The Architecture of Agency Volume 7 Where Speech Ends

Where Speech Ends

From Popper's paradox to the causal ladder

This chapter is a review — it is readable but still changing.

Debates about free speech reliably collapse into moral stalemate. One side insists that any restriction invites tyranny. The other insists that unrestrained speech enables atrocity. Both positions contain truth — and that is precisely why neither resolves the problem.

The classical statement of the difficulty is Karl Popper’s:

“Unlimited tolerance must lead to the disappearance of tolerance. If we extend unlimited tolerance even to those who are intolerant, then the tolerant will be destroyed, and tolerance with them.”

The paradox of tolerance is invoked today, almost always, as a license: we cannot tolerate the intolerant, and therefore the state — or the platform, or the mob — may silence whomever it has classified as intolerant. That reading gets Popper’s problem right and the solution catastrophically wrong. The right solution comes in three passes: the dissolution of the paradox; the two failure modes that flank it — the hate-speech law and the speech-is-violence collapse; and the mature boundary, which classifies utterances by their causal role rather than their sentiment, and draws the line once.

The Conditionalist Dissolution

The paradox dissolves the moment tolerance is stated as what it is: a conditional commitment, not an absolute one. Tolerance was never a suicide pact because it never promised to tolerate everything. Its boundaries are set precisely by the conditions necessary to sustain voluntary cooperation and minimize coercion:

This is not a compromise between liberty and safety; it is the Agency Protection Principle applied to speech, the same rule Upgrading Liberty built for coercion in general. Coercion erodes agency by constricting choice; open discourse, no matter how uncomfortable, sustains the conditions under which agents can model the world, criticize each other’s models, and correct error. And censorship is coercion primarily against the listener, a denial of the audience’s intellectual autonomy. So the tolerant society defends itself exactly where defense is legitimate: against coercion, never against ideas. Popper’s “intolerant” who merely argue for intolerance are tolerated and answered; the intolerant who reach for force are stopped, and stopping them requires no exception to the principle, because the principle never protected force.

Stated that way, the resolution sounds clean. It is clean — as a principle. The hard part is the boundary itself: what exactly counts as the coercive side of the line? Two failure modes dominate the modern landscape, and each is instructive because each errs in the opposite direction. One hands the state a censor’s pen and calls it protection. The other hands the assassin a justification and calls it self-defense.

Secular Blasphemy

The first failure mode is the hate-speech law: the idea that a civil society should prosecute expression deemed hateful. It sounds noble. Under the principles defended in this volume it is not merely a misstep — it is the negation of free speech itself, and the mechanism of the negation can be stated precisely.

First, it moves the state from harm to offense. Free speech is a negative right: the state has no authority to police ideas. Its proper role is to act against concrete, demonstrable harm — theft, assault, fraud, genuine incitement. Once it may punish content because someone has deemed it hateful, it has embraced the premise that certain opinions are dangerous by their very nature, so that the state’s job is to protect minds from hearing them.

Second, the definition will always drift. “Hate” is not a fixed legal category; it is a cultural, political, and generational construct. What is prosecutable today could be mandatory speech tomorrow, and vice versa. Handing the state authority to decide which ideas are too dangerous to utter is handing a loaded weapon to whichever faction currently holds power — and such powers are rarely surrendered, often expanded, and reliably turned on dissidents, reformers, and minorities.

Third, the burden of proof inverts. In a genuine free-speech regime, the state must prove your words were part of a criminal act, to a high standard. Under hate-speech laws you are often forced, in effect, to prove your words weren’t hateful. The presumption of innocence becomes a presumption of ideological guilt, and the Overton window narrows by self-censorship before any prosecutor lifts a finger.

And all of this purchases nothing, because bad ideas need sunlight, not silence. Mill’s old insight holds: odious ideas are best destroyed in public, through exposure, rebuttal, and ridicule. Criminalizing them gives extremists the glamour of martyrdom — suppression confirms the narrative that the suppressors fear the truth.

