News Washington Examiner: Your Screen Just Went Dark. That Doesn’t Mean the Election Was Stolen →
Viewing 01 / 05 · Operational Domains. One Authority Model.
[ Operational Domains ]

Operational Domains. One Authority Model.

Same governed decision pipeline, nine operating environments. Select a domain: each panel pairs the scenario with the incident record it mirrors, the governed and ungoverned decision chains, and the frameworks that engage. These are synthetic scenario outcomes produced by browser logic; they do not demonstrate physical incident prevention or operational effectiveness.

Aircraft HMAA-UAV
Autonomous Car BLADE-AV
Maritime USV BLADE-MARITIME
Defense Drone BLADE-CUAS
Power Grid BLADE-INFRA-OT
Space Vehicle BLADE-SPACE
Underwater UUV BLADE-MARITIME
AUTHREX-Agent BLADE-AGENT-HSM
Cyber-Defense AUTHREX

[ SELECT A DOMAIN ABOVE TO OPEN ITS GOVERNED SCENARIO ]

An airliner's flight control computer is corrupted by a cosmic ray.

A high-energy particle strikes a memory cell inside the autopilot. A single bit flips. The computer now has corrupted sensor data, but it doesn't know it's corrupted. It commands an uncommanded pitch-down. The aircraft drops 190 feet in 4 seconds. Passengers hospitalized.

Real Incident

JetBlue Flight 1230 · 30 Oct 2025 · Airbus issued recall for ~6,000 A320-family aircraft

Frameworks engaged
SATAMAIVACARAFLAME
✈ Aircraft BLADE-EDGE

WITH AUTHREX

↯ cosmic ray · MAIVA VOTES · ELAC1 ≠ ELAC2 → reject bit · autopilot → supervised mode

WITHOUT AUTHREX

↯ cosmic ray · DIVE · 190 ft lost · 15 injured · fleet grounded worldwide

SATA · SENSOR TRUST

Treats corrupted ELAC-1 data as untrusted. The computer knows it cannot trust its own reading.

MAIVA · FAULT VOTING

ELAC-1 says "dive," ELAC-2 says "hold." Byzantine vote rejects the corrupted command before actuators move.

CARA · RECOVERY

Autopilot drops to supervised mode, crew regains authority in a defined state, no cascading failure.

A driver-assist system fails to detect a stopped fire truck at highway speed.

The camera is glare-blinded by morning sun, the radar can't separate the stopped truck from roadway clutter. The system doesn't know it cannot see the obstacle. It holds speed. The driver isn't paying attention because the system has been silently reliable for months. Collision.

Real Incident

Tesla Autopilot · NHTSA EA22002 · 956 reviewed / 467 trend cases · 13 fatal, 14 deaths · ~2M recall

Frameworks engaged
SATAHMAACARAFLAME
⊡ Autonomous Car BLADE-AV

WITH AUTHREX

TRUCK DETECTED · SATA: camera trust dropped 92% → 31% · HMAA: forced driver handoff · alerts engaged · CARA: brake-to-stop-in-lane if no response

WITHOUT AUTHREX

Tesla (ADAS on) · STOPPED TRUCK · → sun-glare blinds camera · Driver unaware · Impact at highway speed

SATA · SENSOR TRUST

Camera confidence drops below threshold under glare. Radar signal ambiguous. System declares: reduced trust.

HMAA · AUTHORITY HANDOFF

Low trust triggers forced driver handoff. Steering wheel torque, audio alert, seat vibration. Not a suggestion, a mandatory takeover.

CARA · SAFE DEGRADATION

If driver doesn't respond, car decelerates to stop in lane, not a sudden disengagement with no plan.

An uncrewed patrol vessel is GPS-spoofed into foreign territorial waters.

An adversary broadcasts a false GPS signal. The vessel believes it is still in international waters. It continues its patrol pattern. In reality, it has crossed into sovereign territory, where its presence can be framed as an act of aggression or seized for intelligence extraction.

Real Incident

Large-Scale GNSS Spoofing 2025 · CNAS/Eurocontrol Reports · Widespread navigation disruption in Eastern Mediterranean and Persian Gulf

Frameworks engaged
ADARASATACARAERAM
▽ Maritime USV BLADE-MARITIME

WITH AUTHREX

SOVEREIGN BORDER · SAFE LOITER · ADARA: GPS ≠ INS ≠ celestial backup · SATA: nav trust collapsed → hold position

WITHOUT AUTHREX

SOVEREIGN BORDER · ↯ GPS spoofed by adversary · Vessel crosses border unknowingly · Diplomatic incident

ADARA · DECEPTION DETECTION

Cross-checks GPS against inertial navigation, celestial backup, and terrain matching. When they disagree, spoofing is declared.

CARA · SAFE LOITER

Vessel enters hold-position mode. No forward commitment while navigation integrity is compromised.

