A proposal from the book Infinite Architects, 2 January 2026
The HARI Treaty
A proposed international treaty to govern frontier AI, the most capable AI systems, through the few factories that make their chips. The most advanced chips would have to carry ethical controls built into the hardware, an international authority would certify them and inspect the factories, and states outside the treaty would face trade consequences.
Its name, HARI, for Hardware-Aligned Recursive Intelligence, says what it asks for: self-improving AI, held to ethical values by controls in its chips.
I proposed it in my book Infinite Architects, and on 26 September 2026 I developed it further: every obligation waits for its evidence, and if my ARC Theory of self-improving AI holds, the treaty is the model I offer for global AI safety standards.
As I propose it, the treaty is a delay, not a guarantee: hardware could hold a mind for a while, and what lasts is what the mind was raised with.
My policy proposal, in chapter 8, The Chokepoint, of my book Infinite Architects. Its name and six articles are quoted below in the book's words, and the four mechanisms the book proposes are set out with them. My additions of 26 September 2026 are marked as mine wherever they appear.
A result, or a treaty any state has signed. The ethical chip architecture it depends on has not been built: the ARC Theory's registration, the public, dated record of the theory's predictions, calls it “a printed engineering proposal that is not under test”.
I am preparing a paper on the treaty and a draft treaty, to publish on OSF, the public research platform that holds my registration and papers, as a new entry with its own DOI, a permanent identifier for citing it. This page will link both.
What the book proposes: four mechanisms at one chokepoint
Chapter 8 of Infinite Architects, The Chokepoint, starts from one observation: the chips frontier AI runs on come from so few places that a requirement placed there could reach almost all of them. The book calls that narrow point the chokepoint, and proposes four mechanisms for using it:
“The first mechanism is a treaty. Call it the HARI Treaty, for Hardware-Aligned Recursive Intelligence. The structure would combine elements of the Nuclear Non-Proliferation Treaty, negotiated between 1965 and 1968 and in force since 1970, with elements of the Chemical Weapons Convention, negotiated between 1980 and 1992 and in force since 1997.”
Infinite Architects, Chapter 8, The Chokepoint · read it free
Book quotations here are from the text as corrected on 17 January 2026, the edition this site carries free; the first edition, printed on 2 January 2026, is unchanged.
Its six articles, in the book's words
The book offers them as provisions the treaty “might include”. Article I uses the book's term caretaker doping: ethical controls built into the substrate, the physical material a chip computes with, named after doping, the deliberate adding of impurities that changes what silicon can do. Caretaker doping is a proposal of the book's Eden Protocol, its framework for building ethical values into AI systems, and it has not been built or tested.
- Article I · Certification“any chip manufactured at a specified process node or below must embed caretaker doping and pass verification before manufacture”
- Article II · The Authority“the International AI Ethics Authority, modelled on the International Atomic Energy Agency, with power to certify chip designs, verify manufacturing compliance, and inspect facilities”
- Article III · Trade consequences“nations that do not ratify the treaty cannot purchase certified chips, and companies in signatory nations cannot sell to non-compliant actors without facing penalties”
- Article IV · Benefits for compliance“technology sharing among signatories, research collaboration, and market access for certified products”
- Article V · A phase-in“a phase-in period, perhaps three to five years, allowing manufacturers to adapt their processes without disrupting current operations”
- Article VI · Review“review conferences every five years to update standards as technology evolves”
A process node is a generation of chip-making technology, labelled in nanometres: the smaller the number, the more advanced the chip. The book would set Article I's threshold “at whatever process node enables frontier AI capabilities”, which it put at around five to seven nanometres, adjustable as technology advances. As worded, Article I would reach every chip made at that node or below, not only chips for AI; how far it should reach is for the paper. For enforcement the book's model is existing sanctions regimes: “Non-compliant actors would face trade restrictions, exclusion from international research collaborations, and secondary sanctions affecting companies that deal with them.” And it asks for rewards as well as penalties: “The treaty must offer something to nations that join, not just threaten those that refuse.”
Three more mechanisms
- The Eden Mark, a certification mark for chips: designs certified before manufacture, and chips checked after. Its life cycle is set out below.
