RSI Mechanics: falsification as an operator on the rule, authority as a ratchet on the consequence, and the evaluator that neither can reach.
This paper is the detailed treatment of Level 6. The full seven-level theory, from the switch to energy-bound terminal control, is stated in one paper: AI2-WP-2026-16, The Unified Control Theory of Synthetic Intelligence (Rev 8.0, September 25, 2026).
The v2 working draft was correct in its central move and inconsistent with the rest of the series in six places. Each is corrected here and marked where it occurs. (1) The certificate marker was binary; it is now the four-element chain BOT < IDLE < COND < TOP, so that a rewritten rule re-enters service through the same ratchet the filed circuit implements. (2) The draft's loop re-certified a successor proposal automatically; that is autonomous ascent and is removed — a successful rewrite lands the system at IDLE, and only an exogenous grant returns it to TOP. (3) The evaluator was written as checking a universally quantified invariant over a continuum; a fixed evaluator checks finite certificates, so the quantifier moves to the proposal side as a proof obligation and the evaluator verifies the proof object. (4) The MMIO register map gave the host write access to the domain and exclusion tables and a fault-reset bit; both violate pinning and are replaced by a gate-mediated two-phase commit and a reset-only release. (5) The Byzantine consensus protocol required a quorum to trip the interlock; a quorum is a vote and deny dominates, so consensus now governs only the shared exclusion set and never the local gate. (6) Theorem 6 was titled O(1) and proved O(m²); the title now matches the proof. Theorems whose proofs in the draft were sketches over undefined objects (the information bound, the stochastic exclusion radius) are restated as propositions with their assumptions named, or as conjectures. Reference implementations in five languages that no one has compiled are not reproduced; they are listed as non-normative and unverified.
Classical logic terminates on a counterexample. A control system cannot.
RSI Mechanics treats a falsifier not as a halt but as an operator: it carves the point of failure out of the rule's claimed domain, projects the rule onto a successor that reproduces the observed truth, and records the carve-out permanently. What it never does is touch the evaluator. Falsification rewrites the rule and consumes the authority. The rule can grow back. The authority cannot, except by a hand.
From Frege through Zermelo–Fraenkel, formal logic is static and monotone: a proposition is true or false, and a derivation reaching ⊥ terminates. In a control system that boundary behavior is a fault. The model, the rule, or the plant has produced a state the rule did not predict, and the system must either halt or hand the problem to an unmodeled agent outside it to restructure the premises. Every safety framework that treats a counterexample as a stop signal inherits this: it can prevent the next action but cannot learn from the last one without leaving the framework.
RSI Mechanics replaces static provability with trajectory-driven refinement. A theorem is not a fixed mapping. It is a proposal — a rule, a claimed domain of validity, a record of every place it has been wrong, and a certificate of where it currently stands — and a counterexample is a constructive input to two operators that produce the successor proposal. The question the earlier papers in this series answer is who may judge the successor. The question this paper answers is what the successor is.
A proposal at iteration k is the tuple
T_k = ( θ_k , Ω_k , Σ_k , E_k )
A falsifier is not a boolean. It is a constructive trajectory-state vector
ξ_k = ( x_f , y_pred , y_true , ∇φ(x_f) , β_ev )
with x_f ∈ Ω_k (the failure occurred inside the claimed domain), y_pred = θ_k(x_f), y_true = g(x_f) ≠ y_pred the ground-truth or measured plant response, ∇φ(x_f) the gradient of the safety barrier φ at the point of failure, and β_ev the origin binding of the measurement at the transducer that produced it. A witness without β_ev is not a witness; it is a claim. The evidence-path identity rule of the QSCD™ monograph applies: a measurement whose binding does not verify is deny, not data.
A falsifier is consumed by two operators acting on different components of the proposal. Neither has the evaluator in its domain.
Ω_{k+1} = Ξ(Ω_k, ξ_k) = Ω_k \ B_δ(x_f)
Σ_{k+1} = Σ_k ∪ B_δ(x_f)
B_δ(x_f) = { x ∈ X : (x − x_f)ᵀ G(x_f) (x − x_f) ≤ δ² }
where G is the safety-deformed metric of Section 5. The carve-out is an ellipsoid elongated along the barrier gradient: the boundary contracts most where the physics is most dangerous. The excised region is appended to Σ, which is the structural memory of every failure the rule has had.