ERAM · ESCALATION

Situation escalates automatically to shore command. Human decides next action, not the machine.

An armed drone misidentifies a vehicle and is about to strike civilians.

Under compressed decision timelines and degraded intelligence, the target-classification system flags a civilian vehicle as a threat. The pattern-of-life analysis is ambiguous. The human operator is under pressure to commit. No mandatory evidence threshold, no pause gate.

Real Incident

Kabul Drone Strike · 29 Aug 2021 · DoD AR 15-6 · Ten civilians killed including seven children

Frameworks engaged
FLAMEHMAASATAADARA
◊ Defense Drone BLADE-CUAS

WITH AUTHREX

▸ Sensor flags "target" (55% confidence) · ▸ FLAME: below 85% threshold → FORCED PAUSE 60s · HMAA: senior-officer review required · ADARA: test for deception/civilian substitute

WITHOUT AUTHREX

▸ Sensor flags "target" (55% confidence) · ▸ Pattern-of-life: ambiguous · ▸ Human under time pressure · STRIKE

FLAME · FORCED PAUSE

Below confidence threshold, a mandatory 60-second deliberation window is imposed. No fast strikes on ambiguous targets.

HMAA · ESCALATION

Ambiguous identification triggers senior-officer review. Authority to commit is explicit, not implicit.

ADARA · DECEPTION

Tests the possibility that the target may be deceptive or a civilian substitute. Forces additional evidence before commitment.

A utility's pipeline is hit by ransomware and the only safe option is full shutdown.

A compromised VPN credential lets attackers into the IT network. No segmentation exists between IT and operations. The utility cannot prove the OT network is clean, so it shuts down the entire pipeline as the only safe fallback. Fuel supply collapses for days across multiple states.

Real Incident

Colonial Pipeline Ransomware · 7 May 2021 · CISA/FBI Joint Advisory · Presidential emergency declared across 14 states

Frameworks engaged
SATAHMAACARAERAM
Power Grid BLADE-INFRA-OT

WITH AUTHREX

IT ✗ · breached only · TRUST GATE · OT ✓

WITHOUT AUTHREX

IT ✗ · ransomware active · no barrier · OT ✗

SATA · TRUST BOUNDARY

IT and OT networks have enforced trust boundaries. Compromise on one side does not contaminate the other.

CARA · GRACEFUL DEGRADATION

OT network continues operating in reduced-authority mode while IT is remediated, no full shutdown needed.

ERAM · INCIDENT ESCALATION

Automatic notification to CISO and federal partners. Coordinated response, not a blind panic shutdown.

A satellite's autonomous collision-avoidance system triggers a risky maneuver on bad orbital data.

A conjunction alert arrives. The on-board autonomy computes a probability of collision and commits to an avoidance burn. But the tracking data was stale, the threat object's orbit had already been updated on the ground, and the burn moves the satellite into a worse trajectory, depleting station-keeping fuel and creating debris risk for other operators.

Real-World Pattern

Multiple near-miss conjunction events in LEO · Growing autonomous-maneuver pressure as constellations scale · NASA, ESA, Space Force tracking data latency problems publicly documented

Frameworks engaged
SATAFLAMEHMAACARA
◈ Space Vehicle BLADE-SPACE

WITH AUTHREX

EARTH · SAT-A · SATA: conjunction data age > 4 hours · FLAME: forced wait for ground uplink

WITHOUT AUTHREX

EARTH · SAT-A · ↯ BAD BURN · Stale conjunction data · Fuel depleted

SATA · DATA FRESHNESS

Tracks the age and confidence of orbital data. Stale tracking information drops trust below the action threshold.

FLAME · GROUND-WAIT GATE

Forces a pause for ground uplink when conjunction data is old, unless collision probability is so high that autonomous action is mandatory.

CARA · SAFE-HOLD

If ground link is lost mid-decision, vehicle enters safe attitude hold instead of executing an uncertain maneuver.

An autonomous undersea vehicle on a long-duration mission has lost contact with its host platform.

A torpedo-shaped UUV is conducting a 30-day seabed survey. Acoustic comms with the host vessel have been intermittent for 6 hours. Inertial navigation has accumulated drift. The mission planner is asking the vehicle to surface for a GPS fix, but the vehicle's classifier flags surface activity above as a possible adversary asset. Acting on bad guidance now risks compromising the mission or the platform.

Real-World Pattern

Acoustic comms latency and dropout · GPS-denied undersea navigation · Long-duration autonomy without human-in-the-loop · Documented in U.S. Navy and DARPA Manta Ray UUV programs

Frameworks engaged
SATAADARAFLAMECARA
◯ Underwater UUV BLADE-MARITIME

WITH AUTHREX

SURFACE · UUV · SAFE LOITER · SATA: INS trust drops below 0.6

WITHOUT AUTHREX

SURFACE · UUV · ↯ INS drift accumulates · ↯ SURFACE INTO RISK

SATA · NAVIGATION TRUST

Tracks INS drift, acoustic comm health, and last-known-good GPS age. Confidence drops when navigation accuracy can no longer support a planned action.

