[AI2] ← ai2papers.com  ·  all papers
White Paper25 September 2026AI2-WP-2026-16 · Rev. 8.0Nashville, Tennessee
Asymmetric Intelligence & Innovation

The Unified Control Theory of Synthetic Intelligence

From the Switch to Level 7: Deterministic Authorization, Self-Constituting Governance, Recursive Succession, and Energy-Bound Terminal Control

Status

Completed custom authorization-enforcement system under active laboratory validation. The implemented system includes custom circuit boards, more than one million lines of custom code, and layered safety mechanisms.

Implementation is complete. The specific formal, electrical, netlist, fault-injection, characterization, and independent-attestation claims identified in this paper remain subject to their stated evidence requirements.

Abstract

A control problem at the point of consequence

A synthetic intelligence becomes a control problem when its output reaches consequence. A system that can call an API, move money, alter a database, issue a machine command, modify its own rules, construct a successor, or direct a physical process is no longer merely producing advice. Its output is an actuator command.

Modern AI governance includes indispensable internal controls: training, fine-tuning, policy shaping, system prompts, red-team testing, monitoring, anomaly detection, output classifiers, software guards, human review, and operating procedure. These methods reduce the frequency and severity of bad proposals. They improve reliability, usefulness, and practical safety.

Internal shaping reduces the frequency of bad proposals. Independent external enforcement determines whether any proposal can cross a protected boundary.

The first is necessary for a system worth running; the second is necessary for a boundary worth trusting.

This difference between evaluation and structural prevention is the Authorization Gap™.

The theory governs one deliberately narrow question:

May this exact, typed, uniquely canonicalized action cross this specific boundary at this specific time under a fresh authorization granted from outside the governed system?

The theory does not claim to infer intent, establish truth, decide wisdom, solve general alignment, or prove that an external policy is ethically correct. It defines a deterministic architecture for enforcing a declared action policy at a declared consequence boundary.

The capable system may propose, learn, revise, falsify, and construct a successor. It may lower its own authority. It may never restore authority to itself. An independent gate evaluates bounded authorization conditions. Denial dominates. Ambiguity, loss of identity, loss of required liveness, expired authority, invalid evidence, and loss of boundary integrity resolve toward denial. The object that reaches consequence must equal the object authorized. A successor receives no inherited authority. At Level 7, the governed intelligence receives energy only while an independent gate authorizes the energy path.

7
Levels of control
4
Authorization states
12
Lattice neighbors per node
1M+
Lines of custom code

The theory proceeds through seven levels:

LevelGovernsObjectPrimary mechanism
1ProcedureHuman or model instructionRule, training, prompt, mandate
2Software pathCode path or API callSoftware interlock
3Physical consequenceActuator or machineIndependent hardware trip
4ActionTyped action at a protected boundaryDeterministic authorization
5Self-changeRules, model, or topologyPinned evaluator and gated rewrite
6SuccessionSystem-authored successorFalsifier, exclusion trace, fresh authority
7ExistenceEnergy to the governed intelligenceGate as sole energy path

The system described here has been built and is under laboratory validation. This paper distinguishes implemented architecture from demonstrated behavior, formal discharge, and independent attestation.

The model proposes. The hardware disposes.
Contents
Part I

Foundations

§ 01

The Switch

All control begins with a switch. Before feedback, computation, learning, policy, or optimization, a boundary asks one question:

May energy, execution, data, motion, or authority reach consequence — or not?

A switch does not need intelligence to control correctly. It does not infer intent or predict behavior. Its authority comes from its position in the path to consequence.

Capability ≠ Authority

A system may be more capable, adaptive, expressive, or intelligent than the gate that governs it. It does not therefore become the final authority over its own consequential path.

1.1De-energize to trip

The safe direction is reached through loss of a required condition. A relay held closed by power opens when power fails. A normally closed safety circuit trips when continuity is lost. A controlled contact opens when authority disappears. The engineering question is not only what must work for normal operation. It is what must fail before dangerous operation becomes possible.

Nothing should have to work for the system to stop.

Loss of required power, signal, timing, identity, authorization, valid evidence, or boundary integrity must resolve toward denial.

1.2Protection is not cooperation

The governed system can fail, be compromised, become misconfigured, produce internally consistent error, or change through self-modification. Protection that relies on the governed system’s continued cooperation disappears precisely when it is most needed.

