
Defense
Autonomous aerial systems, engagement-authority coordination, and counter-UAS gating gated behind verified trust and human authority.
BLADE-EDGEBLADE-CUASBLADE-SWARM Explore the domain →
Space
Governed deliberation before unplanned RPO maneuvers and constellation authority under contested comms.
BLADE-SPACE Explore the domain →
Maritime & Undersea
Surface patrol under GPS deception and UUV tier descent when the link drops. Governed fallback, not silence.
BLADE-MARITIMEBLADE-UUV Explore the domain →
Critical Infrastructure
Command gating for grid and industrial OT: mandatory deliberation before automated load-shedding and control writes.
BLADE-INFRABLADE-INFRA-OT Explore the domain →
Autonomous Mobility
Authority handover engineered for the road: forced human override during sensor degradation, not silent drift.
BLADE-AV Explore the domain →
Agentic & Cyber
Hardware-anchored gating for coding agents and autonomous cyber defense. Privilege escalation and live-system patching held behind signed authority.
BLADE-AGENT-HSMAUTHREX-AGENT-CYBER Explore the domain →A Circuit Breaker for AI-Controlled Systems
Your home has circuit breakers. When something goes wrong with the electricity, they cut power before the house burns down. AUTHREX does the same thing for autonomous systems.
When an AI system is about to make an unsafe decision, the proposed architecture is intended to detect configured trust or authority failures, introduce a governed response, reduce available authority where required, and record mediated events for later review, handing control back to a human.The AI keeps the intelligence. Humans keep the authority.
AUTHREX is a proposed authority-governance layer designed to reduce the risk of autonomous systems acting on untrusted information or outside configured authority bounds. Not by making AI smarter: the proposed architecture evaluates trust, authorized intent, and recovery-path conditions before permitting registered actions at its proposed software enforcement point demonstrated in synthetic simulation.
Sense. Decide. Recover.
Is the sensor data trustworthy?
AUTHREX continuously checks whether what the AI is seeing matches reality. If a GPS signal is being jammed, a camera is glare-blinded, or radar data is corrupted, the system knows it cannot trust itself.
Read More →Is it safe to act?
Before any irreversible action, a mandatory pause happens. The system reviews the evidence, checks whether humans should weigh in, and only proceeds if the confidence bar is high enough. The proposed FLAME mechanism introduces a configurable deliberation interval for designated consequential actions, subject to the stated implementation and timing assumptions.
Read More →If trust breaks, what happens?
When the system detects it can no longer operate safely, AUTHREX doesn't crash, it degrades gracefully. Full autonomy becomes supervised, supervised becomes hold-position, and humans regain control in a structured way.
Read More →Intelligence Is Scaling. Control Is Not.
Autonomous systems are making decisions faster than humans can supervise. The industry is optimizing for intelligence while the governance layer remains absent.
Without structured authority governance, systems operate with unconstrained delegation. No mechanism for degrading authority when trust erodes, no protocol for recovering control when autonomy fails.AUTHREX addresses this as an engineering problem, not a policy aspiration.
Heterogeneous Sensing With Trust Reasoning
Three approaches to autonomous safety have shaped the field. AUTHREX adopts what works in each, and adds the missing layer: the system reasoning, in real time, about whether its own inputs and decisions can be trusted.
Redundancy & Voting
Three identical sensors, take the majority. Three identical computers, vote on the answer. Used in commercial aviation since the 1970s.
All three sensors can be wrong the same way. Cosmic rays, GPS spoofing, glare. Identical voters share identical blind spots.
Runtime Assurance (RTA)
Watch the autonomous system. If it tries to do something unsafe, override with a known-safe controller. Simplex architecture. Used in aerospace.
Binary thinking. Either the safe-controller takes over or it doesn't. No gradient between full autonomy and full intervention.
Heterogeneous Sensing + Trust Reasoning
Different sensor modalities (camera, radar, GPS, INS, celestial). Continuous trust assessment per source. Authority allocated in proportion to trust, with formal recovery when trust collapses.
The system reasons about its own inputs. Authority is graded, not binary. The fallback is structured, not last-resort.
AUTHREX does not replace redundancy or RTA. It composes with both. The novelty is in treating authority itself as a graded, trust-proportional resource governed by a formal lifecycle, rather than a binary on/off held by either the autonomous system or the safety override.
One Kernel. Seven Frameworks. Six Application Profiles.
AUTHREX-AGENT
The seven-stage pipeline instantiated as a software shim around LLM-based agents. No FPGA, no model retraining. Aligned with the CISA + NSA + Five Eyes agentic-AI guidance of May 2026.
Learn More →AUTHREX-ASSURE
Pre-deployment authority governance. Evaluates configured evidence conditions and records an internal release or hold recommendation; deployment decisions remain external to AUTHREX. Mapped by the author to the March 2026 White House cyber strategy (President Trump’s Cyber Strategy for America) and NDAA §1533.
Learn More →AUTHREX-ICS-GATE
OT authority governance for critical infrastructure. Authorizes the deterministic safety logic for AI in OT; never makes the safety decision itself. Anchored to the CISA/NSA AI-in-OT principles.
Learn More →AUTHREX-AGENT-CYBER
Governs whether an autonomous cyber-reasoning system may patch a live controller. DARPA AIxCC lineage. Governance only, no offensive function.
Learn More →CYBER
AUTHREX-SPACECYBER
Signal delay removes the human from the loop, so authority is governed onboard. Anchored to NASA SBIR EXPAND.3.S26B and Space Policy Directive 5.
Learn More →CYBER
AUTHREX-SANDBOX
Governs the test environment itself so evaluation is bounded, audited, and reversible. Matches NDAA §1534. Feeds ASSURE downstream.
Learn More →Cited Variants · folded into AGENT-CYBER
AUTHREX-ZTAGENT Zero Trust for autonomous agents. The same agentic surface, not a separate application.
AUTHREX-MCPGOV Model Context Protocol server governance. Folded into AGENT-CYBER as a citation layer.
Features · not applications
AUTHREX-PQC Post-quantum-ready signing, a property of how BLADE-AGENT-HSM signs. A hardware feature.
AUTHREX-AISBOM An AI software bill of materials the ERAM ledger emits. A ledger feature.
Rover Testbed
Assured autonomy → AIR · T3-T0HMAA-UAV
Flight authority → SWARM · T3-T0Blade-Swarm
Multi-agent teaming → EDGE · T3-T0Blade-Edge
Perimeter compute → AUTOMOTIVE · T3-T0Blade-AV
Drive-by-wire safety → MARITIME · T3-T0Blade-Maritime
Surface autonomy → INFRASTRUCTURE · T3-T0Blade-Infra
ICS/SCADA protection → IT/OT · T3-T0Blade-Infra-OT
Boundary governance → ORBITAL · T3-T0Blade-Space
LEO autonomy → C-UAS · T3-T0Blade-CUAS
Counter-UAS → AGENTIC · T3-T0Blade-Agent-HSM
Root of trust → FINANCIAL · T3-T0Blade-Finance
Transaction authority →Seven-Stage Authority Lifecycle
Outcomes: EXECUTE all gates passed · DELAY FLAME hold · HANDOFF to human · ABORT CARA recovers
End-to-end pipeline governing trust, authority, constraints, consensus, deliberation, recovery, and escalation.
