Deterministic governance for independent, three-dimensional, self-constituting intelligence.
This paper defines the object the series governs. The full seven-level theory, from the switch to energy-bound terminal control, is stated in one paper: AI2-WP-2026-16, The Unified Control Theory of Synthetic Intelligence (Rev 8.0, September 25, 2026).
Contemporary artificial intelligence is built on a category error. It treats inference — a statistical operation over distributions — as if it were a decision, and treats the resulting model as if it could govern itself. A probabilistic system can propose. It cannot authorize. The gap between proposal and authorization is the Authorization Gap™, and it is not closed by better models, better prompts, or better policy. It is closed by architecture.
This paper specifies that architecture.
We define a Synthetic Intelligence (SI) not as a model, and not as a model plus a safety layer, but as a single, structurally unified object:
SI := ⟨ 𝒬₆₄³ , 𝓛_codex , Π_PCR , 𝒯_TARTARUS ⟩
where 𝒬₆₄³ is a three-dimensional quaternary spatial automaton substrate, 𝓛_codex is a total, bounded, canonical symbolic language, Π_PCR is a deterministic permission runtime, and 𝒯_TARTARUS is a hermetic environmental seal.
The SI is constituted by these elements, not wrapped in them.
Its law of motion is its own constitution. Its substrate physically cannot violate that constitution. Its instantaneous state space is finite; its trajectory space is infinite.
The framework is laid out in five core domains:
We state what is proved, what is conditionally proved, and what remains an engineering obligation. We delineate the IP lineage, outline the go-to-market strategy, and declare the explicit limits of the framework.
Series alignment. This paper adopts the state vocabulary fixed in AI2-WP-2026-10 (Rev. 4.4) and in the filed circuit of USPTO provisional 64/157,181: the quaternary chain is ⊥ (BOT) < IDLE < COND < ⊤ (TOP), and the energizing threshold is τ = ⊤. Earlier drafts of this series that used {⊥, 0, 1, ⊤} or {⊥, Q₀, Q₁, ⊤} are superseded by this vocabulary.
A model produces a proposal. An agent turns it into a tool call. A router decides where it goes. Nothing in that execution chain decides whether it goes. By the time a request reaches the router, the action is already assumed. Guardrails, policy filters, and alignment run inside the same host that runs the model. Whatever bypasses the model bypasses the guardrails.
This is not a tuning problem. It is a boundary problem. Deterministic governance imposes three non-negotiable architectural requirements:
Every element of the framework wires the safe direction to the loss of a condition:
Let Λ_t be the actuator latch at clock step t, p_t the payload presented at the point of consequence, a_t the object authorized for that step, and H a collision-resistant digest. The framework maintains one invariant:
∀ t : Effect_t ⇒ ( Λ_t = ⊤ ) ∧ ( H(p_t) = H(a_t) ) An irreversible external effect occurs at step t only if the latch is energized AND the delivered payload is the authorized payload.
This is not a policy statement. It is a structural property of the physical architecture: the effect path is electrically conditioned on both conjuncts, and neither conjunct can be asserted by the execution plane.
Let 𝓛₄ = {⊥, IDLE, COND, ⊤} be a totally ordered set with ⊥ < IDLE < COND < ⊤ and meet operation a ∧ b ≡ min(a, b).
A finite chain is a complete, bounded, distributive lattice. It is non-Boolean: IDLE and COND have no complements. There is no operation in the algebra that inverts a hold into a grant.
| Symbol | Role | Operational state | Exit |
|---|---|---|---|
⊥ (BOT) | Absorbing inhibit | Latched. deny_latched asserted. | Effective reset only — escalated principal, exogenous. |
IDLE | Unarmed hold | Active hold. Not latched. No authorization epoch open. | New arm edge — ordinary principal, exogenous. |
COND | Conditional hold | Evaluation pending, or predicted trajectory inside the margin band. Not latched. | Clears when evaluation completes above margin within an open epoch; a new epoch requires a new arm edge. |
⊤ (TOP) | Energized | Fully authorized. The only state in which the output driver is enabled. | Entered only through a physical arm input. τ = ⊤. |
Let 𝒱 be the set of evaluator nodes, each producing a valuation v(σ) ∈ 𝓛₄ over the horizon frame σ. The global aggregate is the meet across all nodes:
V(σ) = ⋀_{v ∈ 𝒱} v(σ) = min { v(σ) : v ∈ 𝒱 }
Λ_{t+1} = Λ_t ∧ V(σ_{t+1}) (autonomous update)
Λ_{t+1} = G(Λ_t) (exogenous principal event)
Each clock step applies exactly one of the two update rules, and fault evaluation precedes any grant. The autonomous rule is the only rule the execution plane can influence, and it is a meet.
