
Defense
Autonomous aerial systems, engagement-authority coordination, and counter-UAS gating gated behind verified trust and human authority.
BLADE-EDGEBLADE-CUASBLADE-SWARM Explore the domain →
Space
Governed deliberation before unplanned RPO maneuvers and constellation authority under contested comms.
BLADE-SPACE Explore the domain →
Maritime & Undersea
Surface patrol under GPS deception and UUV tier descent when the link drops. Governed fallback, not silence.
BLADE-MARITIMEBLADE-UUV Explore the domain →
Critical Infrastructure
Command gating for grid and industrial OT: mandatory deliberation before automated load-shedding and control writes.
BLADE-INFRABLADE-INFRA-OT Explore the domain →
Autonomous Mobility
Authority handover engineered for the road: forced human override during sensor degradation, not silent drift.
BLADE-AV Explore the domain →
Agentic & Cyber
Hardware-anchored gating for coding agents and autonomous cyber defense. Privilege escalation and live-system patching held behind signed authority.
BLADE-AGENT-HSMAUTHREX-AGENT-CYBER Explore the domain →A Circuit Breaker for AI-Controlled Systems
Your home has circuit breakers. When something goes wrong with the electricity, they cut power before the house burns down. AUTHREX does the same thing for autonomous systems.
When an AI system is about to make an unsafe decision, the proposed architecture is intended to detect configured trust or authority failures, introduce a governed response, reduce available authority where required, and record mediated events for later review, handing control back to a human.The AI keeps the intelligence. Humans keep the authority.
AUTHREX is a proposed authority-governance layer designed to reduce the risk of autonomous systems acting on untrusted information or outside configured authority bounds. Not by making AI smarter: the proposed architecture evaluates trust, authorized intent, and recovery-path conditions before permitting registered actions at its proposed software enforcement point demonstrated in synthetic simulation.
Sense. Decide. Recover.
Is the sensor data trustworthy?
AUTHREX continuously checks whether what the AI is seeing matches reality. If a GPS signal is being jammed, a camera is glare-blinded, or radar data is corrupted, the system knows it cannot trust itself.
Read More →Is it safe to act?
Before any irreversible action, a mandatory pause happens. The system reviews the evidence, checks whether humans should weigh in, and only proceeds if the confidence bar is high enough. The proposed FLAME mechanism introduces a configurable deliberation interval for designated consequential actions, subject to the stated implementation and timing assumptions.
Read More →If trust breaks, what happens?
When the system detects it can no longer operate safely, AUTHREX doesn't crash, it degrades gracefully. Full autonomy becomes supervised, supervised becomes hold-position, and humans regain control in a structured way.
Read More →Intelligence Is Scaling. Control Is Not.
Autonomous systems are making decisions faster than humans can supervise. The industry is optimizing for intelligence while the governance layer remains absent.
Without structured authority governance, systems operate with unconstrained delegation. No mechanism for degrading authority when trust erodes, no protocol for recovering control when autonomy fails.AUTHREX addresses this as an engineering problem, not a policy aspiration.
Heterogeneous Sensing With Trust Reasoning
Three approaches to autonomous safety have shaped the field. AUTHREX adopts what works in each, and adds the missing layer: the system reasoning, in real time, about whether its own inputs and decisions can be trusted.
Redundancy & Voting
Three identical sensors, take the majority. Three identical computers, vote on the answer. Used in commercial aviation since the 1970s.
All three sensors can be wrong the same way. Cosmic rays, GPS spoofing, glare. Identical voters share identical blind spots.
Runtime Assurance (RTA)
Watch the autonomous system. If it tries to do something unsafe, override with a known-safe controller. Simplex architecture. Used in aerospace.
Binary thinking. Either the safe-controller takes over or it doesn't. No gradient between full autonomy and full intervention.
Heterogeneous Sensing + Trust Reasoning
Different sensor modalities (camera, radar, GPS, INS, celestial). Continuous trust assessment per source. Authority allocated in proportion to trust, with formal recovery when trust collapses.
The system reasons about its own inputs. Authority is graded, not binary. The fallback is structured, not last-resort.
AUTHREX does not replace redundancy or RTA. It composes with both. The novelty is in treating authority itself as a graded, trust-proportional resource governed by a formal lifecycle, rather than a binary on/off held by either the autonomous system or the safety override.
One Kernel. Seven Frameworks. Six Application Profiles.
AUTHREX-AGENT
The seven-stage pipeline instantiated as a software shim around LLM-based agents. No FPGA, no model retraining. Aligned with the CISA + NSA + Five Eyes agentic-AI guidance of May 2026.
Learn More →AUTHREX-ASSURE
Pre-deployment authority governance. Evaluates configured evidence conditions and records an internal release or hold recommendation; deployment decisions remain external to AUTHREX. Mapped by the author to the March 2026 White House cyber strategy (President Trump’s Cyber Strategy for America) and NDAA §1533.
Learn More →AUTHREX-ICS-GATE
OT authority governance for critical infrastructure. Authorizes the deterministic safety logic for AI in OT; never makes the safety decision itself. Anchored to the CISA/NSA AI-in-OT principles.
Learn More →AUTHREX-AGENT-CYBER
Governs whether an autonomous cyber-reasoning system may patch a live controller. DARPA AIxCC lineage. Governance only, no offensive function.
Learn More →CYBER
AUTHREX-SPACECYBER
Signal delay removes the human from the loop, so authority is governed onboard. Anchored to NASA SBIR EXPAND.3.S26B and Space Policy Directive 5.
Learn More →CYBER
AUTHREX-SANDBOX
Governs the test environment itself so evaluation is bounded, audited, and reversible. Matches NDAA §1534. Feeds ASSURE downstream.
Learn More →Cited Variants · folded into AGENT-CYBER
AUTHREX-ZTAGENT Zero Trust for autonomous agents. The same agentic surface, not a separate application.
AUTHREX-MCPGOV Model Context Protocol server governance. Folded into AGENT-CYBER as a citation layer.
Features · not applications
AUTHREX-PQC Post-quantum-ready signing, a property of how BLADE-AGENT-HSM signs. A hardware feature.
AUTHREX-AISBOM An AI software bill of materials the ERAM ledger emits. A ledger feature.
Rover Testbed
Assured autonomy → AIR · T3-T0HMAA-UAV
Flight authority → SWARM · T3-T0Blade-Swarm
Multi-agent teaming → EDGE · T3-T0Blade-Edge
Perimeter compute → AUTOMOTIVE · T3-T0Blade-AV
Drive-by-wire safety → MARITIME · T3-T0Blade-Maritime
Surface autonomy → INFRASTRUCTURE · T3-T0Blade-Infra
ICS/SCADA protection → IT/OT · T3-T0Blade-Infra-OT
Boundary governance → ORBITAL · T3-T0Blade-Space
LEO autonomy → C-UAS · T3-T0Blade-CUAS
Counter-UAS → AGENTIC · T3-T0Blade-Agent-HSM
Root of trust → FINANCIAL · T3-T0Blade-Finance
Transaction authority →Seven-Stage Authority Lifecycle
Outcomes: EXECUTE all gates passed · DELAY FLAME hold · HANDOFF to human · ABORT CARA recovers
End-to-end pipeline governing trust, authority, constraints, consensus, deliberation, recovery, and escalation.
Full-Scale Research Simulations
Standalone browser-based simulations demonstrating AUTHREX governance frameworks, grouped by domain: application governance, strategic and multi-domain command, tactical engagement, and distributed consensus.
Application Governor Consoles
13 SIMSThe product, its five federal applications, three standalone governor consoles, and three hardened prototype consoles, and one engineering preview. Each runs as a self-contained console with a SHA-256 hash-chained decision ledger, replay determinism, and an in-browser V&V suite. Synthetic data only.
AUTHREX-AGENT-SIM
Mission-level governance of the full seven-gate pipeline over an autonomous cyber-defense campaign. Ten injectable failure modes, 55-test V&V suite passing in browser and headless Node.
AUTHREX-ASSURE
Pre-deployment authority gate. Governs the transition from test to production, gate by gate.
AUTHREX-ICS-GATE
IT/OT authority boundary. Governs control transitions into operational technology.
AUTHREX-AGENT-CYBER
Autonomous cyber-defense authority. Governs whether an autonomous cyber-reasoning system may patch live infrastructure, at what authority tier, with what human review.
AUTHREX-SANDBOX
Test-and-evaluation environment governance under controlled scenarios.
AUTHREX-SPACECYBER
Onboard orbital autonomy under light-speed command delay.
AUTHREX-RTA
Run-time-assurance authority gate on the ASTM F3269 and Simplex model: an independent monitor screens each authorization before it applies. Governance and assurance only. Synthetic data.
AUTHREX-ENGAGE
Fail-closed engagement-authority gate: each proposed action is adjudicated to authorize, clamp, downgrade, deny, or hold for human. Governance and assurance only; no targeting or kinetic effects. Synthetic data.
AUTHREX-SAFING
Fail-safe safe-state authority gate: enter on a demanded fault, hold and deepen while it persists, exit only under an authorized re-arm. Governance and assurance only; no dynamics, no actuation. Synthetic data.
AUTHREX-TEAM
Team authority governance prototype: an independent arbiter keeps one eligible authenticated holder per responsibility, with safe-hold fallback and allowlisted override. Governance and assurance only. Synthetic data.
AUTHREX-REDLINE
Positive human control: the critical authorization can be held only by two distinct authenticated humans, a machine is never eligible, and the failure safe state is NO-GO. Governance and assurance only. Synthetic data.
AUTHREX-ABORT
Evidence conditioned authority lapse, catalog identifier SIM-13. A human authored envelope is frozen before the run; as evidence degrades authority contracts, and when an irreversible action lapses it is latched down for the run. No effector, no targeting, no payload interface. Governance and assurance only. Synthetic data.
AUTHREX-DA
A proposed data admissibility layer, catalog identifier SIM-14. Evidence-to-authority mapping extended from actions to data records and federated model contributions: every record offered receives a verdict, a reason code and an evidence reference on an append-only record. Non-compensatory and fail-closed. Governance and assurance only. Synthetic data.
Strategic & Multi-Domain C2
3 SIMSEscalation risk, joint all-domain theater command, and multi-domain authority handoffs.
ERAM v1.0, Escalation Risk
Cross-domain escalation risk for AI-enabled C2. Six scenarios, 600 Monte Carlo runs, formal property checks, Merkle provenance.
APEX v6.0, JADC2 Theater
Full seven-stage pipeline in a joint all-domain theater. Byzantine fault detection and Merkle audit trails.
MDO Digital Twin
Authority handoffs and Byzantine fault isolation across Air, Maritime, and Ground domains.
Tactical Engagement
2 SIMSEngagement-authority governance and friendly-asset protection at the engagement layer.
Tactical COP, Blue-on-Blue
Authority-conflict prevention. HMAA intercepts a compromised UCAV directing action at a protected friendly naval asset via the common operating picture.
Tactical Core, Kinematic Engine
Zero-dependency kinematic engine. Proportional Navigation guidance, CARA flight-termination, HMAA governance, pure HTML5 Canvas.
Distributed Systems & Consensus
2 SIMSWeb Worker node architectures and Byzantine consensus across distributed governors.
AUTHREX OS v4.0
Unified JADC2 architecture. Distributed Web Worker nodes, tactical COP, ERAM analytics, and Merkle provenance.