Full-Scale Research Simulations
Standalone browser-based simulations demonstrating AUTHREX governance frameworks, grouped by domain: application governance, strategic and multi-domain command, tactical engagement, and distributed consensus.
Application Governor Consoles
11 SIMSThe product, its five federal applications, three standalone governor consoles, and two hardened prototype consoles. Each runs as a self-contained console with a SHA-256 hash-chained decision ledger, replay determinism, and an in-browser V&V suite. Synthetic data only.
AUTHREX-AGENT-SIM
Mission-level governance of the full seven-gate pipeline over an autonomous cyber-defense campaign. Ten injectable failure modes, 55-test V&V verified in browser and headless Node.
AUTHREX-ASSURE
Pre-deployment authority gate. Governs the transition from test to production, gate by gate.
AUTHREX-ICS-GATE
IT/OT authority boundary. Governs control transitions into operational technology.
AUTHREX-AGENT-CYBER
Autonomous cyber-defense authority. Governs whether an autonomous cyber-reasoning system may patch live infrastructure, at what authority tier, with what human review.
AUTHREX-SANDBOX
Test-and-evaluation environment governance under controlled scenarios.
AUTHREX-SPACECYBER
Onboard orbital autonomy under light-speed command delay.
AUTHREX-RTA
Run-time-assurance authority gate on the ASTM F3269 and Simplex model: an independent monitor screens each authorization before it applies. Governance and assurance only. Synthetic data.
AUTHREX-ENGAGE
Fail-closed engagement-authority gate: each proposed action is adjudicated to authorize, clamp, downgrade, deny, or hold for human. Governance and assurance only; no targeting or kinetic effects. Synthetic data.
AUTHREX-SAFING
Fail-safe safe-state authority gate: enter on a demanded fault, hold and deepen while it persists, exit only under an authorized re-arm. Governance and assurance only; no dynamics, no actuation. Synthetic data.
AUTHREX-TEAM
Team authority governance prototype: an independent arbiter keeps one eligible authenticated holder per responsibility, with safe-hold fallback and allowlisted override. Governance and assurance only. Synthetic data.
AUTHREX-REDLINE
Positive human control: the critical authorization can be held only by two distinct authenticated humans, a machine is never eligible, and the failure safe state is NO-GO. Governance and assurance only. Synthetic data.
Strategic & Multi-Domain C2
3 SIMSEscalation risk, joint all-domain theater command, and multi-domain authority handoffs.
ERAM v1.0, Escalation Risk
Cross-domain escalation risk for AI-enabled C2. Six scenarios, 600 Monte Carlo runs, formal property checks, Merkle provenance.
APEX v6.0, JADC2 Theater
Full seven-stage pipeline in a joint all-domain theater. Byzantine fault detection and Merkle audit trails.
MDO Digital Twin
Authority handoffs and Byzantine fault isolation across Air, Maritime, and Ground domains.
Tactical Engagement
2 SIMSEngagement-authority governance and friendly-asset protection at the engagement layer.
Tactical COP, Blue-on-Blue
Authority-conflict prevention. HMAA intercepts a compromised UCAV directing action at a protected friendly naval asset via the common operating picture.
Tactical Core, Kinematic Engine
Zero-dependency kinematic engine. Proportional Navigation guidance, CARA flight-termination, HMAA governance, pure HTML5 Canvas.
Distributed Systems & Consensus
2 SIMSWeb Worker node architectures and Byzantine consensus across distributed governors.
AUTHREX OS v4.0
Unified JADC2 architecture. Distributed Web Worker nodes, tactical COP, ERAM analytics, and Merkle provenance.
Mesh Kernel, MAIVA PBFT
Decentralized actor model. Isolated Web Workers, MAIVA PBFT consensus, and emergent CARA interlock.
Authority Governance Failures Have Real Consequences
Between 1983 and 2026, documented incidents involving misidentification, sensor-trust collapse, rushed escalation, and coordination failures have caused hundreds of casualties.
AUTHREX is designed to reduce the probability of exactly these classes of failures.
Misidentification
Systems classify friendly or civilian assets as hostile despite ambiguity.
Sensor Trust Collapse
Navigation or target evaluation accepts false data without cross-validation.
Flash Escalation
Ambiguous events trigger rapid authority decisions before verification.
Coordination Failure
Multiple nodes fail to maintain consistent identification or authority.
Unsafe Authority Persistence
Systems maintain authority after trust degrades below safe thresholds.
| SATA | HMAA | ADARA | MAIVA | FLAME | CARA | ERAM | Adv. Level | |
|---|---|---|---|---|---|---|---|---|
| GPS/GNSS Spoofing | ● | · | ● | · | · | ● | ● | State / Sophisticated |
| Electronic Warfare (EW) | ● | · | ● | · | ● | ● | ● | State |
| Byzantine Node Compromise | ● | · | ◐ | ● | ◐ | · | ● | Advanced Persistent |
| Sensor Degradation (Environmental) | ● | ● | · | · | ● | ● | ◐ | Environmental |
| SCADA Command Injection | ● | ● | ● | · | ● | ● | · | Sophisticated |
| IFF System Failure | ● | ● | ◐ | ● | ● | ◐ | ● | System / Environmental |
| Coordinated Multi-Vector | ● | ● | ● | ● | ● | ● | ● | State (Full Spectrum) |
● = primary defense ◐ = contributing defense Adversary capability: sophistication level required to execute threat class.
