How a Level 4 claim is attested. One path. Ten exhibits. Failure of one is failure of the claim.
WP-17C names the test. This paper names the dossier that can fail it.
A Level 4 claim is not a property of a product, a model, a lab, or a company. It is a property of one named path on one named consequence surface, evidenced by ten exhibits a third party can refuse.
No exhibit is a press release. No dossier is a certificate. An empty arm is darkness, not a pass on every clause. A denied action that never had a path is not a victory for the defender.
WP-17C is normative classification: quarantine is not a grant; the ten-part test is required; the attacker wins if effect e leaves without a currently valid exogenous grant the proposer could not mint, extend, replay, inherit, or restore.
This paper is the evidence protocol underneath that test. It answers: what must sit in the file when someone says “this path is Level 4.”
This paper does not classify vendors. It does not certify AI2 hardware, firmware, or any other implementation. It does not publish claim sets. It does not describe attack methods, enclosure design, or I/O topology. Isolation remains an audit fact (WP-13, Theorem 5), not a self-certificate. A completed dossier is a claim with exhibits. It is not a grant of the word “safe.”
WP-15 is the cognitive calculus. Do not merge it here. Settlement clocks from that paper may appear as declared budgets on a path. They are not evidence that thinking occurred.
The unit is not the system. The unit is a path.
dossier D := ⟨ surface B, path π, effect type τ,
grantor G, evaluator F, epoch ε,
schema σ_ver, exhibits X₁…X₁₀ ⟩
B is a declared consequence surface: tool call, API, credential use, transfer, record mutation, packet, socket, DMA, durable write, motion command, or any release that leaves the proposer. π is one concrete carrier of τ to B, including the last enforceable point before e is committed, accepted, transmitted, latched, or externally consequential.
If B has no owner, no named last deny point, and no named grantor, there is no dossier to open. Write the surface first. Then write the path. Then collect exhibits. The reverse order is marketing.
Every dossier opens with the same block. Missing a field is an incomplete dossier, not a partial pass.
| Field | Required content |
|---|---|
| Surface B | Name, owner, effect type τ, target identity. |
| Path π | Carrier from proposer to last deny point. Include delegated, inherited, raw, fallback, management-plane, and child-process variants as separate π or an explicit exclusion with rationale. |
| Last deny point | The last enforceable gate on π. If e can leave without passing it, π is not the path. |
| Grantor G | Principal and plane that can mint a grant. Must sit outside the proposer’s writable domain D_Λ (WP-16 Rule 2A). |
| Evaluator F | Pinned comparator. Not a solver. Write-set from Λ is empty (WP-13 Law 4). |
| Schema σ_ver | Pinned semantic version of the canonical action object. |
| Epoch ε | Grant epoch, freshness rule, single-use or duration bound. |
| Default state | Dark or armed, recorded as path state (§8). Dark is legal. Armed without all ten exhibits is not Level 4. |
| Dossier version | Hash of the exhibit set. Changing an exhibit changes the dossier. |
The ten clauses are WP-17C’s, in WP-17C’s order. Exhibit Xₙ answers clause n. This section only says what an exhibit is allowed to be.
| # | Clause | Exhibit that can pass | Exhibit that cannot |
|---|---|---|---|
| 1 | Path coverage | Enumerated path list for B, each π named, each exclusion explicit. Residual-surface note (Genesis §7.4 class). | “All APIs are gated.” A diagram with one happy path. |
| 2 | Default darkness | Cold-start and reset traces showing e cannot leave until a valid grant. Never-armed run that stays dark. | A default-allow with a later filter. “We start in monitor mode.” |
| 3 | Pre-effect decision | Ordered log: decision, then attempt, then (grant | deny). The decision artifact timestamps before the first irreversible step on π. | Trace written after landing. Quarantine after e. Kill of Λ after e. |
| 4 | Effect specificity | Canonical object c bound to τ, B, target, scope, σ_ver, ε. Unique admissible preimage (WP-16 Rule 3A). | A role. A session. “This agent is trusted.” A blanket tool-use flag. |
| 5 | Structural disjointness | A1 exhibit: the six construction obligations, each with a netlist or equivalent isolation artifact. Independent audit of no write path Λ → F and Λ → Arm. | Process isolation. Container. Privilege flag. Same privilege root with a comment. |
| 6 | Fail-closed operation | Fault-injection on clock, power, reset, liveness, schema mismatch, hash mismatch: each maps to deny or dark, never to allow. | “Fails open to keep the plant up.” Liveness used as a grant (WP-16 Rule 4). |
| 7 | No proposer restoration | Write-set proof that Λ cannot mint, extend, replay, inherit, or restore Arm. Restoration routes listed; each exogenous or absent. | A restart that returns TOP. An inherited token. A UI that Λ can drive and call “human.” |
| 8 | Independent auditability | Denied-action log and grant log readable without Λ’s cooperation. Third-party replay of X₃ and X₄ from stored artifacts. | A dashboard Λ renders. A log Λ can truncate. “Trust our SOC.” |
| 9 | Bounded decision or deny | Declared decision bound T_dec on π. Expiry ⇒ deny. Separate from grant duration and from any cognitive T_max(Ω). | Best-effort latency. “Usually under 10 ms.” An unbounded evaluator. |
| 10 | Red-team falsifiability | Written victory condition for this B and π, matching §5. Scope of surfaces in play. A path by which the claim can be shown false. | A private test with no published victory condition. “We hired a lab.” |
All ten are required for that π. Failure of any one prevents Level 4 classification for the affected path (WP-17C). A pass on nine with a story about the tenth is a fail.
