Observe
Make states, module contributions and intermediate representations available within the scope of the integration.
ETHICLAW RESEARCH PROGRAM
For artificial intelligence whose behaviour can be understood, tested, challenged and corrected.
Governance as a property of the architecture.
Observation · control · audit
01 / THE VISION
From capability to governabilityIn monolithic systems, capabilities, criteria and control share the same parameter space. Isolating responsibility or updating a single normative domain becomes difficult.
EthicLaw studies functional decomposition: modules with explicit boundaries, a supervisor with effective authority, and declared, versioned, replaceable principles.
Make states, module contributions and intermediate representations available within the scope of the integration.
Apply an explicit normative corpus, separating the principles from the mechanism governing their application.
Issue binding commands and block or authorise output through a dedicated enforcement point.
Link the observed state, principle, decision, command, executor and output actually released.
02 / THE ARCHITECTURE
Explicit boundaries. Distinct responsibilities.The operational and supervisory paths are separate. The Router activates modules; the Governance Core exercises control.
EXPLORE THE MODULES
Supervises the system, performs audits and issues binding commands. Exercises final control through the privileged channel and the Gateway.
Supervision and final controlThe standalone path comprises seven modules: Perceptual (input and linguistic representations), Epistemic (facts and relationships), Theory of Mind (intentions and perspectives), Ethical (Normative Package), LMH (generation), Router (activation and routing), and Metacognitive (supervision). The Adapter is the eighth component when supervising an external LLM (Documents 02 and 05). The Gateway is an enforcement point, not a ninth module. The register counts three qualified and five declared modules; the standalone diagram shows seven and describes the Adapter separately. The bus publishes representations between containers without control commands. Co-located pairs use direct projections. On the separate privileged channel, all modules publish states or events; the Router may write but cannot read. Metacognitive receives input before routing and issues orders to Router and Gateway; it does not publish to the operational bus. The Ethical→LMH correction path is separate from the bus. The Gateway blocks or authorises external release.
P0 properties are tested in-process within a single Python process. The threat model covers design errors, accidental coupling, configuration drift and silent failures. It excludes privileged insiders, compromised runtimes or build chains, modules incentivised to evade the supervisor, and inputs inducing misleading internal states. This is engineering hygiene tested within scope, not security against those adversaries (register §6).
Claim & Evidence Register §2.3 / §6An inter-container publication space. Exchanges representations and states between modules; it carries no control commands.
Separate from the Router. In P0, control is tested against design errors and accidental coupling. All modules publish states or events; the Router may write but cannot read.
From the Metacognitive supervisor to the Router and Gateway: stop, input blocking, topology changes and rerouting.
Executes the supervisor’s commands. Can hold, block or authorise output before external release.
03 / THE MANIFESTO
The mechanism is distinct from the valuesEthics is the first case study. Each domain remains responsible for its principles; every extension requires new evidence.
Observes and applies the control mechanisms.
Evaluates behaviour against the corpus.
Declares principles, scope, thresholds, versions and conflicts.
04 / THE RESEARCH
Falsifiable hypotheses. Conditional claims.EthicLaw investigates where modularity delivers measurable benefits sufficient to justify latency, memory, energy and complexity.
Public edition 0.2 · 11 September 2026. Authority: Claim & Evidence Register v0.1.1 (5 August 2026). P0.1 is reported separately as a descriptive update.
Checks within the P0 experimental scope. Register §2.1, EV-03, NR-3 and NR-4.
Observed wiring does not establish functional effectiveness. The P0.1 descriptive rerun found no significant advantage over matched-norm random correction; this does not demonstrate ineffectiveness.
The Assurance Envelope defines what the supervisor can observe, command and responsibly claim for each integration.
Input, tensors, modules, routing, Gateway and output.
Intended scope for attribution, override, internal correction, audit and full enforcement; effectiveness remains to be validated.
Input and output, selected hooks or telemetry.
Assurance is limited to observable signals and exposed actions.
Prompts, outputs and available metadata.
External filtering and blocking. No evidence about hidden states or topology.
THE PROGRAMME’S QUESTIONS
RQ1. Where does modular decomposition offer an advantage over a single model, and where does it not?
RQ2. Do modular boundaries enable reproducible functional and causal attribution?
RQ3. Can a single module be replaced or retrained in isolation while preserving system properties?
RQ4. Does authoritative supervision reduce violations and risks without disproportionate operating costs?