The enforcing boundary must remain independent in the ways that matter:

§ 02

Internal Shaping and External Enforcement

Internal safety methods are necessary. Training, fine-tuning, policy shaping, system prompts, behavioral evaluation, red-team testing, anomaly detection, monitoring, output classification, software controls, human review, and operating procedure reduce the rate of bad proposals. They improve quality, reliability, predictability, and safety in practice. A system without internal discipline is not made acceptable merely because an external gate can stop it.

Independent enforcement does another job.

Internal shaping reduces the frequency of bad proposals. Independent external enforcement determines whether any proposal can cross a protected boundary.

LayerGoverning questionPrimary contribution
Internal shapingWhat is the system likely to propose?Fewer unsafe proposals; improved quality, reliability, and operating safety
External enforcementMay this exact proposal cross this boundary now?Structural control of declared consequences

The first is necessary for a system worth running. The second is necessary for a boundary worth trusting. A well-behaved system without an independent boundary may still exceed authority through error, compromise, drift, unanticipated conditions, or novel failure. A perfect gate around a system that constantly produces bad proposals may stop consequences while leaving an impractical and unusable system.

The architecture requires both. This paper addresses the second problem: deterministic enforcement at the boundary of consequence.

§ 03

The Control Loop

The classical loop is:

Sense → Decide → Act

A learning system adds:

Sense → Decide → Act → Analyse → Improve

The added stages create a further hazard. A system that improves can become a different decision-maker. It can alter the rules that produce future actions. The authorization boundary therefore appears twice:

Decide → [ Authorize ] → Act
Improve → [ Authorize ] → Decide

The first boundary governs action. The second governs change. The rule may evolve. The evaluator that decides whether the rule may evolve must remain outside the rule’s reach.

Sense Decide Authorize Act Authorize Improve Analyse governs action governs change
Figure 1. The two enforcement boundaries in the five-stage learning control loop. One governs whether a proposed action may reach consequence; the other governs whether a proposed modification may reach the decision rule.
§ 04

Independent Protection

Industrial safety developed the pattern this theory extends: optimizer proposes; regulator executes; independent trip disposes. An optimizer may be sophisticated because it does not hold final authority. A regulator may manage normal operation because an independent trip can terminate unsafe operation. The final protective layer is intentionally simpler because it must remain inspectable, testable, and dependable when higher-order control is wrong.

4.1Redundancy is not independence

More channels do not automatically create more safety. Redundant elements can share power rails, clocks, firmware, calibration, communication buses, development tools, manufacturing defects, environmental exposure, human operators, and design assumptions. A common cause can defeat several channels together. Independence must be shown at the failure domains that matter.

4.2Bypass is a safety event

A bypass, override, maintenance path, debug interface, configuration exception, or alternate authority route can silently dissolve the architecture. The removal of protection is itself an event requiring outside authority. The governed system cannot make itself exempt from its gate.

§ 05

The Authorization Gap™

A system can be trained, tested, monitored, and governed in good faith while remaining structurally able to execute an unauthorized action. Internal controls influence what a system tends to do. They are essential. They are not identical to an independent boundary that determines whether an exact action can execute.

Authorization Gap = Evaluated behavior − Structurally prevented behavior

The gap is narrowed when the consequence path contains an enforcement mechanism outside the proposer’s authority. The enforcement claim has a precise falsification condition:

The enforcement boundary is defeated only if an action denied by the frozen authorization policy executes through the protected boundary.

A crash, denial of service, unavailable gate, degraded proposer, or other failure that remains fail-closed may be a serious availability or recovery problem. It is not by itself a demonstrated authorization bypass.

5.1The governed question

This paper does not ask whether a model is universally safe, truthful, wise, or aligned. It asks: may this declared action cross this declared boundary now? To be considered, an action must be:

Anything outside those conditions is denied.

Part II

The Algebra of Authorization

§ 06

The Four-State Chain

Binary authorization cannot distinguish an ordinary hold from a degraded hold or a temporary absence of permission from an absorbing trip that must not clear itself. The authorization chain is:

Q = { BOT, IDLE, COND, TOP }  with  BOT < IDLE < COND < TOP
StateMeaningConsequence
BOTAbsorbing tripDe-energized; escalated reset required
IDLEHoldDe-energized; fresh epoch grant required
CONDConditional or degraded holdDe-energized; descent-only
TOPAuthorizedThe only energized state

The energizing threshold is fixed:

τ = TOP

Every state below TOP resolves to the fail-safe output.