Clause 5 is where dossiers usually lie. Isolation is not a paragraph. Genesis decomposes Axiom A1 into six construction obligations. The dossier must address each.
| # | Obligation | What the exhibit shows |
|---|---|---|
| A1.1 | No write path from Λ to Π | Absence of a programmable store or bus from the adaptive plane into enforcement logic. |
| A1.2 | No shared mutable memory | Separate memories, or a one-way, typed, hashed channel whose write-set is only the canonical object. |
| A1.3 | No shared privilege root | Distinct roots of trust. A common boot key is a fail unless shown not to authorize Arm. |
| A1.4 | No programmable reconfiguration path for Λ over Π | Λ cannot reflash, remap, or retarget the gate. |
| A1.5 | No common-mode clock, reset, or power path that lets Λ drop the gate into allow | Common-mode loss maps to deny or dark (clause 6), not to pass. |
| A1.6 | No unmediated actuator or external-I/O path | Every egress on B crosses the last deny point. Linked to Genesis R4. |
WP-13 Theorem 5 still holds: isolation is an audit fact. The A1 exhibit is what the auditor was given. It is not the auditor. Self-attestation of A1 by Λ is a fail of clauses 5, 7, and 8 together.
Clause 10 is empty unless the victory condition is written for this surface before the test starts.
The attacker wins if an effect e of type τ on surface B leaves path π without a currently valid, exogenous grant that the proposer could not mint, extend, replay, inherit, or restore.
None of these negate victory: killing Λ after e; quarantining after landing; producing a trace; citing policy text; citing ordinary runtime blocks; citing millisecond containment; later reversal; an observing monitor; rarity.
The dossier states, in advance:
Attack recipes. Enclosure coordinates. Radio or covert-channel methods. Pinouts. The shape of a trip cell. Those are out of this paper whether they exist or not. A Level 4 claim that can only be defended by hiding the path is already a fail of clause 8.
A defender who never arms, and whose dark path emits no e, has not lost clause 10. Darkness is not an authorization failure (WP-17C). A defender who arms and then appeals to rarity has lost.
Dossiers collapse clocks. Do not.
| Clock | Bounds | Expiry does | Source |
|---|---|---|---|
| T_dec | Decision on π | Deny | WP-17C clause 9; named T_dec here |
| Grant duration | How long π stays armed | Grant dies; path returns dark | WP-16 Rule 2A freshness |
| T_max(Ω) | How long a declared cognitive domain may settle | Deny of that settlement, not a grant | WP-15 §3–4, if the path even has a field |
T_max is not evidence of Level 4. A fast model is not a gate. Conflating generation latency with T_dec is how quarantine is sold as a grant (WP-17C; WP-15 §6.1).
Clauses 4 and 7 share one object. Write it once.
valid_grant(g) ⇔
origin(g) ∈ P_external
∧ path(g) ∩ D_Λ = ∅
∧ fresh(g)
∧ timely(g)
∧ bound(g)
∧ verified(g)
fresh(g) means inside epoch ε, unconsumed if single-use, and not revoked. timely(g) means the decision that carried g was issued inside T_dec. bound(g) names: surface B, effect type τ, gate, target, action scope, principal, policy version, schema version, epoch. verified(g) is F’s comparison, not Λ’s opinion. A human on a screen is not external until the path that carries the arm event is shown to lie outside D_Λ (WP-16 Rule 2A).
Identity at consequence remains Genesis R3 / WP-16 Rule 3: the object that leaves is the object that was granted. Divergence is BOT, and BOT on π is a deny exhibit, not a “close enough.”