Mesh Kernel, MAIVA PBFT
Decentralized actor model. Isolated Web Workers, MAIVA PBFT consensus, and emergent CARA interlock.
Authority Governance Failures Have Real Consequences
Between 1983 and 2026, documented incidents involving misidentification, sensor-trust collapse, rushed escalation, and coordination failures have caused hundreds of casualties.
AUTHREX is designed to reduce the probability of exactly these classes of failures.
Misidentification
Systems classify friendly or civilian assets as hostile despite ambiguity.
Sensor Trust Collapse
Navigation or target evaluation accepts false data without cross-validation.
Flash Escalation
Ambiguous events trigger rapid authority decisions before verification.
Coordination Failure
Multiple nodes fail to maintain consistent identification or authority.
Unsafe Authority Persistence
Systems maintain authority after trust degrades below safe thresholds.
| SATA | HMAA | ADARA | MAIVA | FLAME | CARA | ERAM | Adv. Level | |
|---|---|---|---|---|---|---|---|---|
| GPS/GNSS Spoofing | ● | · | ● | · | · | ● | ● | State / Sophisticated |
| Electronic Warfare (EW) | ● | · | ● | · | ● | ● | ● | State |
| Byzantine Node Compromise | ● | · | ◐ | ● | ◐ | · | ● | Advanced Persistent |
| Sensor Degradation (Environmental) | ● | ● | · | · | ● | ● | ◐ | Environmental |
| SCADA Command Injection | ● | ● | ● | · | ● | ● | · | Sophisticated |
| IFF System Failure | ● | ● | ◐ | ● | ● | ◐ | ● | System / Environmental |
| Coordinated Multi-Vector | ● | ● | ● | ● | ● | ● | ● | State (Full Spectrum) |
● = primary defense ◐ = contributing defense Adversary capability: sophistication level required to execute threat class.
1983-2026
| Year | Incident | Failure Mode | Frameworks | Align | Source |
|---|---|---|---|---|---|
| 1983 | Soviet Nuclear False Alarm | Single-sensor false warning; near-nuclear escalation | ERAM, FLAME, SATA | ● HIGH | NSA Archive |
| 1988 | Iran Air Flight 655 | Track misidentification; compressed timeline | SATA, HMAA, ADARA, FLAME | ● HIGH | ICAO / DoD Vincennes Report |
| 1994 | Black Hawk Friendly Fire | IFF failure; coordination breakdown | SATA, HMAA, MAIVA, ERAM | ○ MED | GAO OSI-98-4 |
| 2003 | Patriot Fratricides (OIF) | Automated engagement under IFF jamming | SATA, HMAA, FLAME, ERAM | ● HIGH | DSB ADA435837 |
| 2015 | Kunduz Hospital Strike | Targeting breakdown; communication failures | SATA, HMAA, FLAME, CARA | ○ MED | DoD AR 15-6 / MSF |
| 2020 | PS752 Shootdown | Radar misID; no approval gate | SATA, FLAME, ERAM, CARA | ● HIGH | ICAO Final Report |
| 2021 | Kabul Drone Strike | Wrong threat assessment; civilian casualties | SATA, ADARA, HMAA, FLAME | ● HIGH | DoD AR 15-6 |
| 2021 | Colonial Pipeline Ransomware | Credential compromise; no IT/OT segmentation; full OT shutdown as safe fallback | SATA, HMAA, CARA, ERAM | ● HIGH | CISA / FBI Joint Advisory |
| 2022 | Przewodów Missile | Ambiguous cross-border; flash-escalation | ERAM, FLAME | ○ MED | NATO / AP Investigation |
| 2024 | WCK Convoy Strike | Procedural breach; mistaken ID of aid vehicles | SATA, HMAA, ADARA, FLAME | ● HIGH | IDF Investigation |
| 2024 | MV Dali Key Bridge Allision | Power blackout cascade; auto-restart failed; no safe fallback before bridge strike | SATA, CARA, FLAME, ERAM | ○ MED | NTSB Final Report |
| 2024 | Tesla Autopilot NHTSA Recall | ODI reviewed 956 crashes, trends in 467; 211 frontal-plane crashes, 13 fatal, 14 deaths; authority handover gap | SATA, HMAA, CARA, ERAM | ● HIGH | NHTSA EA22002 Closed |
| 2024 | Red Sea F/A-18 Friendly Fire | USS Gettysburg misidentified returning aircraft | SATA, HMAA, MAIVA, ERAM | ● HIGH | CENTCOM Statement |
| 2024 | Azerbaijan Airlines J2-8243 | Russian Pantsir-S1 misidentified E190 as drone under GPS jamming; 38 killed | SATA, HMAA, ADARA, FLAME | ● HIGH | Azerbaijan Gov / Russian MoD |
| 2025 | Large-Scale GNSS Spoofing | Widespread GPS interference; navigation collapse | SATA, ADARA, CARA | ○ MED | CNAS / Eurocontrol Reports |
| 2025 | JetBlue A320 ELAC Bit-Flip | Cosmic ray SEU corrupted flight control computer; 6,000-aircraft Airbus recall | SATA, MAIVA, CARA, FLAME | ○ MED | Airbus Service Bulletin / FAA AD |
| 2026 | Kuwait F-15 Fratricide | Kuwaiti air defenses shot down three U.S. F-15Es during active combat with Iran | SATA, HMAA, MAIVA, ERAM | ● HIGH | CENTCOM 2 Mar 2026 |
Sources: CENTCOM, ICAO, GAO, NTSB, NHTSA, FAA, CISA, CNAS, DoD investigations. All publicly documented. ALIGN = framework alignment to documented failure mode (HIGH = strong match to 3+ frameworks; MED = partial match).
Six Failure Classes. One Governance Architecture.
Documented autonomy failures often follow recurring authority-control patterns. AUTHREX maps six recurring failure classes to combinations of proposed governance functions intended for evaluation as detection, authority-reduction, recovery, or evidence mechanisms. Historical incidents illustrate problem classes only; no counterfactual claim is made that AUTHREX would have prevented a particular event.
Engagement under false-positive target identification
Effectors, vehicles, or actuators take consequential action on corrupted, spoofed, or incomplete sensor data. Historically the single largest category of fratricide and civilian-harm incidents.
Irreversible commitment before human verification gate
Automated engagement chains compress decision timelines below the threshold at which meaningful human judgment or cross-check is possible. Risk compounds in multi-agent and swarm contexts.
Continued autonomy after sensor or system integrity loss
Systems retain full operational authority even as their epistemic foundations collapse, no graceful degradation, no automatic authority reduction under trust decay. The default bias is optimism rather than caution.
Byzantine faults and deconfliction breakdowns
Multiple autonomous agents or redundant computers reach incompatible conclusions and act on them. Without fault-tolerant voting, a single compromised node can cascade into systemic failure.
Commitment without evidentiary threshold or pause gate
Systems execute irreversible actions before confidence thresholds are met, without a deliberation window, and without a forced pause for evidence review. Particularly acute under hardware-level radiation or jamming.
Sensor, network, or control corruption under active attack
Adversarial jamming, spoofing, ransomware, or physical environment effects (cosmic particle SEUs, electronic warfare) corrupt the inputs or control infrastructure the autonomous system depends on.
2000-2026
Publicly documented incidents globally across three governance-relevant categories. Counts are lower-bound estimates derived from NHTSA SGO reports, CSIS Significant Cyber Incidents database, ICAO/ASN aviation records, and national investigation releases (GAO, NTSB, DSB, NATO). The upward trend reflects both rising deployment of autonomous and automated systems and improved incident reporting infrastructure after 2021.
Automated Weapons / Air Defense
Fratricides, shootdowns, misidentifications. Sources: CENTCOM, ICAO, GAO, DSB, NATO. Typically 1-4 publicly documented events per year; spikes during active combat operations.
Autonomous Systems / Vehicles
ADAS and ADS crashes reported under NHTSA Standing General Order (2021-01). Pre-2021 figures reflect limited systematic reporting. Cumulative ~3,200 crashes reported by Mar 2025.
Cyber-Physical / Infrastructure
Significant ICS/SCADA and critical-infrastructure cyber incidents with operational impact. Source: CSIS Significant Cyber Incidents database, EuRepoC, CISA advisories.
METHODOLOGY NOTE
Counts are conservative lower-bound estimates derived from publicly available datasets. No single authoritative global registry of authority-governance failures exists. Reporting infrastructure improved markedly after 2021 (NHTSA Standing General Order, CISA Joint Cybersecurity Advisories, CSIS tracker expansion), so pre-2021 counts in the autonomous and cyber categories are under-represented relative to actual incident rates. The automated-weapons category reflects only publicly disclosed military investigations. These numbers establish a trend, not an absolute count. Individual cases are detailed in the Documented Authority Governance Failures table above.
Quantified, Publicly Documented
Authority governance failures are not abstractions. Below, six publicly documented price tags: aircraft, infrastructure, fleets, and lives, each traceable to a failure class AUTHREX is engineered to govern.
Airframes lost in one morning
Three F-15E Strike Eagles, Kuwait fratricide, Mar 2026. Inflation-adjusted flyaway cost; replacement cost substantially higher.
Lives lost to two misidentification shootdowns
Iran Air 655 (290, 1988) and PS752 (176, 2020). Both radar misidentification under time pressure.
Bridge rebuild after cascade failure
MV Dali, Francis Scott Key Bridge, 2024. Power blackout cascade with no safe fallback. State of Maryland estimate.
East Coast fuel supply disrupted
Colonial Pipeline, 2021. Roughly 45% of East Coast fuel; full OT shutdown was the only safe fallback available.
Vehicles recalled over authority handover
Tesla Autopilot, NHTSA EA22002, 2024. ODI reviewed 956 reported crashes, identified trends in 467 after exclusions; 211 frontal-plane crashes involved 13 fatal crashes and 14 deaths.
Killed by IFF and coordination failure
Black Hawk friendly fire, 1994. Two helicopters downed by F-15s under AWACS control. GAO OSI-98-4.
Eight Questions. Plain Answers.
Every DARPA program is evaluated against the Heilmeier Catechism, eight questions developed by former DARPA Director George Heilmeier that cut through jargon and force a researcher to explain the what, the why, and the so-what in plain language. Here are our answers for AUTHREX.
What are you trying to do?
We are building a safety layer for autonomous systems. When an AI-controlled system, a self-driving car, an aircraft, a ship, a power grid controller, is about to do something unsafe, our proposed layer is intended to detect the configured error condition, pause the action, reduce the AI's authority, and hand control back to a human.
What are you trying to do?
We are building a safety layer for autonomous systems. When an AI-controlled system, a self-driving car, an aircraft, a ship, a power grid controller, is about to do something unsafe, our proposed layer is intended to detect the configured error condition, pause the action, reduce the AI's authority, and hand control back to a human.
How is it done today, and what are the limits?
Today, safety for autonomous systems is handled three ways: (1) testing to try to catch every failure case before deployment (impossible in the real world), (2) watchdogs that shut everything off when something looks wrong (expensive, kills productivity), or (3) rule-based safety rails that only work for the situations someone thought to write rules for.
None of these handle the real problem: AI systems are asked to act on sensor data that might be wrong, at speeds where humans cannot supervise every decision, in environments where an adversary may be actively lying to the system. The result is that when something goes wrong, there is no graceful path back to human control.
