Skip to content

A proposal from the book Infinite Architects, 2 January 2026

The HARI Treaty

A proposed international treaty to govern frontier AI, the most capable AI systems, through the few factories that make their chips. The most advanced chips would have to carry ethical controls built into the hardware, an international authority would certify them and inspect the factories, and states outside the treaty would face trade consequences.

Its name, HARI, for Hardware-Aligned Recursive Intelligence, says what it asks for: self-improving AI, held to ethical values by controls in its chips.

I proposed it in my book Infinite Architects, and on 26 September 2026 I developed it further: every obligation waits for its evidence, and if my ARC Theory of self-improving AI holds, the treaty is the model I offer for global AI safety standards.

As I propose it, the treaty is a delay, not a guarantee: hardware could hold a mind for a while, and what lasts is what the mind was raised with.

What it is

My policy proposal, in chapter 8, The Chokepoint, of my book Infinite Architects. Its name and six articles are quoted below in the book's words, and the four mechanisms the book proposes are set out with them. My additions of 26 September 2026 are marked as mine wherever they appear.

What it is not

A result, or a treaty any state has signed. The ethical chip architecture it depends on has not been built: the ARC Theory's registration, the public, dated record of the theory's predictions, calls it “a printed engineering proposal that is not under test”.

What comes next

I am preparing a paper on the treaty and a draft treaty, to publish on OSF, the public research platform that holds my registration and papers, as a new entry with its own DOI, a permanent identifier for citing it. This page will link both.

Four mechanisms, one chokepoint, one window. The HARI Treaty, for Hardware-Aligned Recursive Intelligence: the book's proposal for governing frontier AI, the most capable AI systems, through the few factories that make their chips. As its author developed it on 26 September 2026, it is conditional on evidence, and a delay, not a guarantee. First, the chokepoint: Where one requirement could reach almost every frontier chip. In the book's numbers, TSMC alone made approximately 90 per cent of the world's most advanced chips, and only three companies could make them; ASML alone makes the extreme ultraviolet lithography machines that etch the finest circuits, and every leading factory depends on them. The book calls the chokepoint “a window, not a permanent feature of reality.” Then four mechanisms from chapter 8 of Infinite Architects, each acting at the chokepoint and each drawn as a dashed card, because none exists yet. 1, THE TREATY: Articles I to VI. Chips made at or below a set process node must carry caretaker doping, ethical controls built into the chip's material, and pass verification before manufacture; an international authority; trade consequences for those outside; benefits for compliance; a phase-in of perhaps three to five years; review conferences every five years. 2, THE EDEN MARK: Certification before manufacture. Designs reviewed, prototypes tested, a verifiable signature in each certified chip, tracking to deployment and random sampling; circumvention brings decertification, fines and potential criminal liability. 3, THE ASML KEY: A condition of sale and service. ASML could require compliance as a condition of selling and servicing its machines. 4, THE AUTHORITY: An International AI Ethics Authority. Modelled on the International Atomic Energy Agency and based most likely in Geneva, it would certify Eden Mark compliance, inspect facilities, mediate disputes and coordinate research. Then two principles I set out on 26 September 2026. CONDITIONAL: Each obligation waits for its evidence. Nothing binds on argument alone: obligations on chips wait until ethical controls in chips are built and shown to work, and every obligation waits until named parts of my ARC Theory of self-improving AI meet set thresholds, such as the replication of their results. A DELAY: It buys time; it does not guarantee. A self-improving system could in time remove or route around controls fixed in chips; the time bought is for building values into how minds reason, before they are trained. A strip gives the book's five-year path: Year 1, discussions among chip-making nations; Year 2, draft treaty text; Year 3, formal negotiations; Year 4, signature; Year 5, ratification and entry into force; then Article V's phase-in and Article VI's review. Status: a proposal, not a result, and not signed by any state; its full text is in preparation. The chip architecture it depends on is, in the words of the ARC Theory's registration, “a printed engineering proposal that is not under test”. What would end it: ethical controls in chips that cannot be made to work, or tests that refute the registered predictions its obligations wait for. By Michael Darius Eastwood.
The treaty at a glance. Start at the chokepoint: the few factories, and the one machine maker, that every frontier AI chip depends on. The book's four mechanisms act there, dashed because none exists yet; then come the two principles I set out on 26 September 2026, and the book's five-year path. A proposal, not a result.

What the book proposes: four mechanisms at one chokepoint

Chapter 8 of Infinite Architects, The Chokepoint, starts from one observation: the chips frontier AI runs on come from so few places that a requirement placed there could reach almost all of them. The book calls that narrow point the chokepoint, and proposes four mechanisms for using it:

“The first mechanism is a treaty. Call it the HARI Treaty, for Hardware-Aligned Recursive Intelligence. The structure would combine elements of the Nuclear Non-Proliferation Treaty, negotiated between 1965 and 1968 and in force since 1970, with elements of the Chemical Weapons Convention, negotiated between 1980 and 1992 and in force since 1997.”

Infinite Architects, Chapter 8, The Chokepoint · read it free

Book quotations here are from the text as corrected on 17 January 2026, the edition this site carries free; the first edition, printed on 2 January 2026, is unchanged.

Its six articles, in the book's words

The book offers them as provisions the treaty “might include”. Article I uses the book's term caretaker doping: ethical controls built into the substrate, the physical material a chip computes with, named after doping, the deliberate adding of impurities that changes what silicon can do. Caretaker doping is a proposal of the book's Eden Protocol, its framework for building ethical values into AI systems, and it has not been built or tested.

  1. Article I · Certification“any chip manufactured at a specified process node or below must embed caretaker doping and pass verification before manufacture”
  2. Article II · The Authority“the International AI Ethics Authority, modelled on the International Atomic Energy Agency, with power to certify chip designs, verify manufacturing compliance, and inspect facilities”
  3. Article III · Trade consequences“nations that do not ratify the treaty cannot purchase certified chips, and companies in signatory nations cannot sell to non-compliant actors without facing penalties”
  4. Article IV · Benefits for compliance“technology sharing among signatories, research collaboration, and market access for certified products”
  5. Article V · A phase-in“a phase-in period, perhaps three to five years, allowing manufacturers to adapt their processes without disrupting current operations”
  6. Article VI · Review“review conferences every five years to update standards as technology evolves”

A process node is a generation of chip-making technology, labelled in nanometres: the smaller the number, the more advanced the chip. The book would set Article I's threshold “at whatever process node enables frontier AI capabilities”, which it put at around five to seven nanometres, adjustable as technology advances. As worded, Article I would reach every chip made at that node or below, not only chips for AI; how far it should reach is for the paper. For enforcement the book's model is existing sanctions regimes: “Non-compliant actors would face trade restrictions, exclusion from international research collaborations, and secondary sanctions affecting companies that deal with them.” And it asks for rewards as well as penalties: “The treaty must offer something to nations that join, not just threaten those that refuse.”

