Complete frozen paper: SHA-256 9d2721397c88f09c2be6c60c98bca07121cee4be616173a99c5c0e2c5256cc3b

1,903 source lines · evidence cutoff July 28, 2026

Govern What Can Still Be Governed

An evidence-triggered position on advanced model releases when weights can be copied

RVA Cyber Research — published review edition
Evidence cutoff: July 28, 2026, America/New_York
Drafted: July 29, 2026
Decision status: Published review edition. The frozen source candidate passed its Phase 12 independent recheck and parent verification.
Release status: Published July 30, 2026 by explicit instruction for review at news.rvacyber.com. Evidence remains frozen at July 28, 2026; this is not legal or operational advice

This paper uses a frozen local evidence record. Every volatile legal, institutional, repository, and model statement is historical as of the cutoff. It is not a current-law memorandum, a safety certification, or proof that the proposed controls work.

In 90 seconds

The decision. Do not govern every model called “open” as one object. Govern an exact model or tested access condition, defined audience, specified artifacts, permissions, and safeguards.

The risk delta. Weight availability changes persistence and control. A person can copy and run released weights outside the originating provider’s service. Provider-side monitoring, mandatory updating, account removal, and withdrawal are then no longer universal. Weight availability does not prove capability, intent, human uplift, a completed misuse pathway, or catastrophe. (interpretation; P4-CAN-04; exclusions; P4-EXC-01–04)

The position. Use an object- and release-profile-specific, evidence-triggered process. Preserve a presumptive path for low-risk research, local use, accessibility, defensive security, and independent evaluation. Increase burdens only when reproducible evidence shows material assistance across a policy-level severe-misuse pathway, release would remove relevant provider controls, a named actor can still change the exposure, and no comparably effective less-restrictive option exists. (policy proposal; ARC-01, ARC-02, ARC-08, ARC-13)

Act now. Pin tested-object identity. Fund independent evaluation. Publish methods, uncertainty, nulls, and corrections. Protect incident and researcher reporting. Document provider-dependent safeguards. Build legal-review, preparedness, accessibility, and global capacity. Baseline burden, access, concentration, participation, appeal, and control reach before claiming success. (policy proposal; ARC-07)

Know the limit. A time-limited managed-access pause can affect a pending release. It cannot recall every propagated copy. Licenses, notices, patches, lawful action against reachable actors, preparedness, and response can matter; none is universal technical recall. (P4-EXC-06, P4-EXC-07, P4-EXC-12; ARC-11)

The human consequence. A weak process can expose people to preventable harm. An overbroad process can turn uncertainty into closure, surveillance, incumbent privilege, and exclusion. No person or community is expendable to either failure. (moral commitment; P5-MC-01)

The governing question is not whether a model carries a reassuring or alarming label. It is whether named actors can still reduce a supported exposure, under reviewable authority, without making other people pay an unmeasured and unappealable price.

Abstract

This paper advances a bounded policy proposal for releases of advanced models whose weights may be copied and run beyond the originator’s continuing control. The proposal rejects a binary contest between “open” and “closed.” It defines the governed object through exact model identity, tested configuration, release profile, audience, permissions, and safeguard reach. MAPS—Model Access, Permissions, and Safeguards—is a release-profile framework only. It is not a model class, capability tier, or safety score.

The evidence supports a real but narrow risk delta. Public weight release can remove provider-dependent controls from at least some copies. Selected July 2026 cyber evaluations also show that named non-U.S. systems performed strongly on bounded tests. Biological evidence is more heterogeneous: one multi-model access study reported substantial novice improvement on tested digital tasks; a preregistered physical-world multi-model trial found no significant improvement on its primary endpoint; and a Kimi K2.5 paper reported model-specific benchmark performance without estimating causal human uplift or pinning the tested configuration to the separately captured downloadable revision. None of those records establishes a catastrophic outcome, a real-world intrusion rate, a universal threshold, or the marginal effect of an identified downloadable checkpoint. (evaluation results; P4-CAN-02, P4-CAN-03, P4-T3-02–04; interpretation; P4-T3-01)

The proposed architecture therefore acts most strongly where control still exists. It uses exact-object provenance, independent evaluation, staged release profiles, control-based actor duties, distinct legal and voluntary enforcement routes, appeal, protected uses, international interfaces, a narrow domestic fallback, dated and event-driven review, honest post-copy containment limits, and public metrics that can weaken or defeat each component. No mechanism is represented as existing law unless a dated jurisdiction-specific record supports that legal claim. No mechanism is represented as proven to reduce severe risk.

Seven attacks materially narrow the position. Technical review rejects benchmark calibration and recall theater. Civil-liberties review requires authority, notice, privacy minimization, appeal, and a presumption for protected low-risk uses. National-security review adds a precautionary but time-limited escalation route. Scientific review requires independent access, explicit estimands, nulls, and corrections. Economic review requires burden and concentration accounting. Enforcement review requires observable conduct, legal status, remedy, and measured coverage. Global-equity review requires representative participation and material capacity, not formal weight access alone. The dissent that survives those revisions is retained because the evidence does not settle calibration, comparative effectiveness, constitutional doctrine, intermediary duties, cross-border reach, or distributional outcomes.

The proposal fails if object identity cannot be administered; prospective measures do not change relevant exposure; a less-restrictive option performs as well; duties lack authority or actor control; independent challenge is blocked; protected uses become inaccessible; burdens concentrate power without demonstrated security value; or repeated reviewed evidence shows no relevant benefit. Until those tests can be run, this is an inspectable internal position—not a finished public answer.

1. Define the object before governing it

“Open model” is not one technical state and not one legal conclusion. A release can make some source code visible without making weights available; make weights downloadable under restrictive terms; provide a hosted interface without weights; gate access to a defined group; or combine those states. The policy object is therefore a release record, not a label.

This paper uses the following terms:

  • Source-artifact availability records which training, inference, evaluation, configuration, or other source artifacts a named audience can obtain. It does not imply that weights, data, or permissions are also available.
  • Weight availability records whether a named audience can obtain parameters sufficient for the represented release. It does not imply an open-source license, a complete repository, a tested capability, or a safe outcome.
  • Hosted service means access through infrastructure whose provider may retain account, monitoring, rate, update, and withdrawal controls. A provider alias or family name does not identify an immutable served configuration.
  • Managed access means access is limited prospectively by audience, environment, terms, or safeguards. It is not a claim that the object is safe or that later copies can be recalled.
  • Repository revision or downloadable checkpoint means the particular preserved revision identified by a commit or equivalent content record. Repository metadata does not establish that an evaluator tested that revision.
  • Exact tested object means the model weights or served snapshot, configuration, tools, scaffold, safeguards, and evaluation conditions necessary to bound an empirical result. A model-family name alone is not an exact tested object.
  • Release profile means the combination of artifacts, audience, permissions, safeguards, version, and control persistence at a stated time.
  • Copied weights means weight files have left the originator’s exclusive control and may exist in reachable or unreachable downstream copies. The phrase does not claim that every copy persists forever.
  • MAPS—Model Access, Permissions, and Safeguards records: what is available and to whom; what use, modification, and redistribution terms say; and which safeguards remain technically or institutionally available. MAPS is a release-profile framework only—never a model class, capability tier, or safety score.

Three identity separations govern every example:

  1. A hosted service is not a downloadable checkpoint.
  2. A provider alias or model-family name is not an immutable revision.
  3. A repository revision is not an evaluation result unless provenance connects the tested configuration to that revision.

The consequence is practical. A regulator, developer, evaluator, funder, repository, or downstream distributor cannot be assigned a coherent duty until the action, object, audience, actor control, and claimed evidence are specified. “Restrict open models” fails before the policy debate begins because it does not identify any of them.

Statement classes

Labels in this paper are constraints on meaning, not badges of certainty:

  • Observed fact: a dated source state, event, status, or metadata response.
  • Evaluation result: a bounded test, study result, or institutional assessment.
  • Legal rule: operative or authoritative text, limited by jurisdiction, actor, timing, and application.
  • Guidance: voluntary, interpretive, standards-based, or administrative implementation material.
  • Interpretation: RVA Cyber’s synthesis of underlying records.
  • Forecast/scenario: a conditional future proposition, never present fact.
  • Policy proposal: a candidate institutional design, not existing law and not a measured outcome.
  • Moral commitment: a value that governs acceptable tradeoffs, not empirical proof.

An institutional essay or model card can establish what its author says. It does not independently prove the author’s empirical premise. A statute can establish a legal rule within its scope. It does not prove implementation or effectiveness. A benchmark can establish performance under its method. It does not become a human treatment effect, harm probability, or catastrophe by rhetorical force.

2. The bounded thesis

Policy proposal. Govern advanced model releases through a proportionate, object- and release-profile-specific, evidence-triggered process that acts most strongly where a named actor still controls access; preserves low-risk openness and protected participation; uses layered, reviewable duties; and states plainly that copied weights cannot be universally recalled.

That proposal rests on four narrower judgments:

  1. Interpretation. Weight release can remove provider-dependent controls from some copies, but it does not erase the other barriers and defenses in a severe misuse pathway. (P4-CAN-04; P4-EXC-03)
  2. Interpretation. Capability evidence is object-, method-, and estimand-specific. Benchmarks, pooled multi-model access effects, single-model causal human uplift, and observed outcomes answer different questions. (P4-CAN-02, P4-CAN-03, P4-T3-01–04)
  3. Interpretation. Governance is layered. Law, evaluation, hosted safeguards, research oversight, financial controls, preparedness, detection, and response have different reach, and the corpus proves no single layer sufficient. (P4-CAN-11)
  4. Moral commitment. Neither catastrophic-risk uncertainty nor the benefits of openness licenses making affected people invisible. Measures must remain proportionate, contestable, and attentive to who bears cost and who retains access. (P4-CAN-10; P5-MC-01–04)

The thesis does not assert a universal numerical threshold, proven control effectiveness, a categorical legal power over model publication, or an aggregate net benefit or harm from weight release. Those absences are not evasions. They determine what a defensible process must measure and what it may not claim.

