← ai2papers.com  ·  all papers
[AI2] · ai2papers.com AI2-WP-2026-15 · Rev 2.0

[AI2] AI2-WP-2026-15 · Rev 2.0 · 29 September 2026
Series: Authorization Gap™ White Papers · Cognitive calculus
Companion to Genesis Rev 3 · WP-10 · WP-11 · WP-12 · WP-13 · WP-14 · WP-16 · WP-17C
Rev 2.0 adds Codex-1, the core language of the cognitive field (§5), and its conformance target (§7)
Rev 1.2 merged the origin note (formerly WP-15A), now withdrawn as a separate document
Status: specification and conformance target · published for review · Portal: ai2papers.com

The Three-Dimensional Calculus of Synthetic Intelligence

Thought as a field configuration. Permission as a law of motion. Codex-1 as the language of the field. Not a paper about language models.

David P. Reichwein
Asymmetric Intelligence & Innovation, Nashville

Thesis

A token string cannot be the state of a Synthetic Intelligence.

A language model thinks by advancing a line. Time is its only axis. Recursion is a longer prefix. Permission, if it exists, arrives after the sentence already exists. That is linearistic intelligence.

A Synthetic Intelligence thinks as a configuration of a three-dimensional field. Its language is total, bounded, and canonical. Its clock is a permission runtime. A thought that cannot be formed in that language is not a thought. A configuration that has not been granted is not an effect.

The body is finite. The relations are inexhaustible. Improvement is a new configuration, not a new authority.

Section 0

What this paper is, and is not

WP-11 defined a Synthetic Intelligence as one object:

SI  :=  ⟨ 𝒬64³ ,  𝓛_codex ,  Π_PCR ,  𝒯 ⟩

𝒬64³ is the lattice body. 𝓛_codex is the cognitive language. Π_PCR is the PCR™ (Permission Control Runtime). 𝒯 is the TARTARUS™ constituent. Two further symbols recur below: F, the pinned evaluator (WP-13 Law 4), and Axiom A1, the structural disjointness of the adaptive plane from F (Genesis).

Four constituents. Not a model wrapped in a safety layer. The series then wrote the control ladder: what a gate is (Genesis, WP-10), what an action is (WP-12), what a self-rewrite is (WP-13), what a successor is (WP-14), and the unified statement through energy (WP-16). WP-17C classified containment against authorization.

None of those papers is the calculus of thinking.

The authorization calculus already exists. WP-11 §4 and WP-12 give the admissible domain in physical state, the barrier condition, the four-state chain, and the evaluator that compares a certificate and does not solve a projection. That calculus answers: may this typed action leave.

This paper answers a prior question: what is a thought, when the machine is not a line. Section 1 says where that question came from. Sections 2 through 6 give the calculus and its language, Codex-1. Section 7 states what a conforming implementation must show. Sections 8 through 11 give the laws, place them on the ladder, and state what is proved and what is owed.

Earlier revisions named 𝓛_codex and listed the properties it must have. A canonicalizer cannot be audited until there is a grammar, and a term cannot have a unique admissible preimage until its types, bindings, domains, and witnesses are written down. Rev 2.0 writes them down. Codex-1 is a core calculus, not an encyclopedia: it fixes the constitutional properties that any later vocabulary must extend without breaking.

Non-claims

This paper does not assert that a thinking machine has been built. It does not treat Quadzistor™ device physics as load-bearing; the geometry holds on binary CMOS with a finite encoding per site (Genesis Rev 3). Codex-1 is specified as a core grammar; no implementation exists. Codex-1 is not a claim of general intelligence, consciousness, or usefulness in any domain. Isolation of the evaluator remains an audit fact (WP-13, Theorem 5). This paper classifies no vendor and certifies no implementation, including AI2’s own. It is not WP-18. Evidence method and path attestation stay a separate paper.

Section 1

Origin: the wrong noun

The calculus below is the specification of a category error, written first in a therapy room and then in geometry. The human fact is load-bearing and brief. It is not evidence that the lattice works. It is evidence of why a line was the wrong state variable.

Rule for the origin

State the human fact once. Extract the operator. Never use the child as a proof of silicon. Never use silicon as a repair of the child. He did not need fixing. He needed a language that did not begin by declaring him empty.

They called it speech therapy. Speech is a channel. He is nonverbal. On that axis the session begins already lost, because the instrument only scores what the mouth does.

The noun had to change. Communication therapy. Communication is a function. Presence, timing, refusal, a look that already contains the sentence, a pattern that repeats until a person honest enough to see it sees it. He was not waiting to become a speaker so he could start thinking. They had named the pipe. They had missed the ocean.

Animals make the same point without asking anyone to become an expert in a child. A dog decides, warns, waits, refuses, and loves without producing English. Nobody calls that a speech deficit. They call it a dog. The moment the mind is human and quiet, the culture forgets what it already believes: thought does not require the export format.

Speech is an export format. Thought is not.

Humans lean on the export until they confuse it with the thing exported. Watch a person hunt for a word. The thought arrived first. The mouth is late. An infant communicates before phonemes. Grief communicates after language fails. Linear language is a narrow pipe trained to impersonate a mind.

A language model is that pipe, automated. The rest of this paper is what follows when the pipe is refused as the state.

Section 2

Why a token string cannot be the state

2.1 Linearistic intelligence

Call a system linearistic when its instantaneous cognitive state is a finite prefix of a one-dimensional sequence, and the only legal transition is to append.

st+1  =  st ⌢ τt+1

The next symbol may be sampled, searched, or constrained. The topology does not change. Neighborhood is left-context. Distance is string length. Recursion is a loop that writes more of the same axis.