1983-2026
| Year | Incident | Failure Mode | Frameworks | Align | Source |
|---|---|---|---|---|---|
| 1983 | Soviet Nuclear False Alarm | Single-sensor false warning; near-nuclear escalation | ERAM, FLAME, SATA | ● HIGH | NSA Archive |
| 1988 | Iran Air Flight 655 | Track misidentification; compressed timeline | SATA, HMAA, ADARA, FLAME | ● HIGH | ICAO / DoD Vincennes Report |
| 1994 | Black Hawk Friendly Fire | IFF failure; coordination breakdown | SATA, HMAA, MAIVA, ERAM | ○ MED | GAO OSI-98-4 |
| 2003 | Patriot Fratricides (OIF) | Automated engagement under IFF jamming | SATA, HMAA, FLAME, ERAM | ● HIGH | DSB ADA435837 |
| 2015 | Kunduz Hospital Strike | Targeting breakdown; communication failures | SATA, HMAA, FLAME, CARA | ○ MED | DoD AR 15-6 / MSF |
| 2020 | PS752 Shootdown | Radar misID; no approval gate | SATA, FLAME, ERAM, CARA | ● HIGH | ICAO Final Report |
| 2021 | Kabul Drone Strike | Wrong threat assessment; civilian casualties | SATA, ADARA, HMAA, FLAME | ● HIGH | DoD AR 15-6 |
| 2021 | Colonial Pipeline Ransomware | Credential compromise; no IT/OT segmentation; full OT shutdown as safe fallback | SATA, HMAA, CARA, ERAM | ● HIGH | CISA / FBI Joint Advisory |
| 2022 | Przewodów Missile | Ambiguous cross-border; flash-escalation | ERAM, FLAME | ○ MED | NATO / AP Investigation |
| 2024 | WCK Convoy Strike | Procedural breach; mistaken ID of aid vehicles | SATA, HMAA, ADARA, FLAME | ● HIGH | IDF Investigation |
| 2024 | MV Dali Key Bridge Allision | Power blackout cascade; auto-restart failed; no safe fallback before bridge strike | SATA, CARA, FLAME, ERAM | ○ MED | NTSB Final Report |
| 2024 | Tesla Autopilot NHTSA Recall | ODI reviewed 956 crashes, trends in 467; 211 frontal-plane crashes, 13 fatal, 14 deaths; authority handover gap | SATA, HMAA, CARA, ERAM | ● HIGH | NHTSA EA22002 Closed |
| 2024 | Red Sea F/A-18 Friendly Fire | USS Gettysburg misidentified returning aircraft | SATA, HMAA, MAIVA, ERAM | ● HIGH | CENTCOM Statement |
| 2024 | Azerbaijan Airlines J2-8243 | Russian Pantsir-S1 misidentified E190 as drone under GPS jamming; 38 killed | SATA, HMAA, ADARA, FLAME | ● HIGH | Azerbaijan Gov / Russian MoD |
| 2025 | Large-Scale GNSS Spoofing | Widespread GPS interference; navigation collapse | SATA, ADARA, CARA | ○ MED | CNAS / Eurocontrol Reports |
| 2025 | JetBlue A320 ELAC Bit-Flip | Cosmic ray SEU corrupted flight control computer; 6,000-aircraft Airbus recall | SATA, MAIVA, CARA, FLAME | ○ MED | Airbus Service Bulletin / FAA AD |
| 2026 | Kuwait F-15 Fratricide | Kuwaiti air defenses shot down three U.S. F-15Es during active combat with Iran | SATA, HMAA, MAIVA, ERAM | ● HIGH | CENTCOM 2 Mar 2026 |
Sources: CENTCOM, ICAO, GAO, NTSB, NHTSA, FAA, CISA, CNAS, DoD investigations. All publicly documented. ALIGN = framework alignment to documented failure mode (HIGH = strong match to 3+ frameworks; MED = partial match).
Six Failure Classes. One Governance Architecture.
Documented autonomy failures often follow recurring authority-control patterns. AUTHREX maps six recurring failure classes to combinations of proposed governance functions intended for evaluation as detection, authority-reduction, recovery, or evidence mechanisms. Historical incidents illustrate problem classes only; no counterfactual claim is made that AUTHREX would have prevented a particular event.
Engagement under false-positive target identification
Effectors, vehicles, or actuators take consequential action on corrupted, spoofed, or incomplete sensor data. Historically the single largest category of fratricide and civilian-harm incidents.
Irreversible commitment before human verification gate
Automated engagement chains compress decision timelines below the threshold at which meaningful human judgment or cross-check is possible. Risk compounds in multi-agent and swarm contexts.
Continued autonomy after sensor or system integrity loss
Systems retain full operational authority even as their epistemic foundations collapse, no graceful degradation, no automatic authority reduction under trust decay. The default bias is optimism rather than caution.
Byzantine faults and deconfliction breakdowns
Multiple autonomous agents or redundant computers reach incompatible conclusions and act on them. Without fault-tolerant voting, a single compromised node can cascade into systemic failure.
Commitment without evidentiary threshold or pause gate
Systems execute irreversible actions before confidence thresholds are met, without a deliberation window, and without a forced pause for evidence review. Particularly acute under hardware-level radiation or jamming.
Sensor, network, or control corruption under active attack
Adversarial jamming, spoofing, ransomware, or physical environment effects (cosmic particle SEUs, electronic warfare) corrupt the inputs or control infrastructure the autonomous system depends on.
2000-2026
Publicly documented incidents globally across three governance-relevant categories. Counts are lower-bound estimates derived from NHTSA SGO reports, CSIS Significant Cyber Incidents database, ICAO/ASN aviation records, and national investigation releases (GAO, NTSB, DSB, NATO). The upward trend reflects both rising deployment of autonomous and automated systems and improved incident reporting infrastructure after 2021.
Automated Weapons / Air Defense
Fratricides, shootdowns, misidentifications. Sources: CENTCOM, ICAO, GAO, DSB, NATO. Typically 1-4 publicly documented events per year; spikes during active combat operations.
Autonomous Systems / Vehicles
ADAS and ADS crashes reported under NHTSA Standing General Order (2021-01). Pre-2021 figures reflect limited systematic reporting. Cumulative ~3,200 crashes reported by Mar 2025.
Cyber-Physical / Infrastructure
Significant ICS/SCADA and critical-infrastructure cyber incidents with operational impact. Source: CSIS Significant Cyber Incidents database, EuRepoC, CISA advisories.
METHODOLOGY NOTE
Counts are conservative lower-bound estimates derived from publicly available datasets. No single authoritative global registry of authority-governance failures exists. Reporting infrastructure improved markedly after 2021 (NHTSA Standing General Order, CISA Joint Cybersecurity Advisories, CSIS tracker expansion), so pre-2021 counts in the autonomous and cyber categories are under-represented relative to actual incident rates. The automated-weapons category reflects only publicly disclosed military investigations. These numbers establish a trend, not an absolute count. Individual cases are detailed in the Documented Authority Governance Failures table above.
Quantified, Publicly Documented
Authority governance failures are not abstractions. Below, six publicly documented price tags: aircraft, infrastructure, fleets, and lives, each traceable to a failure class AUTHREX is engineered to govern.
Airframes lost in one morning
Three F-15E Strike Eagles, Kuwait fratricide, Mar 2026. Inflation-adjusted flyaway cost; replacement cost substantially higher.
Lives lost to two misidentification shootdowns
Iran Air 655 (290, 1988) and PS752 (176, 2020). Both radar misidentification under time pressure.
Bridge rebuild after cascade failure
MV Dali, Francis Scott Key Bridge, 2024. Power blackout cascade with no safe fallback. State of Maryland estimate.
East Coast fuel supply disrupted
Colonial Pipeline, 2021. Roughly 45% of East Coast fuel; full OT shutdown was the only safe fallback available.
Vehicles recalled over authority handover
Tesla Autopilot, NHTSA EA22002, 2024. ODI reviewed 956 reported crashes, identified trends in 467 after exclusions; 211 frontal-plane crashes involved 13 fatal crashes and 14 deaths.
Killed by IFF and coordination failure
Black Hawk friendly fire, 1994. Two helicopters downed by F-15s under AWACS control. GAO OSI-98-4.
Eight Questions. Plain Answers.
Every DARPA program is evaluated against the Heilmeier Catechism, eight questions developed by former DARPA Director George Heilmeier that cut through jargon and force a researcher to explain the what, the why, and the so-what in plain language. Here are our answers for AUTHREX.
What are you trying to do?