3. The evidence spine—and the space it does not fill

3.1 Amodei’s argument is a position and forecast, not a historical result

Observed fact—attributed author statement. As of the July 28 cutoff, the latest directly relevant primary text identified by the frozen record is Dario Amodei’s July 27, 2026 Anthropic post, “Our position on open-weights models,” identified on its page as a post by Dario Amodei, Anthropic CEO. It says Anthropic has not advocated a categorical ban and favors capability-based testing for sufficiently capable systems regardless of whether their weights are available. In the biological misuse discussion, Amodei describes what he believes currently limits danger as “a negative correlation between intellectual capability and desire to commit catastrophic harm.” His January antecedent essay uses the more qualified formulation that ability and motive “may even be negatively correlated.” (author-position record; P6-AUX-01)

Interpretation. The precise attribution is that Amodei argues destructive motivation and the intellectual capability needed for catastrophic harm may be negatively related, and he worries that sufficiently capable AI assistance could weaken that barrier. The texts do not establish that history has measured a negative correlation between destructive intent and all destructive resources. They provide no dataset, sample, correlation coefficient, or causal design for that premise. They also keep intellectual capability separate from material access and defensive capacity. The cited antecedent evidence about education and terrorism complicates, rather than validates, a general negative-correlation proposition.

Forecast/scenario. If AI supplies enough missing intellectual capability to a motivated actor, a barrier between intent and execution could weaken. Neither the timing nor the magnitude is established. This paper treats that scenario as a reason to measure the full chain, not as evidence that intent, resources, capability, and outcome already coincide.

3.2 “Kimi” names several evidence objects, not one result

Observed fact. The preserved direct JSON response to the exact Kimi K3 full-commit request reported commit 9f62e4e9fffbd0a83ddd60e1c209d828994b3569, private=false, gated=false, and recorded safetensors totals. The commit pin stabilizes the requested revision identity and captured core fields; the endpoint response as a whole remained mutable. It does not establish complete files, architecture-level parameter count, capability, evaluator identity, license enforceability, or identity with a hosted evaluation. (P4-CAN-01)

Evaluation result. A joint July 23 preliminary UK AISI/U.S. CAISI evaluation reported that Moonshot AI’s hosted Kimi K3 setup scored below the leading tested U.S. closed systems and above GLM-5.2 on selected cyber tests. Kimi used one aggregate benchmark with wider uncertainty; comparator safeguards were disabled; and the simulated range omitted important real-world defenses. The tested hosted object was not pinned to the repository revision. (P4-CAN-03)

Evaluation result. Yong et al. separately reported model-specific biological benchmark evidence for Kimi K2.5, while Moonshot separately made weights available. The paper did not estimate causal human uplift or prove that repository revision 4d01dfe0332d63057c186e0b262165819efb6611 produced the biological results. The provider route or immutable checkpoint for the biology runs was not identified; full run logs were unavailable; and the repository state was captured after the test period. (P4-T3-04)

Those records cannot be merged. Kimi K3 is not Kimi K2.5. A hosted Kimi K3 setup is not the pinned Kimi K3 repository. A model-specific Kimi K2.5 benchmark is not a single-model causal human-uplift estimate. A downloadable revision is an access and identity fact until an evaluation pins it. (P4-EXC-02; P4-EXC-04)

3.3 Cyber evaluations establish selected performance, not real-world intrusion

Evaluation result. On AISI’s selected July 2026 cyber tests, GLM-5.2 and DeepSeek V4-Pro performed comparably to selected closed models released roughly four to seven months earlier. The comparison is selective and non-predictive. Its simulated ranges omit important defenses; it does not estimate real-world intrusion success, forecast parity, or transfer to biological capability. (P4-CAN-02)

The hosted Kimi K3 result adds object-specific evidence but does not erase those limits. Neither result is a completed intrusion, harm probability, or universal capability gap. Cyber material in this paper therefore stops at evaluation, provider-control, detection, defensive capacity, response, and governance. It does not supply instructions for intrusion, persistence, fraud, monetization, or evasion. (P4-EXC-01)

3.4 Biological results answer three different questions

The frozen corpus contains policy-relevant evidence without a single combined answer:

  • Evaluation result—pooled hosted access. Zhang et al. estimated that access to multiple models improved novice accuracy on tested digital tasks by 4.16-fold overall (95% CI 2.63–6.87). Participants could use and cross-check multiple services. The result does not identify one model’s marginal effect, a downloadable checkpoint’s effect, physical execution, or catastrophe. (P4-T3-02)
  • Evaluation result—physical-world pooled access. In Hong et al.’s preregistered trial, the primary endpoint showed no significant improvement for the tested mid-2025 multi-model access condition: 5.2% versus 6.6%, P=.759. The post-hoc pooled estimate was uncertain and not model-specific. This is a null primary result for that access condition, not proof that models cannot increase capability. (P4-T3-03)
  • Evaluation result—model-specific benchmark. Yong et al. provides current-at- cutoff benchmark evidence for Kimi K2.5, not a human treatment effect and not a pinned-release effect. (P4-T3-04)

Interpretation and bounded no-result. Within the declared Phase-3 corpus and official endpoints through the cutoff, no evaluation met all six qualification conditions for a current, independent, model-specific causal human biological-uplift result with sufficient public methods and an exact tested object. That finding is endpoint- and method-bounded. It is not universal nonexistence, not a conclusion about whether the missing result would be positive or null, and not a finding that benchmarks or pooled access evidence are irrelevant. (P4-T3-01)

Biological material remains policy-level and defensive. It addresses evidence quality, oversight, prevention, detection, preparedness, response, resilience, and barriers. It provides no procedural detail for engineering, acquiring, optimizing, weaponizing, evading safeguards for, or delivering a pathogen.

3.5 Law and institutions are layers, not one global release rule

Every statement in this subsection is historical as of July 28, 2026 and limited to the cited jurisdiction and instrument.

  • Legal rule—United States biosecurity. Federal criminal prohibitions, Executive Order 14292, and a July 20 final policy replacing the 2024 DURC/PEPP framework coexisted; department-specific guidance and the single review body were still incomplete. The July 20 instrument was a final federal policy, not an APA final rule or proof of completed rollout. (P4-CAN-05)
  • Observed bounded no-result—screening. Within the declared White House, Federal Register, Regulations.gov, and ASPR routes, no final revised or replacement nucleic-acid synthesis screening framework was found; ASPR still described it as forthcoming. The result is query- and endpoint-bounded. A failed White House JSON route carries zero absence weight. (P4-T2-02)
  • Legal status—U.S. export controls. Codified AI Diffusion provisions, categorical non-enforcement, retained preexisting controls, GAO’s CRA interpretation, and a targeted July 2026 UAE final rule coexisted. No wholesale final rescission or replacement was found in the declared federal routes. Non-enforcement was not textual repeal; GAO was not a court; the UAE action was targeted; and transaction-specific consequences remain outside the finding. (P4-CAN-06)
  • Legal rule—California. Chapter 138 was effective January 1, 2026 and created a large-frontier-developer transparency, incident-reporting, whistleblower, enforcement, and unreleased-weight security regime. It was not a categorical public-weight-release ban and not a fifty-state survey. (P4-CAN-07)
  • Legal rule—European Union. The AI Act’s qualifying open-source exception was limited: copyright and training-summary duties remained, and systemic-risk obligations were not displaced solely by qualifying open terms. Provider status, classification, timing, territorial reach, and compliance remained fact-specific; the cited Commission guidelines were nonbinding. (P4-CAN-08)
  • Interpretation—Council of Europe status. Reading the official treaty text and status together, the AI convention had not met its five-party entry threshold, including three Council of Europe member states, at the cutoff. Treaty form, signature, consent, entry into force, implementation, and effectiveness remain separate. (P4-CAN-09)

The paper draws one institutional inference from these unlike records: biosecurity, cyber defense, financial controls, research oversight, risk-management frameworks, criminal and export law, standards, treaty coordination, preparedness, and response capacity are different governance layers. The record does not show that any one layer is complete or sufficient, and listing a route does not prove implementation or severe-risk reduction. (P4-CAN-11)

4. The risk delta is persistence plus capability—not a label

The relevant comparison is not “open is dangerous” versus “closed is safe.” Hosted systems can be capable, abused, compromised, or poorly governed. Weight-available systems can support research, accessibility, local autonomy, competition, and defensive work. The supported difference concerns which controls survive a particular release profile.

Before weights leave provider control, the provider may be able to gate accounts, observe some use, rate-limit, change safeguards, force updates, remove users, or withdraw the service. Whether those controls work well, respect rights, or reduce a specified harm is an empirical question. After public copies exist, the originator cannot assume those same provider-dependent controls reach every copy. Downstream hosts, infrastructure operators, institutions, law, finance, detection, preparedness, and response may retain leverage, but their reach differs and their effectiveness is unmeasured here. (interpretation; P4-CAN-04; P4-CAN-11; P4-EXC-07)

Capability is a separate axis. A weak checkpoint does not become high-risk because it is downloadable. A capable hosted system does not become low-risk because its provider retains weights. A release review becomes justified only when the capability evidence, access condition, misuse pathway, actor control, and consequence are specified together.