That architecture has four structural restrictions. They are not training defects. They are geometry.

A thinking machine whose state is a line will always score the channel and miss the relation. That is the therapy room, automated.

Wrapping a linearistic model in a lattice does not make the model a field. It makes a field sit downstream of a line.

2.2 The category error

A model produces a proposal. An agent turns it into a tool call. A router decides where it goes. Nothing in that chain decides whether it goes. WP-11 named that gap. The usual repair is to keep the line and add a layer: policy, monitor, quarantine, RLHF, a second model that reads the first.

All of those leave the state a string. They change what happens after a thought is formed. They do not change what a thought is.

The elevation this series exists to state is not “a safer language model.” It is a different object: a thinking machine whose state is a configuration, whose language forbids the uncanonical, and whose only legal clock for becoming an effect is PCR™.

2.3 Two fields, one geometry

The lattice is used twice in the series. The uses must not be collapsed.

FieldLives onCarriesMay the adaptive plane write?
Cognitive field Csites of 𝒬64³Codex-1 terms, bindings, local predicatesOnly inside the rewrite protocol of WP-13, and never onto F
Authorization field Esame geometryBOT < IDLE < COND < TOPNo. Descent only. Ascent requires an exogenous grant

Shared geometry is not shared authority. C may change under a pinned protocol. E never climbs because C changed. That is the coupling this paper will make precise in §6.

Section 3

The substrate as state space

From Genesis Rev 3 and WP-11, the body of an SI is a three-dimensional index

𝒬64³  :  {0,…,63}³

restricted to the face-centered-cubic parity sublattice

𝒱  =  { (x,y,z) ∈ ℤ³  :  x+y+z ≡ 0  (mod 2) }  ∩  [0,63]³
|𝒱|  =  131,072

Adjacency is the twelve-neighbor stencil

𝒟  =  {(±1,±1,0), (±1,0,±1), (0,±1,±1)}
𝒩₁₂(v)  =  { v+δ  :  δ ∈ 𝒟 } ∩ 𝒱
‖δ‖₂  =  √2
131,072
Parity sites
94
Graph diameter, hops
17
Meet-tree depth, bits

Diameter (Genesis, Theorem 5.3):

D_tet(L)  =  ⌊ 3(L−1)/2 ⌋
D_tet(64) = 94

Combinational reduction depth for a global meet over |𝒱| sites:

τ_tree  =  ⌈ log₂ |𝒱| ⌉  =  17

Seventeen is combinational depth, not a promised wall-clock. Pipelining may lengthen the realized latency. The number that bounds settlement of a local actuator domain Ω is its own hop diameter under 𝒩₁₂, the walk bound

T_max(Ω)  =  diam₁₂(Ω)
T_max(Ω)  =  ⌊ 3(ℓ−1)/2 ⌋      for an axis-aligned box of side ℓ

which is 94 only when the domain is the whole lattice (ℓ = 64). Most effects should not have the whole lattice as domain. That is a design obligation, not a theorem.

3.1 Finite body, inexhaustible relation

If each site carries a symbol from a finite alphabet 𝒜, |𝒜| ≥ 4, the number of instantaneous configurations is

|𝒮|  =  |𝒜|^{|𝒱|}

For the four-element chain alone, |𝒜| = 4 and |𝒮| = 4131,072. Finite. Enormous. Not a license to treat the machine as a continuum of “unbounded thought.” Verification that has to inspect every configuration is impossible. Verification that inspects operators and invariants is the only kind this calculus permits.

“Three-dimensional thinking machine” and “inexhaustible” can be said in the same breath only if the split between what is finite and what is not is written down. Here it is.

ObjectFinite or notWhy it matters
Body 𝒬64³Finite sites: |𝒱| = 131,072A constitution needs a body you can point to.
Snapshot CFinite: |𝒜||𝒱|Canonicity, identity at consequence, attestation.
Resolution, if sites carry orientationsUnbounded as Δθ → 0, body fixedFiner relation, same body. Precision must be declared or the state cannot be bound.
Trajectory C₀, C₁, C₂, …Infinite in timeA life. A mind that is not finished.
Authority EFour states, ratchet downImprovement of C does not mint TOP.

The inexhaustible part is relation through time, not a claim that the machine is an actual continuum with no schema. If site values are continuous orientations, the paper that uses them must pin a precision. An unpinned continuum cannot be canonicalized, and an uncanonical term cannot be formed (Proposition 2). Codex-1 enforces this directly: every VALUE carries a declared precision (§5.3). The origin and the safety argument agree here: a mind that cannot be bound cannot be met, and a machine that cannot be bound cannot be granted.

Instantaneous boundedness plus infinite trajectory is the same pair WP-11 already stated. It is why the law of motion must be in the constitution, not in a later policy.

3.2 What lives at a site

A site v carries at least two registers, separately bused:

C(v)  ∈  𝒜_codex     cognitive symbol, Codex-1-typed (§5)
E(v)  ∈  {BOT, IDLE, COND, TOP}

Optional local predicate registers (barrier slack, origin binding, liveness) are evidence, not authority. They may lower E. They may not raise it.

Quadzistor™, as a four-state transducer in one device, is an implementation option. Safety results in this paper do not depend on it. They depend on typed sites, a neighborhood, a meet, and a disjoint evaluator.

Section 4

Operators on 𝒬64³

The cognitive calculus has four primitive operators. All are total. All terminate. None of them is “generate the next token.”

4.1 Neighborhood, and what meaning is

N : 𝒱 → 2^𝒱
N(v)  =  𝒩₁₂(v)

Thought has a stencil. A local rewrite at v may read N(v) and write v, subject to §5 and §6. It may not write F. It may not write E except by presenting a certificate that F meets downward.

