Across the scenarios, the framework works at the level of requirements — no local AI judgment may erase basic standing, important gates must stay contestable, signals need bounded jurisdiction, and so on. Requirements do not enforce themselves. Each must be instantiated through actual mechanisms: law, software, institutions, audits, standards, appeals bodies, procurement rules, technical protocols, and political authority. So a requirement like a participant must be able to challenge an automated denial becomes a set of implementation questions — what exposes the decision basis, what records are kept, who hears the appeal, how quickly, what authority can overturn it, and what happens while it is pending — that the framework poses but cannot answer alone.

The distinction matters because it corrects a misreading of “necessary but not sufficient.” The mechanisms are not conceptually external to the finished system — the law, the code, and the institutions become part of the NWG civilization. They are simply not derivable from NWG alone: the framework can say what a system must preserve, and it cannot say whether one privacy technique, one statute, one cryptographic protocol, one database design, or one regulatory agency is the best way to preserve it. The recurring pattern, useful for every scenario: the framework defines the functional requirement; domain expertise builds the machinery that satisfies it.