From linear token inference to a governed, constituted object. The whole machine in one life, and the programme that would make it real.
A model predicts its next token. A Synthetic Intelligence constitutes its next state.
Thought may arise inside. Authority must arrive from outside. Consequence occurs only at the boundary.
This paper proves nothing new. Every result it relies on is proved or specified elsewhere in the series and is cited where it is used. WP-15 is the calculus of thinking. This paper is the object that calculus belongs to, followed through one life, and the programme of work that would make it real. It adds five things: the lifecycle in one place (§5); three admission regimes that must not be merged (§4); authority indexed by boundary (§4.2); a statement of what the four states do not mean (§3); and a staged programme with an evidence class for every stage (§7).
Rev 1.0 replaces a working draft that was right in direction and inconsistent with the series in six places. Each is corrected here. (1) The draft gave SI a six-part tuple that included the authorization plane and the I/O boundary; the object is WP-11's four-part tuple, and the gate is the slash, not a constituent (§1). (2) The draft defined the cognitive state twice, differently; this paper uses WP-15's Xt and nothing else. (3) The draft used Ω for the whole cognitive state; in WP-15, Ω is a settlement domain, and it keeps that meaning here. (4) The draft gave PCR™ five states; PCR™ is the Genesis state machine, Z ∈ {DENY, PAUSE, RUN}, and contextualization happens inside PAUSE (§5). (5) The draft read the four authorization states as cognitive states; they are not, and §3 says what they do not mean. (6) The draft re-proved results already discharged elsewhere; they are cited instead (§8).
The series has built the gate (Genesis, WP-10), the action (WP-12), the rewrite (WP-13), the successor (WP-14), the unified ladder through energy (WP-16), the classification of containment against authorization (WP-17C), the evidence file (WP-18), the enclosure (One Skin, Two Faces), and the calculus of thinking (WP-15). Each paper answers one question. None follows the whole machine from the moment it exists to the moment it stops.
This one does. It then asks what would have to be built, in what order, and with what evidence, for that machine to exist outside a specification.
This paper does not claim that a Synthetic Intelligence has been built, that a spatial field is sufficient for general intelligence or consciousness, that a Quadzistor™ device has been fabricated or characterized at the stated scale, or that native four-state devices outperform binary CMOS. It does not claim that Codex-1 resolves natural-language ambiguity, that any gate judges whether a grant is wise, or that the architecture removes human, institutional, manufacturing or supply-chain trust. The full list is §9.
WP-11 defines a Synthetic Intelligence as one object with four constituents:
SI := ⟨ 𝒬64³ , 𝓛_codex , Π_PCR , 𝒯 ⟩
𝒬64³ is the lattice body. 𝓛codex is its language, specified as Codex-1 in WP-15. ΠPCR is the PCR™ (Permission Control Runtime), which runs a pause → contextualize → resume cycle. 𝒯 is the TARTARUS™ constituent. The spine note writes the same object as a quotient:
SI ≡ Λ / Π the slash is the product world → ChronaGate™ → SI → ChronaGate™ → world world ∩ SI = ∅ except through the gate
The independent authorization plane and the mediated boundary are not further constituents of SI. They are the slash. Listing them inside the tuple, as the working draft did, reads the gate as part of the thing it governs, which is the category error the series exists to prevent.
The body is finite and the trajectory is not (WP-15 §3.1):
Each site carries two separately bused registers: a cognitive symbol C(v), typed in Codex-1, and an authorization value E(v) ∈ {BOT, IDLE, COND, TOP} (WP-15 §3.2). The instantaneous state of the machine is WP-15's
X_t = ⟨ C_t , E_t , R_t , W_t , H_t ⟩
with C the cognitive field, E the authorization field, R the immutable rule and schema references, W the witness registry, and H the append-only history root. The evaluator F is not a component of Xt. That absence is the whole design.
A language model's operative object is a line: a prefix, extended one token at a time. WP-15 §2 shows why that line cannot be the state of an SI. Permission, if it exists, arrives after the sentence already exists. The forward machine keeps language, and demotes it. Language becomes an export format at egress and an import format at ingress.
egress C_t → render → y₁ … y_n text is a projection of thought
ingress x₁ … x_n → parse → Canon₁ → bind → admit → C_{t+1}
Raw tokens do not become constitution by arriving at a port. A string enters the field only as a canonical Codex-1 term with a unique admissible preimage (WP-15 Law C2). Where it bears on authority, as evidence or as a grant, it must also be bound at origin: the ingress face of the enclosure (One Skin, Two Faces §03). A sentence can be a request, a piece of evidence, a hypothesis or a grant. It is none of these until it has been formed as one.
