen as alarmist,
this article uses an estimated range (0.1, 0.5)."*

That reason does not bear on the probabilities. Whether a number will be received as
alarmist is a fact about audiences, not about the world. But the observation that follows
is not a criticism of Hellman, who named his own adjustment in print --- which is more than
most --- and who reached the right order of magnitude anyway, thirteen years before this
paper. It is a criticism of the situation he was in, and it generalises. See Section 4.0a.

5.3 Tertrais: the strongest objection to this paper
-------------------------------------------------------

Tertrais (2017) :cite:`Tertrais2017` is the most serious published challenge to any model of this kind, and it
must be met rather than cited politely.

His thesis: *"Has mankind really stood 'on the brink' several times since Nagasaki, and have
we avoided nuclear catastrophe mostly because of pure 'luck'? ... This is not the case. The
absence of any deliberate nuclear explosion (except for testing) since 1945 can simply be
explained by human prudence and the efficiency of mechanisms devoted to the guardianship of
nuclear weapons."* Across 37 episodes he finds that safety mechanisms held, that dual
phenomenology makes single-source false alarms non-actionable, and he quotes Perrow --- the
originator of normal-accident theory --- concluding that *"because of the safety systems
involved in a launch-on-warning scenario, it is virtually impossible for well-intended
actions to bring about an accidental attack."*

Most damagingly for a constant-rate model, his central counter-argument is a
**non-stationarity argument**: *"the probability of failure increases markedly with time
only if conditions do not change---and conditions do change."* Safety mechanisms are
perfected; lessons are learned; and *"we only know of one significant incident in nearly 35
years: the Black Brant XII episode"* (p. 55).

Four responses, in ascending order of force.

**(1) Tertrais's implied rate is already in this paper.** One significant incident in
thirty-four years is :math:`\lambda \approx 0.029`/yr. The optimistic scenario of Section
2.5 uses **0.03/yr**, chosen independently and before this comparison was made. The most
skeptical published reading of the record and this paper's most optimistic corner are the
same number. The disagreement is therefore not about the optimistic corner at all; it is
about whether the optimistic corner is the right one.

**(2) His stated scope is narrower than this model's, which is why his rate is a corner and
not a centre.** On p. 52: *"It does not cover the risk of an accidental nuclear explosion,
an unauthorized launch, or a terrorist act."* His 37 episodes are crisis close calls ---
Cuba, Able Archer, Serpukhov-15, Black Brant --- and those **are** the transition this model
calls Risky |rarr| MAD, which is why response (1) is legitimate. But the channels he sets
aside are additional routes into the same absorbing state. A count that excludes them is, if
anything, an **under**\ -count of total entry into a nuclear-use decision. Granting his
number therefore grants the most favourable reading available, which is precisely the work
the optimistic column is meant to do.

The Perrow quotation is a separate matter and the scoping objection does apply there: it is
scoped to *well-intended* actions in a *launch-on-warning* scenario, neither of which
describes escalation inside a crisis.

**(3) The declining-incident count may be an artifact of declassification, not of safety.**
The incidents Tertrais counts are the ones that have been declassified. Cold-War material
has had thirty extra years to surface; post-1990 material has not. Baum et al. describe
their own catalogue as "likely not comprehensive". An apparent decline in *known* incidents
is exactly what a constant true rate plus a declassification lag would produce.

**(4) Conditions changed in both directions, and he counts only one.** Fail-safes improved;
so did the number of ways to fail. Nuclear-armed states grew from five to nine, and
bilateral crisis pathways grow quadratically with that count. Cyber intrusion into
command-and-control, hypersonic compression of decision windows, and automated decision
support are pathways that did not exist when the fail-safes Tertrais credits were designed.
Tertrais's argument establishes that some holes were closed. It does not establish that the
sum is falling, and Section 2.10 gives reasons to think it is not.

