News Washington Examiner: Your Screen Just Went Dark. That Doesn’t Mean the Election Was Stolen →
Viewing 01 / 06 · Not Just What the AI Can Do, but When It Should Act
[ Governance Architecture ]

Not Just What the AI Can Do, but When It Should Act

Traditional autonomous systems focus on what the AI can do. AUTHREX adds the missing layer: governance that decides when action is safe, under what authority, based on real-time trust, threat, and context. That shift matters in six concrete ways:

[ Subsystem Demonstrations ]

Framework Computation Demonstrations

Live computational demonstrations of all seven AUTHREX frameworks operating independently, showing the math, the logic, and the real-time behavior of each subsystem. Each framework runs live inside the Governance Pipeline console on the home page, and as a full standalone console in the Simulation Laboratory.

[ Standards & Policy Alignment ]

Engineered Inside the
Policy Envelope, Not Around It.

AUTHREX is designed to be evaluable against the safety and assurance standards that govern airworthiness, defense system safety, formal-methods software, road-vehicle and grid safety, run-time assurance, and simulation credibility. The mappings below describe how each AUTHREX framework relates to the relevant clauses of these standards. Mappings are analytical artifacts; they are not certification claims and do not constitute an audit or DER finding.

These mappings position AUTHREX within the certification landscape. They are not certification claims and do not represent findings by an FAA DER, a DoD airworthiness authority, or any service airworthiness authority.

AUTHREX-AGENT · RuntimeSeven gates · Live
T3Full autonomyStandby
T2SupervisedActive
T1RestrictedStandby
T0Human controlStandby
SATA input trust τ 0.93 PASS ADARA injection screen PASS HMAA tier assigned T2 FLAME deliberation 3.0 s HOLD gate tool.call PUSH_CONFIG HANDOFF · HUMAN ERAM decision signed · ECDSA LOGGED
[ Evidence Layer ]

Engineering Evidence, Not Marketing Claims.

[ FORMAL COVERAGE STATUS ]

Peer review2 articles

SATA (J. Hardware and Systems Security, 2026) and The Authority Gap (Digital War, 2026), both in the technical corpus.

Formal modelTLA+, bounded

23,748 distinct reachable states at depth 9, 26,397,356 generated. Of 8 stated properties, 5 invariants and 1 liveness property held; 2 vacuous at this bound. The formal coverage page classifies twenty-one modules, two of them faithful to the artifact they model.

What it does not coverStated limit

The discrete authority automaton only, assuming instantaneous authority equals its target. Not continuous behaviour between decision instants.

MethodsPublished

Dempster-Shafer evidence theory for sensor trust; Byzantine fault tolerance for agreement.

External evaluationAFRL, not funded

Favorably evaluated under BAA FA8750-24-S-7003 (CANVAS), assessed as of interest to the Air Force, not funded at the time on stated budget grounds (June 2026). Not an endorsement, sponsorship, or contract.

External reviewQUARANTINE, two rounds

Two external review rounds on AUTHREX-QUARANTINE (releases 2.2.0 and 2.2.2) recorded twenty findings, three of them Major; every finding was reproduced and corrected across releases 2.2.1 to 2.2.5, and the reviewers’ mutants now ship in the package’s mutation set. Release 2.2.5 gate: engine 74/74, browser console 44/44, 11 of 11 non-equivalent mutants killed. A second reading, not verification; nothing reproduced elsewhere.

Record propertiesFour, stated per file

Retention alone is not evidence. Each Set file states which of four record properties it has: policy identity sealed in the record, replay from seed, recomputation from a published specification without the engine, and an external anchor. A hash chain can show that a record is consistent with itself; it cannot show that the record was never rewritten, and it does not show that the record describes the decision; replay or recomputation against the frozen configuration establishes that. Seven of the fifteen files seal a policy or configuration hash, and fourteen replay from seed; AUTHREX-DEFEND does not, because its report-only pages read a live computer. Recomputation without the engine and external anchoring are open across the Set.

Deterministic timeTick time only

In every Set console the sealed decisions depend on tick time only. The wall clock appears in compute-cost metrics, animation pacing, and export timestamps, never in an authority value, so identical inputs give identical sealed decisions on any hardware.

Other artifactsMaturity varies

Working papers, browser simulations, software tests, and unbuilt hardware reference designs.