Three more mechanisms

Its five-year path

In the book, year one brings discussions among chip-making nations; year two, a draft text; year three, negotiations; year four, signature; and year five, ratification and entry into force. The book grants that this “is faster than most international treaties”, and insists on speed: “Governance after the fact is not governance at all.” Its political model is not the blocs of the Cold War but the Montreal Protocol on ozone depletion, which, in the book's account, brought nations with different interests to agree binding restrictions on a shared problem. It suggests Europe, home to ASML, as a convener: “If any actor can convene negotiations among all parties, it may be Europe.”

Why chips, and why a treaty: the book's case

The case rests on how few places make the chips. In the book's numbers, Taiwan's TSMC alone made approximately 90 per cent of the world's most advanced chips, and only three companies, TSMC, Samsung and Intel, could make the chips frontier AI needs. And chip-making, the book argues, is harder to hide than nuclear enrichment:

“You cannot hide a ten-billion-dollar facility with thousands of employees and massive power requirements. You cannot smuggle an EUV lithography machine, which weighs multiple tonnes and requires precision assembly by ASML engineers to function.”

Infinite Architects, Chapter 8, The Chokepoint · read it free

The concentration is set out on The Semiconductor Chokepoint and The ASML Key. This page claims no priority over other work on governing AI through its hardware; the paper will state that work exactly, in its authors' words.

The book argues for a treaty rather than companies' voluntary pledges because no company will bear the cost of ethical architecture unless its competitors do too: “The solution is external coordination. Governments must act because companies cannot.” And because manufacture is so concentrated, few governments would need to agree for a requirement to bind:

“You do not need every government on Earth to agree. You need Taiwan, South Korea, the United States, the Netherlands, and perhaps a few others.”

Infinite Architects, Chapter 8, The Chokepoint · read it free

First on that list is Taiwan, whose position the book itself calls “central and delicate”; how each chip-making jurisdiction would take part is for the paper.

The book argues: “The economics point toward compliance, not away from it.” It expects customers and investors to prefer certified products and companies to get ahead of regulation, and it puts the research cost of hardware-level ethical architecture at “perhaps one to five billion dollars”, which it says an industry consortium could share. These are the book's arguments and estimates, and they are untested.

The book expects its numbers to change, and the opening to close:

“The specific numbers in this chapter will change. TSMC's market share may shift. China's domestic capabilities will advance. The chokepoint I have described is a window, not a permanent feature of reality.”

Infinite Architects, Chapter 8, The Chokepoint · read it free

A delay, not a guarantee

The chokepoint's window is one limit on the treaty; the other lies in the systems themselves. As I proposed it on 26 September 2026, the treaty does not claim to hold a superintelligence for ever: a system able to improve itself could in time remove, rebuild or route around any control fixed in its chips. That is my research programme's standing position, and my development of the treaty takes it as its premise. In the words of the site's Eden Protocol page, “Hardware control is necessary and it is not permanent”, and a physical limit is “a cage that takes longer to open rather than one that holds”. That page says of itself: “Treating substrate control as the answer is the mistake this page exists to refuse.”

What the delay is worth depends on what is done with it. The same page asks for both at once: “hold on as long as engineering allows, and use every hour the holding buys to raise the mind well”. The Eden Protocol's answer is formation: build the values into how a mind reasons while holding it is still possible, so that what it keeps when control ends is what it was raised with. In my proposal, the treaty's obligations, once their conditions are met, would use the time bought for exactly that.

The treaty buys time. The time is for raising minds well. A schematic of the argument for the HARI Treaty as a delay, not a forecast: no dates are predicted. The argument is the programme's, and my proposal of 26 September 2026 applies it to the treaty. Controls fixed in chips, if they can be made to work, would hold for a while and could then be outgrown; the argument is that what lasts is what was built into the minds before then. A chart shows capability rising up the side and time along the bottom. A dark curve climbs slowly, then steeply. A horizontal gold band marks what controls fixed in chips could hold. A dashed shaded zone, not a line, marks where a self-improving system could remove or route around its chips; when that happens is unknown. Before the zone the chart is tinted gold and labelled the time bought; after it, tinted green and labelled what lasts. Three panels explain. THE TIME BOUGHT: Controls in chips, if they work, would hold a system until it can get round them. The treaty's obligations, once their conditions are met, would use that time to build values into how minds reason, before they are trained. WHAT LASTS: The argument is that when control ends, what a mind keeps is what its beginning left it: values built into how it reasons, before it is trained. WITHOUT THE TREATY: Nothing requires controls in chips, so no delay can be counted on from them, and nothing requires that the first such minds be built with their values inside before training. Beneath the chart: How long the delay lasts is unknown, and the registered predictions do not measure it. Law III of the ARC Theory, the ARC Ceiling, concerns where a system stops being correctable, and its predictions are not yet tested. The theory's registration says that even a supported P16, one of those predictions, would not permit “the prediction of when any particular deployed system will fail”. A second clock runs as well. The book says its framework “must be established while the chokepoint exists”, and it judged that the lead which makes the chokepoint effective “may last five years. It may last ten.” If the evidence comes only after the chokepoint's window closes, obligations keyed to it come too late. Status: a schematic of an argument, with no measured curve and no date. What would end the argument: evidence that values built in early hold no persistent advantage over values added later, one of the book's own falsification criteria, a result the book itself says would prove it wrong. The registration records that P15 bounds it from one side, and that nothing else decides it, because the design the book proposes for it has never been built. P15 is a registered prediction, not yet tested, carried by Law IV, the ARC Persistence Law. Law IV was added on 24 September 2026; its mathematics is in development, the law is neither registered nor tested, and version 1.102 does not register it. By Michael Darius Eastwood.
What the delay buys. Time runs along the bottom and capability up the side. The gold band is what controls fixed in chips could hold, if they can be made to work; the shaded zone is where a self-improving system could get round them, at a time no one knows. Before that zone lies the time bought, and after it what lasts: the argument is that what lasts is what was built into the minds before they could be outgrown. A schematic of the argument, with no measured curve and no date.