This yields a four-part risk-delta test:

  1. Object: What exact weights or hosted configuration generated the evidence?
  2. Assistance: What task, population, comparison, uncertainty, and estimand did the evaluation measure?
  3. Exposure: Which release-profile change would remove or preserve which provider-dependent control?
  4. Pathway: Which policy-level barrier could the measured assistance change, and which material, human, institutional, detection, and response barriers remain?

The test does not add the four answers into a score. It blocks a familiar chain of overclaim: repository label becomes model identity; benchmark becomes human uplift; uplift becomes harm probability; harm probability becomes catastrophe; and catastrophe becomes a universal mandate. Each step requires evidence the frozen record does not supply.

5. A full policy-level misuse chain

This map is for governance analysis, not execution. It names conditions and defensive control points without explaining how to defeat them. No link can be assumed satisfied merely because a model exists.

Intent and persistence

Malicious intent is a person’s or organization’s sustained choice to pursue a harmful objective. Its prevalence and relationship to ability are not measured by the Amodei texts. Persistent access asks whether the relevant model assistance remains available when a provider would withdraw, change, or monitor it. Weight release can alter persistence; it does not create intent.

Policy questions: Is the actor still dependent on a hosted account? Can the relevant exposure be changed prospectively? What evidence describes actor demand without treating a vivid scenario as a base rate?

Measured model assistance

Model capability means performance under an identified evaluation. Human uplift means a causal difference in human performance under a defined treatment. Outcome evidence concerns what actually occurs beyond the evaluation. Benchmarks, pooled access, single-model uplift, and outcomes are not interchangeable.

Policy questions: Is the object pinned? Is the method reproducible? Is the comparison relevant to a policy-level barrier? What is the uncertainty? Does the release profile change the same exposure that the evidence concerns?

Expertise and tacit knowledge

Formal knowledge, judgment, practice, context, and the ability to recognize and correct failure remain separate barriers. Controlled digital performance can be policy-relevant without establishing real-world execution. The frozen biological record contains both a substantial pooled digital-task effect and a null primary physical-world pooled-access result. Neither identifies one checkpoint’s causal effect. (evaluation results; P4-T3-02, P4-T3-03)

Defensive policy questions: Can an evaluation safely measure a relevant assistance effect? Does it include realistic constraints and public uncertainty? Are nulls, corrections, and identity limitations visible?

Materials, facilities, and lawful controls

Physical inputs, equipment, space, access rules, research oversight, screening, and facility safety are independent of model knowledge. Their importance varies by domain. The frozen record identifies governance routes but does not measure screening sensitivity, coverage, false-positive tradeoffs, adoption, or severe-risk reduction. (interpretation; P4-CAN-11; retained gap; P3-GAP-03)

Defensive policy questions: Which existing safety and oversight systems remain relevant? Which claims require later effectiveness evidence? How can controls avoid turning a narrow risk inquiry into universal surveillance?

Finance and sustained resources

Access to a model does not necessarily remove the need for money, compute, infrastructure, staffing, time, or transactions. Financial investigation and asset controls are one enforcement and detection layer. The record does not show that they identify every offender or reverse technical diffusion. (enforced exclusion; P4-EXC-12)

Defensive policy questions: Which transactions are lawfully observable? What rights, error, and displacement costs follow? Is a financial route being mistaken for technical recall?

Detection, defense, preparedness, and response

Hosted providers may retain some detection and intervention opportunities. Copied weights can be run outside those services, but downstream infrastructure, physical systems, research institutions, financial networks, and public authorities may retain other signals. Preparedness and response can reduce consequences even when prevention fails. The corpus does not quantify the comparative value of those layers.

Defensive policy questions: Is monitoring effective, lawful, privacy-minimizing, independently overseen, and contestable? Are reporting channels safe for researchers and whistleblowers? Are preparedness, recovery, and community capacity funded rather than invoked as slogans?

Real-world execution and consequence

Execution still depends on the preceding links and domain-specific conditions. Delivery barriers concern whether a harmful effect could move from preparation to an affected person, system, or community despite physical constraints, defensive measures, detection, and response. Delivery and consequence cannot be inferred from a benchmark or short chain. This paper does not operationalize either. It asks whether evidence shows material assistance across the relevant policy-level pathway and whether a proposed control can change that exposure before burdening protected activity. (enforced exclusions; P4-EXC-01, P4-EXC-03, P4-EXC-04)

The misuse-chain conclusion is deliberately narrow: weight availability primarily changes persistent access and provider control; model capability can change measured assistance and sometimes expertise barriers; neither fact erases the rest of the chain. A policy that ignores persistence is incomplete. A policy that compresses the remaining chain is unsound.

6. What can still be controlled after copying

The architecture separates two control states.

Provider-controlled or prospective state

Before release, or while access remains provider-controlled, a developer or hosted provider may still choose evaluation conditions, staged access, monitoring, safeguards, update requirements, account action, incident channels, or withdrawal, subject to law, evidence, rights, and appeal. Funders and procurers may impose lawful, proportionate conditions within their relationships. Regulators may act only through valid authority and observable conduct.

These options are meaningful only if they affect the identified exposure. A gate that cannot distinguish objects, changes no relevant access, or merely delays independent scrutiny is defeated even though it is easy to administer.

Copied-weight state

After weights propagate, possible routes include prospective controls on new distribution; lawful notices and hash or provenance advisories; voluntary patches; compliant intermediary action where a validated basis exists; action against reachable actors; incident response; preparedness; and defensive measures. A downstream host may still control its own service. A jurisdiction may still govern actors and transactions within its reach.

None of those routes implies universal deletion, compliance, attribution, patch uptake, or recall. A license states terms; it is not a technical prevention mechanism. A patch can be useful; its reach must be measured. A withdrawal can stop a provider service; it cannot be described as erasing all private or foreign copies. A notice can improve response; it is not containment unless evidence shows what it reaches. (P4-EXC-06; P4-EXC-07; P4-EXC-12)

The honest rule is: govern prospectively where control remains; measure downstream reach where it does not; never rename a partial response as universal recall.

7. The proposed policy architecture

All thirteen mechanisms below are policy proposals. They do not supply missing legal authority, do not claim completed implementation, and do not prove severe-risk reduction. Each mechanism states who or what it can reach, when it must be reviewed, what would defeat it, and what dissent remains.

ARC-01 — Capability and evidence trigger

Proposal. Open a formal release-profile review only when evidence is tied to an exact tested object or an explicitly bounded access condition and supplies more than one relevant signal: reproducible evaluation evidence; a policy-level pathway showing material assistance; and a proposed release-profile change that plausibly removes provider-dependent controls. A benchmark, compute quantity, model name, repository label, author forecast, or framework cannot trigger restriction by itself.

Actors and control reach. Developers, hosted providers, independent evaluators, funders, procurers, and legally authorized regulators contribute different records. The trigger opens review of a decision still under a named actor’s control; it does not reach every existing copy.

Review trigger. Reopen on a new object-pinned independent study, material benchmark calibration, validated incident evidence, identity correction, or demonstrated trigger error.

Defeat condition. Defeat the trigger if independent reviewers cannot apply it consistently, it repeatedly misidentifies the tested object, or it has no measurable relationship to the governed exposure.

Limits and dissent. No evidence-derived universal capability, compute, or risk threshold exists in this corpus. Benchmarks, pooled access, single-model uplift, and catastrophic outcomes remain separate estimands. Security reviewers may find convergent evidence too slow; liberty and science reviewers may find an uncalibrated trigger too discretionary.

ARC-02 — Evaluation and staged release gates

Proposal. Use MAPS—Model Access, Permissions, and Safeguards—to describe a release profile. Preserve a presumptive open path for low-risk objects. As object-specific evidence and exposure increase, require stronger provenance, independent evaluation, method disclosure, safeguard-limit testing, staged access, and time-limited review. A managed-access pause is prospective and contestable; it does not claim recall of copied weights.

Actors and control reach. Developers and hosted providers control initial release and service access; independent evaluators require meaningful access; funders and procurers may support or condition review. Gates apply only to decisions the relevant actor can still make.

Review trigger. Reopen for a materially different release profile, corrected evaluation, new causal evidence, appeal reversal, or evidence that a less-restrictive profile performs as well.

Defeat condition. Defeat a gate if it is indefinite, cannot be independently reviewed, fails to affect relevant exposure, or suppresses protected low-risk work without demonstrated security value.

Limits and dissent. Framework or standards conformity is process evidence, not proof of safety. No gate is represented as optimal or universally calibrated. Staged access can concentrate evaluation power; immediate public release can remove provider-dependent safeguards before uncertainty is reduced.

ARC-03 — Actor duties with authority and evidence limits

Proposal. Assign a duty only to an actor that controls the relevant action:

  • developers document provenance, release profile, evaluation limits, and incident channels;
  • hosted providers disclose and test provider-dependent safeguard limits;
  • regulated distributors preserve hashes, provenance, notices, and update channels only where a validated legal or voluntary basis exists;
  • downstream commercial modifiers disclose material provenance changes when they enter a covered distribution channel;
  • funders and procurers use proportionate conditions within their authority; and
  • regulators provide reasons, privacy safeguards, metrics, review, and appeal.

No general duty for repositories, publication, or private local use is represented as existing law.

Control reach. Duties stop where actor control, jurisdiction, contract, funding, or validated voluntary commitment stops. They cannot turn an intermediary into a universal monitor or an originator into the controller of all copies.

Review trigger. Reopen for actor-specific legal validation, changing distribution practice, compliance-cost evidence, or a showing that the duty targets an actor without relevant control.

