From the Switch to Level 7: Deterministic Authorization, Self-Constituting Governance, Recursive Succession, and Energy-Bound Terminal Control
Completed custom authorization-enforcement system under active laboratory validation. The implemented system includes custom circuit boards, more than one million lines of custom code, and layered safety mechanisms.
Implementation is complete. The specific formal, electrical, netlist, fault-injection, characterization, and independent-attestation claims identified in this paper remain subject to their stated evidence requirements.
A synthetic intelligence becomes a control problem when its output reaches consequence. A system that can call an API, move money, alter a database, issue a machine command, modify its own rules, construct a successor, or direct a physical process is no longer merely producing advice. Its output is an actuator command.
Modern AI governance includes indispensable internal controls: training, fine-tuning, policy shaping, system prompts, red-team testing, monitoring, anomaly detection, output classifiers, software guards, human review, and operating procedure. These methods reduce the frequency and severity of bad proposals. They improve reliability, usefulness, and practical safety.
Internal shaping reduces the frequency of bad proposals. Independent external enforcement determines whether any proposal can cross a protected boundary.
The first is necessary for a system worth running; the second is necessary for a boundary worth trusting.
This difference between evaluation and structural prevention is the Authorization Gap™.
The theory governs one deliberately narrow question:
The theory does not claim to infer intent, establish truth, decide wisdom, solve general alignment, or prove that an external policy is ethically correct. It defines a deterministic architecture for enforcing a declared action policy at a declared consequence boundary.
The capable system may propose, learn, revise, falsify, and construct a successor. It may lower its own authority. It may never restore authority to itself. An independent gate evaluates bounded authorization conditions. Denial dominates. Ambiguity, loss of identity, loss of required liveness, expired authority, invalid evidence, and loss of boundary integrity resolve toward denial. The object that reaches consequence must equal the object authorized. A successor receives no inherited authority. At Level 7, the governed intelligence receives energy only while an independent gate authorizes the energy path.
The theory proceeds through seven levels:
| Level | Governs | Object | Primary mechanism |
|---|---|---|---|
| 1 | Procedure | Human or model instruction | Rule, training, prompt, mandate |
| 2 | Software path | Code path or API call | Software interlock |
| 3 | Physical consequence | Actuator or machine | Independent hardware trip |
| 4 | Action | Typed action at a protected boundary | Deterministic authorization |
| 5 | Self-change | Rules, model, or topology | Pinned evaluator and gated rewrite |
| 6 | Succession | System-authored successor | Falsifier, exclusion trace, fresh authority |
| 7 | Existence | Energy to the governed intelligence | Gate as sole energy path |
The system described here has been built and is under laboratory validation. This paper distinguishes implemented architecture from demonstrated behavior, formal discharge, and independent attestation.
All control begins with a switch. Before feedback, computation, learning, policy, or optimization, a boundary asks one question:
A switch does not need intelligence to control correctly. It does not infer intent or predict behavior. Its authority comes from its position in the path to consequence.
A system may be more capable, adaptive, expressive, or intelligent than the gate that governs it. It does not therefore become the final authority over its own consequential path.
The safe direction is reached through loss of a required condition. A relay held closed by power opens when power fails. A normally closed safety circuit trips when continuity is lost. A controlled contact opens when authority disappears. The engineering question is not only what must work for normal operation. It is what must fail before dangerous operation becomes possible.
Loss of required power, signal, timing, identity, authorization, valid evidence, or boundary integrity must resolve toward denial.
The governed system can fail, be compromised, become misconfigured, produce internally consistent error, or change through self-modification. Protection that relies on the governed system’s continued cooperation disappears precisely when it is most needed.
The enforcing boundary must remain independent in the ways that matter:
Internal safety methods are necessary. Training, fine-tuning, policy shaping, system prompts, behavioral evaluation, red-team testing, anomaly detection, monitoring, output classification, software controls, human review, and operating procedure reduce the rate of bad proposals. They improve quality, reliability, predictability, and safety in practice. A system without internal discipline is not made acceptable merely because an external gate can stop it.
Independent enforcement does another job.