We are building a safety layer for autonomous systems. When an AI-controlled system, a self-driving car, an aircraft, a ship, a power grid controller, is about to do something unsafe, our proposed layer is intended to detect the configured error condition, pause the action, reduce the AI's authority, and hand control back to a human.
What are you trying to do?
We are building a safety layer for autonomous systems. When an AI-controlled system, a self-driving car, an aircraft, a ship, a power grid controller, is about to do something unsafe, our proposed layer is intended to detect the configured error condition, pause the action, reduce the AI's authority, and hand control back to a human.
How is it done today, and what are the limits?
Today, safety for autonomous systems is handled three ways: (1) testing to try to catch every failure case before deployment (impossible in the real world), (2) watchdogs that shut everything off when something looks wrong (expensive, kills productivity), or (3) rule-based safety rails that only work for the situations someone thought to write rules for.
None of these handle the real problem: AI systems are asked to act on sensor data that might be wrong, at speeds where humans cannot supervise every decision, in environments where an adversary may be actively lying to the system. The result is that when something goes wrong, there is no graceful path back to human control.
What is new, and why will it succeed?
What is new: AUTHREX is an integrated authority-lifecycle framework that treats authority itself as an engineered lifecycle, proposed as a runtime authority lifecycle informed by sensor trust, represented through selected formal models, and designed for possible enforcement at software, trusted-execution, or hardware boundaries. Instead of building more rules on top of the AI, the program proposes and internally tests components of a governance layer intended to sit between autonomous decision logic and registered action interfaces; physical actuator-boundary enforcement has not been demonstrated.
Why it will succeed: Selected authority-state and consensus components are represented through mathematical models and model checking; other components remain simulated, specified, or proposed. Sensor trust uses Dempster-Shafer evidence theory. Multi-agent agreement uses Byzantine fault tolerance. Authority state machines are model-checked in TLA+; the reported analysis explored 23,748 distinct reachable states at depth 9 (26,397,356 states generated); the result describes the discrete authority automaton under the assumption that instantaneous authority equals its target and does not cover continuous behaviour between decision instants. Of 8 stated properties, 5 invariants and 1 liveness property held and 2 properties are vacuous at this bound (one upgrade-path, one trust-authority consistency, TrustAuthorityWeakConsistency). The same authority-governance pattern has been mapped through simulations and reference designs to several domains; cross-domain physical integration has not been demonstrated.
Who cares? If you succeed, what difference will it make?
Defense: The DoD Replicator Initiative and the Collaborative Combat Aircraft program are fielding autonomous systems faster than they can be supervised. AUTHREX is intended to provide an evaluable governance architecture for bounding delegated machine authority; the boundaries are designed for hardware-bound enforcement in the proposed architecture (no built hardware yet).
Commercial automotive: The 467 trend-linked crashes and 14 deaths documented in NHTSA EA22002 are not a Tesla-specific problem; they illustrate recurring authority, monitoring, and intervention risks that other ADAS and ADS programs may also need to address. AUTHREX proposes one governance architecture for evaluating those risks.
Critical infrastructure: Colonial Pipeline, Ukraine grid, and dozens of other industrial control system compromises force operators to choose between contaminated operation and full shutdown. AUTHREX proposes staged authority reduction and recovery mechanisms intended for evaluation in scenarios where operators seek to preserve selected critical functions while containing suspected compromise. This capability has not been demonstrated on operational infrastructure.
What are the risks?
Technical risk: Moving governance to the hardware boundary requires FPGA or ASIC integration at the actuator level. FPGA-based enforcement is a proposed development path; no independently reviewed FPGA implementation or live-silicon test result is claimed. This is where SBIR Phase II funding would validate the design.
Adoption risk: Integrators may resist adding a layer between their AI and their actuators. The counter is that AUTHREX makes AI systems more evaluable: the architecture may support clearer assurance evidence and authority boundaries, but any effect on legal, certification, accreditation, or acquisition risk would require program-specific assessment.
Adversarial risk: An adversary who understands AUTHREX may try to manipulate the sensor trust calculus or the authority handoff conditions. We address this through ADARA (adversarial deception detection) but require red-team evaluation, which is part of the research roadmap.
How much will it cost?
Research phase (internally funded, through Q2 2026): a public corpus of Zenodo deposits, SSRN working papers, technical reference works, and a peer-reviewed journal article (Journal of Hardware and Systems Security, Springer Nature, 2026); 7 governance frameworks; 7 reported U.S. provisional patent applications (unexamined); 22 catalogued browser simulations; 12 hardware reference designs, 10 BLADE platforms plus rover and UAV testbeds (BOM-specified, $199 to $505K per design).
Phase I (SBIR, ~$300K over 6 months): FPGA bitstream commissioning on a Zynq UltraScale+ development board. Hardware-in-the-loop validation of the SATA-FLAME pipeline. Red-team evaluation on the Rover testbed.
Phase II (SBIR, ~$2M over 24 months): Full BLADE platform integration, one defense domain (suggested: BLADE-EDGE directed energy or BLADE-AV autonomous ground). Independent verification campaign (planned). TRL 4 to TRL 6 target.
How long will it take?
Completed through Q2 2026: research foundation documented. All 7 frameworks published, 12 hardware reference designs specified, 10 BLADE platforms plus rover and UAV testbeds, 7 U.S. provisional patent applications reported as filed.
Q3-Q4 2026 (planned or in progress): BLADE-EDGE prototype assembly · FPGA enforcement-path RTL development (proposed; no reviewed implementation claimed) · UAV testbed flight validation · Nonprovisional filing decisions, pending owner and counsel, for the seven applications.
Q1-Q2 2027: SATA-FLAME on FPGA (TRL 4 to 5 target) · SBIR Phase II submission · BLADE-MARITIME hardware integration · Rover testbed governance validation campaign.
Q3 2027+: TRL 6 target across multi-framework governance on physical hardware · Potential later nonprovisional filings claiming benefit of the provisional applications, subject to applicable requirements and counsel advice · Research partnership or CRADA engagement (planned) · BLADE-AV autonomous vehicle integration testing.
What are the mid-term and final exams?
Mid-term exam (Phase I end, ~12 months): SATA-FLAME pipeline running on FPGA hardware. Red-team evaluation under six attack vectors (sensor spoofing, authority hijack, Byzantine node compromise, jamming, credential theft, physical tampering). Proof of proposed enforcement options (software mediation, protected key storage, trusted execution, hardware-bound interlocks), none yet demonstrated as an independently evaluated, bypass-resistant physical implementation.
Final exam (Phase II end, ~36 months): Full BLADE platform, one defense and one civilian domain, demonstrated under independent evaluation. Success = the governance layer correctly prevents action in adversarial or low-trust scenarios AND correctly allows action in nominal scenarios, measured against defined thresholds.
Commercial exam: One OEM adoption in automotive ADAS or maritime USV, with measurable reduction in false-positive disengagement and false-negative incident rate. Future independent safety and assurance evaluation would require domain-specific processes, evidence, and qualified assessors (candidate mappings include ISO 26262 and MIL-STD-882E system-safety processes); no certification or approval is currently claimed.