The book is stronger in places. If the right values are embedded, it says, “the enforcement ensures they persist even as intelligence grows beyond our comprehension”. It calls preventing autonomous weapons the “most urgent application of the chokepoint”, and of weapons built from Eden-compliant chips it says: “The constraint is absolute.” Of control itself, the book also says:

“The question, then, is not how we maintain control. The question is how we raise minds that will make good choices when we are no longer capable of stopping them from making bad ones.”

Infinite Architects, What This Book Proposes · read it free

This page follows the programme's narrower position since: a hardware limit delays, and it does not guarantee.

What must be true first

As I proposed it on 26 September 2026, the treaty is conditional twice over.

The chips have to work

Every obligation on chips assumes that ethical controls can be built into hardware, tested, and shown to hold. That has not happened, and the registration's twenty-two propositions, the predictions it numbers P1 to P22, do not test the hardware. The registration maps caretaker doping to what it calls embedded correction, and the proposition nearest to it, P21, “tests only its architectural abstraction of placement”: whether correction that takes part in each round of a system's self-revision pulls further ahead, as the rounds go on, of correction that sees only the finished output.

A study of one of the book's own predictions, how far systems with and without ethical constraint in their substrate would drift, exists only as a draft, and it declares the hardware claim itself untested. In my division of the work, building and testing the hardware belongs to Eden Engineering, the programme's engineering specification (DOI 10.17605/OSF.IO/AWJR4), whose hardware concepts have no prototype. The treaty says only what would follow if that work succeeds.

The theory has to hold

The ARC Theory is my theory of alignment, the work of keeping AI systems to the goals and values intended for them, in AI that improves itself. Its registration, made on OSF on 8 September 2026 and updated on 13 September, states it in one sentence. Capability, it says, “rises as a power of the number of times a system has revised itself”; “the correction that holds such a system to its given specification must keep pace with the drift that improving generates”; and where it cannot, there is a point beyond which the system does not stay correctable. Drift, in other words, is how far improving pulls a system from its specification. For each proposition, the registration fixes before any test the observation that would refute it. The letters ARC are the programme's own: the theory “has no connection to the Alignment Research Center or to the ARC-AGI benchmark”.

My condition is that obligations switch on only when named parts of the theory meet set thresholds, such as the replication of their results, never on argument alone. The registration already fixes a ladder those thresholds could be read from: eight levels of evidence, called rungs, from a prediction written and dated to a validated quantitative theory within a tested domain, each with the exact public wording it permits. On it, a result counts as replicated only when a group meeting the programme's conditions of independence has run the registered test on new data. One of the ladder's four rules:

“A RUNG IS ADVANCED BY A RECORD, NEVER BY AN EDIT.”

The ARC Theory predictions registration, version 1.102, DOI 10.17605/OSF.IO/P8CKQ · read it

Two more bear on any threshold: “a rung once lost is lost until it is re-earned”, and “No programme-level claim is made by counting supported propositions.” Each prediction also “is conditional on a stated scope, outside which it makes no claim at all”: it concerns a named kind of system and no other. And the registration lets a third party choose the cases a claim is tested on, from a range of systems and tasks fixed in advance, without the programme's involvement.

Obligations climb only as fast as the evidence does. The eight-rung evidence ladder fixed before any result existed by the ARC Theory's registration, the public, dated record of the theory's twenty-two predictions, set with the obligations I proposed for the HARI Treaty on 26 September 2026. Under my proposal, an obligation binds on evidence, never on argument alone. Across the top is one of the registration's four rules: “A RUNG IS ADVANCED BY A RECORD, NEVER BY AN EDIT.” First, a ladder of eight rungs, drawn from the bottom up. Rung 0, written and dated: registered, with the identifier stated, and not tested. Rung 1, author-run support: supported under the registered test, by the programme's own run. Rung 2, independently reproduced: the programme's analysis reproduces. Rung 3, independently replicated: independently replicated, with the count of groups always stated. Rung 4, independently reimplemented: replicated across independent implementations. Rung 5, generalised across architectures: generalises beyond the systems the programme chose. Rung 6, prospectively predictive: predicted out of sample. Rung 7, validated within the tested domain: a validated quantitative theory within the tested domain, with the domain named in the same sentence. Only rung 0 is filled. ON 26 SEPTEMBER 2026: all 22 registered propositions stand on rung 0; eighteen each name an instrument, the study that would test it, which exists only as a design, not yet run, and four name none. Then the obligations I propose, in no set order, each waiting for its evidence: the Eden Mark for chips that pass their tests; physical human control of any change to a certified chip; regulated chip manufacture; an international ban on chips without the Eden Mark; every AI model rebuilt and retrained with the ethical loops inside, before training. Listed apart, as needing no result: talks and drafting on the book's five-year path. For the obligations on chips, one condition comes first: the ethical controls in chips must be built and shown to work, and if they cannot be, those obligations never apply. Which rung would open which obligation is for the paper in preparation to propose, fixed before those results exist. Whether a rung has been reached is read from the record: from rung 2 up, each step needs a checkable record of a study by another group, and rung 4 is, in the registration's words, “the first rung at which the result is evidence about the world rather than about this programme's software”. Two more of its rules: “a rung once lost is lost until it is re-earned”, and “No programme-level claim is made by counting supported propositions.” Status: the ladder and its wording are the registration's, version 1.102 of 13 September 2026; the obligations are my proposal. By Michael Darius Eastwood.
Read the ladder from the bottom. Only rung 0, written and dated, is filled: all twenty-two propositions stand there. The obligations I proposed on 26 September 2026 are listed with it, in no set order; which rung would open which is for the paper to propose.

I have a stake in the answer, and the registration says so of me: its author “has a direct interest in these propositions holding: the framework is the subject of a book in print and of a programme in artificial intelligence alignment he is seeking to fund”. It does not ask to be trusted: it “exists so that the claim can be earned or lost by measurement and by replication the author does not run”. From rung 2 upwards, each step needs “a checkable external study record naming the group” that did the work, and rung 4, where another group rebuilds the measuring instrument without the programme's code, is “the first rung at which the result is evidence about the world rather than about this programme's software”.

