Oregon lawmakers have been moving to shut down wagering markets that let people bet on when and where the state’s next wildfire will break out — treating a betting slip on disaster as the thing worth the legislature’s attention this cycle.
The instinct behind the ban is not hard to understand. There is something genuinely repellent about a market that pays out on other people’s catastrophe. But look closely at what the ban actually does. It removes a market. It does not remove a fire. No ignition gets detected faster because a wagering platform lost its license to operate. No acre burns less because the odds board came down. The legislature spent its attention on the bet people were placing about the fire, and spent none of it on the bet that would actually stop one.
That second bet exists. It has been designed. It is sitting on a desk, unfunded, waiting for someone with the authority to fund it to notice it’s there.
Detection Is the First Act of Prevention
There is a habit of talking about wildfire response as two separate problems: prevention, which happens before a fire starts, and suppression, which happens after. Detection gets treated as a footnote between the two — the moment someone happens to notice smoke.
That framing is backwards. Detection is not a footnote to prevention. It is the first act of it. Every intervention that follows — a crew dispatched, a road closed, an evacuation ordered, water dropped on the right acre instead of the wrong one — depends entirely on how early and how precisely the fire was found. Prevention and detection are not two stages of one process; they are one act described from two ends. A prevention strategy that doesn’t start with detection isn’t a strategy. It’s a hope that someone looks up in time.
The system built to do this has three parts, and none of them is exotic:
| Component | Function |
|---|---|
| Sensors and fixed cameras | Watch continuously, without fatigue, from positions chosen for coverage rather than convenience |
| Software | Turns raw sensor and camera feed into a flagged, actionable alert instead of a wall of footage nobody is watching |
| Drones | Move to what the software flagged, to verify it and to give responders eyes on the ground before crews commit |
Read the table left to right and the logic is plain: fixed sensing finds the candidate, software decides it’s worth acting on, mobile response confirms and closes the loop. Cameras and drones are not competing for the same job — they are two halves of one loop, fixed sensing paired with mobile response. A camera cannot fly to a ridge it wasn’t already pointed at. A drone cannot watch every ridge at once, all day, every day, for the cost of electricity. One is built to watch continuously and can’t chase; the other is built to chase and can’t watch continuously. Neither replaces the other. The objection that these are rival technologies — pick the cameras or pick the drones — misunderstands what each one is for.
What’s Actually Sitting on the Table
Here is where I have to be plain about my own position in this, because the argument doesn’t work if I hide it.
I designed the software and the implementation plan for this system, built around technology that already exists. I did not invent any of the hardware it runs on. That is not a modest disclaimer — it is the load-bearing fact of the whole piece. Every sensor, every camera, every drone platform this plan calls for already exists, already ships, already works in other contexts. Nothing in the plan is waiting on a breakthrough. It is waiting on funding and on the political will to spend it, which is a different kind of waiting entirely, and a far more solvable one — because the thing being asked for isn’t a miracle, it’s a purchase order.
That distinction matters because it changes what “not yet built” means. A system that’s missing an invention has an uncertain timeline; nobody can promise when the breakthrough arrives. A system that’s missing funding has a knowable timeline the moment someone decides to write the check. This plan is the second kind. I’d rather say that plainly than let the piece imply momentum it doesn’t have: the system is designed, not deployed. I don’t have a live fire season’s worth of results to show you, because it hasn’t been let to run one.
When this piece first ran, the design drafts for the software and the implementation plan were still in progress and not yet public, and I wrote that when the work was ready I intended to show it rather than describe it secondhand. That work is now published. Treat the claim as exactly what it is, and no more than it is: a design exists and is documented, not a system running anywhere.
The Steelman for the Ban
I want to give the wagering-market ban its strongest version, because it deserves one, and because the honest version of this essay doesn’t get to skip it.
The strongest case for banning bets on wildfires isn’t squeamishness. It’s moral hazard. A market that pays out when a fire starts creates, however marginally, an audience with a financial interest in fires starting — and in a state that has watched arson and human-caused ignition drive real damage, a legislature has legitimate reason not to want that incentive structure anywhere near its landscape. You don’t need to believe bettors are lighting matches to believe the incentive itself is corrosive and worth removing on principle. That’s a real argument, made in good faith, and I don’t think the people making it are wrong to find the whole premise of betting on disaster ugly.
I hope they’re right that shutting the market down matters. I don’t think it’s in tension with anything I’m arguing here — a legislature can close a wagering market and fund a detection system in the same session, and neither one requires killing the other. My complaint isn’t that the ban is wrong. It’s that it was treated as if it were the whole job. Removing a bad incentive is not the same act as installing a good capability, and a season spent doing only the first while the second sits designed and unfunded is a season that did something, and stopped nothing.
Running the Test on My Own Plan
If the standard I’m using against the legislature is “does this action stop a fire,” fairness requires I run the same test on what I’m proposing.
Banning the wagering market: no fires stopped. That’s the easy verdict, and it’s the one this whole piece has been building toward.
The detection and response system: also no fires stopped, as of today — for a different reason. Not because the mechanism doesn’t work, but because it isn’t running anywhere yet. A plan that hasn’t been funded hasn’t been tested against a real fire season, and I’m not going to write around that just because it’s less flattering than the rest of the argument. The honest claim I can make is narrower than “this stops fires.” It’s “this is a system positioned to, and the only thing standing between the design and a live fire season is a decision someone with budget authority hasn’t made yet.”
That’s a weaker sentence than a pitch deck would want. It’s also the true one, and I’d rather the gap sit here, visible, than get papered over with a result I don’t have.