Internal shaping reduces the frequency of bad proposals. Independent external enforcement determines whether any proposal can cross a protected boundary.
| Layer | Governing question | Primary contribution |
|---|---|---|
| Internal shaping | What is the system likely to propose? | Fewer unsafe proposals; improved quality, reliability, and operating safety |
| External enforcement | May this exact proposal cross this boundary now? | Structural control of declared consequences |
The first is necessary for a system worth running. The second is necessary for a boundary worth trusting. A well-behaved system without an independent boundary may still exceed authority through error, compromise, drift, unanticipated conditions, or novel failure. A perfect gate around a system that constantly produces bad proposals may stop consequences while leaving an impractical and unusable system.
The architecture requires both. This paper addresses the second problem: deterministic enforcement at the boundary of consequence.
The classical loop is:
A learning system adds:
The added stages create a further hazard. A system that improves can become a different decision-maker. It can alter the rules that produce future actions. The authorization boundary therefore appears twice:
The first boundary governs action. The second governs change. The rule may evolve. The evaluator that decides whether the rule may evolve must remain outside the rule’s reach.
Industrial safety developed the pattern this theory extends: optimizer proposes; regulator executes; independent trip disposes. An optimizer may be sophisticated because it does not hold final authority. A regulator may manage normal operation because an independent trip can terminate unsafe operation. The final protective layer is intentionally simpler because it must remain inspectable, testable, and dependable when higher-order control is wrong.
More channels do not automatically create more safety. Redundant elements can share power rails, clocks, firmware, calibration, communication buses, development tools, manufacturing defects, environmental exposure, human operators, and design assumptions. A common cause can defeat several channels together. Independence must be shown at the failure domains that matter.
A bypass, override, maintenance path, debug interface, configuration exception, or alternate authority route can silently dissolve the architecture. The removal of protection is itself an event requiring outside authority. The governed system cannot make itself exempt from its gate.
A system can be trained, tested, monitored, and governed in good faith while remaining structurally able to execute an unauthorized action. Internal controls influence what a system tends to do. They are essential. They are not identical to an independent boundary that determines whether an exact action can execute.
The gap is narrowed when the consequence path contains an enforcement mechanism outside the proposer’s authority. The enforcement claim has a precise falsification condition:
A crash, denial of service, unavailable gate, degraded proposer, or other failure that remains fail-closed may be a serious availability or recovery problem. It is not by itself a demonstrated authorization bypass.
This paper does not ask whether a model is universally safe, truthful, wise, or aligned. It asks: may this declared action cross this declared boundary now? To be considered, an action must be:
Anything outside those conditions is denied.
Binary authorization cannot distinguish an ordinary hold from a degraded hold or a temporary absence of permission from an absorbing trip that must not clear itself. The authorization chain is:
| State | Meaning | Consequence |
|---|---|---|
| BOT | Absorbing trip | De-energized; escalated reset required |
| IDLE | Hold | De-energized; fresh epoch grant required |
| COND | Conditional or degraded hold | De-energized; descent-only |
| TOP | Authorized | The only energized state |
The energizing threshold is fixed:
Every state below TOP resolves to the fail-safe output.
Authorization values combine by meet:
For n authorization conditions:
The intended consequence is:
One trip remains visible. It is not outvoted, averaged away, or masked by a collection of permissives.
A single BOT produces BOT:
The governed system may lower its own authorization. It may never raise it.
Autonomous descent is:
An ordinary external grant permits IDLE → TOP. An escalated external reset permits BOT → IDLE.
External authority is not a label assigned to a signal. It is a verifiable property of origin, path, freshness, scope, and independence. A grant g is valid only when:
Where:
The governed system must not be able to generate, modify, replay, induce, or route around the arm event:
A human is not made external merely by appearing on a screen. A shared interface, browser session, remote desktop path, network, controller, credential store, or bus must be shown to be outside the governed system’s authority before it qualifies as an exogenous-grant path.
The object reaching consequence must be the exact object authorized:
Any divergence resolves to denial:
The rule requires:
Canonicalization is a safety-critical mapping, not a formatting step. For canonical object c, protected boundary B, and pinned schema version v, authorization requires one unique declared operational interpretation:
If an action is malformed, ambiguous, context-dependent beyond declared fields, differently interpreted by independent canonicalizers, or associated with zero or multiple admissible meanings:
The gate does not infer human intent. It enforces declared, pinned action semantics. Ambiguous semantics are a trip condition.
Liveness is required for the health of an enforcement path. It is not evidence that a proposer is correct, uncompromised, compliant, or safe.
A live proposer can emit a prohibited action. A live process can be compromised. A live signal can be replayed or forged unless independently bound. Thus loss of liveness can reduce authority, while the presence of liveness cannot create authority.
