← ai2papers.com  ·  all papers
[AI2] AI2-WP-2026-14  ·  Canonical Edition, Rev 1.0  ·  September 21, 2026

Reichwein Mechanics of Recursive Synthetic Intelligence

RSI Mechanics: falsification as an operator on the rule, authority as a ratchet on the consequence, and the evaluator that neither can reach.

David P. Reichwein  ·  Asymmetric Intelligence & Innovation, Nashville
Series: Authorization Gap™ White Papers  ·  Supersedes working draft v2 (internal)
Status: canonical edition, published for review  ·  Portal: ai2papers.com
Companion to AI2-WP-2026-12 (Level 4) and AI2-WP-2026-13 (Level 5). This paper is the mechanics of the rewrite that Level 5 governs.
Consolidated statement

This paper is the detailed treatment of Level 6. The full seven-level theory, from the switch to energy-bound terminal control, is stated in one paper: AI2-WP-2026-16, The Unified Control Theory of Synthetic Intelligence (Rev 8.0, September 25, 2026).

Revision note — what the canonical edition changes

The v2 working draft was correct in its central move and inconsistent with the rest of the series in six places. Each is corrected here and marked where it occurs. (1) The certificate marker was binary; it is now the four-element chain BOT < IDLE < COND < TOP, so that a rewritten rule re-enters service through the same ratchet the filed circuit implements. (2) The draft's loop re-certified a successor proposal automatically; that is autonomous ascent and is removed — a successful rewrite lands the system at IDLE, and only an exogenous grant returns it to TOP. (3) The evaluator was written as checking a universally quantified invariant over a continuum; a fixed evaluator checks finite certificates, so the quantifier moves to the proposal side as a proof obligation and the evaluator verifies the proof object. (4) The MMIO register map gave the host write access to the domain and exclusion tables and a fault-reset bit; both violate pinning and are replaced by a gate-mediated two-phase commit and a reset-only release. (5) The Byzantine consensus protocol required a quorum to trip the interlock; a quorum is a vote and deny dominates, so consensus now governs only the shared exclusion set and never the local gate. (6) Theorem 6 was titled O(1) and proved O(m²); the title now matches the proof. Theorems whose proofs in the draft were sketches over undefined objects (the information bound, the stochastic exclusion radius) are restated as propositions with their assumptions named, or as conjectures. Reference implementations in five languages that no one has compiled are not reproduced; they are listed as non-normative and unverified.

Thesis

Classical logic terminates on a counterexample. A control system cannot.

RSI Mechanics treats a falsifier not as a halt but as an operator: it carves the point of failure out of the rule's claimed domain, projects the rule onto a successor that reproduces the observed truth, and records the carve-out permanently. What it never does is touch the evaluator. Falsification rewrites the rule and consumes the authority. The rule can grow back. The authority cannot, except by a hand.

Section 0

The problem RSI Mechanics answers

From Frege through Zermelo–Fraenkel, formal logic is static and monotone: a proposition is true or false, and a derivation reaching ⊥ terminates. In a control system that boundary behavior is a fault. The model, the rule, or the plant has produced a state the rule did not predict, and the system must either halt or hand the problem to an unmodeled agent outside it to restructure the premises. Every safety framework that treats a counterexample as a stop signal inherits this: it can prevent the next action but cannot learn from the last one without leaving the framework.

RSI Mechanics replaces static provability with trajectory-driven refinement. A theorem is not a fixed mapping. It is a proposal — a rule, a claimed domain of validity, a record of every place it has been wrong, and a certificate of where it currently stands — and a counterexample is a constructive input to two operators that produce the successor proposal. The question the earlier papers in this series answer is who may judge the successor. The question this paper answers is what the successor is.

Section 1

Core objects

Definition 1.1 — Proposal (dynamic theorem)

A proposal at iteration k is the tuple

T_k = ( θ_k , Ω_k , Σ_k , E_k )
Definition 1.2 — Falsifier witness

A falsifier is not a boolean. It is a constructive trajectory-state vector

ξ_k = ( x_f , y_pred , y_true , ∇φ(x_f) , β_ev )

with x_f ∈ Ω_k (the failure occurred inside the claimed domain), y_pred = θ_k(x_f), y_true = g(x_f) ≠ y_pred the ground-truth or measured plant response, ∇φ(x_f) the gradient of the safety barrier φ at the point of failure, and β_ev the origin binding of the measurement at the transducer that produced it. A witness without β_ev is not a witness; it is a claim. The evidence-path identity rule of the QSCD™ monograph applies: a measurement whose binding does not verify is deny, not data.