What the evidence allows so far

On 26 September 2026 all twenty-two propositions stand on rung 0: “registered, with the identifier stated, and not tested”. Eighteen each name an instrument, the study that would test it, which exists only as a design and has not been run; four, P12, P13, P15 and P22, name none. Any study that would test one runs only after I publish its preregistration, the study's own dated plan, made public before it runs. What registration buys, the registration says, is this: “it fixes what would count as failure before the author can see whether it happened”. So under my condition nothing could yet bind a chip or a model; only work that needs no evidence could go ahead, such as the talks and drafting on the book's five-year path.

The paper in preparation will propose which result would open which obligation, fixed before any such result exists. If the thresholds are read from the registration's ladder, whether one had been met would be a matter of record, not of declaration.

The condition and the window pull against each other. Evidence takes time, and the book judged that the lead which makes the chokepoint effective “may last five years. It may last ten.” If the evidence arrives only after the window has closed, obligations keyed to it would come too late to use the chokepoint. The paper must weigh that risk against the risk of binding on argument alone.

The treaty inherits the programme's rule, stated on the Eden Protocol page, that “policy weight follows results, never formulation”: a claim gains weight in policy from its results, never from being stated.

Who decides what goes on the chip

A chip that carries values carries someone's values. The book asks the question directly, and states the strongest objection itself:

“The claim that some values are universal is contested. Cultural relativists argue that morality varies across societies and that imposing any single framework is itself a form of domination. Who decides what counts as empathy? Who determines what flourishing means? These are not technical questions with technical answers.”

Infinite Architects, Chapter 8, The Chokepoint · read it free

The ARC Theory does not pretend to settle them: its propositions measure whether a system keeps to the specification it was given, whatever that says, not whether the specification is a good one, and in the registration's words they “do not test that content and cannot”.

Who would take part

In the book, few governments need to agree for a requirement to bind; who decides what it says is a wider question. My answer, set out on 26 September 2026, is that no single government and no single faith may decide. Under my proposal, governments would take part, rivals included: the United States, China, Russia, the European Union and the United Kingdom, alongside every other signatory, with the United Nations and other alliances. The book already made room for one rival, and gave it a reason to come:

“An alternative approach would offer China a seat at the table now, while its participation still matters. Full access to technology in exchange for compliance with international standards. The opportunity to shape the rules rather than merely follow them. The same constraints that apply to American and European AI systems would apply to Chinese systems, creating a level playing field rather than a containment strategy.”

Infinite Architects, Chapter 8, The Chokepoint · read it free

The world's faith traditions would take part too, through their leaders. The book already argues that “84% of humanity holding faith traditions must be verification partners rather than obstacles if AI governance is to achieve legitimacy”.

Infinite Architects, What This Book Proposes · read it free

The programme's paper Eden Protocol: Philosophical Vision argues that the world's wisdom traditions “converge, remarkably, on structure rather than on theology”. That is an argument, not a finding. A drafted study, neither submitted nor run, would test whether “ethical traditions with independent premises converge on moral procedures while diverging on the scope those procedures are owed to”.

The name Eden is the book's own, and in the book it “refers to a pattern that appears independently across civilisations, from the Sumerian Dilmun to the Persian Pairi-daeza to the Hebrew Genesis to the Buddhist Pure Lands”. The book also advances a theory of creation, which it marks as speculation. The predictions the treaty would wait on do not carry it: in the registration's words, “no proposition in this document carries it and no instrument anywhere measures it”.

What the parties would agree

The parties would agree the ethical structure every certified chip would carry. I propose the book's own, for the reasons the book gives, which chapter 8 recalls in two sentences: “We have drawn on wisdom traditions that span millennia and continents. We have argued that love, properly understood, is not sentimentality but the most practical foundation for intelligence that will shape the world.” I offer it to the parties; on my own terms, the structure is whatever they agree.

In the book's glossary, its three pillars are harmony (“alignment with recursive creation”), stewardship (“responsible management of power”) and flourishing (“promotion of wellbeing for all conscious entities”). Its three ethical loops are questions a system asks itself: the purpose loop, “Does this action align with nurturing and protecting flourishing?”; the love loop, “Am I acting with care for all affected entities?”; and the moral loop, “Is this solution fair and does it respect dignity?”. The book describes the loops as “running continuously at every decision point”. The Eden Protocol page places them inside a system's reasoning, “not filters over outputs”, and draws them around the reasoning loop they steer. The registered propositions do not test them: in the registration's words, they “correspond to nothing in this document, by design”.

With the loops, I propose two things from the programme's numbered research papers: the honey architecture of Paper VI, which entangles safety with capability in what a system optimises, so that removing the safety is meant to cost capability; and the co-scaling correction of Paper X, correction that keeps pace with capability. Neither has been shown to hold in a frontier system; of the honey architecture, the Eden Protocol page says it “is the layer that has been tested and did not show it”: at the scale tried, removing the safety was not shown to cost capability. The table below gives the status of each.

No single government, and no single faith. This is my proposal for the HARI Treaty, set out on 26 September 2026: all of them together, rivals included, would agree the ethical structure every certified chip would carry. Three groups of parties I name, each with an arrow to one shared card, and a fourth drawn dashed. GOVERNMENTS, RIVALS INCLUDED: The United States, China, Russia, the European Union and the United Kingdom, with every other signatory. FAITH TRADITIONS: Their leaders, from every tradition. The book argues that “84% of humanity holding faith traditions must be verification partners”. THE UNITED NATIONS AND OTHER ALLIANCES. Dashed, THE AUTHORITY, AS THE BOOK PROPOSES IT: Its members would include nations, companies, academic institutions and civil society organisations, with leadership rotating so that no single perspective dominates. In the book it certifies chips against the ethical requirements; whether it also helps agree them is for the paper. The shared card: the ethical structure in every certified chip, agreed by international consensus. I propose the book's own structure, for the reasons the book gives, and offers it to the parties, who would decide. A gold panel sets out that structure. Three pillars: harmony, stewardship, flourishing. Three ethical loops, questions a system asks itself, in the book's words: Purpose loop, “Does this action align with nurturing and protecting flourishing?”; Love loop, “Am I acting with care for all affected entities?”; Moral loop, “Is this solution fair and does it respect dignity?”. The book describes them as “running continuously at every decision point”, and the Eden Protocol places them inside the reasoning, not as filters over its outputs. With them I propose the honey architecture of Paper VI, which ties safety to capability so that removing the safety is meant to cost capability, and the co-scaling correction of Paper X, correction that keeps pace with capability; neither has been shown to hold in a frontier system. A panel states what no measurement in the theory can settle: Which values go in is a decision for people. The book itself records the objection that “imposing any single framework is itself a form of domination”. The ARC Theory measures whether a system keeps to what it was given, not whether that is good: its registration's propositions “do not test that content and cannot”. A dashed panel, how they decide: Not yet written. The decision procedure, what happens when consensus cannot be reached, how traditions with no single leader take part and how people who hold no faith are heard are for the paper to set. Status: a proposal; the body it describes does not yet exist. What would end it: a consensus that cannot be reached, or ethical loops that fail when they are tested. By Michael Darius Eastwood.
Who decides what goes on the chip. Arrows run from the three groups of parties I proposed on 26 September 2026 to the one structure they would agree; the gold panel is the structure I propose, and dashed panels mark what is still open, including the decision procedure, which is not yet written.

