Thinking in Systems: Why Nothing Ever Seems to Change (And What Actually Does)

Thinking In Systems by Donella Meadows (2017)

BOOK HIGHLIGHTS

19 min read

Donella Meadows spent her career as a systems scientist at MIT, working on the World3 model - the computer simulation behind The Limits to Growth. Thinking in Systems is the book she spent years writing. It's not a business book, nor a self-help book. It's a manual for understanding how the world actually works and why so many of our attempts to fix things make them actually worse.

The core argument is that most of the problems we struggle with (poverty, addiction, environmental collapse, organisational dysfunction, political stalemate) are not caused by bad people or random misfortune. They're caused by systems that are perfectly designed to produce exactly the results they're producing. Once we see that, we can stop blaming actors and start redesigning structures that actually change something.

What a System Actually Is

A system has three parts:

Elements - the people, the trees, the money, the machines. These are the parts we notice first, but they're usually the least important thing about the system. You can swap out every employee in a company and if the incentive structures stay the same, the behaviour stays the same. Elements are the most obvious and often the least powerful place to intervene.

Interconnections - how elements relate to each other and communicate. Often invisible, often information flows. E.g., the academic standards that determine who gets into a university, the price signals that tell producers and consumers what to do, the gossip that shapes what people believe. Most interconnections run through information, which is why changing what information flows where is a very powerful leverage point.

Purpose (or function) - the goal the system is actually serving, whether or not it's the stated goal. This is the hardest to see and the most important. Watch what a system does, not what it says it does. A government that claims to protect the environment but allocates no resources to it - environmental protection is not actually its purpose, even if it says it is. Similarly, a company that claims to put people first but fires people every time quarterly earnings dip - people are not actually its purpose.

The purpose of a system is often not what anyone consciously intends. Sub-purposes within the system (think: the student wants a grade, the professor wants tenure, the administrator wants a balanced budget) can add up to an overall behaviour that nobody wanted and nobody designed. This is one of the main reasons organisations do things that seem obviously self-defeating. Nobody is steering toward the bad outcome; they're all locally rational, and the system gets there anyway.

The hierarchy of importance: changing elements (swapping people, replacing equipment) has the least effect. Changing interconnections (altering how information flows, who reports to whom) has more effect. Changing purpose or goals - changing what the system is fundamentally trying to achieve - has the most effect of all. A leader can change the purpose by playing a different game with different rules toward a different goal.

Stocks and Flows

A stock is the accumulation of something at a given moment. E.g., water in a bath, money in a bank account, goodwill in a relationship, people in a population, knowledge in a brain.

A flow is what fills or drains that stock. Think: income and spending, births and deaths, deposits and withdrawals, trust built and trust broken.

Stocks change slowly. You can't instantly drain a bath or instantly rebuild a depleted fishery. Stocks have inertia. This is why systems often surprise us - we expect fast responses and get slow ones. It's also why historical momentum matters. The state of a stock right now is the accumulated result of everything that has flowed through it over time.

Stocks allow inflows and outflows to be decoupled. This is what gives systems their buffering capacity. Your savings account lets you keep spending even when income dips. A forest's stored carbon decouples short-term weather from long-term climate. Most stabilising behaviour in systems comes from this buffering property of stocks.

Counterintuitive but important: you can build up a stock by decreasing its outflow as well as by increasing its inflow. You can grow a workforce by reducing quitting, not just by hiring more. You can build national wealth by reducing decay of existing assets, not just by investing in new ones.

Feedback Loops

Balancing feedback loops are goal-seeking. They try to bring a stock to a desired level. If the room gets too cold, the thermostat turns on the heat. If your bank account drops, you work more hours. If a population grows too large, death rates rise. Balancing loops create stability and resist change. They're why systems often don't respond to interventions the way we expect - there's a loop actively pushing back.

Key property: balancing loops require a goal. The loop is always comparing the current state to some desired state. Change the goal and you change what the loop is trying to achieve. This is why purpose/goal is such a high leverage point - the balancing loops in the system will obediently try to reach whatever goal you set.

