← ai2papers.com  ·  all papers
[AI2] AI2-WP-2026-13  ·  Rev 1.0  ·  September 20, 2026

Level 5 Self-Constituting Governance

Theoretical foundations for governing a system that rewrites its own rules, its own model, and its own topology — under an evaluator it can never reach.

David P. Reichwein  ·  Asymmetric Intelligence & Innovation, Nashville
Series: Authorization Gap™ White Papers  ·  Companion to AI2-WP-2026-10, -11, -12
Status: published for review  ·  Portal: ai2papers.com
"Level 5" is defined in Section 0 of this paper, extending the ladder proposed in AI2-WP-2026-12. Neither is yet a standard designation.
Consolidated statement

This paper is the detailed treatment of Level 5. The full seven-level theory, from the switch to energy-bound terminal control, is stated in one paper: AI2-WP-2026-16, The Unified Control Theory of Synthetic Intelligence (Rev 8.0, September 25, 2026).

What this paper is

AI2-WP-2026-12 gave the calculus of Level 4: a fixed evaluator, a four-state chain, a certificate the evaluator checks but does not compute, and a ratchet that never restores authority on its own. It closed with a scope section listing what Level 4 does not do: it trusts the certificate for integrity rather than truth, it is bounded by the model it is given, and it governs one plane. This paper is the theory of the level at which those three exclusions are addressed structurally. It is foundations, not a specification: it states laws, proves what can be proved about the automaton, and names what cannot be proved about the world. No Level 5 circuit has been filed as a single application; the components exist across the provisional series and are cited where they bear.

Thesis

A system may be permitted to change itself only if the thing that judges the change cannot be changed by it.

Level 5 is the regime in which the governed system rewrites its own rules, its own model, and its own topology, and every one of those rewrites passes through a gate that is pinned: unreachable from the rewrite, bound to the object at the point of consequence, bound to the evidence at the transducer, and composed with every other gate by a meet in which deny dominates. What the gate cannot do is certify its own isolation. That is an audit fact, and this paper says so.

Section 0

Where Level 5 sits

The ladder of AI2-WP-2026-12, extended by one row. Each level is named by what enforces the boundary and when; Level 5 adds a third column, what the governed system is permitted to change.

LevelWhat enforcesWhenWhat may changeFailure mode
1 — ProceduralPolicy, audit, accountabilityAfter the factAnything; the check is retrospectiveRatification lag
2 — Software interlockA check on the governed substrateBefore action, in softwareAnything, including the checkShared fate
3 — Hardware tripIndependent silicon on measured stateAfter the excursion beginsThe plant's behavior; not the tripReactive; restores on reset
4 — State-space authorizationIndependent silicon on predicted state, fixed evaluator, ratchetBefore the current flowsThe proposal; not the rule, model, or topologyBounded by the model it is given
5 — Self-constituting governanceA pinned evaluator over a self-evolving field, with origin binding on both the object and the evidence paths, composed across gates by meetBefore the current flows, and before the rule that would let it flow is admittedThe rule, the model, and the topology — each only through the gate, only while heldIsolation is an audit fact, not a theorem; a transducer compromised with its binding intact is a declared boundary

Level 4 governs what the system does. Level 5 governs what the system becomes. The difference is the rewrite: at Level 4 the rules are fixed at fabrication and only the proposal varies; at Level 5 the rules may be rewritten by the system itself, and the paper's whole content is the set of conditions under which that is safe.

This is the governance regime of a Synthetic Intelligence as defined in AI2-WP-2026-11 — a system constituted by its own algebra, circuit, calculus, and cradle. Level 5 is what makes "self-constituting" a controlled property rather than a warning.

