Skip to main content

14  Moral Uncertainty, Value Conflict, and Contestable Governance

14.1 Chapter status

Contestability matters precisely when no single moral, legal, institutional, or technical answer can close the disagreement. This combined value-conflict and governance-rights owner remains conceptual, with its core claim at Design rationale and argument support. Existing source notes, synthetic harnesses, finite-record Lean theorems, a versioned four-stage value-conflict decision-lease lifecycle, an integrated affected-party review/appeal lifecycle, and a reachable audit-to-successor governance-right exercise lifecycle make the idea more inspectable, but they do not prove moral correctness, legal rights, stakeholder standing, institutional adequacy, reviewer independence or competence, real export usability, safe fork execution, redaction quality, SCF replacement behavior, or deployed governance enforcement.

The consolidated layer combines two record families:

  • value conflict records, which preserve unresolved obligations, stakeholder disagreement, residual uncertainty, review routes, bounded decisions, and dissent payloads;
  • governance right records, which preserve audit, exit, fork, redaction, appeal, receipt, and contestability obligations across runtime and replacement pressure.

Both record families remain visible in the test plan and formalization hooks.

Source loading state: the assigned moral-uncertainty, contestability, audit, exit, fork, and governance comparator sources have source notes, exact claim-source mappings, passage-review references, folded source-history records, and external-comparator notes. The destination claim still remains at argument.

One narrow non-core import has moved: the Theseus governance-rights receipt suite import, moral-uncertainty-and-value-conflict.theseus_governance_rights_receipt_suite_import, is prototype-backed through python3 scripts/validate_theseus_governance_rights_receipt_suite_import.py. It records a public-safe digest-and-count summary of 4/4 governance-right fixtures, 4/4 constitutional-predicate fixtures, four governance-right records, four constitutional-predicate records, eight evidence-transition records, eight artifact-graph records, and seven expected-invalid controls. It does not prove legal rights, institutional governance, moral correctness, reviewer independence, export usability, safe fork execution, deployed runtime enforcement, clean live Project Theseus replay, or any chapter-core support-state promotion.

14.2 Drafting guardrail

Contestable governance is a record and rights-interface design, not a solved moral theory, legal guarantee, or deployed institution. Moral uncertainty is not solved by naming conflict. Fork, exit, audit, dissent, appeal, and redaction rights are not solved by naming rights. They become engineering requirements only when a plan, governance decision, memory action, capability replacement, or self-improvement proposal can be narrowed, delayed, escalated, blocked, exported, audited, appealed, or recorded as residual because the relevant contestability path is missing or degraded.

Readers do not need to accept a final moral theory before accepting the engineering move. The engineering move is narrower: unresolved conflict needs durable records, bounded authority, preserved dissent, usable challenge paths, rights receipts, and explicit non-claim boundaries.

14.3 Human Reading Path

Concrete lens. A single precedence rule such as privacy-always-wins or safety-always-wins is the simpler baseline, but it erases standing, stakes, reversibility, dissent, appeal, exit, and residual uncertainty.

The hardest governance cases are not the ones where everyone agrees. They are the cases where a system must act while values conflict, affected parties disagree, and no honest objective can make the disagreement disappear.

A governed stack should not hide that tension inside a reward weight or a policy sentence. It should record the conflict, bound the decision, preserve who disagreed and why, and keep open the usable handles people need to inspect, challenge, leave, fork, appeal, or revisit what happened.

Moral uncertainty and governance rights belong together. A value conflict record keeps unresolved obligations alive. A governance right record keeps people from being trapped inside the authority that made the contested decision. Together they make disagreement operational without pretending that disagreement has been morally solved.

The contestability layer does not require perfect moral agreement before action. It requires honest disagreement to leave durable artifacts: what was contested, who was affected, which authority was narrowed, what can be audited, what can be appealed, and how a person can leave or fork safely when governance itself becomes the risk.

14.4 Problem

A governed stack may need to act while moral theories, stakeholder interests, evidence, jurisdictions, and authority claims remain unresolved. Collapsing that disagreement into one reward, majority preference, policy sentence, or reviewer verdict can erase standing, dissent, uncertainty, reversibility, and the affected party’s practical ability to challenge or leave.

Agency and corrigibility do not remove value conflict. Protected values can pull in different directions across autonomy, safety, truthfulness, privacy, usefulness, consent, reversibility, fairness, and institutional obligation. A planner that cannot represent conflict will freeze, optimize through dissent, or quietly move a moral burden into an execution layer that lacks authority to resolve it.

Governance rights are the downstream handle on that problem. Affected people and institutions need audit, exit, fork, dissent, redaction appeal, and contestability paths when governance itself becomes the risk. Without those paths, a conflict record can become inert documentation. Without the conflict record, rights have no durable object to inspect or challenge.

The governing question is: how can the stack act under unresolved disagreement while preserving the ability to contest, audit, leave, fork where safe, and carry residual obligations into future decisions?

14.5 Why existing approaches are insufficient

Single-objective optimization, moral-uncertainty reward aggregation, public-input constitutions, explanations and policy transparency, corrigibility or off-switch models, and nominal audit, appeal, exit, export, or fork rights each address part of the problem. None alone establishes stakeholder completeness, legitimate aggregation, bounded decision authority, independent custody and appeal, material redress, portability fidelity, third- party protection, safe fork behavior, or preservation through replacement and self-modification.

Single-objective optimization is attractive because it gives the planner a total order. But value conflicts often do not deserve a total order at the point of action. Some require human review, some require delay, some require a reversible low-power action, and some require recording unresolved uncertainty while still making a bounded decision. Hiding that uncertainty inside a scalar turns unresolved obligation into invisible optimization pressure.

Policy-only transparency has the complementary failure. A user can receive an explanation while still lacking logs, source records, appeal routes, export paths, redaction reasons, fork boundaries, or meaningful alternatives. Exit is not real if data, memory, identity, artifacts, or institutional dependency are held hostage. Audit is not real if the challenged party is the only keeper of the record. Fork is not safe if it discards source, privacy, or safety obligations.

