Capstone: the sovereign runtime is a fold of refused collapses terminating in stipulation by fiat
Ran Tao (Octoryn Research)
摘要
Capstone over a five-paper arc. A sovereign execution runtime is reframed as a series of refused collapses that a naive Believe-then-Act agent flattens: token vs world, reasoning vs capability, experience vs authority, knowledge vs reality, and authority vs liability vs solvency. Structurally it is a FOLD: authority delegates down, liability re-converges up via respondeat superior, audit is the spine. Every undecidable boundary is closed by an explicit STIPULATION BY FIAT, not by proof. "Sovereign" means both compute sovereignty and liability sovereignty. A paper synthesis, no implementation.
本 Research Object 以其原始语言(英文)发表。
What this synthesis argues
This is a capstone over a five-paper arc that began as a convergence question for an agentic product loop and bottomed out at the architecture of a sovereign execution runtime. It names the single structure shared by all five papers. It is a paper synthesis: no implementation, no measured runtime, no code.
The runtime as a series of refused collapses — a FOLD, not a line
A naive agent collapses one chain: Believe -> Act (it knows, therefore it acts; it acted, therefore it is right; it is right, therefore no one is liable). Each layer of the proposed architecture refuses one such collapse:
- A world-model layer refuses token != world (it carries a trust state, not the raw symbol).
- A skill-activation layer refuses reasoning != capability (capabilities are activated, not re-derived at use time).
- A product-loop / authority layer refuses experience != authority (knowledge does not by itself grant the right to act).
- A finality layer refuses knowledge != reality (one cannot prove the world safe; commit-finality is undecidable, by analogy to Two-Generals / FLP / Rice).
- A liability layer refuses authority != responsibility != liability != solvency, and adds the missing bridges liability != solvency (judgment-proof parties) and responsibility != control (the moral crumple zone).
The decisive structural correction is that these arrows are not co-directional. Authority flows down a delegation chain; liability flows up via respondeat superior; audit is the spine along which the fold can be reconstructed. The runtime is therefore a fold (authority out, liability in), not a linear sequence of bridges. The naive agent flattens the fold; the proposed runtime keeps it open and audited.
The single base case: each layer terminates in a STIPULATION BY FIAT
Each undecidable boundary is closed not by proof but by an explicit stipulation:
- The world-model layer stipulates a world-state as ground truth.
- The commitment layer stipulates a step as final (finality is undecidable, so it is decided).
- The liability layer stipulates a party as the solvent backstop of last resort (liability re-convergence is unprovable, so it is decided by fiat).
So the architecture is one machine: at every undecidable boundary, make the necessary fiat explicit — scoped, solvency-verified, and audited — rather than pretending to decide the undecidable. It does not decide truth, finality, or fault; it makes the stipulation legible and accountable.
The double meaning of "sovereign"
"Sovereign" here carries two meanings that coincide: compute sovereignty (running on owned hardware without a third-party inference dependency) and liability sovereignty (the entity holding the final, solvent, audited fiat — the stipulator of last resort). The fold terminates at the sovereign: the runtime bottoms out at a sovereign stipulator, and its role is to make that stipulator's fiats explicit and auditable.
Proposed identity
The honest identity is a Solvent-Backstop-Aware Auditable Execution Runtime that is fail-closed: no commit without a pre-established solvent liable backstop plus a machine-checkable scope that survives respondeat superior; reserves indexed to irreversibility; a typed responsibility-gap policy (bounded -> sign / unbounded -> refuse / tragic -> sign for process, not outcome); and an audit-to-liability firewall that feeds an external adjudication layer rather than adjudicating internally.
Where deployability, not accuracy, is the binding constraint
A claim of the synthesis is that in liability-bearing domains the binding question is not accuracy but who bears the cost when an action is wrong. Being-wrong tends to be cheap and easily commoditized; establishing the solvent, audited party who answers for a wrong action is the hard, accountable part. A runtime that cannot make "who answers when wrong" explicit is not deployable in such domains regardless of accuracy.
Irreducible residuals (no engineering removes these)
Forward-undecidability, stale certainty, non-monotone confidence windows, and finality-is-not-a-fixed-point; judgment-proof solvency; the audit-to-liability gap (causation is a counterfactual never present in the log, and richer provenance can worsen allocation by manufacturing crumple-zone evidence); and ultra-vires / scope-severance (an out-of-scope act can sever vicarious liability and drop into the responsibility gap with no liable party, and "scope" is partly a post-hoc judicial construct). The architecture narrows but cannot remove these; it makes them explicit, scoped, solvent, and audited — which is the entire point.
声明边界
作者对范围的明确界定——本工作证明了什么、未证明什么——沿用自 Octoryn Research 的发表模型。
证明
- The five-paper arc reduces to one structure: a sovereign runtime is a FOLD of refused collapses where authority delegates down, liability re-converges up via respondeat superior, and audit is the spine.
- Every undecidable boundary (world ground-truth, commit-finality, liability) is closed by an explicit stipulation by fiat, not by proof; the runtime's role is to make that fiat scoped, solvency-verified, and audited.
- 'Sovereign' carries two coincident meanings — compute sovereignty and liability sovereignty (the stipulator of last resort) — and the fold terminates at the sovereign.
- The honest identity is a Solvent-Backstop-Aware Auditable Execution Runtime in which deployability under who-answers-when-wrong, not accuracy alone, is the binding constraint.
未证明
- Any of this as implemented or validated — it is a paper synthesis with no code and no runtime.
- That the irreducible residuals (forward-undecidability, judgment-proof solvency, audit-to-liability gap, ultra-vires scope-severance) are removed; they are narrowed and made explicit, never eliminated.
- A closed-form bound on convergence or safety — both are stipulated by fiat and are domain- and solvency-dependent.
适用于
- Designing or evaluating an execution runtime that takes irreversible actions in liability-bearing domains and must remain deployable under who-answers-when-wrong, not merely accurate.
不适用于
- Purely reversible, no-liability software actions where the fold flattens safely; or as a substitute for an external legal adjudication layer.
作者
- Ran Tao — 调查研究, 写作
引用本文
引用格式
Tao, R., Octoryn Research. (2026). Capstone: the sovereign runtime is a fold of refused collapses terminating in stipulation by fiat (AP-2026-0010). Octopus Research Institute.
BibTeX
@techreport{oriap20260010,
title = {Capstone: the sovereign runtime is a fold of refused collapses terminating in stipulation by fiat},
author = {Tao, Ran and {Octoryn Research}},
institution = {Octopus Research Institute},
year = {2026},
note = {Permanent ID AP-2026-0010. Not peer reviewed.}
}披露
- 资助
- 硬件与基础设施由 Octoryn / Octopus Core Pty Ltd 提供。
- 利益冲突
- Octoryn 提供商业推理与治理工具;相关发现独立报告。
