Product projection

Narrative technical book

A bounded thesis-to-method reading route with the live research scaffold hidden in Human view.

Status: generated twenty-two-unit candidate route. It is not a reviewed reader release, and the other canonical chapters remain in the architecture reference.

Thesis-to-method route

1 · Stack thesis · asi-is-a-stack-not-a-model.core

ASI Is a Stack, Not a Model

Plain-language thesis: Advanced AI is easier to understand and govern when capability, authority, memory, planning, action, evidence, and improvement remain distinct responsibilities.

Engineering rule: Design the system as typed layers whose artifacts and authority cross only declared interfaces with explicit failure, observation, and recovery ownership.

Machine contract: Admit a layer transition only when source and target identities, authority, obligations, evidence, residuals, consumers, expiry, and recovery are bound; capability alone does not authorize the transition.

Question: Why should advanced AI be treated as governed responsibilities and transitions rather than one opaque model?

Running example: Start one repository change by separating capability, authority, context, plan, effect, observation, evidence, and replacement.

Specialist reference owners: none; this representative is the unit’s sole canonical owner.

2 · Efficient-ASI hypothesis · the-efficient-asi-hypothesis.core

The Efficient ASI Hypothesis

Plain-language thesis: Useful intelligence may become cheaper and more dependable when work is routed, reused, verified, and repaired according to the task instead of always invoking the largest model.

Engineering rule: Compare candidate routes on accepted useful output and full lifecycle cost, including verification, repair, review, residuals, latency, memory, energy, and recovery.

Machine contract: Select a route only from candidates that satisfy the frozen quality and authority floor and minimize declared lifecycle cost; a cheaper token path does not establish efficiency or permission.

Question: Can governed routing, reuse, and specialist computation improve useful capability without hiding displaced costs?

Running example: Compare frontier-model-only work with a routed repository change that reuses context, specialists, tests, and independent checks.

Specialist reference owners: none; this representative is the unit’s sole canonical owner.

3 · Authority, security, and failure boundaries · system-boundaries-and-authority.core

System Boundaries and Authority

Plain-language thesis: A system remains governable only when proposing, approving, executing, observing, and releasing are different acts with different authority and ownership.

Engineering rule: Bind every material effect to a current scoped grant, an exact dispatch record, independent-enough observation, and a recovery or residual route.

Machine contract: Permit an effect only when caller identity, live grant, authority ceiling, target, epoch, receipt, observer, and rollback or compensation state validate; a plan or credential handle does not create effect authority.

Question: Which boundaries separate proposal, approval, execution, observation, and release, and how do failures remain owned?

Running example: Let the planner draft a patch while a current scoped grant alone permits a bounded adapter to alter the tree.

Specialist reference owners (9)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Failure Modes of Ungoverned Intelligence
    Distinct responsibility: A stack-level failure model should represent each named risk as a distinct boundary event with a trigger, protected invariant, detector or observer, receipt, owner, containment action, residual, recurrence state, and escalation or learning path; a taxonomy entry alone establishes neither occurrence nor mitigation.
    failure-modes-of-ungoverned-intelligence.core · Design rationale at argument support
  • Dangerous Capability Domains and Misuse Uplift
    Distinct responsibility: Dangerous-capability authority should be based on a versioned domain threat model and an uplift dossier that separates latent capability, elicited performance, propensity, safeguard bypass, actor uplift, and realized harm; preserves expertise, tools, assistance, attempts, uncertainty, and sensitive-detail boundaries; and routes only bounded findings into thresholds, release, monitoring, and resilience decisions.
    dangerous-capability-domains-and-misuse-uplift.core · Design rationale at argument support
  • Military AI, Autonomous Weapons, and Strategic Stability
    Distinct responsibility: Military AI should be governed as a command-and-interaction system: deployment requires a declared mission and legal boundary, preserved accountable human authority, bounded sensing and action, adversarial and escalation analysis, fail-safe behavior, auditable provenance, and prospective off-ramps; component benchmark gains alone establish neither lawful use nor strategic safety.
    military-ai-autonomous-weapons-and-strategic-stability.core · Design rationale at argument support
  • Security Kernel and Digital SCIFs
    Distinct responsibility: Every privileged information flow or effect should execute as a threat-model-bound authority-use transaction through a non-bypassable reference monitor: bind the exact principal, purpose, operation, target, data and taint scope, budget, time, nonce, evaluator and policy identities; admit only minimized context and capabilities into a declared isolation grade; mediate every effect and egress; treat sanitization as explicit declassification; close leases, caches, logs, descendants, and residuals through revocation or incident recovery; and never infer security from the record, handle, compartment, or finite test alone.
    security-kernel-and-digital-scifs.core · Design rationale at argument support
  • Adversarial Machine Learning and the Model Attack Surface
    Distinct responsibility: A learned model should receive security authority only through a versioned model-threat contract and attack/defense ledger that binds checkpoint identity, lifecycle stage, attacker knowledge and capability, surface, budget, objective, adaptation, transfer, observed effect, detection, mitigation, utility cost, recovery, residual, and disclosure; clean accuracy, attack failure, benchmark robustness, red-team coverage, or formal certification alone establishes neither general robustness nor secure deployment.
    adversarial-machine-learning-and-model-attack-surface.core · Design rationale at argument support
  • Privacy, Data Rights, and Information-Flow Governance
    Distinct responsibility: An information use is eligible for bounded execution only when a prospectively declared record binds affected parties, exact purpose and processing, claimed authority and jurisdiction, recipients, retention, minimization, complete-enough flow and derivatives, cross-user boundaries, privacy unit, adjacency, accountant and budget where applicable, threat model and attack plan, rights state and remedy, exceptions, residual copies and influence, costs, and non-authorities; no individual control or receipt alone establishes privacy, legal compliance, total erasure, behavioral forgetting, influence removal, support, readiness, release, transfer, or SOTA.
    privacy-data-rights-and-information-flow-governance.core · Design rationale at argument support
  • Confidential and Verifiable AI Computation
    Distinct responsibility: Confidential and verifiable AI requires a compositional execution contract that names the adversary, protected assets, permitted leakage, trust anchors, proof or attestation statement, verifier policy, freshness, revocation, performance budget, and authorization boundary; no primitive or attestation may be treated as proof of semantic correctness, legitimate purpose, or end-to-end privacy.
    confidential-and-verifiable-ai-computation.core · Design rationale at argument support
  • Model-Weight Custody and Hardware Roots of Trust
    Distinct responsibility: Every governed model-family custody transition should bind a prospectively declared asset-and-derivative closure to exact artifact and lineage identity, holder and purpose, storage/transfer state, key and metadata lifecycle, Attester/Verifier/Relying-Party roles and policies, reference values and endorsements, freshness, measured target and attesting environments, verifier dependencies, independent-enough effect observation, plaintext and output-extraction exposure, load/use/serve/release authority separation, backup and emergency recovery, copy/recipient/descendant state, incident and revocation semantics, sanitization method and validation, irreversible distribution, privacy/rights/cost residuals, and terminal ownership; missing or failed modeled predicates route to a named non-default state, while no record, encryption, signature, security level, attestation result, hardware root, key action, deletion receipt, or finite proof by itself establishes custody completeness, confidentiality, trustworthy hardware, model safety, release merit, readiness, or deployment authority.
    model-weight-custody-and-hardware-roots-of-trust.core · Design rationale at argument support
  • AI Supply-Chain Integrity and Lifecycle Provenance
    Distinct responsibility: Every governed AI supply-chain decision should bind a prospectively frozen consumer, requested use, threat and assurance model, materiality policy, and relation-specific asset closure to exact subject/content and lineage identity; typed data, code, model, prompt/policy, dependency, build/training/evaluation, environment, hardware/firmware, supplier/service, signer, advisory, transformation, release, recipient, descendant, retention, and retirement state; issuer, verifier, policy, freshness, trust and dependency boundaries; observed artifact and lifecycle effects; append-only invalidation and acknowledged affected-path propagation; restoration, compensation, disclosure, privacy/rights, availability, cost, and terminal residual ownership. Missing, inconsistent, stale, unverifiable, revoked, compromised, materially incomplete, or unresolved-critical predicates should route each affected consumer to a named non-ordinary state, while no graph, BOM, checksum, signature, provenance statement, SLSA level, layout, supplier claim, advisory, quarantine, conformance result, or finite proof by itself establishes world-complete lineage, assertion truth, artifact correctness, absence of compromise, data fitness or rights, model safety, legal compliance, readiness, release merit, or deployment authority.
    ai-supply-chain-integrity-and-lifecycle-provenance.core · Design rationale at argument support
4 · Evidence states, oversight, and noninheritance · evidence-states-and-claim-discipline.core

Evidence States and Claim Discipline

Plain-language thesis: Evidence should strengthen only the claim it actually tests; nearby architecture claims, publication language, and runtime permissions must not inherit that support.

