LP-2 · v1 · status: published

LP-2 · Continuous Standard of Care — reference standard (RS-1)

A conformance specification for out-of-band verification of autonomous systems

RS-1 · v1 · 2026-09-10 · Author: Elias Moosman · elias@thetadriven.com

Publication candidate. Bounded by docs/legal/disclosures-and-limitations.md, which governs on any conflict. Not legal advice. Not a standard adopted by any standards body — it is a published specification anyone may implement, and its only authority is that it is public, dated, and checkable.

Working title of record: Continuous Standard of Care: non-parametric drift measurement for deterministic telemetry in autonomous systems.


1. Scope — the pair this document is sufficient for

A specification is not "accurate" or "inaccurate" in the abstract. It is sufficient for a question, or it is not, and sufficiency is a property of the pair (projection, question). This standard therefore declares both halves in its first section rather than its last.

1.1 Sufficient for: did a unit of autonomous work land inside a scope that was declared before it ran, and can a third party recompute that finding without the operator's cooperation?

1.2 NOT sufficient for: was the work correct, safe, or free from defect? No conforming implementation may claim it. The question is undecidable in the general case (Rice, 1953), and a conforming implementation is required to say so in its own output.

1.3 Why the second half is stated at all. An insufficient projection does not fail loudly. It fills the gap with the most likely completion — the population average — and reports a clean verdict. That failure mode is why this document declares its own limit as a conformance requirement rather than a disclaimer at the bottom.

2. Terms

2.1 Declared Operational Scope — the specification of authorised operations for an agent, recorded before deployment, immutable within a measurement period save by a timestamped amendment.

2.2 Unit of work — one bounded, countable increment of agent activity: a commit, a completed task, a discrete decision.

2.3 Placement — the coordinate a unit of work occupies on the lattice, computed deterministically from sealed inputs.

2.4 Drift — a placement outside the Declared Operational Scope. Drift is graded, not binary: a unit of work has a distance from its declared lane, not merely an in/out flag.

2.5 Corrective pass — an out-of-band re-examination fired when drift is observed. A corrective pass does not block, halt, or gate execution. It examines whether the drift is a defect in the work or a defect in the declared scope, which are both real and are not distinguishable by the sensor alone.

2.6 Attestation — a signed record of one placement, together with the inputs sufficient to recompute it.

2.7 Verification gap — an interval in which an agent operated and no reproducible attestation covers it. A gap is itself a countable event; a hole in a monotonic sequence is data.

3. The measurement

3.1 The lattice. Declared scope and observed work are each projected onto a fixed 144×144 lattice of categories. Positions are addresses, not descriptions: a definition resolves to a coordinate in a finite space rather than to further words, which is what makes placement halt instead of recursing.

3.2 The sensor is non-parametric. Drift is measured by gzip-based normalized compression distance (Cilibrasi & Vitányi, 2005) between the declared scope and the observed work. It is a distance, not a model. A conforming implementation MUST NOT use a language model to compute a placement or a verdict — a verdict that depends on a paraphrase is not reproducible, and we have the incident to prove it: on 2026-07-04 a model in the verdict path made one unchanged input render three different results across three runs.

3.3 Reality is read from the immutable record. Placement MUST be computed against the sealed, committed artifact, never against a mutable working copy. The checkpoint has to read a record the actor did not author, or it is the actor's own account of itself.

3.4 The walk. Placement proceeds by an ordered walk (row → column → row) through the lattice. Ordering is derived from the content, never assigned.

3.5 Cost reporting. Where an implementation reports the cost of a boundary crossing, it MUST report a median with its [min, max] spread over a stated number of runs, and MUST refuse to report a verdict — printing NOT ADMISSIBLE — when its control band fails. A lone point value is not a measurement.

3.6 The apparatus boundary. Direct performance-counter / MSR reads are apparatus scope: privileged, platform-gated, used to characterise the instrument. A conforming implementation MUST NOT present them as a shipped default capability.

4. Conformance requirements

A conforming implementation:

C-1 records a Declared Operational Scope before the work it will judge, and refuses to place work against a scope recorded after it.

C-2 computes placement as a deterministic function of sealed inputs, with no model in the verdict path (§3.2).

C-3 emits, for each unit of work, an attestation that a third party can recompute to the same coordinate and the same verdict from the recorded inputs alone.

C-4 refuses to emit a verdict rather than emitting a misleading empty one. Reporting no specification and reporting an empty specification are different claims, and an instrument that returns a clean pass on an empty input is worse than no instrument.

