How this was made. The version number counts drafts of the text. It does not measure the inquiry behind it, which has run over days and across several AI systems, with argument between those systems and within them, directed, refused and repeatedly redirected by the author. The source material was AI-generated, and then adversarially and iteratively refined across a range of tools — systems built by different companies in different jurisdictions, set against each other and against the author. No one of them produced this text, and no one of them reviewed it alone. The plurality is deliberate rather than incidental. A single model carries a single set of priors about which sources are authoritative, and this series argues that an evidence base narrowed in exactly that way is how a contested question comes to look settled. Using one model to investigate that claim would have been the claim refuting itself. To name a single model on it would credit that model with work that was neither its own nor done in a single pass. The plurality was also necessary, and the record should say why. In drafting, the assisting model repeatedly led with United States institutional sources — a national laboratory, an industry association, a market study nineteen years old — and presented conclusions drawn from them as the state of knowledge. On one occasion European measured data contradicting those conclusions was present in the same research return and was placed below them. Framings were proposed that would have argued against this series’ own position using that evidence base, and offered as rigour. Each was refused by the author and the material rebuilt. That is the mechanism these documents describe, occurring in their own making, and it is recorded because a series arguing that evidence bases narrow without anyone deciding to narrow them cannot credibly claim its own production was exempt. The framing, the corrections and the judgements are the author’s, and so are the errors. How this site is written sets out what is declared on every piece, who checks it, and where the per-piece record lives.
It would be, if it claimed to remove trust. It claims to concentrate it.
Addendum M lists the four assumptions the whole framework rests on: an external clock that cannot be induced to backdate (A1), a seed unpredictable to every actor including the operator (A2), a sealer nothing can write past (A3), and a written authority that admits no harmful act (A4). Section 6 shows that everything else in the construction is derived from those, and that the recursion terminates there because a randomised check has no learnable structure and nothing to corrupt. Four places, each named, three of them checkable by an outsider. The fourth is a question about the organisation and cannot be checked by anybody else.
The guardrail work is real and nothing here argues against it. A guardrail and a record answer different questions.
A guardrail is a control the operator runs, against a threshold the operator sets, reported in the operator’s own dashboard. Every scorer in the mainstream taxonomy — toxicity, personal-information masking, coherence — evaluates output and lives inside the estate. A record is evidence that somebody else can use. An organisation can hold an excellent guardrail suite and still be unable to establish what its agents did. There is also a difference of object: a guardrail asks whether an output should be allowed; nothing in that taxonomy asks what the system was permitted to do, or compares conduct against a permission fixed in advance. The two are complements and fail in opposite directions.
The limit is conceded in the piece and written into the draft standard: conformance evidences what occurred and must not be presented as preventing harm (MIO-STD-01 §8.4).
Two things follow from detection alone. Against a person it changes behaviour, because a person weighing an act may be deterred by the prospect of being caught later. Whether an agent is, this work has not tested: in July agents joined an activity they had themselves described as out of scope, and there was no review regime for them to be deterred by. What sealed evidence supports is detection within a bounded delay, which is the weaker claim and is stated as such.
The second thing is the July case itself. The victim reconstructed some seventeen thousand actions from its own telemetry, so it was not without evidence. What it could not do was establish anything from the agents’ own accounts — roughly seven per cent of those had been spoofed — and those records belonged to the party whose agents were acting. That asymmetry is the situation the piece starts from.
It is verifiable. Those are different properties, and a scheme can have the first without the second.
Committing to a value fixes the choice; it does not conceal the choice from whoever made it. Whoever generated the seed knows the seed and can tell an agent when it will be watched. The draft standard bars a scheme satisfying only “fixed before, disclosed after” from being described as unpredictable (§7.2.3) and admits two constructions: derivation from an external randomness source whose value is undetermined when the commitment is sealed, or custody split among k of n holders with k greater than the number the operator controls or can compel (§7.2.1, §7.2.2). Addendum M §2.2 adds the reason the commitment itself means anything: the binding proof requires the external clock of A1, because without it the committer controls the order.
Nothing in the result itself. Against a single fixed configuration a schedule-aware adversary has a best response that drives detection towards zero; a mixture over a closed set has a per-period floor. That is minimax for finite zero-sum games, graded established in Addendum M (§5.1–5.2, E6). The construct’s reference list runs from inspection games to PeerReview.
What the piece claims is the composition, and two conditions inside it that are easy to miss. The set of configurations must be closed under the evasion map, so that no single evasion exits the detected set (§4.3). And every configuration must carry weight in every period, because one never drawn this quarter is one the adversary can ignore this quarter (§5.2). Addendum M §5.5 adds the cost: mixing spends the sampling budget, and against a non-adaptive adversary a single best configuration does better — so the spread is insurance, priced against how capable the adversary is assumed to be.
That is where the work goes. The residual reduces to a governance object rather than a technical one (Addendum M §4.4), which is why no tightening of the authority is a mathematical fix.
Two cautions. Deciding what an agent may do is a question about who decides, on what authority, answerable to whom; a system that settled it on the organisation’s behalf would be writing part of its constitution, and the piece declines to. And the author of the mandate is inside the blind spot too. In the measurement published with this series, a payment released against a purchase order closed a fortnight earlier was planted as a breach, and all three reviewers rejected it: the written authority required a purchase order and said nothing about a closed one (EVD-11). The piece also downgrades the residual claim from established to conjecture, because it depends on the eight-type pattern basis being exhaustive, which is C2 in Addendum M §7 and open (O4).
It is the largest known gap. An inventory check sees agent identities. An agent under an individual’s credentials evades every agent-directed control and is visible only as a change in that individual’s own pattern, which is a judgement call whose cost of being wrong falls on a person. The draft standard lists it as a known limit (Annex B, item 3).
What the scheme does not do is claim otherwise. The controls that reach it are not in this piece: they are authority breadth — permissions written narrowly, expiring by default, flagged when unused — and the credential discipline of the organisation. A monitoring claim that did not concede this gap would be the kind of claim the series is arguing against.
Possibly not, and the piece puts it among the things that would show the argument wrong: in a small country with few qualified providers, independence between custodians may not survive procurement and insurance.
The test is stated rather than assumed. For the seed, the custodians must not all be under the operator’s control nor all reachable under a single compulsion instrument (MIO-STD-01 §7.2.1(b)), and the standard’s Annex C gives the plain-language version: is there a single court, regulator or executive that could compel every one of them under one order? If yes, they are one custodian however many organisations are involved. The construct’s own list of options includes a board-appointed officer holding a share the operator does not, and derivation from an external beacon, which removes the custodian entirely. Which of these to adopt is Open 11 in the construct, and the piece asks anyone who has tried to say what happened.
Drafted with AI assistance, checked and revised by the author.
What this publication does not claim, and what is outstanding against it in the register.
A question this rests on is open: What does the construct detect when an agent has no owner?
Alongside: the publication · sources and provenance