Bolt antilock brakes onto a fleet of taxis and the drivers don’t get safer. They follow closer and brake later. A German study from the 1980s (Aschenbrenner and Biel) put ABS in Munich cabs and watched the driving get more aggressive — enough to eat most of the safety the brakes were supposed to buy. The same argument has been made about seatbelts, ski helmets, and football pads: make the activity feel safer and people don’t bank the safety. They spend it.
The name for this is risk compensation, and its stronger cousin is risk homeostasis — the idea that each of us carries a target level of risk we’re willing to tolerate, like a thermostat setpoint. Lower the felt danger and behavior drifts back up to refill the gap. Worth an honest hedge: the strong version, where people fully cancel out every safety gain, is contested and probably too neat. The robust, replicated finding is partial — behavior moves toward the risk it’s willing to live with. It doesn’t sit still just because you made things safer.
Here’s why that belongs in a builder’s head. Every safety net you ship is also a behavior change you forgot to put in the changelog.
Autosave doesn’t just protect work — it quietly teaches people to stop saving, stop keeping their own copies, stop being careful with the thing in front of them. Undo makes people delete freely. A “we’ll confirm before we charge you” makes them click straight through the scary screen. A dry-run mode makes them skip reading the real one. A sandbox makes someone paste the live API key “just to test.” You built a net; they recalibrated to it. And most of the time that’s the entire point — you want them bold, exploring, not hoarding drafts in fear. A net that buys courage is a feature, not a bug.
The failure comes in two shapes.
The first is assuming the net is invisible — that adding undo changes nothing except the rare rescue. It doesn’t touch the rare case much at all. It changes the median action, the everyday level of care, for everyone.
The second is worse: dressing your one genuinely irreversible action in the same reassuring costume as all the reversible ones. A delete that empties a shared workspace. A “publish to everyone.” A payout. A production migration. If that step wears the soft, low-friction, one-tap confidence of every safe action around it, the thermostat reads this is fine, go fast — and someone goes fast into a wall they can’t back out of.
So the build decision isn’t “add safety” or “add friction.” It’s narrower and more useful than that: match the felt safety to the true reversibility.
Where an action is genuinely a two-way door — you can undo it cheaply — add the net loudly, strip the friction, and let the thermostat push people to move quickly. That’s a good trade, and you should make it on purpose. Where the action is a one-way door, do the opposite. Don’t sand the friction off. Don’t wrap it in a one-tap confirm that reads as nothing to see here. Keep an honest, proportionate speed bump — type the name, wait the beat, show the blast radius — not to punish, but to keep the driver’s thermostat calibrated to the real stakes.
A tell you can hunt for: any place your safety feature quietly became load-bearing. If pulling out autosave would now cause data loss — because nobody saves anymore — then the net didn’t only catch failures, it manufactured the behavior that needs catching. On a reversible surface, fine; that’s the deal you wanted. On an irreversible one, that’s a quiet emergency.
The seatbelt didn’t fail. It just changed the driver. Every guardrail you ship does the same thing — and the only real question is whether you designed for the new driver, or shipped for the old one.
The science, to look up: risk compensation and the Peltzman effect (Sam Peltzman, 1975, on auto-safety regulation); risk homeostasis theory (Gerald J. S. Wilde); the Munich ABS-taxi field study (Aschenbrenner & Biel). Note the honest caveat: full offset is disputed, but partial compensation replicates across domains.
Sources
- Risk compensation and the Peltzman effect (Sam Peltzman, 1975)
- risk homeostasis theory (Gerald J. S. Wilde)
- the Munich ABS-taxi study (Aschenbrenner & Biel)
Liked this? Get the next one in Working Theory.
Going weekly in August (it's in beta now). One genuinely interesting read on building, the brain, and the science most people missed.
Subscribe →