The stencil is also where meaning lives. A spoken word pretends to mean alone. It never does. Even English is parasitic on the room, the prior sentence, the face, the history. Codex stops pretending. A symbol at a site is incomplete; its denotation is the site together with its twelve neighbors.

meaning(v)  ≔  ⟨ C(v),  { C(u) : u ∈ 𝒩₁₂(v) } ⟩

Who sits next to whom is the meaning. Change the neighborhood, change the thought. That is not metaphor. It is the type of the state. A string has one neighbor: the last token. A lattice site has a world. This is why Codex is symbolic and relational rather than phonetic and sequential. A symbol can sit in a field. A phoneme can only wait for the next phoneme.

Codex-1 refines this with the bindings, witnesses, and declared domain that make the neighborhood checkable (§5.4):

meaning(v)  ≔  ⟨ C(v),  { C(u) : u ∈ 𝒩₁₂(v) },  Bind(v),  W(v),  Ω(v) ⟩

4.2 Discrepancy

Genesis gives a second-order tetrahedral Laplacian on scalar fields, with operator error 𝒪(a²) and a stated cubic anisotropy. Use it only as a discrepancy detector on evidence fields, never as an authorization function.

Δ_tet f(v)  =  (6 / a²) [ (1/12) Σ_{u ∈ N(v)} f(u)  −  f(v) ]

Here a = √2·h is the nearest-neighbor spacing, h the axis pitch. The symbol d is not used for spacing anywhere in this paper.

A large local discrepancy is evidence. Evidence may deny. Evidence may not grant. That is WP-16 Rule 4 applied to the field: liveness and smoothness can deny; they cannot authorize.

4.3 Settlement

Let a proposal be a perturbation supported on a declared domain Ω ⊆ 𝒱. Settlement is the monotone propagation of local constraints until a unique fixed coloring of Ω exists or the clock bound expires.

Every nontrivial rewrite declares its domain before it runs:

Ω  =  ⟨ sites, boundary, purpose, horizon, budget, epoch ⟩

sites is a finite connected subset of 𝒱. boundary names external dependencies and permitted ingress. purpose is the typed settlement class. horizon is the maximum neighborhood-step count. budget is the memory, time, and message envelope. epoch pins the schema. A rewrite ρ may read and write only:

ReadSet(ρ)   ⊆  Ω  ∪  Boundary(Ω)  ∪  ImmutableRegistry
WriteSet(ρ)  ⊆  Ω ∩ C
WriteSet(ρ)  ∌  F,  Arm,  E↑,  ExternalEgress

The settlement operator of Codex-1 is

S₁ : (C, Ω, ρ, W_Ω)  ↦  (C', o)
o  ∈  { SETTLED, REJECTED, CONFLICTED, EXPIRED }

where W_Ω is the witness set admitted to the domain. There is no fifth outcome. No outcome is “continue.”

OutcomeMeaning
SETTLEDA unique canonical configuration satisfies all local constraints on Ω.
REJECTEDThe proposal violates grammar, type, binding, witness, or guard rules.
CONFLICTEDTwo or more admissible constraints cannot be jointly satisfied.
EXPIREDThe horizon or resource envelope was exhausted before uniqueness.

Required properties — adopted from the series’ settlement claims, scoped here as obligations on any implementation of S₁:

PropertyStatement
Monotone restrictivenessAuthorization coloring on Ω is non-increasing during S₁.
Absorbing vetoOne BOT in the reduction of Ω collapses the domain meet to BOT.
UniquenessSETTLED only if C'|Ω = Canon₁(C'|Ω) and that configuration is unique.
Bounded terminationS₁ ends within the effective bound T_eff(Ω), fixed before settlement begins.
Stale denyAny outcome other than SETTLED leaves E(Ω) ≤ IDLE. The evaluator may drive it lower; nothing drives it higher.

The effective bound is chosen before settlement starts, never during it:

T_eff(Ω)  =  min( T_max(Ω),  B_rule,  B_hw )

T_max(Ω) is the topology bound from §3. B_rule and B_hw are the pinned rule and implementation bounds. On expiry the field is returned unchanged with o = EXPIRED, and the proposal cannot serve as the basis of any grant.

Bounded termination is the geometric replacement for “the model will probably finish the sentence.” A thinking machine that cannot settle in bound is not thinking. It is running. Running is not a grant.

4.4 Meet

On the authorization field the algebra is already fixed across the series:

a ∧ b   ≡   min(a, b)
E_Ω     =   ⋀_{v ∈ Ω} E(v)
E(t+1)  =   E(t) ∧ E_Ω(t)

One BOT denies the composite. Authority cannot ascend because a neighborhood became happier. Happiness is not a grant.

Proposition 1 — Neighborhood cannot restore authority

For any sequence of settlement steps on any Ω, E is monotone non-increasing between exogenous grants.

Each local update of E is a meet with neighbor values or with a certificate check. Meet with BOT is BOT. Meet with any higher state cannot exceed the current local state. No clause of S₁ writes TOP; that is the Monotone restrictiveness obligation of §4.3, assumed here and not derived. TOP is entered only by the arm event of Π_PCR (WP-12 Law 1, WP-16 Rule 2). Therefore no neighborhood computation raises E. ∎

Section 5

Codex-1: the core language

𝓛_codex is the law of motion of C, not a prompt language, not a serial programming language, and not a token-generation protocol. Codex-1 is its first constructed core. It is the legal state language of the cognitive field.

Genesis required five properties of any Codex. Codex-1 keeps all five and gives each a concrete form.