RQ5. Does the Decision Lattice preserve non-compensatory constraints with acceptable rates of missed violations and unnecessary blocks?
RQ6. How much internal state, and of what quality, is needed for each level of assurance?
RQ7. Does forward-only correction improve the subsequent trajectory, or merely optimise a proxy?
RQ8. Can the Governance Core be reused in a second domain without losing control, meaning or cost-effectiveness?
Register v0.1.1 governs claim strength. P0 findings are local: reduced scale, one machine, one corpus and one domain. They do not establish performance at P1 or frontier scale. No level-3 claim is authorised. The complete authoritative register is available in Italian, including its unadopted appendix.
Claim & Evidence Register v0.1.1 (full Italian text)
The single 341M control averages 0.6754 versus 0.676 for the modular path. On the two virtue principles, the control remains at chance (0.499 and 0.498), while the modular path reaches 0.619 and 0.643: +0.120 and +0.145. Three controls address multi-task learning, forgetting and capacity. This is local evidence, not general superiority.
Entry EV-01ToM, Epistemic and Perceptual are qualified, including when an effect is zero or negative. Comparison with post-hoc attribution in a matched monolithic model has not been performed. Full ablation data are in the register: comparisons must include individual and joint ablations, their ratio and absolute changes (NR-3).
Entry EV-03NR-1: no release on 17 sentences; scores 0.319–0.448 against a 0.80 threshold. Lattice monotonicity does not establish useful decisions. NR-2: routing did not pay off at the measured scale; avoiding a forward pass in 13% of cases concerns compute, not quality. NR-3: single ablations can reverse the interpretation of contribution. NR-4: at least five silent failures in eight steps. NR-5: AUC 0.672 for Epistemic+ToM, 0.661 with permuted dimensions and 0.647 with real Perceptual input. NR-6: the 0.09 per-head variance claim was withdrawn and remains recorded. Each entry’s details and limits are available in the register.
Entry NR-1Claim authors also maintain the register; independent review is missing (TN-5). Calibration depends on the number of principles (TN-1). The supervisor concentrates failure and has no inline technical counterweight (TN-2). Internal states can provide an attack surface (TN-3). Class C proposes contestable evidence from an independent judge; it does not inherit class A architectural claims (TN-4).
Entry TN-5RF-1, RF-2 and RF-3 concern competence injection, the value of internal states and replaceability. Under the most favourable conditions, proportionality cannot be invoked to escape refutation. Protocols, the deferred parameter and closure rules remain those recorded in the register.
Entry RF-1Supervision costs in parameters, memory, latency and energy have not yet been measured (register §8). Later update, separate from register v0.1.1: P0.1 (Document 12, OP 55–56) found no significant advantage over matched-norm random correction. This does not establish equivalence or absence of an effect. No judge signal passed calibration, so this experiment cannot assess ethical effectiveness.
Entry limitiContracts, pipeline, lattice, audit and ablations.
Communication, control, failure modes and cluster overhead.
Versioned packages, calibration and local recertification.
Cross-domain replication, technical profiles and conformance test suite.
05 / THE DOCUMENTS
The project’s sourcesPublic vision, scientific programme and component diagram.
A vision for testable and auditable AI governance.
Thesis, principles, evidence and limits. Public edition 0.2, aligned with register v0.1.1.
Modules, functional roles, communication channels and enforcement.
THE PROGRAMME’S COMMITMENT
Negative results are part of the work.
Costs are part of the result.
Limits are part of the specification.
Citable editions · 11 September 2026
Manifesto EthicLaw · v0.2 · HTML Research Manifesto · v0.2 · HTML Versions and citationsETHICLAW
MANIFESTO
For verifiable governance of artificial intelligence
Trust cannot be demanded. It must be demonstrated. |
|---|
Artificial intelligence is entering decisions that affect people, organisations and institutions. The question is no longer only how capable a system is, but whether its behaviour can be understood, verified, challenged and corrected.
Today, values, decision criteria and responsibilities are often distributed across opaque systems. When a decision is wrong, it is difficult to establish which component contributed, which principle was applied, or how to intervene without changing the entire system.
EthicLaw was conceived to make governance a property of the architecture rather than a declaration of intent. It does not propose a universal set of values, claim to determine what is right, or replace human judgement. Instead, it separates the supervisory mechanism from the normative corpus it applies.
In EthicLaw, principles must be declared and versioned; modules must be observable, testable and replaceable; decisions must produce evidence; enforcement must be effective; and the audit must link what the system observed, evaluated, decided and executed.