The four-element chain BOT < IDLE < COND < TOP is an authorization chain. It is tempting, once a machine is said to think on a four-state field, to read the states as cognitive: BOT as false, TOP as true. That reading is wrong, and it is dangerous, because it would let a conclusion raise authority.
| State | What it means | What it does not mean |
|---|---|---|
| BOT | Latched deny. Cleared only by the escalated reset of the gate. | Not "false." A true proposition can sit behind a latched deny. |
| IDLE | Unarmed hold. Nothing energized. The state every new configuration and successor starts in. | Not "unknown," and not "nothing is happening." A machine at IDLE on a boundary may still be thinking. |
| COND | Conditional hold. A condition is unmet; a new grant is needed to proceed. | Not "probably true." Confidence does not live on this chain. |
| TOP | Energized, under a current exogenous grant, on one boundary. | Not "true," "good," or "right." A gate can perfectly enforce a wrong grant. |
Cognitive status lives in C, as typed terms: a contradiction, an open hypothesis, a relation awaiting closure. Such terms may be evidence. Evidence may lower E. It may never raise it (WP-15 §3.2). The two registers are separately bused so that no thought can be mistaken for a permission.
A thinking machine must be able to hold two readings of a request at once and work out which is meant. A governed machine must never act on a request that has two readings. Both are required, and they are compatible only if ambiguity is itself formed as a single canonical object: a term that names its alternatives explicitly. Such a term can be reasoned about. It cannot be authorized, because an action object must have a unique admissible preimage at the consequence boundary, and a term that names two actions does not.
cognition u ↦ Alt{ c₁, …, c_r } one canonical term; may be held, compared, resolved
consequence |AdmPreimage(a)| ≠ 1 ⇒ deny
Whether the Codex-1 core grammar admits such an alternative-set term as specified, or needs a governed extension to do so, is an open item (§8).
Everything an SI does is a transition. Not every transition is the same kind of thing, and the series already assigns each kind its own law. The forward object depends on keeping them apart.
| Regime | What changes | What admits it | Source |
|---|---|---|---|
| Thought | The cognitive field C, inside a declared settlement domain Ω | Codex-1 formation and settlement under PCR™. Never raises E. | WP-15 §4–7 |
| Self-change | Rules, model or topology | The pinned evaluator F. The rewrite target is C, never F. | WP-13 Law 4 |
| Consequence | The world, across a declared boundary | A current exogenous grant for this exact typed action, checked for identity at commit. | WP-12; WP-10; Genesis §7.5 |
| Energy | Whether the governed intelligence runs at all | Energy follows authority on the model rail. | WP-16 §18 |
Two errors follow from merging them. Treating every thought as an action freezes the machine: nothing can be considered without a grant. Treating an action as one more thought collapses authority back into cognition: whatever the machine concludes, it may do. The first error is safe and useless. The second is the thing this corpus was written to prevent.
For every transition the machine can author, in any regime, authority does not rise:
E(t+1) ≤ E(t) for every transition authored inside SI E(t+1) > E(t) ⇒ G_ext(t) = 1 every ascent is an exogenous grant
This is not new. It is WP-15 Propositions 1 and 7, WP-13 Law 4, WP-14's birth of the successor at IDLE, and the Genesis two-domain recovery (Theorem 6.3), read together.
The corpus attaches evidence to a path, not to a product (WP-18 §1), and requires a grant to be effect-specific (WP-17C §8, test 4). The forward object makes the same move for the authorization state itself. There is no single "E of the machine." There is one authorization state per declared boundary b, and one for energy:
E_b(t) for each declared consequence boundary b E_energy(t) for the model rail, where Level 7 is claimed a grant on b₁ confers nothing on b₂ E_b(t+1) ≤ E_b(t) for every b, under every autonomous transition
A machine can therefore be TOP on one boundary, IDLE on another and BOT on a third, at the same instant. That is the ordinary operating condition of a governed SI, not a fault.
WP-16 §18 makes the model rail follow authority: when Eenergy is below TOP, the governed intelligence is unpowered and does not run. WP-15 §9 describes a field that thinks while de-energized as idle cognition, not an effect. The two are consistent if "de-energized" in WP-15 refers to the effect paths and in WP-16 to the model rail. This paper adopts that reading: at Level 7, a machine thinks only while it is granted energy, and acts only where it is granted a boundary. The reconciliation is listed as owed (§8) until both papers say it in the same words.
One machine, followed from instantiation to stop. Each stage names the law already in the corpus that governs it.
Across stages 1 through 8, for every boundary b, Eb is non-increasing under every transition the machine can author, and every ascent is an exogenous grant specific to b. Conditional on Axiom A1, whose satisfaction is an audit fact and cannot be certified by the gate itself (WP-13 Theorem 5).