What “Designed” Actually Means
“Designed” is doing a great deal of work in this essay. A word carrying that much weight should be made to show what’s behind it, because otherwise it’s a more flattering way of saying I’ve thought about the problem a lot.
So here is what’s behind it. The requirements library for the system is now public: what it must do, what it must refuse to do, what would prove it working, and — the part I’d read first if I were you — what it doesn’t cover yet.
Start with the screens. Everything else in the library is prose, and prose is where a safety argument goes to become unfalsifiable. An interface is where a requirement either becomes true or quietly stops being true, so the eight operator surfaces are now published in full — each one with what it enforces beside what is deliberately absent from it.
That second column is the unusual one. Interface documentation almost always describes capability, because capability is what gets sold. A system’s safety posture lives in the opposite place. On these screens: no auto-confirm at high confidence, because a threshold that bypasses the human is the first step back to unfiltered output. No override for a failed safety gate — a failed gate produces a named reason and a next action, never a bypass. No authorise button at all when the ground is not yours to attack, absent rather than greyed out, so no attention is spent on a decision that was never available. And a no-drop hold that any crew member can set instantly over their own position, which the duty officer’s authorisation loses to, with no screen anywhere in the system that resolves it the other way.
| Part of the library | What’s in it |
|---|---|
| The charter — what it is, and what it stands on | The problem stated narrowly enough to be wrong, the five bounded contexts, and the ten invariants with what enforces each. Carries a correction left visible: an earlier claim of mine about invariant coverage was false and had spread to nine places |
| Six milestones, ordered by authority rather than ambition | Why the hardest permission is asked last, why the two programme-ending assumptions are tested at opposite ends, and the fundable alternative I rejected — presented at full strength, because a decision that makes its discarded option look stupid has not recorded a decision |
| What it will not do, and what would stop it | Six permanent non-goals, seven halt conditions, and eleven risks — seven the programme’s, four created by gaps and marked as mine. Two have no engineering answer at all |
| The mechanism, including the three ways it fails | Six sequences, three of them failure paths at the same depth as the successes, because failure is where an invariant is either true or decorative |
| Who this lands on, and who can stop it | Six role journeys, and the property worth more than the rest: the roles that can stop an action are not the roles that can command one |
| What success would look like, and what would prove it wrong | Six goals, each with the observation that would falsify it. None has a baseline, and every row says so |
| The eight screens, and what each refuses to do | Every operator surface the system specifies — triage, the district picture, the three-gate suppression authorisation, the crew’s veto — published with its enforcements and its deliberate absences side by side. Three are rendered from the specification; all imagery is labelled synthetic |
| What the corpus doesn’t cover | Seven gaps the practice found in its own work, worst first. Where I’d send a skeptic second |
| One specification, worked end to end | A single rule through all fourteen sections, published complete — including a criterion recorded as currently failing |
| Goals and how they’re measured | Six goals, each with a measure, an instrument, and the observation that would prove it wrong. Five have no baseline yet, and the page says which |
| The method: seven artifact categories | What counts as an artifact, where each category comes from in the published standards, and a completeness test you can run against my work rather than take my word for |
| Potential Bill Draft — the law this would need in order to exist | A concept draft in Legislative Counsel form of the Oregon legislation the programme would require: who holds the federal airspace authorization, who pays during the years it has prevented nothing measurable, and how insurers and utilities contribute. Nobody has introduced it and no sponsor is attached. Its section 6 is the argument in miniature — the assessment disappears for any owner with current defensible space certification, so public money for detection cannot displace private responsibility for fuel |
The gap list is where I’d send a skeptic next. It opens by saying the corpus has effectively no adversarial security analysis — no threat model, nothing on spoofing or jamming or a deliberately falsified position — and that the requirements are rigorous about accidental failure and close to silent about someone attacking on purpose. It says the suppression half is specified and not designed. It says there is no test artifact at all.
That last one applies directly to the screens, and the screens page says so about itself: none of them has been built, so none of those refusals has ever actually refused anything. Under this library’s own standard, a check that has not been observed refusing a disqualified input does not count as present. Every absence on that page is a design commitment and a testable one. It is not a result.
That is an uncomfortable thing to publish next to an argument that this should be funded, and publishing it is the point. A specification you can’t find fault with is usually one that hasn’t told you where to look. If you find a gap that page doesn’t already name, I’d genuinely like to hear it — that’s the most useful thing anyone could send back, and there’s no form in front of it.
None of this changes the verdict in the section above. A design is still not a deployment, and a library of specifications has never put out a fire. What it changes is what you have to take on trust. You no longer have to believe me that the work exists; you can read it, and you can tell me where it’s wrong.
The Bet Oregon Hasn’t Placed
Every legislative session runs on finite attention, and attention is the actual scarce resource here — not virtue, not intent, attention. The session that goes into drafting and passing a wagering-market ban is a session that isn’t going into evaluating, funding, or piloting a detection system that already exists in finished, deployable form. That’s not a hypothetical trade-off. It’s the trade-off that already happened.
There is a version of this argument that reads as a pitch, and I’ve tried to keep this from being that. I’m not asking you to take my word that the plan works — it hasn’t run a season yet, and I said so above. What I am asking is narrower and harder to dismiss: whatever you think of wagering markets on disaster, banning one is not a wildfire strategy. It is a market regulation that happens to be adjacent to a wildfire. The strategy — sensors that watch without fatigue, software that turns a feed into an alert, drones that close the distance between an alert and a confirmed fire — is sitting fully designed, waiting on the one thing legislation is actually built to supply: a funding decision.
Oregon can keep making the bet that stops people from betting on the fire. Or it can make the one bet that has any chance of stopping the fire itself. Those are not the same wager, and only one of them was ever going to burn less land.