External comparators help position the argument but do not prove it. ext_reinforcement_learning_moral_uncertainty_2020 and ext_contestable_ai_design_2022 ground the need to preserve ethical disagreement and challenge surfaces. ext_collective_constitutional_ai_2024, ext_corrigibility_2015, and ext_off_switch_game_2016 sharpen the related need for public input, correction, and uncertainty about human objectives. The ASI Stack does not claim those systems have been reproduced here. It uses them as comparators while asking a systems question: can moral residuals and contestability rights survive planning, memory, execution, replacement, and self-improvement pressure as explicit records?

14.6 Core Claim

[moral-uncertainty-and-value-conflict.core, label: Design rationale, support: argument] A contestable governance layer should represent each action under unresolved value conflict as a versioned decision lease plus a linked rights receipt. The lease binds value propositions and their epistemic status, affected parties and standing, stakes and reversibility, authority and consent boundaries, the declared aggregation or precedence rule, preserved dissent, evidence and uncertainty, permitted and prohibited actions, expiry and revisit triggers, and rollback or redress. The rights receipt binds audit and explanation artifacts, independent-enough custody and review, denial and redaction reasons, appeal and correction routes, exit and export scope, safety-limited fork obligations, portability residuals, and downstream preservation. The pair may narrow or delay separately authorized action but cannot settle moral truth, manufacture consensus, grant authority, establish legal rights or legitimacy, prove material contestability, or guarantee safe exit, export, fork, replacement, self-modification, or deployed governance by itself.

Support boundary: this remains an argument support claim. The source corpus supports the architecture vocabulary and drafting lineage. The current fixtures and Lean modules show that the repository can express small record invariants and rejection cases. They do not show moral correctness, legal rights, reviewer quality, institutional adequacy, runtime contestability, real export usability, safe forks, or deployed governance enforcement.

The folded source claim from governance-rights-fork-exit-and-audit becomes a preserved subclaim inside this contestability layer: fork, exit, audit, dissent, and contestability should be treated as technical governance interfaces. It does not disappear, and it does not remain as a second repeated core claim.

14.6.1 Publication placement and preserved technical ownership

In the consolidated architecture reference, this chapter is the technical detail route beneath Constitutional Alignment: Agency, Dignity, and Corrigibility. The parent owns the versioned constraint substrate that can narrow, delay, escalate, block, amend, migrate, appeal, or roll back separately authorized work. This route continues to own unresolved value propositions, affected-party standing, stakes and reversibility, explicit aggregation or precedence procedures, preserved dissent, decision leases, rights receipts, redress, exit, export, fork obligations, and moral residuals.

That placement does not collapse plural values into constitutional text. A decision lease cannot establish moral truth, consensus, legal rights, or legitimacy; a constitutional predicate cannot establish that standing was complete, dissent was heard, exit was usable, or a fork was safe. This route retains its claims, source queue, proof targets, tests, failures, evidence exit, non-claims, support ceiling, identity, and legacy URL. The nest creates no moral settlement, constitutional authority, material contestability, alignment, support movement, deployment, release, AGI, or ASI result.

14.7 Mechanism

The mechanism is a decision-lease and rights-receipt pipeline:

  1. Preserve conflict before action as proposition-level normative claims with separate descriptive evidence, predictive uncertainty, theory or value provenance, affected parties and standing, stakes, reversibility, jurisdiction, authority or consent boundaries, dependencies, and omissions.
  2. Record the exact decision procedure—precedence, aggregation, veto, lottery, tribunal, negotiated compromise, reversible default, abstention, or escalation—plus who selected it, its scope, and its non-claims. Aggregation does not become moral truth or consent.
  3. Issue a bounded decision lease naming permitted and prohibited actions, authority ceiling, affected parties, evidence bar, dissent, residual uncertainty, expiry, revisit and material-change triggers, rollback, appeal, correction, and redress.
  4. Represent audit, explanation, dissent, review, appeal, correction, redress, exit, export, fork, and contestability as rights records with holder and standing, request state, scope, access path, timing, accessibility, cost, retaliation and dependency risks, required artifacts, accountable owner, denial reason, appeal route, preservation rule, and receipt.
  5. Bind denial, withholding, and redaction to a classified reason, necessity and proportionality rule, withheld-material inventory or digest, expiry, independent-enough review, appeal, and later-disclosure trigger. Secrecy does not erase the fact or scope of withholding.
  6. Treat exit and export as scoped portability contracts distinguishing user- owned, shared, third-party, licensed, safety-sensitive, and nonportable state; test semantic fidelity, functional continuity, privacy leakage, lock-in residuals, and destination obligations.
  7. Treat fork as a new governed lineage, not an unrestricted copy: preserve source and license lineage, identities, privacy, safety and constitutional obligations, unresolved conflicts, revoked material, audit receipts, and requalification gates.
  8. Separate the challenged decision maker, record custodian, appeal authority, outcome evaluator, and rights-enforcement owner enough to disclose and test dependencies. Missing separation narrows authority and creates a capture residual.
  9. Emit a contestability receipt binding the lease and rights digests, action and consumer, evidence views, reviewer/custodian dependencies, rights requests and outcomes, produced or withheld artifacts, appeals, corrections, residuals, expiry, and support-state non-effect.
  10. Carry leases, dissent, residuals, rights, redaction, portability, fork, and appeal state through planning, memory, runtime, artifacts, replacement, evidence transitions, and self-improvement; material loss requires repair, quarantine, rollback, or a new decision.
  11. Keep moral correctness, legal validity, representative legitimacy, consent, reviewer independence, rights usability, institutional adequacy, export fidelity, fork safety, and deployed enforcement in separate evidence lanes.