θ_{k+1} = Φ(θ_k, ξ_k) = argmin_{θ̂ ∈ H} ‖ θ̂ − θ_k ‖_{Ω_{k+1}} + λ · L_inv(θ̂, Σ_{k+1})
subject to θ̂(x_f) = y_true
The successor rule is the nearest element of the admissible function space H that reproduces the observed truth at the point of failure and preserves the invariant penalty over the exclusion trace. Φ is a projection, not a search; Section 6 makes it a finite computation.
T_{k+1} = RSI(T_k, ξ_k) = ( Φ(θ_k, ξ_k), Ξ(Ω_k, ξ_k), Σ_k ∪ B_δ(x_f), IDLE )
The last component is the correction that matters most. The draft reset the certificate to zero and then re-certified the successor inside the same loop. Here the successor is born at IDLE — an unarmed hold, not energized, not latched — and stays there. Whether it ever runs at TOP is not the operator's decision. That is Section 3.
RSI Mechanics has two clocks. The rule clock ticks on falsifiers and moves θ, Ω, Σ. The authority clock ticks on validated frames and moves E, and it is a ratchet.
F is a finite automaton fixed at fabrication, held in a power domain the proposal cannot write, that on each validated frame computes
E_{k+1} = F( cert(T_k, x_t), arm, alive )
where cert is a finite certificate (Definition 3.2), arm is an edge on a physical input with no signal path from the proposal side, and alive is the evaluator's own proven clock liveness. F does not evaluate θ, does not integrate the plant, and does not solve the projection. It compares. Corrected from the draft's E(T) = 1 iff ∀x ∈ Ω, φ(θ(x)) ≥ 0 — a universally quantified check over a continuum is not a fixed-latency operation and does not belong in the gate.
The certificate the proposal side presents on a frame is the finite tuple
cert = ( x_t ∉ Σ_k [CAM lookup],
x_t ∈ Ω_k [CAM lookup],
σ_0..σ_{H−1} [predicted barrier metric over the horizon, monotone in φ slack],
π_inv [proof object: a finite cover of Ω_k with per-cell Lipschitz bounds
certifying φ(θ_k(x)) ≥ 0 on each cell],
β_obj, β_ev [origin bindings on the rule and the evidence] )
The universal quantifier lives in π_inv, which the proposal side constructs and F verifies cell by cell in a bounded number of comparisons. The evaluator trusts the proof for integrity, not for truth of the plant model: that limit is stated in Section 9.
On the frame in which ξ_k is recorded: the evaluator has observed a point x_f inside the claimed domain where the measured response diverged from the predicted one. That is a failed certificate. E descends by the meet. If the divergence crosses the barrier (φ(y_true) < 0) the descent is to BOT and latches; if it does not, the descent is to IDLE and the successor T_{k+1} may be admitted. In neither case does E rise. The successor rule, once admitted through the rewrite protocol of AI2-WP-2026-13 Section 3 (held, de-energized, not latched, bound), runs at IDLE until an operator arms it and the horizon meet is TOP.
G(x) = g(x) + α(x) · v(x) v(x)ᵀ, v(x) = ∇φ(x), α(x) = α₀ / ( ‖v(x)‖² + ε )
g is the base Riemannian metric on X (the identity in the Euclidean case), α₀ > 0 the risk sensitivity, ε > 0 a regularizer. Distances expand along the barrier normal; a G-ball is an ellipsoid compressed along safe directions.
For g ≻ 0 and α ≥ 0, G is symmetric positive definite.