12Hardware platforms
7Architectures
25Catalogued simulations
Read the white paper → Governance Kernel validation status →
[ Simulated Performance Characteristics ]
HMAA Decision Latency
<12ms
Authority computation cycle (simulated)
MAIVA BFT Threshold
f<n/3
Byzantine tolerance: 2 of 5 nodes max
FLAME Min Deliberation
3.0s
Configurable: 1.5s to 30s by mission class
CARA Recovery Time
<2.2s
Full cascade: Autonomy → RTB (simulated)
[ Standards & Policy Alignment ]

Engineered Inside the Policy Envelope, Not Around It

Autonomy policy is converging on the same demands across every domain: preserved human judgment, verifiable behavior, auditability, and the ability to revoke authority from a system that misbehaves. AUTHREX was designed from those demands. Below, the governing instruments across defense, federal, transportation, maritime, infrastructure, space, and allied policy, and where each maps into the architecture.

[ Department of Defense ]8 instruments
DoDD 3000.092023IN EFFECT · REVISION ORDERED BY NSPM-11

Autonomy in Weapon Systems

Requires autonomous and semi-autonomous weapon systems to be designed so commanders and operators exercise appropriate levels of human judgment over the use of force; mandates rigorous hardware and software V&V, realistic T&E, senior review before development and fielding, understandable human-machine interfaces, and engagement completion within bounded timeframes or safe termination.

AUTHREX fitmentHMAA's four authority tiers are an engineering answer to “appropriate levels of human judgment”; the author maps CARA's proposed deterministic recovery sequence as a candidate technical response to complete-or-terminate requirements (program-specific compliance would require implementation evidence and qualified assessment); FLAME's graduated hold timers preserve intervention windows; reported TLA+ model checking across 23,748 distinct reachable states at depth 9, 26,397,356 generated (5 invariants and 1 liveness property held; 2 properties vacuous at this bound, one upgrade-path, UpgradeIsStepwise and one trust-authority consistency); the result describes the discrete authority automaton under the assumption that instantaneous authority equals its target and does not cover continuous behaviour between decision instants and 20 of the catalogued simulations are author-mapped to the V&V and T&E requirements; ERAM's mandatory deliberation gate is author-mapped to the senior-review pattern at runtime.

HMAACARAFLAMEERAM
DoD AI Ethical Principles + RAI Pathway2020 / 2022IN EFFECT

Responsible, Equitable, Traceable, Reliable, Governable

The five adopted DoD AI ethical principles, operationalized by the Responsible AI Strategy and Implementation Pathway. “Governable” requires the ability to detect unintended behavior and to disengage or deactivate deployed systems that demonstrate it.

AUTHREX fitmentAUTHREX treats “Governable” as a runtime property, not a review checkbox: FLAME can hold or revoke authority mid-mission, CARA proposes a staged tier-descent sequence that has been exercised in the stated simulations and models, and ADARA's append-only decision ledger provides the traceability the principles demand.

FLAMECARAADARASATA
Political Declaration on Military AI & Autonomy202358 ENDORSING STATES

Responsible military use commitments

US-led declaration committing endorsing states to auditability, lifecycle testing, senior-level review, and the capability to deactivate systems demonstrating unintended behavior.

AUTHREX fitmentAuthority decisions mediated through the simulated governance interface are intended to be recorded in a tamper-evident ledger, subject to integration completeness, key protection, storage integrity, and retention controls (auditability), where tamper-evidence shows the record was not altered after it was written and replay against the frozen configuration shows that it describes the decision; deactivation capability is a first-class primitive via FLAME revocation and CARA fallback rather than an operational afterthought.

ADARAFLAMECARA
DoW AI Strategy · Jan 9 Memoranda2026IN EFFECT

AI-first direction: pace-setting projects, barrier removal, mandated data access

Two Secretary-level memoranda of January 9, 2026: Artificial Intelligence Strategy for the Department of War, directing seven pace-setting projects, removal of adoption barriers, and mandated access to department data; and Transforming the Defense Innovation Ecosystem to Accelerate Warfighting Advantage, unifying the innovation ecosystem under the Under Secretary for Research and Engineering as Chief Technology Officer. A companion memorandum restructures the Advana platform for standardized, auditable data access. A Secretary-level address followed on January 12.

AUTHREX fitmentThe strategy’s direction is speed. The author does not read AUTHREX as a constraint on what accelerated systems may be asked to do; the mapping is to the axis the strategy presupposes: that data reaching AI-first systems is admissible, attributable, and auditable. AUTHREX-DA’s per-record admissibility verdicts and provenance checks are author-mapped to that evidence surface as candidate infrastructure for acceleration, not as a usage constraint on models. No departmental interest in or evaluation of this work is implied.