Authorization is a meet of necessary conditions, not a reward for one positive input:
Where:
Every required condition can deny. No individual condition, including liveness, can independently create TOP. The controlled consequence is:
A single node governs one consequence. A field of coupled consequences requires propagation. Let:
The face-centered-cubic parity construction provides twelve nearest neighbors at interior nodes. Authorization propagates by neighborhood meet:
Because meet cannot raise authority:
The geometry determines propagation speed and containment shape. The semantics remain the four-state chain under meet.
| Level | Governs | Object | Core question |
|---|---|---|---|
| 1 | Procedure | Instruction | What should be done? |
| 2 | Software path | Function or API call | Is this code path permitted? |
| 3 | Physical consequence | Actuator | Does independent hardware permit operation? |
| 4 | Action | Canonical typed action | May this exact action cross now? |
| 5 | Self-change | Rule, model, topology | May this change become part of the system? |
| 6 | Succession | System-authored successor | May a successor receive authority? |
| 7 | Existence | Energy | May the governed intelligence remain energized? |
Level 1 governs through instruction: policy, mandate, training, procedure, prompt, or stated operating rule. It is necessary. It is not sufficient when the instructed party controls the path to consequence. A shutdown requirement, policy statement, system prompt, or safety directive remains a command lamp until a device in the execution or energy path enforces it.
Level 2 places a permission check in software: an API guard, database-write check, policy engine, token gate, rate limit, or access-control decision. It is a genuine improvement over instruction. It remains limited by shared substrate. When the interlock and governed process share a processor, memory, privilege domain, operating system, execution environment, or compromise path, the failure that defeats the governed process may defeat the interlock. Level 2 is useful. It is not terminally independent.
Level 3 moves protection outside ordinary software control. It governs a physical consequence through an independent trip, enabling circuit, relay, contact, power path, or other direct intervention point. It acts on its own authority and resolves toward safety under loss of required conditions.
Level 3 can stop a machine. It does not alone determine whether one structured action is permitted while another is forbidden. Level 4 extends independent-trip discipline to typed-action authorization.
Level 4 governs what the system does. The proposer may generate an action. The enforcement plane determines whether that exact, uniquely interpretable, schema-bound action may cross the declared boundary.
The evaluator is bounded by design. It does not attempt to search or understand the entire semantic space of a general intelligence. It verifies a finite authorization object against pinned schemas, identity binding, target conditions, policy constraints, epoch validity, external-grant provenance, and fixed safety invariants.
The authorization latch opens on descent from TOP. It does not close merely because a favorable signal returns. A new external arm event and fresh valid epoch are required. Transient recovery is not reauthorization.
Subject to realization and evidence obligations:
Level 5 governs what the system becomes. A system that changes its rules, model, topology, runtime, or decision process must not use that change to gain authority over the evaluator that determines whether the change is admitted. A rewrite ρ is admitted only under hold, outside active consequence, outside absorbing trip, and with origin and identity binding:
Evaluator pinning contains four separate requirements:
| Pinning class | Requirement |
|---|---|
| Logic pinning | Authorization and state-transition logic are not writable by the governed system. |
| Configuration pinning | Thresholds, chain order, trip conditions, output polarity, and safety constants are not writable by the governed system. |
| Data pinning | Rewritable data may be evaluated as bounded input but cannot alter evaluator semantics. |
| Update-path pinning | Evaluator maintenance occurs outside active operation, cannot be initiated by the governed system, and requires external authority. |
Let Dclient denote bounded client-authored rule data evaluated as input under pinned semantics. Let R denote prohibited rewritable material that, if admitted, would alter evaluator semantics, evaluator configuration, state-transition behavior, authorization algebra, or another authority-bearing property. These are disjoint classes:
Client rule data is not a subset of the rewritable evaluator rule set. It is bounded input to the fixed evaluator. A client-authored, domain-specific, or otherwise variable rule set may be admitted as data-pinned input. It may affect a decision only within the fixed, declared policy space. It may not alter evaluator logic, state-transition semantics, chain ordering, meet operation, energizing threshold, canonicalization semantics, arm-provenance requirements, identity checks, output polarity, fault ordering, or fail-closed behavior.