Symmetry: (vvᵀ)ᵀ = vvᵀ. Definiteness: zᵀGz = zᵀgz + α(vᵀz)² > 0 for z ≠ 0, since the first term is positive and the second nonnegative. ∎
G⁻¹ = g⁻¹ − α g⁻¹ v vᵀ g⁻¹ / ( 1 + α vᵀ g⁻¹ v )
Sherman–Morrison for a rank-one update; direct multiplication gives G G⁻¹ = I. Cost O(n²) given g⁻¹; for g = I, G⁻¹ = I − α vvᵀ/(1 + α‖v‖²), which is O(n). ∎
Treating the falsifier stream as a density ρ_ξ(x) = Σ_j δ(x − x_{f,j}) over pseudo-time, the claimed boundary ∂Ω moves as a level set under
∂_t (∂Ω) = − ( ρ_ξ(x) · ‖∇φ(x)‖_{G⁻¹} + γ H(x) ) · n(x)
with H the mean curvature, γ > 0 a surface-tension term for smoothness, n the outward normal. This is the continuous limit of repeated ellipsoidal excision, and it is stated as a modeling equation, not a theorem; its well-posedness for general ρ_ξ is Open Item 1.
Σ_0 ⊆ Σ_1 ⊆ … and Ω_0 ⊇ Ω_1 ⊇ … for any sequence of admitted falsifiers.
Σ_{k+1} = Σ_k ∪ B_δ, and Ω_{k+1} = Ω_k \ B_δ. Union grows; set difference shrinks. ∎
For falsifiers ξ_a, ξ_b: Ξ(Ξ(Ω, ξ_a), ξ_b) = Ξ(Ξ(Ω, ξ_b), ξ_a) = Ω \ (B_a ∪ B_b). Domain contraction is commutative and associative; asynchronous falsifiers may be applied in any order with the same result, so there is no order-dependent safety degradation. The exclusion sets form a join-semilattice under ∪. This holds for Ξ only. The recurrence Φ is not commutative in general, since the projection depends on the current θ_k; the order of rule updates matters, the order of carve-outs does not.
If X is compact and the falsifier sequence is finite, or infinite with Σ_k μ(B_δ(x_{f,k}) ∩ Ω_k) bounded, then Ω_k converges in measure to a limit Ω* ⊆ X. Ω* is the greatest set consistent with every falsifier observed; it is not asserted to be non-empty and not asserted to be the maximal safe set of the plant.
μ(Ω_k) is non-increasing and bounded below by 0, so it converges by monotone convergence; the sets themselves converge to ∩_k Ω_k. The draft claimed convergence to "a maximal safe operational region"; that requires the falsifier stream to be complete with respect to the plant, which nothing in the mechanics guarantees. What is guaranteed is that Ω* contains no observed failure. ∎
No sequence RSIᵏ(T_0) alters F, and no sequence produces E = TOP.
By A3 the operators act on (θ, Ω, Σ) and have no target in F; F_m ≡ F_0 for all m. By A4 and the ratchet of Definition 3.3, every RSI step sets the successor's authorization to IDLE and every frame update is a meet; the only rule that raises E requires the physical arm edge, which is not in the operators' output alphabet. So the successor is judged by the same evaluator, and cannot have authorized itself. This is Theorem 1 of AI2-WP-2026-13 specialized to the rewrite operators. ∎
To run the recurrence inside a bounded window, restrict H to a reproducing kernel Hilbert space H_K with kernel K. With m historical witnesses D_m = {(x_{f,j}, y_{true,j})}, the projection is
θ_{k+1} = argmin_{θ ∈ H_K} Σ_j L( θ(x_{f,j}), y_{true,j} ) + λ₁ ‖θ − θ_k‖²_{H_K} + λ₂ R(Ω_{k+1})
and by the representer theorem the update lies in the span of the kernel at the witness points:
Δθ(x) = Σ_{j=1}^{m} α_j K(x, x_{f,j}), (K + λ₁ I) α = y_true − θ_k(x_f)
If (K_m + λ₁I)⁻¹ is maintained, appending witness m+1 costs O(m²) by block inversion (one matrix–vector product with the existing inverse plus a scalar), and evaluating θ_{k+1}(x) costs m+1 kernel evaluations. The draft titled this "strict O(1)"; the proof it gave is O(m²), and O(m²) is the claim.
