Adam B. Straughn · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.23092344
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Autonomous and AI-mediated systems increasingly treat the output of a model, heuristic, or human operator as sufficient grounds to change the world. When the relevant world is a generator operating envelope, final settlement, dose bound, production database, or physical actuator, that substitution can be irreversible. This paper develops a conceptual model that separates three roles commonly conflated: *computation* (candidate generation), *authority* (bounded permission on a designated object), and *consequence* (mutation of authoritative state or actuation). The Verifiable Safety Kernel (VSK) is a neurosymbolic assurance thesis: neural, heuristic, external, or human components may propose; a trusted kernel is required to combine discrete plan checking, optional continuous constraint filtering, and chained audit receipts. CEAK-PRO refines that thesis at a single consequential-transition boundary. The scope that an authority licenses is matched to a predicted-effect manifest computed in isolation under a fixed policy. Commit additionally requires a durable decision record before effect, a recoverable capability lifecycle, and a typed terminal disposition for each boundary-reaching attempt. A three-plane reference-architecture profile illustrates how an untrusted proposal plane, deterministic admission plane, and minimal execution plane separate these concerns without turning a secure channel, attestation artifact, simulation result, or signed receipt into authority. The contribution is the separation and joint necessity of five assurance sorts at one consequential boundary: evidence/proposal separation, affine authority, dual identity, state-and-sequence continuity, and constraint satisfaction. Cross-cutting manifest canonicality and assent binding, journal-before-effect ordering, and terminal audit of boundary-reaching attempts complete the lifecycle obligation. The paper does not claim to invent control barrier functions, capabilities, runtime assurance, cryptographic logs, secure transport, or pre-action gates. The paper is conceptual. Its claims rest on definition, argument, and related-work synthesis; it reports no model-checking, proof, implementation, or physical-validation results. Bounded state-machine models and a reference implementation of selected admission logic are being developed separately for a companion implementation paper, where any verification result will be accompanied by reachability evidence demonstrating non-vacuous exercised paths. Conceptual argument; no discharged formal-verification, model-checking, or implementation results.
No comments yet — start the discussion below.