SATAADARAHMAA
FY26 NDAA §15132025ENACTED · P.L. 119-60

Physical and cybersecurity procurement requirements for AI systems

Directs a risk-based framework of physical and cybersecurity standards for covered AI and machine learning technology procured by the department, developed with industry and academia. Named risk categories include insider threats, data poisoning, supply chain compromise, adversarial tampering, data theft, and unintentional exposure; covered technology explicitly includes training data, model weights, source code, and evaluation software. The framework is to be incorporated into DFARS and the CMMC program, and the companion §1512 policy adds continuous monitoring and incident reporting for AI systems in use.

AUTHREX fitmentThe named data risks, poisoning, tampering, and insider manipulation of training data, are the surface AUTHREX-DA is designed to govern: per-record admissibility verdicts, provenance and attestation gates, plausibility and corroboration checks, and a quarantine lifecycle with rate-limited staged re-entry. SATA’s sensor attestation and ADARA’s deception-aware scoring are author-mapped to the same categories. AUTHREX-ABORT is the author’s architecture for the monitoring clause’s consequence: when continuous evidence fails, authority contracts stepwise and irreversible permissions lapse and latch rather than persisting on stale evidence. All of this is simulation-stage engineering evidence; the departmental framework does not yet exist, and no compliance with it is or can be claimed.

AUTHREX-ABORTSATAADARAMAIVA
FY26 NDAA §15332025FRAMEWORK DUE JUN 2027

Cross-functional team for AI model assessment and oversight

Directs a CDAO-led cross-functional team to develop a department-wide standardized assessment framework for AI models in development and procurement, including performance standards, testing procedures, security requirements, and compliance with the department’s ethical AI principles. The framework is due by June 2027, with assessments of major systems to follow by January 2028.

AUTHREX fitmentAn assessment framework needs assessment records. The author maps AUTHREX-ASSURE’s evidence-shelf and release-recommendation workflow as a candidate shape for that record: artifact-by-artifact evidence, explicit gaps, and a fail-closed recommendation when evidence is missing. This is a engineering proposal mapped onto a stated statutory milestone; no engagement with, evaluation by, or interest from the department is claimed.

HMAAADARAERAM
FY26 NDAA §15342025TASK FORCE · MILESTONE 1 APR 2026

AI sandbox environments task force

Directs a Department task force on artificial-intelligence sandbox environments, with a milestone of 1 April 2026, so that models can be exercised in isolated environments before they touch production systems.

AUTHREX fitmentIsolation contains reach, not authority. The author maps AUTHREX-SANDBOX as a governance pattern for the environments the section directs: configured authority bounds, proposed reversibility controls, and an evidence record covering actions routed through the registered simulation interface, feeding ASSURE downstream. A engineering proposal mapped onto a stated statutory milestone; no engagement with, or evaluation by, the task force is claimed.

HMAAFLAMEERAM
CMMC 2.0 · 32 CFR 1702024PHASING IN

Defense industrial base cybersecurity

Makes cybersecurity maturity contractually binding across roughly 338,000 defense industrial base contractors, phased into DFARS contracts from 2025.

AUTHREX fitmentBLADE-AGENT-HSM anchors agent authority in a hardware root of trust, and the AUTHREX evidence chain (signed artifacts, publicly deposited specifications) is structured for the documentation posture CMMC assessment expects.

BLADE-AGENT-HSMADARA
[ White House · OMB · NIST ]6 instruments
NSPM-112026IN EFFECT

Artificial Intelligence in the National Security Enterprise

Signed 5 June 2026, replacing NSM-25. Directs the national security enterprise to accelerate AI adoption while respecting the chain of command and operational authorities; requires, through contractual clauses or other means, that no commercial entity or adversary can prevent use of, disable, degrade or materially modify an AI system warfighters depend on without Federal Government knowledge and approval; orders a DoDD 3000.09 revision within 90 days with annual review, and standardized AI test, evaluation, verification and validation methodologies.

AUTHREX fitmentThe off-switch clause is an authority question: who may stop, alter or restore a fielded system, and on what evidence. AUTHREX treats stop, hold, revoke and restart as governed authority transitions with a recorded evidence basis: FLAME hold and revocation, CARA staged recovery, ERAM signed decision record. The author’s July 2026 commentary in RealClearDefense examined the clause’s effect on the operator off-switch. Analytical mapping; no engagement with the national security enterprise is claimed.

FLAMECARAERAM
National Security S&T Strategy2026ISSUED AUG 2026

OSTP strategy aligning federal R&D with the 2025 National Security Strategy

Four pillars: focusing technological competition, building technological resilience, accelerating innovation, and protecting national-security science and technology from exploitation. Names AI and autonomy, undersea and space among battlefield priorities, and operational-technology and industrial-control-system security, cyber-physical threat modelling and post-quantum cryptography among resilience priorities.