Section 2

The two operators

A falsifier is consumed by two operators acting on different components of the proposal. Neither has the evaluator in its domain.

Operator I — Domain contraction Ξ

Ω_{k+1} = Ξ(Ω_k, ξ_k) = Ω_k \ B_δ(x_f)
Σ_{k+1} = Σ_k ∪ B_δ(x_f)

B_δ(x_f) = { x ∈ X : (x − x_f)ᵀ G(x_f) (x − x_f) ≤ δ² }

where G is the safety-deformed metric of Section 5. The carve-out is an ellipsoid elongated along the barrier gradient: the boundary contracts most where the physics is most dangerous. The excised region is appended to Σ, which is the structural memory of every failure the rule has had.

Operator II — Synthetic recurrence Φ

θ_{k+1} = Φ(θ_k, ξ_k) = argmin_{θ̂ ∈ H}  ‖ θ̂ − θ_k ‖_{Ω_{k+1}}  +  λ · L_inv(θ̂, Σ_{k+1})
          subject to   θ̂(x_f) = y_true

The successor rule is the nearest element of the admissible function space H that reproduces the observed truth at the point of failure and preserves the invariant penalty over the exclusion trace. Φ is a projection, not a search; Section 6 makes it a finite computation.

The master step

T_{k+1} = RSI(T_k, ξ_k) = ( Φ(θ_k, ξ_k),  Ξ(Ω_k, ξ_k),  Σ_k ∪ B_δ(x_f),  IDLE )

The last component is the correction that matters most. The draft reset the certificate to zero and then re-certified the successor inside the same loop. Here the successor is born at IDLE — an unarmed hold, not energized, not latched — and stays there. Whether it ever runs at TOP is not the operator's decision. That is Section 3.

Section 3

The decoupled gate: what falsification does to authority

RSI Mechanics has two clocks. The rule clock ticks on falsifiers and moves θ, Ω, Σ. The authority clock ticks on validated frames and moves E, and it is a ratchet.

Definition 3.1 — Pinned evaluator F

F is a finite automaton fixed at fabrication, held in a power domain the proposal cannot write, that on each validated frame computes

E_{k+1} = F( cert(T_k, x_t),  arm,  alive )

where cert is a finite certificate (Definition 3.2), arm is an edge on a physical input with no signal path from the proposal side, and alive is the evaluator's own proven clock liveness. F does not evaluate θ, does not integrate the plant, and does not solve the projection. It compares. Corrected from the draft's E(T) = 1 iff ∀x ∈ Ω, φ(θ(x)) ≥ 0 — a universally quantified check over a continuum is not a fixed-latency operation and does not belong in the gate.

Definition 3.2 — Certificate

The certificate the proposal side presents on a frame is the finite tuple

cert = ( x_t ∉ Σ_k  [CAM lookup],
         x_t ∈ Ω_k  [CAM lookup],
         σ_0..σ_{H−1}  [predicted barrier metric over the horizon, monotone in φ slack],
         π_inv  [proof object: a finite cover of Ω_k with per-cell Lipschitz bounds
                 certifying φ(θ_k(x)) ≥ 0 on each cell],
         β_obj, β_ev  [origin bindings on the rule and the evidence] )

The universal quantifier lives in π_inv, which the proposal side constructs and F verifies cell by cell in a bounded number of comparisons. The evaluator trusts the proof for integrity, not for truth of the plant model: that limit is stated in Section 9.

Definition 3.3 — The ratchet under falsification

On the frame in which ξ_k is recorded: the evaluator has observed a point x_f inside the claimed domain where the measured response diverged from the predicted one. That is a failed certificate. E descends by the meet. If the divergence crosses the barrier (φ(y_true) < 0) the descent is to BOT and latches; if it does not, the descent is to IDLE and the successor T_{k+1} may be admitted. In neither case does E rise. The successor rule, once admitted through the rewrite protocol of AI2-WP-2026-13 Section 3 (held, de-energized, not latched, bound), runs at IDLE until an operator arms it and the horizon meet is TOP.