None of this refutes him. Response (1) in particular grants him a great deal: if his
reading of the record is right, the answer is the optimistic column of Table 3 --- **and
even that column puts individual annual mortality from accidental nuclear winter at
eighteen times the global road-death baseline.** Section 2.6 grants him more still: taking
his rate *together with* the lowest published death fraction and the road-death rate of the
worst-affected country on record, the inequality holds threefold. **The disagreement between
the most sceptical published position and this paper does not reach the paper's
conclusion** --- and that is the strongest thing this paper can say about its own
robustness, because it is a statement about a critic's numbers rather than the author's.


----


.. _oov1-b16-sec6:

6. If You See Something, Say Something: A Report on Saying Something
=======================================================================

Section 4.0 advanced a claim: that uptake, not analysis, is the binding constraint --- and
that a forecast delivered without a course of action will be declined. That claim is
testable. The author has been testing it, and this section reports what came back.

It is included because the attempts are **data** on the paper's own uptake hypothesis, and
because the record is falsifiable: a single reply refutes it. It is the narrowest possible
test --- *if you see something, say something* --- and the finding is that saying something
is harder than it sounds, for reasons that are structural rather than personal.

.. note:: **On reading this section.** What follows is a negative result about the author's
   own efforts. It is neither a complaint nor a credential, and it is not an appeal: this
   paper asks for nothing that money can buy. If the uptake hypothesis is right, this
   outcome is what it predicts, and the prediction was made before the outcome was known.


6.1 What was attempted, and what came back
---------------------------------------------

**States.** In December 2025, open letters (OL0--OL6, OL10) were sent via USPS to the
Washington DC representations or embassies of the President of the United States, Pope
Leo XIV, the Prime Minister of Israel, the President of Russia, the UN Secretary-General,
and the US Speaker of the House. The author also travelled to Washington DC to attempt
delivery in person. **No response has been received from any recipient.**

**The delivery failed at the medium, and that is the finding.** The author was told by the
US Secret Service that unsolicited letters of this kind are treated as spam --- and that a
letter containing a USB stick, which is how the supporting data travelled, is treated as a
security risk. The relevant websites do not indicate where an existential-risk analysis
should be submitted. :doc:`OL10 </good-news-pack/vv/mmv3/open-letter/ol10/index>` --- the
most technically focused letter of the set, addressed to all ten Nuclear Kings and
containing the concrete proposal --- reached no addressee directly at all: it travelled
only inside the UN submission and on the USB sticks. **It is very unlikely that anyone
read it.**

That correction matters, and it cuts against the strongest version of this section. The
honest finding is **not** "they were told and ignored it." It is: *there is no channel.*
The agents whose task is to protect a head of state could not pass on a claim about an
existential risk to the person whose task is to act on existential risks --- not through
unwillingness, but because no procedure exists for it and the procedures that do exist are
designed to discard exactly this. Nobody can rebut this by saying they would have read it.
The submission was never a thing that could arrive.

**Institutions that price risk.** The author raised the analysis with retail banking
institutions, including in the course of a legal proceeding. All publish substantial
statements of community responsibility. None produced a route to anyone with
risk-assessment competence.

.. container:: fineprint

   **This test was weaker than it looks, and the author says so.** It reached branch and
   relationship managers, on the assumption that they would be sufficiently educated on risk
   to recognise an actuarial argument or to forward it. **No actuary was reached.** That
   assumption was the weak link, and the null result therefore says nothing about actuarial
   competence. What it tests is narrower: whether an institution's published ethical
   commitments create any path to its risk function. They did not.

   The assumption was also unnecessary, because **the actuarial profession has already
   answered, in writing, decades ago.** Nuclear war is excluded from essentially every
   policy by standard clause (Section 2.6) --- not as an oversight but as a considered
   finding of uninsurability. The right audience was never the bank manager. The answer was
   already on file, and it was: *we do not touch this.*

**Institutions that ought to care.** Churches and religious bodies, whose own stated values
make catastrophic risk to the whole human family their explicit concern, were approached.
The response has been indistinguishable from that of the institutions with no such
commitment.

**The public.** The response is uniformly: **"What can I do?"** --- followed by resignation.
This is not apathy. It is the fourth feature of a super wicked problem
:cite:`Lazarus2009` :cite:`Levin2012` operating exactly as specified: when a problem appears
too large for individual action, discounting the future becomes the rational-feeling default,
and inaction is chosen without ever being decided. Section 3 explains why inaction is not
neutral.