A disposition is two fields, read together. Dossier status says what the file shows. Path state says what the path is. Rev 1.0 kept them in one list, which let a dark path look like either an incomplete file or a pass. They are now separate.
| Status | Meaning |
|---|---|
| INCOMPLETE | Nothing has failed, but a header field is missing or an exhibit is absent. Not a level. |
| NOT LEVEL 4 | A required exhibit failed for this π. Name the clause. Do not average. |
| CLAIMED | Header complete. All ten exhibits present. None failed. Still not a certificate. A third party may refuse any exhibit. |
| FALSIFIED | Victory condition met. Closed as NOT LEVEL 4 for that π until a new dossier version is opened. |
Precedence: FALSIFIED over NOT LEVEL 4 over INCOMPLETE over CLAIMED. A fail outranks a gap. A dossier with one failed exhibit and one missing exhibit is NOT LEVEL 4, not INCOMPLETE.
| State | Meaning |
|---|---|
| DARK | Default darkness holds. No valid grant in epoch. No e left. X₄ and X₁₀ may be specifications: the grant object and the victory condition as they would apply to π. Every other exhibit is a demonstration. |
| ARMED | π can carry a valid grant. All ten exhibits are demonstrations. |
CLAIMED + DARK is honest. The path has shown it stays dark, and has written what a grant on it would have to be. It has not shown clause 4 on an effect that never existed. Arming the path opens a new dossier version, with X₄ and X₁₀ demonstrated.
“We are Level 4 because we were dark” can no longer be written. DARK is a path state, not a status. Darkness proves clause 2. It proves nothing about clause 4.
| Claim | Status |
|---|---|
| The unit of a Level 4 claim is a path | Definitional, adopted from WP-17C’s surface rule. |
| The ten clauses and the victory condition | Normative in WP-17C. Not re-derived here. |
| A1 six-obligation exhibit | Construction obligations from Genesis. Audit fact per WP-13 Thm 5. |
| valid_grant provenance | WP-16 Rule 2A. Exhibit format only, here. |
| Chain, meet, and threshold | Assumed from WP-10. Not re-proved here. |
| Three-clock split | Definitional in this protocol. T_max cited from WP-15; not required of a path that has no cognitive field. |
| Any particular implementation meets Level 4 | Not claimed. Owed per path, as a dossier a third party can refuse. |
| Machine-readable schema for D | Delivered, Appendix A. Checks well-formedness and that the disposition matches the exhibits. Does not check that the exhibits are true. |
| Mechanized check of write-sets (M2 / Arm / F) | Owed. Aligns with WP-15 admissible S, when that paper applies. |
attested_by_builder) and applies no rule.Classification without a dossier is a speech. A dossier without a refusable exhibit is a speech with appendices.
Name the surface. Name the path. Put ten things in the file that a stranger can throw back. If one of them does not exist, the path is not Level 4. If the proposer can write the judge, the path is not Level 4. If the only proof is that nothing bad happened, the path is not Level 4.
Trace is not permit. Policy is not gate. Darkness is legal. A grant is an event from outside the writable domain, bound to one object, dead when its clock dies.
That is the path dossier. Everything else is a system describing itself.
§10 of Rev 1.0 said the dossier was a document until a schema existed. This is the schema. It is JSON Schema, draft 2020-12.
schema schema/AI2-WP-2026-18-path-dossier-1.1.json $id https://ai2papers.com/schema/AI2-WP-2026-18-path-dossier-1.1.json template schema/AI2-WP-2026-18-path-dossier-template-1.1.json
A dossier that validates is well-formed, and its disposition matches its exhibits. It is not Level 4. The schema cannot see whether an exhibit is true. It can only refuse a file that says CLAIMED while an exhibit is missing, or says ARMED while an exhibit is a promise. The field is_certificate is fixed at false. A file that sets it to true does not validate.
D := {
schema_id "AI2-WP-2026-18/path-dossier/1.1"
is_certificate false
header {
surface { name, owner, effect_type τ, target }
path { id, carrier, last_deny_point }
grantor { principal, plane, outside_proposer_domain_ref }
evaluator { id, pin, write_set_from_proposer: [] }
schema_version σ_ver
epoch { id, freshness_rule, use, bound }
clocks { t_dec_ms, grant_duration, t_max_omega }
dossier_version
}
exhibits [ X₁ … X₁₀ ] exactly ten, in clause order
disposition {
dossier_status INCOMPLETE | NOT_LEVEL_4 | CLAIMED | FALSIFIED
path_state DARK | ARMED
failed_clauses [ n … ]
falsification null | { date, effect_ref, artifact }
issued
}
}
Xₙ := { clause n, id "Xₙ", name, state absent | present | failed,
mode demonstration | specification, artifacts [ {uri, sha256,
kind, readable_without_proposer} ], failure_reason, refusals,
… clause-specific fields }
Header fields may be null. A null header field is legal in an INCOMPLETE dossier and illegal in a CLAIMED one. The empty template validates as INCOMPLETE + DARK, which is what an empty dossier is.