Reinforcing feedback loops are self-amplifying. The more you have, the more you get. Or: the less you have, the less you get. Compound interest, viral spread, erosion (fewer plants → more erosion → fewer plants). Poverty traps (lower income → worse education → lower income). The rich getting richer. These loops produce exponential growth or exponential collapse. They don't self-correct. Left unchecked, every reinforcing loop eventually destroys itself - it runs into physical limits, exhausts its supply, or triggers a balancing loop strong enough to bring it down.

Handy trick: if a stock is growing exponentially through a reinforcing loop, you can estimate its doubling time by dividing 70 by the growth rate (as a percentage). Money earning 7% a year doubles in about 10 years (70 ÷ 7). It's a quick way to feel just how fast something "slow-looking" compounds - useful for savings, for population growth, or for how fast a bad pattern on a team can take over once it gets a foothold.

Real systems have both running simultaneously. The oscillations, the collapses, and the surprising recoveries come from the interaction between them.

How Systems Behave

Resilience is about having several different ways to recover, operating through different mechanisms and different timescales, so that if one fails another one is already there to catch it. The problem is that these backup mechanisms often look wasteful when nothing's going wrong, so they're usually the first thing cut in the name of efficiency - and you don't feel the cost until the day you actually needed them and they were gone.

Self-organisation is a system's ability to grow more complex on its own: to learn, adapt, and invent structures nobody designed in advance. It's how a seed becomes a plant and how three people in a garage become a company with departments. It needs freedom, experimentation, and a real tolerance for disorder and failure - which is exactly why it's usually the first thing sacrificed the moment anyone gets nervous about control, leading to compliance instead of adaptation.

Hierarchy lets each layer manage itself without every part having to track everything happening everywhere else, which is what makes big, complex systems bearable to run at all. The catch is direction. "Hierarchical systems evolve from the bottom up. The purpose of the upper layers is to serve the purposes of the lower layers." A hierarchy that forgets this - that starts existing to control the bottom instead of support it - has stopped being a hierarchy that works and become one that extracts. You can see the same failure mode in governments, corporations, and even biological systems - any hierarchy that inverts this stops serving the whole and starts serving itself.

Delays

When there's a delay in a balancing feedback loop, the system tends to oscillate. For example: you're in a shower with a slow hot water response. You turn the knob hotter, but nothing happens immediately. So you turn it more. Still nothing. A few seconds later the water scalds you, so you turn it cold. But then you overshoot again. The oscillation is a product of the delay.

If a stock is constantly leaking (think: heat escaping a room, interest accruing on a debt, individuals dying out of a population you're trying to rebuild), aiming your balancing loop straight at your actual target will always leave you short. You have to aim past it, to cover the leak. For example, if you want the room at 18°C, you’ll set the thermostat a bit above 18°C, because heat is escaping the whole time you're heating it. Want to clear a credit card? Your repayments need to outpace the interest still accruing, not just match the balance. Want to rebuild a population to 1,000 individuals? Births need to outpace the deaths still happening, not just add up to 1,000. Easy to say, easy to forget.

But pattern plays out everywhere:

  • The business cycle: overproduction during booms, underproduction during busts, driven by delayed information about market conditions

  • Urban sprawl: decisions to build based on land prices that don't yet reflect the congestion those decisions will cause

  • Drug addiction: seeking relief from a state that was itself caused by the last dose

  • Hiring and training cycles in organisations

The policy implication: when we're working with a system that has long delays, we need foresight. Acting only when a problem becomes obvious is often too late - we've already committed to the trajectory, and the correction will overshoot. Slow down the rate of change so the feedback loops can keep up and don't just hope the delays go away.

Bounded Rationality

Every actor in a system makes decisions based on local information - what they can see from their position. A fisherman doesn't know the total fish population, a manager doesn't know the full cost of her decisions on other departments; a government doesn't know the long-term environmental cost of today's subsidies. So bounded rationality doesn't mean people are stupid. It just means they're making perfectly rational decisions based on incomplete information. Put a different, reasonable person into the same position with the same information, and they'll make the same decisions. This is why replacing people rarely fixes systemic problems. The behaviour is produced by the position, not the person.

