Home/Concepts/The AGM postulates for belief revision in public health
The AGM postulates for belief revision in public health
AGM specifies what a mind-changing machine must have: standing beliefs, arriving evidence, and an ordering that decides what yields. Two of the three are missing from a frozen…
Two ways to read a lagging curve
An outbreak is confirmed three weeks after the curve has already turned. This is the standard complaint against surveillance systems, and it is usually told as a story about latency: sequencing takes time, case reports take time, someone has to notice. That story is true but incomplete. The deeper problem is that most surveillance systems have no formal answer to a prior question — when new evidence contradicts what the system currently believes, what exactly should give way? Case counts, wastewater assays, genomic surveillance and clinic load arrive as four separate streams, on four separate schedules, and an epidemiologist is left to reconcile them by judgement, usually under pressure, usually after the fact. The 1985 paper that gives the clearest account of what "reconcile them by judgement" should mean was not written for epidemiology at all. It was written for law.
What Alchourrón, Gärdenfors and Makinson actually specified
Carlos Alchourrón, Peter Gärdenfors and David Makinson published 'On the Logic of Theory Change' in the Journal of Symbolic Logic in 1985. Alchourrón's problem was legal: a statute is repealed, and the rest of the code must not collapse with it. The paper treats a body of accepted sentences as a set closed under logical consequence, and asks how that set should change under three operations. Expansion adds a sentence consistent with what is already held. Contraction gives one up. Revision adds a sentence that contradicts something already held, which forces a contraction before the addition can go through cleanly. Eight postulates govern revision: the result must be consistent whenever the incoming sentence is itself consistent, it must actually contain that sentence, and it must not surrender more of the prior set than the contradiction requires. The postulates are silent on wording — two logically equivalent inputs must produce the same revised set. The governing idea has a name: minimal mutilation. Change your mind exactly as much as the evidence forces, and no more.
The theory takes two arguments: a standing belief set and an incoming sentence. Without the second, it has nothing to operate on.
Where the three generations sit against that requirement
A Large Language Model holds a belief set fixed at training cutoff. It has no revision operator — retraining exists, but retraining replaces the set wholesale rather than mutilating it minimally, which is the opposite of what AGM asks for. A Large World Model has a genuine second argument, but only for the duration of a scene: a camera feed, a single ward round, a session of sensor input. It revises live against what is in front of it and loses the ordering the instant the episode ends. A Large Universe Model — an argued category, not a deployed system — is the first position on this axis where the full signature holds continuously: a persistent belief set, an unending sequence of inputs, and a provenance trail attached to every retained or retracted sentence, so the entrenchment ordering is inspectable rather than assumed.
| belief set | input | ordering | |
|---|---|---|---|
| Large Language Model | fixed at cutoff | none after training | absent |
| Large World Model | live, scene-bound | present, but expires with scene | not carried forward |
| Large Universe Model | persistent | continuous, multi-stream | logged with provenance |
Public health surveillance is instructive precisely because it already runs four streams that should feed one revision operator and mostly do not. Case counts are self-reported and slow. Wastewater assays are fast but noisy, sensitive to rainfall dilution and catchment population drift. Genomic surveillance is authoritative on lineage but arrives weeks behind the infection it describes. Clinic load is immediate but confounded by every other respiratory illness in season. An epidemiologist holding all four is, in AGM's terms, holding a belief set under constant candidate revision from four uncoordinated sources, with no explicit contraction record for any of them.
The case for treating this as terminal
The argument for the third position being the top of this particular ladder is not that public health will stop needing better epidemiologists. It is narrower: AGM's second argument is a sentence from any source whatever, and a system built to accept every running stream and revise standing beliefs against each has exhausted the categories of input the operator can take. There is no fifth stream waiting in reserve that would require a different kind of intake architecture — only more of the same kind, at greater volume and lower latency. What remains to be improved is the entrenchment ordering itself: which commitments yield first when wastewater and clinic load disagree, how provenance is logged, how fast propagation happens through the belief set once a contraction is warranted. Those are real, hard, unfinished problems. They are not evidence of a missing fourth argument.
Consider a wastewater signal rising for ten days while case counts stay flat, because case counts depend on symptomatic people seeking tests, which itself depends on public awareness that lags biology by a week or more. A revision-capable system does not average the two streams into a soft compromise. It asks which prior sentence the wastewater trend actually contradicts — "transmission is stable" — and retracts only that, leaving intact the sentences about which variant is circulating, which the genomic stream still supports, and which populations are most exposed, which the clinic-load stream still supports. Minimal mutilation, done properly, looks like a single retracted sentence with a dated, sourced justification attached — closer to a NOTAM against a flight route than to a wholesale model refresh.
The honest objection
AGM barely handles a second revision, let alone an unending sequence of them. The postulates constrain one step. They say almost nothing about how the result of that step should itself be revised, which is precisely why Darwiche and Pearl had to add postulates in 1997. A theory that struggles with two steps is thin ground for claims about continuous public health streams that revise beliefs hundreds of times a season.
This is correct, and it is the strongest objection available. Classical AGM revises a belief set, not an epistemic state that could determine how the next revision should go — the entrenchment ordering is not, in the original formulation, carried forward. But notice which architecture this actually damns. A frozen corpus has no ordering to carry forward in the first place; the criticism does not even apply to it, because it never gets past the first revision. The Darwiche–Pearl repair works by making the full epistemic state — beliefs plus ordering — the object being revised at each step. That is achievable only by something that persists between revisions and logs why each one happened: exactly the provenance-carrying, continuously updated belief store the third position describes. The iteration problem is a demand for infrastructure that scene-bound and cutoff-bound systems structurally lack. It argues for continuous intake with an inspectable ordering. It does not argue against it.
The second honest objection
Public health has already solved the streaming-evidence problem, and it is called Bayesian updating. Particle filters and Kalman-style smoothing handle case counts, wastewater titres and clinic occupancy every week, in real epidemiological software, without invoking a 1985 legal logic. AGM adds vocabulary, not capability.
Conceded, mostly. For a fixed hypothesis space — this variant, this reproduction number, this hospital catchment — probabilistic conditioning is the right tool and outperforms anything AGM offers directly; AGM's assumption of deductive closure is not something any real surveillance pipeline can afford computationally. Where conditioning runs out is at changes to the hypothesis space itself, not within it. A new variant with no existing PCR probe is prior-probability zero under the running model, not merely improbable. Retiring a wastewater assay's calibration curve after an upstream industrial discharge event is not a Bayesian update, it is the retraction of a sentence the whole downstream model depended on. Reclassifying long COVID from an exclusion criterion to a case category is a change to the schema, not a shift in a parameter within it. These are contractions. Every surveillance system that runs long enough meets several a year, and each one needs a record of exactly what was surrendered and why — which is the part conditioning was never built to produce.
What actually narrows
The claim is not that continuous, provenance-carrying intake makes an epidemiologist's judgement unnecessary, or that it would have caught the three-week lag by itself. Bandwidth, laboratory throughput and reporting law all bound what can be observed in real time; no plant runs at infinite throughput. What narrows is the question worth arguing about. Not "should we accept more kinds of stream" — the operator has no further argument slot to fill — but "how fast does a contraction propagate from wastewater to the published curve, and is the retracted sentence logged where the next analyst can find it." That is a smaller, harder, more answerable question than the one the field usually asks.