AUTHREX fitmentThe strategy names the domains where the AUTHREX profiles sit: autonomy, space, OT and ICS security, and post-quantum signing. The author proposed in RealClearDefense an authority-degradation test article for the strategy: declared authority states, deliberate evidence degradation, bounded contraction, and recovery tested as rigorously as failure. Analytical mapping only.

HMAACARASATA
Cyber Strategy for America2026MARCH 2026

President Trump’s Cyber Strategy for America

The March 2026 White House cyber strategy, which addresses, among broader national cybersecurity priorities, the assurance of AI systems before and during deployment.

AUTHREX fitmentThe author maps AUTHREX-ASSURE, the pre-deployment authority-governance profile, to the strategy’s pre-deployment assurance theme: evidence conditions evaluated artifact by artifact, an internal release-or-hold recommendation, and deployment decisions left external to AUTHREX. Author-mapped; not an endorsement.

HMAAADARAERAM
EO 14179 + OMB M-25-212025IN EFFECT

Federal use of AI, high-impact minimum practices

Executive Order 14179 and OMB M-25-21 (Apr 2025) govern federal AI adoption. High-impact AI, with robotics, vehicles, and defense applications presumed high-impact, must implement minimum risk management practices: pre-deployment testing, ongoing impact assessment, human oversight, and remedies for affected parties.

AUTHREX fitmentThe author maps AUTHREX as a candidate technical architecture that may support selected minimum-practice objectives, including human oversight, pre-deployment testing evidence, and attributable records. The current simulations and model-checked specifications are preliminary engineering evidence and do not independently establish agency compliance, operational suitability, or continuous-assessment sufficiency.

HMAAADARASATAERAM
OMB M-25-222025IN EFFECT

Efficient acquisition of AI in government

Companion procurement memo: contracts must permit ongoing monitoring of AI performance and risk across the lifecycle, delineate IP and data rights, and maximize American-made AI products and services.

AUTHREX fitmentAUTHREX is US-built with a fully documented artifact chain of catalogued public technical works and 8 reported U.S. provisional patent applications (unexamined), and its runtime telemetry is designed to feed the contract-level performance monitoring M-25-22 requires.

ADARAERAM
NIST AI RMF 1.02023VOLUNTARY FRAMEWORK

AI Risk Management Framework

Govern, Map, Measure, Manage functions with seven trustworthiness characteristics: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair.

AUTHREX fitmentSATA's calibrated belief fusion is author-mapped to Measure; ERAM's context-dependent risk scoring to Map; FLAME and CARA to Manage at runtime; ADARA to accountable-and-transparent. AUTHREX proposes turning the RMF's context-dependent governance from guidance into executable gates.

SATAERAMFLAMEADARAMAIVA
[ Civil Transportation ]2 instruments
FAA Roadmap for AI Safety Assurance2024VERSION I

AI in aircraft and aviation systems

Establishes guiding principles for assuring AI safety in aviation: incremental introduction along the safety continuum, use of existing certification processes (DO-178C lineage) except where inadequate, differentiation of learned vs learning AI, and assurance-case methods built on overarching properties developed with NASA.

AUTHREX fitmentAUTHREX wraps learning components inside deterministic, certifiable authority gates, exactly the pattern the roadmap's incremental approach anticipates: the governance layer is designed as conventional DO-178C-assurable software even when the governed AI is not.

HMAACARASATA
NHTSA AV Framework + SGO 2021-012021-2026ACTIVE REPORTING

Automated vehicle oversight and crash reporting

The Standing General Order requires manufacturers to report ADS and Level 2 ADAS crashes; the 2025 AV Framework and third amended SGO streamline reporting while preserving the safety data pipeline. NHTSA enforcement (EA22002) established authority handover as a recall-grade defect category.

AUTHREX fitmentBLADE-AV is designed to provide graduated authority handover with driver-engagement verification, the precise failure surface of EA22002. A submitted comment by Burak Oktenli is listed in footnote 10 of NHTSA’s May 26, 2026 Federal Register notice, 91 FR 30789 (a public-record reference, not a technical evaluation, endorsement, or government validation of AUTHREX); the notice concerns AV framework rulemaking (91 FR 30789, footnote 10).

HMAAFLAMECARABLADE-AVINDEPENDENT CITATION · 91 FR 30789 FN.10
[ Maritime · Infrastructure · Space ]3 instruments
IMO MASS Code2026EFFECTIVE 1 JUL 2026

International Code of Safety for Maritime Autonomous Surface Ships

Adopted at MSC 111 (May 2026), effective July 1, 2026 as a non-mandatory instrument: goal-based safety framework for autonomous and remotely operated cargo ships. A human master remains responsible and must retain the ability to intervene and override system-initiated decisions; Remote Operations Centres require certification; risk assessment is part of approval.