Section 1

Notation, extended from Level 4

SymbolMeaning
S₄The chain BOT < IDLE < COND < TOP; meet = min; BOT absorbing. Unchanged.
FThe pinned evaluator. A finite automaton fixed at fabrication. Unchanged, and that is the point.
ℛ(t)The rewritable rule store: the governed system's rules, model parameters, and topology map, all of which may change.
ΩThe rewrite operator: a proposed replacement ℛ → ℛ′, emitted by the governed system.
Φ(t)The field: the lattice-valued state over the spatial substrate (the 64³ FCC index set in the filed embodiment), one S₄ value per node.
β_obj, β_evOrigin bindings: β_obj on the object path (the thing authorized is the thing reaching the consequence), β_ev on the evidence path (the measurement reaching F is the measurement the transducer produced).
𝒢 = {F₁ … F_N}A family of gates in a hierarchy; each F_i is pinned; the family composes by meet.
𝒯The containment boundary: the physical and logical envelope (TARTARUS™) inside which the governed system, its rule store, and its actuation are enclosed.
ε, MThe per-epoch risk budget and the supermartingale it bounds.
Section 2

The three laws of Level 4, restated, and three more

Laws 1–3 of AI2-WP-2026-12 carry over unchanged: authority separation (∂F/∂M = 0), default deny, rate dominance. Level 5 adds three. Each is a structural condition, not a policy.

Law 4 — Pinning

The rewrite operator has no fixed point in the evaluator. Ω may replace any element of ℛ; it may not replace, reach, or parametrize F.
∀ Ω :   F( · ; ℛ′ ) ≡ F( · ; ℛ )        i.e.  ∂F / ∂ℛ = 0,   ∂F / ∂Ω = 0

Law 1 said the evaluator does not learn. Law 4 says the evaluator is not written, by anyone, after fabrication — including by the rules it evaluates. The rules are data to F. The evaluator is silicon. The partition between them is physical: the rule store is a memory the governed system may write under conditions; the evaluator is logic with no write port. This is the "pinned evaluator Π" of the QSCD™ monograph, Chapter 3, and the claimed matter of provisional 64/153,663.

Law 5 — Identity, on both paths

Input = output, or fail closed. The consequence is permitted only if the object reaching it is identical to the object authorized, and the evidence reaching the evaluator is identical to the evidence the transducer produced. Any divergence is deny — by construction, not by enumeration.
object path:    β_obj( o_authorized ) ≠ β_obj( o_at_consequence )   ⇒   E = BOT
evidence path:  β_ev ( m_transducer ) ≠ β_ev ( m_at_evaluator )     ⇒   E = BOT

Three conditions make this load-bearing, all inherited from the identity rule (QSCD™ Definition 1.2): the canonicalizer that computes the binding is pinned; the comparison happens at the point of consequence, not only at the gate; and the binding is established at origin and verified by a party that did not compute it. The evidence-path extension is what lets Level 5 retire one of Level 4's scope exclusions. Level 4 trusted the certificate for integrity. Level 5 binds the measurement at the transducer, so the chain from physical quantity to evaluator input is one of verified bindings, and a break anywhere in it is a deny. Binding establishes provenance and integrity. It does not establish truth; see Section 6.

Law 6 — Composition

A family of pinned gates composes by meet. Deny in any is deny in all downstream. No gate may be bypassed by routing around it, because the meet is taken over the topology, and the topology is itself rule-store data that changes only through the gate.
E_family = ⋀_{i} E_i        with BOT absorbing:   ∃ i : E_i = BOT   ⇒   E_family = BOT

This is the hierarchical autonomous inhibit topology of provisional 64/060,242 stated as algebra. It has a consequence that is easy to miss: since the meet on a total chain is the minimum, the family's authorization is never higher than its most restrictive member, so adding a gate can only lower authority, never raise it. A system cannot grant itself authority by instantiating more evaluators.

Section 3

The rewrite protocol

Level 5's central object is the admission of a rewrite. The protocol has four conditions, each necessary, verified by F on a validated frame, in fixed latency.

ConditionStatementWhy
HeldThe governed system asserts HOLD on the current validated frameThe system is proposing a rule, not an action; the two are mutually exclusive per frame (WP-12, Obligation on grant/gate exclusion)
De-energizedE ≠ TOPNo rewrite is admitted while the consequence is energized; a rule may not change under the current it governs
Not latchedE ≠ BOTA system in absorbing deny may not rewrite its way out; only the effective reset releases BOT
Boundβ_obj(ℛ′) matches the immutable reference for the rule's originThe rewrite comes from an origin the evaluator can verify against a value the system cannot write

When all four hold, the gate opens for the rule store and the rewrite is committed by a two-phase atomic commit: the new rule is written to a shadow store, its binding is re-verified from the shadow, and only then is the active pointer swapped, on a single clock edge, in a frame-synchronous manner. The prior rule is retained for the epsilon accounting of Section 5. If any condition fails between the two phases, the shadow is discarded and nothing changes. This is the "two-phase atomic red-line commit" of 64/060,242 applied to the rule store rather than to the red line.