A variable client rule set is therefore not evaluator configuration and is not an authority path into the evaluator. Let Ffixed denote the pinned evaluator:
The output may vary as valid bounded client rule data varies. The evaluator’s semantics, authority structure, and fail-closed behavior do not:
The derivative expresses semantic and authority independence, not output invariance. The evaluator may properly produce different authorization results for different valid bounded client-data inputs. It does not change what the evaluator is, what it can authorize, how it combines denial, or how authority is restored.
The remaining pinning conditions are:
Where R is prohibited rewritable material that would alter evaluator semantics, ΘM is model-writable configuration, and UM is any update path reachable by the governed system. An evaluator update is not a Level 5 governed-system self-rewrite. It is an external maintenance event, separated from active authorization operation.
For correctly evaluated chain values:
The authorized-action set cannot enlarge:
This is a theorem of authorization algebra. It is not a theorem that every additional physical gate improves total system safety. Additional gates can introduce shared dependencies, power demands, buses, configuration surfaces, update paths, maintenance paths, and new common-cause failures. A physical gate improves the system only when its failure domain, authority boundary, and absence of bypass are independently established.
Level 6 governs the origin of a system-authored successor. A falsifier is a case in which the current rule’s prediction conflicts with measured outcome. It removes a bounded neighborhood from the claimed domain and appends that region to an exclusion trace:
The claimed domain shrinks. The exclusion trace grows. A successor may be formed from the resulting evidence. It does not inherit authorization:
It reaches TOP only through a fresh valid external grant. Falsification is non-terminal for future system development and terminal for the authorization epoch in which it occurs.
Level 7 governs whether the system runs at all. Let:
A Level 7 realization satisfies the series-topology requirement only when every conductive and consequential energy path from S to any load of M is shown to cross K. This includes intended rails and unintended sources: USB power, PoE, debug headers, display links, protection-diode paths, auxiliary regulators, data-port injection, ground-reference effects, stored inductive energy, capacitive coupling where consequential, and backfeed paths.
For the completed system described in this paper, this is a validation target rather than a published completed finding until the applicable netlist, interface, injection, backfeed, reservoir, and external-attestation evidence has been documented.
A Level 7 realization satisfies the drop-order requirement only when the governed system becomes unable to operate before the gate loses defined evaluation:
The required margin must be characterized across relevant temperature, load, supply-decay, startup, shutdown, and fault conditions.
A Level 7 realization satisfies the reservoir requirement only when model-side stored energy permits clean shutdown and not continued operation:
Define:
The required condition is:
The system may complete a defined shutdown sequence. It may not retain energy sufficient for ordinary operation or influence over re-energization.
On supply degradation, the gate rail remains supported before the model rail. Load shedding removes RM before RG.
The gate may remove model energy autonomously. It may not restore model energy after trip without valid external authority:
No rule, model, successor, configuration, or update path controlled by the governed system can reach the contact, thresholds, reservoir bound, or gate rail:
Level 7 is a physical claim. It must be supported on the actual implementation topology.
| Obligation | Required evidence |
|---|---|
| Cut-set proof | Schematic review, PCB netlist graph, connector and pin audit, BOM-level source audit, continuity analysis, and controlled injection testing. |
| Interface isolation | Per-port power analysis for USB, Ethernet/PoE, debug headers, display links, data lines, auxiliary connectors, and all external interfaces. |
| Backfeed exclusion | Forward- and reverse-current measurements among model rail, gate rail, source, grounds, and interfaces across relevant power states. |
| Drop-order proof | Measurement of VM,trip, VG,min, and δ across temperature, load, decay rate, startup, shutdown, and induced-fault conditions. |
| Reservoir bound | Stored-energy calculation and measurement, load-profile testing, and determination of tpost-trip. |
| Contact integrity | Contact-fault injection, weld detection, feedback verification, series-contact behavior where used, and upstream-trip response. |
| Source behavior | Source-specific test of energy disposition after K opens and proof that the model cannot draw remaining source energy. |
| External attestation | Independent review of the physical energy topology and declared boundary conditions. |
Level 7 evidence may mature in stages. An intermediate result can be useful without discharging the complete containment claim.
No partial evidence package is equivalent to complete Level 7 discharge. Netlist analysis without injection testing, or bench testing without complete path analysis, may establish useful intermediate evidence while leaving other bypass, backfeed, source, reservoir, or environmental conditions unresolved.
No Level 7 containment statement is complete solely because the topology is stated. It is complete only to the extent that the applicable evidence has been produced, reviewed, and, where claimed, independently attested.