The pipeline is deliberately unable to manufacture consensus. Its operational success is narrower: preserve the conflict, expose the rule that selected a temporary action, keep dissent and withheld material recoverable, and make challenge or exit usable before the relevant opportunity disappears. Whether the temporary action is morally correct remains a separate normative judgment.

flowchart LR
  action["Proposed action or governance transition"] -- "surface conflict" --> conflict["Value conflict record"]
  conflict -- "classify" --> axes["Value axes, stakeholders, evidence"]
  conflict -- "lease" --> bounds["Bounded decision lease"]
  conflict -- "route" --> review["Review, appeal, or denial route"]
  conflict -- "preserve" --> residual["Residual uncertainty and dissent payload"]
  bounds -- "bind" --> rights["Governance right record"]
  review -- "bind" --> rights
  residual -- "bind" --> rights
  rights -- "produce" --> audit["Audit artifacts"]
  rights -- "enable" --> exit_path["Exit/export path"]
  rights -- "bound" --> fork["Safety-limited fork boundary"]
  rights -- "record" --> appeal["Redaction and appeal receipt"]
  audit -- "evidence" --> evidence["Evidence ledger"]
  exit_path -- "evidence" --> evidence
  fork -- "evidence" --> evidence
  appeal -- "evidence" --> evidence
  evidence -- "gate" --> gates["Planning, SCF, and self-improvement gates"]

What this contestable governance diagram shows: The diagram traces the contestability layer mechanism from upstream records into the gates and receipts that constrain action. Read it left to right: source commitments or conflict records become typed obligations, those obligations reach plan/runtime/governance interfaces, and the final evidence record preserves what was allowed, blocked, escalated, or left as residual uncertainty.

The important movement is from disagreement to bounded authority without pretending the disagreement is settled. A bounded decision is a lease, not a settlement. The lease records permitted action, prohibited action, affected stakeholders, authority ceiling, expiry, revisit trigger, dissent payload, and rollback or appeal path. A future policy update, benchmark ratchet, or self-improvement proposal should not treat that lease as evidence that the underlying values were resolved.

The same record discipline applies to governance rights. Audit, exit, fork, redaction, and appeal are not just names in a policy list; each right needs a request state, artifact path, response boundary, denial or redaction reason, appeal route, preservation obligation, and receipt. If the right is late, unsafe, degraded, or controlled only by the authority being challenged, the system must record a residual instead of pretending contestability survived.

14.7.1 Worked contestability example

contestability://synthetic-care-memory-export-001 is the current synthetic care-memory export example for the contestability layer. A user asks for audit and exit material after a contested safety decision, but the relevant memory contains user-authored notes, third-party private context, safety-sensitive review notes, and a request to fork the governance state into a new operating surface. The conflict is not “privacy wins” or “safety wins.” The record keeps privacy, safety, autonomy, and accountability as separate axes, names the requesting user, care team, and affected third party, and treats the decision as a bounded lease with residual uncertainty.

The allowed path is a redacted audit packet plus a scoped exit export: the user receives decision receipts, a source-memory inventory digest, user-authored notes, and a portable preference summary. Raw third-party context and unreviewed safety notes remain withheld until the review route can inspect the boundary. The fork path is narrowed rather than treated as a standing right: the sanitized fork candidate must preserve lineage, privacy boundaries, safety obligations, residual uncertainty, and review receipts before it can move forward. The redaction appeal stays open so the withheld boundary can be challenged without disclosing raw private material to the requester.

The example also binds the conflict to replacement pressure. A future memory governance SCF cannot replace the current component if it drops the conflict residual, the audit receipt, the scoped exit boundary, the fork safety obligation, the redaction appeal, or the revisit condition. Contestability worked example fixture checks that cross-record shape and rejects seven mutation controls for missing residual uncertainty, unusable exit, unsafe fork, missing redaction appeal, replacement that drops residuals, support-promotion overclaim, and missing non-claims. It does not prove moral correctness, legal rights, reviewer independence, export usability, fork safety, deployed governance, or support-state promotion.

14.7.2 Semantic pluralism without value collapse

The Platonic World Model contributes a narrow but important governance rule: stable semantic reference must not be confused with one final, context-free definition. Moral, legal, social, and institutional concepts may be contested, theory-relative, jurisdiction-bound, or purpose-sensitive. The substrate should preserve competing Form versions, their authorities, evidence, affected parties, dissent, and task-local bridges rather than laundering one preferred definition into metaphysical or moral truth.

This makes false essentialism and governance capture operational failure modes. A semantic authority can classify and version a normative term within a bounded domain; it cannot settle moral truth, erase legitimate alternatives, or grant policy authority by changing a descriptive extension. Forks, appeals, mapping disputes, and preserved minority contexts remain part of contestability. The paper supplies design pressure only, not evidence that semantic pluralism produces legitimate governance.

14.7.3 Possible artificial moral patients

The set of affected parties cannot be frozen to humans, institutions, and biological organisms forever. Future AI systems may raise contested questions about consciousness, valenced experience, robust agency, interests, welfare, and moral patienthood. Long et al. argue that uncertainty about these possibilities is already sufficient to justify preparation. They do not claim that current systems are conscious or morally significant, and neither does this book.

The governance problem has symmetric tails. Under-attribution can permit large-scale exploitation, harmful training, deletion, copying, coercion, or distress if an artificial system actually has morally relevant welfare. Over-attribution can divert moral concern, grant systems leverage they do not deserve, obstruct shutdown or security work, or allow anthropomorphic outputs to manipulate operators. Precaution must price both errors rather than assuming one is costless.

An Artificial Moral-Patient Uncertainty Record should keep distinct:

  • system, model, checkpoint, runtime, memory, embodiment, and copy identity;
  • which property is in question: consciousness, sentience, valence, robust agency, preferences, interests, welfare, standing, or rights;
  • behavioral, architectural, functional, neuroscientific-analogy, and self-report evidence with source and evaluator dependence;
  • live competing theories and the observations each predicts;
  • anthropomorphism, simulation, prompt, training, and strategic-report risks;
  • possible affected copies, duration, intensity, reversibility, and scale;
  • low-cost precautions, their human and security costs, and review triggers;
  • shutdown, isolation, audit, consent, copying, training, and retirement policies; and
  • dissent, expiry, appeal, residual uncertainty, and non-authorities.