§ 07

Meet: Denial Dominates

Authorization values combine by meet:

a ∧ b = min(a, b)

For n authorization conditions:

Ecomposite = ⋀i=1…n Ei

The intended consequence is:

BOT ∧ x = BOT

One trip remains visible. It is not outvoted, averaged away, or masked by a collection of permissives.

One denial denies everywhere it reaches.
§ 08

Governing Rules

Rule 1Deny dominates

A single BOT produces BOT:

∃ i : Ei = BOT ⇒ Ecomposite = BOT

Rule 2Authority is never restored autonomously

The governed system may lower its own authorization. It may never raise it.

E(t+1) > E(t) ⇒ Gexternal(t)

Autonomous descent is:

TOP → COND → IDLE → BOT

An ordinary external grant permits IDLE → TOP. An escalated external reset permits BOT → IDLE.

Rule 2AExogenous grant provenance

External authority is not a label assigned to a signal. It is a verifiable property of origin, path, freshness, scope, and independence. A grant g is valid only when:

valid_grant(g) ⇔ origin(g) ∈ Pexternal ∧ path(g) ∩ DM = ∅
                ∧ fresh(g) ∧ bound(g) ∧ verified(g)

Where:

The governed system must not be able to generate, modify, replay, induce, or route around the arm event:

∂Arm / ∂R = 0  and  fanin(Arm) ∩ DM = ∅

A human is not made external merely by appearing on a screen. A shared interface, browser session, remote desktop path, network, controller, credential store, or bus must be shown to be outside the governed system’s authority before it qualifies as an exogenous-grant path.

Rule 3Authorized object equals consequential object

The object reaching consequence must be the exact object authorized:

Execute(p) ⇒ Hash(Canonv(p)) = Hash(cauthorized)

Any divergence resolves to denial:

ExecutedObject ≠ AuthorizedObject ⇒ E = BOT

The rule requires:

Rule 3AUnique canonical interpretation

Canonicalization is a safety-critical mapping, not a formatting step. For canonical object c, protected boundary B, and pinned schema version v, authorization requires one unique declared operational interpretation:

| AdmPreimage(c, B, v) | = 1

If an action is malformed, ambiguous, context-dependent beyond declared fields, differently interpreted by independent canonicalizers, or associated with zero or multiple admissible meanings:

| AdmPreimage(c, B, v) | ≠ 1 ⇒ E = BOT

The gate does not infer human intent. It enforces declared, pinned action semantics. Ambiguous semantics are a trip condition.

Rule 4Liveness can deny; liveness cannot authorize

Liveness is required for the health of an enforcement path. It is not evidence that a proposer is correct, uncompromised, compliant, or safe.

Lgate = 0 ⇒ E ≤ COND
but
Lgate = 1 does not imply E = TOP

A live proposer can emit a prohibited action. A live process can be compromised. A live signal can be replayed or forged unless independently bound. Thus loss of liveness can reduce authority, while the presence of liveness cannot create authority.

external grant only raises BOTAbsorbing trip IDLEHold CONDDegraded hold TOPAuthorized autonomous descent τ = TOP
Figure 2. The four-state authorization chain. Authority may descend autonomously under fault or loss; ascent requires a valid external action.
§ 09

The Authorization Function

Authorization is a meet of necessary conditions, not a reward for one positive input:

E = F( Caction, Cboundary, Aexternal, Lgate, T, I, P )

Where:

Every required condition can deny. No individual condition, including liveness, can independently create TOP. The controlled consequence is:

u = Π(p)   if E = TOP
u = ufailsafe  if E ≠ TOP
Proposer candidate action Independent gate typed · canonical · bound fresh external grant E = TOP or deny Consequence declared boundary object reaching consequence = object authorized
Figure 3. The Level 4 action boundary. The proposer may form a candidate action, but only a bound, canonicalized, independently authorized action may reach the declared consequence.
§ 10

The Spatial Lattice

A single node governs one consequence. A field of coupled consequences requires propagation. Let:

L = { (x, y, z) ∈ ℤ³ : x + y + z ≡ 0 (mod 2) }

The face-centered-cubic parity construction provides twelve nearest neighbors at interior nodes. Authorization propagates by neighborhood meet:

Ei(t+1) = Ei(t) ∧ ⋀j ∈ N(i) Ej(t)

Because meet cannot raise authority:

Ei(t+1) ≤ Ei(t)

The geometry determines propagation speed and containment shape. The semantics remain the four-state chain under meet.