So if we want different behaviour, we need to change either

  • the information available to the decision-maker,

  • the incentives and constraints they're operating under, or

  • the goals the system is asking them to serve.

Blaming individuals for systemically-produced behaviour is not just unfair - it's analytically incorrect and it misses the actual leverage point.

Shifting Dominance

Complex systems don't just have one feedback loop running, but many, and at different times different loops dominate. The S-shaped growth curve is a classic example: initially a reinforcing loop drives exponential growth, then a balancing loop (resource limits, competition, saturation) takes over and growth slows. The behaviour you observe at any moment depends on which loop is currently strongest.

This is why simple cause-and-effect models so often fail. The relationship between two variables may look strong in one phase of a system's behaviour and disappear entirely in another phase. "It worked before" doesn't mean it will work now - the dominant loop may have shifted.

When you're testing any model of how something works (whether it's yours or someone else's) ask three questions:

  1. Are the assumed causes actually going to happen the way the model assumes? Not "it's plausible" - will it actually play out that way in reality?

  2. If those causes did happen, would the system actually respond the way the model claims? Just because A and B are both believable on their own doesn't mean the link between them is real.

  3. What's actually causing the causes? Have you traced this back far enough, or did you stop at the first explanation that felt sufficient?

A model doesn't need every assumption to be perfectly realistic to still be useful, but the behaviour it predicts has to actually match what happens in real life. If you test the model and reality doesn't match the pattern it predicted, it means the core loop you think is driving everything is wrong.

Nonlinearity

Linear thinking says: if A causes B, more A causes more B in proportion. Reality is not like this.

More fertiliser improves crop yield - up to a point. Then more fertiliser poisons the soil. More cars on a motorway moves traffic, but later a small increase tips the system into gridlock. More of a drug treats the symptom - until it creates a dependency that makes the original condition worse.

Nonlinearities mean that systems have thresholds - points where a small additional push produces a dramatically different outcome. Thresholds often involve irreversibility: once a fishery collapses below its reproduction threshold, it can't recover on its own. Once soil erosion passes a certain depth, crops fail catastrophically. Once a conflict escalates to a certain level of mutual hostility, de-escalation will need enormous structural effort, not just goodwill.

So we should watch for nonlinear relationships in the systems we're working with, not just assume that more of what's working will keep working. And be especially cautious near thresholds - the cost of a small overshoot can be much higher than the cost of slight undershooting.

Layers of Limits (and Why "the System" Is a Boundary You Draw)

Growing things hit limits, and the limiting factor keeps changing. Meadows uses a classic teaching example: a fast-growing company hires great salespeople who bring in more orders than the factory can fill, so production capacity becomes the bottleneck. Fix that, and rushed hiring drops quality, so labour skill becomes the bottleneck. Fix that, and the order-fulfilment system clogs instead. There's always a next limit. The skill isn't solving "the" constraint once and being done with it - it's staying alert to which one actually matters right now, because it won't be the same one for long.

This is also where it helps to know the difference between stock-limited (nonrenewable) and flow-limited (renewable) resources. A nonrenewable resource (such as oil, a one-off grant, a burst of goodwill you've already spent) is a fixed pile: you can extract it at any rate, but the faster you take it, the sooner it's gone. A renewable resource (say, a fishery, a forest, an aquifer) can support you indefinitely, but only up to its own regeneration rate. Push past that rate for long enough and you don't just slow it down, you can knock it below the point where it recovers at all. Growing fast and growing sustainably are usually different games, and we need to know which one we’re playing.

And "the system" you're analysing is a boundary you chose, not a fact about the world. Everything is connected to everything else, so there's no single correct edge to draw around any system, only a boundary that's useful for the question you're actually asking. That's freeing (you're allowed to scope a problem down to make it workable) and it's a discipline too (you have to keep checking whether the boundary you drew is hiding the thing that's actually going on.

System Traps - Structures That Produce Persistent Problems

Policy Resistance

When multiple actors are all trying to pull the same system state toward different goals, you get policy resistance. Everyone exerts effort, no one achieves their goal, and the system stays stuck, because they're all cancelling each other out.

