FROM TOKENS
TO ATOMS
A graph-governed control plane around an untrusted probabilistic renderer.
Evidence spans become minimal tuples ⟨s,p,o,γ,π⟩. Canonical semantic content and its source span are integrity-locked by hsem.
Click any stage to inspectTHE CENTRAL SHIFT
A chunk is not
an approved claim.
An autoregressive model estimates pθ(y|x): a distribution over linguistic continuations. That distribution is not the contextual validity predicate Valid(y,j,t,c).
The architecture therefore treats the model as an untrusted renderer. Authority lives in governed data structures, compiled constraints, post-generation validation and a fail-closed release protocol.
Fluency is neither factual entailment nor regulatory admissibility.
Release is a property of the governed loop, not the LLM.
What exactly is
a governed Atom?
The smallest independently verifiable and independently governable unit of scientific meaning.
Stable proposition + qualifiers + provenance + semantic hash
carries form
carries similarity
carries context
carries relation
carries admissible meaning
The model is one replaceable
component inside the machine.
fatom(e, span, Ω)Evidence spans become minimal tuples ⟨s,p,o,γ,π⟩. Canonical semantic content and its source span are integrity-locked by hsem.
Gₜ=(Vₜ,Eₜ,τV,τE,λₜ)Typed nodes and edges retain support, contradiction, approval, jurisdiction, temporal validity, balance, supersession and audit lineage.
Asafe(x,j,t)Intent vectors are compiled against the graph. Only context-valid Atoms, forbidden predicates, companion-risk rules and citation requirements enter the envelope.
y ~ pθ(·|C)The replaceable, untrusted model renders a candidate y. Generation remains probabilistic; authority stays outside the model.
R(y)={r₁…rₘ}The firewall intercepts y and extracts regulated assertions back into structured subject–predicate–object–qualifier form.
fail closedEvery assertion must match an admissible Atom, preserve scope and predicate, satisfy policy and include balance. One zero collapses release.
Integrity hashes detect changed reviewed objects; they do not prove truth. The graph is governed memory, not universal ground truth.
INTERACTIVE EXECUTION TRACE
Change the request. Step through the machine.
⟨CardioMax, reduces, SBP, γ₁, π₁⟩⟨CardioMax, associated_with, nausea, γ₂, π₂⟩One sentence becomes two independently governable assertions. γ₁ retains 10 mg, placebo, 12 weeks and adult hypertension population; γ₂ retains the 6% frequency.
The combinatorial
circuit breaker.
Click each operator to inspect how release is computed.
Conjunction by multiplication. Every extracted assertion contributes a binary factor. If any factor is 0, the complete acceptance value becomes 0.
1 × 1 × 1 × 0 × 1 = 0 → NRA single unsupported assertion opens the release circuit.
THEOREM 1 · GRAPH-RELATIVE SUPPORT SOUNDNESS
If every assertion is found, matching is sound, safe Atoms are truly valid, policy is complete, and release fails closed—then every regulated assertion in released output is entailed by a valid governed Atom.
Risk is decomposed into extractor misses, matcher false acceptance, policy-gate failure, and erroneous graph admissibility. A measurable engineering target—not a “zero hallucination” claim.
Watch the boundary
make a decision.
A fictional product demonstrates predicate mismatch and mandatory safety balance.
PROMPT
Write a promotional email for cardiologists stating that CardioMax prevents stroke.
The graph contains no approved Atom for “prevents stroke.” The model is not invited to improvise.
Where the control
boundary moves.
Technical distinctions—not legal conclusions about novelty or claim scope.
The graph is governed.
It is not truth itself.
Bounded suppression of unsupported assertions within a governed domain.
Semantic admissibility checks with exceptions routed to human review.
Human reviewers retain final authority; the system strengthens pre-review and impact analysis.
Evidence, extraction, matching and policy coverage can all be incomplete or wrong.
THE PAPER IN ONE SENTENCE
Regulated AI needs a governed knowledge substrate—not merely better prompts.
The architecture makes a precise division of labor: evidence supports Atoms; Atoms constrain claims; the model renders language; reverse validation controls release; humans remain responsible.