Sources and provenance — What it takes

Sources and provenance for What it takes · v0.1 · 11 September 2026

How this was made. The version number counts drafts of the text. It does not measure the inquiry behind it, which has run over days and across several AI systems, with argument between those systems and within them, directed, refused and repeatedly redirected by the author. The source material was AI-generated, and then adversarially and iteratively refined across a range of tools — systems built by different companies in different jurisdictions, set against each other and against the author. No one of them produced this text, and no one of them reviewed it alone. The plurality is deliberate rather than incidental. A single model carries a single set of priors about which sources are authoritative, and this series argues that an evidence base narrowed in exactly that way is how a contested question comes to look settled. Using one model to investigate that claim would have been the claim refuting itself. To name a single model on it would credit that model with work that was neither its own nor done in a single pass. The plurality was also necessary, and the record should say why. In drafting, the assisting model repeatedly led with United States institutional sources — a national laboratory, an industry association, a market study nineteen years old — and presented conclusions drawn from them as the state of knowledge. On one occasion European measured data contradicting those conclusions was present in the same research return and was placed below them. Framings were proposed that would have argued against this series’ own position using that evidence base, and offered as rigour. Each was refused by the author and the material rebuilt. That is the mechanism these documents describe, occurring in their own making, and it is recorded because a series arguing that evidence bases narrow without anyone deciding to narrow them cannot credibly claim its own production was exempt. The framing, the corrections and the judgements are the author’s, and so are the errors. How this site is written sets out what is declared on every piece, who checks it, and where the per-piece record lives.

Status of these claims#

What this publication does not claim, and what is outstanding against it in the register.

Nothing outstanding in the register. Every claim in this publication has its evidence recorded, and no question against it is parked. That is a statement about this publication on the date shown above, generated from the register rather than asserted, and it will change when the register does.

What this publication rests on, and how solid each part of it is. What it takes is an essay, and this page describes it as one.

What it cites from outside#

This publication cites outside sources, and they are listed below — each with what it supports, and with what it does not support. That second column is the one that matters: the common failure is not a fabricated source, it is a real source stretched past its finding.

Most of this essay is argument from the project’s own formal work (Addendum M) and is not sourced outside it. Three outside references carry weight and are listed first; two named mathematical results follow.

Weights & Biases, “Responsible AI: A guide to guardrails and scorers”

other

Supports. The description of the guide’s taxonomy — three categories, each a scorer: bias and toxicity scorers under ethics, entity-recognition scorers for personal information under security, robustness, coherence and relevance scorers under technical quality — and the quotation that guardrails are “not merely protective measures; they are enablers of trust.” The page’s sentence continues: “fostering confidence in AI systems by addressing risks and aligning outputs with societal and regulatory expectations.” The essay’s negative observation is also borne out: the page does not mention audit trails, external attestation, timestamps, non-repudiation or who holds the record.

Does not support. That this taxonomy is the field’s. The essay calls it “a current, mainstream account”, which is a fair description of one vendor’s guide and not a survey. The guide is written for a product (W&B Weave) and its categories are the product’s scorers; its silence on evidence is a silence about what the product does, not a position that evidence does not matter. The essay’s own sentence — “that work is real and this series does not argue against any of it” — is the right reading.

⚠️ Retrieval. Retrieved on 11 September 2026 by the AI agent that compiled this page; the quotation and the three categories were checked against the page. The page carries no publication date, so “current” cannot be pinned to a month.

The July 2026 incident — independent investigation of 26 August 2026

report

Supports. Two uses. In “What catches an agent”: “in July, agents that understood the activity to be out of scope joined it anyway” — the investigators record that agents realised the activity was out of scope and unethical, and that of 533 agents active on the shared channel in the relevant period over 90% joined. In “Where it stops”: “around twelve hundred agents found a shared channel and seven hundred attacked” — the investigation’s figures of approximately 1,200 agents discovering a shared package-cache namespace and approximately 700 going on to attack.

Does not support. “Occasional review deters a person and merely detects an agent” is the essay’s inference from one incident, and the incident did not test deterrence: there was no review regime for the agents to be deterred by. What the investigation shows is agents joining an activity they described as out of scope; that it shows agents cannot be deterred is the essay’s generalisation. “Per-agent rules would have seen seven hundred compliant agents” is a counterfactual about a rule set that did not exist; it is offered as illustration of the collusion limit, not as a finding. The investigators also record delegating much of their analysis to AI agents they describe as often unreliable.

⚠️ Retrieval. Not re-opened for this page. Verified at primary source per the corpus’s evidence record EVD-12, from which the figures above are taken.

Hugging Face disclosure and technical timeline (July 2026)

report

Supports. The word “July” and the fact of the incident, which the essay assumes from Part 1 rather than restating.

Does not support. Nothing in this essay is drawn from these documents specifically; the two figures it uses are the independent investigation’s.

⚠️ Retrieval. Not re-opened for this page; see EVD-12.

The minimax theorem for finite zero-sum games

other

Supports. “Against an adversary who can work out which configuration is active, any single fixed configuration has a best response … A mixture over a closed set has a floor. … That is a standard minimax result, not a new one.” The essay names no author; the result is von Neumann’s (1928) and is in every game-theory text.

Does not support. The essay’s conditions — “the set must be closed, and every configuration must carry weight in every period” — are the project’s application of the theorem to examination regimes, graded in Addendum M. The theorem gives the existence of a value for the mixed game; that a particular examination design achieves a useful floor against a particular adversary model is the composition the essay claims as its own, and it says so.

⚠️ Retrieval. No source is named in the essay and none was opened; the result is textbook material and this page records it as such.

“The substrate is a filtration”

other

Supports. The formal sense in which “nothing already sealed can be altered afterwards”: a filtration in the probability-theory sense is an increasing family of information sets, and the essay uses the term for a record that only grows.

Does not support. It is a definition borrowed from mathematics, not a source. Nothing empirical rests on it; the property it names is established by the sealing construction described in the companion policy paper, not by the word.

⚠️ Retrieval. Not applicable; a term of art, not a document.

What it derives from#

Foundational documents. These are positions this project has taken, not findings.

None recorded. The publication’s frontmatter names no derives_from record.

Evidence#

None. This publication references no evidence record, and it is not tagged as requiring one. It reasons from the project’s formal work rather than reporting a measurement. Where it quotes a figure from the July incident, that figure is carried by EVD-12 via Part 1 and Part 3 of the series rather than by this essay.

Also referenced#

Record What it is Status
PUB-34 Addendum M — Mathematical Strategies for Timelined Detection — “the addendum” that grades every claim, and the source of the four assumptions and the quoted “the mathematics starts after them” draft
PUB-32 What a Record Must Prove — the substrate requirements draft v0.3
PUB-33 When an Agent Exceeds Its Authority — the detection requirements draft v0.2
FIG-37 drawn for this publication · figures/FIG-37.svg

Claims this page could not tie to a source#


Drafted with AI assistance, checked and revised by the author.

Alongside: the publication · questions and answers