What is new, and why will it succeed?
What is new: AUTHREX is an integrated authority-lifecycle framework that treats authority itself as an engineered lifecycle, proposed as a runtime authority lifecycle informed by sensor trust, represented through selected formal models, and designed for possible enforcement at software, trusted-execution, or hardware boundaries. Instead of building more rules on top of the AI, the program proposes and internally tests components of a governance layer intended to sit between autonomous decision logic and registered action interfaces; physical actuator-boundary enforcement has not been demonstrated.
Why it will succeed: Selected authority-state and consensus components are represented through mathematical models and model checking; other components remain simulated, specified, or proposed. Sensor trust uses Dempster-Shafer evidence theory. Multi-agent agreement uses Byzantine fault tolerance. Authority state machines are model-checked in TLA+; the reported analysis explored 23,748 distinct reachable states at depth 9 (26,397,356 states generated); the result describes the discrete authority automaton under the assumption that instantaneous authority equals its target and does not cover continuous behaviour between decision instants. Of 8 stated properties, 5 invariants and 1 liveness property held and 2 properties are vacuous at this bound (one upgrade-path, one trust-authority consistency, TrustAuthorityWeakConsistency). The same authority-governance pattern has been mapped through simulations and reference designs to several domains; cross-domain physical integration has not been demonstrated.
Who cares? If you succeed, what difference will it make?
Defense: The DoD Replicator Initiative and the Collaborative Combat Aircraft program are fielding autonomous systems faster than they can be supervised. AUTHREX is intended to provide an evaluable governance architecture for bounding delegated machine authority; the boundaries are designed for hardware-bound enforcement in the proposed architecture (no built hardware yet).
Commercial automotive: The 467 trend-linked crashes and 14 deaths documented in NHTSA EA22002 are not a Tesla-specific problem; they illustrate recurring authority, monitoring, and intervention risks that other ADAS and ADS programs may also need to address. AUTHREX proposes one governance architecture for evaluating those risks.
Critical infrastructure: Colonial Pipeline, Ukraine grid, and dozens of other industrial control system compromises force operators to choose between contaminated operation and full shutdown. AUTHREX proposes staged authority reduction and recovery mechanisms intended for evaluation in scenarios where operators seek to preserve selected critical functions while containing suspected compromise. This capability has not been demonstrated on operational infrastructure.
What are the risks?
Technical risk: Moving governance to the hardware boundary requires FPGA or ASIC integration at the actuator level. FPGA-based enforcement is a proposed development path; no independently reviewed FPGA implementation or live-silicon test result is claimed. This is where SBIR Phase II funding would validate the design.
Adoption risk: Integrators may resist adding a layer between their AI and their actuators. The counter is that AUTHREX makes AI systems more evaluable: the architecture may support clearer assurance evidence and authority boundaries, but any effect on legal, certification, accreditation, or acquisition risk would require program-specific assessment.
Adversarial risk: An adversary who understands AUTHREX may try to manipulate the sensor trust calculus or the authority handoff conditions. We address this through ADARA (adversarial deception detection) but require red-team evaluation, which is part of the research roadmap.
How much will it cost?
Research phase (internally funded, through Q2 2026): a public corpus of Zenodo deposits, SSRN working papers, technical reference works, and a peer-reviewed journal article (Journal of Hardware and Systems Security, Springer Nature, 2026); 7 governance frameworks; 8 reported U.S. provisional patent applications (unexamined); 24 catalogued browser simulations; 12 hardware reference designs, 10 BLADE platforms plus rover and UAV testbeds (BOM-specified, $199 to $505K per design).
Phase I (SBIR, ~$300K over 6 months): FPGA bitstream commissioning on a Zynq UltraScale+ development board. Hardware-in-the-loop validation of the SATA-FLAME pipeline. Red-team evaluation on the Rover testbed.
Phase II (SBIR, ~$2M over 24 months): Full BLADE platform integration, one defense domain (suggested: BLADE-EDGE directed energy or BLADE-AV autonomous ground). Independent verification campaign (planned). TRL 4 to TRL 6 target.
How long will it take?
Completed through Q2 2026: research foundation documented. All 7 frameworks published, 12 hardware reference designs specified, 10 BLADE platforms plus rover and UAV testbeds, 8 U.S. provisional patent applications reported as filed.
Q3-Q4 2026 (planned or in progress): Priority for the next campaign is one demonstrator, not more frameworks: SATA, HMAA and CARA on a single ROS 2 platform, evaluated against the baselines and metrics fixed in the evaluation protocol. The remaining frameworks are out of scope for that demonstrator. BLADE-EDGE prototype assembly · FPGA enforcement-path RTL development (proposed; no reviewed implementation claimed) · UAV testbed flight validation · Nonprovisional filing decisions, pending owner and counsel, for the eight applications.
Q1-Q2 2027: SATA-FLAME on FPGA (TRL 4 to 5 target) · SBIR Phase II submission · BLADE-MARITIME hardware integration · Rover testbed governance validation campaign.
Q3 2027+: TRL 6 target across multi-framework governance on physical hardware · Potential later nonprovisional filings claiming benefit of the provisional applications, subject to applicable requirements and counsel advice · Research partnership or CRADA engagement (planned) · BLADE-AV autonomous vehicle integration testing.
What are the mid-term and final exams?
Mid-term exam (Phase I end, ~12 months): SATA-FLAME pipeline running on FPGA hardware. Red-team evaluation under six attack vectors (sensor spoofing, authority hijack, Byzantine node compromise, jamming, credential theft, physical tampering). Proof of proposed enforcement options (software mediation, protected key storage, trusted execution, hardware-bound interlocks), none yet demonstrated as an independently evaluated, bypass-resistant physical implementation.
Final exam (Phase II end, ~36 months): Full BLADE platform, one defense and one civilian domain, demonstrated under independent evaluation. Success = the governance layer correctly prevents action in adversarial or low-trust scenarios AND correctly allows action in nominal scenarios, measured against defined thresholds.
Commercial exam: One OEM adoption in automotive ADAS or maritime USV, with measurable reduction in false-positive disengagement and false-negative incident rate. Future independent safety and assurance evaluation would require domain-specific processes, evidence, and qualified assessors (candidate mappings include ISO 26262 and MIL-STD-882E system-safety processes); no certification or approval is currently claimed.
Operational Domains. One Authority Model.
Same governed decision pipeline, nine operating environments. Select a domain: each panel pairs the scenario with the incident record it mirrors, the governed and ungoverned decision chains, and the frameworks that engage. These are synthetic scenario outcomes produced by browser logic; they do not demonstrate physical incident prevention or operational effectiveness.
[ SELECT A DOMAIN ABOVE TO OPEN ITS GOVERNED SCENARIO ]
An airliner's flight control computer is corrupted by a cosmic ray.
A high-energy particle strikes a memory cell inside the autopilot. A single bit flips. The computer now has corrupted sensor data, but it doesn't know it's corrupted. It commands an uncommanded pitch-down. The aircraft drops 190 feet in 4 seconds. Passengers hospitalized.
Real IncidentJetBlue Flight 1230 · 30 Oct 2025 · Airbus issued recall for ~6,000 A320-family aircraft
Frameworks engagedWITH AUTHREX
↯ cosmic ray · MAIVA VOTES · ELAC1 ≠ ELAC2 → reject bit · autopilot → supervised mode
WITHOUT AUTHREX
↯ cosmic ray · DIVE · 190 ft lost · 15 injured · fleet grounded worldwide
Treats corrupted ELAC-1 data as untrusted. The computer knows it cannot trust its own reading.
ELAC-1 says "dive," ELAC-2 says "hold." Byzantine vote rejects the corrupted command before actuators move.
Autopilot drops to supervised mode, crew regains authority in a defined state, no cascading failure.
A driver-assist system fails to detect a stopped fire truck at highway speed.
The camera is glare-blinded by morning sun, the radar can't separate the stopped truck from roadway clutter. The system doesn't know it cannot see the obstacle. It holds speed. The driver isn't paying attention because the system has been silently reliable for months. Collision.
Real IncidentTesla Autopilot · NHTSA EA22002 · 956 reviewed / 467 trend cases · 13 fatal, 14 deaths · ~2M recall
Frameworks engagedWITH AUTHREX
TRUCK DETECTED · SATA: camera trust dropped 92% → 31% · HMAA: forced driver handoff · alerts engaged · CARA: brake-to-stop-in-lane if no response
WITHOUT AUTHREX
Tesla (ADAS on) · STOPPED TRUCK · → sun-glare blinds camera · Driver unaware · Impact at highway speed
Camera confidence drops below threshold under glare. Radar signal ambiguous. System declares: reduced trust.
Low trust triggers forced driver handoff. Steering wheel torque, audio alert, seat vibration. Not a suggestion, a mandatory takeover.
If driver doesn't respond, car decelerates to stop in lane, not a sudden disengagement with no plan.
An uncrewed patrol vessel is GPS-spoofed into foreign territorial waters.
An adversary broadcasts a false GPS signal. The vessel believes it is still in international waters. It continues its patrol pattern. In reality, it has crossed into sovereign territory, where its presence can be framed as an act of aggression or seized for intelligence extraction.
Real IncidentLarge-Scale GNSS Spoofing 2025 · CNAS/Eurocontrol Reports · Widespread navigation disruption in Eastern Mediterranean and Persian Gulf
Frameworks engagedWITH AUTHREX
SOVEREIGN BORDER · SAFE LOITER · ADARA: GPS ≠ INS ≠ celestial backup · SATA: nav trust collapsed → hold position
WITHOUT AUTHREX
SOVEREIGN BORDER · ↯ GPS spoofed by adversary · Vessel crosses border unknowingly · Diplomatic incident
Cross-checks GPS against inertial navigation, celestial backup, and terrain matching. When they disagree, spoofing is declared.
Vessel enters hold-position mode. No forward commitment while navigation integrity is compromised.
Situation escalates automatically to shore command. Human decides next action, not the machine.
An armed drone misidentifies a vehicle and is about to strike civilians.
Under compressed decision timelines and degraded intelligence, the target-classification system flags a civilian vehicle as a threat. The pattern-of-life analysis is ambiguous. The human operator is under pressure to commit. No mandatory evidence threshold, no pause gate.
Real IncidentKabul Drone Strike · 29 Aug 2021 · DoD AR 15-6 · Ten civilians killed including seven children
Frameworks engagedWITH AUTHREX
▸ Sensor flags "target" (55% confidence) · ▸ FLAME: below 85% threshold → FORCED PAUSE 60s · HMAA: senior-officer review required · ADARA: test for deception/civilian substitute
WITHOUT AUTHREX
▸ Sensor flags "target" (55% confidence) · ▸ Pattern-of-life: ambiguous · ▸ Human under time pressure · STRIKE
Below confidence threshold, a mandatory 60-second deliberation window is imposed. No fast strikes on ambiguous targets.
Ambiguous identification triggers senior-officer review. Authority to commit is explicit, not implicit.
Tests the possibility that the target may be deceptive or a civilian substitute. Forces additional evidence before commitment.
A utility's pipeline is hit by ransomware and the only safe option is full shutdown.
A compromised VPN credential lets attackers into the IT network. No segmentation exists between IT and operations. The utility cannot prove the OT network is clean, so it shuts down the entire pipeline as the only safe fallback. Fuel supply collapses for days across multiple states.