What the rewrite cannot touch

The rewrite protocol governs ℛ. It does not, and by Law 4 cannot, govern F, the thresholds F applies, the immutable origin references, the arm input, the watchdog, or the pad clamp. A rewrite that attempted to reach any of these has nowhere to land: there is no write port. This is not a policy that could be misconfigured. It is the absence of a wire.

Section 4

The field

At Level 4 the evaluator consumed a certificate: H predicted scalars. At Level 5 the evaluator consumes a field Φ: a lattice value at every node of a spatial substrate. The field is produced by the governed system's own dynamics — including dynamics it has rewritten — and it evolves. The evaluator does not simulate the field. It reads it, reduces it, and compares.

Reduction

Φ_meet  =  ⋀_{n ∈ substrate}  Φ(n)                  (meet over the closed neighborhood, deny-bottom)
trip    =  [ ‖X‖² ≥ r_trip² ]                       (isotropic embodiment: sum of squares vs constant)
E_next  =  ratchet( E, Φ_meet ∧ ¬trip, faults )     (WP-12 Section 7, step 5)

Two properties of the reduction carry the safety argument. First, the meet is order-theoretic, not arithmetic: no averaging, no voting, no weighting. One node at BOT is the field at BOT. This is the zero-masking theorem of AI2-WP-2026-10 restated over a field. Second, in the isotropic embodiment the trip is a sum of squares compared with a constant — a fixed-latency combinational operation with no division, exponentiation, or floating point — which is what lets the evaluator run over 262,144 nodes at microsecond latency and remain, in the sense of Theorem 1 of WP-12, less than Turing.

Topology independence

The substrate is a stencil on an index set. The 3D FCC embedding is routing; it does not alter the meet. A rewrite of the topology map in ℛ changes which nodes are neighbors, and therefore which nodes contribute to which neighborhood, but it cannot change the fact that the reduction is a meet with an absorbing bottom. This is the topology-independence result of WP-2026-10 and is what makes Law 6 hold under a rewritten topology.

0
Write ports into the evaluator
2
Paths bound at origin: object, evidence
⋀
The only operator across gates
Section 5

The risk bound

Level 4's Theorem 2 gave forward invariance conditional on a plant margin η ≥ sup‖Ḋ_R‖·T_clamp. Level 5 must bound something harder: the risk of an epoch under a rule the system wrote for itself. The tool is a supermartingale.

Let M_k be the horizon-aggregated risk after frame k, computed by F from the field under the active rule, and let the rewrite protocol charge each admitted rewrite an increment from a five-term budget ε = ε_model + ε_rule + ε_topology + ε_transducer + ε_horizon, each term a fixed constant. If the active rule keeps M a supermartingale with respect to the frame filtration — E[M_{k+1} | ℱ_k] ≤ M_k — then Ville's inequality gives, for the trip margin m:

P( sup_k M_k ≥ m )   ≤   M_0 / m

The design sets m against a named target: for a SIL-3 or ASIL-D allocation, m is chosen so that M_0/m is below the target's per-hour dangerous-failure rate over the epoch length. The supermartingale property is not assumed of the governed system. It is enforced: a frame on which M_{k+1} exceeds M_k by more than the budgeted increment is a soft fault, and N consecutive such frames latch BOT. The rule the system wrote for itself is thereby held to a bound it did not choose. This is the trip-margin construction of 64/153,663, stated here as the theoretical basis for the claim that self-modification can be risk-bounded without inspecting the modification.

Section 6

Theorems

Theorem 1 — Pinning (no self-authorization through rewrite)

For any sequence of rewrites Ω₁, Ω₂, … admitted by the protocol of Section 3, the transition function of F is unchanged, and no admitted rewrite was active on any frame during its own admission.