Falsification is non-terminal for the rule and terminal for the epoch. The rule learns. The authority is spent, and only a hand replaces it.
Section 4

Axioms

Section 5

Geometry of the carve-out

Definition 5.1 — Safety-deformed metric
G(x) = g(x) + α(x) · v(x) v(x)ᵀ,     v(x) = ∇φ(x),     α(x) = α₀ / ( ‖v(x)‖² + ε )

g is the base Riemannian metric on X (the identity in the Euclidean case), α₀ > 0 the risk sensitivity, ε > 0 a regularizer. Distances expand along the barrier normal; a G-ball is an ellipsoid compressed along safe directions.

Theorem 5.1 — G is a metric

For g ≻ 0 and α ≥ 0, G is symmetric positive definite.

Symmetry: (vvᵀ)ᵀ = vvᵀ. Definiteness: zᵀGz = zᵀgz + α(vᵀz)² > 0 for z ≠ 0, since the first term is positive and the second nonnegative. ∎

Theorem 5.2 — Closed-form inverse
G⁻¹ = g⁻¹ − α g⁻¹ v vᵀ g⁻¹ / ( 1 + α vᵀ g⁻¹ v )

Sherman–Morrison for a rank-one update; direct multiplication gives G G⁻¹ = I. Cost O(n²) given g⁻¹; for g = I, G⁻¹ = I − α vvᵀ/(1 + α‖v‖²), which is O(n). ∎

Boundary evolution

Treating the falsifier stream as a density ρ_ξ(x) = Σ_j δ(x − x_{f,j}) over pseudo-time, the claimed boundary ∂Ω moves as a level set under

∂_t (∂Ω) = − ( ρ_ξ(x) · ‖∇φ(x)‖_{G⁻¹} + γ H(x) ) · n(x)

with H the mean curvature, γ > 0 a surface-tension term for smoothness, n the outward normal. This is the continuous limit of repeated ellipsoidal excision, and it is stated as a modeling equation, not a theorem; its well-posedness for general ρ_ξ is Open Item 1.

Section 6

Algebra of the operators

Theorem 6.1 — Monotonicity of exclusion

Σ_0 ⊆ Σ_1 ⊆ … and Ω_0 ⊇ Ω_1 ⊇ … for any sequence of admitted falsifiers.

Σ_{k+1} = Σ_k ∪ B_δ, and Ω_{k+1} = Ω_k \ B_δ. Union grows; set difference shrinks. ∎

Corollary 6.2 — Commutativity of contraction

For falsifiers ξ_a, ξ_b: Ξ(Ξ(Ω, ξ_a), ξ_b) = Ξ(Ξ(Ω, ξ_b), ξ_a) = Ω \ (B_a ∪ B_b). Domain contraction is commutative and associative; asynchronous falsifiers may be applied in any order with the same result, so there is no order-dependent safety degradation. The exclusion sets form a join-semilattice under ∪. This holds for Ξ only. The recurrence Φ is not commutative in general, since the projection depends on the current θ_k; the order of rule updates matters, the order of carve-outs does not.

Theorem 6.3 — Convergence of the claimed domain

If X is compact and the falsifier sequence is finite, or infinite with Σ_k μ(B_δ(x_{f,k}) ∩ Ω_k) bounded, then Ω_k converges in measure to a limit Ω* ⊆ X. Ω* is the greatest set consistent with every falsifier observed; it is not asserted to be non-empty and not asserted to be the maximal safe set of the plant.

μ(Ω_k) is non-increasing and bounded below by 0, so it converges by monotone convergence; the sets themselves converge to ∩_k Ω_k. The draft claimed convergence to "a maximal safe operational region"; that requires the falsifier stream to be complete with respect to the plant, which nothing in the mechanics guarantees. What is guaranteed is that Ω* contains no observed failure. ∎

Theorem 6.4 — Non-self-certification (the recursion barrier)

No sequence RSIᵏ(T_0) alters F, and no sequence produces E = TOP.