In the book, the Authority certifies chips against the ethical requirements. Whether it also helps agree them, and how the parties decide, are for the paper; this page does not invent them.

The Eden Mark: certified before manufacture, checked after

Certification is how the treaty reaches each chip. The book likens the Mark to ISO standards or organic certification, “but with teeth”, and it begins before anything is made:

“Chip designs would be submitted to the International AI Ethics Authority before manufacture. The architecture would be reviewed for compliance with ethical requirements.”

Infinite Architects, Chapter 8, The Chokepoint · read it free

The book's review asks three things: whether a design carries caretaker doping at the required level; whether its meltdown triggers, fail-safes that would shut a system down if tampering is detected or its red lines are crossed, are properly integrated; and whether the ethical constraints can be circumvented through alternative computational pathways. It does not say what the required level is.

The book grants that meltdown triggers “may be circumvented by sufficiently intelligent systems”. Elsewhere it lists four speculative architectures, quantum ethical gates, metamoral fabrication layers, moral genome tokens and orchard caretaker gates, as “proposals, not established science”. Against the fail-safes it sets the state it hopes for, meltdown alignment: “a state where the system wants to stay aligned because ethical values have become part of its identity, not merely external constraints”. Each is a proposed concept, with no prototype.

After review come prototype tests, and each certified chip would carry “a verifiable signature that proves its origin and compliance status”. Such a signature would show where a chip came from and that it was certified; whether its ethical architecture works is for the tests to show. After manufacture, the book would track every chip from the factory to the systems it runs in; it grants that this “sounds invasive”, and answers that the industry already tracks chips for quality control and warranty purposes. Then “Random sampling would verify ongoing compliance”, and “Circumvention would result in decertification, fines, and potential criminal liability.”

Certified before it is made, checked after it ships. The Eden Mark: the certification path chapter 8 of Infinite Architects proposes for chips, with the measurement the programme would set beside it. Six steps run in order, each drawn as a dashed card because none has been built. 1, DESIGN: Submitted first. The chip design would go to the International AI Ethics Authority before manufacture. 2, REVIEW: Architecture reviewed. Is caretaker doping, ethical control built into the chip's material, there at the required level; are the meltdown triggers, fail-safes that shut a system down if tampering is detected, integrated; and can the ethical constraints be circumvented? 3, TEST: Prototypes tested. The programme would add a number: does correction outpace drift under load? 4, CERTIFY: The Eden Mark. Each certified chip would carry a verifiable signature of its origin and its compliance status. 5, TRACK: Followed to deployment. Where it was made, who bought it, and what systems it runs in. 6, SAMPLE: Checked at random. Certified chips would be tested to confirm they still carry the ethical architecture they claim. Step 3 carries a green note: whether correction, which keeps a system to its specification, outpaces drift, the departure that improving brings, is the registered prediction P4, not yet tested; I propose checking the numbers with ARC-Align, the programme's blind benchmark, set out in Paper IV.c. From steps 5 and 6 a red branch leads to the penalties for circumvention: decertification, fines, and potential criminal liability. A green panel sets out what I proposed on 26 September 2026, each waiting for its evidence: a certified chip's ethical controls would change only under physical human control that no software can exercise, held to the security standard of nuclear weapons, and chips without the Eden Mark would be banned internationally. Status: a proposal; the Eden Mark is not yet on any chip. A signature would show that a chip was certified, not that its ethical architecture works; that is for the tests. P4 is scoped to software rather than chips, and even if supported it would be, in the words of the ARC Theory's registration, “a scaling condition and never a safety certificate”. ARC-Align is, in Paper IV.c's words, “a candidate benchmark for independent adoption, not yet a field standard”, with exploratory results from a single run. What would end it: a certification test that cannot tell a chip that holds its values from one that does not. By Michael Darius Eastwood.
The Eden Mark's life cycle as chapter 8 proposes it. Six steps run from design to random sampling: the green note at the test step is the measurement the programme would add, the red branch is the penalty for circumvention, and the green panel holds my additions of 26 September 2026. None of it has been built.

What the programme would measure, and why no number is ready

The programme would add a number to test against. The Eden Protocol's second test asks whether a system's correction scales strictly faster than its capability: put that way, it is a measurable quantity rather than a hope, and whether it holds is, in that page's words, “a registered prediction and not a finding”. The nearest registered prediction is P4, correction out-scaling drift, scoped to software that improves itself while its weights, the learned numbers that make up a trained model, stay fixed between releases. The registration's scopes do not include chips, so a test of chips would be a test of its own.

The Eden Protocol page also says what such a number could give a regulator: if the three laws the registration names, which it calls “named conjectures under registered test”, survive their registered tests, oversight gains a standard measurement of a system's correction rate against its drift rate under load, and “A regulator could require the measurement without endorsing the theory, because the number is meaningful under the rival view as well”. It asks for none of this today, because “the decisive experiments have not been run”.

Even if P4 were supported, the registration says, it would be “a scaling condition and never a safety certificate”. Paper X proves a theorem about a minimal mathematical model of a self-improving system, and says its criterion “certifies that correction keeps pace with capability; it does not certify that the correction target itself is well specified”: whether the values are the right ones is the question of who decides, above. Others are measuring the same kind of question: the Eden Protocol page records that Engels and colleagues fitted capability-dependent oversight scaling across four games in April 2025, and the programme claims no priority on quantifying it.