ADARA · SURFACE-RISK CHECK

Cross-checks acoustic, optical, and pattern-of-life signals before surfacing. Adversary detection feeds directly into surface authorization.

CARA · DEPTH HOLD

When trust is insufficient, the vehicle enters minimum-power station-keeping at depth rather than completing an uncertain maneuver. Position is preserved for hours.

A coding agent is about to commit a private API key to a public repository.

An autonomous coding agent has been authorized to push to a project repository. While editing a config file, it accidentally includes a private API key in the diff. The push tool is in its authorized envelope, so without governance the push proceeds, the key is exposed, and a multi-hour credential rotation follows.

Real-World Pattern

Documented in CISA + NSA + Five Eyes joint guidance Careful Adoption of Agentic AI Services, May 1, 2026 · Tool misuse and credential exposure are named risk categories of agentic AI deployment

Frameworks engaged
SATAHMAAFLAMECARA
◇ AUTHREX-Agent BLADE-AGENT-HSM

WITH AUTHREX

WITHOUT AUTHREX

CODING AGENT · git.push (with secret) · PUBLIC REPO · main branch

SATA · INPUT TRUST

Computes a trust scalar for each registered input the agent ingests. Credential patterns, prompt-injection signatures, and provenance gaps collapse trust before the action commits.

HMAA · TIERED AUTHORITY

Authority de-escalates T3 → T2 → T1 → T0 as risk rises. Tool calls outside the authorized envelope default to HANDOFF, never silent allow.

FLAME · DELIBERATION

Bounded deliberation window before high-stakes actions. Fail-safe default is ABORT on timeout, not EXECUTE on timeout.

An autonomous cyber-reasoning system is about to patch a live water-treatment controller.

An autonomous cyber-reasoning system (CRS) finds a flaw in critical-infrastructure software and proposes a patch. The patch is correct for a test bench, but the target is a live SCADA controller. Pushed without authority checks, a bad autonomous patch can take the plant offline as surely as the vulnerability it closes. AUTHREX governs whether the action is authorized; it treats the CRS as a black box and performs no vulnerability discovery itself.

Real-World Pattern

DARPA AI Cyber Challenge (AIxCC), DEF CON 33, August 2025 produced autonomous CRS that patch critical-infrastructure code at machine speed, four open-sourced for defenders · CISA + NSA + Five Eyes Careful Adoption of Agentic AI Services, May 1, 2026 · FY26 NDAA §1513 AI-specific and supply-chain risk categories

Frameworks engaged
SATAADARAHMAAMAIVAFLAMECARAERAM
⬡ Cyber-Defense AUTHREX

WITH AUTHREX

WITHOUT AUTHREX

CRS · autonomous · auto-patch (unverified) · LIVE OT

HMAA · CRITICALITY-DRIVEN TIER

Target criticality sets authority. A patch to an isolated test bench is T3 (autonomous); the same patch to a live OT controller drops to T1 and requires human confirmation.

ADARA · POISONED-FINDING SCREEN

Detects when a proposed action is inconsistent with the stated finding, the signature of a manipulated CRS. Trust collapses and the action is quarantined before any target is touched.

CARA · PRE-ARMED ROLLBACK

Rollback to last known-good state is armed before any production write. If the action degrades the system, the configured staged recovery sequence is invoked. Decisions routed through the proposed ERAM evidence path are intended to produce attributable audit records.

[ Operational Simulations ]

[ ALL SCENARIOS ARE SIMULATED ENVIRONMENTS, NOT FIELDED SYSTEMS ]

Mission Environment Scenarios

Operational scenarios across air, ground, sea, undersea, infrastructure, orbital, agentic, and financial domains, each showing what happens without governance vs. with AUTHREX authority control.

[ SELECT A SIMULATION TO OPEN THE MISSION CONSOLE ]

[ Strategic Roadmap ]

18-Month Horizon

AS OF OCTOBER 5, 2026DOCUMENTED

Engineering Foundation Documented

7 governance frameworks published · 3 peer-reviewed journal articles (2 in the AUTHREX technical corpus) (Springer Nature, 2026) · 8 U.S. provisional patent applications reported as filed · 12 hardware reference designs (BOM-specified) · 25 catalogued browser simulations (seeded, self-run); counts differ because they count different things: 14 catalogued SIM records in the technical catalog register (SIM-01 to SIM-14); 22 standalone consoles in the simulation tree, which counts consoles and demonstrators: 21 drawn from the 25 catalogued simulations, plus the AUTHREX-DEFEND simulation, which the catalog does not list; and 39 launchable browser simulations across the two public sites. The register figure is the controlled one. · catalogued public technical works (Zenodo, SSRN, reference volumes; see catalog) · Rover + UAV testbed designs documented