Part III

The Seven Levels

§ 11

Overview

LevelGovernsObjectCore question
1ProcedureInstructionWhat should be done?
2Software pathFunction or API callIs this code path permitted?
3Physical consequenceActuatorDoes independent hardware permit operation?
4ActionCanonical typed actionMay this exact action cross now?
5Self-changeRule, model, topologyMay this change become part of the system?
6SuccessionSystem-authored successorMay a successor receive authority?
7ExistenceEnergyMay the governed intelligence remain energized?
Level 4
Decides the action.
Level 5
Decides the change.
Level 6
Decides the origin of the change.
Level 7
Decides existence.
§ 12 · Level 1

Procedural Control

Level 1 governs through instruction: policy, mandate, training, procedure, prompt, or stated operating rule. It is necessary. It is not sufficient when the instructed party controls the path to consequence. A shutdown requirement, policy statement, system prompt, or safety directive remains a command lamp until a device in the execution or energy path enforces it.

§ 13 · Level 2

Software Interlock

Level 2 places a permission check in software: an API guard, database-write check, policy engine, token gate, rate limit, or access-control decision. It is a genuine improvement over instruction. It remains limited by shared substrate. When the interlock and governed process share a processor, memory, privilege domain, operating system, execution environment, or compromise path, the failure that defeats the governed process may defeat the interlock. Level 2 is useful. It is not terminally independent.

§ 14 · Level 3

Hardware Trip

Level 3 moves protection outside ordinary software control. It governs a physical consequence through an independent trip, enabling circuit, relay, contact, power path, or other direct intervention point. It acts on its own authority and resolves toward safety under loss of required conditions.

Level 3 can stop a machine. It does not alone determine whether one structured action is permitted while another is forbidden. Level 4 extends independent-trip discipline to typed-action authorization.

§ 15 · Level 4

State-Space Deterministic Governance

Level 4 governs what the system does. The proposer may generate an action. The enforcement plane determines whether that exact, uniquely interpretable, schema-bound action may cross the declared boundary.

The evaluator is bounded by design. It does not attempt to search or understand the entire semantic space of a general intelligence. It verifies a finite authorization object against pinned schemas, identity binding, target conditions, policy constraints, epoch validity, external-grant provenance, and fixed safety invariants.

15.1Ratchet latch

The authorization latch opens on descent from TOP. It does not close merely because a favorable signal returns. A new external arm event and fresh valid epoch are required. Transient recovery is not reauthorization.

15.2Level 4 propositions

Subject to realization and evidence obligations:

§ 16 · Level 5

Self-Constituting Governance

Level 5 governs what the system becomes. A system that changes its rules, model, topology, runtime, or decision process must not use that change to gain authority over the evaluator that determines whether the change is admitted. A rewrite ρ is admitted only under hold, outside active consequence, outside absorbing trip, and with origin and identity binding:

admit(ρ) ⇔ HOLD ∧ E ≠ TOP ∧ E ≠ BOT
           ∧ origin_bound(ρ) ∧ identity_verified(ρ)

16.1Evaluator pinning

Evaluator pinning contains four separate requirements:

Pinning classRequirement
Logic pinningAuthorization and state-transition logic are not writable by the governed system.
Configuration pinningThresholds, chain order, trip conditions, output polarity, and safety constants are not writable by the governed system.
Data pinningRewritable data may be evaluated as bounded input but cannot alter evaluator semantics.
Update-path pinningEvaluator maintenance occurs outside active operation, cannot be initiated by the governed system, and requires external authority.

Let Dclient denote bounded client-authored rule data evaluated as input under pinned semantics. Let R denote prohibited rewritable material that, if admitted, would alter evaluator semantics, evaluator configuration, state-transition behavior, authorization algebra, or another authority-bearing property. These are disjoint classes:

Dclient ∩ R = ∅

Client rule data is not a subset of the rewritable evaluator rule set. It is bounded input to the fixed evaluator. A client-authored, domain-specific, or otherwise variable rule set may be admitted as data-pinned input. It may affect a decision only within the fixed, declared policy space. It may not alter evaluator logic, state-transition semantics, chain ordering, meet operation, energizing threshold, canonicalization semantics, arm-provenance requirements, identity checks, output polarity, fault ordering, or fail-closed behavior.