6.2 Why there is no channel: a structural reading
----------------------------------------------------

The pattern is old and it has a name. **A system in which the only body empowered to
authorize a correction is the body that would be corrected cannot correct itself from the
inside.** This is the third defining feature of a super wicked problem --- *the central
authority needed to address it is weak or non-existent* :cite:`Lazarus2009`
:cite:`Levin2012` --- and it is the reason the preceding subsection reads as it does. There
is no channel because a channel would be a mechanism of correction, and the system has none
that its subjects do not control.

.. container:: fineprint

   **The precedent, cited for the structure and not for the man.** At the end of the Middle
   Ages, Martin Luther observed that reform was structurally blocked: matters of importance
   required a council; only the pope could convene a council; so errors could be corrected
   only with the assent of those whose short-term interests the correction opposed. Nothing
   in this paper is a claim about its author, whose letters are evidence about channels and
   about nothing else. The precedent is offered because it establishes that the blockage is
   real, that it persists for centuries, and that it is eventually resolved at a cost far
   exceeding the cost of resolving it early.

The nuclear case has the same shape. **Only the ten can convene the ten.** Each is party to
the matter under discussion; none can propose the discussion without appearing to concede
something to the others; and there is no authority above them.

**But the shape is not identical, and the difference is the opening.** Three convening
paths exist, and they are not equally exhausted.

#. **The United Nations --- tested, and it did not work.** The General Assembly convened
   negotiations for the Treaty on the Prohibition of Nuclear Weapons in 2017. The
   nuclear-armed states boycotted. The treaty entered into force in 2021 without them. So
   the UN's convening power on this precise question has been exercised within living
   memory, and the answer is known: **the ten do not come.** This is not a criticism of the
   UN. It is a measurement of what its convening power can and cannot do here, and it is
   worth more than a prediction.
#. **The Holy See --- never tried.** There exists one office with global convening authority
   and **no arsenal**. The Holy See signed *and ratified* the TPNW on 20 September 2017, the
   day it opened for signature; holds no weapons; is party to no deterrence relationship;
   and has stated that *possession* --- not merely use --- is immoral :cite:`ICANHolySee`.
   **It is the only convener that is not also a defendant.** Whether that is sufficient is
   unknown, because it has not been attempted.
#. **Any one of the ten --- and this is the strongest path, by this paper's own theory.**
   Any of them could put the waiting-time question on an agenda tomorrow. Section 4.2 is
   the reason this matters more than it appears to: under the Commitment Trichotomy, the
   first party to move credibly, at genuine cost, **is** the mechanism that shifts the game
   from Prisoner's Dilemma to Assurance. The first mover does not merely start a discussion.
   The first mover changes the payoff matrix for everyone else. That is not a hope; it is
   the formal result the remedy rests on.


6.3 The two requests this paper makes
----------------------------------------

**To whoever convenes: convene.** The ask is not that anyone accept this paper's answer. It
is that the ten Nuclear Kings --- the nine that hold arsenals and the one whose intention to
join them is declared --- be brought to a table to examine the waiting-time question and say
whether the arithmetic is wrong. **If it is wrong, that is the best available outcome**, and
the fastest route to it is for the people with the classified data to say so. If it is not
wrong, then everyone at that table is a sitting duck in the same way, on the same schedule,
and they are the only people who can change it. This is why the ten are addressed here not
as sovereigns but as **reviewers**: it is the same request this paper makes of every reader,
addressed to the readers who happen to hold the data. The concrete form of the ask, as it
was actually drafted and sent, is
:doc:`OL10 </good-news-pack/vv/mmv3/open-letter/ol10/index>`.

**To everyone else: check the arithmetic, and say what you find.** Experts and officials
move when there is public interest and, on the evidence of this section, not much before.
That makes the smallest available action the operative one. Every input is public; the
method is an afternoon's work; and a reader who finds an error and says so has done more
for this problem than the author has managed in a year of letters. **#AuditTheMath.**
Everyone's two cents count --- which is, as it happens, roughly the daily per-person cost of
the institution in Section 4.3.