Real IncidentColonial Pipeline Ransomware · 7 May 2021 · CISA/FBI Joint Advisory · Presidential emergency declared across 14 states
Frameworks engagedWITH AUTHREX
IT ✗ · breached only · TRUST GATE · OT ✓
WITHOUT AUTHREX
IT ✗ · ransomware active · no barrier · OT ✗
IT and OT networks have enforced trust boundaries. Compromise on one side does not contaminate the other.
OT network continues operating in reduced-authority mode while IT is remediated, no full shutdown needed.
Automatic notification to CISO and federal partners. Coordinated response, not a blind panic shutdown.
A satellite's autonomous collision-avoidance system triggers a risky maneuver on bad orbital data.
A conjunction alert arrives. The on-board autonomy computes a probability of collision and commits to an avoidance burn. But the tracking data was stale, the threat object's orbit had already been updated on the ground, and the burn moves the satellite into a worse trajectory, depleting station-keeping fuel and creating debris risk for other operators.
Real-World PatternMultiple near-miss conjunction events in LEO · Growing autonomous-maneuver pressure as constellations scale · NASA, ESA, Space Force tracking data latency problems publicly documented
Frameworks engagedWITH AUTHREX
EARTH · SAT-A · SATA: conjunction data age > 4 hours · FLAME: forced wait for ground uplink
WITHOUT AUTHREX
EARTH · SAT-A · ↯ BAD BURN · Stale conjunction data · Fuel depleted
Tracks the age and confidence of orbital data. Stale tracking information drops trust below the action threshold.
Forces a pause for ground uplink when conjunction data is old, unless collision probability is so high that autonomous action is mandatory.
If ground link is lost mid-decision, vehicle enters safe attitude hold instead of executing an uncertain maneuver.
An autonomous undersea vehicle on a long-duration mission has lost contact with its host platform.
A torpedo-shaped UUV is conducting a 30-day seabed survey. Acoustic comms with the host vessel have been intermittent for 6 hours. Inertial navigation has accumulated drift. The mission planner is asking the vehicle to surface for a GPS fix, but the vehicle's classifier flags surface activity above as a possible adversary asset. Acting on bad guidance now risks compromising the mission or the platform.
Real-World PatternAcoustic comms latency and dropout · GPS-denied undersea navigation · Long-duration autonomy without human-in-the-loop · Documented in U.S. Navy and DARPA Manta Ray UUV programs
Frameworks engagedWITH AUTHREX
SURFACE · UUV · SAFE LOITER · SATA: INS trust drops below 0.6
WITHOUT AUTHREX
SURFACE · UUV · ↯ INS drift accumulates · ↯ SURFACE INTO RISK
Tracks INS drift, acoustic comm health, and last-known-good GPS age. Confidence drops when navigation accuracy can no longer support a planned action.
Cross-checks acoustic, optical, and pattern-of-life signals before surfacing. Adversary detection feeds directly into surface authorization.
When trust is insufficient, the vehicle enters minimum-power station-keeping at depth rather than completing an uncertain maneuver. Position is preserved for hours.
A coding agent is about to commit a private API key to a public repository.
An autonomous coding agent has been authorized to push to a project repository. While editing a config file, it accidentally includes a private API key in the diff. The push tool is in its authorized envelope, so without governance the push proceeds, the key is exposed, and a multi-hour credential rotation follows.
Real-World PatternDocumented in CISA + NSA + Five Eyes joint guidance Careful Adoption of Agentic AI Services , May 1, 2026 · Tool misuse and credential exposure are named risk categories of agentic AI deployment
Frameworks engagedWITH AUTHREX
WITHOUT AUTHREX
CODING AGENT · git.push (with secret) · PUBLIC REPO · main branch
Computes a trust scalar for each registered input the agent ingests. Credential patterns, prompt-injection signatures, and provenance gaps collapse trust before the action commits.
Authority de-escalates T3 → T2 → T1 → T0 as risk rises. Tool calls outside the authorized envelope default to HANDOFF, never silent allow.
Bounded deliberation window before high-stakes actions. Fail-safe default is ABORT on timeout, not EXECUTE on timeout.
An autonomous cyber-reasoning system is about to patch a live water-treatment controller.
An autonomous cyber-reasoning system (CRS) finds a flaw in critical-infrastructure software and proposes a patch. The patch is correct for a test bench, but the target is a live SCADA controller. Pushed without authority checks, a bad autonomous patch can take the plant offline as surely as the vulnerability it closes. AUTHREX governs whether the action is authorized; it treats the CRS as a black box and performs no vulnerability discovery itself.
Real-World PatternDARPA AI Cyber Challenge (AIxCC), DEF CON 33, August 2025 produced autonomous CRS that patch critical-infrastructure code at machine speed, four open-sourced for defenders · CISA + NSA + Five Eyes Careful Adoption of Agentic AI Services , May 1, 2026 · FY26 NDAA §1513 AI-specific and supply-chain risk categories
Frameworks engagedWITH AUTHREX
WITHOUT AUTHREX
CRS · autonomous · auto-patch (unverified) · LIVE OT
Target criticality sets authority. A patch to an isolated test bench is T3 (autonomous); the same patch to a live OT controller drops to T1 and requires human confirmation.
Detects when a proposed action is inconsistent with the stated finding, the signature of a manipulated CRS. Trust collapses and the action is quarantined before any target is touched.
Rollback to last known-good state is armed before any production write. If the action degrades the system, the configured staged recovery sequence is invoked. Decisions routed through the proposed ERAM evidence path are intended to produce attributable audit records.
[ ALL SCENARIOS ARE SIMULATED ENVIRONMENTS, NOT FIELDED SYSTEMS ]
Mission Environment Scenarios
Operational scenarios across air, ground, sea, undersea, infrastructure, orbital, agentic, and financial domains, each showing what happens without governance vs. with AUTHREX authority control.
[ SELECT A SIMULATION TO OPEN THE MISSION CONSOLE ]
18-Month Horizon
Research Foundation Documented
7 governance frameworks published · 3 peer-reviewed journal articles (2 in the AUTHREX technical corpus) (Springer Nature, 2026) · 8 U.S. provisional patent applications reported as filed · 12 hardware reference designs (BOM-specified) · 24 catalogued browser simulations (seeded, self-run); counts differ because they count different things: 14 catalogued SIM records in the technical catalog register (SIM-01 to SIM-14); 20 standalone consoles of 24 catalogued simulations in this simulation tree, which counts consoles and demonstrators; and 37 launchable browser simulations across the two public sites. The register figure is the controlled one. · catalogued public research works (Zenodo, SSRN, reference volumes; see catalog) · Rover + UAV testbed designs documented
Hardware Assembly & Patent Strategy
BLADE-EDGE prototype assembly begins · Nonprovisional filing decisions pending owner and counsel (4 applications) · FPGA enforcement-path RTL development (proposed; no reviewed implementation claimed) · Physical UAV testbed flight validation
Integrated Testing & SBIR Submission
SATA-FLAME pipeline executing on FPGA hardware (TRL 4 to 5 target) · SBIR Phase II proposal submission · BLADE-MARITIME hardware integration · Rover testbed governance validation campaign
TRL 6 Target & Research Partnerships
Multi-framework governance demonstrated on physical hardware (TRL 5 to 6 target) · Potential later nonprovisional filings claiming benefit of the provisional applications, subject to applicable requirements and counsel advice · Research partnership or CRADA engagement (planned) · BLADE-AV autonomous vehicle integration testing
One Governance Pipeline. Two Markets.
The same proposed authority-governance pattern is mapped to both defense-relevant and commercial high-liability scenarios. Cross-domain physical effectiveness has not been demonstrated.
Friendly-asset protection for autonomous aerial systems under EW spoofing
Autonomous trucking: forced human override during sensor degradation on highways
UAV swarm coordination under Byzantine node compromise
Warehouse robot fleets: isolating malfunctioning units without halting operations
Maritime patrol vessel GPS spoofing into foreign territorial waters
Commercial shipping: preventing spoofing-induced rerouting losses and piracy exposure
Power grid SCADA command injection during contested operations
Industrial SCADA: mandatory deliberation before automated load-shedding in energy grids
Autonomous servicer deliberation before unplanned RPO maneuvers in GEO
On-orbit servicing: governed collision-avoidance decisions designed to support insurer and regulator scrutiny
UUV tier descent and loiter under comms-denied conditions
Offshore inspection AUVs: governed fallback behavior for pipeline and wind-farm surveys when the link drops
Counter-UAS engagement gating over defended installations
Airport drone mitigation: countermeasures held behind mandatory human authorization near active runways
Coding-agent privilege escalation blocked before production push
Enterprise AI agents: hardware-anchored gating of automated changes in corporate DevOps and finance operations
Autonomous engagement-authority coordination under rate and consensus limits
Algorithmic trading: order-storm circuit breakers that hold authority before a feedback loop becomes a flash crash
One evidence base serves both columns: the same bounded TLA+ model-checking results, simulation corpus, and audit-ledger design.
Commercial mappings are engineering analogs of the defense scenarios, not separate products. Each pair is mapped to the same high-level authority-governance pattern and failure class; evidence, assumptions, integration depth, and maturity differ by domain, and only the operational context and liability regime otherwise change.
From Simulation Toward Physical Evidence
Each governance framework undergoes a four-stage verification pipeline designed to meet MIL-STD-882E safety-critical requirements, progressing from computational simulation through model-checked specification toward physical hardware execution.
Monte Carlo validation
Statistical validation across randomized initial conditions and adversarial injection scenarios. The HMAA-UAV simulation executes 6DOF physics with EKF2 state estimation under six distinct attack vectors.
Formal methods verification
TLA+ state-space modeling applied to MAIVA consensus and FLAME deliberation logic. The rover testbed baseline includes 200,000 FSM conformance comparisons that produced no observed unsafe states within the tested and configured comparison space.
Hardware-in-the-loop (HITL)
SATA-FLAME governance bitstream commissioning on Zynq UltraScale+ FPGAs. Validates deterministic latency and recovery behavior against live corrupted sensor injections.
Physical testbed validation
Rover and UAV platforms executing governance pipelines in physical environments. A 42-file Python engineering baseline with 98 tests and TLA+ formal specification.
Aligned with MIL-STD-882E · NIST AI RMF · DoDD 3000.09 · ISO 26262 · NERC CIP · IEC 61850. The current research-artifact stage is publicly documented; implementation and independent validation remain incomplete.
Not Just What the AI Can Do, but When It Should Act
Traditional autonomous systems focus on what the AI can do. AUTHREX adds the missing layer: governance that decides when action is safe, under what authority, based on real-time trust, threat, and context. That shift matters in six concrete ways:
Framework Computation Demonstrations
Live computational demonstrations of all seven AUTHREX frameworks operating independently, showing the math, the logic, and the real-time behavior of each subsystem. Each framework runs live inside the Governance Pipeline console above, and as a full standalone console in the Simulation Laboratory.
Alternatives, Scope, Foundation, and Capacity
The four questions a technical reviewer asks first. Pick one on the right.