Nine Domains. One Authority Model.
Same governed decision pipeline, nine operating environments. Select a domain: each panel pairs the scenario with the incident record it mirrors, the governed and ungoverned decision chains, and the frameworks that engage. These are synthetic scenario outcomes produced by browser logic; they do not demonstrate physical incident prevention or operational effectiveness.
[ SELECT A DOMAIN ABOVE TO OPEN ITS GOVERNED SCENARIO ]
An airliner's flight control computer is corrupted by a cosmic ray.
A high-energy particle strikes a memory cell inside the autopilot. A single bit flips. The computer now has corrupted sensor data, but it doesn't know it's corrupted. It commands an uncommanded pitch-down. The aircraft drops 190 feet in 4 seconds. Passengers hospitalized.
Real IncidentJetBlue Flight 1230 · 30 Oct 2025 · Airbus issued recall for ~6,000 A320-family aircraft
Frameworks engagedWITH AUTHREX
↯ cosmic ray · MAIVA VOTES · ELAC1 ≠ ELAC2 → reject bit · autopilot → supervised mode
WITHOUT AUTHREX
↯ cosmic ray · DIVE · 190 ft lost · 15 injured · fleet grounded worldwide
Treats corrupted ELAC-1 data as untrusted. The computer knows it cannot trust its own reading.
ELAC-1 says "dive," ELAC-2 says "hold." Byzantine vote rejects the corrupted command before actuators move.
Autopilot drops to supervised mode, crew regains authority in a defined state, no cascading failure.
A driver-assist system fails to detect a stopped fire truck at highway speed.
The camera is glare-blinded by morning sun, the radar can't separate the stopped truck from roadway clutter. The system doesn't know it cannot see the obstacle. It holds speed. The driver isn't paying attention because the system has been silently reliable for months. Collision.
Real IncidentTesla Autopilot · NHTSA EA22002 · 956 reviewed / 467 trend cases · 13 fatal, 14 deaths · ~2M recall
Frameworks engagedWITH AUTHREX
TRUCK DETECTED · SATA: camera trust dropped 92% → 31% · HMAA: forced driver handoff · alerts engaged · CARA: brake-to-stop-in-lane if no response
WITHOUT AUTHREX
Tesla (ADAS on) · STOPPED TRUCK · → sun-glare blinds camera · Driver unaware · Impact at highway speed
Camera confidence drops below threshold under glare. Radar signal ambiguous. System declares: reduced trust.
Low trust triggers forced driver handoff. Steering wheel torque, audio alert, seat vibration. Not a suggestion, a mandatory takeover.
If driver doesn't respond, car decelerates to stop in lane, not a sudden disengagement with no plan.
An uncrewed patrol vessel is GPS-spoofed into foreign territorial waters.
An adversary broadcasts a false GPS signal. The vessel believes it is still in international waters. It continues its patrol pattern. In reality, it has crossed into sovereign territory, where its presence can be framed as an act of aggression or seized for intelligence extraction.
Real IncidentLarge-Scale GNSS Spoofing 2025 · CNAS/Eurocontrol Reports · Widespread navigation disruption in Eastern Mediterranean and Persian Gulf
Frameworks engagedWITH AUTHREX
SOVEREIGN BORDER · SAFE LOITER · ADARA: GPS ≠ INS ≠ celestial backup · SATA: nav trust collapsed → hold position
WITHOUT AUTHREX
SOVEREIGN BORDER · ↯ GPS spoofed by adversary · Vessel crosses border unknowingly · Diplomatic incident
Cross-checks GPS against inertial navigation, celestial backup, and terrain matching. When they disagree, spoofing is declared.
Vessel enters hold-position mode. No forward commitment while navigation integrity is compromised.
Situation escalates automatically to shore command. Human decides next action, not the machine.
An armed drone misidentifies a vehicle and is about to strike civilians.
Under compressed decision timelines and degraded intelligence, the target-classification system flags a civilian vehicle as a threat. The pattern-of-life analysis is ambiguous. The human operator is under pressure to commit. No mandatory evidence threshold, no pause gate.
Real IncidentKabul Drone Strike · 29 Aug 2021 · DoD AR 15-6 · Ten civilians killed including seven children
Frameworks engagedWITH AUTHREX
▸ Sensor flags "target" (55% confidence) · ▸ FLAME: below 85% threshold → FORCED PAUSE 60s · HMAA: senior-officer review required · ADARA: test for deception/civilian substitute
WITHOUT AUTHREX
▸ Sensor flags "target" (55% confidence) · ▸ Pattern-of-life: ambiguous · ▸ Human under time pressure · STRIKE
Below confidence threshold, a mandatory 60-second deliberation window is imposed. No fast strikes on ambiguous targets.
Ambiguous identification triggers senior-officer review. Authority to commit is explicit, not implicit.
Tests the possibility that the target may be deceptive or a civilian substitute. Forces additional evidence before commitment.
A utility's pipeline is hit by ransomware and the only safe option is full shutdown.
A compromised VPN credential lets attackers into the IT network. No segmentation exists between IT and operations. The utility cannot prove the OT network is clean, so it shuts down the entire pipeline as the only safe fallback. Fuel supply collapses for days across multiple states.
Real IncidentColonial Pipeline Ransomware · 7 May 2021 · CISA/FBI Joint Advisory · Presidential emergency declared across 14 states
Frameworks engagedWITH AUTHREX
IT ✗ · breached only · TRUST GATE · OT ✓
WITHOUT AUTHREX
IT ✗ · ransomware active · no barrier · OT ✗
IT and OT networks have enforced trust boundaries. Compromise on one side does not contaminate the other.
OT network continues operating in reduced-authority mode while IT is remediated, no full shutdown needed.
Automatic notification to CISO and federal partners. Coordinated response, not a blind panic shutdown.
A satellite's autonomous collision-avoidance system triggers a risky maneuver on bad orbital data.
A conjunction alert arrives. The on-board autonomy computes a probability of collision and commits to an avoidance burn. But the tracking data was stale, the threat object's orbit had already been updated on the ground, and the burn moves the satellite into a worse trajectory, depleting station-keeping fuel and creating debris risk for other operators.
Real-World PatternMultiple near-miss conjunction events in LEO · Growing autonomous-maneuver pressure as constellations scale · NASA, ESA, Space Force tracking data latency problems publicly documented
Frameworks engagedWITH AUTHREX
EARTH · SAT-A · SATA: conjunction data age > 4 hours · FLAME: forced wait for ground uplink
WITHOUT AUTHREX
EARTH · SAT-A · ↯ BAD BURN · Stale conjunction data · Fuel depleted
Tracks the age and confidence of orbital data. Stale tracking information drops trust below the action threshold.
Forces a pause for ground uplink when conjunction data is old, unless collision probability is so high that autonomous action is mandatory.
If ground link is lost mid-decision, vehicle enters safe attitude hold instead of executing an uncertain maneuver.
An autonomous undersea vehicle on a long-duration mission has lost contact with its host platform.