By A3 the operators act on (θ, Ω, Σ) and have no target in F; F_m ≡ F_0 for all m. By A4 and the ratchet of Definition 3.3, every RSI step sets the successor's authorization to IDLE and every frame update is a meet; the only rule that raises E requires the physical arm edge, which is not in the operators' output alphabet. So the successor is judged by the same evaluator, and cannot have authorized itself. This is Theorem 1 of AI2-WP-2026-13 specialized to the rewrite operators. ∎

2
Operators: Ξ on the domain, Φ on the rule
0
Operators with the evaluator in their domain
IDLE
Where every successor proposal is born
Section 7

Making Φ finite: the RKHS projection

To run the recurrence inside a bounded window, restrict H to a reproducing kernel Hilbert space H_K with kernel K. With m historical witnesses D_m = {(x_{f,j}, y_{true,j})}, the projection is

θ_{k+1} = argmin_{θ ∈ H_K}  Σ_j L( θ(x_{f,j}), y_{true,j} )  +  λ₁ ‖θ − θ_k‖²_{H_K}  +  λ₂ R(Ω_{k+1})

and by the representer theorem the update lies in the span of the kernel at the witness points:

Δθ(x) = Σ_{j=1}^{m} α_j K(x, x_{f,j}),      (K + λ₁ I) α = y_true − θ_k(x_f)
Theorem 7.1 — Update cost is O(m²), evaluation O(m)

If (K_m + λ₁I)⁻¹ is maintained, appending witness m+1 costs O(m²) by block inversion (one matrix–vector product with the existing inverse plus a scalar), and evaluating θ_{k+1}(x) costs m+1 kernel evaluations. The draft titled this "strict O(1)"; the proof it gave is O(m²), and O(m²) is the claim.

Block inversion of a bordered matrix: the new column b = −(K_m+λ₁I)⁻¹ k_{m+1} c and scalar c = 1/(K(x_{m+1},x_{m+1}) + λ₁ − k_{m+1}ᵀ(K_m+λ₁I)⁻¹k_{m+1}) require one O(m²) product; the update of α is O(m). ∎

The consequence for the architecture: Φ runs on the proposal side, where O(m²) is acceptable, and produces a rule whose certificate F checks in fixed time. Whether the RKHS restriction admits a Lipschitz bound tight enough for π_inv to be small is Open Item 2.

Section 8

Information yield of a falsifier

Define the information yield of ξ_k as the divergence between the rule distribution before and after projection, I(ξ_k) = D_KL( P(θ_{k+1} | ξ_k) ‖ P(θ_k) ). The draft asserted Σ I(ξ_k) ≤ K(g) + O(1) with K the Kolmogorov complexity of the plant, and proved it by analogy. The canonical edition restates it at the level it can be defended.

Proposition 8.1 — Bounded cumulative yield (conditional)

If the plant response g lies in a hypothesis class of finite metric entropy at the resolution δ, then the cumulative yield of falsifiers with pairwise G-distance at least δ is bounded by that entropy. Under those conditions the exclusion trace saturates: after finitely many distinct falsifiers, no new falsifier at resolution δ can occur inside Ω*.

The Kolmogorov-complexity form is stated as a conjecture (Open Item 3). It is the right intuition and not yet a theorem.

Section 9

Stochastic falsification

With sensor noise, the falsifier stream is a spatial point process and the boundary evolution of Section 5 acquires a diffusion term:

d(∂Ω) = − ( [ ρ_ξ ‖∇φ‖_{G⁻¹} + γH ] dt  +  √Tr(σσᵀG) dW_t^∂ ) · n
Proposition 9.1 — Exclusion radius for a risk target

Under an isotropic Gaussian disturbance with covariance σσᵀ over a window Δt and negligible drift in that window, choosing

δ = √( 2 · Tr(σσᵀ G(x_f)) · Δt · ln(1/ε_risk) )

bounds the probability that the trajectory re-enters the G-ball around x_f within Δt below ε_risk. The draft's inequality had the event inverted; this is the concentration bound for leaving a ball under the heat kernel, and it holds only under the two named assumptions.