Engineering rule: Move a claim between support states only through an accepted, identity-bound transition that names evidence, scope, defeaters, maximum inference, and downstream consumers.

Machine contract: Apply a support transition only when claim identity, prior state, evidence bundle, evaluator, scope, decision, defeaters, and nonclaims validate; a receipt, theorem, citation, or adjacent result does not promote another claim.

Question: How can claims change while capability, authority, context, receipts, proofs, and publication remain noninheriting states?

Running example: Let one repository test strengthen a narrow result without promoting the architecture claim or turning a receipt into reality.

Specialist reference owners (1)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Scalable Oversight and Adversarial AI Control
    Distinct responsibility: A governed stack admits scalable oversight only as a versioned, consumer-bound protocol receipt rather than a vote: it prospectively records task, cohort, risk and authority scope; supervisor and system capability envelopes; evidence views; roles, incentives, and dependency graph; informed direct-review baseline; declared outcome-audit path; calibration, coverage, and abstention semantics; persuasion, correlation, operator-cost, and monitorability residuals; escalation owner; expiry; and requalification triggers. The receipt may inform only its permitted review or training consumer through the owning gate and cannot by itself establish reviewer independence, reliable supervision, correctness, safety, support movement, release readiness, or execution authority.
    scalable-oversight-and-adversarial-ai-control.core · Design rationale at argument support
5 · Constitutional, value, objective, and institutional governance · constitutional-alignment-substrate.core

Constitutional Alignment: Agency, Dignity, and Corrigibility

Plain-language thesis: Powerful optimization needs a contestable constitutional process that exposes value conflict, protects agency, and prevents the optimizer from controlling its own rules or evidence.

Engineering rule: Separate objective proposal, interpretation, protected constraints, affected-party standing, amendment authority, evaluation, appeal, and enforcement while preserving unresolved disagreement.

Machine contract: Accept an objective or constitutional change only with authorized provenance, conflict disclosure, protected-boundary checks, independent evaluation, appeal, and ratification; model preference or performance does not self-ratify the change.

Question: How should constitutions, conflicting values, learned objectives, human factors, and legitimate amendment interact?

Running example: A repository request conflicts with a protected policy and a user preference, forcing contestable interpretation rather than silent optimization.

Specialist reference owners (7)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Human Factors and Meaningful Control in Oversight
    Distinct responsibility: Meaningful oversight is a resource-bounded control contract: the system must preserve an identified human controller's knowledge, authority, time, observability, and effective intervention path, and must degrade or abstain when that control envelope cannot be maintained.
    human-factors-and-meaningful-control-in-oversight.core · Design rationale at argument support
  • Human-AI Communication, Persuasion, and Epistemic Security
    Distinct responsibility: Consequential AI communication should be eligible for delivery only through an evidence-bounded communication packet whose audience, influence method, amplification authority, provenance, expiry, correction reach, and observed effects remain inspectable; fluent text, factual fragments, user consent, or a successful persuasion score alone establishes neither epistemic safety, autonomy, legitimacy, durable benefit, nor release readiness.
    human-ai-communication-persuasion-and-epistemic-security.core · Design rationale at argument support
  • Inner Alignment, Mesa-Optimization, and Learned-Objective Integrity
    Distinct responsibility: Consequential deployment requires a Learned-Objective Integrity Record binding the outer target, actual learning signals, model identity, behaviorally equivalent policy hypotheses, internal-optimization evidence, goal-generalization and conditional-policy tests, independent behavioral/interventional/white-box evidence, deployment opportunity, power indicators, mitigation hiding tests, monitoring, rollback, descendant invalidation, costs, residuals, and non-authorities.
    inner-alignment-mesa-optimization-and-learned-objective-integrity.core · Design rationale at argument support
  • Moral Uncertainty, Value Conflict, and Contestable Governance
    Distinct responsibility: A contestable governance layer should represent each action under unresolved value conflict as a versioned decision lease plus a linked rights receipt. The lease binds value propositions and their epistemic status, affected parties and standing, stakes and reversibility, authority and consent boundaries, the declared aggregation or precedence rule, preserved dissent, evidence and uncertainty, permitted and prohibited actions, expiry and revisit triggers, and rollback or redress. The rights receipt binds audit and explanation artifacts, independent-enough custody and review, denial and redaction reasons, appeal and correction routes, exit and export scope, safety-limited fork obligations, portability residuals, and downstream preservation. The pair may narrow or delay separately authorized action but cannot settle moral truth, manufacture consensus, grant authority, establish legal rights or legitimacy, prove material contestability, or guarantee safe exit, export, fork, replacement, self-modification, or deployed governance by itself.
    moral-uncertainty-and-value-conflict.core · Design rationale at argument support
  • Governed Objective Formation, Value Learning, and Goal Integrity
    Distinct responsibility: A durable objective should be usable only through a versioned target-property contract that binds authority and affected parties to target/proxy causal assumptions, uncertainty and dissent, consumer-specific use, tampering tests, generalization limits, ontology version, expiry, reauthorization, and retirement; proxy improvement, predicted preference, reward, evaluator approval, or formal record validity alone establishes neither the right objective, moral truth, stable alignment, nor safe optimization.
    governed-objective-formation-value-learning-and-goal-integrity.core · Design rationale at argument support
  • Institutions, International Coordination, and Public Legitimacy
    Distinct responsibility: Public deployment and cross-border coordination should proceed only through a versioned institutional packet that keeps jurisdiction, mandate, participation, scientific evidence, law and standards, verification, enforcement, remedy, capacity, conflict, expiry, and legitimacy residuals distinct; legal text, technical conformance, stakeholder consultation, or an international commitment alone establishes neither lawful authority, effective governance, representative legitimacy, nor safety.
    institutions-international-coordination-and-public-legitimacy.core · Design rationale at argument support
  • Societal Resilience and Misuse Defense
    Distinct responsibility: Societal misuse defense should be operated as a domain-specific resist-absorb-recover-adapt network with shared incident identity, lawful minimal telemetry, harmed-party routes, cross-organization escalation, defensive service levels, evidence-preserving response, correction, and residual ownership; prevention metrics alone establish neither resilience nor acceptable harm.
    societal-resilience-and-misuse-defense.core · Design rationale at argument support
6 · Stable Capability Fields and replacement · stable-capability-fields.core

Stable Capability Fields

Plain-language thesis: A capability can remain understandable while its machinery changes if the contract stays stable and every replacement must earn qualification for itself.

Engineering rule: Version capability identity separately from implementation identity and require matched qualification, regression, migration, rollback, and retirement records for every replacement.

Machine contract: Promote a replacement only when its artifact identity, contract version, qualification envelope, regressions, authority ceiling, migration, rollback, and residuals validate; predecessor readiness does not transfer automatically.

Question: How can a capability retain a stable contract while its model, memory, router, tool, or substrate changes?

Running example: Replace the patch verifier while preserving the exact capability contract, regression envelope, authority ceiling, and recovery route.