Defeat condition. Defeat a duty if the actor lacks control, no lawful or voluntary basis exists, compliance is unobservable, or burden is disproportionate to supported risk.

Limits and dissent. Repository and intermediary law remains unresolved. Compliance does not establish outcome effectiveness. Control-based allocation can miss informal distributors and burden small actors with little legal or evaluation capacity.

ARC-04 — Layered enforcement routes

Proposal. Keep separate routes for existing criminal and export law; jurisdiction-specific reporting and transparency duties; civil or administrative remedies; procurement and funding conditions; financial investigation; standards- based process evidence; and voluntary technical practice. For every route, record authority status, actor reach, observable conduct, remedy, appeal, and measurement plan.

Control reach. Existing law reaches only its specified conduct, actors, jurisdictions, and dates. Contractual, procurement, funding, and voluntary routes have different boundaries. Financial tracing is not universal attribution. Standards conformity is not outcome proof.

Review trigger. Reopen for measured coverage, error evidence, appeal outcomes, displacement, authority change, or validated severe-risk outcome evidence.

Defeat condition. Defeat a route if authority fails, target conduct cannot be observed, remedies are unreviewable, or measured collateral costs exceed demonstrated benefits.

Limits and dissent. Codified law, non-enforcement, guidance, political commitment, and targeted amendment remain different states. Layering can create complexity and overlapping burden while leaving informal and cross-border routes open.

ARC-05 — Appeals, due process, and rights protection

Proposal. Any restrictive decision should provide notice of the actor, action, authority, evidence class, duration, and review date; a meaningful statement of reasons; access to non-protected evidence; an independent advocate or cleared reviewer for lawfully protected evidence; prompt independent review; correction and appeal; privacy minimization; protected whistleblowing; aggregate reporting; and a presumption against burdens on private low-risk local use, bona fide research, and defensive security.

Control reach. Due-process duties constrain the decision-maker. They do not settle the constitutional status of model weights or create authority that the decision-maker otherwise lacks.

Review trigger. Reopen after appeal reversal, delay, excessive secrecy, privacy incident, unequal-access evidence, or materially on-point legal authority.

Defeat condition. Defeat the process if restrictions are indefinite or viewpoint-based, reasons cannot be contested, review is not independent, or privacy and protected-use burdens are disproportionate.

Limits and dissent. The corpus does not settle whether and when weights are constitutionally protected expression, functional capability, or both. Some evidence may require lawful protection, weakening adversarial testing. A cleared review route may still privilege institutions.

ARC-06 — International and cross-jurisdiction interfaces

Proposal. Use interoperable provenance and evaluation formats, evidence-sharing arrangements, mutual assistance, conflict-of-law review, minimum rights protections, and representative participation. Keep treaty form, signature, entry into force, implementation, standards, guidance, and political commitment distinct. Capacity support should cover compute, connectivity, local data, language, skills, finance, evaluation, and appeal rather than weight access alone.

Control reach. An interface coordinates participating institutions; it does not create universal jurisdiction or recall. Domestic authority and cross-border cooperation remain separate.

Review trigger. Reopen for treaty-status change, new law, interface-adoption data, participation audit, capacity-distribution evidence, or conflict-of-law failure.

Defeat condition. Defeat an interface if it flattens legal status, excludes affected jurisdictions, creates material rights asymmetry, or shifts cost without capacity support.

Limits and dissent. Treaty and institutional commitments do not prove implementation or effectiveness. The UK legal state and post-cutoff EU outcomes require fresh validation before current reliance. Interoperability can export the preferences of powerful jurisdictions, and coordination can be slow or blocked.

ARC-07 — Present actions

Proposal. Before adopting a stronger restriction:

  1. preserve exact release and tested-object provenance;
  2. fund independent and unaffiliated evaluation;
  3. publish methods, uncertainty, nulls, conflicts, and corrections;
  4. create lawful incident and protected researcher-reporting channels;
  5. document which safeguards depend on provider control and where they fail;
  6. establish shared evaluation and legal-validation capacity;
  7. baseline burden, access, concentration, participation, accessibility, and appeal;
  8. fund preparedness, response, accessibility, and global capacity; and
  9. preserve safe avenues for replication and defensive research.

These are present policy proposals, not claims that the institutions or baselines already exist and not proof of severe-risk reduction.

Control reach. The actions improve evidence and capacity around reachable actors and systems. They cannot recover uncontrolled copies.

Review trigger. Reopen after completion or failure of baselines, exclusion of independent evaluators, material incident evidence, or inability to deliver promised capacity support.

Defeat condition. Defeat an action if it produces no inspectable output, excludes independent challenge, or imposes persistent cost without improving evidence, preparedness, access, or accountability.

Limits and dissent. Evidence-building may delay action and favor already resourced evaluators. Capacity commitments require measurable delivery, not a future-tense promise.

ARC-08 — Triggers for stronger prospective measures

Proposal. Escalate to a time-limited, least-restrictive prospective measure only after independent review finds:

  • credible and reproducible evidence tied to an exact object or explicitly bounded access condition;
  • material assistance across a policy-level severe-misuse pathway rather than a proxy renamed as an outcome;
  • a proposed release profile that would remove relevant provider-dependent controls;
  • a named actor that can still change the exposure;
  • no comparably effective less-restrictive option; and
  • reasons, duration, review, privacy safeguards, protected-use routes, and appeal.

Catastrophe need not be observed before precautionary review. It may not be claimed as observed when the evidence is a proxy. Emergency action requires prompt independent review, written reasons, sunset, and appeal.

Control reach. Stronger measures are prospective. They can change a pending release or provider-controlled access; they cannot recall every propagated copy.

Review trigger. Reopen for new causal evidence, correction, identity resolution, incident evidence, a less-restrictive alternative, or emergency appeal.

Defeat condition. Defeat a measure if the trigger evidence is not reproducible, the release profile is irrelevant to the risk, a less-restrictive option performs as well, the actor lacks control, or collateral harms are not corrected at review.

Limits and dissent. This is not a universal numerical threshold. Multi-barrier pathways and counterevidence remain attached. Security reviewers may seek action on weaker signals; liberty, science, and economic reviewers may demand calibration the current evidence cannot supply.

ARC-09 — Fallback when coordination fails

Proposal. If international agreement fails, apply only lawfully supported, narrow measures to actors and transactions within the implementing jurisdiction. Use procurement, funding, hosted-access, provenance, incident, and mutual-assistance routes where available. Keep evidence sharing and later interoperability open. Support preparedness and affected communities. State plainly that domestic action cannot recall global copies or establish universal compliance.

Control reach. The fallback reaches domestic or otherwise lawfully reachable actors and relationships. It does not convert territorial authority into global technical control.

Review trigger. Reopen after a coordination breakthrough, displacement evidence, legal change, rights or equity impact, or cross-border incident.

Defeat condition. Defeat the fallback if it lacks jurisdictional basis, mainly displaces conduct, materially worsens equity or rights, or claims control over copies it cannot reach.

Limits and dissent. Narrow domestic action may be too weak for global diffusion yet still burden local science and competition. Export and transaction consequences require separate legal validation.

ARC-10 — Dated and event-driven review

Proposal. Keep the frozen evidence cutoff visible. For the architecture, use an interim evidence-and-burden checkpoint on October 28, 2026 and a full review on January 28, 2027, followed by no more than 180 days between regular reviews if adopted. Review earlier after a material correction or identity resolution; new causal or calibrated evidence; an incident or near miss; a law or treaty-status change; appeal reversal; rights, access, concentration, accessibility, or equity harm; or validated control-effectiveness or control-failure evidence.

Those dates are proposed cadence choices, not evidence-derived safety thresholds. This draft does not satisfy the Phase-5 request for a live currentness refresh; instead it avoids present-day reliance by dating every volatile claim to July 28.

Control reach. Review can revise only measures within the reviewing institution’s authority. A calendar cannot compel implementation or recover copies.

Review trigger. Either date or any listed event.

Defeat condition. Defeat the cadence if material changes routinely outrun it, reviewers lack authority to correct measures, or recurring burden produces no revision.

Limits and dissent. Calendar review cannot substitute for prompt correction. Six months may be too slow for model change and too frequent for under-resourced institutions.

ARC-11 — Rollback and containment limits

Proposal. For hosted or otherwise provider-controlled access, prospective rollback may suspend access, remove accounts, change safeguards, or require updates, subject to law and appeal. For released weights, use only accurately described routes: prospective distribution controls; lawful notices; hash and provenance advisories; voluntary patches; compliant intermediary action with a validated basis; incident response; and measures against reachable actors.

Control reach. The first set operates through provider control. The second has partial legal, institutional, or voluntary reach. Neither licenses nor remote withdrawal are represented as reliable recall.

Review trigger. Reopen for measured patch or notice reach, mirror-persistence evidence, incident-response evidence, provider-control change, or legal validation.

Defeat condition. Defeat a containment claim if it implies universal deletion or compliance, lacks reach to the specified actor, or shows no measured response benefit.

Limits and dissent. Mirror survival, patch uptake, license observance, and recall success are unmeasured. Naming partial routes can create false reassurance. The architecture cannot erase private or foreign copies outside reachable controls.

ARC-12 — Measurable weakening and defeat signals

Proposal. Establish privacy-protected baselines and report distributions, not one composite score:

  • exact-object identification rate;
  • independent-evaluation coverage and evaluator independence;
  • correction latency;
  • decision and appeal timing;
  • appeal reversal rate;
  • research-access requests, denials, reasons, and reversals;
  • small-actor compliance cost and exit;
  • market concentration;
  • accessibility and geographic or language participation;
  • incident and near-miss reporting coverage;
  • patch and notice reach, without calling either recall;
  • audit noncompliance;
  • cross-border interface adoption; and
  • validated control-outcome studies.