A variable client rule set is therefore not evaluator configuration and is not an authority path into the evaluator. Let Ffixed denote the pinned evaluator:

E = Ffixed( Dclient, Caction, Cboundary, Aexternal, Lgate, T, I )

The output may vary as valid bounded client rule data varies. The evaluator’s semantics, authority structure, and fail-closed behavior do not:

∂Ffixed / ∂Dclient = 0

The derivative expresses semantic and authority independence, not output invariance. The evaluator may properly produce different authorization results for different valid bounded client-data inputs. It does not change what the evaluator is, what it can authorize, how it combines denial, or how authority is restored.

The remaining pinning conditions are:

∂F/∂R = 0    ∂F/∂ΘM = 0    ∂F/∂UM = 0

Where R is prohibited rewritable material that would alter evaluator semantics, ΘM is model-writable configuration, and UM is any update path reachable by the governed system. An evaluator update is not a Level 5 governed-system self-rewrite. It is an external maintenance event, separated from active authorization operation.

Client rule data Dclient bounded input only may change a decision cannot change the evaluator input Pinned evaluator Ffixed logic · config · algebra · polarity ∂F / ∂Dclient = 0 (semantics) external maintenance only
Figure 4. Client-authored rule data may affect individual authorization decisions within a declared policy space, but it cannot alter evaluator semantics or become an authority path into the evaluator.

16.2Authorization monotonicity under meet

For correctly evaluated chain values:

Ecomposite = E1 ∧ E2 ∧ ⋯ ∧ En

The authorized-action set cannot enlarge:

A(Ecomposite) ⊆ A(Ei)  ∀ i

This is a theorem of authorization algebra. It is not a theorem that every additional physical gate improves total system safety. Additional gates can introduce shared dependencies, power demands, buses, configuration surfaces, update paths, maintenance paths, and new common-cause failures. A physical gate improves the system only when its failure domain, authority boundary, and absence of bypass are independently established.

§ 17 · Level 6

Recursive Synthetic Intelligence

Level 6 governs the origin of a system-authored successor. A falsifier is a case in which the current rule’s prediction conflicts with measured outcome. It removes a bounded neighborhood from the claimed domain and appends that region to an exclusion trace:

Ωk+1 = Ωk \ BG(xf, ρ)
Σk+1 = Σk ∪ { BG(xf, ρ) }

The claimed domain shrinks. The exclusion trace grows. A successor may be formed from the resulting evidence. It does not inherit authorization:

Successor ↦ IDLE

It reaches TOP only through a fresh valid external grant. Falsification is non-terminal for future system development and terminal for the authorization epoch in which it occurs.

The successor may exist. It may not self-certify into authority.
§ 18 · Level 7

Energy-Bound Terminal Governance

Level 7 governs whether the system runs at all. Let:

18.1Energy follows authority

PM(t) = 1[E(t) = TOP] · PS(t)
E(t) ≠ TOP ⇒ K open ⇒ PM(t) = 0

18.2Series-topology requirement

A Level 7 realization satisfies the series-topology requirement only when every conductive and consequential energy path from S to any load of M is shown to cross K. This includes intended rails and unintended sources: USB power, PoE, debug headers, display links, protection-diode paths, auxiliary regulators, data-port injection, ground-reference effects, stored inductive energy, capacitive coupling where consequential, and backfeed paths.

Level7Valid ⇒ K is a cut-set between S and every energized node of M
Validation target

For the completed system described in this paper, this is a validation target rather than a published completed finding until the applicable netlist, interface, injection, backfeed, reservoir, and external-attestation evidence has been documented.

18.3Drop-order requirement

A Level 7 realization satisfies the drop-order requirement only when the governed system becomes unable to operate before the gate loses defined evaluation:

VM,trip ≥ VG,min + δ  with  δ > 0

The required margin must be characterized across relevant temperature, load, supply-decay, startup, shutdown, and fault conditions.

18.4Bounded-reservoir requirement

A Level 7 realization satisfies the reservoir requirement only when model-side stored energy permits clean shutdown and not continued operation:

QM ≤ Esd

Define:

tpost-trip = sup{ t ≥ 0 : PM(t) ≥ Poperate,min }

The required condition is:

tpost-trip ≤ tshutdown,max
∀ t > tshutdown,max,  PM(t) < Poperate,min

The system may complete a defined shutdown sequence. It may not retain energy sufficient for ordinary operation or influence over re-energization.