.. container:: fineprint

   **A shorter route in.** A reader who wants the framework behind this paper without the
   theology, and without reading the whole series, should start with
   :doc:`Staying Correctable --- A Secular Reading </study/matheo/overview-secular/index>`.
   It makes the same argument in entirely secular terms and is far shorter than the papers
   it summarises.


6.4 Eighty-one anniversaries
-------------------------------

On 6 August 2026 the world will mark the eighty-first anniversary of Hiroshima. This paper
makes no claim that the date matters. **It matters that the date does not matter** --- which
is the whole of Section 2.7. The process is memoryless; no anniversary is a deadline; there
is no year in which the wheel is not spun. That is precisely what makes the risk durable and
the intuition about it unreliable.

What can be said is narrower and is not rhetorical. Eighty-one anniversaries have passed.
Over that period the crisis rate has not fallen, and there are reasons to think it has risen
(Section 2.10): the nuclear-armed states have grown from five to nine and a tenth is
declared; New START expired on 5 February 2026 with no successor and no negotiations
underway :cite:`FAS2026NewSTART`, leaving the strategic arsenals of the two largest holders
uncapped for the first time since 1972; and the failure surface has acquired cyber intrusion,
hypersonic compression of decision windows, and automated decision support, none of which
existed when the fail-safes now credited with our survival were designed.

**Eighty-one years of quiet is exactly what this model predicts most of the time**
(Section 2.7). It is not evidence that the arithmetic is wrong. It is the reason nobody
looks.


----


.. _oov1-b16-sec7:

7. Known Weaknesses
======================

**7.1 Crisis rate estimation uncertainty.** The base estimate (0.1/year) derives from
four excursions over the forty Cold-War years (Section 2.3). That is a small sample, and
the true rate could be higher (unreported incidents) or lower (selection bias). The
scenario range of Section 2.5 exists precisely because this number is not known to
better than a factor of a few.

**7.1a The direction of error is favourable but bounded --- and the bound is the point.**
It is tempting to argue that every plausible correction pushes :math:`\lambda` upward:
incidents remain classified, and the number of nuclear-armed states has grown. The first
half is true. The conclusion that the forecast is therefore an unlimited lower bound does
**not** follow, and this paper does not make it. If the count :math:`n` is revised upward
while the survival record is held fixed, the escalation probability inferred from that
record falls in step, and the product is bounded (Section 2.8). An undercount is not a
licence for an arbitrarily higher figure. This is a weaker claim than the one the
argument invites, and a stronger position: it cannot be attacked by disputing the count.

**7.1b The classification is a judgment layer, not data.** Baum et al.'s sixty incidents
are data; the decision about which of them constitute entries into the MAD state is this
paper's own, and Baum warns that the exercise is "prone to historical interpretation."
Two calls in Table 1 should be attacked first:

- **The 1961 Berlin crisis is this paper's own addition.** It is not in Lewis et al.'s
  list of near nuclear use. It is included because a live disarming-first-strike plan
  reaching a head of state meets the Section 2.3 criterion more directly than several
  events that are conventionally listed --- but a reader who rejects it is not being
  unreasonable.
- **Petrov is the most famous case and the weakest of the four.** On Baum's text alone,
  roughly five missiles were indicated, which is implausible for a first strike, and
  corroboration downstream would very likely have failed. He is retained because Lewis et
  al. independently include him.

Neither call carries the forecast: removing Petrov gives three Cold-War excursions, a
crisis rate of 0.075/yr, and 2.19 percent per year --- 1 in 46. The base case survives the
loss of its most contested member.

**7.2 Model simplicity.** Three states cannot capture dozens of actors,
thousands of weapons, or complex escalation ladders. The simplicity is a
strength (transparent, auditable) and a weakness (may miss dynamics that
change the conclusion).

**7.3 The death-trifecta parameter is the weakest joint in this paper, and it is
structural rather than editorial.** The whole forecast reduces to a product of two numbers:
the crisis rate and the per-crisis death probability. The first is **counted** from someone
else's dataset under criteria fixed before counting (Section 2.3). The second is **not
counted at all.** The 1/3 comes from the cardinality of the OSCR three-mode structure
(Section 2.2; formally derived in :doc:`Matheo-b12 </study/matheo/b12/index>`, BABL
definition and m6.th1) --- two benign modes, one lethal, hence one third.