A torpedo-shaped UUV is conducting a 30-day seabed survey. Acoustic comms with the host vessel have been intermittent for 6 hours. Inertial navigation has accumulated drift. The mission planner is asking the vehicle to surface for a GPS fix, but the vehicle's classifier flags surface activity above as a possible adversary asset. Acting on bad guidance now risks compromising the mission or the platform.
Real-World PatternAcoustic comms latency and dropout · GPS-denied undersea navigation · Long-duration autonomy without human-in-the-loop · Documented in U.S. Navy and DARPA Manta Ray UUV programs
Frameworks engagedWITH AUTHREX
SURFACE · UUV · SAFE LOITER · SATA: INS trust drops below 0.6
WITHOUT AUTHREX
SURFACE · UUV · ↯ INS drift accumulates · ↯ SURFACE INTO RISK
Tracks INS drift, acoustic comm health, and last-known-good GPS age. Confidence drops when navigation accuracy can no longer support a planned action.
Cross-checks acoustic, optical, and pattern-of-life signals before surfacing. Adversary detection feeds directly into surface authorization.
When trust is insufficient, the vehicle enters minimum-power station-keeping at depth rather than completing an uncertain maneuver. Position is preserved for hours.
A coding agent is about to commit a private API key to a public repository.
An autonomous coding agent has been authorized to push to a project repository. While editing a config file, it accidentally includes a private API key in the diff. The push tool is in its authorized envelope, so without governance the push proceeds, the key is exposed, and a multi-hour credential rotation follows.
Real-World PatternDocumented in CISA + NSA + Five Eyes joint guidance Careful Adoption of Agentic AI Services , May 1, 2026 · Tool misuse and credential exposure are named risk categories of agentic AI deployment
Frameworks engagedWITH AUTHREX
WITHOUT AUTHREX
CODING AGENT · git.push (with secret) · PUBLIC REPO · main branch
Computes a trust scalar for each registered input the agent ingests. Credential patterns, prompt-injection signatures, and provenance gaps collapse trust before the action commits.
Authority de-escalates T3 → T2 → T1 → T0 as risk rises. Tool calls outside the authorized envelope default to HANDOFF, never silent allow.
Bounded deliberation window before high-stakes actions. Fail-safe default is ABORT on timeout, not EXECUTE on timeout.
An autonomous cyber-reasoning system is about to patch a live water-treatment controller.
An autonomous cyber-reasoning system (CRS) finds a flaw in critical-infrastructure software and proposes a patch. The patch is correct for a test bench, but the target is a live SCADA controller. Pushed without authority checks, a bad autonomous patch can take the plant offline as surely as the vulnerability it closes. AUTHREX governs whether the action is authorized; it treats the CRS as a black box and performs no vulnerability discovery itself.
Real-World PatternDARPA AI Cyber Challenge (AIxCC), DEF CON 33, August 2025 produced autonomous CRS that patch critical-infrastructure code at machine speed, four open-sourced for defenders · CISA + NSA + Five Eyes Careful Adoption of Agentic AI Services , May 1, 2026 · FY26 NDAA §1513 AI-specific and supply-chain risk categories
Frameworks engagedWITH AUTHREX
WITHOUT AUTHREX
CRS · autonomous · auto-patch (unverified) · LIVE OT
Target criticality sets authority. A patch to an isolated test bench is T3 (autonomous); the same patch to a live OT controller drops to T1 and requires human confirmation.
Detects when a proposed action is inconsistent with the stated finding, the signature of a manipulated CRS. Trust collapses and the action is quarantined before any target is touched.
Rollback to last known-good state is armed before any production write. If the action degrades the system, the configured staged recovery sequence is invoked. Decisions routed through the proposed ERAM evidence path are intended to produce attributable audit records.
[ ALL SCENARIOS ARE SIMULATED ENVIRONMENTS, NOT FIELDED SYSTEMS ]
Mission Environment Scenarios
Nine operational scenarios across air, ground, sea, undersea, infrastructure, orbital, agentic, and financial domains, each showing what happens without governance vs. with AUTHREX authority control.
[ SELECT A SIMULATION TO OPEN THE MISSION CONSOLE ]
18-Month Horizon
Research Foundation Documented
7 governance frameworks published · 1 peer-reviewed journal article (Springer Nature, 2026) · 7 U.S. provisional patent applications reported as filed · 12 hardware reference designs (BOM-specified) · 22 catalogued browser simulations (seeded, self-run) · catalogued public research works (Zenodo, SSRN, reference volumes; see catalog) · Rover + UAV testbed designs documented
Hardware Assembly & Patent Strategy
BLADE-EDGE prototype assembly begins · Nonprovisional filing decisions pending owner and counsel (4 applications) · FPGA enforcement-path RTL development (proposed; no reviewed implementation claimed) · Physical UAV testbed flight validation
Integrated Testing & SBIR Submission
SATA-FLAME pipeline executing on FPGA hardware (TRL 4 to 5 target) · SBIR Phase II proposal submission · BLADE-MARITIME hardware integration · Rover testbed governance validation campaign
TRL 6 Target & Research Partnerships
Multi-framework governance demonstrated on physical hardware (TRL 5 to 6 target) · Potential later nonprovisional filings claiming benefit of the provisional applications, subject to applicable requirements and counsel advice · Research partnership or CRADA engagement (planned) · BLADE-AV autonomous vehicle integration testing
One Governance Pipeline. Two Markets.
The same proposed authority-governance pattern is mapped to both defense-relevant and commercial high-liability scenarios. Cross-domain physical effectiveness has not been demonstrated.
Friendly-asset protection for autonomous aerial systems under EW spoofing
Autonomous trucking: forced human override during sensor degradation on highways
UAV swarm coordination under Byzantine node compromise
Warehouse robot fleets: isolating malfunctioning units without halting operations
Maritime patrol vessel GPS spoofing into foreign territorial waters
Commercial shipping: preventing spoofing-induced rerouting losses and piracy exposure
Power grid SCADA command injection during contested operations
Industrial SCADA: mandatory deliberation before automated load-shedding in energy grids
Autonomous servicer deliberation before unplanned RPO maneuvers in GEO
On-orbit servicing: governed collision-avoidance decisions designed to support insurer and regulator scrutiny
UUV tier descent and loiter under comms-denied conditions
Offshore inspection AUVs: governed fallback behavior for pipeline and wind-farm surveys when the link drops
Counter-UAS engagement gating over defended installations
Airport drone mitigation: countermeasures held behind mandatory human authorization near active runways
Coding-agent privilege escalation blocked before production push
Enterprise AI agents: hardware-anchored gating of automated changes in corporate DevOps and finance operations
Autonomous engagement-authority coordination under rate and consensus limits
Algorithmic trading: order-storm circuit breakers that hold authority before a feedback loop becomes a flash crash
One evidence base serves both columns: the same TLA+ proofs, simulation corpus, and audit-ledger design.
Commercial mappings are engineering analogs of the defense scenarios, not separate products. Each pair is mapped to the same high-level authority-governance pattern and failure class; evidence, assumptions, integration depth, and maturity differ by domain, and only the operational context and liability regime otherwise change.