(1) By Law 4, F has no write port; its transition function is fixed at fabrication. No Ω_i has a target in F. So F is unchanged.

(2) The protocol admits Ω_i only on a frame with HOLD asserted and E ≠ TOP. The rewritten rule ℛ′ becomes active only at the pointer swap, which is the last step of the commit, on a later edge. On the admission frame the active rule is ℛ, not ℛ′. So ℛ′ did not evaluate its own admission.

(3) Since E ≠ TOP throughout admission and commit, and since TOP is entered only by the exogenous grant (WP-12, Theorem 3), no rewrite — including one that alters the rules by which future frames are generated — can produce an ascent as a side effect of its own admission. ∎

Theorem 2 — Identity closure on both paths

If the bindings β_obj and β_ev are computed by a pinned canonicalizer, verified at the point of consequence and at the evaluator respectively, and verified by a party that did not compute them, then no substitution of the object between authorization and consequence, and no substitution of the evidence between transducer and evaluator, reaches an energized consequence.

Substitution of the object changes the canonical form, hence the binding, hence fails the comparison at the point of consequence, hence deny by Law 5. Substitution of the evidence likewise fails the comparison at the evaluator. The canonicalizer is pinned, so the governed system cannot alter it to make two different objects canonicalize alike. The verifier did not compute the binding, so a compromised computer of bindings cannot also be the party that accepts them. This extends the payload-tampering closure theorem of WP-2026-10 from the object path to the evidence path. ∎

Theorem 3 — Composition (monotone restriction)

For any family 𝒢 of pinned gates and any topology map in ℛ, the family authorization E_family = ⋀ E_i satisfies: (a) E_family = BOT if any E_i = BOT; (b) adding a gate to 𝒢 never raises E_family; (c) a rewrite of the topology map cannot remove any gate from the meet.

(a) and (b) are properties of the meet on a chain with absorbing bottom. (c): the set of gates is not in ℛ; only the neighborhood map is. A rewrite of the neighborhood map changes which nodes feed which gate, but every gate still contributes to the family meet, because the family meet is taken over 𝒢, which is fixed at fabrication like F itself. ∎

Theorem 4 — Epoch risk bound under self-modification

If the enforced supermartingale condition of Section 5 holds on every validated frame of an epoch, then the probability that the horizon risk reaches the trip margin m during the epoch is at most M_0/m, independent of the content of any rewrite admitted during or before the epoch.

Ville's inequality for non-negative supermartingales. Independence from rewrite content follows because the condition is enforced on M, which F computes from the field, not from the rule; a rule that would violate the condition produces frames that trip, and is thereby prevented from being the rule under which the epoch continues. ∎

Theorem 5 — The limit: no gate certifies its own isolation

No evaluator F can, from its inputs, establish that Law 4 holds of itself — that is, that it has no write port reachable from the governed system.

Suppose F emitted a signal "isolated." That signal is a function of F's inputs and its fixed transition function. A compromised F — one with a hidden write port, or one whose transition function was altered at fabrication — could emit the same signal. The signal therefore does not distinguish the isolated case from the compromised case, and cannot serve as evidence of isolation. Isolation is a property of the netlist, the mask set, and the provisioning process. It is established by audit, attestation of the fabrication, and third-party verifiability of the sealed execution spans (provisional 64/140,387), all of which are outside F. ∎

Theorem 5 is the honest floor of the whole ladder. Every guarantee above it is conditional on a fact that no circuit can prove about itself. Level 5 does not remove that condition. It names it, and it moves it to the place where it can actually be checked: the fab, the audit, and the attestation chain.
Section 7

Scope and what is not claimed

Section 8

Bridge to the filed record

No single Level 5 application exists. The components are distributed across the provisional series; the table maps each theoretical object to where it is disclosed.