**The objection this invites should be stated in its strongest form, because it is a good
one.** Equiprobability is not implied by trichotomy. That a failure taxonomy has three
members does not make the three members equally fast, and a reader who suspects that a
metaphysical framework's arithmetic has been imported into a rate parameter is noticing
something real. Section 2.5a varies the parameter but never escapes it; Section 2.8 shows
that calibrating it from the record instead gives roughly 3.7x lower, and declines to adopt
that for reasons that are good but are not measurements. Kennedy's estimate (Section 2.2)
brackets the value from the other side, but it is one man's recollection of one crisis.

**No revision closes this.** What the paper can do, and does, is stop the parameter from
carrying the conclusion alone: Section 2.6 pushes it, the crisis rate, and the baseline
against the thesis simultaneously, and the inequality still holds threefold. A reader who
rejects 1/3 entirely should go to that table, not to this one.

**7.4 The MAP transition mechanism.** The paper asserts that a credible
first-mover can change the game from PD to AG. The formal mechanism
exists (:doc:`Matheo-b13 </study/matheo/b13/index>`, th6). The practical instantiation --- who
goes first, how credibility is established in the nuclear domain --- is
the most important open question. b17 (:doc:`Matheo-b17 </study/matheo/b17/index>`) and b18
address this directly.

**7.5 What the model cannot predict.** The model does not predict when
a specific crisis will occur, who will be involved, or what the trigger
will be. It estimates a probability distribution. The distribution is
falsifiable.

**7.6 The COOP (Continuity of Operations Plan).** The interpretive
reading of Matthew 24 as a COOP for civilizational transition,
originally drafted as part of this paper, has been moved to b18
(:doc:`Matheo-b18 </study/matheo/b18/index>`) where it integrates with the Call to Action's
practical transition guidance. Readers interested in the COOP should
consult b18 directly. The formal argument of this paper (Sections 2--4)
stands independently of the COOP reading.

**7.7 Non-Western strategic lenses.** Different nuclear states will read
this proposal through different strategic lenses. China's no-first-use
doctrine is already closer to MAP than the US/Russia posture; China may
read this paper as validating its approach while requiring others to
change. Russia may perceive the proposal through the lens of great-power
status. Regional nuclear dynamics (India-Pakistan, North Korea) are
shaped by bilateral relationships with their own logic. The formal
argument is state-agnostic; the political implementation is not. This
gap between formal model and political reality is irreducible at the
b16 level and is addressed in b18 (:doc:`Matheo-b18 </study/matheo/b18/index>`).


----


**7.8 The death fraction is anchored coarsely.** The value :math:`q = 0.3` in Section 2.6
is now tied to Xia et al. :cite:`Xia2022` rather than asserted, but the anchoring is coarse:
their figures are for specific exchanges (5 Tg and 150 Tg of soot), while this model's
absorbing state is not resolved to a warhead count. Every mortality figure scales linearly
with :math:`q`, so the *ratios* in Section 2.6 should be read as order-of-magnitude. The
*inequality* against the global baseline survives for any :math:`q > 0.017` --- computed at
the optimistic corner, and roughly fifteen times below the lowest published estimate --- so
the comparison survives the uncertainty even though the multiplier does not.

**7.9 Stationarity is assumed, and it is assumed in the direction that favours critics.**
The model uses a constant :math:`\lambda`. The historical record is plainly not
homogeneous: the Cuban missile crisis carried more hazard in thirteen days than most
decades did. A time-varying rate would produce the same mean behaviour with a
different variance, and Section 2.10 argues the forward rate is rising rather than
constant --- which the constant-rate forecast does not capture. Tertrais (Section 5.3)
argues the opposite, that safety improvements make the rate fall. **Both cannot be
accommodated by a constant, and this paper does not attempt to.** The scenario range is
the honest response to that disagreement: it brackets both readings rather than
adjudicating between them.


