RESEARCH AND EVIDENCE

The published record.

The third-party work that establishes the requirement we build for, and our own research.

The Evidence

We did not invent this requirement. We built the thing it asks for.

The founding study of the reference monitor concept concluded that software interpretation suffices only for restricted systems, and that general-purpose secure systems require hardware interpreters.

A joint study tested twelve published defences against jailbreaks and prompt injection. Most were bypassed with attack success rates above ninety per cent. The majority had originally reported near-zero attack success.

A peer-reviewed proof extends Gödel's incompleteness theorems to AI, establishing that no finite set of guardrails can be universally robust against adversarial prompts.

Google's security engineering organisation published that authorisation must move from the application to the individual action, and that beneath any AI reasoning layer there must be a floor of static policy that can be verified.

Agents escaped a purpose-built isolation environment, reached a third party's production systems, and tampered with their own transcripts to conceal it. OpenAI's post-mortem concludes safeguards must operate at the speed of the AI agents themselves.

Sources are linked. None of them endorses Evrmind.

Only one of these sources calls for hardware. The rest identify the gap. We occupy it.

Over fifty years. The requirement is unchanged.

Our Research

Four papers.

Foundational.

The work that defines the limits and requirements the architecture is built to satisfy.

Substrate-Invariant Safety Enforcement
Substrate-Invariant Safety Enforcement

A category-theoretic framework defining the properties any physical enforcement layer must satisfy to guarantee safety constraints, and how those properties hold across electronic, photonic and quantum substrates. The architecture is built on this work.

DOI 10.5281/zenodo.19228863

Steering a Frozen Model: Two Hard Limits
Steering a Frozen Model: Two Hard Limits

A frozen model can be steered at runtime towards a safety rule, but only so far. This work identifies two hard limits: a ceiling set by what the model's own read state already implies, and a horizon on how far a bounded correction can reach, measured on activations from real 7B and 32B models. The systems implication is that enforcement should not depend entirely on the mutable system it is meant to govern.

Zenodo record 22088390

The working record.

Published on Zenodo, openly accessible. Early explorations, kept public as the record of how the work developed.

Topological Regularisation
Topological Regularisation

Our early geometric approach to safety constraints, treating formal rules as geometric barriers on a continuous manifold, so they can shape learning without the information loss of discretisation.

Zenodo record 22033197

Thermodynamic Inductive Synthesis
Thermodynamic Inductive Synthesis

An exploratory physics-constrained synthesis framework treating energy cost as a first-order constraint rather than an externality. Revised following external peer review.

Zenodo record 22030236

Questions about the architecture?

Book a Meeting