C-5 records a verification gap as an event, not as an absence.

C-6 states, in its own output, the pair from §1 — what the verdict is sufficient for and what it is not.

C-7 publishes its own miss rate against adversarially-reworded out-of-lane work, and updates it. An implementation that has never measured its own false-negative rate does not conform. (The reference implementation presently observes ≈30%.)

C-8 retains, or explicitly evicts, the record it acts on. A record that is neither retained nor evicted has been discarded, and a discarded record is not expensive to recover — it is unpurchasable, over every reconstruction procedure (data processing inequality, Cover & Thomas §2.8).

5. The legal argument this standard supports — and its exact limits

5.1 What the standard supplies. A record, made contemporaneously, of whether a system operated inside a scope its operator declared in advance. That is evidence. It is not a verdict.

5.2 The cost argument. In the Carroll Towing formulation (United States v. Carroll Towing Co., 159 F.2d 169 (2d Cir. 1947)), the burden of a precaution is weighed against the probability and gravity of the harm it would avert. Where continuous verification costs a fraction of a cent per unit of work, B is small. What follows from a small B on any particular record is for a court, not for this document.

5.3 The custom argument. The T.J. Hooper, 60 F.2d 737 (2d Cir. 1932), holds that industry custom is not itself a defence where an available precaution was not taken. It does not hold that any particular technology is required, and it did not decide the question in the abstract — it decided a record. Anyone citing it for more than "custom is not dispositive" is overreaching, including us.

5.4 What we do not assert. That a party not running such a system is negligent. That is a question of fact and law on a particular record, and asserting otherwise in a commercial context is both wrong and self-defeating: it converts a purchasing decision into a legal accusation, and in-house counsel correctly blocks tools sold that way.

5.5 The undecidability that is load-bearing, stated once. Whether the work was good is undecidable (Rice, 1953). What the system actually did cannot be reconstructed from its own account (the data processing inequality). The only remaining move is to read a record the actor did not write. The two results are independent — that independence is the whole point, because a critic must break both, not one.

6. Reference implementation

6.1 npx thetacog-mcp — MIT-licensed, runs locally, no data leaves the operator's infrastructure. Recompute a receipt: npx thetacog-mcp prove-rice --check (exit 0 = reproduced).

6.2 The measurement is free; the underwriting is paid. Implementing and running this standard is free and open source and stays so. Only the financialization/attestation layer — the part a carrier or a captive relies on to price and settle — is licensed. This is not a trial and not a capped free tier.

6.3 Patent: US Application 19/637,714, pending, not granted (see disclosures §4.4).

7. What an insurer does with this

The paired specimen wording is at docs/legal/endorsement-cy-2026-det-continuous-state-verification.md (endorsement form) and docs/legal/broker-warranty-clause-draft.md (warranty form). Thresholds, periods, triggers and the consequences of breach are the insurer's decisions in every case; we neither set them nor advise on them.

8. Version and errata policy

8.1 This document is versioned. A revision that changes a conformance requirement increments the major version and is listed below with what changed and why.

8.2 Errata are published, not silently corrected.

9. Errata and open items

E-1 — Attribution error, corrected. Working transcripts rendered "Rice's theorem" as "Riesz representation theorem." No claim in this standard uses the Riesz representation theorem.

E-2 — Attribution error, corrected. The B < PL formulation is Carroll Towing (1947), not The T.J. Hooper (1932). Both are cited above for what each actually holds.

E-3 — Open: the units of k_E. The reference implementation uses a per-boundary-crossing constant k_E = 0.003, from which a trust half-life of ln(2)/k_E = 231 crossings is derived. A gloss circulating in our own earlier material reads this as "0.3 bits per crossing." A dimensionless rate of 0.003 and a quantity of 0.3 bits are not the same number, and this standard does not rely on the bits reading pending resolution. Recorded here rather than quietly dropped.

E-4 — Open: false-negative characterisation. C-7's ≈30% figure is a single measurement on a single corpus. It needs a stated protocol and a distribution, not a point.

E-5 — Open: retention debt in the reference implementation. C-8 requires retain-or-evict. The reference implementation currently holds a receipt store outside the append-only log it promises, and at least one component overwrites rather than appends. This is our debt, it is stated here because C-8 applies to us first, and it is tracked in the repository.


Recompute this row: shasum -a 256 public/legal/continuous-standard-of-care.html | cut -c1-16 — compare to the register at /legal/index.json.