Key points
- The core failure is not intelligence or alignment but the absence of an enforceable decision boundary between recommendation and action.
- Semantic control cannot enforce action boundaries: prompt injection shows that instructions and user input share one inference process.
- Four design rules: inference may propose but never authorise; authority is resolved outside the model; execution is impossible without resolved ownership; stop and escalation are system states, not conventions.
- A deterministic decision layer returns allow, escalate or block. Missing authority is a hard condition, not a warning.
- Provenance is first-class: policy evaluation, ownership resolution and execution authorisation are recorded when authority is resolved, not narrated afterwards.
