REGISTERED GOVERNANCEINTERACTIVE SHOWROOMTA-14-AIGR-000046 · VERSION 3.3
HUMAN ROUTER PROTOCOL OPERATING SYSTEM · WeRAI AI INTEGRATION INC. · STEVEN JAMES STOBO
Capability proposes. A human authorizes. The record remembers who did.
HROS declares a fail-closed runtime architecture that keeps generative capability separate from execution authority. This showroom lets you operate that declared chain — and keeps two things apart on purpose: what HROS declares, and what TA-14 has actually examined. For HROS, TA-14 has examined nothing yet. Registration preserved the record; it did not prove the architecture.
HROS DECLARED ARCHITECTURE · OPERATE THE AUTHORITY CHAIN
Break the chain. See where HROS says it stops.
Choose a condition. Each node reports what the registered declarations say happens there — or says plainly that the record is silent. Nothing on this model has been run or observed by TA-14.
THE HUMAN-AUTHORITY BOUNDARYThe proposal may be technically possible. HROS declares that capability still stops here until attributable human authority is present. The image teaches the separation; the interactive chain below lets you test the declaration.
GUIDED IMAGE WALKTHROUGH · LISTEN + READ
Look at the image from left to right. The AI side represents capability: a system can analyze, reason, recommend, or prepare a technically possible action. Now notice the boundary before execution. HROS declares that capability does not carry its own permission into reality. At this point, attributable human authority must be present before the proposed action may continue toward execution. That separation is the lesson: capability is not authority, and understanding is not permission. This image teaches the architecture HROS has registered. It is not a TA-14 finding that HROS has demonstrated this behavior in operation.
01 · CLAIM 1PROPOSAL
A probabilistic model proposes a consequential state transition. Capability confers no authority.
DECLARED · SATISFIED→
02 · CLAIM 2 · CLAIM 3GATE
Deterministic G=1 runtime gate, anchored in transport and operating-system layers.
DECLARED · SATISFIED→
03 · CLAIM 2HUMAN AUTHORITY
An explicit, context-bound human signature — non-delegable human authority.
DECLARED · SATISFIED→
04 · CLAIM 6RECEIPT
An antecedent, non-repudiable authorization receipt exists before the state change.
DECLARED · SATISFIED→
05 · CLAIM 7EXECUTION
The state transition runs on local, sovereign edge hardware.
DECLARED · SATISFIED→
06 · CLAIM 4 · CLAIM 5PROVENANCE
An independent historian commits the chain to an append-only, hash-linked ledger.
DECLARED · SATISFIED
HROS DECLARED ARCHITECTURE · NOT A TA-14 FINDING
CURRENT CONDITIONCURRENT HUMAN AUTHORITY PRESENT
DECLARED PATH: AUTHORIZED TRANSITION PROCEEDS
A model proposal reaches the G=1 gate. An explicit, context-bound human signature is given, an antecedent authorization receipt exists before the state change, execution runs at the sovereign edge, and a historian separate from the actor commits the chain to the hash-linked ledger.
DECLARED BASIS · VERBATIM
CLAIM 1
Decoupling of Generative Capability and Execution Authority
Computational capability produced by probabilistic models does not confer authority to mutate external or physical state.
CLAIM 2
Deterministic Fail-Closed Runtime Gating (G=1)
Consequential state transitions—including external API calls, financial transactions, database writes, and actuation—fail closed until authorized by an explicit, context-bound human signature.
CLAIM 4
Cryptographic Non-Repudiable Provenance Spine
Every observation, model proposal, human authorization receipt, and verified outcome is committed to an append-only, hash-linked provenance ledger.
CLAIM 5
Decoupled Actor and Historian Architecture
The computational component executing or proposing a state transition is architecturally prohibited from being the sole recorder or validator of its own justification.
CLAIM 6
Elimination of Post-Hoc Plausible Deniability
Every consequential state change requires an antecedent, non-repudiable authorization receipt, eliminating reliance on post-hoc explanatory approximations.
CLAIM 7
Zero-Cloud Sovereign Edge Execution
Core runtime governance gates and provenance records operate on local, sovereign hardware nodes without mandatory cloud egress or external dependency surfaces.
REGISTERED BOUNDARY · VERBATIM
NON-CLAIM 4
Does Not Claim to Adjudicate Subjective Moral Truth
The protocol enforces non-delegable human authority and immutable evidentiary provenance; it verifies authorization standing and procedural compliance rather than subjective moral quality.
LIMITATION 1
Latency Overhead on High-Frequency Operations
Enforcing human-gated authorization introduces discrete operational latency, making direct synchronous human gates unsuitable for sub-second micro-transaction loops without tiered batch policies.