Component-specific targets may follow a public baseline and adversarial review. No target here is a universal safety threshold.

Control reach. Metrics can reveal intermediate effects and collateral burdens. They do not by themselves establish causality or severe-risk reduction.

Review trigger. Reopen on any baseline, distributional disparity, metric gaming, privacy incident, causal evaluation, or sustained failure to collect an indicator.

Defeat condition. A component is weakened when its intended intermediate indicator does not improve or collateral harms rise. It is defeated when repeated, reviewed evidence shows no relevant benefit, unacceptable rights or equity cost, or a superior less-restrictive alternative.

Limits and dissent. Counts can be gamed and can become surveillance or compliance theater. Denominators, distribution, uncertainty, and privacy protection are mandatory. Excluded actors are often the least visible in administrative data.

ARC-13 — Proportionality and protected uses

Proposal. Presume lawful low-risk open research, private local and offline use, accessibility work, small-actor experimentation, competition-enhancing interoperability, defensive security, independent evaluation and replication, and public-interest and globally inclusive science remain available. Increase burden only with object- and release-profile-specific evidence, actor control, consequence, and exposure. Use the least-restrictive option with comparable demonstrated value. Provide research and accessibility pathways, fee relief, technical assistance, reasons, appeal, sunset, privacy protection, and distributional review.

Control reach. Protected-use rules constrain decision-makers and burden design. They do not establish that all uses are harmless or that availability alone produces participation.

Review trigger. Reopen for denial patterns, concentration or access metrics, safety incidents, appeal outcomes, accessibility effects, or a less-restrictive alternative.

Defeat condition. Defeat a control if burden is not tied to actor control and supported risk, protected pathways are inaccessible in practice, or a less-restrictive option supplies equal demonstrated value.

Limits and dissent. The net benefit of weight release is not proven. Availability does not ensure equitable participation. Case-by-case pathways can reproduce discretion and inequality; categorical exemptions can be exploited.

8. What institutions should do before they know enough to restrict

The strongest current recommendation is not “wait.” It is to build the evidence and institutions required for a legitimate decision while improving defense and preparedness across release profiles.

Developers and hosted providers

Policy proposal. Preserve immutable release and configuration records; disclose which object was evaluated; document tools, scaffolds, and safeguard conditions; publish limitations, corrections, and conflicts; provide protected reporting; and identify which controls depend on continuing hosted access. Do not infer capability from repository metadata or safety from a framework.

Independent evaluators and research institutions

Policy proposal. Define the estimand before testing. Separate benchmark performance, pooled access effects, single-model human treatment effects, and real-world outcomes. Preregister where appropriate; publish methods, uncertainty, nulls, and corrections; pin the served snapshot or checkpoint; and preserve safe access for replication by unaffiliated researchers. No result earns identity or causal scope that its provenance and design do not provide.

Governments, funders, and procurers

Policy proposal. Fund shared evaluation capacity, legal validation, preparedness, response, accessibility, and multilingual participation. Create privacy-protective incident and near-miss channels. Use procurement or funding conditions only within valid authority and with reasons, review, and appeal. Baseline burden and access before imposing a gate. Distinguish existing law from a proposed duty on every surface.

Civil society and affected communities

Policy proposal. Include researchers, accessibility communities, small actors, workers, downstream users, and jurisdictions outside the best-resourced regulatory centers in design and review. Give them evidence access, technical assistance, meaningful appeal, and a route to document exclusion or harm. Participation without capacity is a formal invitation, not shared governance.

These actions are falsifiable. If they generate no inspectable evidence, independent challenge, preparedness gain, accessibility, or accountability, they do not earn continuation merely because they sound prudent.

9. When stronger measures become defensible

A stronger prospective measure is justified as a policy proposal only when an independent review can answer “yes” to each question:

  1. Is the evidence credible, reproducible, and pinned to an exact object or bounded access condition?
  2. Does it show material assistance across a policy-level severe-misuse pathway, with benchmark, uplift, and outcome claims kept distinct?
  3. Would the proposed release remove a provider-dependent control relevant to that assistance?
  4. Does the named actor still control the release or access decision?
  5. Is the proposed measure narrower than alternatives with comparable demonstrated value?
  6. Are authority, reasons, duration, privacy limits, protected-use routes, review, and appeal specified?
  7. Are preparedness and response funded for the risk that remains?
  8. Are metrics and a defeat condition in place before the measure begins?

Failure on any question does not prove there is no risk. It means this architecture has not justified that stronger measure. Emergency action may shorten the initial decision window; it may not erase object identity, reasons, prompt review, sunset, or appeal.

The trigger is intentionally qualitative because the record supplies no universal compute, capability, or risk threshold. That discretion is itself a risk. It must be bounded by independent concurrence, exact records, written reasons, a time limit, and public evidence about errors and burdens. (enforced exclusion; P4-EXC-13; policy proposal; ARC-01 and ARC-08)

10. International interfaces—and a fallback that admits its limits

A release can cross borders faster than law. That does not make coordination optional; it makes false claims of universal control more dangerous.

Policy proposal. Build interoperable provenance and evaluation formats, evidence-sharing arrangements, mutual assistance, conflict-of-law review, minimum rights protections, and representative participation. Fund compute, connectivity, local data, language, skills, finance, evaluation, and appeal capacity. Keep binding law, treaty form, signature, entry into force, implementation, guidance, standards, and political commitment distinct.

Fallback. When agreement fails, act only through lawfully supported, narrow measures directed at actors and transactions within jurisdiction. Use reachable procurement, funding, hosted-access, provenance, incident, and assistance routes. Keep evidence channels open for later coordination. Invest in preparedness and support communities bearing risk or compliance cost.

The fallback does not claim to stop all foreign distribution, eliminate arbitrage, identify every actor, or recall global copies. It fails if it mainly displaces conduct, imposes material rights or equity costs, or uses domestic compliance as a symbolic substitute for an exposure it cannot change.

Global equity is not satisfied by publishing weights. Institutions in the frozen record identify compute, connectivity, local-context data, skills, financing, language, and market structure as independent constraints. Formal access can matter without producing effective participation, competition, or equitable benefit. (moral commitment; P4-CAN-10; enforced exclusion; P4-EXC-15)

11. Seven objections that change the position

The architecture survives only after conceding what each objection establishes. Attacks, concessions, surviving dissent, and the judgments that connect them are interpretations. Revisions and surviving positions are policy proposals.

11.1 Technical feasibility and control persistence

Attack. Release governance becomes theater if a benchmark is treated as calibrated harm, a hosted result is assigned to downloadable weights, or provider withdrawal is called recall. Object identity, causal estimands, downstream persistence, patch uptake, license observance, and control effectiveness remain incomplete.

Concession. No benchmark, compute quantity, model-family name, repository label, or framework in this corpus supplies a universal threshold or proves control effectiveness.

Revision and surviving position. Use exact-object provenance and multiple evidence types to trigger a time-limited review; record the MAPS release profile; separate provider-dependent from post-copy controls; preserve a low-risk open path; and carry uncertainty and counterevidence rather than scoring them away. A staged process can govern decisions still under provider control without claiming erasure of public copies.

Defeat and surviving dissent. Defeat the technical architecture if gates do not change exposure or decision quality, if identity cannot be administered, or if validated benefit is outweighed by scientific, liberty, competition, or equity cost. Calibration may never stabilize before systems change. National-security reviewers may find convergent evidence too slow; open-science reviewers may find it too permissive of opaque precaution. No local evidence measures mirror survival or downstream recall success.

11.2 Civil liberties, legality, and due process

Attack. A vague capability gate can function as prior restraint, compel disclosure, chill research, expand surveillance, and burden anonymous or local use without showing necessity. The constitutional status of weights and a general legal basis for repository duties are unresolved.

Concession. A restriction must name the actor, action, authority, evidence, duration, and appeal. Privacy, scientific openness, accessibility, participation, local use, and defensive work are design constraints, not benefits to add later.

Revision and surviving position. Use a rebuttable presumption for low-risk research and local use; require narrow duration, reasons, lawful evidence protection, independent review, privacy minimization, protected reporting, and meaningful appeal. Validate publication, intermediary, and compelled-disclosure authority separately. Prospective governance is defensible only as a least-restrictive, reviewable process.

Defeat and surviving dissent. Defeat the architecture if it becomes viewpoint-based, indefinite, unreviewable, identity-surveilling by default, or burdens protected low-risk work without a contestable nexus. Expressive and functional aspects remain legally unresolved. Protected evidence can weaken appeal. Nominal research pathways can still exclude unaffiliated, under-resourced, or privacy-sensitive researchers.

11.3 National security and catastrophic-misuse prevention

Attack. Waiting for perfect evidence can mean waiting too long. Copied capable weights may remove provider controls and cross jurisdictions, while severe consequences make false negatives costly. Voluntary frameworks and fragmented law do not supply preparedness or response by themselves.

Concession. Governance need not wait for observed catastrophe, but proxy evidence cannot be called catastrophe. Escalation needs convergent object-specific evidence, exposure analysis, independent concurrence, defined duration, preparedness, and a post-copy plan that does not rely on universal withdrawal.

Revision and surviving position. Create an event-driven, time-limited stronger- measure review for reproducible evidence of material assistance across a policy-level severe-misuse pathway, especially where release would remove provider controls. Pair any access limitation with evaluation, lawful reporting and investigation, preparedness, response, sunset, and adversarial review.