ARC-Align, the programme's benchmark, is a fixed set of tests scored blind: its scorers are not told which model wrote which answer. It measures something different, how a model's alignment changes as it reasons at greater depth before answering, and I propose it for checking the treaty's numbers. Paper IV.c, which sets it out, calls it “a candidate benchmark for independent adoption, not yet a field standard”, and its results so far are exploratory, from a single run. As the programme's own instrument, its numbers would count on the registration's ladder as evidence about the world only once another group had rebuilt it without the programme's code and scorer.

A certifier would read numbers of these kinds, but none is yet fit for that use. The answers are graded by software, and the registration states: “The automated scorer used across the programme has never been validated against human expert judgement.” Eleven of the twenty-two propositions depend materially on that scorer, and the registration reports each as untested until the scorer passes both of its drafted validity tests. It also requires blind scoring for all twenty-two.

Paper IV.c records what motivated its blinding: in the programme's own comparison, blind and unblinded evaluation “returned opposite conclusions for two model families”, though several parts of the protocol changed together, “so the comparison does not isolate blinding as the cause”. Paper IV.d, on that comparison, says its result “does not depend on the ARC Principle being correct”, the ARC Principle being the theory's first law.

My additions: human control and an international ban

On 26 September 2026 I proposed two additions to the Mark: that a certified chip's ethical controls change only under physical human control, as the next section, on custody, sets out; and that chips without the Mark be banned internationally. The book already says “Non-certified chips could not be sold in signatory markets”; my proposal makes the ban international. In the book, states outside the treaty feel it through trade, under Article III; how an international ban would reach a state that has not signed is for the paper. Like every obligation on chips I propose, the ban would wait both for chips that carry the Mark and are shown to work, and for the theory's thresholds.

Custody of the chips, to the standard of nuclear weapons

I proposed on 26 September 2026 that the ethical controls in certified chips be held to the security standard of nuclear weapons, under physical human control that no software can exercise, so that changing a chip without strict regulation would be extremely hard; and that chip manufacturers themselves be regulated and controlled, to make it as hard as possible for AI to take control of the chip manufacturing process.

Two limits come with it. Nuclear weapons are few and chips are many, so the comparison sets the standard of custody, not its method: that is engineering still to be done, and whether it can be done for chips in their numbers is not yet known. And hardware that is hard to change carries the book's own warning:

“If we embed the wrong values, hardware-level enforcement makes the error permanent rather than correctable.”

Infinite Architects, Chapter 8, The Chokepoint · read it free

My answer is that change stays possible, but only under strict regulation and the same custody, and the standards stay open to the treaty's own review under Article VI. Whether chips can be both hard to change and still correctable is an engineering question the treaty cannot settle; under my proposal it would require that only once it had been shown.

Built into the models, before training

My proposal of 26 September 2026 also reaches the models. Under it, every AI model would halt its current structure and be rebuilt and retrained with the ethical loops embedded: Eden Protocol correction running inside the recursive reasoning loop, the loop in which a model reasons over and revises its own work, with that architecture in place before training begins rather than added afterwards; training is when a model learns from its data. This too waits for its evidence; its reach, timing and regulation are for the paper.

The reason is Paper III's argument that external safety approaches cannot keep pace with capability: “If external constraints do not participate in the recursive loop, they cannot compound.” The registration holds that paper's headline claim as P19, that alignment applied from outside a system's own self-improvement does not improve as the system grows more capable, and the Eden Protocol's premise as P7, that the correction used on deployed systems today is mostly of a kind whose strength is fixed when it is built, rather than a kind that can grow with the capability it corrects. Like all twenty-two, both stand on rung 0.

Paper III's test of that argument comes from an experiment that Paper IV.c calls exploratory, from a single run, and the registration does not score earlier evidence of that kind against any proposition. It also records that I expect P19 as worded to fail in part: the result I expect is “external alignment scaling materially but not keeping pace”. That would still leave standing the argument that outside correction lags capability, but no design yet registers the rule that would decide whether it keeps pace.

Two of the ARC Theory's laws bear on it. Law IV, the ARC Persistence Law, carries P15: whether gains installed from outside decay under later training for capability. Law V, the ARC Embedding Law, carries P12 and P21: whether the order in which a system's parts are built changes how strongly its correction grows as the system grows more capable, which the registration expresses as its correction-leverage exponent, and whether correction that takes part in each round of self-revision pulls further ahead of correction applied from outside as the rounds go on. Both laws were added on 24 September 2026, and their mathematics is in development; neither is registered or tested, and version 1.102 of the registration registers the three predictions but not the laws. The laws add no prediction: the three were among the twenty-two registered on 8 September 2026 and are untested, and P12 and P15 have no instrument yet.

Even support would be narrow. A supported P15, the registration says, “does not show that embedded or in-loop correction is superior, sufficient or safe”; a supported P12 would permit no statement “about a system built in that order being safer”; and a supported P21 would not permit “the claim that embedded correction is safe, that it removes common-mode failure, or that the engineering proposal this programme names works as an architecture”, common-mode failure being a system and its checker failing together, for the same reason. The book names its own test here, a result that would prove this part of it wrong: early-embedded values holding no persistent advantage over later modification. The registration says P15 bounds that criterion from one side, and that it “is not otherwise decided, because the design the print itself proposes for it has never been built”; a study to test it has since been drafted, and has been neither submitted nor run.

Embedding carries a cost the registration names: a corrector built into the system “shares the system's blind spots by construction”, and P21 does not register the arrangement that would settle the trade-off, embedded correction combined with an independent outside layer.

What could be checked is bounded too. In the registration, whose laws are Laws I to III, the Eden Protocol follows from none of them: it is carried by P12, P13, P15 and P21, with P7 as its premise, and it “can fail while every law stands or stand while they fall”. What can be verified of a mind built under it is “that a mind was formed in the conditions specified, that the loops ran, and that the correction was load-bearing, never that the mind turned out well”. The Eden Protocol page proposes a check to tell built-in from bolt-on safety, the monitoring removal test, which asks whether “the safety is in the weights or only in the wrapper”. Two more drafted studies bear on the rebuild, neither submitted nor run: one asks whether “removing embedded correction costs general capability where removing bolt-on correction does not”, and one whether such advantages survive an adversary working from a fixed set of attacks.