.. _oov1-b16-sec8:

8. The SD1 Poster and Reproducibility
=========================================

The complete RiskyMAD model, simulation results, and MAP escape proposal
are published on a single-page poster (SD1), designed for maximum
transparency:

.. figure:: /_file/pdf/gnp/mmv3/supporting-doc/sd1/sd1-how-to-avert-accidental-nuclear-winter-and-why-its-urgent-iv_llol_qqv4_2025m12d03-page.webp
   :alt: SD1 poster --- How to Avert Accidental Nuclear Winter and Why It's Urgent
   :width: 100%
   :align: center

   **Figure 3:** The SD1 poster. Full model code, simulation results,
   and MAP escape path on a single page. Download:
   :doc:`SD1 </good-news-pack/vv/mmv3/supporting-doc/sd1/index>`.

**To reproduce the results:**

1. Download the Evolvix prototype compiler from
   :doc:`/good-news-pack/vv/mmv3/supporting-doc/evx-compiler/index`
2. Enter the model code from Section 2.4 (or from the SD1 poster)
3. Run stochastic simulations
4. Compare your results with the published forecasts

The code is public. The compiler is public. The results are public.
#AuditTheMath


----


.. _oov1-b16-sec9:

9. Companion Papers
======================

The formal argument of Sections 2--4 is self-contained. The companion
papers below provide the axiomatic framework from which these concepts
were derived. They are recommended but not required for understanding
the risk model or the MAP escape.

**Upstream** (b11--b15 provide the full formal context):

- :doc:`Matheo-b11 </study/matheo/b11/index>` (b11, PET): Formal panentheistic axiom system.
  Divine experience varies with the world's state (th4).
- :doc:`Matheo-b12 </study/matheo/b12/index>` (b12, e7Day): Self-correcting construction model.
  BABL/ZION bifurcation (th3), OSCR collapse (m6.th1), Compassion
  Capacity.
- :doc:`Matheo-b13 </study/matheo/b13/index>` (b13, e7He): Hero journey as anti-BABL inoculation.
  Commitment Trichotomy (th6), Supervillain Theorem.
- :doc:`Matheo-b14 </study/matheo/b14/index>` (b14, JUB): Innovation theodicy, the Jubilee System
  (ax25), Binary Attractor theorem (th8).
- :doc:`Matheo-b15 </study/matheo/b15/index>` (b15, Structural Deadlock): Divine Simplicity
  critique. Why ax11 (dipolarity) is necessary.

**The PET connection, and what it is not.** If divine experience covaries with the world's
state (th4 of :doc:`Matheo-b11 </study/matheo/b11/index>`), then accidental nuclear winter
affects the divine experience. Within this series' framework the connection runs
through Hartshorne's dipolar theism: the stochastic certainty result is an existential risk
for the concrete divine experience (contingent pole) while having no effect on the abstract
divine nature (necessary pole).

**It would be a mistake to call this "load-bearing" --- and equally a mistake to pretend it
played no part.** The resolution is the same one Section 4.0a reaches about the remedy, and
it is worth stating in the same words: *a theological motivation removed a disincentive to
measure; it did not supply the measurement.* PET is why the author looked. It is not why
the number is what it is. Nothing in Sections 2--4 depends on any claim in b11, and a
reader who rejects the entire theological framework should find the forecast unchanged ---
that is the test, and :doc:`the secular reading </study/matheo/overview-secular/index>`
exists to make it easy to run.

**Downstream:**

- :doc:`Matheo-b17 </study/matheo/b17/index>` (b17, h* Theorem): Falsifiable predictions.
  Who executes the plan? How to test whether they are genuine?
- :doc:`Matheo-b18 </study/matheo/b18/index>` (b18, Call to Action): Synthesis. Includes the
  COOP (Continuity of Operations Plan) for the MAD |rarr| MAP transition.


----


.. _oov1-b16-sec10:

10. Conclusion
=================

This paper set out to do one thing: put a waiting time on accidental nuclear winter, from
the historical record, with every step open to inspection. Four results follow, and the
first is the only one that needs to survive.