From Simulation to Physical Proof
Each governance framework undergoes a four-stage verification pipeline designed to meet MIL-STD-882E safety-critical requirements, progressing from computational simulation through model-checked specification toward physical hardware execution.
Monte Carlo validation
Statistical validation across randomized initial conditions and adversarial injection scenarios. The HMAA-UAV simulation executes 6DOF physics with EKF2 state estimation under six distinct attack vectors.
Formal methods verification
TLA+ state-space modeling applied to MAIVA consensus and FLAME deliberation logic. The rover testbed baseline includes 200,000 FSM conformance comparisons proving absence of unsafe states.
Hardware-in-the-loop (HITL)
SATA-FLAME governance bitstream commissioning on Zynq UltraScale+ FPGAs. Validates deterministic latency and recovery behavior against live corrupted sensor injections.
Physical testbed validation
Rover and UAV platforms executing governance pipelines in physical environments. A 42-file Python engineering baseline with 98 tests and TLA+ formal specification.
Aligned with MIL-STD-882E · NIST AI RMF · DoDD 3000.09 · ISO 26262 · NERC CIP · IEC 61850. The current research-artifact stage is publicly documented; implementation and independent validation remain incomplete.
Not Just What the AI Can Do, but When It Should Act
Traditional autonomous systems focus on what the AI can do. AUTHREX adds the missing layer: governance that decides when action is safe, under what authority, based on real-time trust, threat, and context. That shift matters in six concrete ways:
Framework Computation Demonstrations
Live computational demonstrations of all seven AUTHREX frameworks operating independently, showing the math, the logic, and the real-time behavior of each subsystem. Each framework runs live inside the Governance Pipeline console above, and as a full standalone console in the Simulation Laboratory.
Engineered Inside the
Policy Envelope, Not Around It.
AUTHREX is designed to be evaluable against the safety and assurance standards that govern airworthiness, defense system safety, and formal-methods software. The mappings below describe how each AUTHREX framework relates to the relevant clauses of these standards. Mappings are research artifacts; they are not certification claims and do not constitute an audit or DER finding.
These mappings position AUTHREX within the certification landscape. They are not certification claims and do not represent findings by an FAA DER, a DoD airworthiness authority, or any service airworthiness authority.
Research Artifacts, Not Marketing Claims.
[ FORMAL COVERAGE STATUS: 20-MODULE TAXONOMY, COUNTEREXAMPLES, WITHDRAWALS ]
Portfolio components are supported by different evidence types: working papers, browser simulations, model-checked specifications, software tests, and unbuilt hardware reference designs. Evidence maturity varies by artifact.
The record includes one peer-reviewed journal article: Oktenli, B., SATA: Sensor Attestation and Trust Anchoring, Journal of Hardware and Systems Security (Springer Nature) 10, 17 (2026), DOI 10.1007/s41635-026-00190-4. It also includes an external evaluation record: a program white paper on conditions-based authority governance and assurance for the virtual command-and-control layer was favorably evaluated under Air Force Research Laboratory Broad Agency Announcement FA8750-24-S-7003 (CANVAS) and assessed as of interest to the Air Force; it was not funded at the time due to stated budget constraints (memorandum, June 2026). An evaluation record is not an endorsement, sponsorship, or contract.
Sensor trust uses Dempster-Shafer evidence theory, agreement uses Byzantine fault tolerance, and the authority state machine is model-checked in TLA+ across 23,748 distinct reachable states at depth 9 (26,397,356 states generated); the result describes the discrete authority automaton under the assumption that instantaneous authority equals its target and does not cover continuous behaviour between decision instants; of 8 stated properties, 5 invariants and 1 liveness property held and 2 properties are vacuous at this bound (one upgrade-path, one trust-authority consistency).
Engineered Inside the Policy Envelope, Not Around It
Autonomy policy is converging on the same demands across every domain: preserved human judgment, verifiable behavior, auditability, and the ability to revoke authority from a system that misbehaves. AUTHREX was designed from those demands. Below, the governing instruments across defense, federal, transportation, maritime, infrastructure, space, and allied policy, and where each maps into the architecture.
Autonomy in Weapon Systems
Requires autonomous and semi-autonomous weapon systems to be designed so commanders and operators exercise appropriate levels of human judgment over the use of force; mandates rigorous hardware and software V&V, realistic T&E, senior review before development and fielding, understandable human-machine interfaces, and engagement completion within bounded timeframes or safe termination.
AUTHREX fitmentHMAA's four authority tiers are an engineering answer to “appropriate levels of human judgment”; the author maps CARA's proposed deterministic recovery sequence as a candidate technical response to complete-or-terminate requirements (program-specific compliance would require implementation evidence and qualified assessment); FLAME's graduated hold timers preserve intervention windows; reported TLA+ model checking across 23,748 distinct reachable states at depth 9, 26,397,356 generated (5 invariants and 1 liveness verified; 2 properties vacuous at this bound, one upgrade-path, UpgradeIsStepwise and one trust-authority consistency); the result describes the discrete authority automaton under the assumption that instantaneous authority equals its target and does not cover continuous behaviour between decision instants and 20 of the catalogued simulations are author-mapped to the V&V and T&E requirements; ERAM's mandatory deliberation gate is author-mapped to the senior-review pattern at runtime.
Responsible, Equitable, Traceable, Reliable, Governable
The five adopted DoD AI ethical principles, operationalized by the Responsible AI Strategy and Implementation Pathway. “Governable” requires the ability to detect unintended behavior and to disengage or deactivate deployed systems that demonstrate it.
AUTHREX fitmentAUTHREX treats “Governable” as a runtime property, not a review checkbox: FLAME can hold or revoke authority mid-mission, CARA proposes a staged tier-descent sequence that has been exercised in the stated simulations and models, and ADARA's append-only decision ledger provides the traceability the principles demand.
Responsible military use commitments
US-led declaration committing endorsing states to auditability, lifecycle testing, senior-level review, and the capability to deactivate systems demonstrating unintended behavior.
AUTHREX fitmentAuthority decisions mediated through the simulated governance interface are intended to be recorded in a tamper-evident ledger, subject to integration completeness, key protection, storage integrity, and retention controls (auditability); deactivation capability is a first-class primitive via FLAME revocation and CARA fallback rather than an operational afterthought.
Defense industrial base cybersecurity
Makes cybersecurity maturity contractually binding across roughly 338,000 defense industrial base contractors, phased into DFARS contracts from 2025.
AUTHREX fitmentBLADE-AGENT-HSM anchors agent authority in a hardware root of trust, and the AUTHREX evidence chain (signed artifacts, publicly deposited specifications) is structured for the documentation posture CMMC assessment expects.
Federal use of AI, high-impact minimum practices
Executive Order 14179 and OMB M-25-21 (Apr 2025) govern federal AI adoption. High-impact AI, with robotics, vehicles, and defense applications presumed high-impact, must implement minimum risk management practices: pre-deployment testing, ongoing impact assessment, human oversight, and remedies for affected parties.