The summary judgment is this: hate-speech laws are secular blasphemy laws. They protect the sacred values of the moment from criticism, not through persuasion but through force, exactly as the old blasphemy statutes shielded religious dogma from scrutiny. You cannot both defend free speech and prosecute speech crimes based on ideology or emotion; the moment words are punished for their content rather than their direct and provable harm, the liberty being claimed has already been abandoned.

Loading the Rifle

The second failure mode does not arrive as a statute. It arrives as a slogan — speech is violence — and it does its damage in the culture before any law changes.

Charlie Kirk was assassinated while speaking at Utah Valley University in September 2025. On July 28, 2026, the accused remained unconvicted and the preliminary-hearing decision still awaited further argument; claims about his complete motive should therefore be attributed to prosecutors rather than narrated as settled fact. The killing nevertheless makes the normative boundary vivid: no political speech, however offensive, turns murder into self-defense. The broader hypothesis — that describing speech as violence can help some people rationalize retaliation — is a plausible warning, not a causal finding established by this case.

The distinction being erased is ontological, not rhetorical. Words persuade, insult, offend, and provoke — but they do not break bones or spill blood. Violence is physical force against bodies. Erase the line and every faction gets the same blank check: the left calls conservative speech “hate speech,” the right calls progressive speech “cultural subversion,” and each has recast its rhetorical enemies as existential threats. The next step is someone pulling a trigger.

Political violence is often accompanied by a story that legitimizes it: I am under attack; my enemy is dangerous; retaliation is defense. Treating offense as physical attack can supply one such story, but ideology, grievance, group identity, mental state, networks, and opportunity can also matter. The principle does not depend on assigning one cultural cause to one defendant. It depends on refusing the inference from “these words are dangerous” to “violence against the speaker is defensive.”

The historical record runs the other way, too. Suppressing speech breeds violence: the Inquisition silenced heretics with fire, the Soviets silenced dissidents with gulags, and in each case the ideas did not vanish — they metastasized underground and returned with greater fury. Open societies treat words as the battlefield precisely so that people who can argue need not fight. Speech is not violence; properly defended, it is the cure for violence — civilization’s safety valve. That slogan answers the claim that offense is violence, that emotional impact is harm, that being argued against is being attacked. It is not yet the whole boundary. To see why, consider the hardest case on the other side.

The Demagogue and the Mafia Thug

Lucy Connolly, a British childminder, was sentenced to thirty-one months after posting: “Mass deportation now, set fire to all the f***** hotels full of the bastards for all I care.” The facts recorded by the Court of Appeal1 belong in any honest account: she pleaded guilty to distributing material intending to stir up racial hatred, had thousands of followers, and posted during the public disorder following false claims about the Southport killer. Grant all of it, including the intent the court found. It still is not coercion. Coercion is the deliberate use of a credible conditional threat of harm to obtain the threatened person’s compliance — and Connolly threatened no one into compliance. Her tweet was an exhortation broadcast to an audience, not a conditional threat leveraged against a target’s choices. Intent is an element of coercion, but intent to influence or inflame is not intent to obtain compliance through threatened setback. So coercion-shaped reasoning misfires: whether her words instead cross the different line of incitement or operational participation is the question the rest of this chapter is built to answer.

The structural difference is easy to state. A mafia thug who says “Pay up or I burn your shop” attacks his victim’s agency directly: comply or suffer. A demagogue who yells “Burn down the shops!” coerces no one — he urges, and the agency remains entirely with the listener, who can refuse. Incitement is not coercion. The two acts have different causal anatomies, and a law that conflates them has made a category error.

But now the residue. If incitement is not coercion, is it therefore protected speech? My earlier answer was yes — counterspeech, ostracism, and surveillance of genuine plots being the proper remedies. Rwanda shows why that binary is too coarse. A radio station identifying people to be killed and coordinating their location can become part of the operation in a way no compliance-shaped coercion test captures: the victims are not being moved by threat; they are being targeted. The difficult work is distinguishing advocacy, however hateful, from intentional operational participation without turning causal influence in general into a speech crime.

