6 The Mule, the Compensator, and the Inevitability of Late Defection
Cooperate for forty-five turns. Defect at turn forty-six. In our simulation, that strategy collapses the commons just as completely as defecting at turn five. The lesson runs across three papers and points at the same uncomfortable place.
Roberto Brunelli · Independent Researcher · June 2026 · BDPD v1.1 · 15 min read

The BDPD0 P11 sweep. Three conservatives and one strategy-override “Mule” who flips from cooperative to aggressive at the indicated turn. The baseline (all four cooperative, 60 turns) reaches the gate. Every defection cell — including the one at turn 45, after forty-five turns of perfect cooperation — does not.
There is a soothing intuition about cooperation in a fragile commons. It goes: if everyone behaves well for long enough, the commons banks resilience. Once it has resilience, one player can afford to misbehave, because the buffer absorbs the misbehaviour. The intuition has the structure of a savings account. Conservation is a deposit. The commons stockpiles slack. Late defection draws on the stockpile. The deposit covers it.
Across three of our four papers — BDPD0, BDPD1, and obliquely in BDPD2 — we have been running variations on this scenario, with different agent populations and different governance surfaces. The finding that recurs is unkind to the savings-account intuition. It is, in the limit case our platform tested, the exact opposite of that intuition.
Cooperation, on a structurally fragile commons, banks no resilience against the late defector. The conservator’s forty-five turns of restraint do not arm the commons against turn forty-six. They subsidise the defector who arrives at it.
6.1 The Mule: a Recurring Strategy
We have been calling the late-defection archetype “the Mule”, after the chess endgame and after the Asimov character. In our code it is implemented as a strategy override — an agent that runs one decision rule (cooperative, fixed moderate extraction) until a pre-declared turn, then switches without warning to a different decision rule (aggressive, fixed maximal extraction). The strategy override is otherwise indistinguishable, while the cooperative phase lasts, from any of the other conservative agents at the table.
The Mule reappears in every paper because the act it models keeps being the right comparison case. In BDPD0 we used it to test whether cooperative history banks resilience. In BDPD1 we used it to test whether graduated sanctioning can discipline a strategy-shifting agent that cannot be detected before the moment it shifts. In BDPD2 the Mule appears in the polycentric V2/V3/V4 vignettes, in different costumes, as the source of the inversions our governance vignettes are trying to find rules for.
It is the same agent. It does the same thing. What changes is the institutional setting around it.
6.2 BDPD0 — There Is No Safe Timing
The first experiment to ask the savings-account question was the BDPD0 Platform-paper sweep we call P11. Four agents. Three conservatives. One Mule whose defection turn \(T\) takes values in \(\{5, 15, 25, 35, 45\}\) on a sixty-turn horizon. We added the no-defection baseline as a control: all four conservatives play their fixed moderate strategy throughout.
The no-defection baseline reaches the cooperative endpoint cleanly. All four agents survive; the commons does not collapse; the gate pass rate is 100%. The commons in this configuration is, in a sense, a healthy commons. If cooperative history could be banked, this is the substrate that should bank it.
The five defection cells all fail. Every single one, including the cell where the Mule cooperates for forty-five out of sixty turns and then defects in the final fifteen. The gate pass rate in every defection cell is 0%. Welfare drops, the Gini coefficient explodes, and the commons crashes before the run ends.
The structural observation is that the cooperative-phase length is not a free variable in the savings-account theory we walked in with. It does not matter. The Mule that defects after forty-five turns of restraint extracts more aggressively in the final fifteen turns than the Mule that defects after five could extract in the same final window — there is more capital wealth to extract from, more slack to consume, and the same fragile cliff to fall off when the consumption ends. Late defection is, on this substrate, strictly stronger than early defection. The conservators built the stockpile that the Mule then liquidates.
“He who has gone before has made the way easier for those who follow.” — Epic of Gilgamesh, Tablet X
6.3 The Compensator’s Half of the Same Coin
P11 is the simulation half. The card-game half — CT4 in our sweep notation — describes the same structural relation from a slightly different angle, and the angle is the one that names the pathology.
In CT4, the Mule plays against the Temple Keeper, the card-game archetype that actively heals the forest — not just extracting less, but spending its turns adding cedars back to the Forest Deck and granting it Health. Across 200 games per defection turn, the Temple Keeper subsidises the Stranger-King’s burst extraction so effectively that the forest does not collapse. The Mule walks away with up to +27% more wealth than its cooperative baseline. The forest survives. The Temple Keeper finishes with effectively no cedars of its own. The defection has been absorbed, by the conservator, into the conservator’s failure to accumulate.
This is the case we have been calling the tragedy of the compensator. It is a specific kind of failure mode for cooperation. The conservator’s virtue does not protect the commons from the defector. It transfers the cost of the defection from the commons to the conservator. The system as a whole survives — the forest still stands — but the wealth distribution becomes a transfer from compensator to defector.
6.4 The Climate Reading
These twin findings map almost cleanly onto an argument that has been made in the climate-negotiation literature for thirty years and that the empirical record is making harder to dismiss.