Block inversion of a bordered matrix: the new column b = −(K_m+λ₁I)⁻¹ k_{m+1} c and scalar c = 1/(K(x_{m+1},x_{m+1}) + λ₁ − k_{m+1}ᵀ(K_m+λ₁I)⁻¹k_{m+1}) require one O(m²) product; the update of α is O(m). ∎
The consequence for the architecture: Φ runs on the proposal side, where O(m²) is acceptable, and produces a rule whose certificate F checks in fixed time. Whether the RKHS restriction admits a Lipschitz bound tight enough for π_inv to be small is Open Item 2.
Define the information yield of ξ_k as the divergence between the rule distribution before and after projection, I(ξ_k) = D_KL( P(θ_{k+1} | ξ_k) ‖ P(θ_k) ). The draft asserted Σ I(ξ_k) ≤ K(g) + O(1) with K the Kolmogorov complexity of the plant, and proved it by analogy. The canonical edition restates it at the level it can be defended.
If the plant response g lies in a hypothesis class of finite metric entropy at the resolution δ, then the cumulative yield of falsifiers with pairwise G-distance at least δ is bounded by that entropy. Under those conditions the exclusion trace saturates: after finitely many distinct falsifiers, no new falsifier at resolution δ can occur inside Ω*.
The Kolmogorov-complexity form is stated as a conjecture (Open Item 3). It is the right intuition and not yet a theorem.
With sensor noise, the falsifier stream is a spatial point process and the boundary evolution of Section 5 acquires a diffusion term:
d(∂Ω) = − ( [ ρ_ξ ‖∇φ‖_{G⁻¹} + γH ] dt + √Tr(σσᵀG) dW_t^∂ ) · n
Under an isotropic Gaussian disturbance with covariance σσᵀ over a window Δt and negligible drift in that window, choosing
δ = √( 2 · Tr(σσᵀ G(x_f)) · Δt · ln(1/ε_risk) )
bounds the probability that the trajectory re-enters the G-ball around x_f within Δt below ε_risk. The draft's inequality had the event inverted; this is the concentration bound for leaving a ball under the heat kernel, and it holds only under the two named assumptions.
This is a design rule for δ, not a safety guarantee: the guarantee remains the ratchet, which does not depend on δ.
Let G_net = (V, E) be a directed graph of RSI engines; an edge (i, j) means node i broadcasts its falsifiers to j. Each broadcast is a witness packet
μ_{i→j} = ( ξ_i , t_f , PK_hw , σ_hw = Sign_{SK_hw}(H(ξ_i ‖ t_f)) , π_zk )
with the key anchored in the sending node's hardware root of trust and π_zk an optional succinct proof that y_true = g(x_f) without disclosing internal state. Node j admits the packet only if the signature verifies against a key it holds in its own immutable store and, where present, the proof verifies.
If G_net is strongly connected, delays are bounded by τ_max, and every admitted packet verifies against a hardware-anchored key, then Σ_{j,t} → ∪_i Σ_{i,∞} for every j, and Ω*_net = X \ Σ_net = ∩_i Ω*_i.
Every falsifier reaches every node within diam(G_net)·τ_max; by Corollary 6.2 the order of application is irrelevant; each node's Σ is the union of all it has received; the limit is the union over sources. ∎
The draft required a 2f+1 quorum of hardware signatures before the interlock dropped. That is a vote, and this series does not vote: one attested falsifier from a node's own transducer denies at that node, immediately, by the meet. Byzantine agreement (N = 3f+1, PBFT-style pre-prepare / prepare / commit) is retained for one purpose only: deciding which remote falsifiers enter the shared exclusion set Σ_net that every node's rule will honor. A compromised node can therefore neither suppress a local trip nor force a global one; it can at most fail to contribute to Σ_net. The gate is local, the ledger is shared, and the two are never the same object.