Classic example: drug enforcement. Police try to drive drug use down. Dealers adapt, diversify, recruit, and users find new supply routes. The harder the intervention, the more sophisticated the workaround. The drug trade adapts faster than enforcement can tighten. All parties expend enormous effort to keep the system where nobody wants it.

The way out: find a goal that all the actors can work toward together. Not "how do we enforce our position harder" but "what outcome do we all actually want, and can we design for that?" This means letting go of narrow goals and asking bigger questions. Hardest to do in the middle of a conflict, but easiest to do before one starts.

Tragedy of the Commons

When a resource is shared and everyone’s access to it is not linked to what they take from it, people tend to take as much as possible. As such, the cost of overuse is spread across all users. At the same time, the benefit of someone else’s restraint also goes to those who may not restrain themselves. What that means is that no individual user has an incentive to hold back, and so collectively they destroy the commons.

This is a structural problem: the feedback from the resource to the user is missing or too weak and too slow. The fisherman doesn't feel the depletion of the fishery in real time, nor does the carbon emitter feel the climate consequences in proportion to their contribution.

There are three structural fixes: educate and appeal to morality (weak, but better than nothing); privatise (make the user feel the direct consequences of their own use); or regulate (create an external feedback mechanism through policy). All three are attempts to restore a feedback link that the commons structure is missing.

Drift to Low Performance

When the goals of a system are allowed to drift downward in response to poor performance instead of staying fixed, we get a slow, self-reinforcing slide toward mediocrity. The standard drops, behaviour meets the new lower standard, and then the standard drops again. We get the classic: "Well, that's just how things are now." What makes this trap insidious is its gradualism. If performance dropped sharply, everyone would respond. But because it drifts slowly, our memories adjust. We forget what good looked like!

The way out: we need to hold standards absolute, or better, and anchor them to the best past performance rather than the average. Use the same structure in reverse - let the best results set the expectation, treat poor results as temporary setbacks. The structural loop is the same; we're just changing which direction it runs.

Escalation

Two actors, each measuring their own state relative to the other's, each trying to stay ahead. Think advertising, negative political campaigning, price wars, noise disputes between neighbours, etc. Each move raises the stakes; the other responds by raising them further. This is how exponential escalation happens, and it usually ends in the collapse of one or both parties. The problem is that within the logic of the system, the only "rational" move is to escalate. De-escalating unilaterally means temporarily falling behind. This is why escalation is so hard to stop from inside.

The way out: we need to either refuse to compete (unilateral de-escalation, which requires courage and short-term tolerance of being "behind"), or negotiate a structural change - disarmament agreements, regulations, new rules that set a mutual ceiling. These feel like losing at first, but they're the only rational long-term move.

Success to the Successful

When the winner of a competition receives, as part of the prize, the resources to compete more effectively next time, you get a reinforcing loop that concentrates advantage. One slight edge compounds into dominance, and eventually all but a few competitors are eliminated.

This is capitalism's central dynamic. It's also the mechanism behind educational inequality, wealth inheritance, institutional inertia, and monopoly formation. It's a structural loop. Which means the fix is also structural: antitrust laws, inheritance taxes, equalising access to education, redistribution mechanisms that level the playing field before each new round of competition. Without these, "competition" stops being a genuine test and becomes a system that rewards prior winning.

Shifting the Burden to the Intervenor (Addiction)

When an external intervention relieves the symptom of a problem without fixing the underlying cause, it gradually erodes the system's own capacity to solve that problem. We get dependency, and the intervention becomes indispensable. The original capacity then atrophies, and more and more intervention is needed to maintain the same effect.

It applies to:

  • Government subsidies to industries that should have had to adapt

  • Welfare systems that relieve poverty symptoms without addressing structural causes of poverty

  • Management practices that solve problems for people rather than building people's capacity to solve their own problems

  • Consultants who fix the thing but don't build the capability that would have fixed it

The fix is to work in a way that restores the system's own self-correcting capacity, then remove ourselves. We need to help the thing learn to help itself. This is much harder - and usually much more effective - than taking over and running it.