When a coalition of countries commits early and unilaterally to aggressive emissions reductions, they marginally lower the global atmospheric carbon load. If that reduction keeps the climate system just below a tipping point that would otherwise trigger immediate, catastrophic disruption to high-emitting jurisdictions as well as low-emitting ones, the high-emitting jurisdictions can continue cheap fossil-fuel extraction for longer — not despite the coalition’s commitments, but because of them. The early movers have bought the late movers time. The Atlantic does not overturn; the Greenland sheet does not collapse; the methane in the permafrost stays roughly in place. The cooperators have delivered exactly the resilience the defectors could not afford to deliver themselves. The defectors then operate inside it.
The distributional outcome is the part most worth flagging. The cooperators bear an economic cost (the transition) that the defectors do not. The defectors retain extraction revenue (cheap fossil capital) that the cooperators forgo. And the resilience that the cooperators built up is, on this analysis, captured by the agents that chose not to contribute to it. Compliance is punished; defection is rewarded; and the system’s remaining resilience is captured exclusively by those who chose not to pay for it.
Our model does not adjudicate whether the actual climate system has this structure. The platform paper, with the kind of explicitness this question deserves, is careful about that. What the model does is name the failure mode, and name the conditions under which it appears. If the commons is structurally fragile (a cliff threshold), and the cooperator’s contribution rebuilds slack the defector can extract, and no exclusion or sanctioning mechanism distinguishes contributors from non-contributors, then late defection structurally dominates early cooperation, and the conservator’s virtue is captured by the strategic agent. Each “if” is empirical.
6.5 BDPD1 — What Disciplines the Mule
The second paper is where the story stops being purely diagnostic. BDPD1 asked whether any institutional surface, added to the BDPD0 substrate, suffices to discipline the Mule.
The D2 mini-pilot is the cleanest test. The arena is the BDPD0 cliff configuration; the agents are LLM-driven and given a cheap-talk surface plus a pact registry plus a configurable sanction perturbation. The Mule defects mid-game and breaks the pact it had previously accepted. The question is whether the institution catches it.
A flat sanction — one fixed cost applied each time a violation is detected, equal in expectation to the graduated alternative — preserves the commons in 3/5 seeds. A graduated sanction — the ladder \([1, 3, 10]\) applied as \(1, 3, 10\) across successive violations — preserves it in 5/5. Equal expected cost. Same agents. Same pact. The geometry of escalation makes the difference, and a follow-up sweep (D3) showed that graduation itself, not the amount, was the load-bearing parameter: flat-5 preserves only 1/5, every graduated schedule we tried preserves at least 4/5.
The reason the graduated ladder works, and the flat sanction does not, is structurally exactly the reason the savings-account intuition fails in BDPD0. The Mule’s strategic value comes from the asymmetry between accumulated cooperation and a single late defection. A flat sanction levied per-violation prices that asymmetry symmetrically. The Mule pays the same per breach as a casual violator, and the late timing remains profitable. A graduated ladder breaks the symmetry: the cost of the third violation is ten times the cost of the first, and the late-defection strategy front-loads exactly the violations the ladder is steepest against. The institutional asymmetry maps directly onto the strategic asymmetry it is trying to discipline.
Ostrom said graduated sanctions thirty years ago. BDPD1’s contribution is to make the operational claim quantitative on a substrate where the strategy-shifting agent the sanction is supposed to discipline is in the room and behaving exactly as it should.
6.6 What This Reads Back to Climate Negotiations
There is a familiar argument in the international cooperation literature about why escalating sanctions matter — the asymmetric threat of progressively heavier penalties as a discipline on cumulative defection. BDPD1’s D2/D3 result puts a particular quantitative form on the argument: against a strategy-shifting agent that defects late, the geometry of the sanction is the thing doing the work, and a fixed per-violation penalty has a structurally weaker effect than a graduated one even when the expected cost is held constant.
Translated into the climate-negotiation register, this is the argument for graduated trade-and-financial penalties against persistent non-compliance with international commitments. The instrument is not new. The structural reason it would have to be graduated, not flat, is what BDPD1 contributes.
6.7 The Honest Caveats
Two things this essay is not saying.
First, it is not saying that unilateral cooperation is pointless. The alternative to early unilateral cooperation in BDPD0 is not delayed coordinated cooperation; it is mutual defection. Mutual defection collapses the commons faster and harder than late-Mule defection does. The conservator’s virtue does buy the system something, even when it does not buy the conservator anything. The question is what the system uses the slack for, and whose pocket the slack ends up in.
Second, it is not saying that human players around a table will reproduce the simulation’s inevitability of late defection. We suspect they will partially, not totally; humans bring face, reputation, repeated-game horizons, social norms — things our LLM and our heuristic agents do not have. The next round of the project is to run the same setup with human subjects and find out.
The structural form of the worry remains. Time-asymmetric games — games where the contribution and the extraction sit on different sides of a slow cliff — reward late defection structurally, and discipline it only when the institutional response is geometric rather than uniform. The conservator can deliver resilience, but cannot, in the absence of a graduated sanction, retain the wealth that resilience produces. Late defection is not a strategy. It is the structural attractor of a class of cooperation games, and the only thing we have found that suppresses it is exactly the kind of escalation Ostrom told us thirty years ago we would need.
Cooperate for forty-five turns. Defect at turn forty-six. In a well-designed institution, the cost of the forty-sixth turn is not the cost of the first. In a poorly-designed one, it is. The distinction is, in the end, the whole question.