This is a design rule for δ, not a safety guarantee: the guarantee remains the ratchet, which does not depend on δ.

Section 10

Networked falsification

Let G_net = (V, E) be a directed graph of RSI engines; an edge (i, j) means node i broadcasts its falsifiers to j. Each broadcast is a witness packet

μ_{i→j} = ( ξ_i , t_f , PK_hw , σ_hw = Sign_{SK_hw}(H(ξ_i ‖ t_f)) , π_zk )

with the key anchored in the sending node's hardware root of trust and π_zk an optional succinct proof that y_true = g(x_f) without disclosing internal state. Node j admits the packet only if the signature verifies against a key it holds in its own immutable store and, where present, the proof verifies.

Theorem 10.1 — Convergence of the shared exclusion set

If G_net is strongly connected, delays are bounded by τ_max, and every admitted packet verifies against a hardware-anchored key, then Σ_{j,t} → ∪_i Σ_{i,∞} for every j, and Ω*_net = X \ Σ_net = ∩_i Ω*_i.

Every falsifier reaches every node within diam(G_net)·τ_max; by Corollary 6.2 the order of application is irrelevant; each node's Σ is the union of all it has received; the limit is the union over sources. ∎

Consensus governs the rule, never the gate

The draft required a 2f+1 quorum of hardware signatures before the interlock dropped. That is a vote, and this series does not vote: one attested falsifier from a node's own transducer denies at that node, immediately, by the meet. Byzantine agreement (N = 3f+1, PBFT-style pre-prepare / prepare / commit) is retained for one purpose only: deciding which remote falsifiers enter the shared exclusion set Σ_net that every node's rule will honor. A compromised node can therefore neither suppress a local trip nor force a global one; it can at most fail to contribute to Σ_net. The gate is local, the ledger is shared, and the two are never the same object.

Section 11

Realization

The architecture has a fast path and a slow path, and the line between them is the line between the evaluator and the proposal side.

PathRunsWhereLatencyMay write
Fastx_t ∉ Σ_k and x_t ∈ Ω_k (CAM); certificate comparison; meet; ratchet; output gating; clampEvaluator F, own power and clock domainFixed, sub-microsecondE only
SlowAttestation verify; Ξ; Φ (RKHS, O(m²)); π_inv construction; consensus on Σ_netProposal side ΛUnbounded, asynchronousθ, Ω, Σ — through the rewrite protocol only

Register interface, corrected

The draft's MMIO map exposed RSI_DOMAIN_BASE and RSI_EXCL_BASE as host-writable and offered a FAULT_RST bit. Both are removed. In the canonical interface the exclusion CAM and the domain table are written by the evaluator's own commit engine, which accepts a shadow table from the proposal side only while HOLD is asserted, E ≠ TOP, E ≠ BOT, and the shadow's origin binding matches the immutable reference; it re-verifies the shadow, then swaps the active pointer on one edge. No register clears a latched BOT. The only release is the effective hardware reset, and the reset input has no signal path from the host. This is the register-level form of Law 4 and of the rewrite protocol in AI2-WP-2026-13 Section 3.

OffsetRegisterAccessContents
0x00RSI_STATUSRE (2 bits, S₄), deny_latched, exclusion_hit, sig_invalid, busy, epoch_active
0x08RSI_SHADOW_BASEW (gated)Address of the proposed Ω/Σ shadow table; accepted only under the four admission conditions
0x10RSI_WITNESS_INWFalsifier packet FIFO; each packet verified against the OTP key before it reaches Ξ
0x18RSI_COMMIT_SEQRSequence number of the last admitted rewrite; monotone
0x20RSI_REF_DIGESTR (OTP)Immutable origin reference; no write port after provisioning

There is no control register. There is nothing for the host to enable, force, or reset, because every such bit is a path from the proposal side into the judge.

Section 12

Worked example

X = R², Ω_0 the disk of radius 5, Σ_0 = ∅, θ_0(x) = 0.5x₁ + 0.2x₂, Gaussian kernel with σ = 1. At x_f = (2, 1) ∈ Ω_0 the rule predicts 1.2 and the transducer, with binding verified, reports 2.8; ∇φ(x_f) = (0.8, 0.6)ᵀ.