Theorem 1 (Zero masking). If any node v_k ∈ 𝒱 evaluates to ⊥, then V(σ) = ⊥.
Proof. ⊥ is the least element of 𝓛₄, so min(⊥, …) = ⊥. ∎
Theorem 2 (Latched invariance under arbitrary state updates). Let R : Σ × U → Σ be any transition function generated by the execution plane, admissible or not, and let V be evaluated on the resulting frames. If Λ_t < τ, then for every sequence of autonomous updates,
Λ_{t+k} ≤ Λ_t < τ for all k ≥ 0.
Proof. Meet is non-increasing in each argument: a ∧ b ≤ a. Hence
Λ_{t+1} = Λ_t ∧ V(σ_{t+1}) ≤ Λ_t < τ, and by induction on k the bound
holds for every autonomous continuation regardless of R. The only
operator that can raise Λ is G, which the execution plane cannot
invoke. ∎
Corollary (Ratchet). Within an authorization epoch the latch is monotone non-increasing. Authority is consumed; it is never regenerated from inside.
Meet aggregation prioritizes safety over availability: the spurious-trip rate scales linearly with |𝒱|, since any single node's false ⊥ collapses the aggregate. This is a deliberate trade-off. It is mitigated — not removed — by fail-closed encoding, real-time diagnostics on every node, hysteresis at the quantizer, and periodic proof testing. A framework that hides this cost is not describing a meet.
The enforcement plane Π is implemented in fixed logic within a dedicated power domain separate from the execution plane Λ. The isolation is defined by six physical properties:
The physical state evolves within a three-dimensional continuous state space:
x(t) = ( z(t), v(t), a(t) ) ∈ ℝ³ z : position v : velocity a : acceleration
This continuous representation maps to spatial configurations on the discrete quaternary lattice through the horizon frame: the enforcement plane never integrates the plant; it evaluates a bounded projection of it.
The safe set 𝒮_ad is bounded by explicit kinematic limits and a conservative stopping-distance function d_stop(x):
𝒮_ad = { x : z_min ≤ z ≤ z_max ,
|v| ≤ v_max ,
|a| ≤ a_max ,
z + sgn(v)·d_stop(x) ∈ [ z_min , z_max ] }
d_stop(x) = v² / (2·a_brake) + |v|·t_lat + ½·a_max·t_lat²
a_brake : guaranteed braking authority t_lat : worst-case gate latency
d_stop is chosen conservatively: it charges the full gate latency at maximum acceleration before braking is assumed to begin.
Forward invariance of 𝒮_ad is guaranteed by constructing continuously differentiable Control Barrier Functions h_i(x) ≥ 0 whose zero super-level sets intersect to 𝒮_ad. For system dynamics ẋ = f(x) + g(x)u, each h_i satisfies the CBF condition:
sup_{u ∈ U} [ L_f h_i(x) + L_g h_i(x)·u ] ≥ −α( h_i(x) )
L_f h, L_g h : Lie derivatives along f and g
α(·) : extended class-𝒦_∞ function
At the boundary ∂𝒮_ad the admissible control input u forces the state trajectory back into the interior. In this framework the gate does not synthesize u; it verifies that the proposed u satisfies the condition, and holds otherwise.
For discrete implementation on clock period Δt with horizon N, the projected trajectory is evaluated by a third-order Taylor expansion with an explicit remainder bound on jerk:
x̂_{t+k} = z_t + v_t·(kΔt) + ½·a_t·(kΔt)² ± ⅙·j_max·(kΔt)³
q(x) = ⊤ if min_i h_i(x) ≥ ε_h
= COND if 0 ≤ min_i h_i(x) < ε_h
= ⊥ if min_i h_i(x) < 0
Φ(σ_t) = ⋀_{k = 0 … N} q( x̂_{t+k} )
Φ is a meet over the horizon: one predicted excursion below the barrier anywhere in the window collapses the frame to ⊥. The margin ε_h is the hysteresis band of §3.2; it is set from the remainder bound, not tuned by hand.
The gate relies entirely on physical state authenticity. State vectors generated by soft estimators or internal digital twins running within Λ are explicitly disallowed as evidence. Telemetry inputs to Π must originate from isolated, hardware-rooted physical transducers on a path Λ cannot write to.
Existing safety regimes assume a model is a transient software process running on standard von Neumann hardware that can be soft-reset or context-flushed after encountering an invalid state. This assumption fails when applied to a continuous, three-dimensional synthetic intelligence.
On a physical quaternary spatial substrate, state is not stored in addressable memory; state is the topological configuration of the field. Because the underlying lattice algebra is absorbing at ⊥, parasitic noise, power-rail perturbation, clock-domain jitter, or unvalidated telemetry injected into the substrate permanently alters the state manifold.