Rule Beating

When rules are in place, people find ways to technically comply with them while violating their spirit. E.g., end-of-year budget spending, land use laws that drive everyone to build lots just over the threshold, or endangered species rules that incentivise landowners to eliminate endangered species before they're documented. Rule-beating doesn't mean people are bad. It just means that the rules created perverse incentives. The system self-organised its way around the rule.

The fix: we shouldn’t try to enforce harder, because that usually creates more elaborate evasion. Instead, we should redesign the rules so that the natural self-organising tendency of the system runs in the direction of the goal, not away from it. Ask: what behaviour am I actually trying to produce, and does the rule point toward that behaviour?

Seeking the Wrong Goal

Systems are good at producing exactly what their feedback loops are trying to achieve. The problem is when the goal of the feedback loop is a proxy for what you actually want - and the proxy is flawed. For example, GDP as a measure of economic wellbeing, standardised test scores as a measure of education quality, hours worked as a measure of productivity, or military spending as a measure of national security. When the proxy becomes the goal, the system will produce the proxy at the expense of the thing the proxy was supposed to represent.

This is one of the most pervasive and least-discussed problems in how we run institutions. We know how to count things that are easy to count. We make those the goals. The system obediently optimises for them. Whatever we actually wanted (wellbeing, learning, safety, meaningful work) doesn't appear in the feedback loop, so it doesn't get produced.

The fix: we need to specify goals that actually reflect what we care about. Be ruthless about the difference between effort and result, between throughput and genuine outcome. This is technically hard (measuring real welfare is harder than counting money spent) and politically hard (powerful actors often benefit from the proxy staying as the goal).

Part Four: Leverage Points - Where to Intervene in a System

Meadows lists twelve places to intervene in a system, ordered from least to most powerful. The counterintuitive part: the places people most commonly try to intervene (changing numbers, tweaking parameters) are at the bottom. The places that actually change systems (changing goals, shifting paradigms) are at the top.

Here's the list, from weakest to most powerful:

12. Numbers (constants and parameters) - tax rates, subsidies, speed limits. These are what most policy fights are about. They rarely change system behaviour in meaningful ways because the feedback structures stay the same.

11. Buffers - the size of stabilising stocks relative to their flows. A bigger reservoir buffers against drought. A larger cash reserve buffers against economic shocks. Buffers are important but expensive to build and slow to change.

10. Stock-and-flow structures - the physical layout of the system. Hard to change once built. The leverage is in designing them right in the first place.

9. Delays - the timing of feedback loops. Very powerful when they can be changed. Usually hard to change in physical systems (you can't make a forest grow faster). The insight here: if you can't change the delay, slow down the rate of change so the system can keep up.

8. Balancing feedback loops - their strength and responsiveness. Making balancing loops faster, more accurate, and more powerful improves self-correction. Stripping away "emergency" balancing mechanisms (social safety nets, regulatory feedback, democratic accountability) for short-term efficiency is a catastrophic long-term mistake.

7. Reinforcing feedback loops - the strength of the gain. Slowing a reinforcing loop is usually more effective than strengthening balancing loops. Slowing population growth is more powerful than technological fixes. Slowing the "rich get richer" loop is more powerful than charity.

6. Information flows - who has access to what information. One of the most underused leverage points. Restoring missing feedback is often cheaper and faster than rebuilding physical infrastructure. The US Toxic Release Inventory law required companies to publicly report emissions. No fines, no enforcement. Within two years, emissions dropped 40% - just from making information visible. Information is power, and those who benefit from the current system will fight hard to keep information hidden or distorted.

5. Rules - incentives, constraints, punishments. Rules define the degrees of freedom in a system. Changing them changes everything downstream. This is why constitutions are so powerful and why lobbyists fight over legislation so fiercely.

4. Self-organisation - the ability of the system to change its own structure. This is biological evolution, technical innovation, social revolution. The conditions for self-organisation: variety (diverse raw material), experimentation (tolerance for disorder and failure), selection mechanisms (ways to test what works). Suppressing self-organisation for the sake of control or efficiency trades long-term resilience for short-term order. Almost every authoritarian system eventually collapses for this reason.