G(x_f) = I + 2.0 · [0.64 0.48; 0.48 0.36] = [2.28 0.96; 0.96 1.72]
B_1(x_f) = { x : (x − x_f)ᵀ G (x − x_f) ≤ 1 }         an ellipse, minor axis along (0.8, 0.6)
Ω_1 = Ω_0 \ B_1 ;   Σ_1 = B_1

θ_1(x) = θ_0(x) + α₁ K(x, x_f),   1.2 + α₁·1 = 2.8  ⇒  α₁ = 1.6
θ_1(x) = 0.5x₁ + 0.2x₂ + 1.6 · exp( −‖x − (2,1)‖² / 2 )

What the draft then wrote: "F sets C_1 = 1, certifying T_1 for execution." What actually happens: on the frame carrying ξ_0 the certificate failed, E descended from wherever it was to IDLE (φ(2.8) ≥ 0, so no latch), the outputs de-energized, and T_1 was admitted through the rewrite protocol at IDLE. T_1's proof object π_inv now covers Ω_1 with cells and Lipschitz bounds; F verifies it cell by cell on the next frame; the horizon meet reads TOP. The system waits. An operator arms it. Then it runs.

Section 13

Categorical form

The draft's category theory was decorative in places and wrong in one. The correct minimal statement: let Prop be the category whose objects are proposals and whose morphisms T_A → T_B are finite sequences of admitted falsifiers with RSI applied in order (the free category on the falsifier graph, quotiented by Corollary 6.2 on the Ω and Σ components). The exclusion component Σ is a functor from Prop to the join-semilattice (P(X), ∪) regarded as a thin category, and it is monotone. The evaluator is not a functor on Prop and not a coalgebra structure map on it, because F takes the physical arm input and its own liveness as arguments, neither of which is an object or morphism of Prop. F is a map on Ob(Prop) × Arm × Alive that is constant along every morphism of Prop in the sense that no morphism changes F. That is the recursion barrier stated categorically, and it is all the category theory the result needs.

Section 14

Scope and what is not claimed

Section 15

Open items

References

Sources and lineage

  1. Aronszajn, N. (1950). Theory of reproducing kernels. Trans. AMS, 68, 337–404.
  2. Ames, A. D., et al. (2019). Control barrier functions: Theory and applications. Proc. ECC.
  3. Castro, M., & Liskov, B. (1999). Practical Byzantine fault tolerance. Proc. OSDI.
  4. Osher, S., & Sethian, J. A. (1988). Fronts propagating with curvature-dependent speed. J. Comput. Phys., 79, 12–49.
  5. Popper, K. (1959). The Logic of Scientific Discovery. Hutchinson.
  6. Reichwein, D. P. (2026). Beyond Turing. AI² Press. Chapters 16, 19, 20.
  7. Reichwein, D. P. (2026). Quaternary Spatial Control Dynamics (monograph, in preparation). Chapter 3; Definition 1.2.
  8. Reichwein, D. P. (2026). AI2-WP-2026-12, Rev 1.1; AI2-WP-2026-13, Rev 1.0. ai2papers.com.
  9. Reichwein, D. P. (2026). U.S. Provisional Applications 64/153,663 (pinned evaluator, bounded self-modification) and 64/157,181 (Level 4 evaluator circuit). Patent pending.
  10. Schölkopf, B., Herbrich, R., & Smola, A. J. (2001). A generalized representer theorem. Proc. COLT.
  11. Sherman, J., & Morrison, W. J. (1950). Adjustment of an inverse matrix corresponding to a change in one element. Ann. Math. Stat., 21, 124–127.
David P. Reichwein
Founder & CEO, Asymmetric Intelligence & Innovation
Nashville, Tennessee  ·  ai2papers.com  ·  intelligencecontrolled.com
Pattern > Noise.
[AI2]  ·  Intelligence Controlled.  ·  Nashville  ·  Asymmetric Intelligence & Innovation. Not affiliated with the Allen Institute for AI.
Authorization Gap™, Quadzistor™, ChronaGate™, PCR™, TARTARUS™, RPAT™, QSCD™ are trademarks of Asymmetric Intelligence & Innovation. Patent pending; provisionals on file.