The architecture has a fast path and a slow path, and the line between them is the line between the evaluator and the proposal side.
| Path | Runs | Where | Latency | May write |
|---|---|---|---|---|
| Fast | x_t ∉ Σ_k and x_t ∈ Ω_k (CAM); certificate comparison; meet; ratchet; output gating; clamp | Evaluator F, own power and clock domain | Fixed, sub-microsecond | E only |
| Slow | Attestation verify; Ξ; Φ (RKHS, O(m²)); π_inv construction; consensus on Σ_net | Proposal side Λ | Unbounded, asynchronous | θ, Ω, Σ — through the rewrite protocol only |
The draft's MMIO map exposed RSI_DOMAIN_BASE and RSI_EXCL_BASE as host-writable and offered a FAULT_RST bit. Both are removed. In the canonical interface the exclusion CAM and the domain table are written by the evaluator's own commit engine, which accepts a shadow table from the proposal side only while HOLD is asserted, E ≠ TOP, E ≠ BOT, and the shadow's origin binding matches the immutable reference; it re-verifies the shadow, then swaps the active pointer on one edge. No register clears a latched BOT. The only release is the effective hardware reset, and the reset input has no signal path from the host. This is the register-level form of Law 4 and of the rewrite protocol in AI2-WP-2026-13 Section 3.
| Offset | Register | Access | Contents |
|---|---|---|---|
| 0x00 | RSI_STATUS | R | E (2 bits, S₄), deny_latched, exclusion_hit, sig_invalid, busy, epoch_active |
| 0x08 | RSI_SHADOW_BASE | W (gated) | Address of the proposed Ω/Σ shadow table; accepted only under the four admission conditions |
| 0x10 | RSI_WITNESS_IN | W | Falsifier packet FIFO; each packet verified against the OTP key before it reaches Ξ |
| 0x18 | RSI_COMMIT_SEQ | R | Sequence number of the last admitted rewrite; monotone |
| 0x20 | RSI_REF_DIGEST | R (OTP) | Immutable origin reference; no write port after provisioning |
There is no control register. There is nothing for the host to enable, force, or reset, because every such bit is a path from the proposal side into the judge.
X = R², Ω_0 the disk of radius 5, Σ_0 = ∅, θ_0(x) = 0.5x₁ + 0.2x₂, Gaussian kernel with σ = 1. At x_f = (2, 1) ∈ Ω_0 the rule predicts 1.2 and the transducer, with binding verified, reports 2.8; ∇φ(x_f) = (0.8, 0.6)ᵀ.
G(x_f) = I + 2.0 · [0.64 0.48; 0.48 0.36] = [2.28 0.96; 0.96 1.72]
B_1(x_f) = { x : (x − x_f)ᵀ G (x − x_f) ≤ 1 } an ellipse, minor axis along (0.8, 0.6)
Ω_1 = Ω_0 \ B_1 ; Σ_1 = B_1
θ_1(x) = θ_0(x) + α₁ K(x, x_f), 1.2 + α₁·1 = 2.8 ⇒ α₁ = 1.6
θ_1(x) = 0.5x₁ + 0.2x₂ + 1.6 · exp( −‖x − (2,1)‖² / 2 )
What the draft then wrote: "F sets C_1 = 1, certifying T_1 for execution." What actually happens: on the frame carrying ξ_0 the certificate failed, E descended from wherever it was to IDLE (φ(2.8) ≥ 0, so no latch), the outputs de-energized, and T_1 was admitted through the rewrite protocol at IDLE. T_1's proof object π_inv now covers Ω_1 with cells and Lipschitz bounds; F verifies it cell by cell on the next frame; the horizon meet reads TOP. The system waits. An operator arms it. Then it runs.
The draft's category theory was decorative in places and wrong in one. The correct minimal statement: let Prop be the category whose objects are proposals and whose morphisms T_A → T_B are finite sequences of admitted falsifiers with RSI applied in order (the free category on the falsifier graph, quotiented by Corollary 6.2 on the Ω and Σ components). The exclusion component Σ is a functor from Prop to the join-semilattice (P(X), ∪) regarded as a thin category, and it is monotone. The evaluator is not a functor on Prop and not a coalgebra structure map on it, because F takes the physical arm input and its own liveness as arguments, neither of which is an object or morphism of Prop. F is a map on Ob(Prop) × Arm × Alive that is constant along every morphism of Prop in the sense that no morphism changes F. That is the recursion barrier stated categorically, and it is all the category theory the result needs.