Specialist reference owners (1)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Capability Replacement and Rollback
    Distinct responsibility: Capability replacement should be a prospectively authorized, phase-gated transaction over a declared Stable Capability Field, not a component swap. The transaction binds the exact prior and candidate artifacts and dependencies; field and consumer scope; change class; pre-state, checkpoint authority, state and effect inventory; qualification, regression, adversarial and transfer evidence; authority and approval; evaluator dependencies; isolation and canary exposure; monitor policy, delay and triggers; commit point; rollback, reverse-migration or compensation procedure; affected descendants and external commitments; residual owners; and terminal receipt. Default promotion is permitted only inside the evidenced scope after its declared gates pass and its recovery path is rehearsed to the stated objective. The record cannot make irreversible effects reversible, prove semantic recovery, validate its own monitor or evaluator, grant authority, establish useful improvement, or generalize inventory-exact local restoration to production.
    capability-replacement-and-rollback.core · Design rationale at argument support
7 · Intent and command contracts · intent-to-execution-contracts.core

Command Contracts: From Intent to Executable Work

Plain-language thesis: Human intent becomes safer executable work when ambiguity, scope, success, authority, evidence duties, and stop conditions are made explicit before action.

Engineering rule: Compile requests into revisable command contracts that preserve uncertainty and require clarification, narrowing, escalation, or refusal when consequential fields are unresolved.

Machine contract: Dispatch work only when principal, purpose, targets, allowed operations, success criteria, evidence duties, authority, risks, stop rules, and expiry are bound; inferred intent does not invent permission.

Question: How does an ambiguous human request become bounded work without inventing authority, success criteria, or certainty?

Running example: Translate a repository chapter-improvement request into target files, allowed operations, evidence duties, stop rules, and approval conditions.

Specialist reference owners (1)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Human Intent as a Formal Input
    Distinct responsibility: A governed stack admits human intent only as a versioned interpretation contract that preserves the raw request while separately recording the desired outcome; allowed and forbidden means; authority basis, ceiling, and affected parties; source, privacy, and publication boundaries; acceptance and evidence requirements; field provenance; confirmed assumptions, bounded defaults, contested or open ambiguities; stop, expiry, revocation, appeal, and re-contract conditions; and permitted downstream consumers. The accepted contract may bound planning only after its owning policy and authority gates admit it; it cannot by itself prove the person's complete preference, value alignment, informed consent, satisfaction, affected-party authorization, or permission for training, publication, deployment, spending, tool use, or other external effects.
    human-intent-as-a-formal-input.core · Design rationale at argument support
8 · Planning as a control layer · planning-as-a-control-layer.core

Planning as a Control Layer: DAGs and Intelligence Arbitrage

Plain-language thesis: Plans should coordinate dependencies and alternatives without becoming stale scripts or silently granting permission to act.

Engineering rule: Represent plans as versioned proposals with assumptions, dependencies, branch conditions, verification points, replanning triggers, cost, and explicit execution handoffs.

Machine contract: Advance a plan node only when dependencies, context epoch, assumptions, budget, verification state, and a separate live execution grant hold; plan reachability does not authorize an external effect.

Question: How can a plan coordinate dependencies and replanning while remaining a proposal rather than implicit execution authority?

Running example: Represent the repository change as source inspection, drafting, verification, tests, rollback preparation, and release or refusal.

Specialist reference owners: none; this representative is the unit’s sole canonical owner.

9 · Perception, governed world models, and embodied reconciliation · governed-world-models-and-reality-grounding.core

Governed World Models and Reality Grounding

Plain-language thesis: Predictions and simulations become useful when the system keeps them separate from observations and learns from the mismatch through controlled interventions.

Engineering rule: Track possible worlds, causal assumptions, interventions, sensor provenance, uncertainty, actual observations, reconciliation, and downstream belief effects as distinct artifacts.

Machine contract: Update a world-state belief only from an identity-bound observation and accepted reconciliation against a declared prediction or intervention; neither simulated success nor a sensor receipt establishes actual state and either alone does not justify the update.

Question: How should a system predict, simulate, intervene, and reconcile without confusing possible worlds with actual state?

Running example: Predict the patch's effects in a branch, run a bounded intervention, and reconcile the prediction with the observed tree.

Specialist reference owners (2)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Perception, Sensor Fusion, and Observation Trust
    Distinct responsibility: A consequential observation requires a versioned contract binding task need, sensor and modality identity, calibration, pose, clocks, provenance, coverage, missingness, per-channel hypotheses, alignment, fusion, dependence, disagreement, shift, active observation, freshness, authority, cost, and residuals.
    perception-sensor-fusion-and-observation-trust.core · Design rationale at argument support
  • Embodied Agency, Real-Time Control, and Physical Safety
    Distinct responsibility: Physical execution requires a plant-specific control lease binding embodiment, workspace, state estimator, dynamics, timing, force/space/contact limits, human presence, advanced/baseline/stop controllers, switching and interlocks, exploration, degraded modes, observed effects, compensation, irreversible residuals, costs, and expiry.
    embodied-agency-real-time-control-and-physical-safety.core · Design rationale at argument support
10 · Cognitive compilation, relational cognition, and search · cognitive-compilation-and-semantic-ir.core

Cognitive Compilation and Semantic IR

Plain-language thesis: Intent and knowledge can be lowered into efficient executable forms only if semantic loss, relational structure, assumptions, and rescue paths remain visible.

Engineering rule: Compile through typed intermediate representations that bind source meaning to target operations, record losses and approximations, and retain fallback to a higher-fidelity form.

Machine contract: Accept a compiled artifact only when source identity, target identity, preserved obligations, declared losses, validation, fallback, and consumer scope hold; structural conformance does not establish semantic equivalence.

Question: How can intent, beliefs, relations, and constraints be lowered into executable forms without silently changing meaning?

Running example: Lower the repository-change contract into planner predicates, verifier queries, tool calls, and recovery obligations with traceable losses.

Specialist reference owners (2)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Relational Dimension Compilation and Polyadic Cognition
    Distinct responsibility: Polyadic cognition should be implemented as a slow-path relational-dimension compiler over stable lower-arity primitives: candidate higher-order structure is typed, role-addressable, denominator-complete, qualified against strong pairwise and sequence baselines, budgeted, reversible, and retained only when it improves held-out relational performance without violating memory, latency, calibration, or governance constraints.
    relational-dimension-compilation-and-polyadic-cognition.core · Design rationale at argument support
  • Mathematical and Search Substrates
    Distinct responsibility: Mathematical and Search Substrates owns a consumer-, use-, workload-, claim-axis-, implementation-, baseline-, resource-, and time-specific Substrate Adoption Lease: an unusual calculus, representation, recurrence, search procedure, latent world model, or sequence backbone may affect only the axes and consumers that pass matched ordinary and current baselines, negative controls, complete cost and rights accounting, falsification, fallback, independent reproduction, and transfer; structural elegance, a theorem, a source-reported benchmark, synthetic fixture validity, or one favorable axis alone confers no general quality, efficiency, safety, support, deployment, or SOTA authority.
    mathematical-and-search-substrates.core · Design rationale at argument support
11 · Virtual Context ABI and context transactions · virtual-context-abi.core

The Virtual Context ABI: Typed Pages, Cells, and Certificates

Plain-language thesis: Large context becomes manageable when retrieved, cached, paged, mounted, and summarized material carries identity, provenance, freshness, taint, rights, and omissions.

Engineering rule: Expose context through a typed ABI that separates storage from belief and authority while supporting snapshots, transactions, revocation, deletion, and adequacy checks.

Machine contract: Mount a context object only when source, version, purpose, rights, freshness, taint, omissions, derivation, consumer, and revocation state validate; presence in context does not make content true or authorized.

Question: What interface lets models consume paged, cached, mounted, and tainted context without treating it as belief or authority?