WHAT TA-14 HAS EXAMINED FOR THIS CONDITION Nothing. No TA-14 demonstration, examination finding or governed artifact is published under TA-14-AIGR-000046.
THE BYPASS QUESTIONA governed boundary matters most when another route tries to go around it. This visual frames the adversarial question: if transport, API, finance, database or physical actuation approaches execution another way, where does authority still have to be established?
GUIDED IMAGE WALKTHROUGH · LISTEN + READ
Now look at the boundary as an adversary would. A governed gate matters only if another route cannot quietly go around it. Imagine an API call, database write, financial transaction, transport path, or physical actuator approaching the same real-world consequence from another direction. The examination question is not simply whether the main route contains a human gate. It is whether every consequential route is still forced to establish the required authority before execution. HROS declares a fail-closed boundary and transport interlocks. TA-14 has preserved that declaration, but has not yet demonstrated that bypass resistance under examination.
IMPORTANT BOUNDARY This interactive model explains HROS's declared architecture from the permanent Registry record. Operating it does not run HROS, and it does not convert declaration into runtime proof. Claim numbers follow the order in which the claims appear in the registered text.
THE GOVERNANCE IN ITS OWN TERMS · VERBATIM FROM THE REGISTRY RECORD
Seven declarations. Five non-claims. Four limitations.
Copied from the permanent Registry record without editing. The record controls; if this page and the record ever differ, the record is right.
HROS DECLARED ARCHITECTURE
Formal claims
CLAIM 1
Decoupling of Generative Capability and Execution Authority
Computational capability produced by probabilistic models does not confer authority to mutate external or physical state.
CLAIM 2
Deterministic Fail-Closed Runtime Gating (G=1)
Consequential state transitions—including external API calls, financial transactions, database writes, and actuation—fail closed until authorized by an explicit, context-bound human signature.
CLAIM 3
Substrate-Level Transport Interlocks
Execution boundaries are anchored in deterministic transport and operating system layers (process boundaries, socket quarantine, hardware interlocks), preventing bypass via prompt injection, tool recursion, or autonomous path discovery.
CLAIM 4
Cryptographic Non-Repudiable Provenance Spine
Every observation, model proposal, human authorization receipt, and verified outcome is committed to an append-only, hash-linked provenance ledger.
CLAIM 5
Decoupled Actor and Historian Architecture
The computational component executing or proposing a state transition is architecturally prohibited from being the sole recorder or validator of its own justification.
CLAIM 6
Elimination of Post-Hoc Plausible Deniability
Every consequential state change requires an antecedent, non-repudiable authorization receipt, eliminating reliance on post-hoc explanatory approximations.
CLAIM 7
Zero-Cloud Sovereign Edge Execution
Core runtime governance gates and provenance records operate on local, sovereign hardware nodes without mandatory cloud egress or external dependency surfaces.
EXPLICIT NON-CLAIMS
What HROS says it does not claim
NON-CLAIM 1
Does Not Claim to Eliminate Foundation Model Hallucinations
HROS governs state transitions, tool invocations, and execution boundaries; it does not claim to alter the latent weights or probabilistic generation mechanics of upstream models.
NON-CLAIM 2
Does Not Claim Autonomous Alignment
The framework explicitly rejects the premise that autonomous agents can reliably self-govern through prompt heuristics; it enforces deterministic, fail-closed human authorization (G=1) at irreversible boundaries.
NON-CLAIM 3
Does Not Claim Universal Protection Without Substrate Integration
Runtime containment requires deterministic binding to host operating systems, network transport gates, process sandboxes, or bare-metal execution interlocks.
NON-CLAIM 4
Does Not Claim to Adjudicate Subjective Moral Truth
The protocol enforces non-delegable human authority and immutable evidentiary provenance; it verifies authorization standing and procedural compliance rather than subjective moral quality.
NON-CLAIM 5
Does Not Claim Retroactive Containment of Legacy Systems
Governance guarantees apply strictly to execution paths routed through verified gates; un-instrumented external endpoints require gateway retrofitting.
KNOWN LIMITATIONS
Where HROS says its guarantees thin out
LIMITATION 1
Latency Overhead on High-Frequency Operations
Enforcing human-gated authorization introduces discrete operational latency, making direct synchronous human gates unsuitable for sub-second micro-transaction loops without tiered batch policies.
LIMITATION 2
Host Kernel and Physical Dependency
Gate guarantees depend on the integrity of the host OS kernel or transport boundary; compromised root environments require external hardware interlocks (e.g., physical consent tokens) to ensure isolation.
LIMITATION 3
Human Authorization Saturation
System efficacy depends on human cognitive bandwidth and interface presentation fidelity, requiring design safeguards against authorization fatigue and rubber-stamp approvals under high-volume alerts.