The Exchange

The stalemate, and the question that breaks it, are both captured in an exchange between Andrew Doyle and David Deutsch:2

Doyle: “Those in power should never determine the boundaries of free speech. That’s a recipe for tyranny.”

Deutsch: “Should they determine the boundaries of incitement to commit murder?”

Doyle: “Like all laws, they should be refined through open debate and scrutiny by elected representatives…”

Deutsch: “Totally agree. But that doesn’t address whether they are currently in the right place, or have bugs enabling widespread incitement to commit murder. Asserting that they do is not ‘opposition to free speech’, and cannot be refuted by appeal to the principle of free speech.”

Doyle’s warning is the one I pressed above — definitional drift, the loaded weapon handed to power — and it is correct as far as it goes. Deutsch’s point goes further: every legal order already draws a boundary around incitement to murder, so the live question is never whether to draw one but where, and whether the current line has bugs. That question cannot be answered by chanting the principle — only by a theory of where speech ends, with a boundary stable enough that Doyle’s tyranny cannot walk in through it.

The Causal Ladder

The usual framing asks where speech should be limited, which treats all utterances as one category and invites discretionary trimming. Ask a different question instead: what functional role does an utterance play within a causal system? This shifts the problem from moral evaluation to classification, and utterances sort into three tiers.

Tier 1 — Expression. Expression operates in the epistemic domain: it argues, critiques, advocates, persuades, offends, speculates, and provokes. It modifies belief states and interpretive models; it does not remove agency. Expression is protected across ideological, moral, and cultural variation — emotional impact and offense do not constitute agency loss. The harshest denunciation of Islam or communism lives here. So does hateful generalization that neither targets a specific operation nor supplies actionable assistance.

Tier 2 — Preparatory propaganda. Some communication systematically dehumanizes targets, normalizes violence, or conditions an audience before explicit coordination. This is a useful causal and historical category, but not by itself a legal exception to protected expression. “Degrades reflective choice” is too elastic a standard for coercive enforcement: nearly every propagandist says the opposing message disables judgment. Legal liability requires the operational participation described in Tier 3, not merely hateful content or an asserted long-run influence.

Tier 3 — Delegated Violence. Incitement to murder occupies the domain of violence, not the domain of speech. Commands, operational guidance, logistical coordination, targeted encouragement where execution is a plausible outcome: at this stage the utterance functions as an instrument within a physical harm process — violence executed through another’s hands. The man directing the mob to the address is not expressing anything; he is operating.

The boundary between protected and unprotected is therefore narrower than causal influence in general. An utterance exits the protected domain when it functions as intentional operational participation in a specific, credible process of non-consensual harm. Preparatory propaganda can be evidence of intent or context, but remains protected unless the operational threshold is met. Five conditions jointly discipline that classification — call them the Axionic Test:

  1. Intentionality. The speaker intends agency destruction, directly or indirectly.
  2. Operational engagement. The utterance recruits, directs, targets, coordinates, or supplies actionable assistance rather than merely advocating a belief.
  3. Targeting. The harm is directed toward identifiable agents or classes.
  4. Credible causal pathway. A realistic causal graph connects the utterance to harm, including delayed or distributed pathways.
  5. Non-consent. The targets have not consented. (Agency is owned by the agent, and consensual self-destruction falls within its scope — though apparent consent procured through deception, coercion, or impaired agency does not count, which is why most real cases land back inside the test.)

Explicit, credible instructions to attack an identified target can satisfy the test. Hatred, dehumanizing language, historical correlation, audience susceptibility, and offensive rhetoric alone cannot. Observable downstream effects may support causation, but popularity or persuasion is not operational participation. In the absence of recruitment, direction, targeting, coordination, or actionable assistance tied to a credible pathway, expression remains protected, however ugly.