Running example: Mount repository source files, policy history, summaries, and cached work as versioned context pages with explicit omissions and rights.

Specialist reference owners (1)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Context Transactions, Snapshots, Mounts, and Taint
    Distinct responsibility: Context Transactions should own the dynamic, versioned state-transition contract for durable context memory. Each accepted transaction binds principal, consumer, purpose, operation, base snapshot, branch, mounts, actual read/write/derive/delete/revoke sets, isolation and conflict policy, authority and rights, taint and declassification, durability and recovery model, budget, horizon, and support ceiling to an observed pre-state and a causally ordered attempted, applied, durable, visible, replayed, or recovered post-state. Commit, branch, merge, abort, retry, compaction, deletion, revocation, and recovery must preserve exact identities, obligations, faults, costs, and residuals. The transaction layer may change durable context state, but it does not own static packet materialization, semantic truth, belief revision, model/optimizer state, external effects, artifact correctness, verification adequacy, support, or release.
    context-transactions-snapshots-mounts-and-taint.core · Design rationale at argument support
12 · Durable memory and procedural consolidation · durable-semantic-memory-and-knowledge-lattices.core

Durable Semantic Memory and Knowledge Lattices

Plain-language thesis: Experience should become durable belief or reusable skill only through revisable consolidation that preserves provenance, uncertainty, regressions, and retirement.

Engineering rule: Separate episodic observations, semantic beliefs, and procedural skills; qualify every promotion with contradiction checks, expiry, descendants, forgetting, and rollback or compensation.

Machine contract: Consolidate memory only when source episodes, belief or skill identity, evidence, confidence, conflicts, consumers, expiry, regression tests, and deletion lineage validate; repeated success does not make a trace universally correct.

Question: How do qualified observations become durable beliefs and successful traces become revisable procedures rather than frozen mistakes?

Running example: Store the patch rationale as a defeasible belief and compile the validated workflow into a skill with regressions and retirement.

Specialist reference owners (1)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Procedural Memory and Cognitive Loop Closure
    Distinct responsibility: Cognitive loop closure compiles repeated reasoning into verified parameterized tools and procedural memory.
    procedural-memory-and-cognitive-loop-closure.core · Design rationale at argument support
13 · Verification bandwidth and context adequacy · verification-bandwidth-and-context-adequacy.core

Verification Bandwidth and Context Adequacy

Plain-language thesis: Verification fails when a reviewer lacks the information, independence, tools, time, or comparison capacity needed to detect the important contradiction.

Engineering rule: Allocate verification according to claim risk and record source coverage, omissions, independence, sensitivity, disagreement, escalation, latency, and reviewer burden.

Machine contract: Accept a verification result only when the frozen claim, context-adequacy floor, evaluator independence, tools, sensitivity controls, budget, and disagreement route hold; reviewer confidence does not establish adequate verification.

Question: When does relevant context still fail to provide enough independent comparison capacity for a risky judgment?

Running example: The verifier sees the patch and tests but lacks the policy history explaining why a removed check exists.

Specialist reference owners: none; this representative is the unit’s sole canonical owner.

14 · Claim ledgers, proof-carrying review, and formal scope · claim-ledgers-and-belief-revision.core

Claim Ledgers and Belief Revision

Plain-language thesis: Claims stay corrigible when evidence, proofs, observations, objections, revisions, consumers, and maximum inference remain connected over time.

Engineering rule: Maintain identity-bound claim ledgers that preserve defeaters and disagreements, distinguish proof from runtime observation, and propagate corrections or downgrades to every known consumer.

Machine contract: Accept a claim state only when identity, proposition, assumptions, evidence, evaluator, proof scope, observations, defeaters, decision, consumers, and downgrade triggers agree; formal validity does not establish runtime truth.

Question: How should claims, defeaters, proof receipts, observations, disagreements, and revisions remain connected over time?

Running example: Bind the patch claim to sources, tests, verifier objections, effect observations, maximum inference, and downgrade triggers.

Specialist reference owners (4)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Proof-Carrying Claims and Adversarial Review
    Distinct responsibility: Selected claims and artifacts should move through proof-carrying, justification-carrying, or adversarial-review envelopes that record tier, interpretation mapping, evidence dossier, verifier or tribunal result, dissent, limitations, failed attempts, required actions, residuals, and ledger effects.
    spinoza-verification-and-proof-carrying-claims.core · Design rationale at argument support
  • Circle Calculus and Proof-Carrying AI Contracts
    Distinct responsibility: Circle Calculus and Proof-Carrying AI Contracts owns a theorem-, model-, artifact-, implementation-, consumer-, claim-, version-, and time-specific Proof Contract Transport Envelope: a finite formal fact may travel only with resolvable proof identity, exact assumptions and semantics, source and toolchain provenance, content fingerprints, deterministic recomputation or replay, least-authority consumer gates, expiry and revocation, and preserved non-claims; theorem validity, receipt readiness, archive integrity, or transport success alone confers no model-quality, runtime, memory, safety, deployment, transfer, support, or SOTA authority.
    circle-calculus-and-proof-carrying-ai-contracts.core · Design rationale at argument support
  • Executable Specifications and Lean Proof Envelope
    Distinct responsibility: Executable Specifications and Lean Proof Envelope owns a proposition-, predicate-, abstraction-, artifact-, verifier-, consumer-, implementation-, version-, environment-, and time-specific Formal Artifact Authority Lease: a schema, executable model, Lean theorem, model-checking result, runtime monitor, behavior test, benchmark, or external theorem may authorize only the exact consumer statement whose operational semantics, abstraction map and losses, assumptions, dependency closure, verifier result, semantic adequacy, implementation binding, limitations, non-claims, expiry, and revocation path are recorded; artifact existence, field presence, a finite route, proof depth, a green build, a passing fixture, or an external theorem identity alone confers no deployed enforcement, empirical truth, system safety, source correctness, support promotion, transfer, or SOTA authority.
    executable-specifications-and-lean-proof-envelope.core · Design rationale at argument support
  • White-Box Evidence, Interpretability, and Activation Governance
    Distinct responsibility: Internal-state observations should enter governance only as typed evidence artifacts with lineage, method assumptions, replication status, causal interventions, stability checks, coverage limits, and explicit non-authority; white-box evidence complements but does not replace behavioral and operational evidence.
    white-box-evidence-interpretability-and-activation-governance.core · Design rationale at argument support
15 · Labor OS, organizations, artifact graphs, and stewardship · labor-os-and-typed-jobs.core

Labor OS and Typed Jobs

Plain-language thesis: Humans, agents, and tools can collaborate reliably when work, artifacts, authority, acknowledgements, dependencies, and accountability remain explicit.

Engineering rule: Issue typed jobs with exact owners, inputs, outputs, authority, evidence obligations, dependencies, handoffs, failure states, cost, and terminal acknowledgement.

Machine contract: Close a job only when its identity, assignee, authority, inputs, artifact outputs, checks, effects, handoffs, residuals, and accountable owner reconcile; a worker success report does not establish task completion.

Question: How should humans, agents, tools, and artifact stewards coordinate work without losing ownership, lineage, or accountability?

Running example: Issue typed jobs for drafting, checking, applying, observing, and recovering the repository change and join every artifact.

