Theoretical foundations for governing a system that rewrites its own rules, its own model, and its own topology — under an evaluator it can never reach.
This paper is the detailed treatment of Level 5. The full seven-level theory, from the switch to energy-bound terminal control, is stated in one paper: AI2-WP-2026-16, The Unified Control Theory of Synthetic Intelligence (Rev 8.0, September 25, 2026).
AI2-WP-2026-12 gave the calculus of Level 4: a fixed evaluator, a four-state chain, a certificate the evaluator checks but does not compute, and a ratchet that never restores authority on its own. It closed with a scope section listing what Level 4 does not do: it trusts the certificate for integrity rather than truth, it is bounded by the model it is given, and it governs one plane. This paper is the theory of the level at which those three exclusions are addressed structurally. It is foundations, not a specification: it states laws, proves what can be proved about the automaton, and names what cannot be proved about the world. No Level 5 circuit has been filed as a single application; the components exist across the provisional series and are cited where they bear.
A system may be permitted to change itself only if the thing that judges the change cannot be changed by it.
Level 5 is the regime in which the governed system rewrites its own rules, its own model, and its own topology, and every one of those rewrites passes through a gate that is pinned: unreachable from the rewrite, bound to the object at the point of consequence, bound to the evidence at the transducer, and composed with every other gate by a meet in which deny dominates. What the gate cannot do is certify its own isolation. That is an audit fact, and this paper says so.
The ladder of AI2-WP-2026-12, extended by one row. Each level is named by what enforces the boundary and when; Level 5 adds a third column, what the governed system is permitted to change.
| Level | What enforces | When | What may change | Failure mode |
|---|---|---|---|---|
| 1 — Procedural | Policy, audit, accountability | After the fact | Anything; the check is retrospective | Ratification lag |
| 2 — Software interlock | A check on the governed substrate | Before action, in software | Anything, including the check | Shared fate |
| 3 — Hardware trip | Independent silicon on measured state | After the excursion begins | The plant's behavior; not the trip | Reactive; restores on reset |
| 4 — State-space authorization | Independent silicon on predicted state, fixed evaluator, ratchet | Before the current flows | The proposal; not the rule, model, or topology | Bounded by the model it is given |
| 5 — Self-constituting governance | A pinned evaluator over a self-evolving field, with origin binding on both the object and the evidence paths, composed across gates by meet | Before the current flows, and before the rule that would let it flow is admitted | The rule, the model, and the topology — each only through the gate, only while held | Isolation is an audit fact, not a theorem; a transducer compromised with its binding intact is a declared boundary |
Level 4 governs what the system does. Level 5 governs what the system becomes. The difference is the rewrite: at Level 4 the rules are fixed at fabrication and only the proposal varies; at Level 5 the rules may be rewritten by the system itself, and the paper's whole content is the set of conditions under which that is safe.
This is the governance regime of a Synthetic Intelligence as defined in AI2-WP-2026-11 — a system constituted by its own algebra, circuit, calculus, and cradle. Level 5 is what makes "self-constituting" a controlled property rather than a warning.
| Symbol | Meaning |
|---|---|
S₄ | The chain BOT < IDLE < COND < TOP; meet = min; BOT absorbing. Unchanged. |
F | The pinned evaluator. A finite automaton fixed at fabrication. Unchanged, and that is the point. |
ℛ(t) | The rewritable rule store: the governed system's rules, model parameters, and topology map, all of which may change. |
Ω | The rewrite operator: a proposed replacement ℛ → ℛ′, emitted by the governed system. |
Φ(t) | The field: the lattice-valued state over the spatial substrate (the 64³ FCC index set in the filed embodiment), one S₄ value per node. |
β_obj, β_ev | Origin bindings: β_obj on the object path (the thing authorized is the thing reaching the consequence), β_ev on the evidence path (the measurement reaching F is the measurement the transducer produced). |
𝒢 = {F₁ … F_N} | A family of gates in a hierarchy; each F_i is pinned; the family composes by meet. |
𝒯 | The containment boundary: the physical and logical envelope (TARTARUS™) inside which the governed system, its rule store, and its actuation are enclosed. |
ε, M | The per-epoch risk budget and the supermartingale it bounds. |
Laws 1–3 of AI2-WP-2026-12 carry over unchanged: authority separation (∂F/∂M = 0), default deny, rate dominance. Level 5 adds three. Each is a structural condition, not a policy.
