Priyanca Ford, G L Kulcinski · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.22645794
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
A controller or a learned advisor on a nuclear-regulated machine should be trusted with exactly as much authority as the evidence behind its models can justify — no more, and no less than the evidence has earned. On a compact, high-power-density spherical tokamak the reaction times are short and every actuation carries a safety consequence, so the question ``how much authority should the automation have?'' cannot be answered by fiat. We give it a quantitative, auditable answer. We define maturity-gated actuation authority: a control-governance law that binds the verification-and-validation credibility of each subsystem's models — scored on a Predictive Capability Maturity Model (PCMM) — to the actuation authority (magnitude, rate, and irreversibility) the controller is permitted at runtime. A static credibility functional aggregates the six PCMM axes of a subsystem into a maturity index m_s[0,1]; a runtime trust T(x)[0,1] combines two independent online signals — a calibrated conformal validated-envelope membership M(x), which measures how far the live state has drifted out of the region where the models were validated, and a model–plant divergence monitor g(D), which watches for silent model failure inside the envelope by tracking a cumulative-sum residual between the predictive twin and the plant. Their product =m_s T(x) gates a monotone authority envelope (), and the applied command is the projection of a maturity-weighted blend of the nominal controller and a deterministic safe floor onto that envelope. We prove that the gated law preserves forward invariance of the certified safe set (so an immature or diverging model can never drive the machine), that authority is monotone non-decreasing in evidence, and that the map recovers the raw nominal controller in the fully-validated limit. We cast the whole law as a Goal-Structuring-Notation assurance case whose model-validation goal is discharged by the effective maturity, anchor it to a measured-boot integrity root-of-trust so authority is granted only on an attested control node, strengthen its per-step barrier invariance to a whole-set reachability certificate (Reach(X_0)X_ unsafe=, verified offline by Hamilton–Jacobi reachability composed with neural-network output bounds), and bind every authority decision to a cryptographically signed, hash-chained provenance ledger. The governance policy realises a four-tier capability-activation ladder — 3Dshadowtwinautonomy — under a single acceptance rule (register gate KX-L1-A7, requirement NFR-012): no capability activates below its validated maturity. We instantiate the law on the Hyperion breeder design point (Q=3.076, P_ fus=85.04, I_p=9.66, δ=-0.30, B_0=8, centrepost 16.84) against frozen register results: a control-barrier clamp intercepts 3,000/3,000 unsafe candidate commands, holds β_N3.5 with 0/150,000 adversarial violations and h=+0.000; a calibrated uncertainty layer matches nominal coverage to within ±3%; an equilibrium surrogate clears its validation bar at 0.139% RMS flux error (2877× faster than the reference); a 40,000-sample anchor-confidence ensemble places the frozen Q=3.076 conservatively below the ensemble mean 3.43; and the one honest open gate — an in-winding quantum magnetometer whose neutron tolerance is ~39× short of requirement — keeps its subsystem correctly clamped to advisory authority. The contribution is an architecture, not a controller: it constrains authority, it does not by itself close any loop, and it gives a byproduct-material or reactor licensing review a transparent rule in which autonomy is a function of demonstrated evidence. Key results (frozen anchors): D_0 = 0 eq; H_98 = 1.007 ±0.030. Methods & codes: FreeGSNKE, FreeGS, CGYRO, TGLF, OpenMC, DAGMC, Sauter. Live verification: 6 gate validator(s) with live-recompute cards (6 reproduced). See the Verification section and data/verification.csv. Related: Paper page · De-risking register · 3D model · Learn more about Kronos Part of the 2026 Kronos publication series; independently re-run and stamped in the Kronos de-risking register (DOI 10.5281/zenodo.22645689). All numerical values are frozen design-point anchors; see the register. Public research artifact. No proprietary, financial, or supply-chain information is included. Note (REPLACE): This record supersedes a prior published version. The exact superseded DOI is pending founder confirmation (see SUPERSESSION_REVIEW.csv); an isNewVersionOf relation will be added before upload. Not yet asserted.
No comments yet — start the discussion below.