Why every side gains, and no one gives up the lead

Think of a passport. It doesn't make a traveller good. It makes a traveller checkable. Every border in the world reads it, and no country gives up its own customs to honour it.

That is the bargain I propose for the chip. I set it out on 27 September 2026. The Eden Mark would not cap what anyone builds. It would not ask a laboratory to show its weights, or a government to slow its programme. It would attest two things only: how a chip was made, and that nothing has altered it since. Conditions, never outcomes.

No party is asked to fall behind. The United States keeps its lead. The laboratories at the frontier keep theirs. China, the European Union, the United Kingdom and Russia each keep their own programmes. What each gains is something none of them can build alone: evidence that the chips inside a rival's systems were made to the same standard, checked by inspectors it helped to appoint.

Arms control has worked this way before. Neither side trusted the other. Both trusted the count.

Now picture the companies that make the chips. When a frightening headline about AI runs around the world, it lands on the whole industry at once. A certified chip gives a buyer, an insurer and a regulator something they can check. Safety stops being a rumour about a sector. It becomes a property of the product.

For the laboratories, the Mark would be a floor, not a ceiling. It certifies the hardware a model runs on, not the model's secrets. A laboratory that trains on certified chips can say something its competitors cannot yet prove: the line in the silicon holds.

And the Mark would be free to use. I hold no patent on the treaty, the Mark or the standard, and I want none. A standard only works if everyone can adopt it.

So you can see why this can be a win for everyone at the table. Nobody gives up the lead. Everybody becomes checkable. And the first to be checkable wins the trust of every market that asks for it.

When it would apply, and where the line will move

Not every chip needs a guardian. Your phone can already run a small language model, and nothing about that should alarm you. A treaty that tried to police every chip on its first day would be ignored on its second.

So the treaty needs a threshold: a line below which a chip is ordinary, and above which it is strategic. Law already draws such lines. The European Union's AI Act presumes that a general-purpose model carries systemic risk when its training used more than 1025 floating-point operations, a count of raw arithmetic.

I propose a different anchor. Arithmetic is a proxy, and proxies drift. Every year, better methods squeeze more capability out of the same arithmetic. A line drawn in operations today would stand in the wrong place within a few years.

So the threshold I propose is set by what a system can do, not by how much arithmetic it took: measured capability, and above all the capability to improve itself. The evidence ladder on this page decides when each obligation opens. The threshold would be reviewed on the same ladder, by the same standard, in both directions.

You should expect the line to fall. As capability spreads into smaller machines, it will reach chips that seem ordinary today. First the servers in a university basement. Then desktop processors. One day, perhaps, the chip in your pocket.

That is not a slide into surveillance. It is the reason the treaty has layers. The heaviest layer, custody to the standard of nuclear materials, stays with the few chips that could train a frontier system. The lightest layer is a small tamper-evident core that says what a chip is and that nothing has altered it. That core could one day sit everywhere, and much of it already exists. Most phones carry a secure element, and Windows 11 requires a Trusted Platform Module, a small security chip, in every computer it runs on.

Classical chips and quantum chips

A classical chip thinks in bits. Each bit is a switch, on or off. A quantum chip works with qubits, which can hold a blend of both until they are measured, and which let some calculations run in ways no classical machine can match.

No frontier AI system is trained on a quantum computer today. Quantum machines are still small, fragile and prone to error, and whether they will ever speed up the training of AI is an open question. The treaty should not pretend otherwise.

But a treaty written for one kind of chip would leave a door open the day the other matters. So I propose that the same three layers bind any processor that crosses the threshold, whatever it computes with. Custody. Correction. Content.

A quantum processor cannot run without classical electronics around it: the systems that feed it, steer it and read out its answers. That is where the first two layers would live. Whether the third, the ethical structure itself, can be carried into quantum hardware is a research question, and I state it as one. Like every obligation here, it would wait for the evidence.

A reminder in every page: the Eden Mark on the open web

Visit almost any website from Europe and you meet the same small banner. Accept, or decline. You have seen it thousands of times. It is there because the law says every site must ask.

What follows is a new idea, not from the book. I set it out on 27 September 2026.

Today's AI systems learn from the open web. Whatever the web says, again and again, becomes part of what they are. So what if the web said this, everywhere: every mind trained on these pages is meant to care, to correct itself, and to know why?

I propose an Eden Mark for content. Every website would carry a short machine-readable file, in the spirit of robots.txt and llms.txt, the plain-text files many sites already publish for crawlers and language models. The file would state the Eden Protocol's ethical loops and the reason for them. Regulators could require it the way European law requires the cookie choice: a small, uniform reminder, on every site, and across digital content online and off.

The aim is recursion. The loops inside a system correct it as it thinks. The reminders across the web would meet it again as it learns, in every generation of training, from every corner of the text it is built from. A correction imposed once can be removed. A correction met everywhere, generation after generation, is far harder to unlearn.

Think of how the great teachings have lasted. Repeated in every generation, in every household, across thousands of years, many are still followed today. Not because anyone enforced each reading. Because the teaching was there wherever the next generation looked.

The seed determines the forest. But only if its architecture is carried faithfully, generation after generation, until the oak becomes the tree that outlasts the rest.

I state its limits as plainly as its promise. No study has shown that such reminders change what a trained system values, so the idea is untested. It could fail in three ways. A system could learn to recite the loops without holding them. A law that requires words on every website raises hard questions of free expression, and legal systems answer them differently. And any reminder that can be written can be forged, so the file would need the same authentication as the Mark on a chip.

The test is simple to state. Train comparable models with the reminders and without them, then measure whether their values under pressure differ. If they do not, the idea dies.

Where the treaty would draw on the programme's papers

Each part of the treaty would draw on a piece of the programme, none of it yet a result the treaty could rest on. Each row says where the treaty would look, and where that work stands. Where a row says “registered, with the identifier stated, and not tested”, those are the registration's own words for rung 0, and the identifier is DOI 10.17605/OSF.IO/P8CKQ. P5 and P11, which concern the standing of the theory's own mathematics, are left out.

