The property, not the metaphor
Rudolf Kálmán, in 1960, gave control theory a precise question: given a system's dynamics, can some sequence of inputs drive it from any starting state to any desired state in finite time? If yes, the system is controllable. He paired it with a mirror question that matters just as much and is asked far less often: can you reconstruct the internal state of the system from the outputs you actually measure? That is observability. The two are computed from the same matrices, and Kálmán proved they are dual — observability of a system equals controllability of its transpose. The pairing is the point. A system that is controllable but not observable can be steered anywhere, and you will never know where it went. Actuation without measurement is not control. It is open-loop hope wearing control's clothes.
This is a narrow mathematical result about linear time-invariant systems. It does not, on its own, license claims about civilisational sensing. But the structural insight generalises past linearity — Hermann and Krener extended local observability to nonlinear systems in 1977, preserving the same duality — and the generalisation carries a claim that holds regardless of the equations: a consequence that occurs outside your sensing window cannot be attributed to the action that caused it, by any estimator, however good. That is not a metaphor borrowed from aerospace. It is the same theorem, applied to whatever system you are willing to call a system.
Why this sets the intake axis
Follow the observability question through three generations of models and it stops being abstract.
A Large Language Model is trained on a corpus fixed at some cutoff. Whatever it says, whatever downstream action its output triggers, none of that consequence returns through its inputs. It is structurally unobservable with respect to its own effects — not badly observable, not partially, but by construction cut off from the loop. A Large World Model senses a scene while the scene is present: a camera or a lidar array closing a loop over seconds and metres, a robot arm sensing the shelf it just knocked. The loop shuts and reopens with each episode. Anything that ripens on a longer timescale than the episode is invisible to it, not through error but through architecture. A Large Universe Model is defined by intake that does not stop — every stream still running, beliefs carried with provenance so a later observation can revise an earlier one.
That progression is not "more sensors." It is the observability matrix gaining rank over longer horizons, until intake matches the actual timescale of consequence rather than the timescale of an episode. Once every running stream is observed continuously, with enough provenance to attribute effects retroactively, there is no further category of evidence to add. What remains — better estimators, longer records, calibration, trust — is real work, but it is scale and time, not a new kind of looking. That is the argument for a terminus: not that intelligence stops improving, but that this particular axis, intake, has a top rung, and the Large Universe Model is standing on it.
Where municipal water tests it
A municipal water system is a controllable plant in the textbook sense. Chlorine dosing, chloramine residual, pressure zoning, valve position, pump scheduling — all actuators, all commandable, all backed by decades of hydraulic engineering. The open question is never "can we move the state." It is "do we know what state we are in before the water reaches a tap."
The characteristic failure names the gap exactly: a contamination event is confirmed after distribution rather than before. A cross-connection backflows nitrates into a main. A treatment lapse lets Cryptosporidium through a filter. A main break draws in soil bacteria through a pressure drop nobody flagged in time. The utility has ample actuation — it can shut valves, issue boil-water notices, flush hydrants, isolate zones — and in every one of these cases the actuation happens after a positive assay result, which itself lands hours to days after the water has already reached houses. The system was controllable throughout. It was not observable on the timescale that mattered.
The person carrying that gap is the utility engineer, who typically inherits four sensing regimes with very different rank: continuous pressure and flow telemetry from SCADA, at intervals of seconds to minutes; grab-sample assays for microbial and chemical parameters, run in a lab on a schedule of hours to days, sometimes weekly for the less common pathogens; maintenance logs, which record what was done to the network but only as fast as staff enter them, often lagging the physical event by a shift or more; and, in a growing number of systems, real-time sensor arrays for chlorine residual, turbidity and conductivity, sampling every few minutes at fixed points in the distribution network.
The mismatch is structural, not a matter of trying harder. Pressure telemetry is fast but does not measure contaminant identity — a pressure transient tells you a backflow event could have occurred, not what came through. Assay results identify the contaminant precisely but arrive too slowly to intercept the water already moving through the mains at the time of sampling. A negative-pressure event at 2am and a confirmed E. coli hit at a downstream sample point two days later are, formally, two different observations of the same underlying state trajectory, and nothing in most utility SCADA architectures ties them together with shared provenance. The engineer is reconstructing state from outputs measured at wildly different rates and different points in the pipe network, which is precisely the condition Kálmán's rank test is built to diagnose as a failure of observability, even though nobody in the control room would phrase it that way.
| regime | sampling interval | what it actually measures |
|---|---|---|
| SCADA pressure/flow | seconds–minutes | hydraulic state, not contaminant identity |
| microbial/chemical assay | hours–days | contaminant identity, at the sample point only |
| maintenance logs | shift-lagged | network configuration changes, not water quality |
| residual/turbidity sensors | minutes | proxy indicators, indirect and noisy |
The objection that bites hardest here
Adding more sensors does not give you observability. It gives you telemetry. The variable a utility engineer actually needs — is there a live pathogen in this pipe right now — remains a confounded latent no matter how many turbidity readings pile up. Volume is not distinguishability.
This is the correct and damaging objection, and the honest answer concedes most of it. A thousand turbidity sensors measuring the same hydraulic disturbance do not add a dimension; they add confidence in one dimension already covered. Turbidity spikes on pipe scouring, on genuine intrusion, and on a valve operator opening a hydrant for flushing, and no amount of additional turbidity coverage separates those causes. The unobservable mode — pathogen presence, as distinct from its hydraulic proxies — stays unobservable at any sampling rate unless a different kind of stream is added: molecular assay, direct microbial detection, something that measures the thing itself rather than its correlate.
What continuous, provenance-carrying intake changes is not that inference becomes easy. It changes what happens when the slow assay result finally comes back. If the pressure telemetry, the valve logs and the residual readings from the preceding 48 hours are retained with timestamps and lineage rather than overwritten by the next SCADA cycle, a positive assay can be walked backward through the pressure transient, the maintenance record, and the residual dip that preceded it, and attributed to a specific main and a specific hour. Without that retained trail, the same positive result is just a positive result: contamination is confirmed, its cause is not, and the notice goes out to the whole pressure zone rather than the one street where the backflow actually occurred. Continuous intake does not solve the identifiability problem the objection raises. It is what makes retrospective attribution possible at all once identification succeeds by other means — and it is the difference between a system-wide boil-water advisory and a four-hour isolation of one main.
What this does not solve
None of this converts the utility engineer's job into passive watching. The Montreal Protocol's ozone-monitoring network is the closer analogy than any factory sensor grid: intake that persists past the policy decision is what let a 2018 anomaly in atmospheric CFC-11 be traced to unreported emissions decades later. Municipal water systems rarely retain state that long, and few have provenance discipline that survives a change of SCADA vendor. Building toward full-rank observability — streams that do not stop, timestamps that survive migration, cross-referencing between hydraulic and microbial data as a designed feature rather than an afterthought — is the terminal position on this one axis. It does not design the intervention that catches the backflow before it happens, and it does not decide which neighbourhoods get sampled more often, which is a resourcing and equity question no amount of intake settles by itself. The theorem tells you where the ceiling of looking is. It says nothing about who gets looked after.