3. Goals - the purpose or function of the system. Change the goal and everything downstream - the rules, the information flows, the feedback loops - bends toward the new goal. This is why a single leader can transform a system: not because they changed the people, but because they changed the goal the whole system is orienting toward.

2. Paradigms - the shared beliefs, assumptions, and mental models from which the system's goals, rules, and structures emerge. "Growth is good." "Nature exists to serve human production." "What can't be measured doesn't matter." "People are fundamentally self-interested." These aren't facts - they're paradigms. And they shape everything. Paradigm shifts are the origin of the most significant social transformations. They're also the hardest things to change, because people protect their paradigms like their identity. Because, in a real sense, they are.

1. Transcending paradigms - recognising that no paradigm is final or complete. That every model is a limited representation of something far larger. That we can choose our mental model based on what it enables, not because it's "true." This is the rarest and most powerful form of leverage, and it requires intellectual humility - the willingness to treat our own model as a model. Most of us will resist this our entire lives.

Part Five: Living in a World of Systems - The Guidelines

Ways of approaching complex systems that reduce error and increase your capacity to do good:

Get the beat of the system before you touch it. Study its actual behaviour over time. Don't start with your hypothesis about what's wrong. Look at the data first. Time graphs that show how multiple variables have moved together will tell you more about the system than any theory.

Expose your mental models to the light of day. Write down what you think is causing what. Draw the diagram. Make your assumptions visible - mental models are slippery because they shift and contradict themselves without us noticing. Externalising them forces clarity and opens them to challenge.

Honour, respect, and distribute information. Biased, delayed, incomplete information is the root cause of most system failure. Timely, accurate, complete information to the right decision-makers is one of the most powerful and cheapest interventions available.

Pay attention to what is important, not just what is quantifiable. Things like resilience, dignity, belonging, beauty, and meaning affect how systems behave. But they're also very hard to count. Our obsession with metrics degrades everything that can't be measured, because the feedback loop ignores them.

Make feedback policies for feedback systems. Policies should respond to the state of the system. The best policies include meta-feedback - something that learns and adapts as conditions change.

Go for the good of the whole. Optimise for the whole system, not for a part of it. Hierarchies exist to serve the lower levels, not the other way around. A system that maximises one part at the expense of the whole is undermining itself.

Locate responsibility within the system. Design systems so that the people who make decisions feel the consequences of those decisions, to close the feedback loop. A factory owner whose water intake is downstream of their own wastewater pipe has strong incentive to manage their waste - that's intrinsic responsibility.

Stay humble - stay a learner. In complex systems, "staying the course" is only good advice if you actually know you're on course. Pretending certainty when you don't have it produces errors that don't get caught. Seeking, using, and sharing information about what went wrong is the only way to improve in a complex environment.

Celebrate complexity. The world is not linear, not tidy, not fully knowable. We can fix this. It's the nature of everything alive and interesting. Our instinct to simplify, to straighten, and to control is natural, but it costs us. Systems reward the people who can hold complexity without needing to reduce it.

Expand time horizons. Discount rates and payback periods are rational within their own logic and catastrophic in long-term thinking. A society that can't think past the next election cannot manage complex systems effectively.

Expand the boundary of caring. Everything is connected. Your organisation is embedded in an economy, embedded in a society, embedded in an ecosystem. Acting as if your system ends at your departmental boundary, or your national border, or the next quarterly report is not just narrow, but analytically wrong.

Most of us are trained to see events. Something happens because something caused it. We fix the cause, but events are the output of structures, and so the structures keep producing new events. You can spend your whole life firefighting events and never touch the structure generating them.

Systems thinking asks us to see the world one level deeper - to see the feedback loops, the delays, the goals, the accumulations, the information flows that produce the events. Once we see those, we can ask: what is this system actually designed to do? Who designed it, and for what purpose? Where is it failing its own stated goals, and why? Where is it perfectly achieving goals nobody actually chose?

The world doesn't behave the way it does because of villains, or because of randomness, or because of fate. It behaves the way it does because of structures. And these can be changed (although not easily).

© Copyright LINA MILESKAITE 2026

Get in touch

If you think we should talk, you can reach out to me via the form below.