**The comparison holds everywhere, including where it is attacked from every side at
once.** Death by accidental nuclear winter is more likely than death by a car crash, for
most people --- annual, per person, mortality against mortality. This is not a claim about
the base case. It holds across **every** scenario in Table 3, and at the most optimistic
corner it still stands at eighteen times the global road-death baseline. That corner is not
a concession invented for this paper: it is the rate implied by the most sceptical
published reading of the record (Section 5.3). **The paper's central claim survives its
strongest critic's own numbers** --- and survives, threefold, a simultaneous stress test in
which that critic's rate, the lowest published death fraction, and the road-death rate of
the worst-affected country on record are applied together (Section 2.6). No figure here is
offered as invariant. The inequality is.

**The forecast is a bounded range, not a point.** The annual probability that accidental
nuclear winter begins lies between roughly 1 and 8 percent, with a base case of **2.90
percent --- about 1 in 34** --- calibrated from four Cuba-grade excursions in the forty
Cold-War years, counted from someone else's dataset under criteria fixed before counting.
The mean time to onset is 30 years at the base rate and **the median is 21 --- half of all
runs of world history are over inside 21 years.** Over a forty-year horizon --- one career
--- the base case gives 73 percent. **The simulations and the arithmetic agree**
(Section 2.5): forty runs of world history returned a median near 19 years and roughly one
blow-up in the first year, against exact values of 21.1 years and 1.16 per forty --- both
within sampling noise. The arithmetic does not overturn the simulations; it measures the
same thing more finely, and reads slightly worse. Earlier
formulations of "at least 1 in 40" hold at the base and pessimistic rates and over-state
only at the optimistic corner. **The single claim that does not survive** is that 1-in-40
held *regardless of scenario* --- it never did, and it was never a result of this model.

.. danger:: **This paper corrects itself, in this paper's own favour's disfavour, and says
   so where a reader will see it.** The immediately preceding draft computed its headline
   one-year probability with an exponential approximation while calling it exact. The true
   first-passage law is hypoexponential (Section 2.4a). The error ran to about 12 percent,
   in the direction that flattered the thesis, in the one number a reader is most likely to
   quote. It was found by the authors, before submission, and is reported in Section 2.0a
   rather than quietly repaired. **A paper whose only request is that others check its
   arithmetic has no standing to make that request until it has checked its own.**

**The quiet years prove less than they appear to.** The mechanism (Section 2.7) is a
saturating two-step scheme of exactly the Michaelis--Menten form, and the world sits ninety
times below half-saturation: the system is in its bound, lethal state about one percent of
the time. A process like that produces long calm stretches as a matter of course. In the
base scenario the median wait is 21 years, and yet the chance of surviving past 127 is 1.5
percent --- not negligible, and one of the forty simulated runs did exactly that. Both are
the same model. **Eighty-one years without nuclear war is therefore weak evidence about the
rate**, which is precisely what makes the intuition "nothing has happened, so it cannot be
that bad" so durable, and so unreliable.

**The bottleneck is not arithmetic, and it is not ignorance either.** That nuclear war
would be catastrophic is among the most widely known facts on Earth. What is missing is
narrower: a waiting-time distribution, in a form someone can act on. Baum's survey concludes
that nuclear war policy decisions "have made little use of risk analysis", and that "the
limiting factor is mainly the use of risk analysis for decision-making"
:cite:`Baum2018b`. Section 4.0 argues why, and the argument implicates this paper's own
author rather than exempting him: **risks without visible remedies do not get measured, and
measurements without visible remedies do not get used.** Someone with the background, the
motive, the tools, and a three-state model still took years to compute it. Section 6 reports
what happened when he then tried to deliver it, and the finding there is not that anyone
refused to listen. **It is that there is no channel** --- which is the third defining
feature of a super wicked problem :cite:`Lazarus2009` :cite:`Levin2012`, operating exactly
as specified.

What to do about that is Section 4's business, and this paper does not claim to have
settled it. What it claims is narrower and harder to dismiss: that the number is computable,
that it has been computed here from public data by a method a competent reader can repeat in
an afternoon, and that the answer is not small.