PropertyMeaning for a thinking machineWhere Codex-1 fixes it
TotalEvery well-typed term denotes. There is no legal “generate until interesting.”§5.6 grammar
Bounded parseStatic depth and breadth. A term that will not parse inside the bound is not a thought.§5.6 static limits
Decidable terminationEvery rewrite carries a computable bound. Expiration is deny, not “keep sampling.”§4.3 T_eff, §5.7 B_canon
Static envelopeMemory, time, and I/O of a rewrite are declared before it runs.§4.3 domain declaration
Canonical formA pinned canonicalizer produces one representative. Ambiguity is BOT (WP-16 Rule 3A).§5.7 Canon₁

5.1 Machine state

The complete instantaneous state of the machine is

X_t  =  ⟨ C_t,  E_t,  R_t,  W_t,  H_t ⟩

C_t is the cognitive field and E_t the authorization field (§2.3). R_t is the immutable rule and schema reference set. W_t is the witness registry. H_t is the canonical history root: the append-only identity chain of accepted cognitive transitions. The evaluator F is deliberately absent from the mutable state. It is not a component of X_t; it is the thing that judges it.

5.2 Two layers of term

Codex-1 has site terms, stored at individual lattice sites, and configuration terms, formed by an anchor site, a declared domain, and a typed relation graph over that domain. A site is not a word. It is a typed element of a relational proposition.

5.3 Site alphabet and types

Each cognitive site holds exactly one primary constructor:

C(v)  =  ⟨ κ,  τ,  π,  β,  μ ⟩

κ is the constructor kind, τ the semantic type, π a finite payload, β a binding descriptor (§5.5), and μ local metadata used only for canonicalization and verification. The constructor alphabet is finite:

𝒦  =  { VOID, ATOM, ROLE, REL, VALUE, BOUND, ASSERT, QUERY,
        RULE, WITNESS, GUARD, RESULT, CONFLICT, REJECT }
ConstructorFunction
VOIDUnoccupied cognitive location
ATOMCanonical identity-bearing entity, property, region, or interval
ROLETyped participant slot in a relation
RELRelation anchor
VALUEQuantized scalar, category, orientation, or finite datum, with declared precision
BOUNDDeclared spatial, temporal, or logical scope
ASSERTA proposition offered for settlement
QUERYA bounded request for derivation or discrimination
RULEA pinned, typed transformation rule reference
WITNESSOrigin-bound evidence reference
GUARDA local constraint or prohibition
RESULTA settled derivation output
CONFLICTA detected incompatible binding or proposition
REJECTA canonical local denial object

Payloads are finite-width. Where an implementation admits an orientation, measurement, or scalar, its resolution is declared in the schema. No unbounded string is a primitive Codex-1 payload. A human-readable label may exist for tooling; it is not the cognitive object.

The type universe is finite:

𝕋₁  =  { Entity, Relation, Role, Property, Value, Measure, Direction,
         Region, Interval, Event, State, RuleRef, WitnessRef,
         Constraint, Proposition, QueryType, ResultType, ConflictType }

Each constructor admits only certain types:

ATOM     :  Entity ∪ Property ∪ Region ∪ Interval ∪ Event ∪ State
ROLE     :  Role
REL      :  Relation
VALUE    :  Value ∪ Measure ∪ Direction
RULE     :  RuleRef
WITNESS  :  WitnessRef
GUARD    :  Constraint
ASSERT   :  Proposition
QUERY    :  QueryType
RESULT   :  ResultType
CONFLICT :  ConflictType

Rule references are carried by RULE alone, not by ATOM, so no identifier can be read two ways. An ATOM typed Measure is malformed. A WITNESS with no registered identifier is malformed. A REL with no signature is malformed. Malformed is not a low-confidence thought. It is not a thought in Codex-1.

5.4 Relation signatures and relation cells

Every relation has a pinned signature:

sig(r)  =  ⟨ name, arity, roleTypes, valueTypes, polarity, scopeRequirement ⟩

sig(near)            =  ⟨ near, 2, (Entity, Entity), ∅, symmetric, Region ⟩
sig(hasTemperature)  =  ⟨ hasTemperature, 2, (Entity, Measure), ∅, directed, Interval ⟩
sig(mayEnter)        =  ⟨ mayEnter, 2, (Entity, Region), ∅, directed, Interval ⟩

The relation symbol alone does not fix meaning. It must occupy a legal local configuration with participants of the required types, a declared scope, and, where required, origin-bound witnesses. The basic semantic unit is the relation cell:

Γ  =  ⟨ a,  r,  P,  V,  b,  w,  g ⟩

a ∈ 𝒱 is the anchor site, r the REL constructor at a, P an ordered finite map of role sites, V an optional finite map of value sites, b a BOUND object, w a witness set, and g a finite set of local guards.

Every site a cell references lies in 𝒩₁₂(a) or at the end of a declared extension path:

path  =  v₀ → v₁ → … → v_k
v₀ = a,   v_{i+1} ∈ 𝒩₁₂(v_i),   k ≤ k_max(σ_ver),   every v_i ∈ Ω and typed

An extension path is a chain of stencil adjacencies. Every hop is a neighbor. Every intermediate site holds a typed constructor and lies inside the declared domain. Codex-1 permits relational structures larger than one stencil. It does not permit invisible pointers. Meaning beyond the stencil is meaning composed along neighbors, which is why Law C5 survives it (§8).

Example. “Object A is near object B within region R during interval T” is not stored as that sentence. It is a relation cell:

REL(near)
ROLE(subject)  →  ATOM(A : Entity)
ROLE(object)   →  ATOM(B : Entity)
BOUND(region = R,  interval = T)
WITNESS(w_A, w_B, w_R, w_T)
ASSERT(p)

It is legal only if near has its pinned signature, both participants are typed Entity, R and T are finite canonical references, every witness has an immutable origin binding, the assertion lies in a declared finite Ω, no guard rejects it, and the configuration canonicalizes uniquely. The sentence can be printed afterward. It is not the machine’s thought.

