EVIDE Research Series
Governance is not event recording. Governance is transformation qualification.
The formal research foundations behind EVIDE. Two working papers, developed in sequence, that define first what accountability-relevant meaning must survive a boundary crossing, and then how a running system continuously verifies that it has.
Recursive Semantic Governance (RSG)
Preserving Accountability Across AI Boundary Transformations
Current AI governance architectures treat accountability as a collection of discrete, static artifacts - audit logs, explainability outputs, snapshot-based compliance states. This model fails at the boundary: the moment a decision crosses from one system, agent, or governance layer to another. RSG replaces static event accumulation with state transformation qualification, and formally defines what accountability-relevant meaning must survive a boundary crossing for responsibility to remain attributable.
- Semantic Custody - measurable preservation of governance-relevant meaning across boundaries
- Governance Vectors - structured accountability state: Decision, Authority, Intervention, Threshold, Continuity, Evidentiary
- Boundary-Trained Connectors - controlled semantic translation between governance layers
- Recursive Boundary Alignment - iterative stabilization cycles at every crossing
- Recursive Evidentiary Governance - externally anchored, independently verifiable governance chronology
- Formal notation: G\u207f(t), semantic divergence \u0394s, causal persistence C\u209a
- Four canonical architectural diagrams, incl. Recursive Drift Amplification
- Eight governance failure mode characterizations
- Full end-to-end walkthrough: AI-assisted insurance claim processing
- Positioning vs. MCP, LangChain/LangGraph, AutoGen, EU AI Act, NIST AI RMF, ISO/IEC 42001
Governance Loop Engineering (G-LOOP-E)
Continuous Verification of Accountability Survivability Across Recursive Boundary Crossings
RSG answers the question of what must survive a boundary crossing. It does not, by design, specify how a running system continuously confirms that survival holds between crossings, across many iterations, inside a live orchestration pipeline. G-LOOP-E is the operational layer built directly on RSG primitives that closes this gap - reframing the exit condition of an iterative system loop away from behavioral convergence and toward accountability verification.
- Governance Heartbeat - a recurring verification pulse, scheduled or event-triggered
- Governance Preservation Loop (GPL) - the formal verification cycle: CONTINUE, DEFER, HALT
- Reconstructability Test - can accountability still be independently reconstructed if the process stopped now
- Inspector Independence - executive isolation and semantic asymmetry against correlated failure
- Scheduled vs. triggered heartbeats, with deadband and refractory period against trigger cascades
- The DEFER Budget - bounding cumulative, undetected degradation across consecutive cycles
- Four verification depth levels (D0–D3), independent of heartbeat frequency
- Six loop-specific failure modes, incl. Convoy Drift and Silent Decoupling
- The Convoy Model - an illustrative figure for non-technical stakeholders
EVIDE Governance Lab: From Research Protocols to Real-World Defensibility
What Each Lab Project Means for Legal Defensibility
RSG and G-LOOP-E define the formal architecture: what accountability-relevant meaning must survive a boundary crossing, and how a running system verifies that survival continuously. This companion document translates six validated Lab projects, built on that architecture, into what each one means in practice -- the question it answers, a real-world scenario, and what changes for an organization that has to defend an AI-assisted decision months or years later.
The table below summarizes all six Lab projects side by side.
| Project | Core Question | Without | With | Key Terms |
|---|---|---|---|---|
| Evidentiary Deposit | Can we prove the event existed? | Event remembered | Independent proof the event occurred | FCC (+ Evidentiary Profile) |
| Observer Reconstructability * | Does the read change by observer? | Divergence unexplained | Divergence explained, not assumed | Declared Visibility |
| Authority Visibility Asymmetry * | Does a visibility claim alone move findings? | Narrative could sway findings | Only verified signals move findings | Declared Visibility |
| Authority Continuity | Was authority still valid? | Authority assumed | Continuous authorization evidence | AuthorityLock |
| Epistemic Stabilization Buffer | Was the decision stable enough? | Immediate crystallization | Proof the decision was stabilized first | ESB |
| Governance Preservation Loop | Did reconstructability survive over time? | One-time verification | Proof reconstructability was maintained | GPL / G-LOOP-E |
* Controlled calibration experiment, not yet a field-validated capability. See the corresponding section in the full paper for scope.
The Evidentiary Status of Internal Reasoning Signals
From "Who Says So?" to "How Do We Know?"
Anthropic's July 2026 interpretability research introduced the J-lens, a technique that reads causally active representations inside a model before they reach its output -- and showed, through direct intervention, that a model's good behaviour under evaluation can depend in part on its private recognition that it is being tested. This paper takes that finding as a starting point and asks a broader question: as AI systems begin exposing signals about their own reasoning, what evidentiary status should each of those signals receive? It proposes that a system's self-report, an external party's attestation, and a causally validated internal reading are not three points on one scale of trust, but three distinct categories that a responsible governance architecture should never collapse into a single notion of "proof."
Three categories, not one scale of increasing strength -- each grounded differently.
| Level | Grounded by | Example |
|---|---|---|
| Declared | The system's own assertion | reasoning_state: policy_check = true |
| Established | A separate accountable party, under a named protocol | AuthorityLock · RFC 3161 |
| Measured | A causally validated reading of internal state | J-lens (Anthropic, 2026) |
This three-level framework is an original proposal developed within the EVIDE Governance Lab. Anthropic's research supplies the empirical grounding for the Measured category and the motivating problem; it does not propose this taxonomy.
EVIDE ANCHOR
Declaring the Operational Perimeter Before an Agent Acts
Motivated by a real incident in which an AI agent mistook a production database for a disposable test environment: the boundary between production and development was never technically enforced nor independently declared - it existed only as an implicit expectation. EVIDE ANCHOR introduces Declaration, an architectural primitive of EVIDE: an explicit, attributable, time-locatable statement of the operational perimeter an agent was authorized within, before it acted - preserved without verifying its truthfulness.
- Six declaration_type categories: environment, privileges, purpose, tools, prohibited operations, agent configuration - free text, not a closed enum
- The Atomic Declaration Rule: one Declaration, one attributable statement - independent facts are never merged into a composite declaration
- declaration_digest, computed server-side over the canonical form (RFC 8785), returned in the response - never supplied by the client
- declared_relations: a later Declaration can state that it supersedes, clarifies, or revokes an earlier one, without ever rewriting it
- Validated through five end-to-end scenarios executed via a real MCP client, including a combination of Declarations, Evidence References, and the Epistemic Stabilization Buffer in the same record
- Does not verify whether a declaration corresponds to operational reality, nor compare declared against observed
- Does not enforce or apply any declared policy, limit, or privilege
- Does not attribute responsibility or establish fault
- Does not assume that the absence of a declaration equals the absence of the corresponding constraint
- Never infers, completes, or interprets declarations that do not exist
Ongoing Research
Both papers are living working papers, developed inside the EVIDE Governance Lab and updated as the framework matures. Future research directions - including a Governance Recovery track beyond CONTINUE / DEFER / HALT - are documented in each paper's closing section.
The boundary is where governance succeeds or fails. The loop is what keeps asking, between boundaries, whether it still can.
This series continues as the EVIDE Governance Lab's research develops.