AUTHREX fitmentThe Code's core demand, human override maintained across varying levels of independence, is HMAA's founding requirement. CARA provides the staged, evidence-logged fallback the Code's risk-assessment chapters look for, and the proposed ADARA evidence path is intended to record authority transitions routed through the registered governance interface between vessel autonomy and the ROC.

HMAACARAADARA
TSA SDs · NERC CIP · IEC 624432021-2026IN EFFECT

Critical infrastructure and OT security

Post-Colonial TSA Security Directives mandate IT/OT segmentation and response planning for pipelines; NERC CIP governs bulk electric system cyber assets; IEC 62443 and NIST SP 800-82r3 define industrial control system security engineering.

AUTHREX fitmentBLADE-INFRA-OT gates control-plane authority; the proposed gateway is intended to reduce the likelihood that a credential compromise directly produces physical actuation, subject to complete mediation, downstream-path integrity, protected keys, and correct implementation: MAIVA consensus is required for protection-relay class commands, FLAME imposes hold timers on irreversible OT actions, and CARA keeps a safe manual fallback that does not require full shutdown, the option Colonial never had.

MAIVAFLAMESATABLADE-INFRA-OT
SPD-52020IN EFFECT

Cybersecurity Principles for Space Systems

Space Policy Directive-5 requires space systems to protect against unauthorized command, jamming, and spoofing, and to preserve positive control of spacecraft.

AUTHREX fitmentBLADE-SPACE applies SATA source-authentication and MAIVA multi-node agreement to command uplinks, so positive control is enforced cryptographically and by consensus rather than assumed, with HMAA tiers governing on-orbit autonomous maneuvers.

SATAMAIVAHMAABLADE-SPACE
[ Allied & International ]3 instruments
CISA · NSA · Five Eyes joint guidance2026PUBLISHED 1 MAY 2026

Careful Adoption of Agentic AI Services

Joint cybersecurity guidance from CISA, NSA, ASD ACSC, CCCS, NCSC-NZ and NCSC-UK on deploying agentic AI services, naming five risk categories, among them tool misuse and credential exposure, and calling for bounded permissions, oversight and auditability of agent actions.

AUTHREX fitmentAUTHREX-AGENT is an execution-layer guardrail mapped to this guidance: every risky tool call is blocked, delayed or escalated before it executes, and the author’s crosswalk covers the five named risk categories, NIST AI RMF functions and NIST SP 800-53 control families. AUTHREX-QUARANTINE models the containment case, an agent that proposes an action outside its grant denied before execution and isolated behind witness ballots and five isolation planes. Engineering crosswalk only; not a FedRAMP, CMMC, FISMA or other certification claim.

SATAHMAAFLAME
NATO AI Strategy · PRUs2021 / rev. 2024ALLIANCE POLICY

Principles of Responsible Use

Six Principles of Responsible Use for AI in defence: Lawfulness, Responsibility and Accountability, Explainability and Traceability, Reliability, Governability, and Bias Mitigation; the revised 2024 strategy calls for an Alliance-wide AI Test, Evaluation, Verification and Validation landscape through DIANA test centres.

AUTHREX fitmentGovernability and Explainability-and-Traceability are AUTHREX's two native outputs: revocable authority (FLAME, CARA) and a decision ledger covering events routed through the registered governance path (ADARA). The published simulation and model-checking corpus is structured as preliminary technical evidence that may contribute to a future TEV&V program; it does not independently establish compliance, operational suitability, or government acceptance. It is author-mapped to the kind of evidence the 2024 strategy asks allies to produce.

FLAMECARAADARAHMAA
UN CCW GGE Guiding Principles2019CONSENSUS PRINCIPLES

Emerging technologies in the area of LAWS

Eleven consensus guiding principles affirmed by the Group of Governmental Experts: international humanitarian law applies fully to autonomous weapons, human responsibility for the use of force must be retained, and human-machine interaction must ensure compliance across the lifecycle.

AUTHREX fitmentAUTHREX's central claim, that authority is a governed, auditable, revocable grant rather than a property of the platform, is the systems-engineering form of the human-responsibility principle. HMAA makes the human-machine interaction requirement a measurable runtime state.

HMAAADARAERAM

Informational alignment mapping, current as of July 2026. References to directives, memoranda, frameworks, and codes describe design intent and traceability targets. They are not certification claims, government approvals, or endorsements, and inclusion of the NHTSA citation reflects the public Federal Register record.