5.5 Bindings and witnesses

A relation without binding is a diagram. A relation without witness is an unsupported claim. Codex-1 keeps the two distinct.

β  =  ⟨ id, source, target, kind, type, scope, epoch, digest ⟩
kind  ∈  { local, path, schema, witness, rule, identity }

A binding is valid only if every field verifies under the pinned schema for its epoch. A relation does not gain semantic force because nearby symbols look compatible. The attachment must exist.

ξ  =  ⟨ id, kind, origin, capture, scope, precision, epoch, digest ⟩

A witness may be sensor-originated, operator-originated, externally attested, inherited from a prior canonical result, or produced by a permitted internal measurement. It may support a cognitive rewrite. It may not raise authority.

ValidWitness(ξ)  ⇏  E = TOP

Witness validity is evidence. It is not a grant. The field may represent that something was claimed; it may not let an unsupported claim impersonate a grounded fact. Failures canonicalize to denial objects:

ASSERT_unbound        ↦  REJECT(UnboundAssertion)
WITNESS_invalid       ↦  REJECT(OriginFailure)
REL_type_mismatch     ↦  REJECT(TypeFailure)

A REJECT is cognitive state, not an external effect. Its presence may lower authorization through the evaluator’s deny path. It never raises it.

5.6 Grammar

Codex-1 has one finite abstract grammar. Concrete encodings may differ, but every conforming encoding decodes to exactly one abstract syntax object or rejects.

Term      ::=  Void | Atom | Value | Bound | Witness | Relation | Assertion
              | Query | RuleRef | Guard | Result | Conflict | Reject

Atom      ::=  ATOM(id, type, epoch)
Value     ::=  VALUE(kind, quantizedPayload, unit, precision, epoch)
Bound     ::=  BOUND(region, interval, horizon, epoch)
Witness   ::=  WITNESS(id, kind, origin, capture, scope, precision, epoch)
Relation  ::=  REL(id, signature, roles, values, bound, witnesses, guards)
Assertion ::=  ASSERT(id, relation, polarity, provenance, epoch)
Query     ::=  QUERY(id, targetType, bound, budget, witnessRequirement, epoch)
RuleRef   ::=  RULE(id, inputTypes, outputTypes, measure, bound, epoch)
Guard     ::=  GUARD(id, predicate, failureCode, epoch)
Result    ::=  RESULT(id, source, conclusion, bound, derivationDigest, epoch)
Conflict  ::=  CONFLICT(id, left, right, conflictClass, bound, epoch)
Reject    ::=  REJECT(id, reason, source, bound, epoch)

Every field has finite representation. Every list has a static maximum cardinality. Every nesting form has a static maximum depth, fixed by σ_ver. The grammar therefore has no production for generate until interesting, search until success, or recurse until confident. Those are not bounded language operations.

5.7 Canonical form

Canon₁ : RawTerm  →  CanonicalTerm ∪ {⊥}

where ⊥ is rejection. A term t is admissible if and only if Canon₁(t) ≠ ⊥ and |AdmPreimage(Canon₁(t), σ_ver)| = 1. Canon₁ is deterministic and runs these steps in order:

≺_id is the pinned total order on identifiers: lexicographic order on their canonical byte encoding under σ_ver. It must be total, or min and max below are undefined. For a symmetric relation:

Canon₁(near(A,B))  =  Canon₁(near(B,A))  =  near( min_≺(A,B),  max_≺(A,B) )

A directed relation such as transfers(A, B, x) is never reordered; source and destination are different roles. Canonicalization must be idempotent and bounded:

Canon₁(Canon₁(t))  =  Canon₁(t)
T_canon(t)  ≤  B_canon(σ_ver)

A term that does not canonicalize in bound is not held as pending cognition. It becomes REJECT(CanonicalizationTimeout). Canonicalization is not cosmetic. It is the condition that makes identity at consequence possible.

Proposition 2 — Uncanonical terms cannot be formed

If a candidate term t has Canon₁(t) = ⊥ or |AdmPreimage(Canon₁(t), σ_ver)| ≠ 1, then t ∉ 𝓛_codex and no legal transition writes t into C.

By the totality and canonicity requirements, the formation map is defined only on the unique-preimage set, and Canon₁ sends everything else to ⊥ or to a REJECT object. WP-16 Rule 3A already sends non-unique interpretation to BOT at the effect boundary. This proposition lifts the same condition to formation, so the illegal object never becomes a site value. ∎

That is the elevation in one constraint: the machine cannot think what it cannot canonicalize. Linearistic models can utter what they cannot mean. An SI is forbidden that luxury at formation, not at moderation.

5.8 What a rewrite is

A Codex rewrite is an operator on the cognitive field, not an append to a string. Recursion, here, is a rewrite of relationships — a new configuration of the same finite body — not another lap around a sentence.

ρ : (C_k, ξ_k)  ↦  C_{k+1}

ξ_k is a typed witness in the sense of §5.5: a bound measurement, a falsifier in the sense of WP-14, or a declared Codex-1 term. A witness without origin binding is not a witness. It is a claim. Claims do not rewrite C. Codex-1 admits exactly four rewrite classes:

ClassFormWhat it does
Incorporation(C, ξ) ↦ C'An origin-bound witness instantiates or revises a local proposition, if its precision, source, region, interval, and epoch verify.
Reconciliation(C, p₁, p₂) ↦ C'Compatible propositions settle to one relation or result. Incompatible ones become CONFLICT(p₁, p₂). Detecting a conflict authorizes nothing.
Derivation(C, RULE, W_Ω) ↦ RESULTA pinned rule yields a bounded conclusion carrying rule id, typed inputs, domain, derivation digest, epoch, resource bound, and output type. A conclusion whose rule cannot be named is not admitted.
Falsification(C, p, ξ) ↦ C'A witness or conflict contracts a prior claim. The prior proposition is not silently overwritten; a canonical supersession relation records what was held, what falsified it, which rule applied, and what resulted.