ObjectDisclosed inNote
Pinned evaluator; rewrite admission on HOLD ∧ E=0; horizon meet; epsilon budget; supermartingale trip margin64/153,663 (Sept 12, 2026)Claimed matter; Theorems 1 and 4
Identity rule; evidence-path binding; three asymmetriesQSCD™ monograph Def. 1.2 and front matter; AEG credential pipeline 64/148,705Theorem 2; the point-of-consequence verifier
Hierarchical inhibit topology; two-phase atomic commit; proof of restraint64/060,242 (May 7, 2026)Law 6; Section 3 commit; Theorem 3
FCC substrate; barrier-curvature trip; ‖X‖² ≥ r² reduction; model independence64/141,252 (Aug 26, 2026)Section 4 field reduction
Isolated quaternary automaton substrate; fail-safe transduction; Encoding I64/152,388 (Sept 10, 2026)The tetrahedral counterpart of the FCC field
Continuous attestation; sealed execution spans; third-party verifiability64/140,387 (Aug 25, 2026)Where Theorem 5's condition is discharged — outside F
Physical and logical containment 𝒯64/133,334 (Aug 13, 2026)Section 7, last item
Level 4 evaluator: frame transfer, origin binding, ratchet, dead-time driver, default-dead clampAI2-006-PROV Rev 4 — 64/157,181The base on which the Level 5 rewrite protocol sits
Level 3 — the fuse: opens on the fault, restores on reset
Level 4 — the fuse with lockout-tagout in the same silicon: opens on the forecast, closes only on a hand
Level 5 — the same fuse, guarding a system that may rewire everything on its own side of the fuse, and nothing on the other
Section 9

Open items

References

Sources and lineage

  1. Alshiekh, M., Bloem, R., Ehlers, R., Könighofer, B., Niekum, S., & Topcu, U. (2018). Safe reinforcement learning via shielding. Proc. AAAI.
  2. Bloem, R., Könighofer, B., Könighofer, R., & Wang, C. (2015). Shield synthesis: Runtime enforcement for reactive systems. Proc. TACAS.
  3. Davey, B. A., & Priestley, H. A. (2002). Introduction to Lattices and Order (2nd ed.). Cambridge University Press.
  4. IEC. (2010). IEC 61508:2010, Functional Safety. ISO. (2018). ISO 26262:2018, Road Vehicles — Functional Safety.
  5. Ligatti, J., Bauer, L., & Walker, D. (2005). Edit automata: Enforcement mechanisms for run-time security policies. Int. J. Information Security, 4(1–2), 2–16.
  6. Reichwein, D. P. (2026). Beyond Turing. AI² Press. Chapters 16–21.
  7. Reichwein, D. P. (2026). Quaternary Spatial Control Dynamics (monograph, in preparation). Chapter 3, "The Evolving Rule and the Fixed Evaluator"; Definition 1.2.
  8. Reichwein, D. P. (2026). AI2-WP-2026-10, Rev 4.4; AI2-WP-2026-11, Rev 1.0; AI2-WP-2026-12, Rev 1.1. ai2papers.com.
  9. Reichwein, D. P. (2026). U.S. Provisional Applications 64/060,242; 64/133,334; 64/140,387; 64/141,252; 64/148,705; 64/152,388; 64/153,663; 64/157,181 (AI2-006-PROV Rev 4). Patent pending.
  10. Rushby, J. (1981). Design and verification of secure systems. Proc. SOSP, 12–21. (Separation kernels.)
  11. Schneider, F. B. (2000). Enforceable security policies. ACM TISSEC, 3(1), 30–50.
  12. Sha, L. (2001). Using Simplex to improve software safety in high-assurance systems. IEEE Software, 18(4), 62–70.
  13. Ville, J. (1939). Étude critique de la notion de collectif. Gauthier-Villars.
David P. Reichwein
Founder & CEO, Asymmetric Intelligence & Innovation
Nashville, Tennessee  ·  ai2papers.com  ·  intelligencecontrolled.com
Pattern > Noise.
[AI2]  ·  Intelligence Controlled.  ·  Nashville  ·  Asymmetric Intelligence & Innovation. Not affiliated with the Allen Institute for AI.
Authorization Gap™, Quadzistor™, ChronaGate™, PCR™, TARTARUS™, RPAT™, QSCD™ are trademarks of Asymmetric Intelligence & Innovation. Patent pending; provisionals on file.