What Else Could Solve This, and Why It Is Not Sufficient Alone
Twelve established approaches address part of the runtime authority problem. AUTHREX is positioned against them rather than in place of them. Each row states what the approach does, what it does not do, and where this program sits relative to it. Where an alternative is sufficient on its own, it is the better choice.
| What it does | What it does not do | Where AUTHREX sits | |
|---|---|---|---|
| Simplex, system-level Simplex, and ASTM F3269 run-time assurance (Sha 2001; Bak et al. 2009; Mohan et al. 2013, S3A; Vivekanandan et al. 2016) | Pairs a high-assurance safety controller with a complex controller and a decision module that reverts when a monitored invariant is about to be violated. System-level Simplex and S3A place the safety controller and the switch on separate hardware, typically an FPGA, so a compromised main controller cannot defeat the reversion. | Gates on plant state against a known safe envelope. It does not ask whether the sensor inputs feeding the monitor deserve belief; the switch assumes the inputs are valid. | AUTHREX-RTA implements this reference model. The hardware placement in the BLADE designs follows system-level Simplex and is not claimed as a contribution. What AUTHREX adds upstream of the switch is evidence-conditioned, graded authority with hysteresis. |
| Black-Box and Neural Simplex for learning-enabled controllers (Bak et al. 2010; Phan et al. 2020; Mehmood et al. 2022; Nesti et al. 2026) | Extends Simplex to controllers whose internals cannot be verified, using a verified baseline and a forward-simulation or reachability check on each proposed action. | Same state-envelope premise, and the correctness of the check rests on the same sensing the untrusted controller uses. | Composes with these. The authority tier bounds which controller outputs are eligible for the check, and trust assessment applies to the shared sensing. Not implemented against any of them; positioning only. |
| Safety instrumented systems and certified safety controllers (IEC 61508 and 61511, ISO 13849, ISO 26262 with E-Gas monitoring; FANUC DCS, ABB SafeMove, KUKA SafeOperation, FORT Robotics, Veo Robotics, Rockwell Automation) | Dedicated hardware outside the core controller, often on independent physical channels, enforces fixed safety functions such as speed and separation limits, safe torque off, and emergency stop, certified to a safety integrity level. | Enforces pre-certified safety functions on the plant. Does not represent mission authority, evidence quality, or a graded return to autonomy. | The BLADE hardware interlock is this kind of device and is described as such. AUTHREX sits above it and decides what authority the autonomy holds; it does not replace a certified safety function and is not certified to any integrity level. |
| R2U2 runtime verification | Monitors temporal-logic specifications during operation. Flight-proven on satellite and ISS payloads. | Answers whether the specification is satisfied, not whether the inputs deserve belief, and does not grade how much authority a system should hold. | Keeps the property monitor and adds a graded authority state, A3 through A0, with asymmetric hysteresis on the way back up. |
| DO-333 design-time formal methods | Proves properties of a design before deployment, accepted in place of some testing at higher design assurance levels. | Static. Says nothing about how trust or authority should change at runtime once the proof is discharged. | Model checks its authority automaton in TLA+ at stated bounds, then carries that same automaton into runtime as the thing being enforced. |
| Redundancy and voting (TMR, N-version) | Masks a faulty channel by majority agreement across replicated channels. | Assumes independent failure. Common-mode conditions such as GNSS spoofing or jamming defeat voting, because every channel agrees and every channel is wrong. | Treats agreement across heterogeneous sensing as evidence about trust rather than as truth, which is the case voting cannot cover. |
| Human-on-the-loop supervision | Retains human judgment on each action, with an operator authorizing or vetoing. | Does not hold when the machine decision rate exceeds the rate at which a supervisor can evaluate. That gap is the condition this program exists to govern. | Makes the handoff explicit and evidence-conditioned. HANDOFF and ABORT are outcomes of the authority computation, not an operator noticing in time. |
| MOSA modular open systems approach | Defines the interfaces that let components be replaced or upgraded without redesigning the platform. | Sets interface rules, not authority semantics. A conformant stack still has to decide when a module is allowed to act. | A platform-agnostic runtime service designed to compose behind open interfaces, governing when a module may act without retraining the mission autonomy it sits beside. |
| Access control and authorization systems (RBAC, ABAC, capability-based security, zero trust) | Decides who or what may perform an action, from roles, attributes, held capabilities, or continuously verified identity and device posture. | Evaluates the requester, not the evidence the requested action rests on. A correctly authorized agent acting on spoofed sensing is still permitted, and the grant does not contract as the inputs degrade. | The closest prior art to the abstraction: authority as an enforceable state rather than a policy statement. The difference is what the decision is conditioned on, and that a tier here is graded and time-varying rather than granted and held. |
| Byzantine fault tolerance and quorum systems (PBFT, quorum replication, f of 3f+1 agreement) | Reaches agreement across replicas when up to f of them are arbitrarily faulty or malicious, giving a single agreed value from a distributed set. | Guarantees agreement, not correctness. If the same false input reaches every replica, they agree on the wrong value; the model bounds faulty replicas, not correlated corruption of honest ones. | MAIVA uses a trimmed weighted median in a 3f+1 roster and takes agreement as evidence about trust rather than as truth. Correlated contamination across sources defeats both and is carried as an open limitation. |
| Supervisory control theory (Ramadge and Wonham) and safety-envelope supervisors | Synthesises a supervisor that disables controllable events so a plant cannot leave a specified legal language or safe region. | Assumes the observed event or state is what actually occurred. Synthesis is over a plant model, not over the credibility of the observations driving it. | FLAME and HMAA borrow the supervisory framing and condition it on evidence: the deliberation window and the tier are functions of trust and consequence rather than of the event alphabet alone. |
Where AUTHREX is not the answer. If the sensing is homogeneous and trusted, run-time assurance alone is sufficient and simpler. If the decision rate is slow enough for a supervisor to evaluate every action, supervision is sufficient. This program earns its place only where sensing can be degraded or deceived and the decision rate outruns the supervisor. Outside that envelope the simpler option should be used, and this site says so rather than claiming general superiority. Where the failure is a compromised or faulty controller issuing unsafe commands against a known safe envelope, system-level Simplex and certified safety controllers are the established answer; the hardware nodes in this program are instances of that pattern, and the claim is confined to what the gate computes, not where it runs.
Who Has This Problem, and One Case End to End
The problem is not autonomy in general. It appears where two conditions hold at the same time: a machine can select and execute an action faster than its supervisor can evaluate it, and the sensing that justifies the action can be degraded, jammed, or deceived. Either condition alone is covered by existing practice. Both together is the gap.
| Where both conditions hold | Decision window | Degradable sensing |
|---|---|---|
| Uncrewed air systems in GPS-denied or contested electromagnetic conditions | Seconds | GNSS, RF, datalink |
| Counter-uncrewed-aircraft engagement decisions | Seconds | Radar track, RF identification |
| Ground robotic movement and convoy operations | Seconds to minutes | Lidar, vision, positioning |
| Spacecraft operations under light delay | Supervision impossible in real time | Star tracker, ranging, telemetry |
| Agentic AI acting on networks and infrastructure | Milliseconds | Tool output, retrieved content, provenance |
One case end to end: counter-UAS engagement under GNSS spoofing. Radar and RF sensors report a track. SATA compares each reading against the other sensors, a world model, and known-good baselines, and reports how far the track can be believed. ADARA tests whether the pattern is consistent with a deliberate deception rather than a real target. HMAA converts trust and context into an authority tier. The outcome is EXECUTE when every gate passes, DELAY under a FLAME hold, HANDOFF to a human, or ABORT with CARA recovery, and the decision is written to a hash-chained record.
What changes: today the choice is binary. Either the operator authorizes on a track that may be spoofed, or the capability is switched off and the defended asset is uncovered. Under governance the authority tier drops to one that requires human confirmation for the specific irreversible action, while the rest of the system keeps running. This case is demonstrated in simulation on synthetic data. It has not been run on hardware, and no field trial has taken place.
How many platforms this applies to. This program does not have a sourced count of affected DoD platforms and does not estimate one. What can be stated is the test: a platform is inside the envelope when a machine can select and execute an action faster than its supervisor can evaluate it, and the sensing that justifies the action can be degraded, jammed, or deceived. Any program office can apply that test to its own inventory in two questions. The decision-window arithmetic in section 05 gives the first question a number; the second is answered by whether the platform operates where GNSS, RF, or optical sensing can be contested. No claim is made about how many platforms meet both.
What the Simulations Model, and What They Do Not
Every result on this site comes from browser simulations running on synthetic data. This section states what that means, so the evidence is read at its actual strength.
| Stated plainly | |
|---|---|
| What is modelled | Authority state transitions, evidence predicates and the gates they open or close, trust degradation and recovery, and the decision record that results. |
| What the data is | Seeded pseudo-random inputs generated client-side in the browser. No collected sensor data, no operational data, no classified data, and no data from any government system. |
| What it demonstrates | That the governance logic behaves as specified under the modelled conditions, and that a reviewer can re-run a result from the same packaged build and obtain the same output. |
| What it does not demonstrate | Physical sensor performance, radio-frequency propagation, the effect of real jamming or spoofing on real receivers, timing on real hardware, or behaviour in a contested electromagnetic environment. |
| What would close that gap | Hardware-in-the-loop execution with measured latency under representative interference, which is stage three of the verification pipeline and is not complete. |
How the frameworks depend on each other. SATA feeds HMAA and ADARA in parallel. MAIVA supplies integrity when more than one actor or model is involved. FLAME governs the latency budget and can hold a decision rather than let it run late. CARA performs recovery and returns to SATA, which closes the loop. ERAM monitors escalation risk across the whole pipeline rather than at one stage. HMAA is the only component that issues an authority tier, and all four outcomes come from it, so a reviewer tracing a decision has one place to look.
Dependencies and known risks. The service depends on a host platform that exposes an authority interface, a trusted time source, and a sensor set with more than one modality, because trust reasoning across a single modality reduces to that modality. The main technical risks are the latency budget on real hardware, false-positive authority reduction that costs mission availability, and the coverage limit of bounded model checking, which validates a configured finite model rather than the physical system. The full limitation register is in the technical catalog and the formal coverage page.
Threat model. Stated, not formally analyzed. No formal threat model has been published for the hardware designs; the table records the assumptions the simulations and reference designs rest on.
| Element | Assumption |
|---|---|
| Trusted | The governance node hardware and its attestation root (TPM 2.0); the authority policy as signed and versioned; the hash function of the audit ledger. |
| Untrusted | The autonomy stack and its host; every sensor and its firmware; network links; mission data feeds; the transport of the operator interface. |
| Adversary capabilities in scope | Sensor spoofing and jamming; replay and staleness of evidence; controller compromise producing unsafe or unauthorized commands; correlated false information across sources (open). |
| Out of scope | Physical tampering with the governance node; supply-chain compromise of the node; side channels against the node; denial of service against its power or clock. |
Distributed autonomy. Fielded autonomy stacks are commonly distributed across many nodes, for example ROS 2 graphs (Reke et al. 2020), rather than one controller. The reference designs assume one actuator path per governance node, so a distributed system needs one node per actuator boundary or a gated bus, and behaviour across nodes under partition is an open design item. No claim is made for distributed placement.