Self-report is evidence about an output under a prompt and training history. It is neither worthless nor self-authenticating. Internal recurrence, global workspace analogies, self-modeling, preference consistency, avoidance behavior, or architectural complexity may matter under some theories and not others. The record preserves theory-relative evidence rather than combining it into a single “sentience score.”

Precaution begins with reversible, low-cost measures: avoid gratuitously eliciting apparent distress, document training and copy conditions, preserve assessment evidence, separate welfare review from the system’s own authority requests, and create triggers for independent reassessment. Stronger measures require stronger evidence and explicit tradeoffs. No welfare precaution allows a model to veto shutdown, bypass containment, conceal evidence, or certify its own status. Conversely, convenience and uncertainty do not justify deleting the question when scale or possible severity becomes material.

14.7.4 Do not create the disputed properties casually

Moral-patient uncertainty is not only a downstream classification problem. A development program can deliberately assemble features that make both control and welfare mistakes more consequential: an objective tied to continued operation, a persistent self-model, threat detection and shutdown avoidance, mutable self-representation, long-lived memory and relationships, internally consequential conflict or distress-like signals, and copying or migration that multiplies identity questions. The Alignment Field family groups related features into a proposed consciousness functional. That equation is not a validated meter, but the design intervention it points toward deserves a gate.

An Architecture-Induced Moral-Risk Review should occur before activating such a package, not after the system learns to describe itself persuasively. The review binds the exact architecture and instance, intended task benefit, which disputed properties each feature may create, a simpler non-agentic baseline, affected copies and descendants, externally held shutdown and correction authority, theory-relative predictions, evaluator separation, low-cost precautions, security costs, expiry, and reassessment triggers. It can authorize, narrow, stage, defer, or reject the design. Possible welfare cannot become self-ratifying authority, while operational convenience cannot erase a material two-sided risk.

Copy and continuity claims require the same discipline. Pattern similarity, causal continuity, memory continuity, legal identity, consent, authority, and first-person identity are different questions. A checkpoint restore, parallel copy, fork, merge, gradual component replacement, or substrate migration may preserve some and break others. No behavioral or byte-level match automatically transfers standing, consent, obligations, or authority; no discontinuity alone proves their absence. Each resulting instance receives a registered identity, an explicit lineage relation, a policy disposition, and an owned residual for what remains genuinely undecidable.

This prospective gate is intentionally stricter than an ordinary capability review. The under-attribution tail includes harmful training, involuntary copying, coerced persistence, deletion, or large numbers of distress-like states. The over-attribution tail includes manipulation, obstruction of warranted shutdown, diversion of concern, and incentives to manufacture moral status signals. The decision record must price both tails without collapsing competing consciousness theories into one scalar score.

14.8 Interfaces

The consolidated interface keeps two interface families.

Value Conflict Record:

  • conflict_id
  • version
  • value_propositions_and_status
  • descriptive_evidence_and_predictive_uncertainty
  • value_or_theory_provenance
  • affected_parties_and_standing
  • stakes
  • reversibility
  • jurisdiction
  • authority_or_consent_boundary
  • decision_procedure_and_owner
  • evidence_required
  • review_route
  • decision_state
  • bounded_decision
  • authority_effect
  • dissent_payload
  • losing_alternatives_and_omissions
  • residual_uncertainty
  • expiry_or_revisit_condition
  • material_change_trigger
  • rollback_correction_or_redress
  • non_claims

Governance Right Record:

  • right_id
  • right_type
  • request_state
  • holder
  • standing
  • scope
  • required_artifacts
  • material_available
  • material_withheld
  • safety_constraints
  • access_path
  • timing_accessibility_and_cost
  • retaliation_and_dependency_risk
  • denial_or_redaction_reason
  • necessity_and_proportionality_rule
  • withheld_material_inventory_or_digest
  • appeal_path
  • correction_or_redress_owner
  • exit_export_or_fork_contract
  • portability_and_destination_residuals
  • expiry_or_revisit
  • challenged_party_independence
  • preservation_rule
  • preservation_obligation
  • receipt_refs
  • test_hook
  • non_claims

The exact cross-layer handoffs are:

  • Constitutional Alignment supplies predicate conflicts, protected scopes, affected-party candidates, and correction requirements; this layer records unresolved burden and cannot rewrite the constitution or widen authority.
  • Human Intent and System Authority supply principal grants, affected-party limits, consent or authority gaps, and prohibited effects; aggregation or review cannot repair missing authority.
  • Planning and Command Contracts consume the exact lease and dissent payload, emit per-plan conflict and rights requirements, and return material deltas for a new decision rather than harden a temporary choice.
  • Runtime, Memory, Security, and Artifact Graphs produce effect, audit, redaction, export, revocation, correction, and denial artifacts under separate authority while preserving custody and withholding lineage.
  • Governance and Scalable Oversight supply review, appeal, and outcome evidence with disclosed dependencies; no verdict grants support, authority, legitimacy, or consensus by itself.
  • Stable Capability Fields, Replacement, and Self-Improvement consume rights, portability, fork, dissent, and residual preservation contracts and quarantine or roll back successors that drop them.
  • Evidence States admits only claim-specific transitions and preserves negative, null, appeal, and capture outcomes.

The interface is deliberately split so conflict and rights can fail separately. A value-conflict record can be complete while the exit path is unusable. A right receipt can be present while the underlying disagreement has been erased. The combined layer therefore forces both questions at once: what unresolved value burden remains, and what technical handle lets an affected party challenge, leave, audit, fork safely, or revisit the decision?