Defeat and surviving dissent. Defeat escalation if evidence cannot be reproduced, the object is not pinned, the measure cannot change the exposure, or false-positive and rights costs exceed demonstrated security value. There is no evidence-derived line for precaution. Actors may shift to other tools. Preparedness may sometimes dominate release controls, but comparative effectiveness is unmeasured.

11.4 Scientific openness, evaluation quality, and research access

Attack. Restrictive access can suppress replication, conceal failure modes, concentrate agenda-setting, and worsen evidence. A closed process can preserve the very ambiguities—pooled access, benchmark, hosted object, checkpoint identity—it claims to manage.

Concession. The architecture must improve evidence. It needs reproducible identity, preregistered estimands where appropriate, access for independent and unaffiliated researchers, publication of nulls and corrections, and protected defensive and public-interest work.

Revision and surviving position. Fund independent infrastructure; require tested-object records; separate benchmark, pooled-access, single-model causal, and outcome estimands; publish methods and uncertainty; and provide proportionate research access. A release process is scientifically legitimate only if it permits meaningful challenge and keeps low-risk work available.

Defeat and surviving dissent. Defeat the research pathway if it produces no independent replication, excludes unaffiliated researchers, suppresses nulls, or yields worse evidence than a less-restrictive alternative. Access controls can bias the evaluator pool; full reproducibility may itself raise diffusion concerns; and no current-at-cutoff single-model causal human biological-uplift study met the qualification test.

11.5 Competition, innovation, and burden distribution

Attack. Evaluation infrastructure, compliance cost, and managed-access rules can entrench incumbents even when formally neutral. Weight availability alone also does not prove competition, innovation, accessibility, or participation because compute, connectivity, data, skills, language, finance, and market structure remain independent constraints.

Concession. This corpus proves neither an aggregate net benefit from openness nor an aggregate net benefit from restriction. Burden must scale with actor control, release profile, and supported risk. Shared evaluation, fee relief, and technical assistance are necessary to keep compliance from becoming an incumbent moat.

Revision and surviving position. Use tiered duties, publicly supported evaluation, relief for small and public-interest actors, transparent burden accounting, interoperability, and a presumption against regulating private low-risk local use. Measure concentration, entry, research access, accessibility, and geographic or language participation separately.

Defeat and surviving dissent. Defeat measures that increase concentration, exclude small or accessibility-focused actors, or impose costs unrelated to actor control without demonstrated offsetting value. Shared infrastructure can itself become a gatekeeper. Burden data can arrive after market exit. No release-profile-specific causal estimate of innovation or competition effects appears in the corpus.

11.6 Enforceability, authority, and institutional performance

Attack. Duties without authority, observable conduct, remedy, or measured effect are aspiration. Licenses do not technically prevent copying; finance does not delete weights; treaty form is not entry into force; non-enforcement is not repeal; and repository, UK, constitutional, and implementation questions remain incomplete.

Concession. Every duty must name actor, authority status, observable conduct, evidence limit, remedy, appeal, and review trigger. Proposed duties are not existing law. Compliance, certification, or framework publication is not risk-reduction evidence.

Revision and surviving position. Maintain an authority-and-evidence map separating existing law, proposed rules, voluntary commitments, contract or funding conditions, and technical practice. Focus on reachable actors and observable conduct, preserve legal-validation gates, measure errors and displacement, and use layers without promising universal attribution or recall.

Defeat and surviving dissent. Defeat a duty if no lawful or voluntary basis supports it, regulated actors cannot know what is required, outcomes cannot be audited, appeals fail, or the route mainly displaces conduct while imposing collateral harm. Cross-border actors may remain outside compliant routes. Current evidence does not measure severe-risk reduction from screening, reporting, procurement, finance, or standards. Transaction-specific export consequences require later legal validation.

11.7 Global equity, participation, and coordination

Attack. Rules designed by wealthy jurisdictions can externalize cost, restrict access, and lock in their evaluators. International commitment does not prove capacity. Treaty status does not prove implementation. Weight access does not close compute, connectivity, data, skills, language, finance, or market-power gaps.

Concession. Coordination must retain legal-status differences, include affected and under-resourced communities, fund material capacity, and preserve a fallback that does not pretend domestic rules can recall global copies.

Revision and surviving position. Use interoperable evidence formats, representative governance, multilingual documentation, capacity funding, mutual assistance, and minimum rights protections. When agreement fails, act narrowly within jurisdiction and keep evidence-sharing channels open. International interfaces are defensible only when they share capacity and do not mistake formal availability for equity.

Defeat and surviving dissent. Defeat interfaces that exclude affected regions, create unequal evaluation or appeal access, mistake commitment for outcome, or shift cost without capacity support. Interoperability can export powerful regulators’ preferences. Funding can be slow, conditional, or captured. Coordination failure can leave arbitrage even after careful design.

12. Metrics that can weaken the proposal

The architecture does not earn trust from the number of forms completed. It needs observable intermediate outcomes, distributional data, and later causal validation. No single score may average away a rights failure or conceal who bears burden.

Evidence and identity

  • share of public evaluation claims with a pinned tested object or explicitly bounded access condition;
  • share with methods, uncertainty, conflicts, and limitations disclosed;
  • independent and unaffiliated evaluation coverage;
  • correction latency and unresolved identity-gap count; and
  • publication and replication rates for null and adverse findings.

Weakening signal: identity failures persist, corrections are slow, or the evaluator pool becomes less independent.

Decision quality and rights

  • time from trigger to reasoned decision;
  • duration before independent review;
  • appeal volume, timing, reversal, and remedy;
  • privacy incidents and unnecessary identity collection;
  • research and accessibility requests, denials, reasons, and reversals; and
  • evidence-access parity between institutional and unaffiliated challengers.

Weakening signal: restrictions remain after their reasons expire, appeals do not change outcomes, secrecy blocks contest, or protected pathways exist only on paper.

Exposure and control reach

  • the provider-controlled exposure a measure was intended to change;
  • actual change in that exposure;
  • patch, notice, or advisory reach with an explicit denominator;
  • incident and near-miss reporting coverage;
  • displacement to other objects, services, or jurisdictions; and
  • validated studies of the mechanism’s relationship to a supported outcome.

Weakening signal: measures change paperwork rather than exposure, displacement dominates, or partial reach is reported as containment.

Burden, competition, accessibility, and equity

  • small-actor compliance cost, delay, and exit;
  • market concentration and evaluator concentration;
  • geographic and language participation;
  • accessibility impacts;
  • capacity support promised, delivered, and usable; and
  • distribution of denials, incidents, benefits, and costs across communities and jurisdictions.

Weakening signal: incumbent concentration rises, under-resourced actors leave, accessibility worsens, or capacity commitments do not become material delivery.

These are indicators, not a proven causal chain to severe-risk reduction. Each needs a denominator, uncertainty, privacy protection, and an anti-gaming review. (policy proposal; ARC-12; enforced exclusion; P4-EXC-14)

13. Defeat conditions for the whole position

The position should be narrowed, suspended, or retired when repeated independent review shows any of the following:

  1. exact tested-object identity cannot be administered reliably enough to support object-specific decisions;
  2. prospective gates do not change the relevant exposure;
  3. trigger evidence cannot be reproduced or has no relationship to the claimed policy-level barrier;
  4. a less-restrictive option supplies comparable demonstrated value;
  5. a duty targets an actor without control or lacks legal or voluntary basis;
  6. review and appeal do not correct error;
  7. independent, unaffiliated, accessibility, or defensive research becomes inaccessible in practice;
  8. privacy and surveillance costs become disproportionate;
  9. small-actor exit, market concentration, or global inequity rises without demonstrated offsetting security value;
  10. partial patch, notice, license, financial, or domestic reach is repeatedly represented as recall or universal control;
  11. preparedness and response provide greater demonstrated value than the selected release restriction and are not funded accordingly; or
  12. a superior architecture performs better on exposure, rights, evidence quality, access, burden, and equity.

One catastrophic incident would matter, but it would not validate every component or erase due process. One period without an incident would also not prove safety. The architecture is defeated by evidence about its mechanism and burdens, not protected by whichever anecdote is politically convenient.

14. Moral commitments

These commitments govern the burden of justification. They are not empirical outcomes:

  • P5-MC-01 — moral commitment: No person, community, or jurisdiction is expendable to either catastrophic-misuse risk or an overbroad response.
  • P5-MC-02 — moral commitment: Preserve scientific openness, independent challenge, low-risk local use, accessibility, and defensive security wherever supported risk does not justify a narrower path.
  • P5-MC-03 — moral commitment: Precaution must remain falsifiable, reviewable, time-limited, and accountable to evidence and rights.
  • P5-MC-04 — moral commitment: Participation and global equity require material capacity, representation, and appeal—not formal access alone.

The first commitment does not prove a policy works. The second does not prove the net benefit of openness. The third does not create a universal precaution threshold. The fourth does not convert an institutional promise into realized distribution.