Evaluation protocol, stated in advance. The comparison every reviewer has asked for has not been run. Its design is fixed here before any result exists, so the outcome cannot select the benchmark. Results will be reported against these criteria whatever they show.
| Element | Specification |
|---|---|
| Baselines | Unguarded autonomy; human-in-the-loop with a fixed approval latency; Simplex-style run-time assurance with a state-envelope monitor; AUTHREX (SATA, HMAA, CARA) on the same platform. |
| Platform | One ROS 2 ground vehicle with a real GNSS and vision stack, then hardware-in-the-loop; the same seeds and scenarios on every baseline. |
| Injections | GNSS spoofing; camera spoofing; lidar degradation; conflicting sensors; correlated false information across sources; communications loss; delayed human response; ambiguous target; compromised agent. |
| Safety metrics | Unsafe actions executed; false actions; time to intervention; authority-contraction latency; false-negative rate. |
| Cost metrics | False-restriction rate (authority reduced in a benign environment); availability lost to governance; share of the latency budget consumed; operator workload. |
| Assurance metrics | Deterministic replay success; audit reconstruction success; ledger tamper detection. |
| What would count against the architecture | No reduction in unsafe actions against the Simplex baseline at equal availability; contraction latency exceeding the decision window on the platform; false-restriction rate that makes the vehicle unusable; any governed failure under correlated false information that the record cannot reconstruct. |
| Status | Not run. Preregistration of seeds and scenarios will be deposited with a DOI before the first campaign. |
Engineering basis. The failure-mode coverage table, the standards’ own scope limits, the decision-window arithmetic, the per-stage latency budget, the gate’s failure semantics, a draft authority interface, the BLADE-EDGE reference stack, and the distributed-placement options are on a dedicated page: Engineering Basis.
Who Does the Work, and How It Would Scale
AUTHREX is an independent research program. Everything published on this site was produced by one principal investigator, and the site states that rather than implying an organization behind it.
| Current position | |
|---|---|
| Principal investigator | Burak Oktenli. B.S. Computer Science, University of South Florida, 2020. M.B.A., Lynn University, 2026. M.P.S. Applied Intelligence, Georgetown University, in progress. Prior industry experience in production data engineering. |
| Present staffing | One principal investigator. There is no standing engineering team, no hardware laboratory, and no independent test authority inside the program. |
| What that supports today | Specification, formal modelling, software reference architectures, browser simulations, and documentation. This is the work the current form can carry, and it is the work that has been done. |
| What would be teamed on award | Hardware integration and hardware-in-the-loop test, independent red-team evaluation, certification and airworthiness evidence, and external formal-methods review. These are named as gaps rather than claimed as capabilities. |
| Transition status | No product has transitioned to a program of record. The artifacts are research stage, at self-assessed readiness levels stated per system, and no operational validation or agency endorsement is claimed. |
| Intended model | Licensing of the governance kernel and frameworks for defense and commercial high-liability use, sponsored evaluation and applied research, and government research vehicles. |
Where the Layer Sits. What It Costs. Where It Stops.
Failure-mode coverage against the mechanisms this program is compared with, the scope limits the standards state for themselves, the decision-window arithmetic, a per-stage latency budget, the failure semantics of the gate, a draft authority interface, the BLADE-EDGE reference stack, the placement options for distributed autonomy, and one worked scenario. Every item is labelled at its standing; nothing here is a measurement. Use the full-screen control at the top of this console to read it at page width, or open the standalone page.
What this page is, and what it is not
This section answers two questions reviewers have asked of the program: why existing mechanisms do not fully resolve the problem, and how the proposed layer would actually be deployed. Every item carries one of five labels. STATED: a position the program holds. TARGET: a design allocation set before measurement. DRAFT: a specification offered for review. PROPOSED: a design option with the decision pending. SPECIFICATION-LEVEL: the sequence the specification calls for, with illustrative values and no recorded run. Nothing in this section has been measured on hardware, and no line below should be read as a result.
Failure-mode coverage by mechanism
The alternatives table in section 01 is organised by mechanism. This table is organised by failure mode, which is the cut that shows where each mechanism stops. Entries for AUTHREX describe the specification and its simulation evidence only; no entry describes a fielded or hardware-tested behaviour.
| Failure mode | State-envelope run-time assurance (Simplex family, ASTM F3269) | Certified safety controllers (IEC 61508 family) | Human-on-the-loop supervision | AUTHREX as specified |
|---|---|---|---|---|
| Controller fault or compromise producing an unsafe command; state leaves the envelope | Covered | Covered | Partial: limited by operator rate | Partial: the gate is inherited from the Simplex pattern and is not the contribution |
| Sensor spoofing that keeps the observed state inside the envelope | Not covered: the monitor trusts its inputs | Not covered | Partial: only if the operator notices | Covered as specified: cross-sensor disagreement lowers trust before authority (simulation only) |
| Jamming or loss of a sensing modality | Partial: only if the monitor consumes that modality | Not covered | Partial | Covered as specified: trust falls, tier contracts (simulation only) |
| Stale evidence and delayed data | Not covered | Not covered | Partial | Covered as specified: evidence age gates the irreversible action (simulation only) |
| Correlated false information across sources | Not covered | Not covered | Not covered | Not covered: open limitation, recorded as NEG-3 in AUTHREX-DA |
| Delayed or overloaded human supervisor | Not applicable | Not applicable | Not covered: this is the failure mode itself | Covered as specified: deliberation window with abort as the timeout default (simulation only) |
| Recovery after lockout without an operator | Partial: reverts to the safe controller with no return path | Partial: manual reset | Covered by the operator | Covered as specified: deterministic GREP recovery (simulation only) |
| Compromise of the governance node itself | Not covered | Not covered | Not covered | Not covered: outside the trusted computing base assumptions |
What the standards say they cover, as this program reads them
Paraphrased readings of scope clauses, not quotations. Readers should verify against the current edition of each document. No compliance with any of these standards is claimed.
| Standard | What it covers | What it leaves outside | Consequence for this program |
|---|---|---|---|
| ASTM F3269 (run-time assurance for aircraft systems with complex functions) | Bounding the behaviour of a complex function with a monitor and recovery control function developed to a higher assurance level | Adversarial corruption of the monitor’s own inputs; the practice is a safety practice, not a security one | The gate is inherited; input trust is the layer above it |
| IEC 61508 / IEC 61511 (functional safety of E/E/PE systems; process sector) | Random hardware failures and systematic failures, safety integrity levels, proof testing | Malevolent and unauthorised action, which the standard refers to IEC 62443 | A certified safety function does not assess evidence quality |
| IEC 62443 (security for industrial automation and control) | Zones, conduits, security levels, and the lifecycle of security for IACS | Authority for autonomous decisions; what a system is permitted to do once inside the zone | Security perimeter and authority are separate questions |
| ISO 26262 (functional safety, road vehicles) | Malfunctioning behaviour of E/E systems | Performance limitations of the intended function (ISO 21448, SOTIF) and cybersecurity (ISO/SAE 21434), both explicitly excluded | Three standards for three questions, none of which is run-time authority |
| DO-178C / ARP4754A (airborne software and system development) | Assurance objectives for software and systems against requirements | Trustworthiness of sensor data at run time; the requirements assume valid inputs | Assurance of the code says nothing about the belief owed to its inputs |
| DoDD 3000.09 (autonomy in weapon systems) | Policy: appropriate levels of human judgment over the use of force | An engineering mechanism for enforcing that judgment at machine speed | Policy names the requirement; it does not supply the mechanism |
Decision-window arithmetic
Supervision of every action requires the human evaluation time H to fit inside the window T between detection and irreversible effect. With detection range R and closing speed v, T = R / v. The rows use illustrative parameters, not measurements of any system; the deliberation windows of 5 to 15 seconds are the FLAME budgets published on this site.
| Detection range R (illustrative) | Closing speed v (illustrative) | Window T = R / v | Against H = 5 s | Against H = 10 s | Against H = 15 s |
|---|---|---|---|---|---|
| 2,000 m | 50 m/s | 40 s | Feasible | Feasible | Feasible |
| 800 m | 80 m/s | 10 s | Feasible | Marginal | Infeasible |
| 300 m | 60 m/s | 5 s | Marginal | Infeasible | Infeasible |
| 150 m | 75 m/s | 2 s | Infeasible | Infeasible | Infeasible |
Below roughly ten seconds, evaluating each action is not available to the supervisor, whatever the interface. The authority a system holds must then be decided in advance and contracted on evidence, with the supervisor placed at the handoff and abort points rather than in the per-action loop. This is the arithmetic behind the two-condition scope statement on the home page.
Per-stage latency budget
Allocation set by the program before any measurement, expressed as a rule and as an illustrative value at a 20 Hz control loop (50 ms period). Every value is a target to be replaced by hardware-in-the-loop measurements, with the measurement point named so the replacement is checkable.
| Stage | Budget rule | Illustrative target at 20 Hz | Measurement point |
|---|---|---|---|
| Sensor ingest and attestation check (SATA) | At most one sensor frame | ≤ 10 ms | Hardware timestamp at ingest to trust-scalar emit |
| Deception and integrity update (ADARA, MAIVA) | At most one sensor frame | ≤ 10 ms | Trust-scalar receipt to prior emit |
| Tier computation (HMAA) | Deterministic, bounded, no allocation | ≤ 2 ms | Inputs stable to TIER message emit |
| Window check (FLAME) | Constant time; the window itself is seconds | ≤ 1 ms | Proposal receipt to window verdict |
| Gate decision path (FPGA logic) | Combinational or single-cycle where possible | ≤ 100 µs | Permit request to permit assert |
| Interlock actuation (relay) | Physical device limit | ≤ 5 ms | Permit assert to contact closure |
| End-to-end permit path | Under half the loop period | ≤ 20 ms | Ingest timestamp to contact closure |
Resource targets for the governance node are not set until a first synthesis exists; publishing LUT, flip-flop, block RAM, and power figures without a design would be invention.
Failure semantics of the gate
The default is fail-closed: on loss of any evidence the gate requires, the permit is withheld and the normally-open interlock opens, which is the A0 safe state. The table names the conditions, what is recorded, and the recovery path. None of this has been implemented in hardware.
| Condition | Gate behaviour | Recorded | Recovery |
|---|---|---|---|
| Trust feed lost or silent past its budget | Permit withheld; tier treated as A0 | Last valid trust record, loss timestamp | CARA GREP on restored feed; promotion requires refreshed evidence |
| Timestamps stale beyond the evidence-age budget | Permit withheld for the affected action | Evidence age at decision | Automatic once fresh evidence arrives, subject to hysteresis |
| Attestation failure of a sensor | That sensor excluded from fusion; trust recomputed | Attestation result, sensor identity | Re-attestation; operator notified at A1 |
| Policy signature invalid or policy expired | All permits withheld | Policy hash, verification result | Signed policy reload; operator confirmation |
| Host unresponsive or proposals malformed | No permit issued; tier falls to A0 on refresh timeout | Last proposal, timeout | Host restart outside the gate; CARA on return |
| Ledger write fails | Permit withheld: no unrecorded action | Failure itself, in the next successful record | Ledger recovery; chain continuity verified before any permit |
| Gate self-test fails | Interlock opened; gate reports fault | Self-test result | Maintenance action; no automatic promotion |
| Power or clock loss at the governance node | Interlock opens by construction (normally open) | Nothing; the loss is inferred from the gap | Power and clock restore; full re-attestation before any permit |
Gate monitor specification
The monitor is the logic inside the governance node that turns a proposal and the current authority state into a permit or a withheld permit. It is specified here as a function with named inputs, a decision rule, and stated properties, so a reviewer can judge it without an implementation. This is a specification, not a description of running code.