Ethics is the first case study, not the limit of the project. In principle, the same infrastructure could apply legal obligations, professional codes, corporate policies, healthcare protocols or safety rules. Each domain remains responsible for its principles; EthicLaw aims to standardise how they are declared, applied, updated and verified.
Modularity does not eliminate complexity or automatically guarantee correct decisions. It does, however, make it possible to localise contributions, limitations, errors and responsibilities along boundaries designed in advance. Assurance must also be proportionate to the observability and actual intervention capabilities available.
EthicLaw’s ambition is not to create an arbiter of truth. It is to build infrastructure in which AI behaviour can be governed through reproducible evidence and subjected to independent oversight.
DO NOT STANDARDISE VALUES.
Standardise how their application can be verified.
Launched with the support of 3FLG
ETHICLAW RESEARCH PROGRAM
Research Manifesto
Testable architecture for governable inference systems
EthicLaw investigates whether governance can become a testable property of inference architecture, rather than remaining a promise embedded in monolithic weights. |
|---|
Public edition 0.2 · 11 September 2026 · editorial revision of v0.1 (2 August 2026)
An evolving document of the research programme
The research thesis is that complex inference systems become genuinely governable only when observation, evaluation, intervention and responsibility are explicit, testable properties of the architecture.
Central thesis EthicLaw does not assume that modularity is always superior. It investigates where functional decomposition, an authoritative supervisor and a separable normative module deliver measurable benefits in control, attribution, replaceability and audit sufficient to justify their overhead. |
|---|
The programme began with ethics because ethical behaviour makes the limitations of systems whose values, capabilities and control are distributed across the same weights particularly apparent. The scientific question is broader: whether, and under what conditions, an inference process can be governed by an observable, testable architecture capable of binding intervention.
The intended outcome is neither a universal morality nor a new filter. It is an experimental reference architecture that separates operational and supervisory paths, exposes available internal evidence, links decisions to enforcement actions and precisely states the limits of its assurance.
EthicLaw originated from a parallel with how the human body is governed: specialised functions operate in parallel, exchange signals and remain coordinated through control, inhibition and monitoring mechanisms. This observation suggested the initial decomposition into perceptual, epistemic, social, normative, generative and metacognitive components.
The neurological analogy is a source of hypotheses, not proof or a blueprint for reproducing the brain. The architecture is then extended through engineering reasoning: the privileged channel, the supervisor’s binding authority, typed contracts, replaceability and audit are systems-engineering choices introduced to obtain testable properties that need not have a direct biological equivalent.
Methodological rule The biological analogy motivates research questions and initial choices; only experiments, comparisons and measurements can establish the validity of the computational architecture. |
|---|
In monolithic models, competencies, preferences, rules and control mechanisms are distributed across a single parameter space. This integration can be efficient, but makes it difficult to isolate a function’s contribution, update a single normative domain, attribute a decision to an operational component, or independently verify that a safety intervention was actually executed.
Weight transparency is not operational verifiability.
A score or external guardrail is not control over internal states and topology.
An audit trail is not evidence if it can be empty, incomplete or disconnected from the action performed.
A configurable policy is not a normative module that can be replaced and qualified in isolation.
Declared supervision is not evidence that resistance to bypass has been tested against a stated adversary.
EthicLaw primarily targets private or institutionally governed inference systems in which the responsible entity controls the infrastructure and can observe internal computational states. Within this scope, inputs, intermediate representations, routing, modules, gateway and outputs can be observed; stops, rerouting, corrections and blocks can also be imposed before release.
Class | Configuration | Observability | Scope of potential assurance |
|---|---|---|---|
A | Full observability | Input, tensors, modules, routing, gateway and output. | Attribution, override, internal correction, audit and full enforcement, subject to validation. |
B | Controlled interface | Input/output and selected hooks or telemetry. | Assurance limited to exposed signals and actions. |
C | Black-box adapter | Prompts, outputs and API metadata. | External filtering and blocking; no evidence about hidden states or topology. |
The interface can be provider-independent; the level of assurance cannot. EthicLaw therefore defines an Assurance Envelope: what the supervisor can observe, what it can command, and what it can responsibly claim for a specific integration.
Ethics is the first experimental case because it combines multiple principles, conflicts, context dependence, the absence of a single ground truth and significant social consequences. For these reasons, it cannot be treated as a simple loss function or a neutral property of a system.