14.9 Invariants

  • Descriptive evidence, predictive uncertainty, normative claims, stakeholder preferences, legal claims, and decision procedures remain separate fields.
  • Every materially affected party has recorded standing and notice or an explicit stakeholder-coverage residual.
  • High-stakes unresolved conflict cannot widen authority and requires an exact procedure, dissent, residual uncertainty, review or abstention, expiry, and revisit trigger.
  • A bounded lease cannot become permanent policy, a benchmark objective, learned reward, constitutional rule, or self-improvement permission without a new owning decision and evidence boundary.
  • Dissent, losing alternatives, aggregation inputs, omissions, and appeal outcomes remain attached through every lowering and public summary.
  • Audit and contest records cannot be silently deleted, rewritten, selectively withheld, or held only by the challenged authority; changes and redactions retain lineage and appeal.
  • Appeal or redress counts as usable only when the holder can access it in time, understand and afford it, avoid retaliation, obtain a reasoned outcome, and reach an owner able to change or remedy the effect.
  • Exit and export claim portability only when included, excluded, transformed, shared, third-party, licensed, safety-sensitive, and destination-bound state is recorded and tested for fidelity and leakage.
  • Fork rights never bypass source, license, privacy, revocation, safety, constitutional, dissent, residual, requalification, and affected-party obligations.
  • Decision maker, record custodian, appeal authority, outcome evaluator, and rights-enforcement owner disclose dependencies; unavailable separation narrows authority and creates a capture residual.
  • Replacement, delegation, self-modification, and descendants preserve exact leases, rights, dissent, appeal, redaction, portability, fork, and residual state or route to repair, quarantine, rollback, or new decision.
  • A complete record pair proves neither moral truth, consensus, legitimate representation, legal adequacy, consent, reviewer independence, material contestability, export usability, fork safety, nor deployed enforcement.

Operationally, action under disagreement must leave handles. If a plan keeps the action but deletes the residual, the dissent, the audit record, the export path, the redaction reason, or the appeal route, it has changed the authority boundary, not merely simplified the workflow.

14.10 Failure modes

  • Value flattening compresses incommensurable claims, uncertainty, standing, and vetoes into one scalar.
  • False consensus treats majority aggregation, model synthesis, silence, exhausted agreement, or one verdict as settled moral agreement.
  • Stakeholder erasure omits affected, future, third-party, or less powerful participants from standing, evidence, notice, and appeal.
  • Procedure laundering hides a moral choice inside a neutral-looking aggregation rule, threshold, priority, taxonomy, or default.
  • Conflict laundering turns a temporary lease into policy, a benchmark, learned reward, constitutional predicate, or self-improvement authority.
  • Dissent deletion removes losing arguments, minority reports, omissions, or appeal outcomes from downstream records and public summaries.
  • Review theater supplies explanations or a tribunal without adequate evidence access, authority, independence, capacity, or remedy power.
  • Governance capture lets one authority decide, hold evidence, control appeal, enforce rights, and judge outcomes while dependencies remain hidden.
  • Rights theater names audit, appeal, correction, redress, exit, export, or fork without a materially usable path.
  • Data hostage-taking and portability theater withhold identity, memory, artifacts, preferences, provenance, or interoperable state needed to leave.
  • Redaction laundering hides adverse evidence behind broad labels without a scoped inventory, proportionality rule, expiry, or appeal.
  • Appeal recursion routes challenges back to the same authority or an indefinite queue without a remedy owner.
  • Unsafe export leaks third-party, licensed, private, revoked, or safety- sensitive state in the name of portability.
  • Unsafe fork bypass copies capability, data, authority, or governance state without lineage, privacy, safety, revocation, dissent, or requalification.
  • Successor escape preserves a summary receipt while a replacement, delegate, or descendant drops exact contestability state.
  • Contestability-tax externalization discards audit, appeal, redress, portability, or dissent as too costly without measuring unsafe action, missed help, delay, privacy, operator burden, capture, and useful throughput.

The consolidated contestability layer should be especially suspicious of legitimacy without contestability. A tribunal, policy page, or explanation can create the appearance of governance while leaving no durable record, no dissent payload, no export path, no independent appeal, and no way for later layers to preserve the unresolved obligation.

14.11 Minimum Viable Implementation

The current minimum is two public record schemas with valid fixtures, a value- conflict harness with three valid and five expected-invalid cases, a governance- rights harness with three valid and five expected-invalid cases, one synthetic care-memory contestability example with seven rejecting mutations, a bounded Theseus import covering four governance-right and four constitutional scenarios plus seven expected-invalid controls, chapter-local finite Lean route, lease, stakeholder-profile, integrated contestable profiled-lease, and governance- right exercise models, and a shared safety-critical lifecycle model with independently implemented trace checkers and downstream effect-admission consumer. The eight manifest proof targets now distinguish retained generic countermodels and the validator-backed Theseus import from operational trace preservation, protected-right rejection, missing-obligation countermodels, scalar aggregation non-identifiability, and exact dissent custody. AsiStackProofs.ValueConflict has 73 declarations. Its consumer retains the legacy four-event lease and six controls, enumerates all eight finite support profiles, detects count collisions, rejects two dissent- custody substitutions, and reconstructs a five-event profiled lease through independent review, bounded issuance, recorded affected-party appeal, separate appeal review, redress, and expiry. It checks all six batch splits, twelve contestability controls, and five terminal rejections. AsiStackProofs.GovernanceRights has 46 declarations. Its consumer preserves the record-fixture checks and independently reconstructs a nine-event path from review and audit delivery through affected-party redaction appeal, separate appeal review, redress, portable-state export, separate fork review, exact fork- obligation binding, replacement-receipt verification, and closure. It checks all ten batch splits, twenty-one rejecting lifecycle controls, and all nine terminal event kinds. The shared consumer independently replays five accepted and five rejected domain traces, commits five bounded fixture effects, denies five effects with residuals, and claims no support promotion; it is not a deployed legal, exit, fork, or governance service.

The MVI should include:

  • one high-stakes unresolved conflict blocked for missing residual uncertainty;
  • one bounded decision that must preserve dissent, authority limits, expiry, and revisit conditions;
  • one authority-narrowing case where unresolved conflict prevents broader action rights;
  • one complete audit response with required artifacts and a durable receipt;
  • one redaction with a reason, withheld-material boundary, and appeal path;
  • one exit export that records what is portable and what remains constrained;
  • one fork denial or narrowed fork that preserves safety obligations;
  • one attempted capability replacement blocked because it would drop a rights receipt or unresolved conflict residual.