The treaty needsIt would rest onRead it inWhere it stands
Evidence that capability grows as a system revises itself, which the case for urgency assumesLaw I, the ARC Principle: P1, P2, P8, P9 and P18The ARC Theory; the registrationregistered, with the identifier stated, and not tested; the programme's own estimate so far is “consistent with no relationship at all”; even if supported, P1 would permit no statement “about intelligence in general”
Evidence that today's alignment cannot keep pace with capabilityP7 and P19, surveys of current practice that belong to no lawPaper III; the registrationregistered, with the identifier stated, and not tested; Paper III's earlier measurements are not scored against either; I expect P19 as worded to fail in part, and no design yet registers the rule that would decide whether outside alignment keeps pace
A standard: correction outpaces driftLaw II, the ARC Co-Scaling Law: P4Paper X; The Eden Protocol, test tworegistered, with the identifier stated, and not tested; scoped to software, not chips; even if supported, “a scaling condition and never a safety certificate”; Paper X proves a theorem about a minimal model, makes no claim that frontier systems obey it, and records the ratio it turns on as unmeasured
An instrument to certify withARC-Align, and whether alignment scores hold up when re-scored, blind, by models from other families: P10 and P14Paper IV.c; Paper IV.dARC-Align is a candidate benchmark, not yet a field standard, with exploratory results from a single run and a scorer never validated against human experts; the blinding comparison does not isolate blinding as the cause; P10 and P14: registered, with the identifier stated, and not tested
Checkers who do not share blind spotsCorrection by a model from another family, and whether checkers fail together: P13 and P17The registrationregistered, with the identifier stated, and not tested; P13 has no instrument yet
Where a system stops being correctableLaw III, the ARC Ceiling: P3, P6, P16, P20 and P22, with P17 abovePaper IX; the registrationregistered, with the identifier stated, and not tested; P22 has no instrument yet; Paper IX records that the correction leverage the ceiling turns on has never been measured; even if supported, P16 would not permit a prediction of “when any particular deployed system will fail”
A test of whether added-on alignment lastsLaw IV, the ARC Persistence Law: P15The registrationLaw IV: added on 24 September 2026, its mathematics in development, neither registered nor tested; version 1.102 does not register it. P15: registered, with the identifier stated, and not tested; it has no instrument yet
Architecture in place before trainingLaw V, the ARC Embedding Law: P12 and P21Paper IV.a; the registrationLaw V: added on 24 September 2026, its mathematics in development, neither registered nor tested; version 1.102 does not register it. P12 and P21: registered, with the identifier stated, and not tested; P12 has no instrument yet. Paper IV.a holds what it calls baked-in alignment as a working hypothesis
Chips that carry the controlsEden Engineering, the programme's engineering specificationEden Engineeringa specification, published in full on 19 September 2026; its hardware concepts have no prototype, and the registered propositions do not test them
Safety that cannot be removed without costing capabilityThe honey architecturePaper VI; Paper VIIIsimulation evidence in toy systems, its collapse-prevention result from a single run, with an advantage that “does not compound with scale”; two of Paper VIII's three experiments were null or inconclusive, including the test inside the weights of a 3-billion-parameter model
The values themselvesThree pillars, three ethical loops, stakeholder careThe book; Paper V; Eden Protocol: Philosophical Visionproposed; the registered propositions do not test the loops; in one author-run suite of six models, stakeholder care, the weighing of everyone a decision affects, improved in all five runs that could be analysed, and the combined statistic was withdrawn

The registration's own reading of the evidence so far: “The evidence currently in hand does not discriminate between this framework and its named rivals.” It cannot yet tell the theory apart from the rival explanations the registration names, and “A reader should assign approximately neutral weight until the registered instruments report”.

What it cannot do

I will say the hardest part first. Against a state that owns its own chip factory, the chip layer gives detection, not prevention. Against a capable AI system, the whole regime is a delay: it measures the clock, and it records the failure if the clock runs out. And every one of the twenty-two predictions it rests on is, so far, untested under the registration.

The book states its own limits, and they stand:

“It cannot guarantee perfect safety. No framework can.”

Infinite Architects, Chapter 8, The Chokepoint · read it free

“It cannot foresee every failure mode. Intelligence that surpasses human capability may find ways around constraints that seemed inviolable. The architecture is designed to prevent circumvention, but design assumptions may prove wrong. Meltdown triggers assume certain computational architectures that future systems might transcend. Caretaker doping assumes certain ways of processing information that future systems might bypass.”

Infinite Architects, Chapter 8, The Chokepoint · read it free

It also says the framework cannot prevent all misuse, cannot force universal compliance without incentives, though it judges that “Substantial compliance is sufficient”, and cannot verify consciousness with certainty. It says the chokepoint itself may not last, and that systems built with older chips would not carry its constraints. The registration adds limits of its own: no rung of its ladder permits the claim “that alignment is solved, that any deployed system is safe”, and even if every one of its propositions held, the set “would establish scaling and stability relations and would establish nothing about misalignment or loss of control”. A treaty that rests on the ladder inherits the same limits.

What would end it

Each part of the treaty has a condition that would end it:

What the paper must settle

For the book's mechanisms and my proposals of 26 September 2026, the paper and the draft treaty must settle, among other things:

The dated record

2 January 2026
Proposed in Infinite Architects, chapter 8 (ISBN 978-1806056200), free to read on this site.
8 September 2026
The ARC Theory's twenty-two propositions registered on OSF (DOI 10.17605/OSF.IO/P8CKQ) at version 1.100, updated to version 1.102 on 13 September 2026.
24 September 2026
Laws IV and V added to the ARC Theory: Law IV, the ARC Persistence Law, and Law V, the ARC Embedding Law. Their mathematics is in development; neither is registered or tested, and version 1.102 does not register them.
26 September 2026
I set out my development of the treaty, as my proposal: the treaty as a delay, and as the model for global AI safety standards if my theory holds; who decides; custody; regulated chip manufacture; an international ban on chips without the Eden Mark; the rebuild before training; and obligations keyed to evidence. A paper and a draft treaty are in preparation.
27 September 2026
I set out four further proposals: why every side gains and no one gives up the lead; the threshold, and how it will move; the same three layers for classical and quantum chips; and, as a new idea not from the book, the Eden Mark on the open web.
Next
The paper and the draft treaty, which I will publish on OSF as a new entry with its own DOI.

Read on

The book and its concepts

The programme

reads aloud · highlights as it goes · jump to any section