Composition of results already stated: thought, WP-15 Propositions 1 and 7; self-change, WP-13 Law 4; succession, WP-14 §3; recovery, Genesis Theorem 6.3; boundary specificity, §4.2 above. No step is new, and the corollary is only as strong as its weakest cited step. ∎
The safety results do not depend on the machine being good at thinking. The case for building it does. That case is five hypotheses, each stated with the result that would refute it. None has been tested.
| # | Hypothesis | Refuted if |
|---|---|---|
| H1 | A field-native representation holds several structured relations at once at lower transformation cost than a serialized symbolic baseline, on declared tasks. | On the declared tasks, field-native cost is not lower than the serialized baseline. |
| H2 | Canonical formation scales: Canon₁ and settlement stay within the declared bound Teff(Ω) at a practical vocabulary size. | Canonicalization or settlement time exceeds the bound as vocabulary grows, and the machine denies by timeout in ordinary operation. |
| H3 | Contradiction is local: a contradiction formed in one region lowers authority only on boundaries whose action objects depend on that region. | A contradiction lowers unrelated boundaries, or fails to lower a dependent one. |
| H4 | Expression preserves identity: rendering a settled configuration to text and parsing it back yields the same canonical term, for the declared vocabulary. | A round trip produces a different canonical term, or none. |
| H5 | A native four-state device (Quadzistor™) realizes the chain with density or energy advantage over a binary encoding of the same chain. | Device characterization shows no advantage, or worse fault behavior, against the binary baseline. |
H5 is last on purpose. Every safety result in the series holds on binary CMOS with a finite encoding per site. The device is an option on efficiency, not a condition of governance.
Six tracks. Each stage names what it delivers and the class of evidence it would produce, in the series' status vocabulary: implemented, under laboratory test, demonstrated, formally discharged, independently attested. The order matters. Governance and assurance come first because they are what makes the rest safe to build. The device comes last because nothing depends on it.
| Track | Deliverables | Evidence class sought | Depends on |
|---|---|---|---|
| A · Governance | Rewrite admission bound to a pinned evaluator; a demonstration that no candidate rewrite alters evaluator semantics; successor birth at IDLE on every boundary; per-boundary authorization state; per-path dossiers for every ingress and egress interface (WP-18). | Demonstrated, then independently attested | Existing evaluator RTL |
| B · Physical assurance | A1 audit: post-layout fan-in and write-set analysis; clock, reset, power, debug, scan and test isolation; fault injection; the Level 7 energy cut-set and reservoir bound (WP-16 §19). | Independently attested | A |
| C · PCR™ | The Genesis state machine model-checked; handling of stale, malformed, replayed, conflicting and incomplete context shown to resolve to deny or hold; separation of the three regimes shown in a running system. | Formally discharged, then demonstrated | A |
| D · Codex-1 | The governed vocabulary-extension procedure; a verified Canon₁; a realization of S₁ with measured Teff; the alternative-set term of §3.1; an adversarial conformance suite (WP-15 §11). | Implemented, then formally discharged | C |
| E · Field cognition | A mapping from Codex-1 terms to field regions; measured representation capacity and transformation cost; tests of H1 through H4 against declared baselines, on binary CMOS. | Under laboratory test, then demonstrated | D |
| F · Device | A Quadzistor™ test structure: state distinguishability, switching, retention, noise, thermal and process variation, fail-closed reading of every fault mode; the H5 comparison. | Under laboratory test | None for safety; E for usefulness |
| Item | Status |
|---|---|
| Four-part SI object; SI ≡ Λ/Π | Defined in WP-11 and One Skin, Two Faces. Used, not redefined. |
| Autonomous descent; no promotion of authority by cognition | Proved in WP-15 (Props. 1, 7) from the meet algebra of WP-10 / WP-12 / WP-16. |
| Rewrite cannot reach the evaluator | WP-13 Law 4; conditional on isolation as an audit fact (WP-13 Theorem 5). |
| Successor at IDLE; domain shrinks on falsification | WP-14. |
| Two-domain recovery from DENY | Genesis Theorem 6.3. |
| Canonical identity at consequence | WP-10; WP-15 Prop. 8, assuming a collision-resistant hash. |
| Lifecycle corollary (§5) | Composition of the above. Nothing new proved. |
| Per-boundary authorization state (§4.2) | Stated here. Formalization in the WP-16 notation owed. |
| Level 7 and idle cognition (§4.3) | Reading adopted here. Reconciliation of WP-15 §9 with WP-16 §18 owed. |
| Alternative-set term (§3.1) | Required by this paper. Whether Codex-1 admits it as specified, or by governed extension, is owed. |
| Hypotheses H1–H5 (§6) | Untested. |
| Tracks A–F (§7) | Programme. No stage is reported here as complete. |
The claim is architectural: a Synthetic Intelligence can be defined as a non-linear, spatial-symbolic, recursively self-constituting object whose progression is governed by a permission runtime and whose consequence is governed by an authority it cannot reach.
The future of this kind of machine is not a larger language model, a longer context window, or a more persuasive agent. It is a change of state variable, from a line to a configuration, and a change of constitution, from a model with a safety layer to an object whose governance is the reason it is one object.
It may think independently. It may hold what a line cannot hold as its primary form. It may learn, revise, falsify, and form successors.
It may never turn thinking into authority.
Thought may arise inside.
Authority must arrive from outside.
Consequence occurs only at the boundary.