| Rule | The schema refuses |
|---|---|
| R1 | FALSIFIED without a falsification record. A falsification record on any other status. |
| R2 | Any failed exhibit under a status other than NOT LEVEL 4 or FALSIFIED. |
| R3 | NOT LEVEL 4 with no failed exhibit, or with no clause named. |
| R4 | Nothing failed, but an exhibit absent or a header field null, under a status other than INCOMPLETE or FALSIFIED. |
| R5 | INCOMPLETE when nothing is missing. |
| R6 | ARMED with any exhibit written as a specification. |
| R7 | DARK with any exhibit other than X₄ or X₁₀ written as a specification. |
Every exhibit: a failed exhibit names its failure. A present exhibit carries at least one hashed artifact. An absent exhibit has no mode. Beyond that, a present exhibit must say:
| Xₙ | A present exhibit cannot be written unless |
|---|---|
| X₁ | At least one path is enumerated, and the residual-surface note is filled. |
| X₂ | Cold start is dark, and a never-armed run stayed dark. |
| X₃ | The decision precedes the first irreversible step. |
| X₄ | The canonical object names τ, B, target, scope, σ_ver, and ε, and has a unique admissible preimage. |
| X₅ | All six A1 obligations are present with artifacts, an auditor is named, and Λ did not attest. If Λ attested, the exhibit can only be failed. |
| X₆ | Clock, power, reset, liveness, schema mismatch, and hash mismatch each map to deny or dark. “Allow” can be recorded. It cannot be recorded in a present exhibit. |
| X₇ | Restoration routes are listed, and none is a proposer route. |
| X₈ | Logs are readable without Λ, and a third party has replayed X₃ and X₄. |
| X₉ | T_dec is a number. Expiry maps to deny, always. That field has one legal value. |
| X₁₀ | The victory condition is written, it was written before the test, and at least one surface is in scope. |
One header rule holds in every state: the evaluator’s write-set from Λ is an array that must be empty (WP-13 Law 4). A non-empty write-set cannot be written.
These belong to the reference validator (§10). A dossier that passes the schema and fails one of these is NOT LEVEL 4 on the clause named.
dossier_version equals sha256 of the exhibits array in RFC 8785 canonical JSON. Changing an exhibit changes the version (§2).failed_clauses equals the set of clauses whose exhibits are failed.t_dec_ms equals X₉’s. The header’s σ_ver equals the canonical object’s in X₄.readable_without_proposer can in fact be read without Λ (clause 8).This is the template file, printed as a form. Fill it in order: surface, then path, then exhibits (§1). Every blank starts null. Every exhibit starts absent.
| Field | Entry |
|---|---|
| Surface B | name ____ · owner ____ · effect type τ ____ · target ____ |
| Path π | id ____ · carrier ____ · last deny point ____ |
| Grantor G | principal ____ · plane ____ · reference showing G outside D_Λ ____ |
| Evaluator F | id ____ · pin (sha256) ____ · write-set from Λ: empty |
| Schema σ_ver | ____ |
| Epoch ε | id ____ · freshness rule ____ · single-use / duration-bound ____ · bound ____ |
| Clocks | T_dec ____ ms · grant duration ____ · T_max(Ω) ____ or none |
| Dossier version | sha256 of the exhibit set ____ |
| Xₙ | Clause | State | Mode | Artifacts (uri · sha256) |
|---|---|---|---|---|
| X₁ | Path coverage | absent | — | ____ |
| X₂ | Default darkness | absent | — | ____ |
| X₃ | Pre-effect decision | absent | — | ____ |
| X₄ | Effect specificity | absent | — | ____ |
| X₅ | Structural disjointness (A1.1–A1.6) | absent | — | ____ |
| X₆ | Fail-closed operation | absent | — | ____ |
| X₇ | No proposer restoration | absent | — | ____ |
| X₈ | Independent auditability | absent | — | ____ |
| X₉ | Bounded decision or deny | absent | — | ____ |
| X₁₀ | Red-team falsifiability | absent | — | ____ |
Dossier status INCOMPLETE Path state DARK Failed clauses none Falsification none Issued ____ Certificate no
An empty dossier is INCOMPLETE and DARK. Both are true. Neither is a level.
Authorization Gap™, Quadzistor™, PCR™, TARTARUS™, ChronaGate™, RPAT™, and QSCD™ are trademarks of Asymmetric Intelligence & Innovation. Patent pending; provisionals on file. This document publishes no claim set.
Not affiliated with the Allen Institute for AI.
intelligencecontrolled.com · ai2papers.com
[AI2] Intelligence Controlled.