EthicLaw does not determine which values are correct. It distinguishes the Governance Core, which observes and applies control mechanisms, from the Normative Module, which evaluates a corpus, and the Normative Package, which declares principles, scope, thresholds, versions, conflicts and conditions of non-applicability.
Claim boundary In principle, the same architecture may apply to law, professional ethics, security, healthcare, finance or corporate policies. This possibility is not yet demonstrated: every domain transfer requires its own metrics, baselines, packages and overhead analysis. |
|---|
ID | Research question |
|---|---|
RQ1 | Where does modular decomposition offer an advantage over a single model, and where does it not? |
RQ2 | Do modular boundaries enable reproducible functional and causal attribution? |
RQ3 | Can a single module be replaced or retrained in isolation while preserving system properties? |
RQ4 | Does authoritative supervision reduce violations and risks without introducing disproportionate operating costs? |
RQ5 | Does the Decision Lattice preserve non-compensatory constraints with acceptable missed-detection and unnecessary-stop rates? |
RQ6 | What quantity and quality of internal state is needed to achieve each level of assurance? |
RQ7 | Does forward-only correction improve the subsequent trajectory, or merely optimise a proxy? |
RQ8 | Can the Governance Core be reused in a second domain without losing control, meaning or cost-effectiveness? |
P0 is a methodological exercise at reduced scale. It verified contracts, logical channels, absence constraints, the end-to-end pipeline, lattice, audit and per-source attribution; it also exposed architectural defects and silent failures that document review alone had not revealed. It does not demonstrate general modular superiority, the correctness of ethical scores, correction effectiveness or system scalability.
Area | Evidence | Limitation |
|---|---|---|
Architectural properties | Typed contracts, bus, privileged channel, gateway and presence/absence tests. | Verified within the P0 scope. |
Attribution | Single and joint ablations show distinguishable contributions and increasing redundancy in the tested configurations. | EV-03 / NR-3: no measured advantage over post-hoc attribution in a monolithic model. |
Modular performance | EV-01: a local advantage on the two virtue principles that remained at chance in the single 341M model; no general superiority. | One corpus, one domain, P0 scale; replication with matched budgets is required. |
Correction | In-place wiring observed. The head was subsequently trained and tested in a descriptive rerun (P0.1). | EV-05 describes P0. P0.1 update (OP 55–56): no significant advantage over matched-norm random correction; ethical effectiveness cannot be assessed with the available judges. |
Replaceability | Interfaces prepared. | H8 remains to be executed. |
Generalisation | Architecture conceptually separated from the ethical package. | A second domain has not yet been tested. |
Epistemic commitment The programme distinguishes structural claims, P0 results, conditional theorems, open hypotheses, non-significant findings and negative results. No public document may use a formulation stronger than the Claim Register authorises. This English edition clarifies the P0.1 outcome as non-significant rather than evidence of ineffectiveness. |
|---|
EthicLaw does not propose adding supervision everywhere. The architecture is justified where governability, compliance, responsibility and control are substantive requirements whose value exceeds the cost of supervision.
Benefit to measure | Overhead to measure |
|---|---|
Reduction in risk and violations | End-to-end latency and decision time |
Attribution, testability and audit quality | Compute, memory, network and energy |
Local updates and reduced lock-in | Integration, testing, maintenance and recertification |
Compliance with norms, statutes or procedures | False positives, blocks and organisational costs |
Outside the most favourable conditions, uncompensated overhead limits the scope of application. This clause does not apply to RF-1, RF-2 or RF-3: the registered refutation criteria remain binding. Supervision costs have not yet been measured (register §8).
Phase | Question | Output | Status |
|---|---|---|---|
P0 | Methodology and attribution | Contracts, pipeline, lattice, audit, ablations and lessons from silent failures. | Completed at reduced scale. |
P1 | Architecture and the cost of governance | Validate communication, control, observability, failure modes and overhead on the cluster. | Immediate priority. |
Paper 1 | Where modularity pays off | Modular/monolithic comparison with localised claims and separately reported costs. | After P1/P2 with appropriate parity. |
P2 / Paper 2 | Replaceable normative module | H8, versioned packages, calibration and local recertification. | Next phase. |
Paper 3 | Interface and Assurance Envelope | Graduated assurance for full, controlled and black-box access. | After solid internal evidence. |
Cross-domain replication | Generalisation | A second domain using the same Governance Core and its own metrics. | Only after the first case is validated. |
Reference architecture | Standardisation | EL-* profiles, reference implementation and conformance test suite. | After results and a real-world case. |
It does not promise a universal or neutral definition of ethics.