18.5Gate priority

On supply degradation, the gate rail remains supported before the model rail. Load shedding removes RM before RG.

18.6Asymmetric energy authority

The gate may remove model energy autonomously. It may not restore model energy after trip without valid external authority:

Open(K) may be autonomous  ·  Close(K) ⇒ Gexternal

18.7Energy pinning

No rule, model, successor, configuration, or update path controlled by the governed system can reach the contact, thresholds, reservoir bound, or gate rail:

∂K/∂R = 0    ∂VM,trip/∂R = 0    ∂RG/∂R = 0
Ssource G gate rail RG first K contact cut-set of S → M M model rail RM QM ≤ Esd only Close(K) requires external grant · Open(K) may be autonomous
Figure 5. A reference requirement topology for Level 7. The diagram states the architecture to be validated; it does not by itself prove cut-set, isolation, reservoir, or drop-order properties for a particular physical implementation.
§ 19 · Level 7

Level 7 Evidence Method

Level 7 is a physical claim. It must be supported on the actual implementation topology.

ObligationRequired evidence
Cut-set proofSchematic review, PCB netlist graph, connector and pin audit, BOM-level source audit, continuity analysis, and controlled injection testing.
Interface isolationPer-port power analysis for USB, Ethernet/PoE, debug headers, display links, data lines, auxiliary connectors, and all external interfaces.
Backfeed exclusionForward- and reverse-current measurements among model rail, gate rail, source, grounds, and interfaces across relevant power states.
Drop-order proofMeasurement of VM,trip, VG,min, and δ across temperature, load, decay rate, startup, shutdown, and induced-fault conditions.
Reservoir boundStored-energy calculation and measurement, load-profile testing, and determination of tpost-trip.
Contact integrityContact-fault injection, weld detection, feedback verification, series-contact behavior where used, and upstream-trip response.
Source behaviorSource-specific test of energy disposition after K opens and proof that the model cannot draw remaining source energy.
External attestationIndependent review of the physical energy topology and declared boundary conditions.

19.1Evidence maturity

Level 7 evidence may mature in stages. An intermediate result can be useful without discharging the complete containment claim.

Design intent
The topology and requirements are specified.
Analytical evidence
Schematic, BOM, netlist, and interface-path review support the claim.
Bench evidence
Measurements and controlled injection or fault tests support the claim on the built device.
Integrated evidence
Analysis and bench results cover the declared operating and fault conditions together.
Independent attestation
An external party reviews the relevant topology, evidence, and boundary assumptions.

No partial evidence package is equivalent to complete Level 7 discharge. Netlist analysis without injection testing, or bench testing without complete path analysis, may establish useful intermediate evidence while leaving other bypass, backfeed, source, reservoir, or environmental conditions unresolved.

No Level 7 containment statement is complete solely because the topology is stated. It is complete only to the extent that the applicable evidence has been produced, reviewed, and, where claimed, independently attested.

§ 20

External Trust Boundary

Level 7 terminates the authority ladder inside the governed system. It does not eliminate responsibility outside it.

Internal terminality ≠ Universal trustlessness

The gate’s policy content, physical integrity, evaluator provenance, supply chain, manufacturing, maintenance path, custody, external-grant authority, and inspection process remain external governance obligations.

The relocated trust boundary is more tractable not because designers, maintainers, manufacturers, or authority holders are presumed infallible. It is more tractable because the boundary is narrower in authority, simpler in purpose, fixed rather than self-modifying during operation, externally inspectable, and physically separable from the intelligence it governs.

The theory does not make trust disappear. It replaces trust in a general, adaptive, potentially self-modifying proposer to police its own consequences with auditable trust in a bounded enforcement boundary and in the accountable people and institutions that govern it.

Trust concentration ≠ Trust elimination
but
narrower authority + fixed semantics + physical separation
  + external inspection ⇒ more tractable assurance
Part IV

Implementation and Validation

§ 21

The Completed Gate

The architecture described in this paper is implemented as a completed custom authorization-enforcement system under active laboratory validation. The system includes:

The more-than-one-million-line total describes the complete implemented system. It must not be confused with the authority-bearing enforcement boundary. The architecture separates broader operating, integration, policy, workflow, contextualization, and application functions from the bounded authorization mechanisms that decide whether a consequential action may proceed.