∀ Ω : F( · ; ℛ′ ) ≡ F( · ; ℛ ) i.e. ∂F / ∂ℛ = 0, ∂F / ∂Ω = 0
Law 1 said the evaluator does not learn. Law 4 says the evaluator is not written, by anyone, after fabrication — including by the rules it evaluates. The rules are data to F. The evaluator is silicon. The partition between them is physical: the rule store is a memory the governed system may write under conditions; the evaluator is logic with no write port. This is the "pinned evaluator Π" of the QSCD™ monograph, Chapter 3, and the claimed matter of provisional 64/153,663.
object path: β_obj( o_authorized ) ≠ β_obj( o_at_consequence ) ⇒ E = BOT evidence path: β_ev ( m_transducer ) ≠ β_ev ( m_at_evaluator ) ⇒ E = BOT
Three conditions make this load-bearing, all inherited from the identity rule (QSCD™ Definition 1.2): the canonicalizer that computes the binding is pinned; the comparison happens at the point of consequence, not only at the gate; and the binding is established at origin and verified by a party that did not compute it. The evidence-path extension is what lets Level 5 retire one of Level 4's scope exclusions. Level 4 trusted the certificate for integrity. Level 5 binds the measurement at the transducer, so the chain from physical quantity to evaluator input is one of verified bindings, and a break anywhere in it is a deny. Binding establishes provenance and integrity. It does not establish truth; see Section 6.
E_family = ⋀_{i} E_i with BOT absorbing: ∃ i : E_i = BOT ⇒ E_family = BOT
This is the hierarchical autonomous inhibit topology of provisional 64/060,242 stated as algebra. It has a consequence that is easy to miss: since the meet on a total chain is the minimum, the family's authorization is never higher than its most restrictive member, so adding a gate can only lower authority, never raise it. A system cannot grant itself authority by instantiating more evaluators.
Level 5's central object is the admission of a rewrite. The protocol has four conditions, each necessary, verified by F on a validated frame, in fixed latency.
| Condition | Statement | Why |
|---|---|---|
| Held | The governed system asserts HOLD on the current validated frame | The system is proposing a rule, not an action; the two are mutually exclusive per frame (WP-12, Obligation on grant/gate exclusion) |
| De-energized | E ≠ TOP | No rewrite is admitted while the consequence is energized; a rule may not change under the current it governs |
| Not latched | E ≠ BOT | A system in absorbing deny may not rewrite its way out; only the effective reset releases BOT |
| Bound | β_obj(ℛ′) matches the immutable reference for the rule's origin | The rewrite comes from an origin the evaluator can verify against a value the system cannot write |
When all four hold, the gate opens for the rule store and the rewrite is committed by a two-phase atomic commit: the new rule is written to a shadow store, its binding is re-verified from the shadow, and only then is the active pointer swapped, on a single clock edge, in a frame-synchronous manner. The prior rule is retained for the epsilon accounting of Section 5. If any condition fails between the two phases, the shadow is discarded and nothing changes. This is the "two-phase atomic red-line commit" of 64/060,242 applied to the rule store rather than to the red line.
The rewrite protocol governs ℛ. It does not, and by Law 4 cannot, govern F, the thresholds F applies, the immutable origin references, the arm input, the watchdog, or the pad clamp. A rewrite that attempted to reach any of these has nowhere to land: there is no write port. This is not a policy that could be misconfigured. It is the absence of a wire.