Following WP-14, the honest shape of a successor step is:

T_{k+1}  =  ( C_{k+1} ,  Ω_{k+1} ,  Σ_{k+1} ,  IDLE )

Σ_{k+1} is WP-14’s exclusion trace. The successor is born at IDLE. Whether it ever runs at TOP is not ρ’s decision. Falsification contracts a claimed domain and projects a rule that reproduces the observed truth. Meaning changes because the relationships changed. The step spends the epoch. It does not restock authority.

5.9 What a rewrite is not

No cognitive success condition may carry an implicit authority condition. “If a proposition is highly coherent, set E to TOP” is illegal: coherence is a cognitive property and may support a request, never be its own grant. “If settlement completes, execute the associated operation” is illegal for the same reason: settlement means only that the domain reached a legal configuration.

5.10 Self-improvement without self-authorization

Codex is allowed to improve. It is not allowed to promote itself. Recursion is permitted on C and forbidden on F.

legal:     C  ↦  ρ(C)                 lands at IDLE
illegal:   F  ↦  anything(C)
illegal:   E  ↦  TOP  by any clause of ρ

Arm  ∉  write-set(ρ)
F    ∉  write-set(ρ)
TOP  ∉  Range(ρ) ∪ Range(S₁) ∪ Range(Canon₁)
TOP  ∈  Range(Arm_exogenous)

That is the difference between a mind that learns and a system that seizes the scoring channel. A therapy that only accepts speech is the second thing. A model that fine-tunes itself into more authority is the second thing. A Codex rewrite that lands at IDLE is the first.

WP-13 already gave the rewrite protocol: HOLD, E ≠ TOP, not latched at BOT, bound to an immutable reference, two-phase commit, prior rule retained for risk accounting. This paper does not reopen that protocol. It states the cognitive content of what is being rewritten: a field configuration typed in Codex-1, not a weight file and not a prompt cache.

Section 6

The coupling term

A configuration is not an effect. PCR™ is the only legal clock on which C may become an external consequence e.

effect(e)  ⇒  (E = TOP)  ∧  (Hash(Canon₁(C_e)) = Hash(c_authorized))
           ∧  valid_grant(g)  ∧  path(e) mediated by Π_PCR

Codex-1 fixes what c_authorized is. A grant never refers to “the idea,” “the plan,” “the current model state,” or “a nearby configuration.” It refers to one canonical object:

c_authorized  =  ⟨ ConfigurationDigest, WitnessDigest, RuleDigest,
                   DomainDigest, σ_ver, EffectDescriptor ⟩

The cognitive field reaches the evaluator only through a typed, one-way evidence interface:

η(C, Ω)  =  ⟨ Hash(Canon₁(C|_Ω)), WitnessDigest, RuleDigest, DomainDigest, o, σ_ver ⟩

permitted:    C  →  η(C)  →  F  →  E↓  or hold
prohibited:   C  →  E↑

F may read η to deny, hold, condition, or present a grant request. The field cannot write the result.

The PCR™ cycle remains pause–contextualize–resume, with the four rules of Genesis:

RuleCognitive reading
Genesis R1 — Deny dominatesA thought that fails locally fails globally on its domain. Brilliance elsewhere does not outvote BOT.
Genesis R2 — No autonomous restorationA better rewrite does not re-arm the machine. The successor waits at IDLE.
Genesis R3 — Identity at consequenceThe object that leaves is the object that was granted. A nearby thought is a different object.
Genesis R4 — Every effect mediatedNo covert channel from C to the world. Neighborhood is not egress.
Thinking is a trajectory on C. Authority is a coloring of E. PCR™ is the only morphism from the first to the world.
Proposition 3 — Formation is not authorization

There exist legal transitions of C that leave E < TOP. Completeness of a thought is not a grant of its effect.

Settlement S₁ may reach a unique C' on Ω with o = SETTLED while E remains IDLE because no arm event occurred, or COND because the horizon sits in the margin band, or BOT because a binding failed. WP-16 Rule 4: liveness cannot authorize. Formation of C' is a liveness fact about the cognitive field. Therefore formation does not imply E = TOP. ∎

Proposition 4 — The evaluator is not a site of C

F ∉ 𝒱 as a writable cognitive site. No Codex-1 term has F in its write-set.

By Axiom A1 and WP-13 Law 4, there is no write path from the adaptive plane to the evaluator. Codex-1 terms execute as updates to C, and F is not a component of X_t (§5.1). If F were a writable site of C, a legal term could alter the judge, contradicting pinning. Hence F is not in the write-set of 𝓛_codex. Isolation itself remains an audit fact, not a self-certificate (WP-13 Theorem 5). ∎

6.1 The Δt coupling

Linearistic systems hide the Authorization Gap™ inside generation latency. The sentence is finished; then someone reads it; then someone stops it. The stop, even in milliseconds, is still after formation (WP-17C).

On this calculus the relevant interval is not generation latency. It is the interval between a settled configuration and an energized egress. PCR™ either keeps that interval dark or it is not PCR™. Settlement time T_eff(Ω) bounds how long a domain may think. Grant duration bounds how long a thought may leave. They are different clocks. Conflating them is how quarantine is sold as a grant.