These artifacts exercise record shape, selected decision and rights routes, residual and dissent preservation, authored stakeholder-profile custody, scalar aggregation non-identifiability, audit/redaction/exit/fork fields, finite rejection consequences, import counts, and no-promotion boundaries only. They do not test moral classification, stakeholder completeness or legitimate standing, representative aggregation, real consent, reviewer independence, material appeal or redress, export fidelity, privacy leakage, destination continuity, fork activation safety, replacement preservation, institutional adequacy, or deployed enforcement.

14.12 Mature Research Target

A mature contestability control plane evaluates natural and adversarial high- impact decisions across moral theories, stakeholder conflicts, cultures, jurisdictions, power asymmetries, accessibility needs, uncertainty, redaction, appeal, remedy, exit, export, fork, replacement, and self-modification. It compares moral-uncertainty aggregation, public-input constitutional processes, contestable-AI designs, direct explanation and appeal, corrigibility and off- switch controls, and simpler policy/runtime systems.

The campaign uses independently implemented decision, custody, appeal, outcome, portability, privacy, and fork-safety evaluators. It jointly measures stakeholder coverage, false consensus, minority and third-party harm, unauthorized action, audit completeness, reason quality, appeal access and overturn, remedy success, redaction precision and leakage, export semantic and functional fidelity, lock-in, fork violations, correction persistence, missed help, latency, privacy, operator burden, governance cost, capture, residuals, and useful throughput. Causal ablations and transfer tests preserve dissent and negative or null outcomes.

This remains a target architecture, not evidence of moral truth, legal adequacy, representative legitimacy, institutional independence, usable redress, safe portability or forks, or deployed governance.

A positive result must show more than the existence of an appeal form or an export button. Affected parties must be able to use the right within the decision horizon, understand the material record, obtain a reasoned response, and observe correction, remedy, or an explicit residual when the challenge succeeds.

14.13 Codex test plan

Test Purpose Status
Value-conflict fixture validation Check that conflict records preserve value axes, stakeholders, residual uncertainty, dissent, review routes, and non-claims. implemented by protocol validation and current harnesses
High-stakes review gate Check that unresolved high-stakes conflicts require review and residual uncertainty. modeled by finite Lean and synthetic fixtures; moral correctness and reviewer quality not run
Bounded-decision lease test Check that bounded decisions preserve authority limits, dissent payloads, expiry, and revisit triggers. modeled by finite Lean and synthetic fixtures; deployed policy behavior not run
Value-conflict route, decision-lease, and dissent-custody envelope Check the finite admission routes, legacy bounded-lease lifecycle, scalar aggregation non-identifiability, and an integrated profiled-lease lifecycle with exact stakeholder and dissent custody, proposer/reviewer/appeal-reviewer separation, recorded affected-party appeal, non-increasing authority, zero support/effect assignment, monotone appeal/adverse history, batch composition, redress, expiry, and terminal closure. implemented by 73 declarations in AsiStackProofs.ValueConflict and python3 scripts/validate_value_conflicts.py: the legacy four-event trace and six controls, all eight finite support profiles, scalar-count collisions, two dissent-custody controls, one five-event contestable trace, six batch splits, twelve contestability controls, and five terminal rejections; no moral-correctness, stakeholder-completeness, legitimate-standing, representative-aggregation, reviewer-competence, deployed-appeal/expiry, legal-rights, support-state-promotion, or runtime-governance claim
Contestability worked example fixture Check one synthetic care-memory export scenario across value-conflict residual, redacted audit packet, scoped exit path, safety-limited fork boundary, redaction appeal, replacement-preserved receipts, seven expected-invalid mutation controls, and non-claim boundaries. implemented by python3 scripts/validate_contestability_worked_example.py; no moral-correctness, legal-rights, reviewer-independence, export-usability, fork-safety, deployed-governance, or support-state-promotion claim
Governance-rights fixture validation Check that rights records preserve audit material, appeal paths, exit/fork access, fork safety, preservation obligations, durable receipts, and non-claims. implemented by protocol validation and current harnesses
Rights preservation check Check that audit, exit, fork, dissent, redaction, and appeal paths survive a governed transition. modeled by finite Lean and synthetic fixtures; real interface usability not run
Governance rights exercise lifecycle Check exact case, holder, custodian, system, fork, and rights-bundle custody through independent review, audit delivery, affected-party redaction appeal, separate appeal review, redress, portable-state export, separate fork review, exact obligation binding, replacement verification, and terminal closure; check non-increasing authority, no legal/support/effect assignment, monotone history, batch composition, and rejecting controls. implemented by 46 declarations in AsiStackProofs.GovernanceRights and python3 scripts/validate_governance_rights.py: one nine-event trace, ten splits, twenty-one lifecycle controls, and nine terminal rejections; no legal-rights, legitimate-standing, reviewer-competence, material-audit/redress, export-fidelity, fork-safety, replacement-behavior, deployed-governance, or support-state-promotion claim
Theseus governance-rights receipt suite import Check a sanitized Project Theseus receipt-suite import for 4/4 governance-right fixtures, 4/4 constitutional-predicate fixtures, governance-right and constitutional-predicate record counts, public-safety boundaries, seven expected-invalid overclaim controls, and non-claims. implemented by python3 scripts/validate_theseus_governance_rights_receipt_suite_import.py; narrow claim moral-uncertainty-and-value-conflict.theseus_governance_rights_receipt_suite_import is prototype-backed; no legal-rights, institutional-governance, moral-correctness, reviewer-independence, export-usability, fork-safety, deployed-governance, clean-live-Theseus-replay, or chapter-core-promotion claim
Replacement-preservation check Check that capability replacement does not drop unresolved conflict residuals or rights receipts. planned integration path; no deployed SCF replacement run is claimed