At Level 4 the evaluator consumed a certificate: H predicted scalars. At Level 5 the evaluator consumes a field Φ: a lattice value at every node of a spatial substrate. The field is produced by the governed system's own dynamics — including dynamics it has rewritten — and it evolves. The evaluator does not simulate the field. It reads it, reduces it, and compares.
Φ_meet = ⋀_{n ∈ substrate} Φ(n) (meet over the closed neighborhood, deny-bottom)
trip = [ ‖X‖² ≥ r_trip² ] (isotropic embodiment: sum of squares vs constant)
E_next = ratchet( E, Φ_meet ∧ ¬trip, faults ) (WP-12 Section 7, step 5)
Two properties of the reduction carry the safety argument. First, the meet is order-theoretic, not arithmetic: no averaging, no voting, no weighting. One node at BOT is the field at BOT. This is the zero-masking theorem of AI2-WP-2026-10 restated over a field. Second, in the isotropic embodiment the trip is a sum of squares compared with a constant — a fixed-latency combinational operation with no division, exponentiation, or floating point — which is what lets the evaluator run over 262,144 nodes at microsecond latency and remain, in the sense of Theorem 1 of WP-12, less than Turing.
The substrate is a stencil on an index set. The 3D FCC embedding is routing; it does not alter the meet. A rewrite of the topology map in ℛ changes which nodes are neighbors, and therefore which nodes contribute to which neighborhood, but it cannot change the fact that the reduction is a meet with an absorbing bottom. This is the topology-independence result of WP-2026-10 and is what makes Law 6 hold under a rewritten topology.
Level 4's Theorem 2 gave forward invariance conditional on a plant margin η ≥ sup‖Ḋ_R‖·T_clamp. Level 5 must bound something harder: the risk of an epoch under a rule the system wrote for itself. The tool is a supermartingale.
Let M_k be the horizon-aggregated risk after frame k, computed by F from the field under the active rule, and let the rewrite protocol charge each admitted rewrite an increment from a five-term budget ε = ε_model + ε_rule + ε_topology + ε_transducer + ε_horizon, each term a fixed constant. If the active rule keeps M a supermartingale with respect to the frame filtration — E[M_{k+1} | ℱ_k] ≤ M_k — then Ville's inequality gives, for the trip margin m:
P( sup_k M_k ≥ m ) ≤ M_0 / m
The design sets m against a named target: for a SIL-3 or ASIL-D allocation, m is chosen so that M_0/m is below the target's per-hour dangerous-failure rate over the epoch length. The supermartingale property is not assumed of the governed system. It is enforced: a frame on which M_{k+1} exceeds M_k by more than the budgeted increment is a soft fault, and N consecutive such frames latch BOT. The rule the system wrote for itself is thereby held to a bound it did not choose. This is the trip-margin construction of 64/153,663, stated here as the theoretical basis for the claim that self-modification can be risk-bounded without inspecting the modification.
For any sequence of rewrites Ω₁, Ω₂, … admitted by the protocol of Section 3, the transition function of F is unchanged, and no admitted rewrite was active on any frame during its own admission.
(1) By Law 4, F has no write port; its transition function is fixed at fabrication. No Ω_i has a target in F. So F is unchanged.
(2) The protocol admits Ω_i only on a frame with HOLD asserted and E ≠ TOP. The rewritten rule ℛ′ becomes active only at the pointer swap, which is the last step of the commit, on a later edge. On the admission frame the active rule is ℛ, not ℛ′. So ℛ′ did not evaluate its own admission.
(3) Since E ≠ TOP throughout admission and commit, and since TOP is entered only by the exogenous grant (WP-12, Theorem 3), no rewrite — including one that alters the rules by which future frames are generated — can produce an ascent as a side effect of its own admission. ∎
If the bindings β_obj and β_ev are computed by a pinned canonicalizer, verified at the point of consequence and at the evaluator respectively, and verified by a party that did not compute them, then no substitution of the object between authorization and consequence, and no substitution of the evidence between transducer and evaluator, reaches an energized consequence.