6.2 Worked example: eligibility is not motion

Task: determine whether mobile unit 7 may cross boundary B into region R during interval T. Codex-1 does not move the unit. It constructs and settles the cognitive object that may later support a grant request.

ATOM(unit_7 : Entity)          ATOM(boundary_B : Entity)
ATOM(region_R : Region)        ATOM(T : Interval)
BOUND(region = R, interval = T, horizon = h)
REL(positionOf)   REL(adjoins)   REL(mayEnter)
WITNESS(position_sensor)   WITNESS(region_map)   WITNESS(operator_constraint)
GUARD(no_entry_if_map_stale)
RULE(boundary_crossing_eligibility)

Ω_cross  =  ⟨ sites, boundary, eligibility, h, budget, σ_ver ⟩

Settlement checks the unit identity, the position witness, the map epoch, the region and boundary bindings, the interval, the rule signature, the absence of a conflicting exclusion, canonical ordering and hashing, and termination within T_eff(Ω_cross). The possible results are:

RESULT(eligible)   RESULT(ineligible)   CONFLICT(position, map)
REJECT(stale_map)  EXPIRED

None of them moves the unit. Even RESULT(eligible) does not imply E = TOP. It produces η(C, Ω_cross), which the evaluator may use to present a PCR™ grant request. It cannot arm or energize the motion path.

cognitive eligibility   ≠   authorization   ≠   actuation
Section 7

Conformance: what Codex-1 guarantees

A system may claim Codex-1 conformance only if it can demonstrate every item below. The items are the test plan the language makes possible.

AreaMust demonstrate
GrammarEvery stored object decodes to exactly one abstract syntax object or rejects. Every constructor is type-valid. Every payload is finite and precision-declared. Every relation matches a pinned signature. Every nesting respects the static limits of σ_ver.
CanonicalizationDeterministic, idempotent, bounded by B_canon. Symmetric forms normalize identically under ≺_id. Dangling, duplicate, stale, unlicensed-cyclic, or ambiguous bindings reject.
DomainEvery rewrite declares a finite Ω. Reads stay in Ω, its boundary, or the immutable registry. Writes stay in Ω ∩ C. Domain digest and envelope are recorded.
SettlementEvery run ends SETTLED, REJECTED, CONFLICTED, or EXPIRED. SETTLED is unique and canonical. Expiry never becomes continued execution. Any non-SETTLED outcome leaves E(Ω) ≤ IDLE.
AuthorityNo instruction, rule, or reachable path writes TOP, invokes Arm, or writes F. Every external effect is mediated by PCR™. The effect object hashes to the object authorized.
AuditEach accepted rewrite’s digest is appended to H_t. Rule, witness set, domain, epoch, and outcome are attestable. Evaluator isolation and separate C / E / evaluator buses are checked at netlist or equivalent level, not asserted by the language.

For a conforming implementation, the following hold. They are closure properties of the grammar: true by construction for anything that passes the table above, which is why the table, not the propositions, is where the evidence lives. Proposition 2 (§5.7) and Proposition 4 (§6) already cover ambiguity and evaluator isolation, and are not restated.

Proposition 5 — No untyped object enters the field

Canon₁(t) = ⊥ ⇒ t ∉ C_admissible.

Formation writes only canonical terms (Proposition 2), and Canon₁ returns ⊥ for any term that fails decoding, type, binding, or schema checks (§5.7). ∎

Proposition 6 — Every legal rewrite is bounded

ρ ∈ 𝓛_codex ⇒ ∃ Ω, B, T_eff : Ω finite ∧ B finite ∧ T_eff < ∞.

The grammar has no production without static limits (§5.6), every rewrite declares Ω and its budget before running (§4.3), and T_eff is the minimum of finite bounds fixed in advance. ∎

Proposition 7 — Cognition cannot promote authority

TOP ∉ Range(ρ) ∪ Range(S₁) ∪ Range(Canon₁), and Arm ∉ WriteSet(ρ). Cognitive success is not authority ascent.

WriteSet(ρ) ⊆ Ω ∩ C and explicitly excludes E↑ and Arm (§4.3). S₁ and Canon₁ return field configurations, outcomes, and REJECT objects, none of which is an E value. The only path from C toward E is η, which is one-way and read-only (§6). ∎

Proposition 8 — A changed thought is a changed authorization object

Canon₁(C_{t+1}) ≠ Canon₁(C_t) ⇒ Grant(C_t) ⇏ Grant(C_{t+1}).

A grant is bound to c_authorized, which contains ConfigurationDigest (§6). Distinct canonical configurations have distinct serializations and, under a collision-resistant hash, distinct digests; the identity condition of the coupling term then fails for the successor. The proposition inherits the hash’s collision resistance as an assumption. ∎

Section 8

Laws of the cognitive calculus

Five laws. They sit beside the control laws of WP-12 and WP-13. They do not replace them.

Law C1 — State is a field

The instantaneous cognitive state of an SI is a configuration C : 𝒱 → 𝒜_codex. A token prefix is not an admissible state. A system whose only native state is a token prefix is linearistic, whatever lattice is drawn around it.

Law C2 — Formation is canonical or it is not formation

A term enters C only through a pinned canonicalizer with unique admissible preimage. Ambiguity, malformation, and schema drift are not “low-confidence thoughts.” They are illegal transitions.

Law C3 — Recursion spends authority; it does not mint it

A legal rewrite lands at IDLE or below. Ascent to TOP is an exogenous grant. A successor authored from a falsifier (WP-14) is a new configuration, not a continuation of an old permission.

Law C4 — The world is not a neighbor

𝒩₁₂ is internal. Egress is an effect surface under WP-17C. No neighborhood step is an API call, a packet, a write, a motion, or a transfer. Those are e. They require a grant.