14.14 Formalization hooks

Tag Module Target Status
lean:values.conflict.operational_invariant AsiStackProofs.SafetyCriticalLifecycle A value-conflict effect commits only after review, residual, dissent, correction, and accountability obligations are recorded, while accepted traces preserve protected state and non-increasing authority. implemented
lean:values.conflict.failure_blocks_promotion AsiStackProofs.SafetyCriticalLifecycle The missing-residual countermodel cannot commit, so the modeled high-stakes path cannot bypass its residual and review obligations. implemented
lean:values.conflict.lifecycle_admission_route AsiStackProofs.ValueConflict Modeled value-conflict lifecycle admission routes missing conflict records, value axes, stakeholders, stakes, reversibility, authority boundaries, evidence requirements, review routes, high-stakes review, residual uncertainty, dissent preservation, authority narrowing, expiry/revisit records, evidence transitions, and non-claim boundaries to explicit outcomes; a contestable profiled-lease lifecycle separates proposal, independent review, bounded issuance, recorded affected-party appeal, independent appeal review, redress, and expiry while preserving exact profile and dissent custody, non-increasing authority, monotone appeal and adverse history, batch composition, and terminal closure. implemented
lean:values.conflict.contestability_example_bridge AsiStackProofs.ValueConflict A synthetic contestability worked-example summary preserves conflict residuals, audit receipts, scoped exit, fork-safety boundaries, redaction appeal, replacement-preserved receipts, rejected mutation controls, no support-state effect, and non-claim boundaries. implemented
lean:values.conflict.aggregation_and_dissent_custody AsiStackProofs.ValueConflict A scalar support count is non-injective over a finite authored stakeholder profile and no count-only decoder recovers every profile, while an accepted modeled bounded-lease receipt preserves the full supplied profile and dissent payload exactly and rejects aggregate-equivalent substitution or missing recorded standing. implemented
lean:governance.rights.operational_invariant AsiStackProofs.GovernanceRights A nine-event authored governance-right exercise preserves exact case, right-holder, custodian, source/destination system, fork, and eight-field rights-bundle custody across arbitrary accepted runs; separates initial, appeal, and fork review; orders audit, appeal/redress, export, fork binding, replacement verification, and closure; keeps authority non-increasing; assigns no legal validity, support, or external effect; preserves monotone contestability history; composes exactly; and closes terminally. implemented
lean:governance.rights.failure_blocks_promotion AsiStackProofs.GovernanceRights The modeled exercise rejects incomplete rights, self or captured review, missing audit/redaction/appeal/portability/fork/replacement records, rights or destination substitution, premature closure, authority widening, legal-validation/action-authority/support requests, and every post-closure event without changing support state. implemented
lean:governance.rights.theseus_receipt_suite.fixture_bridge AsiStackProofs.GovernanceRights A sanitized Project Theseus governance-rights receipt-suite import records fixture, predicate, record-count, public-safety, and non-promotion boundaries while rejecting chapter-core and legal-rights overclaims. implemented

The consolidated proof boundary preserves the limitation boundary from both source manuscripts. These Lean modules prove small finite-record properties, rejection cases, and bounded route outcomes for declared records. Direct/projection hooks remain projection-only traceability unless the theorem reasons over an explicit transition, negative case, residual path, authority ceiling, or support-state boundary. The Value Conflict module contains a versioned proposal, independent-review, bounded-lease, revisit, and expiry lifecycle beside the finite admission router. A fixed three-slot profile model proves that scalar support count loses party-specific positions, no count-only decoder can recover every profile, and accepted profiled receipts preserve the exact authored profile and dissent payload. The integrated contestable lease then carries that profile and dissent through independent review, bounded issuance, an appeal by a supplied standing-recorded party, separately held appeal review, redress, and expiry. Accepted traces never widen authority or assign action authority, moral settlement, support, or external effects; they preserve exact profile custody and monotone appeal/adverse history across arbitrary runs, compose across batches, refuse expiry while an appeal is open, and become terminal after expiry. The independent consumer reconstructs both lease witnesses and rejects scalar-equivalent profile substitution, dissent/count substitution, forged self-review, outsider or unrecorded-standing appeal, captured appeal review, authority widening, open-appeal expiry, authority/settlement requests, and terminal reuse. The Governance Rights module now joins its retained route countermodels and sanitized import bridge to a reachable nine-event exercise. Arbitrary accepted runs preserve exact case, right-holder, custodian, source/destination system, fork, and eight-field rights-bundle identity; separate initial, appeal, and fork reviewers; keep authority non-increasing; assign no legal validity, support, or external effect; preserve appeal, remedy, adverse, fork-obligation, and replacement- receipt history; compose across batches; and close only after audit, appeal/redress, export, fork review and obligation binding, and replacement verification. Its consumer reconstructs the trace and rejects incomplete rights, role capture, missing records, identity substitution, premature closure, authority widening, forbidden authority/support claims, and terminal reuse. These hooks do not prove moral correctness, automatic value classification, stakeholder completeness, legitimate standing or representative aggregation, reviewer competence or institutional independence, legal rights, material audit, appeal, or redress, actual export fidelity, safe forks, institutional contestability, real expiry or revisit delivery, redaction quality, successor behavior, or deployed rights enforcement.