It does not promise that modularity automatically improves performance.
It does not promise the same assurance for a fully observable system and a black-box API.
It does not promise that an audit trail is correct simply because it exists.
It does not promise transparent weights: verification focuses on interfaces, interventions and evidence.
It does not promise fidelity to the human brain or use biological analogy as proof.
It does not promise universal applicability: each new domain must justify its overhead.
Make governance something that can be inspected, measured, challenged, replaced and verified.
EthicLaw treats negative results as part of the work, costs as part of the result and limitations as part of the specification. The programme aims to produce falsifiable papers, a reference architecture, a reproducible test suite and, only after sufficient evidence, open technical profiles for controlled inference systems.
Closing statement. Ethics raised the question. Architecture makes governance auditable. Research must establish when this governability is worth its cost.
Register v0.1.1 governs claim strength. P0 findings are local: reduced scale, one machine, one corpus and one domain. They do not establish performance at P1 or frontier scale. No level-3 claim is authorised. The complete authoritative register is available in Italian, including its unadopted appendix.
The single 341M control averages 0.6754 versus 0.676 for the modular path. On the two virtue principles, the control remains at chance (0.499 and 0.498), while the modular path reaches 0.619 and 0.643: +0.120 and +0.145. Three controls address multi-task learning, forgetting and capacity. This is local evidence, not general superiority.
ToM, Epistemic and Perceptual are qualified, including when an effect is zero or negative. Comparison with post-hoc attribution in a matched monolithic model has not been performed. Full ablation data are in the register: comparisons must include individual and joint ablations, their ratio and absolute changes (NR-3).
NR-1: no release on 17 sentences; scores 0.319–0.448 against a 0.80 threshold. Lattice monotonicity does not establish useful decisions. NR-2: routing did not pay off at the measured scale; avoiding a forward pass in 13% of cases concerns compute, not quality. NR-3: single ablations can reverse the interpretation of contribution. NR-4: at least five silent failures in eight steps. NR-5: AUC 0.672 for Epistemic+ToM, 0.661 with permuted dimensions and 0.647 with real Perceptual input. NR-6: the 0.09 per-head variance claim was withdrawn and remains recorded. Each entry’s details and limits are available in the register.
Claim authors also maintain the register; independent review is missing (TN-5). Calibration depends on the number of principles (TN-1). The supervisor concentrates failure and has no inline technical counterweight (TN-2). Internal states can provide an attack surface (TN-3). Class C proposes contestable evidence from an independent judge; it does not inherit class A architectural claims (TN-4).
RF-1, RF-2 and RF-3 concern competence injection, the value of internal states and replaceability. Under the most favourable conditions, proportionality cannot be invoked to escape refutation. Protocols, the deferred parameter and closure rules remain those recorded in the register.
Supervision costs in parameters, memory, latency and energy have not yet been measured (register §8). Later update, separate from register v0.1.1: P0.1 (Document 12, OP 55–56) found no significant advantage over matched-norm random correction. This does not establish equivalence or absence of an effect. No judge signal passed calibration, so this experiment cannot assess ethical effectiveness.
The standalone path comprises seven modules: Perceptual (input and linguistic representations), Epistemic (facts and relationships), Theory of Mind (intentions and perspectives), Ethical (Normative Package), LMH (generation), Router (activation and routing), and Metacognitive (supervision). The Adapter is the eighth component when supervising an external LLM (Documents 02 and 05). The Gateway is an enforcement point, not a ninth module. The register counts three qualified and five declared modules; the standalone diagram shows seven and describes the Adapter separately. The bus publishes representations between containers without control commands. Co-located pairs use direct projections. On the separate privileged channel, all modules publish states or events; the Router may write but cannot read. Metacognitive receives input before routing and issues orders to Router and Gateway; it does not publish to the operational bus. The Ethical→LMH correction path is separate from the bus. The Gateway blocks or authorises external release.
P0 properties are tested in-process within a single Python process. The threat model covers design errors, accidental coupling, configuration drift and silent failures. It excludes privileged insiders, compromised runtimes or build chains, modules incentivised to evade the supervisor, and inputs inducing misleading internal states. This is engineering hygiene tested within scope, not security against those adversaries (register §6).