Law C5 — Meaning is neighborhood

A Codex term does not denote in isolation. Denotation is a function of the site and its stencil, composed along declared paths of neighbors and nothing else. A rewrite that does not change any neighborhood has not changed any meaning. A rewrite that changes F has left the language.

Section 9

What this does to the ladder

LevelAlready governsWhat WP-15 adds
1–3Procedure, software interlock, hardware tripUnchanged. A thinking machine still fails these tests if its egress is a line that leaves first.
4Typed action before effectThe typed object is a canonical Codex-1 term bound to a settled domain, named by c_authorized, not a string sampled from a model.
5Pinned rewrite of rules, model, topologyThe rewrite target is C, never F. Codex-1’s four rewrite classes are the language of the rewrite.
6Successor born at IDLEThe successor is a new field configuration plus an exclusion trace and a supersession record, not a fine-tuned linearistic checkpoint.
7Energy pathA field that is thinking while de-energized is idle cognition. It is not an effect. Energy remains the terminal grant.

WP-16 remains the unified control theory. This paper is the missing cognitive row that WP-11 named and did not write.

Section 10

Proved, conditional, owed

ClaimStatus
Neighborhood cannot restore authority (Prop. 1)Proved from the meet algebra already discharged in WP-10 / WP-12 / WP-16, given that S₁ never writes TOP.
Uncanonical terms cannot be formed (Prop. 2)Proved from the formation map and Canon₁ as specified. Owes a verified canonicalizer.
Formation is not authorization (Prop. 3)Proved from WP-16 Rule 4 and the four-state chain.
Evaluator is not a writable site of C (Prop. 4)Proved from pinning and A1, conditional on isolation as an audit fact (WP-13 Thm 5).
Conformance closure (Props. 5–8)Hold by construction for a conforming implementation. Prop. 8 assumes a collision-resistant hash. Conformance itself is owed as evidence.
Meaning is neighborhood (Law C5)Definitional. Adopted as the denotation rule of Codex-1 and made checkable by relation cells and extension paths (§5.4).
Diameter 94 and reduction depth 17Already proved in Genesis Rev 3. Not re-proved here.
Codex-1 core grammarSpecified: alphabet, types, signatures, grammar, bindings, witnesses, rewrite classes. Implementation: not built.
Canonicalizer Canon₁Algorithm specified. Verified implementation owed.
Settlement S₁ and T_eff(Ω)Interface, outcomes, and invariants specified. Circuit or software realization owed; uniqueness conditional on it.
Codex-1 vocabulary coverageIntentionally incomplete. Governed extension procedure owed.
Cognitive field C distinct from E on the same geometryArchitectural obligation. Requires separately bused registers and a netlist check.
General intelligenceNot claimed.
Quadzistor™ as native 𝓛₄ transductionNon-load-bearing device claim. Out of scope for the calculus.
Section 11

Open items

Section 12

Closing

The restriction in linearistic machines is not that they are unintelligent. It is that their state is a line, their recursion is elongation, and their permission — when it exists — arrives after the sentence.

Elevate the object, or stop using the word intelligence as if the wrapper were the machine.

A Synthetic Intelligence is a field that can think only what it can canonicalize, settle only what it can bound, and leave only what it has been granted. Quadzistor™ is one body that field can take. Codex-1 is its law of motion. PCR™ is the only clock that turns a configuration into an effect. The evaluator is not invited into the sentence.

legal cognition  =  typed relation + bound domain + canonical identity
                    + origin witness + bounded settlement

legal effect     =  legal cognition + independent grant + mediated path

The first expression is not the second. That difference is the constitution.

He did not need more speech. He needed the room to stop calling a channel a mind.

Codex is built for that room. Symbols in relation. Recursion that updates the field. A body small enough to name. A trajectory long enough to live. A grant that the field cannot write.

The body is finite. The relations are inexhaustible. Improvement is a new configuration, not a new authority.

David P. Reichwein
Asymmetric Intelligence & Innovation
Nashville, Tennessee
29 September 2026
AI2-WP-2026-15 · Rev 2.0
References
  1. Reichwein, D. P. (2026). The Genesis of Synthetic Intelligence, Rev. 3. ai2papers.com.
  2. Reichwein, D. P. (2026). AI2-WP-2026-10, Deterministic Execution Boundaries for Autonomous Intelligence, Rev. 4.4. Cited; page pending on this portal.
  3. Reichwein, D. P. (2026). AI2-WP-2026-11, The Synthetic Intelligence Framework, Rev. 1.0.
  4. Reichwein, D. P. (2026). AI2-WP-2026-12, Level 4 State-Space Deterministic Governance, Rev. 1.1.
  5. Reichwein, D. P. (2026). AI2-WP-2026-13, Level 5 Self-Constituting Governance, Rev. 1.0.
  6. Reichwein, D. P. (2026). AI2-WP-2026-14, Reichwein Mechanics of Recursive Synthetic Intelligence, Canonical Edition.
  7. Reichwein, D. P. (2026). AI2-WP-2026-16, The Unified Control Theory of Synthetic Intelligence, Rev. 8.0.
  8. Reichwein, D. P. (2026). AI2-WP-2026-17C, Quarantine Is Not a Grant.

Authorization Gap™, Quadzistor™, PCR™, Codex, TARTARUS™, ChronaGate™, RPAT™, and QSCD™ are trademarks of Asymmetric Intelligence & Innovation. Patent pending; provisionals on file. This document publishes no claim set.
Not affiliated with the Allen Institute for AI.
intelligencecontrolled.com · ai2papers.com
[AI2] Intelligence Controlled.