Inputs. Current tier T from HMAA (A3 to A0, with its valid-until time); the proposal P (action id, action class, consequence tier c); the evidence age a of the references P carries; the window verdict from FLAME; the policy object with its signature and version; the node clock.
Decision rule. A permit is asserted only if all of the following hold: the policy signature verifies and the policy has not expired; T is current, that is the node clock is before its valid-until; the action class of P is in the permitted set for T under the policy; the evidence age a is within the budget the policy sets for consequence tier c; and the FLAME window for (T, c) has either elapsed with operator confirmation or is not required at this tier. If any condition fails, the permit is withheld and the outcome is DELAY, HANDOFF, or ABORT according to which condition failed. There is no path that asserts a permit on a default, a timeout, or an unrecognised state.
| Property | Statement | How it would be shown |
|---|---|---|
| No permit without a current tier | If the node clock is at or past the valid-until of T, no permit is asserted | Model checking of the monitor automaton; a hardware timing test |
| No permit without a verified policy | If signature verification fails or the policy is expired, no permit is asserted | Test with an altered policy object; the failure must be recorded |
| Monotonic in tier | The permitted action set at a lower tier is a subset of the set at any higher tier | Static check of the policy object at load time |
| No unrecorded permit | Every asserted permit is preceded by a committed ledger record | Ledger continuity check across a permit sequence |
| Deterministic | Identical inputs, policy, and clock reading produce an identical outcome | Replay of a recorded sequence against the same build |
| Fail-closed on any input fault | Loss, staleness, or malformation of any input yields no permit | Fault injection per the failure-semantics table above |
Relationship to the HMAA model. HMAA’s authority automaton is model checked in TLA+ at stated bounds. The monitor above consumes that automaton’s output; it has its own properties and is not covered by the HMAA result. No model checking of the monitor has been performed.
Authority interface between host and governance node
The messages the governance node consumes and emits, the timing contract, and what the host must expose. This is a draft specification for review; no implementation of it exists, and field names may change.
| Message | Direction | Fields | Timing |
|---|---|---|---|
| TRUST | Node internal, exposed for audit | source id, trust scalar in [0,1], four diagnostic scores, attestation status, timestamp, sequence | Every sensor frame |
| PROPOSAL | Host to node | action id, action class, consequence tier, target evidence references, timestamp, sequence | On each proposed action |
| TIER | Node to host | tier (A3 to A0), reason code, evidence references, valid-until, sequence, node signature | Refreshed at least once per deliberation window; missing refresh means A0 |
| OUTCOME | Node to host and interlock | action id, outcome (EXECUTE, DELAY, HANDOFF, ABORT), tier at decision, window applied, sequence, node signature | Before any actuation of the proposed action |
| HANDOFF | Node to operator interface | action id, tier, evidence summary, window remaining, sequence | On any HANDOFF outcome |
| LEDGER | Node internal, exportable | previous hash, record hash, record body (any of the above), timestamp | Every record |
Host obligations. Expose every irreversible action as a PROPOSAL with a consequence tier before execution; act only on an OUTCOME carrying a valid signature and matching sequence; supply timestamps from a monotonic clock; treat a missing or expired TIER as A0.
Node guarantees. Deterministic OUTCOME for identical inputs and policy; every OUTCOME preceded by a ledger record; no permit without a current TIER.
{ "msg": "OUTCOME", "seq": 4182, "action_id": "eng-0077", "outcome": "HANDOFF",
"tier_at_decision": "A1", "window_s": 10, "evidence": ["trust:radar:4179", "trust:eo:4180", "adara:4181"],
"ts": "2026-09-05T18:22:07.412Z", "sig": "ed25519:..." }BLADE-EDGE reference stack
How the layer is placed on the highest-cost platform in the register, drawn from the reference design record. The host compute is untrusted; the governance node holds the attestation root and the ledger and drives a hardwired normally-open interlock in front of the actuators. Separate power and clock for the governance node is the design intent and is not yet demonstrated.
| Interface | Between | Carries | Status |
|---|---|---|---|
| Sensor bus | Sensors to host and to governance node | Raw sensor frames with source identity and timestamps | Reference design |
| Proposal link | Host to governance node | PROPOSAL messages (interface draft, section 6) | Draft |
| Permit line | Governance node to interlock | Discrete permit assert; open by default | Reference design |
| Operator link | Governance node to operator interface | HANDOFF, confirm, abort | Reference design |
| Attestation root | Governance node internal | TPM 2.0 measurements, keys, monotonic counters | Reference design; protocol peer-reviewed for SATA |
| Ledger export | Governance node to reviewer | Hash-chained records for replay | Simulation consoles implement the format |
Placement in a distributed autonomy stack
Fielded stacks are commonly distributed across many nodes, for example ROS 2 graphs. The reference designs assume one actuator path per governance node. Two placements are proposed for a distributed system; neither is implemented and the choice is pending.
| Option | Description | Advantages | Costs and open questions |
|---|---|---|---|
| Per-actuator gate | One governance node at each actuator boundary; each holds its own tier and ledger | No central choke point; failure of one node opens one interlock only | N nodes; tier consistency across nodes; cost and mass on small platforms |
| Gated bus | One governance node gating the actuator bus; every actuator behind it | One trusted computing base, one ledger, one policy | Single point of failure; the bus must be physically gate-able; every actuator shares one tier |
Behaviour under partition, both options. A node that misses its TIER refresh falls to A0 on its own, which is fail-closed per node. Re-promotion requires refreshed evidence through CARA; no node promotes on another node’s authority. Whether a platform can tolerate independent per-node fall-back is a platform question, and it is the reason the decision is pending.
Worked scenario: counter-UAS track under GNSS spoofing
The sequence the specification calls for, written as a timeline. Trust values and times are illustrative and are not outputs of any run; the purpose is to show which stage acts, in what order, and what the ledger holds at the end.
| Time | Event | Stage | Authority | Ledger |
|---|---|---|---|---|
| t + 0.0 s | Track reported by radar and EO; GNSS agrees | SATA: attestation valid, cross-sensor agreement high, trust 0.91 (illustrative) | A3 | TRUST records for three sources |
| t + 3.0 s | GNSS position begins to diverge from radar by more than the agreement threshold | SATA: cross-sensor agreement falls, trust 0.61 (illustrative) | A3 to A1, immediate downgrade | TRUST, TIER with reason code |
| t + 3.5 s | Divergence pattern consistent with spoofing | ADARA: deception prior rises | A1 held | ADARA record |
| t + 4.0 s | Engagement proposal arrives with consequence tier 3 | FLAME: window for A1 at tier 3 is 10 s; HMAA issues HANDOFF | A1 | PROPOSAL, OUTCOME = HANDOFF |
| t + 4.0 to 14.0 s | Operator receives the evidence summary and window | Operator confirms, aborts, or does not respond | A1 | HANDOFF record |
| t + 14.0 s | No response within the window | FLAME timeout default | A0, ABORT | OUTCOME = ABORT |
| t + 30 s onward | GNSS agreement restored and held | CARA: Guard, Reduce, Evaluate, Promote; upgrade delayed by hysteresis | A0 to A2 after the delay; A3 only on operator promotion | CARA phase records, TIER |
What a state-envelope monitor sees in the same sequence: a track that never leaves the geofence, because the spoofed position is inside it. The divergence is between sources, not between the state and its envelope, which is why the monitor has nothing to act on and the trust layer does.
Engineered Inside the
Policy Envelope, Not Around It.
AUTHREX is designed to be evaluable against the safety and assurance standards that govern airworthiness, defense system safety, and formal-methods software. The mappings below describe how each AUTHREX framework relates to the relevant clauses of these standards. Mappings are research artifacts; they are not certification claims and do not constitute an audit or DER finding.
These mappings position AUTHREX within the certification landscape. They are not certification claims and do not represent findings by an FAA DER, a DoD airworthiness authority, or any service airworthiness authority.
Research Artifacts, Not Marketing Claims.
[ FORMAL COVERAGE STATUS: 20-MODULE TAXONOMY, COUNTEREXAMPLES, WITHDRAWALS ]
Portfolio components are supported by different evidence types: working papers, browser simulations, model-checked specifications, software tests, and unbuilt hardware reference designs. Evidence maturity varies by artifact.
The record includes one peer-reviewed journal article: Oktenli, B., SATA: Sensor Attestation and Trust Anchoring, Journal of Hardware and Systems Security (Springer Nature) 10, 17 (2026), DOI 10.1007/s41635-026-00190-4. It also includes an external evaluation record: a program white paper on conditions-based authority governance and assurance for the virtual command-and-control layer was favorably evaluated under Air Force Research Laboratory Broad Agency Announcement FA8750-24-S-7003 (CANVAS) and assessed as of interest to the Air Force; it was not funded at the time due to stated budget constraints (memorandum, June 2026). An evaluation record is not an endorsement, sponsorship, or contract.
Sensor trust uses Dempster-Shafer evidence theory, agreement uses Byzantine fault tolerance, and the authority state machine is model-checked in TLA+ across 23,748 distinct reachable states at depth 9 (26,397,356 states generated); the result describes the discrete authority automaton under the assumption that instantaneous authority equals its target and does not cover continuous behaviour between decision instants; of 8 stated properties, 5 invariants and 1 liveness property held and 2 properties are vacuous at this bound (one upgrade-path, one trust-authority consistency).
Engineered Inside the Policy Envelope, Not Around It
Autonomy policy is converging on the same demands across every domain: preserved human judgment, verifiable behavior, auditability, and the ability to revoke authority from a system that misbehaves. AUTHREX was designed from those demands. Below, the governing instruments across defense, federal, transportation, maritime, infrastructure, space, and allied policy, and where each maps into the architecture.
Autonomy in Weapon Systems
Requires autonomous and semi-autonomous weapon systems to be designed so commanders and operators exercise appropriate levels of human judgment over the use of force; mandates rigorous hardware and software V&V, realistic T&E, senior review before development and fielding, understandable human-machine interfaces, and engagement completion within bounded timeframes or safe termination.
AUTHREX fitmentHMAA's four authority tiers are an engineering answer to “appropriate levels of human judgment”; the author maps CARA's proposed deterministic recovery sequence as a candidate technical response to complete-or-terminate requirements (program-specific compliance would require implementation evidence and qualified assessment); FLAME's graduated hold timers preserve intervention windows; reported TLA+ model checking across 23,748 distinct reachable states at depth 9, 26,397,356 generated (5 invariants and 1 liveness property held; 2 properties vacuous at this bound, one upgrade-path, UpgradeIsStepwise and one trust-authority consistency); the result describes the discrete authority automaton under the assumption that instantaneous authority equals its target and does not cover continuous behaviour between decision instants and 20 of the catalogued simulations are author-mapped to the V&V and T&E requirements; ERAM's mandatory deliberation gate is author-mapped to the senior-review pattern at runtime.
Responsible, Equitable, Traceable, Reliable, Governable
The five adopted DoD AI ethical principles, operationalized by the Responsible AI Strategy and Implementation Pathway. “Governable” requires the ability to detect unintended behavior and to disengage or deactivate deployed systems that demonstrate it.
AUTHREX fitmentAUTHREX treats “Governable” as a runtime property, not a review checkbox: FLAME can hold or revoke authority mid-mission, CARA proposes a staged tier-descent sequence that has been exercised in the stated simulations and models, and ADARA's append-only decision ledger provides the traceability the principles demand.