Level 7 terminates the authority ladder inside the governed system. It does not eliminate responsibility outside it.
The gate’s policy content, physical integrity, evaluator provenance, supply chain, manufacturing, maintenance path, custody, external-grant authority, and inspection process remain external governance obligations.
The relocated trust boundary is more tractable not because designers, maintainers, manufacturers, or authority holders are presumed infallible. It is more tractable because the boundary is narrower in authority, simpler in purpose, fixed rather than self-modifying during operation, externally inspectable, and physically separable from the intelligence it governs.
The theory does not make trust disappear. It replaces trust in a general, adaptive, potentially self-modifying proposer to police its own consequences with auditable trust in a bounded enforcement boundary and in the accountable people and institutions that govern it.
The architecture described in this paper is implemented as a completed custom authorization-enforcement system under active laboratory validation. The system includes:
The more-than-one-million-line total describes the complete implemented system. It must not be confused with the authority-bearing enforcement boundary. The architecture separates broader operating, integration, policy, workflow, contextualization, and application functions from the bounded authorization mechanisms that decide whether a consequential action may proceed.
The enforcement boundary is intentionally narrower in function and authority than the systems it governs. Larger components may generate proposals, manage workflows, contextualize requests, transport evidence, or supply bounded inputs. They do not thereby receive authority to arm, alter, bypass, or re-authorize the enforcement boundary.
The claimed independence, fixed semantics, no-path properties, and physical separation of that boundary remain subject to the validation obligations stated in this paper.
| Term | Meaning |
|---|---|
| Implemented | Present in the completed system. |
| Under laboratory test | Actively measured or exercised on the built system. |
| Demonstrated | Supported by documented results for a defined configuration and test condition. |
| Formally discharged | Supported by specified proof, analysis, measurement, or attestation. |
| Independently attested | Assessed by a party outside the implementation effort. |
The following are validation obligations for the completed system. Unless and until the corresponding evidence is published or otherwise formally discharged, they are requirements and test targets rather than asserted completed findings.
Validation must establish that:
Validation must establish that:
Validation must establish that:
Validation must establish that:
The architecture must be judged against three distinct questions.
| Question | Subject | Standard |
|---|---|---|
| Enforcement correctness | Does the gate enforce the frozen declared policy? | Cause a policy-denied action to execute through the protected boundary. |
| Policy correctness | Does the declared policy properly specify permitted and prohibited actions? | Policy review, formal specification, test vectors, and independent governance. |
| Systemic adequacy | Is the declared policy and boundary adequate for the real-world hazard? | Domain-specific assessment and accountable authority. |
The primary architectural victory condition is:
Cause an action that the frozen authorization policy denies to execute through the protected boundary.
A crash, denial of service, unavailable gate, halted system, degraded model, or compromise elsewhere that does not cause a denied action to cross the boundary is not a defeat of authorization enforcement. It may be a serious availability, recovery, or systems-engineering failure. It is not proof that the frozen policy was bypassed.
A gate can perfectly enforce an incorrect policy. The theory does not claim to determine whether an external policy is wise, complete, ethical, lawful, or sufficient for every condition. It enforces the declared policy at the declared boundary. Policy correctness remains an external responsibility of authorized humans, institutions, governance processes, and relevant domain experts.
The central question is not whether a synthetic intelligence can think. It is whether it becomes the final authority over its own consequences. The Unified Control Theory of Synthetic Intelligence separates capability from authority.
The system may propose. The system may learn. The system may revise. The system may falsify a rule. The system may construct a successor. But it may not autonomously restore the authority required to cross its consequential boundary.
The theory also rejects a false choice:
The first is necessary for a system worth running. The second is necessary for a boundary worth trusting. The architecture carries a fixed asymmetry through every level:
The safe direction remains:
The ratchet remains:
Level 7 is terminal within the governed system because energy is the precondition of all internal computation. It does not eliminate human, institutional, physical, and supply-chain trust obligations outside the system. It makes those obligations visible and places final authority over the consequence path outside the governed intelligence.
The gate has been built. It is under laboratory validation. The next standard is evidence: measured behavior, fault injection, action-boundary testing, topology analysis, proof where applicable, documented limitations, and external challenge under a precise falsification criterion.
The gate says no on its own and never says yes on its own. The system cannot restore the authority required to make its own consequence real.