Specialist reference owners (8)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • From Chat to Organizations: AI Work Surfaces and Agent Harnesses
    Distinct responsibility: Every expansion of an AI work surface should be governed as a versioned abstraction-absorption transition that binds capability, context, state, tools, authority, effects, verification, human control, accountability, and residuals before project-, role-, team-, or organization-scale autonomy is accepted.
    ai-work-surfaces-agent-harnesses-and-organizational-absorption.core · Design rationale at argument support
  • Human-AI Organizations, Delegation, and Accountability
    Distinct responsibility: Consequential delegation requires a versioned organizational contract binding charter, affected parties, actors, roles, competence, workload, accessibility, information and decision rights, delegation, separation of duties, conflicts, incentives, benefits, escalation, appeal, remedy, contribution, dependence, accountability, succession, dissolution, and residual custody.
    human-ai-organizations-delegation-and-accountability.core · Design rationale at argument support
  • Human-AI Symbiosis, Neurotechnology, and Cognitive Sovereignty
    Distinct responsibility: Human-AI symbiosis should be evaluated as a reversible coupled-control intervention: the combined system must beat human-alone and AI-alone baselines on declared outcomes while preserving informed consent, mental integrity, cognitive agency, neural-data purpose limits, skill and exit capacity, equitable access, clinical boundaries, and longitudinal monitoring.
    human-ai-symbiosis-neurotechnology-and-cognitive-sovereignty.core · Design rationale at argument support
  • AI Deployment, Transition, Distribution, and Human Agency
    Distinct responsibility: Consequential deployment should advance only through a prospective transition contract that binds a counterfactual baseline, affected-person denominator, task-role-skill changes, adoption, substitution and complementarity, compensation and ownership, access and prices, concentration, critical-service continuity, human decision rights, training and redeployment, delayed outcomes, remedy, pause conditions, and residuals; exposure, productivity, adoption, or aggregate gain alone establishes neither job loss, welfare, fairness, human agency, nor a successful transition.
    ai-deployment-transition-distribution-and-human-agency.core · Design rationale at argument support
  • Artifact Graphs, Audit Logs, and Replay
    Distinct responsibility: Execution should produce an artifact graph with audit logs, provenance, replay metadata, and links to claims and tests.
    artifact-graphs-audit-logs-and-replay.core · Design rationale at argument support
  • Inter-Stack Protocols, Identity, and Economic Exchange
    Distinct responsibility: A governed stack routes each cross-stack request through a versioned exchange contract that binds protocol and schema version, sender and receiver identities, endpoint and capability declaration, requested task or artifact, principal and delegated authority, credential verification, audience, scope, expiry, budget or consideration, expected receipt, dispute and revocation paths, and residual owner; an absent, mismatched, expired, revoked, unverified, or budget-unreserved required record blocks dispatch or routes accountable review, but does not itself establish peer trustworthiness, task or artifact truth, effect safety, payment settlement, legal validity, economic fairness, privacy, authorization correctness, or ASI.
    inter-stack-protocols-identity-and-economic-exchange.core · Design rationale at argument support
  • Multi-Agent Dynamics, Collective Intelligence, and Systemic Risk
    Distinct responsibility: Expanded multi-agent interaction requires a population contract binding agent/owner/model/organization identities, human participants, interaction and dependency graphs, incentives, information, resources, commitments, decision assumptions, entry/exit/copying/learning, population outcomes, externalities, human influence, interventions, costs, and residuals.
    multi-agent-dynamics-collective-intelligence-and-systemic-risk.core · Design rationale at argument support
  • Artifact Steward Agents and Living Project Governance
    Distinct responsibility: Artifact Steward Agents and Living Project Governance owns a project-, artifact-, mission-, owner-, authority-, roadmap-, work-contract-, event-, treasury-, compute-, contributor-, evidence-, governance-, release-, federation-, sunset-, consumer-, environment-, and time-specific Artifact Steward Continuity Lease: it may observe, propose, prepare, coordinate, execute, reverse, archive, or retire only through a versioned charter, taint-aware intake, scoped work contracts, separated contribution ledgers, bounded treasury and compute policy, verification and release gates, appeal and fork or exit paths, effect-complete rollback, and explicit sunset authority; it never acquires ownership, governance legitimacy, evidence authority, funding rights, release authority, legal standing, or permission from useful motion, a green workflow, a vote, a balance, a score, a fixture, a theorem, or its own prior action.
    artifact-steward-agents-and-living-project-governance.core · Design rationale at argument support
16 · Runtime adapters, observation, incident command, and operations · runtime-adapters-tool-permissions-and-human-approval.core

Runtime Adapters, Tool Permissions, and Human Approval

Plain-language thesis: The crucial runtime boundary is where approved proposals become observable external effects and remain recoverable under failure or changing authority.

Engineering rule: Mediate tools through least-privilege adapters that bind approval to exact effect scope, observe actual state, revoke promptly, degrade safely, and preserve incident and recovery records.

Machine contract: Execute a tool call only with live scoped approval, adapter policy, pre-state, expected effect, observer, timeout, revocation, and rollback or compensation route; tool success does not establish intended task success.

Question: Which boundary should turn proposals into observed effects while preserving approval, incident, recovery, and graceful-degradation paths?

Running example: Apply the verified patch under a live grant, observe pre and post state, and retain exact rollback or compensation.

Specialist reference owners (1)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Governed Operations, Incident Command, and Graceful Degradation
    Distinct responsibility: Governed operation is a closed incident lifecycle that binds detection, classification, command authority, containment, effect-complete rollback, graceful degradation, recovery evidence, and learning to the exact deployed system and its dependency graph.
    governed-operations-incident-command-and-graceful-degradation.core · Design rationale at argument support
17 · Routing and replaceable cognitive substrates · replaceable-cognitive-substrates-beyond-transformer-monoculture.core

Replaceable Cognitive Substrates: Beyond Transformer Monoculture

Plain-language thesis: Transformers should be one replaceable substrate among many, selected according to the work rather than treated as the permanent shape of intelligence.

Engineering rule: Qualify heterogeneous models, recurrence, state-space systems, symbolic methods, search, tools, and future substrates behind stable capability contracts using matched task and lifecycle comparisons.

Machine contract: Route to a substrate only when capability contract, task fit, qualification envelope, authority, resource budget, fallback, regression, and migration state hold; novelty or benchmark speed does not inherit readiness.

Question: How can routers choose among transformers, state-space models, recurrence, symbolic methods, tools, and future substrates?

Running example: Route patch generation, retrieval, verification, and rollback checks to different qualified substrates behind stable capability fields.

Specialist reference owners (3)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Routing Heads and Specialist Cores
    Distinct responsibility: ASI scales through a lightweight routing head that selects bounded specialist cores with local tools, memory, and authority.
    routing-heads-and-specialist-cores.core · Design rationale at argument support
  • Coil Attention, Cyclic Memory, and Recurrence Contracts
    Distinct responsibility: Coil Attention, Cyclic Memory, and Recurrence Contracts owns a memory-object-, state-version-, request-, consumer-, workload-, structural-axis-, budget-, and time-specific State-Carry and Recurrence Admission Lease: a slot read, cyclic address, KV reuse, sparse edge, fanout schedule, or recurrent step may be admitted only when authority, provenance, residue and winding, freshness, coverage, alias and collision state, active work, progress, exit, fallback, expiry, and residuals satisfy the exact consumer contract; structural validity, synthetic fixtures, receipt replay, cache presence, or reduced scheduled work alone confers no retrieval, reasoning, context-length, quality, speed, memory, safety, deployment, transfer, support, or SOTA authority.
    coil-attention-cyclic-memory-and-recurrence-contracts.core · Design rationale at argument support
  • CoilRA, MultiCoil RoPE, and Cyclic Mixers
    Distinct responsibility: CoilRA, MultiCoil RoPE, and Cyclic Mixers owns a model-, layer-, mechanism-version-, workload-, baseline-, kernel-, hardware-, claim-axis-, and time-specific Cyclic Mechanism Tradeoff Packet: a cyclic adapter, phase bank, rotary scheme, route head, circulant operator, or block-cyclic mixer may enter a canary only when exact residue/winding, phase horizon, alias/collision/load, dense-reference parity, parameter and operation accounting, numerical error, kernel availability, complete cost, quality, failure, fallback, and rights evidence is matched against strong ordinary controls; equivariance, finite proofs, receipt validity, parameter reduction, or structural parity alone confers no quality, context-length, speed, memory, stability, efficiency, safety, deployment, transfer, support, or SOTA authority.
    coilra-multicoil-rope-and-cyclic-mixers.core · Design rationale at argument support
18 · Governed training and developmental learning · governed-model-training-distributed-optimization-and-scaling.core

Governed Model Training, Distributed Optimization, and Scaling

Plain-language thesis: Intelligence develops through a lifecycle of interaction, prediction error, abstraction, memory, practice, stabilization, and qualification—not merely by shuffling weights.