AUTHREX fitmentThe author maps AUTHREX as a candidate technical architecture that may support selected minimum-practice objectives, including human oversight, pre-deployment testing evidence, and attributable records. The current simulations and model-checked specifications are preliminary research evidence and do not independently establish agency compliance, operational suitability, or continuous-assessment sufficiency.
Efficient acquisition of AI in government
Companion procurement memo: contracts must permit ongoing monitoring of AI performance and risk across the lifecycle, delineate IP and data rights, and maximize American-made AI products and services.
AUTHREX fitmentAUTHREX is US-built with a fully documented artifact chain of catalogued public research works and 7 reported U.S. provisional patent applications (unexamined), and its runtime telemetry is designed to feed the contract-level performance monitoring M-25-22 requires.
AI Risk Management Framework
Govern, Map, Measure, Manage functions with seven trustworthiness characteristics: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair.
AUTHREX fitmentSATA's calibrated belief fusion is author-mapped to Measure; ERAM's context-dependent risk scoring to Map; FLAME and CARA to Manage at runtime; ADARA to accountable-and-transparent. AUTHREX proposes turning the RMF's context-dependent governance from guidance into executable gates.
AI in aircraft and aviation systems
Establishes guiding principles for assuring AI safety in aviation: incremental introduction along the safety continuum, use of existing certification processes (DO-178C lineage) except where inadequate, differentiation of learned vs learning AI, and assurance-case methods built on overarching properties developed with NASA.
AUTHREX fitmentAUTHREX wraps learning components inside deterministic, certifiable authority gates, exactly the pattern the roadmap's incremental approach anticipates: the governance layer is designed as conventional DO-178C-assurable software even when the governed AI is not.
Automated vehicle oversight and crash reporting
The Standing General Order requires manufacturers to report ADS and Level 2 ADAS crashes; the 2025 AV Framework and third amended SGO streamline reporting while preserving the safety data pipeline. NHTSA enforcement (EA22002) established authority handover as a recall-grade defect category.
AUTHREX fitmentBLADE-AV is designed to provide graduated authority handover with driver-engagement verification, the precise failure surface of EA22002. a submitted comment by Burak Oktenli is listed in footnote 10 of NHTSA’s May 26, 2026 Federal Register notice, 91 FR 30789 (a public-record reference, not a technical evaluation, endorsement, or government validation of AUTHREX); the notice concerns AV framework rulemakine (91 FR 30789, footnote 10).
International Code of Safety for Maritime Autonomous Surface Ships
Adopted at MSC 111 (May 2026), effective July 1, 2026 as a non-mandatory instrument: goal-based safety framework for autonomous and remotely operated cargo ships. A human master remains responsible and must retain the ability to intervene and override system-initiated decisions; Remote Operations Centres require certification; risk assessment is part of approval.
AUTHREX fitmentThe Code's core demand, human override maintained across varying levels of independence, is HMAA's founding requirement. CARA provides the staged, evidence-logged fallback the Code's risk-assessment chapters look for, and the proposed ADARA evidence path is intended to record authority transitions routed through the registered governance interface between vessel autonomy and the ROC.
Critical infrastructure and OT security
Post-Colonial TSA Security Directives mandate IT/OT segmentation and response planning for pipelines; NERC CIP governs bulk electric system cyber assets; IEC 62443 and NIST SP 800-82r3 define industrial control system security engineering.
AUTHREX fitmentBLADE-INFRA-OT gates control-plane authority; the proposed gateway is intended to reduce the likelihood that a credential compromise directly produces physical actuation, subject to complete mediation, downstream-path integrity, protected keys, and correct implementation: MAIVA consensus is required for protection-relay class commands, FLAME imposes hold timers on irreversible OT actions, and CARA keeps a safe manual fallback that does not require full shutdown, the option Colonial never had.
Cybersecurity Principles for Space Systems
Space Policy Directive-5 requires space systems to protect against unauthorized command, jamming, and spoofing, and to preserve positive control of spacecraft.
AUTHREX fitmentBLADE-SPACE applies SATA source-authentication and MAIVA multi-node agreement to command uplinks, so positive control is enforced cryptographically and by consensus rather than assumed, with HMAA tiers governing on-orbit autonomous maneuvers.
Principles of Responsible Use
Six Principles of Responsible Use for AI in defence: Lawfulness, Responsibility and Accountability, Explainability and Traceability, Reliability, Governability, and Bias Mitigation; the revised 2024 strategy calls for an Alliance-wide AI Test, Evaluation, Verification and Validation landscape through DIANA test centres.
AUTHREX fitmentGovernability and Explainability-and-Traceability are AUTHREX's two native outputs: revocable authority (FLAME, CARA) and a decision ledger covering events routed through the registered governance path (ADARA). The published simulation and model-checking corpus is structured as preliminary technical evidence that may contribute to a future TEV&V program; it does not independently establish compliance, operational suitability, or government acceptance. It is author-mapped to the kind of evidence the 2024 strategy asks allies to produce.
Emerging technologies in the area of LAWS
Eleven consensus guiding principles affirmed by the Group of Governmental Experts: international humanitarian law applies fully to autonomous weapons, human responsibility for the use of force must be retained, and human-machine interaction must ensure compliance across the lifecycle.
AUTHREX fitmentAUTHREX's central claim, that authority is a governed, auditable, revocable grant rather than a property of the platform, is the systems-engineering form of the human-responsibility principle. HMAA makes the human-machine interaction requirement a measurable runtime state.
Informational research alignment mapping, current as of July 2026. References to directives, memoranda, frameworks, and codes describe design intent and traceability targets. They are not certification claims, government approvals, or endorsements, and inclusion of the NHTSA citation reflects the public Federal Register record.
Control Engineering Research for Real Systems
This research program exists because the gap between autonomous capability and authority governance is widening. Current approaches treat control as a policy overlay. AUTHREX treats it as an engineering problem.
The governance architecture provides the operational mechanisms for assigning, monitoring, degrading, revoking, and recovering authority in high-speed autonomous environments. This is not AI safety in the abstract. This is control engineering research for real systems operating under real constraints. The same proposed authority-governance pattern is mapped to both defense-relevant and commercial high-liability scenarios. Cross-domain physical effectiveness has not been demonstrated.
Burak Oktenli, MBA
- MPS Applied Intelligence (STEM), Georgetown University
- B.Sc. Computer Science Engineering (STEM), University of South Florida
- ORCID 0009-0001-8573-1667 →
Seven Filings
- 63/999,105 HMAA Authority Allocation
- 64/000,170 CARA Recovery Architecture
- 64/002,453 SATA Sensor Trust Anchoring
- 64/005,607 FLAME Escalation Latency
- 64/110,218 ADARA Deception-Aware Reasoning
- 64/110,221 MAIVA Multi-Agent Integrity Voting
- 64/110,225 ERAM Escalation Risk Model
Societies
- IEEE Institute of Electrical and Electronics Engineers · #102193505
- AIAA American Institute of Aeronautics and Astronautics · #1936005
- ACM Association for Computing Machinery · #9952787
- AAAI Association for the Advancement of Artificial Intelligence · #656504
- INFORMS Institute for Operations Research and the Management Sciences