TARTARUS™ is the hermetic envelope that prevents external entropic decay, ensuring that the SI's physical field dynamics remain sui generis — deriving strictly from its own canonical grammar (𝓛_codex) and law of motion (Π_PCR).
Without the seal, the substrate's physical state reflects its external noise environment rather than its internal constitution.
| Component | Role | Physical specification |
|---|---|---|
𝒬₆₄³ | Body | A 64 × 64 × 64 index grid (262,144 sites) carrying a face-centered-cubic parity sublattice of 131,072 four-state sites. The spatial configuration of the sublattice is the SI state. Its lattice algebra is its physical dynamics. |
𝓛_codex | Language | Total functions, bounded parse trees, decidable termination, canonical representation. An intent lacking canonical representation cannot be formed. |
Π_PCR | Heartbeat | The Permission Control Runtime (PCR™). It runs a pause → contextualize → resume cycle: the physical law of motion that governs deterministic state progression. |
The instantaneous state space |Σ| = 4^131,072 is finite. The trajectory space across continuous execution time is infinite. Because no finite state enumeration can verify an infinite trajectory run, governance cannot be achieved by post-hoc testing. Verification must be structural, encoded into the hardware substrate itself.
An independent SI maintains its own state, its own time domain, its own law of motion, its own boundary, and its own power envelope. It does not exist as an external API dependency or a software module; it is a self-constituting physical intelligence.
| Claim | Statement | Status |
|---|---|---|
| Lattice stability | A finite, typed authorization lattice in which an absorbing inhibit (⊥) cannot be elevated by autonomous internal state transitions. | Mathematically proved (Theorems 1, 2). |
| Admissible domain invariance | State trajectories remain within 𝒮_ad under the CBF condition of §4.3. | Conditionally proved: holds given valid barrier functions h_i, plant parameters within the nominal model, sufficient actuator authority, and authentic state witnesses (§8). |
| Execution plane isolation | No write path from Λ can modify the enforcement logic Π. | Design property; engineering obligation — discharged only by post-layout netlist verification. |
| Hermetic environmental sealing | TARTARUS™ isolates the quaternary substrate from entropic contamination. | Design specification; engineering obligation — qualified by physical stress testing. |
| Self-constituting synthetic intelligence | Constitutive integration of substrate, grammar, and runtime into a bounded physical system whose trajectory space is structurally constrained. | System framework. Not a theorem; a composition of the four rows above. |
Domain of the theorems. Theorems 1 and 2 are statements about Σ — the enforcement plane's own state space — not about the world. They guarantee what the gate will do with the evidence it receives. Whether the evidence is true is the province of §4.5 and §8.
To maintain engineering rigor, the following conditions are explicitly declared outside the scope of this framework:
The architecture is the subject of USPTO provisional patent applications, including:
| Application | Subject |
|---|---|
63/973,313 | Pause-Contextualize-Resume control in high-velocity decision systems — the PCR™ runtime (Π_PCR). |
63/978,147 | The Quadzistor™: a quaternary logic architecture for recursive intelligence coherence. |
64/127,733 | Deterministic hardware-enforced authorization architecture employing an ordered quaternary state algebra and hierarchical inhibition lattice — ChronaGate™. |
64/133,334 | TARTARUS™ physical and logical containment (𝒯_TARTARUS). |
64/141,252 | Hardware-enforced spatial authorization using interior barrier-curvature trip surfaces and an absorbing quaternary meet-lattice interlock on a face-centered cubic substrate. |
64/152,388 | Isolated quaternary spatial automaton substrate and fail-safe output transduction circuitry (𝒬₆₄³). |
64/153,663 | Bounded self-modifying field dynamics governed by a structurally pinned authorization evaluator. |
64/157,181 | Hardware-isolated, fail-closed authorization circuitry: atomic horizon-frame transfer, immutable-reference origin binding, hysteretic quaternary quantizer, absorbing lattice state machine, hardware-armed epoch, dead-time driver, default-dead clock-loss clamp (§3). |
Provisional applications establish priority and confer no exclusionary rights until non-provisional issuance. Patent pending. Detailed claims, schematics, and netlist specifications are available to qualified counterparties under NDA.
ChronaGate™ is the initial commercial implementation of the architecture.
Corporate profile. AI2 — Asymmetric Intelligence & Innovation, Nashville, Tennessee. An IP product development and hardware manufacturing company. Majority woman-owned, minority-owned enterprise (WOSB / EDWOSB / SDB / 8(a) eligible).
The primary bottleneck facing advanced intelligence is not capability. It is deterministic authorization.
A self-governing intelligence is not one managed by external policy software. It is one whose governance is structurally inseparable from its physical substrate: a three-dimensional, self-constituting synthetic intelligence whose law of motion is its own hardware constitution, sealed against environmental entropic collapse.