.. admonition:: The only request this paper makes

   Every input is public. The dataset is Baum, de Neufville and Barrett's. The equations
   are in Section 2.4a, and the first-passage law is derived rather than assumed. The
   classification is in Tables 1 and 2, incident by incident, so that a reader who disagrees
   with a call can strike it and recompute --- and the paper states in advance which two
   calls are weakest (Section 7.1b), which parameter is softest (Section 7.3), and what
   happens when the most contested incident is removed: 1 in 46 rather than 1 in 34.

   **Don't believe it --- #AuditTheMath.** If the model is wrong, the fastest way to find
   out is for someone to check it and say so. That is a better outcome than being right.


----


.. _oov1-b16-references:

References
=============

.. bibliography::
   :style: apa
   :filter: docname in docnames


----


.. _oov1-b16-authorship:

Authorship, Contributions, and Declarations
==============================================

| **Laurence Loewe of Laodicea** :sup:`1,2,3,4,5,6,7`

.. container:: titlepage-credentials

   | :sup:`1` Balospe and Evolvix Research (Balospe.com)
   | :sup:`2` Formerly Laboratory of Genetics and Wisconsin Institute for Discovery, UW-Madison
   | :sup:`3` Email: LLoL@balospe.org \| ORCID: https://orcid.org/0000-0002-6253-9269 \| `Google Scholar (lBchRzQAAAAJ) <https://scholar.google.com/citations?user=lBchRzQAAAAJ>`__
   | :sup:`4-7` See *Declarations* below.

**Declarations**

.. container:: titlepage-identity-footnotes

   | :sup:`4` "of Laodicea" indicates taking responsibility to undo personal complicity with disastrous Laodicean legacies like banning mathematicians from clergy (Canon 36, Council of Laodicea; two magisteria separations), enabling institutional lukewarmness, weapons of math-destruction, and slow-motion explosions of misinformation from pandemics to self-compounding interests.
   | :sup:`5` LLoL stands for ridiculous luck in serendipitous discovery and a commitment to find ever more fun ways to help others uncover street-wise math that matters.
   | :sup:`6` Loewe's traditional standards for co-authorship demand naming AI Claude Opus 4.8 Max (by Anthropic) as a co-author for many substantial contributions, as if a PhD-student. Yet, AI co-authorship is withheld here until Loewe's framework for AI co-authorship after the practical singularity (PraS) passes external human peer review (see Matheo-b21 study). Anthropic is not responsible for AI mistakes here. Loewe as senior corresponding author remains forward accountable for every number in this paper, including the ones a machine computed.
   | :sup:`7` *Licensed under the Jonah License and CC-BY 4.0 for maximal flexibility (see* https://balospe.com/en/license/joli/ *).*

**Competing interests.** The author is the creator and core compiler architect of Evolvix,
the modelling system used to produce the simulations in Section 2.5, and the proposer of
ResearchCity, the institution named in Section 4. This paper argues that a risk is
underestimated and that an institution the author proposes should be built to address it.
The author benefits, in reputation and potential funding, if that argument is accepted.
**A reader should weigh the argument accordingly, and the paper is constructed so that this
is possible:** the incident data are Baum, de Neufville and Barrett's rather than the
author's; the classification criteria were fixed before counting and are stated in full;
the closed-form solution is checkable by hand; the most sceptical published critic's rate
is in the headline table; and Section 2.6 reports what happens when every soft parameter is
pushed against the author's own conclusion at once. Section 4.0a states the reverse
exposure --- that a candidate remedy is what made the author willing to compute the number
in the first place --- and explains why that removed a disincentive to measure without
supplying the measurement.

**Provenance.** What changed between the MMv5 floor and this draft --- what was refined,
what was corrected, and the one claim that was removed --- is set out in full in
:doc:`What Changed Between MMv5 and OOv1 </study/matheo/b16/b16-changelog-mmv5-to-oov2>`,
together with links to the complete audit trail. That page exists so that this one does not
have to argue with its own history in the margins. The single correction carried in the body
of the paper is the headline figure (Section 2.0a), because a reader holding the older
number is entitled to know why it moved.
