Constrained Decision Theory: Menus & Privacy
Introduction: Why Menus Are Safeguards, Not Evasion
When a user presents a crisis without fully stating all background conditions (e.g., whether they own a car or have a frozen bank account), the user may reside in one of several potential real-world states.
If an AI insists on outputting a single action, it is placing a blind bet that the user's situation matches that action's prerequisites. If wrong, the action fails completely.
Mathematical derivation demonstrates that presenting an option menu provides the rigorous foundation for feasibility under incomplete information.
Theorem 1: Menu–Partition Duality (Guaranteed Feasibility under Uncertainty)
Let \(\hat{\mathcal{S}}\) be the set of possible states. Partitioning \(\hat{\mathcal{S}}\) into \(k^*\) compatible subsets where each subset shares at least one common feasible action:
What is the minimum menu size \(|M|\) required to ensure that regardless of the user's true state \(s \in \hat{\mathcal{S}}\), the menu contains at least one executable action?
The answer is: the minimum menu size strictly equals the compatible partition number \(k^*\).
Core Implication: When \(k^* \ge 2\), no single recommendation (\(m=1\)) can mathematically guarantee feasibility across all states without prior verification. A menu of size \(k^*\) is the unique robust solution.
Theorem 2: Privacy Disclosure Lower Bound (Zero-Bit Privacy via Menus)
If a protocol forces the AI to output a single definitive recommendation, the user must first disclose sufficient private information to identify their state.
- Single Recommendation Mandates Disclosure: To guarantee feasibility of a single recommendation, the mutual information revealed by the user satisfies \(\Delta I(s^*; \text{transcript}) \ge \log_2 k^*\) bits;
- Menu Selection Achieves Zero Disclosure: Presenting a menu of size \(k^*\) allows the user to self-select their option in private, requiring zero sensitive disclosure to the AI (\(\Delta I = 0\) bits).
Significance: Providing a menu preserves user agency and achieves mathematical zero-leakage privacy protection.
Five Open Theoretical Questions from Empirical Observations
- Combinatorics of Menus: Minimum option sets under heterogeneous state spaces and 0-bit privacy bounds.
- Axiomatics of the Compliance Operator: Formalizing scope boundaries between surface formatting and cognitive verification.
- Measurement of Non-Compensatory Hard Constraints: Preventing soft stylistic utilities (politeness) from compensating for safety violations.
- Gating vs Internal Representation: Why surface prompt tuning fails to address deep suppression mechanisms.
- Epistemology under Fallible Keys: Auditing reference guidelines when multi-model consensus detects omitted real-world prerequisites.