George Melville, Dena Ghiassi, Scott Inthathirath, Julian Yeomans · AI 2026 · 2026
DOI: 10.3390/ai7090366
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
AI and machine learning deployments in regulated decision contexts face an intolerance for inadmissible outputs (“hallucinations” when the model is generative) that current explainability methods address only after the fact. Bounded AI denotes prevention by architectural design. This study establishes five conditions (C1–C5) under which a bounded artificial intelligence (AI) architecture transfers from one regulated decision domain to another. Conditions C1 through C4 adapt or combine previously established principles. The most significant contribution is the discrete joint-state topology condition, C5, for which no precedent was found in this role. The claim is that these five conditions are jointly necessary for the closure property to survive an architectural transfer—while sufficiency is not claimed. Two of the five conditions are structural prerequisites governing whether the architecture’s operators can be constructed in a destination at all. The remaining three provide warrant conditions governing whether it is the appropriate instrument or not. In existing runtime-assurance architectures, the constraint acts after inference, on the output of the learned component. In contrast, the pattern developed in this paper reverses the assurance steps via a deterministic-first/learned-second approach. Namely, the assurance architecture acts before inference on the input domain: a deterministic filter admits only rule-compliant objects, and the trigger fires non-discretionarily on joint-state cell occupancy rather than on the learned score. The architecture’s domain-neutral type signatures are formalized, and three structural transfers are developed in depth: predictive maintenance, energy-grid management, and credit underwriting, each concluding with a closure proof. All three transfers remain conceptual and report no deployment outcomes. The proofs are conditional on three stated premises that establish soundness with respect to a rule set rather than a safety case. The strongest evidence of transferability is a market-surveillance destination classified as admissible in advance and later realized on a live venue. C5 is what discriminates the transferability. It is shown that the autonomous-vehicle perception case satisfies C1 through C4, but fails C5 because the required distinctions are absent from the representation at every granularity—which is a failure that no additional compute can resolve. The architecture becomes domain-neutral through the act of transfer, not before it.
No comments yet — start the discussion below.