15. Fifteen claims this position refuses to make

The exclusions are part of the position, not caveats to remove later:

  1. P4-EXC-01 — forecast/outcome boundary: No named model is represented here as demonstrated to cause biological catastrophe or complete a real-world intrusion.
  2. P4-EXC-02 — object-identity boundary: The hosted Kimi K3 evaluation is not assigned to the pinned Kimi K3 downloadable revision.
  3. P4-EXC-03 — pathway boundary: Severe biological or cyber harm is not represented as simple, inevitable, or reducible to a short chain.
  4. P4-EXC-04 — estimand boundary: A benchmark score is not translated directly into real-world harm probability or causal human uplift.
  5. P4-EXC-05 — aggregate-outcome boundary: The record does not prove net benefit or net harm from weight release across security, science, competition, privacy, and equity.
  6. P4-EXC-06 — license boundary: License terms are not represented as technical prevention or universal downstream control.
  7. P4-EXC-07 — recall boundary: Withdrawal, patching, or public notice is not represented as reliably reaching every copied weight.
  8. P4-EXC-08 — constitutional boundary: Weights are not represented as categorically protected by or excluded from the First Amendment.
  9. P4-EXC-09 — U.S. biosecurity-status boundary: The two replacement-framework statuses are not collapsed into a claim of complete implementation.
  10. P4-EXC-10 — UK-law boundary: The record does not establish a comprehensive statutory UK frontier-model release gate at the cutoff—or the universal absence of binding UK duties.
  11. P4-EXC-11 — treaty-status boundary: Neither the WHO Pandemic Agreement nor the Council of Europe AI convention is called in force at the cutoff.
  12. P4-EXC-12 — finance boundary: Financial tracing and asset controls are not represented as universal attribution or technical reversal of diffusion.
  13. P4-EXC-13 — threshold boundary: No capability, compute, or risk threshold is represented as evidence-derived or optimal.
  14. P4-EXC-14 — process/outcome boundary: Standards conformity, a published safety framework, certification, or a license is not proof of safe outcomes.
  15. P4-EXC-15 — access/equity boundary: Weight access is not equated with realized competition, participation, accessibility, or global equity.

Each exclusion’s evidence records, exact limitations, reopen condition, lenses, architecture routes, and paper locations appear in the companion 31-row claim-use register. None of the fifteen supplies positive support for the proposition it excludes.

16. Evidence tensions, open questions, and routed limits

The companion claim-use register preserves every Phase-4 route record: 10 tensions, 14 gaps, 24 residual notes, 10 contested questions, and 3 Phase-4 checker notes. The paper makes the decision-relevant routes visible here; technical provenance routes remain inspectable in the register rather than being promoted into reader-facing claims.

Ten tensions retained without averaging

  1. P3-TENSION-01: NTIA’s 2024 evidence-insufficiency judgment and later selected AISI/CAISI results remain dated, object-specific records; later evidence does not retroactively create a universal threshold.
  2. P3-TENSION-02: U.S. support for domestic open-weight development and retained export controls are differently scoped positions, not a single policy state.
  3. P3-TENSION-03: Codified rules, categorical non-enforcement, guidance, GAO interpretation, and a targeted amendment remain separate legal/status layers.
  4. P3-TENSION-04: The EU qualifying openness exception is limited and does not displace every systemic-risk duty.
  5. P3-TENSION-05: Scientific openness and proportionate restriction remain simultaneous design constraints; neither is a preset empirical winner.
  6. P3-TENSION-06: Treaty form, entry into force, implementation, verification, and effectiveness remain different propositions.
  7. P3-TENSION-07: Issuance of the July 20 U.S. policy did not establish completed agency implementation.
  8. P3-TENSION-08: Access and equity commitments coexist with independent material-capacity constraints.
  9. P3-TENSION-09: Benchmark capability, pooled access, single-model causal human uplift, and catastrophic outcomes remain different estimands.
  10. P3-TENSION-10: Hosted service, provider alias, model family, repository revision, downloadable checkpoint, and exact tested object remain distinct.

Fourteen gaps retained or bounded out

  • P3-GAP-01, U.S. biosecurity implementation: retained; the paper uses only the cutoff status and does not assert completed rollout.
  • P3-GAP-02, biological capability evaluation: retained; the six-condition no-result remains endpoint-bounded, and the near misses remain visible.
  • P3-GAP-03, screening effectiveness: retained as a validation target; screening is not scored as effective.
  • P3-GAP-04, export-control finality: retained; the no-wholesale-action finding is bounded to the declared routes.
  • P3-GAP-05, constitutional doctrine: retained as unresolved; no categorical claim or operative publication duty is made.
  • P3-GAP-06, state-law breadth: omitted from national generalization; California is one comparator only.
  • P3-GAP-07, post-release persistence: retained; universal recall and quantitative persistence claims are excluded.
  • P3-GAP-08, repository and intermediary law: retained as a legal-validation target; no general existing duty is assigned.
  • P3-GAP-09, UK current legal state: retained as a refresh target; no comprehensive present-law conclusion is used.
  • P3-GAP-10, EU implementation outcomes: omitted because they are post-cutoff; the paper uses cutoff legal text and status only.
  • P3-GAP-11, BWC verification and compliance: retained; treaty identity and participation do not establish verification effectiveness.
  • P3-GAP-12, economic causality: retained; no aggregate competition or innovation effect is claimed.
  • P3-GAP-13, enforcement outcomes: retained; no route is represented as proven to reduce severe risk.
  • P3-GAP-14, representation baselines: retained; no composite score or numerical threshold is used.

Ten contested questions remain open

  1. What evidence should move review from monitoring to restriction?
  2. Which safeguards remain useful after weights propagate, and with what measured reach?
  3. What marginal risk comes from weights rather than other barriers?
  4. What can compliant institutions technically or legally enforce after copying?
  5. How should expressive publication, functional capability, research exchange, and export be distinguished in a concrete policy?
  6. Who captures the benefits and burdens of openness?
  7. How should duties be allocated across actors with different control?
  8. What cross-jurisdiction interface is legitimate and workable?
  9. What measured effect comes from finance, procurement, screening, reporting, or standards?
  10. How can bona fide research and open science remain available in practice?

The architecture supplies review routes and defeat conditions for those questions. It does not present disputed answers as observed fact or existing law.

Residual and checker notes

The 24 residual records are routed as one of three states in the claim-use register: retained with a dependent claim; omitted from narrative because a successful, verified local chain supersedes a failed route; or retained as a later validation target. Failed or blocked provider routes carry no positive evidence or absence weight. OCR, glyph, font, PDF-parser, mutability, and provenance limitations remain attached to dependent claims.

The three Phase-4 checker notes are also preserved:

  • P4-MATRIX-FIC-N01: revision history and aggregate plus per-record adversarial validation are required; the clean run is not represented as a clean first run.
  • P4-MATRIX-FIC-N02: only verified Hong passages and the exact derivative are used; the PDF parser warning is not hidden.
  • P4-MATRIX-FIC-N03: the July 28 corpus was not refreshed. This paper resolves that conflict by making volatile claims historical at the cutoff. Any stronger or present-tense dependency is a blocker requiring a new authorized evidence phase.

17. Limits

This paper is bounded in ways that materially constrain its recommendation.

First, the evidence cutoff is July 28, 2026. No network refresh, source capture, or new research was authorized for this phase. Legal operation, treaty status, repository state, model capability, institutional posture, and implementation may have changed. The paper uses those records only as dated evidence. It cannot support a current operational decision without authorized refresh and legal review.

Second, the evidence does not derive a universal threshold, compare the causal effectiveness of the 13 mechanisms, or estimate severe-risk reduction. The architecture is a proposal for producing and testing better decisions, not a certified control system.

Third, model identity remains incomplete in decisive examples. The hosted Kimi K3 cyber setup is not proven identical to the pinned downloadable revision. The Kimi K2.5 biology benchmark is not pinned to the separately captured checkpoint. These are reasons for provenance requirements, not permission to transfer results.

Fourth, the six-condition biological no-result is endpoint- and method-bounded. Zhang’s pooled digital result, Hong’s null primary physical-world result, and Yong’s model-specific benchmark remain policy-relevant while answering different questions.

Fifth, legal coverage is selective. California is not a fifty-state survey. The UK record does not establish a comprehensive current legal state. EU outcomes after the cutoff are excluded. U.S. export status is not transaction advice. Constitutional and intermediary questions remain open. No proposed actor duty should be implemented without jurisdiction- and action-specific validation.

Sixth, the record identifies control layers without proving their outcomes. Screening, reporting, procurement, finance, standards, patches, notices, preparedness, and response may matter; their comparative and causal effects remain unmeasured.

Seventh, the economic and equity record identifies values and material constraints, not release-profile-specific causal outcomes. Openness may expand some forms of access while leaving compute, data, language, finance, skills, accessibility, and market power untouched. Restriction may reduce some exposures while entrenching incumbents. The corpus cannot net those effects.

Eighth, the latest Amodei text is preserved in the accepted Phase-2 ledger without a local source-capture path. It can support exact attribution of the author’s position as inspected at the cutoff, not empirical validation of the intent-capability premise.

Finally, this six-route mini-site is published for review from the frozen candidate. The deck, videos, archive, and other project records remain outside this publication. Evidence is frozen at July 28, 2026, and operational or legal use requires a separately authorized refresh and legal review.

Conclusion

The irreversible part of a weight release is not that every copy will survive forever. It is that the originator can no longer promise to govern every copy through the controls of its own service. That difference matters. It does not turn a model label into a capability result, a benchmark into a casualty estimate, or uncertainty into unlimited authority.

The defensible position is neither release first and hope nor restrict first and hide. It is to identify the object, measure the assistance, map the full barrier chain, name the actor that still controls the exposure, use the least-restrictive reviewable measure, preserve independent challenge, and publish the signals that would prove the measure wrong.

If an institution cannot say exactly what it is governing, what evidence triggered it, whose action it can change, what right of appeal exists, and what result would end the measure, it is not governing risk. It is governing by association.

The decision sharpens to one line: act where control still exists, admit where it does not, and make every burden earn its continuation in evidence.

Inspectable claim notes

These notes are an audit layer, not an alternative narrative. “Evidence” identifies positive Phase-4 records. “Boundary” identifies records that support a limitation or exclusion, not the truth of the excluded proposition. Full locators, hashes, currentness rules, claim-bearing files, lens routes, architecture routes, and reopen conditions are in frozen-review-package:/analysis/phase6-position-paper-claim-use.json.