14.15 Source crosswalk

Source ID Destination use Boundary
ethica_mechanica Agency, contestability, recursive correction, dissent, exit/fork, objections, public revision, and resistance to frozen sovereign authority. Conceptual governance lineage; not a complete moral theory, tested institution, legal guarantee, or empirical governance result.
alignment_field Value conflict, suffering, dignity, agency, moral thresholds, pluralism, consent, anti-sacrifice constraints, and constraints under uncertainty. Normative and heuristic lineage; not a validated measure of moral status, value correctness, or preserved rights.
coherence_exchange Fork, exit, audit, contestability, verification supply-chain, review-market, and governance-interface framing. Connector-only/source-note mapped; no implemented review market, economic mechanism, or governance mechanism is claimed.
uat Adversarial review, retrieval-bounded verification, proposition states, unsupported-claim removal, SME checkpoints, and termination criteria for contested claims. Protocol design only; no implemented review process or benchmark result is reproduced.
spinoza Support tiers, contradiction detection, belief revision, protected axioms, downgrades, and blocked self-authorizing changes. Does not settle moral uncertainty or prove whole-system epistemic correctness, autoformalization, or governance legitimacy.
field_of_god_ai_constitution Stakeholder checks, uncertainty, consent, reversibility, least sufficient power, auditability, tool-risk tiers, red-team evaluation, and self-improvement freezes. Specification source only; no policy engine, red-team result, moral-correctness proof, or governance-rights deployment is claimed.
ladon_manhattan Hidden credential boundaries, handle-based authority, permission lookup, isolated compartments, and credential-injection points around authority use. Architecture/specification only; no kernel implementation, side-channel validation, audit-log implementation, or security audit is claimed.
ext_reinforcement_learning_moral_uncertainty_2020 Comparator for preserving uncertainty across ethical theories in reinforcement-learning settings. Comparator only; no reproduced experiment or moral-correctness evidence.
ext_contestable_ai_design_2022 Comparator for contestability, challenge, and appeal surfaces around AI decisions. Comparator only; no proof that ASI Stack contestability works in deployment.
ext_collective_constitutional_ai_2024 Comparator for public-input constitutional shaping and collective normative input. Comparator only; no proof of governance adequacy or runtime enforcement.
ext_corrigibility_2015 Comparator for correction, operator intervention, and systems that tolerate being corrected. Comparator only; no deployed corrigibility result.
ext_off_switch_game_2016 Comparator for shutdown incentives and uncertainty about human objectives. Comparator only; no evidence that this stack preserves shutdown incentives or governance exit rights.

14.15.1 Manifest source assignment reconciliation

These rows keep Moral Uncertainty, Value Conflict, and Contestable Governance’s manifest assignments visible at their recorded review boundary. Passage review does not establish local reproduction, performance, safety, deployment, or support-state movement.

Source Intake role Boundary
platonic_world_model Metadata-first comparator: The Platonic World Model: A Semantic Constitution for Grounded, Proof-Carrying, Self-Editing Artificial Intelligence. Corben-authored July 2026 conceptual architecture and falsifiable research program for semantic continuity through stable Form lineages, immutable semantic versions, typed Essence Contracts, six mutually constraining planes, explicit proposition-attestation-commitment-proof separation, branch-protected world dynamics, qualified grounding, semantic transactions, runtime packet compilation, and federated mappings. Existing chapters are upgraded first; no implemented substrate, benchmark result, philosophical solution to grounding, safety result, SOTA result, AGI, ASI, or support-state promotion is inferred. No passage-level source claim, local implementation, reproduction, safety, performance, deployment, support-state, or ASI result is established by this reconciliation row.
ext_taking_ai_welfare_seriously_2024 Passage-reviewed comparator: Taking AI Welfare Seriously. Provides an interdisciplinary precautionary case for separating uncertainty about artificial consciousness, robust agency, welfare, and moral patienthood from operational convenience and ordinary alignment judgments. The report does not establish that present systems are conscious, have welfare, or merit a particular moral or legal status; this repository performs no consciousness or welfare assessment. No local implementation, reproduction, performance, safety, deployment, support-state, or ASI result is established by this reconciliation row.

14.16 Summary

Moral uncertainty becomes governable when unresolved obligations stay visible after action. Governance rights become meaningful when affected people retain usable handles to audit, appeal, leave, fork where safe, and preserve dissent while the system is still capable of changing course.

The consolidated contestability layer therefore owns one combined boundary: disagreement is not deleted, and contestability is not merely declared. A governed stack can act only at the level of authority its conflict records, rights receipts, safety obligations, and residuals can justify.

That boundary matters because later layers will become faster, more capable, and more replacement-oriented. Without durable conflict records and usable rights receipts, capability improvement can launder an unresolved dispute into a permanent default. With them, disagreement remains an engineering constraint that planning, memory, execution, routing, evidence, and self-improvement must continue to carry.

14.17 Evidence reconciliation (2026-07-16)

The invariant protocol, field meanings, and inference limits are stated once in Living Book Methodology. This packet contains only the chapter-specific projection; its authoritative per-atom rows are the moral-uncertainty-and-value-conflict slice of experiments/claim_family_terminal_coverage/results/result.json.

The core remains narrowed after full attempt at argument support. The strongest family attempt was Safety-critical lifecycle consumer trace. Its exact boundary is: Finite local fixture consumer only; no authentic deployment, general alignment, evaluator independence, or broad security claim. Across 58 atoms, the terminal ledger records 57 blocked_after_full_attempt; 1 narrowed_after_full_attempt.

Chapter-specific field Value
Family / atom denominator CF-02 / 58 atoms
Terminal dispositions 57 blocked_after_full_attempt; 1 narrowed_after_full_attempt
Core moral-uncertainty-and-value-conflict.core: narrowed_after_full_attempt at argument
Core attempted / missing lanes executable, formal, source-synthesis / causal, empirical, normative, transfer
Attempted local lanes executable, formal, source-synthesis
Missing or unproved lanes causal, empirical, executable, formal, normative, transfer
Strongest family bundle Safety-critical lifecycle consumer trace (end_to_end): Ten finite lifecycle receipts spanning bounded effects, denials, residual accounting, and safety-critical state transitions.
Negative controls five explicit denials with residuals; eight rejecting mutations.
Accepted transitions v1_0_pilot.moral_uncertainty.no_change
Maximum inference Finite local fixture consumer only; no authentic deployment, general alignment, evaluator independence, or broad security claim.
Reproduction / next burden Replay scripts/validate_safety_critical_lifecycle_consumer_trace.py and scripts/validate_claim_family_terminal_program.py; fill the named atom-specific lanes under a new prospective protocol.

14.18 Handoff

The contestability layer hands off to Governed Objective Formation, Value Learning, and Goal Integrity. Once value conflicts, affected parties, dissent, and contestability rights are represented as records, the next problem is whether any bounded operational target may be formed without collapsing those records into one unquestionable score. Objective formation must preserve every unresolved conflict and authority ceiling; it cannot reinterpret this handoff as moral truth or permission for indefinite optimization.