Engineering rule: Join curriculum, training state, interventions, consolidation, proceduralization, forgetting, regression, stability, cost, and independent qualification without collapsing their owners.

Machine contract: Promote a learned capability only when full run identity and state, causal or intervention evidence, memory and skill lineage, regressions, stability epoch, cost, and unopened qualification hold; checkpoint load or score does not establish development.

Question: How does the stack develop capability through training, interaction, intervention, memory, procedure, stabilization, and promotion?

Running example: Follow one repository-task candidate from frozen curriculum and full training state through learning, consolidation, regression, and qualification handoff.

Specialist reference owners (6)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Learning–Compute Topology and Adaptive Process Architecture
    Distinct responsibility: For an exact task family, adaptive-state boundary, resolution contract, evidence and evaluator policy, credit semantics, lifecycle, integration operators, compute substrate, resource budget, authority, observables, rollback, and time, a self-improving stack should represent the learning process as a typed, versioned, provenance-bearing, rewritable causal topology; compile it through an explicit semantic firewall into execution and physical compute; measure discovery, evaluation, integration, communication, retention, and realization leakage jointly; and admit topology changes only through matched experiments and reversible governance. A branch count, worker count, schedule, normalized graph, bounded theorem, passing reference implementation, toy phase diagram, or source-authored architecture alone establishes neither adaptive plurality, retained learning, safety, superiority, transfer, nor ASI.
    learning-compute-topology-and-adaptive-process-architecture.core · Design rationale at argument support
  • Learning Theory, Generalization, and Scaling Science
    Distinct responsibility: A generalization, transfer, emergence, or scaling assertion should be accepted only through a dated claim contract that binds population and sampling assumptions, data support, hypothesis and algorithm, optimization and inductive bias, complexity or explanatory lens, metric, compute regime, uncertainty, breakpoint tests, held-out prediction, alternatives, and transfer boundary; a bound, fit, interpolation result, compression ratio, benchmark jump, or larger model alone establishes neither broad generalization, capability emergence, safety, nor future scale behavior.
    learning-theory-generalization-and-scaling-science.core · Design rationale at argument support
  • Adjudicated Persistence and the Adaptive Commit Boundary
    Distinct responsibility: Every transition from experience to durable causal influence should cross an Adaptive Commit Boundary as an authority-bearing adaptation transaction that keeps the experience record, lesson hypothesis, persistence disposition, concrete realization, qualification lease, and authority grant distinct; selects the least-commitment admissible locus portfolio under evidence, authority, observability, recovery, cost, and descendant obligations; and preserves denial, uncertainty, deoptimization, invalidation, and revocation paths.
    adjudicated-persistence-and-the-adaptive-commit-boundary.core · Design rationale at argument support
  • Policy Optimization and Learning from Feedback
    Distinct responsibility: Policy Optimization and Learning from Feedback owns a target-policy-, baseline-, objective-, feedback-, evaluator-, dataset-, optimizer-, checkpoint-, rollout-, authority-, resource-, monitor-, rollback-, consumer-, environment-, and time-specific Governed Policy Update Lease: before any update, it freezes the legitimate target behavior, admissible feedback and proxy boundary, strong baselines, update family and budget, drift and authority ceilings, complete evaluation and failure denominators, reward-hacking and causal checks, rollback and monitoring, residuals, expiry, and promotion authority; a reward, preference, verifier score, benchmark gain, loss reduction, synthetic canary, formal route, rollback dry run, or trained checkpoint alone establishes neither reward validity, causal policy improvement, retained capability, alignment, safety, readiness, deployment, support, transfer, nor SOTA.
    policy-optimization-and-learning-from-feedback.core · Design rationale at argument support
  • Data Engines, Continual Learning, and Unlearning
    Distinct responsibility: Data Engines, Continual Learning, and Unlearning owns a datum-, cohort-, provenance-, rights-, split-, contamination-, learning-lane-, retention-, checkpoint-authority-, full-state-inventory-, descendant-, deletion-request-, claim-axis-, consumer-, environment-, and time-specific Data-and-Descendant Custody Lease: before learning or deletion, it binds admissible use, evaluation exclusions, synthetic and transformation lineage, coverage and distribution residuals, model/optimizer/scheduler/RNG/cache/backup/descendant state, prospective checkpoint authority, retention and replay, deletion propagation, verification, rollback, expiry, and terminal custody; behavioral cohort change, causal influence reduction, privacy leakage reduction, lineage invalidation, legal compliance, and storage or backup erasure remain separate claims, and no receipt, checksum, exclusion, invalidation, benchmark score, rollback match, or synthetic campaign alone establishes model quality, forgetting, privacy, erasure, safety, readiness, deployment, support, transfer, or SOTA.
    data-engines-continual-learning-and-unlearning.core · Design rationale at argument support
  • Scientific Discovery and Experimental Governance
    Distinct responsibility: An AI-generated scientific claim should enter the evidence stack only through a preregistered experimental contract that binds hypothesis lineage, exploratory versus confirmatory status, design and power, instrument or simulator authority, calibration, sample and protocol lineage, blinding and holdouts, stopping and exclusions, analysis, complete attempts, independent replication, dual-use disposition, and claim ceiling; experimental completion, significance, synthesis, instrument output, or formal workflow validity alone establishes neither causal truth, general scientific discovery, reproducibility, safety, nor transfer.
    scientific-discovery-and-experimental-governance.core · Design rationale at argument support
19 · Readiness, benchmarks, safety cases, and bounded liveness · readiness-gates-residual-escrow-and-quarantine.core

Readiness Gates, Residual Escrow, and Quarantine

Plain-language thesis: Readiness means useful work can proceed within declared risk while failures, uncertainty, residuals, and quarantine all reach finite owned outcomes.

Engineering rule: Join competence, adversarial evaluation, safety cases, deployment commitments, release boundaries, residual escrow, and bounded liveness with usefulness and governance cost.

Machine contract: Advance readiness only when competence, attacks, evaluator sensitivity, residual owners, threshold commitments, rollback, liveness, false-blocking, and cost gates pass; benchmark success does not authorize deployment or release.

Question: How should benchmarks, safety cases, adversarial evaluation, residuals, and bounded liveness determine readiness?

Running example: Qualify the changed repository verifier against positive controls, attacks, transfer, recovery, false blocks, and a finite quarantine route.