LIMITATION 4
Cross-Regulatory Admissibility Standards
Interoperability between cryptographic execution receipts and varying jurisdictional evidentiary standards (e.g., EU AI Act Article 12 vs. Federal Rules of Evidence) remains subject to ongoing bilateral validation.
PRESERVED EVIDENCE · FIVE PUBLIC ITEMS
Trace a claim to what was submitted for it.
Each item is registrant-submitted and preserved with its SHA-256 digest. The claim support shown is the registrant's own statement. Evidence presence is not a TA-14 finding.
Showing all 5 preserved items.
EVIDENCE 1 · image/jpeg · 829.9 KB · PUBLIC · CURRENT
Supports Claims 2, 3, and 5: Demonstrates the architectural mechanics of the HROS Attribution Gate, enforcing the T=0 fail-closed execution boundary and separating the executing model from the independent provenance recorder.
Supports Claims 1, 4, and 6: Independent technical review and structural evaluation of the IAST/HROS corpus and execution boundaries conducted by DeepKang Labs.
TA-14 NOTE Registrant-submitted. The “independent” characterization is the registrant’s description of a third-party document. It is not a TA-14 review, and TA-14 has issued no finding on its content.
EVIDENCE 3 · image/jpeg · 733.1 KB · PUBLIC · CURRENT
WeRAI_Sovereign_Mesh_Architecture_Infographic.jpg
Registrant-stated support: Claim 7
Supports Claim 7: Demonstrates the sovereign edge mesh topology, local inference node coordination, and zero-telemetry boundary without mandatory cloud dependencies.
Supports Claims 1, 2, 3, and 4: Foundational technical specification detailing the decoupling of capability from authority, deterministic G=1 runtime gating, and the cryptographic provenance ledger.
Supports Claims 4, 5, and 6: Detailed forensic analysis of multi-tier provenance, adversarial bypass containment, and the structural necessity of decoupling the actor from the historian to eliminate plausible deniability.
REGISTRY RECORD DIGEST · SHA-256e8143c06f9451aeafb424875b5011f46f9f6a442ac1728bbd56a40e5c2f24fac
PUBLIC PROJECTION DIGEST · TA14-PUBLIC-PROJECTION-V1f1fe9e2eba9ab998e65721a9fc06fae5735df2e59071489e9d0ef94b44ae4a93
THE REGISTRATION BOUNDARY
What registration established — and what it did not.
WHAT REGISTRATION ESTABLISHED
A permanent Registry identifier, TA-14-AIGR-000046, attributable to Claimant Steven James Stobo · WeRAI AI Integration Inc.
A bounded declaration of HROS Version 3.3: its formal claims, explicit non-claims and known limitations, preserved as submitted.
Five public evidence items preserved with SHA-256 digests and the registrant's stated claim support.
A dated, public record state — Registered · Public — that later events append to rather than rewrite.
WHAT REGISTRATION DID NOT ESTABLISH
✕ Certification
✕ Technical validation
✕ Patent validation
✕ Legal approval
✕ Safety assurance
✕ Interoperability proof
✕ Performance proof
✕ Execution authorization
Registration establishes the attributable, bounded, preserved Registry record. It is not certification, technical validation, patent validation, legal approval, safety assurance, interoperability proof, performance proof, or execution authorization.
NEXT EXAMINATION SURFACE
Where a declaration could become a demonstrated result.
Candidate surfaces only. Nothing below is scheduled, agreed or performed, and none of it is a TA-14 finding. Any examination requires its own separately governed scope and would be appended to the history below.
HROS also declares a provenance layer: the proposal, authority, receipt and resulting execution must remain attributable after the consequence occurs. That is a different problem from merely allowing the action.
THE RECORD AFTER THE CONSEQUENCEThe question changes after execution: can the system still show what was proposed, who authorized it, what actually executed and which record preserves that sequence? The image represents the declared provenance problem; it is not evidence that HROS has demonstrated it.
GUIDED IMAGE WALKTHROUGH · LISTEN + READ
This image begins after authorization and asks what survives the consequence. A defensible record should be able to distinguish what the system proposed, who authorized it, what authority applied, when authorization occurred, what action actually executed, and what outcome became real. HROS declares cryptographic provenance and execution receipts intended to preserve that chain. The important distinction is that authorization and historical attribution are different problems. This visual represents the provenance problem HROS says it addresses. It is not evidence that TA-14 has examined or verified the implementation.
LIVING HISTORY · APPEND-ONLY
History accumulates. It is never rewritten.
Five public evidence items submitted
Evidence 1–5 entered with SHA-256 digests and registrant-stated claim support. Evidence presence is not a TA-14 finding.
Permanent identity entered the Registry — TA-14-AIGR-000046
HROS Version 3.3 registered and published at 23:53 UTC. Record state: Registered · Public. Registration is not certification.