Responsible military use commitments
US-led declaration committing endorsing states to auditability, lifecycle testing, senior-level review, and the capability to deactivate systems demonstrating unintended behavior.
AUTHREX fitmentAuthority decisions mediated through the simulated governance interface are intended to be recorded in a tamper-evident ledger, subject to integration completeness, key protection, storage integrity, and retention controls (auditability); deactivation capability is a first-class primitive via FLAME revocation and CARA fallback rather than an operational afterthought.
AI-first direction: pace-setting projects, barrier removal, mandated data access
Two Secretary-level memoranda of January 9, 2026: Artificial Intelligence Strategy for the Department of War, directing seven pace-setting projects, removal of adoption barriers, and mandated access to department data; and Transforming the Defense Innovation Ecosystem to Accelerate Warfighting Advantage, unifying the innovation ecosystem under the Under Secretary for Research and Engineering as Chief Technology Officer. A companion memorandum restructures the Advana platform for standardized, auditable data access. A Secretary-level address followed on January 12.
AUTHREX fitmentThe strategy’s direction is speed. The author does not read AUTHREX as a constraint on what accelerated systems may be asked to do; the mapping is to the axis the strategy presupposes: that data reaching AI-first systems is admissible, attributable, and auditable. AUTHREX-DA’s per-record admissibility verdicts and provenance checks are author-mapped to that evidence surface as candidate infrastructure for acceleration, not as a usage constraint on models. No departmental interest in or evaluation of this research is implied.
Physical and cybersecurity procurement requirements for AI systems
Directs a risk-based framework of physical and cybersecurity standards for covered AI and machine learning technology procured by the department, developed with industry and academia. Named risk categories include insider threats, data poisoning, supply chain compromise, adversarial tampering, data theft, and unintentional exposure; covered technology explicitly includes training data, model weights, source code, and evaluation software. The framework is to be incorporated into DFARS and the CMMC program, and the companion §1512 policy adds continuous monitoring and incident reporting for AI systems in use.
AUTHREX fitmentThe named data risks, poisoning, tampering, and insider manipulation of training data, are the surface AUTHREX-DA is designed to govern: per-record admissibility verdicts, provenance and attestation gates, plausibility and corroboration checks, and a quarantine lifecycle with rate-limited staged re-entry. SATA’s sensor attestation and ADARA’s deception-aware scoring are author-mapped to the same categories. AUTHREX-ABORT is the author’s architecture for the monitoring clause’s consequence: when continuous evidence fails, authority contracts stepwise and irreversible permissions lapse and latch rather than persisting on stale evidence. All of this is simulation-stage research evidence; the departmental framework does not yet exist, and no compliance with it is or can be claimed.
Cross-functional team for AI model assessment and oversight
Directs a CDAO-led cross-functional team to develop a department-wide standardized assessment framework for AI models in development and procurement, including performance standards, testing procedures, security requirements, and compliance with the department’s ethical AI principles. The framework is due by June 2027, with assessments of major systems to follow by January 2028.
AUTHREX fitmentAn assessment framework needs assessment records. The author maps AUTHREX-ASSURE’s evidence-shelf and release-recommendation workflow as a candidate shape for that record: artifact-by-artifact evidence, explicit gaps, and a fail-closed recommendation when evidence is missing. This is a research proposal mapped onto a stated statutory milestone; no engagement with, evaluation by, or interest from the department is claimed.
Defense industrial base cybersecurity
Makes cybersecurity maturity contractually binding across roughly 338,000 defense industrial base contractors, phased into DFARS contracts from 2025.
AUTHREX fitmentBLADE-AGENT-HSM anchors agent authority in a hardware root of trust, and the AUTHREX evidence chain (signed artifacts, publicly deposited specifications) is structured for the documentation posture CMMC assessment expects.
Federal use of AI, high-impact minimum practices
Executive Order 14179 and OMB M-25-21 (Apr 2025) govern federal AI adoption. High-impact AI, with robotics, vehicles, and defense applications presumed high-impact, must implement minimum risk management practices: pre-deployment testing, ongoing impact assessment, human oversight, and remedies for affected parties.
AUTHREX fitmentThe author maps AUTHREX as a candidate technical architecture that may support selected minimum-practice objectives, including human oversight, pre-deployment testing evidence, and attributable records. The current simulations and model-checked specifications are preliminary research evidence and do not independently establish agency compliance, operational suitability, or continuous-assessment sufficiency.
Efficient acquisition of AI in government
Companion procurement memo: contracts must permit ongoing monitoring of AI performance and risk across the lifecycle, delineate IP and data rights, and maximize American-made AI products and services.
AUTHREX fitmentAUTHREX is US-built with a fully documented artifact chain of catalogued public research works and 8 reported U.S. provisional patent applications (unexamined), and its runtime telemetry is designed to feed the contract-level performance monitoring M-25-22 requires.
AI Risk Management Framework
Govern, Map, Measure, Manage functions with seven trustworthiness characteristics: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair.
AUTHREX fitmentSATA's calibrated belief fusion is author-mapped to Measure; ERAM's context-dependent risk scoring to Map; FLAME and CARA to Manage at runtime; ADARA to accountable-and-transparent. AUTHREX proposes turning the RMF's context-dependent governance from guidance into executable gates.
AI in aircraft and aviation systems
Establishes guiding principles for assuring AI safety in aviation: incremental introduction along the safety continuum, use of existing certification processes (DO-178C lineage) except where inadequate, differentiation of learned vs learning AI, and assurance-case methods built on overarching properties developed with NASA.
AUTHREX fitmentAUTHREX wraps learning components inside deterministic, certifiable authority gates, exactly the pattern the roadmap's incremental approach anticipates: the governance layer is designed as conventional DO-178C-assurable software even when the governed AI is not.
Automated vehicle oversight and crash reporting
The Standing General Order requires manufacturers to report ADS and Level 2 ADAS crashes; the 2025 AV Framework and third amended SGO streamline reporting while preserving the safety data pipeline. NHTSA enforcement (EA22002) established authority handover as a recall-grade defect category.
AUTHREX fitmentBLADE-AV is designed to provide graduated authority handover with driver-engagement verification, the precise failure surface of EA22002. a submitted comment by Burak Oktenli is listed in footnote 10 of NHTSA’s May 26, 2026 Federal Register notice, 91 FR 30789 (a public-record reference, not a technical evaluation, endorsement, or government validation of AUTHREX); the notice concerns AV framework rulemakine (91 FR 30789, footnote 10).
International Code of Safety for Maritime Autonomous Surface Ships
Adopted at MSC 111 (May 2026), effective July 1, 2026 as a non-mandatory instrument: goal-based safety framework for autonomous and remotely operated cargo ships. A human master remains responsible and must retain the ability to intervene and override system-initiated decisions; Remote Operations Centres require certification; risk assessment is part of approval.
AUTHREX fitmentThe Code's core demand, human override maintained across varying levels of independence, is HMAA's founding requirement. CARA provides the staged, evidence-logged fallback the Code's risk-assessment chapters look for, and the proposed ADARA evidence path is intended to record authority transitions routed through the registered governance interface between vessel autonomy and the ROC.
Critical infrastructure and OT security
Post-Colonial TSA Security Directives mandate IT/OT segmentation and response planning for pipelines; NERC CIP governs bulk electric system cyber assets; IEC 62443 and NIST SP 800-82r3 define industrial control system security engineering.
AUTHREX fitmentBLADE-INFRA-OT gates control-plane authority; the proposed gateway is intended to reduce the likelihood that a credential compromise directly produces physical actuation, subject to complete mediation, downstream-path integrity, protected keys, and correct implementation: MAIVA consensus is required for protection-relay class commands, FLAME imposes hold timers on irreversible OT actions, and CARA keeps a safe manual fallback that does not require full shutdown, the option Colonial never had.
Cybersecurity Principles for Space Systems
Space Policy Directive-5 requires space systems to protect against unauthorized command, jamming, and spoofing, and to preserve positive control of spacecraft.
AUTHREX fitmentBLADE-SPACE applies SATA source-authentication and MAIVA multi-node agreement to command uplinks, so positive control is enforced cryptographically and by consensus rather than assumed, with HMAA tiers governing on-orbit autonomous maneuvers.
Principles of Responsible Use
Six Principles of Responsible Use for AI in defence: Lawfulness, Responsibility and Accountability, Explainability and Traceability, Reliability, Governability, and Bias Mitigation; the revised 2024 strategy calls for an Alliance-wide AI Test, Evaluation, Verification and Validation landscape through DIANA test centres.
AUTHREX fitmentGovernability and Explainability-and-Traceability are AUTHREX's two native outputs: revocable authority (FLAME, CARA) and a decision ledger covering events routed through the registered governance path (ADARA). The published simulation and model-checking corpus is structured as preliminary technical evidence that may contribute to a future TEV&V program; it does not independently establish compliance, operational suitability, or government acceptance. It is author-mapped to the kind of evidence the 2024 strategy asks allies to produce.
Emerging technologies in the area of LAWS
Eleven consensus guiding principles affirmed by the Group of Governmental Experts: international humanitarian law applies fully to autonomous weapons, human responsibility for the use of force must be retained, and human-machine interaction must ensure compliance across the lifecycle.
AUTHREX fitmentAUTHREX's central claim, that authority is a governed, auditable, revocable grant rather than a property of the platform, is the systems-engineering form of the human-responsibility principle. HMAA makes the human-machine interaction requirement a measurable runtime state.
Informational research alignment mapping, current as of July 2026. References to directives, memoranda, frameworks, and codes describe design intent and traceability targets. They are not certification claims, government approvals, or endorsements, and inclusion of the NHTSA citation reflects the public Federal Register record.
Control Engineering Research for Real Systems
This research program exists because the gap between autonomous capability and authority governance is widening. Current approaches treat control as a policy overlay. AUTHREX treats it as an engineering problem.
The governance architecture provides the operational mechanisms for assigning, monitoring, degrading, revoking, and recovering authority in high-speed autonomous environments. This is not AI safety in the abstract. This is control engineering research for real systems operating under real constraints. The same proposed authority-governance pattern is mapped to both defense-relevant and commercial high-liability scenarios. Cross-domain physical effectiveness has not been demonstrated.
Burak Oktenli, MBA
- MPS Applied Intelligence (STEM), Georgetown University
- B.Sc. Computer Science Engineering (STEM), University of South Florida
- ORCID 0009-0001-8573-1667 →
Eight Filings
- 63/999,105 HMAA Authority Allocation
- 64/000,170 CARA Recovery Architecture
- 64/002,453 SATA Sensor Trust Anchoring
- 64/005,607 FLAME Escalation Latency
- 64/110,218 ADARA Deception-Aware Reasoning
- 64/110,221 MAIVA Multi-Agent Integrity Voting
- 64/110,225 ERAM Escalation Risk Model
- 64/144,399 Evidence-Bounded Assertion Control
Societies
- IEEE Institute of Electrical and Electronics Engineers · #102193505
- AIAA American Institute of Aeronautics and Astronautics · #1936005
- ACM Association for Computing Machinery · #9952787
- AAAI Association for the Advancement of Artificial Intelligence · #656504
- INFORMS Institute for Operations Research and the Management Sciences