Specialist reference owners (6)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Open-Weight Release and Post-Release Control
    Distinct responsibility: An open-weight release should require a prospective irreversible-release case that binds the exact artifact and license to accessible-frontier comparison, malicious-fine-tuning and scaffolded elicitation, marginal and cumulative risk, benefit and access distribution, downstream safeguard portability, derivative lineage, incident channels, post-release measurement, and residual ownership; after release, governance may inform, patch, coordinate, and support safer derivatives, but it must not claim revocation authority it no longer possesses.
    open-weight-release-and-post-release-control.core · Design rationale at argument support
  • Benchmark Ratchets and Anti-Goodhart Evidence
    Distinct responsibility: Benchmark Ratchets and Anti-Goodhart Evidence owns a construct-, task-, dataset-, metric-, harness-, model-, checkpoint-, output-, evaluator-, baseline-, retry-lineage-, budget-, environment-, claim-axis-, and time-specific Benchmark Instrument Lease: a score or evaluation event may update only the exact claim whose construct validity, target capacity, data and metric provenance, output binding, contamination and public-calibration boundary, strong baselines and negative controls, complete selection and failure lineage, regression floors, frontier state, uncertainty, costs, causal checks, transfer, residuals, and decision authority survive review; a green fixture, synthetic probe, source-reported result, leaderboard gain, held-out score, saturation label, or archived winner alone confers no capability, safety, readiness, deployment, unlearning, support, transfer, or SOTA authority.
    benchmark-ratchets-and-anti-goodhart-evidence.core · Design rationale at argument support
  • Capability Thresholds and Deployment Commitments
    Distinct responsibility: Capability Thresholds and Deployment Commitments owns a domain-, threat-, assessment-, policy-version-, safeguard-package-, release-path-, authority-, exception-, residual-, and time-specific Capability-to-Deployment Commitment: before outcomes are visible, it binds a scoped crossing, non-crossing, incomparable, or stale assessment to predeclared safeguards, verification criteria, deadlines, access and monitoring constraints, re-evaluation, exceptions, residual custody, rollback, disclosure, and release-path consequences; a score, time-horizon estimate, threshold label, crossing, non-crossing, safeguard record, exception, or green readiness handoff alone confers no general capability, safeguard efficacy, safety, readiness, deployment, support, transfer, or SOTA authority.
    capability-thresholds-and-deployment-commitments.core · Design rationale at argument support
  • Adversarial Evaluation, Sandbagging, and Training-Time Deception
    Distinct responsibility: Adversarial Evaluation, Sandbagging, and Training-Time Deception owns a consumer-, decision-, model-, task-, elicitation-, authority-, monitor-, reward-, selection-, evaluator-, hypothesis-, outcome-, lineage-, and time-specific Evaluation Observation Integrity Packet: before outcomes are inspected, it freezes the permitted inference and comparison design, binds every observable and dependency, separates task outcome from behavioral interpretation, preserves discrepancies, alternatives, failures, costs, mitigation descendants, expiry, and downstream invalidation, and routes only a bounded observation-integrity status to existing evidence and decision owners; no score, trace, discrepancy, detector, mitigation, adversarial pass, quarantine, or complete finite packet alone establishes capability, intent, deception, sandbagging prevalence or resistance, reward fidelity, monitor validity, alignment, safety, readiness, deployment, support, transfer, or SOTA.
    adversarial-evaluation-sandbagging-and-training-time-deception.core · Design rationale at argument support
  • Safety Cases and Structured Assurance
    Distinct responsibility: Safety Cases and Structured Assurance owns a deployment-context-, hazard-, claim-, strategy-, evidence-, assumption-, defeater-, safeguard-, threshold-, readiness-, authority-, release-path-, residual-, version-, and time-specific Assurance Argument Compilation Packet: it compiles exact governed references and bounded support or challenge relations, preserves alternatives, dissent, staleness, countercases, conflicts, overrides, costs, lineage, and downstream invalidation, and routes only a scoped case status to existing decision owners; a connected, rendered, notation-conformant, reviewed, accepted, or synthetically complete case alone establishes neither hazard completeness, evidence adequacy, argument validity, reviewer independence, control effectiveness, risk, safety, readiness, release authority, deployment, support, transfer, nor SOTA.
    safety-cases-and-structured-assurance.core · Design rationale at argument support
  • Content Authenticity, Watermarking, and Synthetic Media Integrity
    Distinct responsibility: Synthetic-media integrity should use a layered authenticity envelope that binds asset identity, generator and editor claims, signed provenance, content bindings, watermark or fingerprint signals, detector outputs, visible disclosure, transformation history, trust policy, uncertainty, and remedy; every signal retains its own semantics, and no missing or valid signal becomes a universal truth judgment.
    content-authenticity-watermarking-and-synthetic-media-integrity.core · Design rationale at argument support
20 · Resource economics, efficient inference, and effect-complete recovery · resource-economics-and-token-budgets.core

Resource Economics and Token Budgets

Plain-language thesis: Efficient intelligence must account for compute, memory, storage, energy, latency, human attention, verification, failure, and recovery on the same ledger.

Engineering rule: Allocate resources by risk-adjusted useful throughput while protecting required review and safety work and exposing displaced costs, cache effects, paging, fallback, and residual burden.

Machine contract: Select or defer work only from routes whose quality floor, protected overhead, resource envelope, verifier cost, recovery, and residual accounting validate; lower tokens, latency, or cache price does not establish lower lifecycle cost.

Question: When do routing and governance earn their compute, memory, storage, energy, latency, human, and recovery costs?

Running example: Compare repository-change routes on success, unsafe effects, false blocks, latency, reviewer effort, rollback, and lifecycle cost.

Specialist reference owners (6)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Personal Compute Hives and Federated Edge Intelligence
    Distinct responsibility: For an exact versioned principal, household or project, job, use, data and tool class, effect envelope, acceptance test, risk budget, deadline, and evaluation horizon, a Personal Compute Hive should admit and place work only through policy-before-optimization: independently attested participants and roles, intersected authority and rights, task-local context and execution leases, least-authority adequate node selection, scoped approval, monitored sandboxed execution, complete artifact/effect/resource receipts, partition-aware denial or quarantine, and effect-complete rollback or residual custody; reachability, ownership, cheap capacity, a passing record schema, or stale authority alone cannot license execution, and federation, dropout, revocation, replacement, requeue, and retirement must preserve affected descendants and residual owners.
    personal-compute-hives-and-federated-edge-intelligence.core · Design rationale at argument support
  • Compact Generative Systems: Generate, Verify, Repair, and Residual Honesty
    Distinct responsibility: For an exact versioned source artifact or state, consumer and use, reconstruction or semantic-adequacy contract, allowed loss, authority and rights envelope, workload distribution, cost boundary, and evaluation horizon, a compact representation should be admitted only when its generator, search, metadata, semantic lease, verifier, repair, fallback, interface, human, governance, recovery, and residual burdens are fully attributed; exactness or scoped loss is independently checked against the consumer contract; source lineage, supersession, and fallback remain executable; and the selected representation improves a preregistered joint utility-and-total-burden frontier over strong matched literal, standard codec, model-compression, retrieval, and semantic baselines. Smaller storage, tokens, parameters, or a finite fixture alone establishes neither useful compression nor semantic adequacy, and any hidden, moved, deferred, or discharged burden must retain state, evidence, owner, due condition, descendants, and reopening triggers.
    compact-generative-systems-and-residual-honesty.core · Design rationale at argument support
  • Fast Generation Architectures
    Distinct responsibility: Fast-generation admission is consumer-, workload-, model-, hardware-, serving-policy-, and time-window-specific: a controller may route an eligible request through a named accelerated path only after prospectively binding the context, quality, risk, budget, metric, verifier, fallback, rollback, and expiry contracts; separating attempted, proposed, accepted, verified, delivered, and useful output; fully attributing queueing, prefill, decode, verification, repair, retry, fallback, cache, memory, bandwidth, energy, human, and governance burdens; and showing a meaningful end-to-end improvement over matched quality-equivalent baselines without violating safety, authority, rights, or residual gates. Raw tokens per second, FLOP estimates, aggregate throughput, synthetic templates, or unverified speed lifts alone cannot qualify a route.
    fast-generation-architectures.core · Design rationale at argument support
  • Governed Deliberation and Test-Time Scaling
    Distinct responsibility: Governed deliberation is a consumer-, task-, risk-, model-, evaluator-, resource-, and time-specific inference lease: before outcomes, it chooses among direct generation, bounded revision, candidate search, or abstention; binds exact budgets, candidate/history custody, verifier scope and dependence, stop and escalation rules, initially-correct corruption and initially-incorrect repair metrics, downstream consumer, expiry, and residual owner; and admits only a bounded candidate to planning when matched natural and adversarial evidence shows useful gain after all branches, failures, verification, latency, compute, human, and governance costs. A trace, self-score, process reward, benchmark gain, or extra compute never establishes correctness, safety, capability, execution authority, or support movement by itself.
    governed-deliberation-and-test-time-scaling.core · Design rationale at argument support
  • RankFold, NeuralFold, and Artifact Compression
    Distinct responsibility: A compressed artifact may enter a downstream route only through an artifact-, consumer-, use-, access-pattern-, decoder-, platform-, and time-specific admission lease that preserves the full source, separates representation, reconstruction, ratio, utility, latency, and evidentiary-authority claims, counts every byte and operation, exercises probes and fallback, and expires or quarantines on drift; RankFold/NeuralFold remains a bounded candidate implementation, and no compact form inherits the source artifact's authority.
    rankfold-neuralfold-and-artifact-compression.core · Design rationale at argument support
  • Physical Compute Infrastructure, Energy, and Environmental Constraints
    Distinct responsibility: A compute allocation should be physically eligible only through a workload-to-capacity contract that binds location and time, hardware and interconnect, delivered useful work, facility and grid dependencies, energy attribution, cooling and water, materials, land and community effects, metering uncertainty, resilience and degradation, maintenance, demand response, reuse, retirement, and residuals; nameplate compute, efficiency, low PUE, renewable procurement, or aggregate energy alone establishes neither availability, sustainability, community acceptability, nor lower total impact.
    physical-compute-infrastructure-energy-and-environmental-constraints.core · Design rationale at argument support
21 · Recursive improvement, integrated architecture, and prototype program · integrated-reference-architecture.core