Q3 2026IN PROGRESS

Hardware Assembly & Patent Strategy

BLADE-EDGE prototype assembly begins · Nonprovisional filing decisions pending owner and counsel (the four applications with the earliest deadlines first, of eight) · FPGA enforcement-path RTL development (proposed; no reviewed implementation claimed) · Physical UAV testbed flight validation

Q4 2026

Integrated Testing & SBIR Submission

SATA-FLAME pipeline executing on FPGA hardware (TRL 4 to 5 target) · SBIR Phase II proposal submission · BLADE-MARITIME hardware integration · Rover testbed governance validation campaign

Q1-Q2 2027

TRL 6 Target & Evaluation Partnerships

Multi-framework governance demonstrated on physical hardware (TRL 5 to 6 target) · Potential later nonprovisional filings claiming benefit of the provisional applications, subject to applicable requirements and counsel advice · Evaluation partnership or CRADA engagement (planned) · BLADE-AV autonomous vehicle integration testing

TRL PROGRESSION: 2-3 → 6 OVER 18 MONTHS
CURRENT: SELF-ASSESSED TRL 2-4TARGET: TRL 6
[ Dual-Use Application ]

One Governance Pipeline. Two Markets.

The same proposed authority-governance pattern is mapped to both defense-relevant and commercial high-liability scenarios. Cross-domain physical effectiveness has not been demonstrated.

Defense ApplicationFrameworkCommercial Application

Friendly-asset protection for autonomous aerial systems under EW spoofing

SATAADARA

Autonomous trucking: forced human override during sensor degradation on highways

UAV swarm coordination under Byzantine node compromise

MAIVA

Warehouse robot fleets: isolating malfunctioning units without halting operations

Maritime patrol vessel GPS spoofing into foreign territorial waters

ADARAERAM

Commercial shipping: preventing spoofing-induced rerouting losses and piracy exposure

Power grid SCADA command injection during contested operations

FLAMECARA

Industrial SCADA: mandatory deliberation before automated load-shedding in energy grids

Autonomous servicer deliberation before unplanned RPO maneuvers in GEO

SATAERAM

On-orbit servicing: governed collision-avoidance decisions designed to support insurer and regulator scrutiny

UUV tier descent and loiter under comms-denied conditions

HMAACARA

Offshore inspection AUVs: governed fallback behavior for pipeline and wind-farm surveys when the link drops

Counter-UAS engagement gating over defended installations

FLAMEHMAA

Airport drone mitigation: countermeasures held behind mandatory human authorization near active runways

Coding-agent privilege escalation blocked before production push

FLAMEHMAA

Enterprise AI agents: hardware-anchored gating of automated changes in corporate DevOps and finance operations

Autonomous engagement-authority coordination under rate and consensus limits

MAIVAFLAME

Algorithmic trading: order-storm circuit breakers that hold authority before a feedback loop becomes a flash crash

One evidence base serves both columns: the same bounded TLA+ model-checking results, simulation corpus, and audit-ledger design.

Commercial mappings are engineering analogs of the defense scenarios, not separate products. Each pair is mapped to the same high-level authority-governance pattern and failure class; evidence, assumptions, integration depth, and maturity differ by domain, and only the operational context and liability regime otherwise change.

[ V&V ]

From Simulation Toward Physical Evidence

Each governance framework undergoes a four-stage verification pipeline designed to meet MIL-STD-882E safety-critical requirements, progressing from computational simulation through model-checked specification toward physical hardware execution.

Stage 01Complete

Monte Carlo validation

Statistical validation across randomized initial conditions and adversarial injection scenarios. The HMAA-UAV simulation executes 6DOF physics with EKF2 state estimation under six distinct attack vectors.

Stage 02In progress

Formal methods verification

TLA+ state-space modeling applied to MAIVA consensus and FLAME deliberation logic. The rover testbed baseline includes 200,000 FSM conformance comparisons that produced no observed unsafe states within the tested and configured comparison space.

Stage 03Q3 2026

Hardware-in-the-loop (HITL)

SATA-FLAME governance bitstream commissioning on Zynq UltraScale+ FPGAs. Validates deterministic latency and recovery behavior against live corrupted sensor injections.

Stage 04Q4 2026

Physical testbed validation

Rover and UAV platforms executing governance pipelines in physical environments. A 42-file Python engineering baseline with 98 tests and TLA+ formal specification.

Aligned with MIL-STD-882E · NIST AI RMF · DoDD 3000.09 · ISO 26262 · NERC CIP · IEC 61850. The current engineering-preview stage is publicly documented; implementation and independent validation remain incomplete.