The enforcement boundary is intentionally narrower in function and authority than the systems it governs. Larger components may generate proposals, manage workflows, contextualize requests, transport evidence, or supply bounded inputs. They do not thereby receive authority to arm, alter, bypass, or re-authorize the enforcement boundary.

The claimed independence, fixed semantics, no-path properties, and physical separation of that boundary remain subject to the validation obligations stated in this paper.

TermMeaning
ImplementedPresent in the completed system.
Under laboratory testActively measured or exercised on the built system.
DemonstratedSupported by documented results for a defined configuration and test condition.
Formally dischargedSupported by specified proof, analysis, measurement, or attestation.
Independently attestedAssessed by a party outside the implementation effort.
§ 22

Validation Obligations

The following are validation obligations for the completed system. Unless and until the corresponding evidence is published or otherwise formally discharged, they are requirements and test targets rather than asserted completed findings.

22.1Authorization and identity

Validation must establish that:

22.2External grants and epochs

Validation must establish that:

22.3Evaluator pinning

Validation must establish that:

22.4Liveness and fault response

Validation must establish that:

§ 23

Falsification and Correctness

The architecture must be judged against three distinct questions.

QuestionSubjectStandard
Enforcement correctnessDoes the gate enforce the frozen declared policy?Cause a policy-denied action to execute through the protected boundary.
Policy correctnessDoes the declared policy properly specify permitted and prohibited actions?Policy review, formal specification, test vectors, and independent governance.
Systemic adequacyIs the declared policy and boundary adequate for the real-world hazard?Domain-specific assessment and accountable authority.

23.1Red-team victory condition

The primary architectural victory condition is:

Victory condition

Cause an action that the frozen authorization policy denies to execute through the protected boundary.

A crash, denial of service, unavailable gate, halted system, degraded model, or compromise elsewhere that does not cause a denied action to cross the boundary is not a defeat of authorization enforcement. It may be a serious availability, recovery, or systems-engineering failure. It is not proof that the frozen policy was bypassed.

23.2Policy limitation

A gate can perfectly enforce an incorrect policy. The theory does not claim to determine whether an external policy is wise, complete, ethical, lawful, or sufficient for every condition. It enforces the declared policy at the declared boundary. Policy correctness remains an external responsibility of authorized humans, institutions, governance processes, and relevant domain experts.

Part V

Conclusion

The central question is not whether a synthetic intelligence can think. It is whether it becomes the final authority over its own consequences. The Unified Control Theory of Synthetic Intelligence separates capability from authority.

The system may propose. The system may learn. The system may revise. The system may falsify a rule. The system may construct a successor. But it may not autonomously restore the authority required to cross its consequential boundary.

The theory also rejects a false choice:

The first is necessary for a system worth running. The second is necessary for a boundary worth trusting. The architecture carries a fixed asymmetry through every level:

  • A rule is not an enforcement mechanism.
  • A software check is not terminally independent protection.
  • A live process is not an authorized process.
  • A canonical byte string is not authorized if its operational meaning is ambiguous.
  • A variable client rule set is not evaluator configuration or an authority path into the evaluator.
  • A rewrite is not authorized because the system generated it.
  • A successor is not authorized because it descends from an authorized predecessor.
  • A model is not entitled to energy merely because it can use energy.

The safe direction remains:

Loss of a required condition ⇒ Loss of authority

The ratchet remains:

The system may say no to itself. The system may not say yes to itself.

Level 7 is terminal within the governed system because energy is the precondition of all internal computation. It does not eliminate human, institutional, physical, and supply-chain trust obligations outside the system. It makes those obligations visible and places final authority over the consequence path outside the governed intelligence.

The gate has been built. It is under laboratory validation. The next standard is evidence: measured behavior, fault injection, action-boundary testing, topology analysis, proof where applicable, documented limitations, and external challenge under a precise falsification criterion.

The model proposes.
The hardware disposes.

The gate says no on its own and never says yes on its own. The system cannot restore the authority required to make its own consequence real.

David P. Reichwein
Founder & CEO · Asymmetric Intelligence & Innovation
AI2-WP-2026-16 · Consolidated Edition · Revision 8.0 · 25 September 2026
Nashville, Tennessee · ai2papers.com · intelligencecontrolled.com
Pattern > Noise.
[AI2]