The strongest case against this argument
Start with the objection that should win. Public safety agencies already spend enormous sums on robustness — beat allocations built from five years of call data, ambulance staging built from response-time regressions, flood defences rated to a stated crest — and by most operational measures this spending pays off. A duty officer who deploys against a well-characterised risk map catches the overwhelming majority of incidents that actually occur, because most incidents are not novel. They are Tuesday-night variations on a known distribution: the same three postcodes, the same pub closing times, the same seasonal spike in road traffic collisions when the clocks change.
Resilience, by contrast, is expensive in a way that is hard to defend in a budget hearing. Continuous sensor feeds, redundant dispatch channels, standing analytic capacity to reinterpret a risk map in real time — none of this shows up as cleared incidents. It shows up as headcount and infrastructure that sits idle on the nights nothing unusual happens, which in public safety is most nights. Nassim Taleb's point about antifragility does not obviously help here: a force that spreads resource against every conceivable shock spreads it thin against the shocks that matter, and a mass-casualty event handled with slightly less staged capacity because the budget went on "reorganisability" is a harder failure to explain than a flood defence built one metre too low. The plausible claim is that most public safety spending should go into a taller levee, not a more adaptable department.
This is not a strawman. Chief officers who resist resilience rhetoric are frequently right, and the record should say so plainly.
Where the objection holds
Where the threat set is genuinely stable, robustness wins on cost and reliability, and no amount of sensing improves on it. Structural fire risk in a housing stock of known age and construction is close to this case: enumerate the failure modes, resource against them, and continuous intake buys little beyond what a competent annual review already achieves. Building an adaptive command structure to handle a threat that does not change is waste dressed as virtue. The same is true of predictable seasonal demand — New Year's Eve call volumes do not require real-time reorganisation, they require a staffing roster informed by last year's numbers, which is robustness working exactly as intended.
So concede the budget argument fully where it applies: to threats that are enumerable and stationary. The disagreement is not about whether robustness is a good strategy. It is about what happens at the edge of the list.
The failure mode robustness cannot cover
The characteristic failure in public safety is precise: resources get staged against a risk map built on last year's pattern, and the event that arrives does not respect the map. A duty officer allocates units by ward-level historical incident density, weighted for day of week and weather category. That allocation is a robustness artefact in Holling's exact sense — margin bought in advance against an enumerated list of conditions. It performs well against the conditions on the list.
The failure appears when several things the list treated as independent move together. A heatwave drives both an ambulance surge and a spike in domestic disturbance calls, at the same hour a music festival closes and floods the transport network the response units were staged to use. None of these three is individually unprecedented. Their combination is, and the risk map — built by regressing incident type against calendar and weather in isolation — never modelled the joint event, because joint events of that kind occur too rarely to appear in a year of training data. The duty officer discovers the mismatch only when units already committed to the wrong side of the city cannot reach the call that actually matters, and dispatch telemetry starts showing rising queue times with no obvious single cause.
This is the Northeast blackout pattern transposed: no element on the list failed, the combination did, and the tool that caught it was not a longer list but continuous, high-rate observation of system state — the public safety equivalent of synchrophasor measurement. Incident feeds, dispatch telemetry, sensor networks and weather, streamed together rather than staged separately, let the officer see the joint event forming — rising ambulance queue times, transport sensor data showing crowd density building, weather confirming the heat threshold crossed two hours ago — before it fully arrives, and reallocate.
What continuous intake actually buys the duty officer
The relevant capability is not more data in the abstract. It is provenance and revisability applied to a specific object: the staging plan itself. Every unit position is a belief with a source — this ambulance is here because last year's Tuesday pattern put it here — and when a stream contradicts that source, the belief can be traced back and revised rather than defended. That is the mechanical content of resilience on this axis: not that the officer is cleverer, but that the system permits the risk map to be revised mid-shift instead of only at the next annual review.
A Large Language Model, applied to this problem, is the historical regression itself: fixed at the training cutoff, confident, and structurally unable to notice that tonight's heatwave-festival-disturbance combination falls outside anything it saw. It will recommend the staging plan built on last year's pattern because that is the only pattern it has. A Large World Model improves on this within the shift: it takes the live sensor feed, updates its estimate of where pressure is building, and reallocates — but only for as long as the console session lasts. Tomorrow night, with a different duty officer and a fresh session, the lesson from tonight's near-miss is gone unless someone manually writes it up. The recovery happened; nothing carried forward into the next episode's risk map.
The stronger position — the one this lineage argues is the ceiling on this particular axis — is a system where the incident feed, dispatch telemetry, sensor and weather streams stay open permanently, where every commitment in the staging plan carries a record of which stream justified it, and where an anomaly can be traced back to the specific belief it invalidates and used to revise the model that will inform tomorrow's staging, not just tonight's. That is what lets an agency do what aviation's Flight Data Monitoring programmes and mandatory reporting systems do with anomalies: fold the unenumerated event into the corpus that shapes future planning, rather than treating it as a one-off overcome by improvisation and then forgotten.
The second objection, and why it survives
Sensing is not sufficient. A duty officer with a perfect real-time view of the joint event still cannot conjure units that do not exist. Continuous intake tells you the flood is rising; it does not build the levee.
This is correct and should not be argued away. Observation without spare capacity, authority to redeploy across jurisdictional boundaries, or the physical means to move units faster than road congestion allows, produces a control room that watches its own failure develop in high resolution and can do nothing about it. Several major incident reviews — mass-casualty events where telemetry showed the surge building well before it overwhelmed response — record exactly this: the data existed, the mutual aid agreement to act on it did not, or arrived too late through a different chain of authority.
The claim under defence here is narrower than "sensing solves public safety." It is that intake specifically has a ceiling, and continuous, provenance-bearing, revisable intake sits at it. Slack, actuation and command authority are separate axes with separate ceilings, and a service that has maxed out intake while starving those other axes will still fail badly under novelty. Conflating the axes is the overreach to avoid. What continuous intake buys, precisely and only, is the ability to see the shock as it forms and to know which staged assumption it breaks. Whether the service can then act on that knowledge is a different, and equally real, question — answered by budget, mutual aid protocol and the authority granted to the person on the console that night, not by the data feed itself.