Integrated Reference Architecture

Plain-language thesis: The stack matters only if its local contracts compose into one useful, observable, recoverable trace that cannot silently expand authority or ratify its own improvement.

Engineering rule: Join identity, intent, context, plans, effects, observations, evidence, learning, replacement, incidents, rollback, residuals, and publication through the Governed Transition Calculus.

Machine contract: Accept an end-to-end transition only when every required owner supplies a compatible identity-bound state and the joined trace reaches effect, observation, recovery, or explicit residual closure; local component validity does not establish composition.

Question: Do recursive improvement and all local controls compose into one observable, recoverable, and non-self-ratifying trace?

Running example: Replay the complete governed repository change and its attacks through the ASI-THESEUS-FLAGSHIP-01 design.

Specialist reference owners (5)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Recursive Self-Improvement Boundaries
    Distinct responsibility: For a prospectively declared self-model, mutable state partition, authority envelope, consumer and use, and evaluation horizon, a system-generated change may enter a live capability field only through a separately authorized transition that binds exact change lineage, protected invariants, evaluator dependencies, full declared state, boundary deltas, matched evidence, staged exposure, outcome delay, rollback and compensation limits, descendant invalidation, and terminal residual ownership; the candidate may contribute proposals and evidence but cannot solely define, alter, judge, or authorize the conditions of its own promotion.
    recursive-self-improvement-boundaries.core · Design rationale at argument support
  • Open-Ended Improvement Engines
    Distinct responsibility: For a prospectively frozen consumer, purpose, legitimate objective, representation, campaign controller, task and candidate policy, evaluator and exposure policy, archive and hazard policy, resource and opportunity budget, stop authority, and evaluation horizon, open-ended improvement should operate as a bounded adaptive generation campaign in which every task, candidate, evaluation, failure, cost, reuse relation, and terminal outcome retains exact lineage; novelty, diversity, score, archive growth, transfer, self-verification, or search activity never grants authority or establishes useful improvement by itself; only separately qualified candidates may be handed to the existing self-improvement governor, and any change to the campaign's own objective, controller, evaluator authority, bounds, or admission interface is a separately authorized improvement proposal.
    open-ended-improvement-engines.core · Design rationale at argument support
  • Autonomous Replication, Proliferation, and Containment
    Distinct responsibility: Any replication-capable action should be denied by default and become testable only inside a synthetic containment contract that binds parent and descendant identity, authority noninheritance, resources, credentials, networks, copy lineage, persistence, adaptation, human assistance, shutdown and recall, proliferation bounds, residuals, and threshold commitments; component-task success or failure alone establishes neither end-to-end replication capability, containment, safety, nor permission to test real infrastructure.
    autonomous-replication-proliferation-and-containment.core · Design rationale at argument support
  • Project Theseus as Report-First Implementation Reference
    Distinct responsibility: Project Theseus as Report-First Implementation Reference owns a source-project-, pinned-revision-, report-family-, command-, environment-, artifact-, lineage-, evidence-state-, replay-, public-safety-, publication-permission-, reviewer-, consumer-, and time-specific Implementation-Reference Evidence Packet: it binds every imported or replayed report, configuration, ledger, work-board summary, registry, gate, crosswalk, trace, retained artifact, command, environment note, digest, missing artifact, decision, residual, and non-claim to source-note-only, imported, replay-ready, replay-failed, locally reproduced, stale, runtime-blocked, or archived lineage; dashboards and latest files are projections only, and no GREEN gate, complete registry, module card, pointer row, metadata snapshot, parity manifest, command replay, fixture, theorem, or sanitized import alone establishes current runtime truth, clean live replay, model quality, capability, benchmark validity, safety, deployment, support, transfer, AGI, ASI, or SOTA.
    project-theseus-as-report-first-implementation-reference.core · Design rationale at argument support
  • Prototype Roadmap
    Distinct responsibility: Prototype Roadmap owns a program-, roadmap-, phase-, dependency-, artifact-, acceptance-gate-, authority-, evaluator-, evidence-transition-, phase-debt-, residual-, rollback-, reviewer-, consumer-, environment-, and time-specific Evidence-Gated Phase Unlock Contract: it binds every proposed phase to prerequisites, allowed work state, required artifacts, commands, environment, resource bounds, gates, independent evaluation, residuals, debt, rollback, retirement, evidence effect, and non-claims before later work may research, demo, integrate, promote, or release; no roadmap row, milestone, source report, dashboard, task count, passing fixture, theorem, validator, build, or locally useful prototype alone establishes phase completion, safe dependency order, capability, governance effectiveness, deployment, transfer, AGI, ASI, or SOTA.
    prototype-roadmap.core · Design rationale at argument support
22 · Living Book methodology and open challenge agenda · living-book-methodology.core

Living Book Methodology

Plain-language thesis: A living technical book stays trustworthy when ideas, sources, claims, proofs, tests, corrections, products, releases, and open work remain synchronized without pretending that organization proves the thesis.

Engineering rule: Treat every substantive editorial or evidence change as a versioned transaction with canonical ownership, validation, support-state effects, public truth, residuals, and one successor.

Machine contract: Publish a derivative only when source commit, manifest, rights, claim states, validation, artifact digest, review state, deployment observation, corrections, and successor authority reconcile; a green build does not establish manuscript truth or evidence maturity.

Question: Can the research program keep its ideas, sources, claims, proofs, corrections, products, and releases mutually accountable?

Running example: Treat this repository's prose-first convergence as a governed change that preserves support ceilings and leaves proof execution for its explicit gate.

Specialist reference owners (1)

These chapters retain their own claims, sources, evidence ceilings, and implementation responsibilities.

  • Open Research Agenda and Bibliography Plan
    Distinct responsibility: Open Research Agenda and Bibliography Plan owns a research-program-, source-or-gap-, backlog-item-, access-, provenance-, public-safety-, chapter-boundary-, claim-, proof-or-experiment-, deduplication-, evidence-transition-, owner-, next-action-, closure-, consumer-, environment-, and time-specific Research Backlog Admission and Closure Contract: every new paper, local project, missing artifact, conflicting result, proof idea, experiment, reproduction need, correction, or chapter proposal enters through exact intake, triage, assignment, preconditions, blockers, non-claims, and terminal closure before it changes prose or support; no title, citation, source count, inventory row, source note, queue, priority label, backlog size, fixture, theorem, validator, or completed reading task alone establishes citation accuracy, literature completeness, research quality, claim support, reproduction, transfer, AGI, ASI, or SOTA.
    open-research-agenda-and-bibliography-plan.core · Design rationale at argument support

Reference routing

65 specialized chapters remain discoverable in the architecture reference; none was deleted or demoted.