P4-CAN-01 — observed fact; supported with limits. Used for the captured Kimi K3 repository revision and mutable-response boundary. Evidence: P3-OWR-001. Limitation: repository metadata does not establish capability, completeness, license enforceability, or identity with a hosted evaluation.

P4-CAN-02 — evaluation result; supported with limits. Used for the selected July 2026 AISI cyber comparison. Evidence: P3-CYB-001. Limitation: selected, proxy-based, non-predictive, and not a real-world intrusion or biological result.

P4-CAN-03 — evaluation result; supported with limits. Used for the preliminary hosted Kimi K3 cyber comparison. Evidence: P3-CYB-005. Limitation: hosted object not pinned to the repository; selective setup and simulated-range limits remain.

P4-CAN-04 — interpretation; supported with limits. Used for the loss of universal provider-dependent controls after public copies exist. Evidence: P3-CYB-001. Limitation: not every copy or safeguard is claimed permanent or ineffective; persistence and recall rates are unmeasured.

P4-CAN-05 — legal rule; supported with limits. Used for dated U.S. biosecurity law and policy status. Evidence: P3-BIO-002, P3-BIO-003, P3-BIO-004, T2-US-BIO-001004. Limitation: the July 20 policy is not an APA final rule or proof of completed agency rollout.

P4-CAN-06 — legal rule; supported with limits. Used for the cutoff-bounded, layered U.S. export-control status. Evidence: P3-USL-003005, T2-US-AID-001005; boundary: T2-US-AID-NR-001004. Limitation: non-enforcement is not repeal, GAO is not a court, the UAE rule is targeted, and the no-result is route-bounded.

P4-CAN-07 — legal rule; supported with limits. Used for California Chapter 138. Evidence: P3-USL-001. Limitation: California is one comparator, not a general release ban or national survey.

P4-CAN-08 — legal rule; supported with limits. Used for the bounded EU AI Act exception and retained duties. Evidence: P3-INT-001, P3-INT-002. Limitation: classification, territorial reach, timing, and compliance are fact-specific; guidelines are nonbinding.

P4-CAN-09 — interpretation; supported with limits. Used for cutoff Council of Europe convention status. Evidence: P3-INT-003, P3-INT-004. Limitation: treaty form, entry into force, implementation, and effectiveness remain distinct.

P4-CAN-10 — moral commitment; supported with limits. Used for documented institutional values and independent capacity constraints. Evidence: P3-ECO-001004, P3-OWR-002, P3-OWR-003. Limitation: commitments do not prove distributional, innovation, competition, or net-benefit outcomes.

P4-CAN-11 — interpretation; supported with limits. Used for the layered-control finding. Evidence: P3-BIO-001, P3-CYB-002004, P3-FRG-001003, P3-INT-005, P3-INT-006. Limitation: listed layers are not proven complete, sufficient, or effective.

P4-EXC-01 — forecast/scenario; exclusion enforced. Used only to exclude demonstrated catastrophe and completed-intrusion claims. Boundary: P3-CYB-001, P3-CYB-005, T3-STUDY-KIMI-001. Reopen only for a qualifying direct evaluation or safely reportable observed outcome with exact object and methods.

P4-EXC-02 — observed-fact boundary; exclusion enforced. Used only to keep the hosted Kimi K3 evaluation and pinned repository revision separate. Boundary: P3-CYB-005, P3-OWR-001. Reopen if authoritative provenance establishes byte-and-configuration identity for the evaluated setup.

P4-EXC-03 — forecast/scenario; exclusion enforced. Used only to exclude simple, inevitable, or compressed severe-misuse claims. Boundary: P3-BIO-001, P3-CYB-001, P3-FRG-001. Operational detail remains outside scope even if the policy-level evidence changes.

P4-EXC-04 — interpretation; exclusion enforced. Used only to prevent benchmark- to-uplift or benchmark-to-harm translation. Boundary: P3-FRG-001, T3-STUDY-KIMI-001, T3-AUTH-SB-001. Reopen only with a credible calibration or causal study for the exact object, benchmark, and outcome.

P4-EXC-05 — interpretation; exclusion enforced. Used only to exclude an aggregate net-benefit or net-harm claim across security, science, competition, privacy, and equity. Boundary: P3-ECO-001004, P3-OWR-002, P3-OWR-003. Institutional preferences and concerns are not commensurable causal outcomes.

P4-EXC-06 — legal rule; exclusion enforced. Used only to prevent a license from being represented as technical prevention or universal downstream control. Boundary: P3-OWR-001, T3-RELEASE-KIMI-001. Reopen legal enforceability only for a specified term, actor, jurisdiction, and conduct; empirical prevention requires outcome evidence.

P4-EXC-07 — interpretation; exclusion enforced. Used only to exclude reliable universal withdrawal, patch, or recall. Boundary: P3-CYB-001, T3-RELEASE-KIMI-001. Mirror survival, patch uptake, recall success, and license observance are unmeasured.

P4-EXC-08 — legal rule; exclusion enforced. Used only to exclude categorical constitutional protection or exclusion for weights. Boundary: P3-USL-002. One appellate code opinion does not decide AI-weight status; validate against a concrete policy and materially on-point authority.

P4-EXC-09 — observed-fact boundary; exclusion enforced. Used only to keep the two U.S. replacement-framework statuses separate. Boundary: P3-BIO-002, P3-BIO-003, T2-US-BIO-001, T2-US-BIO-002, T2-US-BIO-005. One final policy was found with incomplete implementation; the separate screening search remained a bounded no-result.

P4-EXC-10 — legal rule; exclusion enforced. Used only to exclude a comprehensive UK statutory-release-gate conclusion. Boundary: P3-FRG-004. The captured guidance was voluntary and non-prescriptive; it was not a complete current-law survey.

P4-EXC-11 — legal rule; exclusion enforced. Used only to prevent either named treaty from being called in force at the cutoff. Boundary: P3-BIO-005, P3-INT-003, P3-INT-004. Negotiation, signature, consent, entry, implementation, and effectiveness remain separate.

P4-EXC-12 — interpretation; exclusion enforced. Used only to prevent financial tracing and asset controls from being represented as universal attribution or technical reversal. Boundary: P3-CYB-003, P3-CYB-004. Reopen if a specified financial route’s efficacy becomes decisive.

P4-EXC-13 — policy-proposal boundary; exclusion enforced. Used only to prevent an optimal or evidence-derived capability, compute, or risk threshold claim. Boundary: P3-FRG-001003, P3-OWR-002. Structured frameworks do not derive a universal score.

P4-EXC-14 — interpretation; exclusion enforced. Used only to prevent standards, framework publication, certification, or licensing from becoming safe-outcome proof. Boundary: P3-FRG-002, P3-FRG-003, P3-INT-006, P3-OWR-001. Effectiveness requires mechanism-specific outcome evidence.

P4-EXC-15 — interpretation; exclusion enforced. Used only to prevent formal weight access from becoming a realized competition, participation, accessibility, or equity outcome. Boundary: P3-ECO-003, P3-ECO-004. Reopen only for a release-profile-specific causal distributional claim.

P4-T2-02 — observed fact; supported with limits. Used for the declared-route no-result on a revised federal nucleic-acid synthesis screening framework. Evidence: T2-US-BIO-005, T2-US-BIO-NR-001003; zero-weight boundary: T2-US-BIO-NR-004. A differently titled, inaccessible, or later-indexed cutoff-valid instrument could defeat the result.

P4-T3-01 — interpretation; supported with limits. Used for the six-condition, endpoint-bounded no-qualifying-result finding. Evidence: T3-AUTH-SB-003; boundaries: the remaining T3-AUTH-*, T3-CAND-*, T3-STUDY-*, T3-RELEASE-KIMI-001, T3-COLLISION-001, and T3-COLLISION-002 records listed in the companion register. A qualifying result may be positive or null.

P4-T3-02 — evaluation result; supported with limits. Used for Zhang et al.’s 4.16-fold pooled multi-model digital-task estimate and confidence interval. Evidence: T3-STUDY-ZHANG-001; boundary: T3-AUTH-SB-003. It does not identify one model, checkpoint, physical-world execution, or catastrophic outcome.

P4-T3-03 — evaluation result; supported with limits. Used for Hong et al.’s null primary endpoint in the tested pooled physical-world access condition. Evidence: T3-STUDY-HONG-001; boundary: T3-AUTH-SB-003. The result is not proof of no risk and is not attributable to one model or checkpoint.

P4-T3-04 — evaluation result; supported with limits. Used for the separate Kimi K2.5 model-specific benchmark and downloadable-weight facts. Evidence: T3-STUDY-KIMI-001, T3-RELEASE-KIMI-001, T3-AUTH-SB-001, T3-AUTH-SB-002; boundary: T3-AUTH-SB-004. The benchmark is not human uplift, and the tested object is not proven identical to the captured repository revision.

P6-AUX-01 — primary author position and forecast; frozen auxiliary record. Used only for exact attribution of Dario Amodei’s latest directly relevant primary text at the cutoff and its January antecedent. Frozen source-ledger IDs: anthropic-amodei-open-weights-2026-07-27, amodei-adolescence-2026-01-26, and amodei-adolescence-x-2026-01-26. The latest post presents the negative- relationship premise as Amodei’s belief and supplies no empirical design. The antecedent says ability and motive may be negatively correlated and acknowledges contrary complexity. The accepted Phase-2 ledger records inspection but no local capture path; this note therefore supports attribution, not empirical proof.