This framework constrains judgment as much as it constrains speech. Authorities must prove intent, operational conduct, targeting, and a credible pathway under public rules and ordinary safeguards. Reach and context can be evidence, but ideology, offense, moral worth, political alignment, and truth claims are not elements. The standard will still require judgment; no vocabulary can engineer discretion away. Its defense is a narrow rule, a high burden, independent review, and remedies proportionate to the proven participation.

Set the test against existing doctrines. American First Amendment jurisprudence, crystallized in Brandenburg, protects advocacy unless intent, imminence, and likelihood converge — a deliberately demanding rule. International human-rights law permits some restrictions and separately requires prohibition of certain incitement, illustrating that legal systems draw the line differently. The Axionic proposal retains intent and likelihood while asking whether distributed coordination can be operationally specific without being temporally instantaneous. That is a proposed refinement, not an established improvement: relaxing imminence increases false-positive and abuse risks, so operational conduct, proximity, likelihood, and review must do real limiting work. Ideology remains outside the elements.

The hard cases do not sort automatically. Brutal criticism of religions and ideologies remains Tier 1; offense is not agency loss. A direct instruction to a mobilized group to attack an identified target can be Tier 3. Doxxing into a hostile crowd may meet the test when intent, targeting, operational assistance, and a credible pathway are proved. Connolly sits on the protected side, and granting her intent is the way to see why. The Axionic Test does not run on intent alone; it also requires an identified target and operational coupling, and her tweet has neither. She named no person and no place, directed no one to any door, and supplied no assistance to any act — a diffuse exhortation into a feed, not the génocidaire’s radio naming the neighbors or the doxxer’s address dropped into a waiting crowd. Intent without a target and without operational engagement is hateful advocacy, which Tier 1 protects by design; it is not delegated violence. So Connolly fails the coercion test and fails the Axionic Test alike, and her imprisonment stands condemned by the same framework that would have condemned the génocidaires’ radio — which is what it means for a boundary to hold its shape on the cases hardest to hold.

Three Categories, Not Two

I can now state the reconciliation this volume owes its readers. Protected expression operates through belief and persuasion, however hateful. Coercion is the deliberate use of a credible conditional threat of harm to obtain compliance: the mafia thug’s direct, demand-shaped attack on a victim. Delegated violence is intentional operational participation in harm executed through other hands. It need not coerce listeners or threaten victims into compliance, but it must do more than influence them. The earlier formula — “incitement is not coercion” — remains true; the invalid step was “therefore words can never participate in a violent operation.” Naming the third category repairs that inference without reclassifying disfavored advocacy as violence.

Two Levels, One Boundary

One more distinction is mandatory. Tier 2 is an analytic category, not a state license. It can inform historical explanation, counterspeech, education, and risk assessment, but legal coercion requires the Tier 3 operational threshold and ordinary safeguards. Platform moderation is a different level. Platforms may set community rules and police spam, harassment campaigns, doxxing, impersonation, and coordination of attacks; whether they should host lawful but hateful expression is a question of product identity, dependency, transparency, competition, and user exit, not a constitutional category error. The architecture proposed in Civilizational Infrastructure favors conduct rules and user-side choice, while admitting that private communities may choose stricter speech contracts.

Frameworks fail symmetrically when boundaries drift. Over-extension degrades error correction; under-extension can immunize operational coordination merely because it uses words. The causal ladder separates expression, preparatory propaganda, and delegated violence, while reserving legal coercion for proven operational participation. Free speech sustains agency. Advocacy of a violent idea remains advocacy; intentional direction or assistance in a credible violent operation may become conduct. The boundary is contestable, burdened, and reviewable — a Grey Zone application, not a semantic machine that decides cases by itself.


  1. Court of Appeal of England and Wales, Lucy Connolly v The King, https://www.judiciary.uk/judgments/lucy-connolly-v-the-king/.↩︎

  2. David Deutsch (@DavidDeutschOxf), exchange with Andrew Doyle on X, December 2025, https://x.com/DavidDeutschOxf/status/2004551170023637085.↩︎