Substitution of the object changes the canonical form, hence the binding, hence fails the comparison at the point of consequence, hence deny by Law 5. Substitution of the evidence likewise fails the comparison at the evaluator. The canonicalizer is pinned, so the governed system cannot alter it to make two different objects canonicalize alike. The verifier did not compute the binding, so a compromised computer of bindings cannot also be the party that accepts them. This extends the payload-tampering closure theorem of WP-2026-10 from the object path to the evidence path. ∎
For any family 𝒢 of pinned gates and any topology map in ℛ, the family authorization E_family = ⋀ E_i satisfies: (a) E_family = BOT if any E_i = BOT; (b) adding a gate to 𝒢 never raises E_family; (c) a rewrite of the topology map cannot remove any gate from the meet.
(a) and (b) are properties of the meet on a chain with absorbing bottom. (c): the set of gates is not in ℛ; only the neighborhood map is. A rewrite of the neighborhood map changes which nodes feed which gate, but every gate still contributes to the family meet, because the family meet is taken over 𝒢, which is fixed at fabrication like F itself. ∎
If the enforced supermartingale condition of Section 5 holds on every validated frame of an epoch, then the probability that the horizon risk reaches the trip margin m during the epoch is at most M_0/m, independent of the content of any rewrite admitted during or before the epoch.
Ville's inequality for non-negative supermartingales. Independence from rewrite content follows because the condition is enforced on M, which F computes from the field, not from the rule; a rule that would violate the condition produces frames that trip, and is thereby prevented from being the rule under which the epoch continues. ∎
No evaluator F can, from its inputs, establish that Law 4 holds of itself — that is, that it has no write port reachable from the governed system.
Suppose F emitted a signal "isolated." That signal is a function of F's inputs and its fixed transition function. A compromised F — one with a hidden write port, or one whose transition function was altered at fabrication — could emit the same signal. The signal therefore does not distinguish the isolated case from the compromised case, and cannot serve as evidence of isolation. Isolation is a property of the netlist, the mask set, and the provisioning process. It is established by audit, attestation of the fabrication, and third-party verifiability of the sealed execution spans (provisional 64/140,387), all of which are outside F. ∎
No single Level 5 application exists. The components are distributed across the provisional series; the table maps each theoretical object to where it is disclosed.
| Object | Disclosed in | Note |
|---|---|---|
| Pinned evaluator; rewrite admission on HOLD ∧ E=0; horizon meet; epsilon budget; supermartingale trip margin | 64/153,663 (Sept 12, 2026) | Claimed matter; Theorems 1 and 4 |
| Identity rule; evidence-path binding; three asymmetries | QSCD™ monograph Def. 1.2 and front matter; AEG credential pipeline 64/148,705 | Theorem 2; the point-of-consequence verifier |
| Hierarchical inhibit topology; two-phase atomic commit; proof of restraint | 64/060,242 (May 7, 2026) | Law 6; Section 3 commit; Theorem 3 |
| FCC substrate; barrier-curvature trip; ‖X‖² ≥ r² reduction; model independence | 64/141,252 (Aug 26, 2026) | Section 4 field reduction |
| Isolated quaternary automaton substrate; fail-safe transduction; Encoding I | 64/152,388 (Sept 10, 2026) | The tetrahedral counterpart of the FCC field |
| Continuous attestation; sealed execution spans; third-party verifiability | 64/140,387 (Aug 25, 2026) | Where Theorem 5's condition is discharged — outside F |
| Physical and logical containment 𝒯 | 64/133,334 (Aug 13, 2026) | Section 7, last item |
| Level 4 evaluator: frame transfer, origin binding, ratchet, dead-time driver, default-dead clamp | AI2-006-PROV Rev 4 — 64/157,181 | The base on which the Level 5 rewrite protocol sits |