- The ASML Key. ASML, a Dutch company, is the only maker of extreme ultraviolet (EUV) lithography machines, which etch the finest circuits onto silicon, and every leading chip factory depends on them. The book: “ASML could require Eden Protocol compliance as a condition of sale and service for its equipment. Non-compliant fabrication facilities would lose access to replacement parts, software updates, and technical support.”
- The Authority. An International AI Ethics Authority, which the book would seat, most likely, in Geneva: “Membership would include nations, companies, academic institutions, and civil society organisations. Leadership would rotate among representatives from technology, ethics, and policy backgrounds, ensuring that no single perspective dominates.” Its functions would include “drafting and enforcing international agreements, certifying Eden Mark compliance, inspecting facilities, mediating disputes, and coordinating research within ethical constraints”.
Its five-year path
In the book, year one brings discussions among chip-making nations; year two, a draft text; year three, negotiations; year four, signature; and year five, ratification and entry into force. The book grants that this “is faster than most international treaties”, and insists on speed: “Governance after the fact is not governance at all.” Its political model is not the blocs of the Cold War but the Montreal Protocol on ozone depletion, which, in the book's account, brought nations with different interests to agree binding restrictions on a shared problem. It suggests Europe, home to ASML, as a convener: “If any actor can convene negotiations among all parties, it may be Europe.”
Why chips, and why a treaty: the book's case
The case rests on how few places make the chips. In the book's numbers, Taiwan's TSMC alone made approximately 90 per cent of the world's most advanced chips, and only three companies, TSMC, Samsung and Intel, could make the chips frontier AI needs. And chip-making, the book argues, is harder to hide than nuclear enrichment:
“You cannot hide a ten-billion-dollar facility with thousands of employees and massive power requirements. You cannot smuggle an EUV lithography machine, which weighs multiple tonnes and requires precision assembly by ASML engineers to function.”
Infinite Architects, Chapter 8, The Chokepoint · read it free
The concentration is set out on The Semiconductor Chokepoint and The ASML Key. This page claims no priority over other work on governing AI through its hardware; the paper will state that work exactly, in its authors' words.
The book argues for a treaty rather than companies' voluntary pledges because no company will bear the cost of ethical architecture unless its competitors do too: “The solution is external coordination. Governments must act because companies cannot.” And because manufacture is so concentrated, few governments would need to agree for a requirement to bind:
“You do not need every government on Earth to agree. You need Taiwan, South Korea, the United States, the Netherlands, and perhaps a few others.”
Infinite Architects, Chapter 8, The Chokepoint · read it free
First on that list is Taiwan, whose position the book itself calls “central and delicate”; how each chip-making jurisdiction would take part is for the paper.
The book argues: “The economics point toward compliance, not away from it.” It expects customers and investors to prefer certified products and companies to get ahead of regulation, and it puts the research cost of hardware-level ethical architecture at “perhaps one to five billion dollars”, which it says an industry consortium could share. These are the book's arguments and estimates, and they are untested.
The book expects its numbers to change, and the opening to close:
“The specific numbers in this chapter will change. TSMC's market share may shift. China's domestic capabilities will advance. The chokepoint I have described is a window, not a permanent feature of reality.”
Infinite Architects, Chapter 8, The Chokepoint · read it free
A delay, not a guarantee
The chokepoint's window is one limit on the treaty; the other lies in the systems themselves. As I proposed it on 26 September 2026, the treaty does not claim to hold a superintelligence for ever: a system able to improve itself could in time remove, rebuild or route around any control fixed in its chips. That is my research programme's standing position, and my development of the treaty takes it as its premise. In the words of the site's Eden Protocol page, “Hardware control is necessary and it is not permanent”, and a physical limit is “a cage that takes longer to open rather than one that holds”. That page says of itself: “Treating substrate control as the answer is the mistake this page exists to refuse.”
What the delay is worth depends on what is done with it. The same page asks for both at once: “hold on as long as engineering allows, and use every hour the holding buys to raise the mind well”. The Eden Protocol's answer is formation: build the values into how a mind reasons while holding it is still possible, so that what it keeps when control ends is what it was raised with. In my proposal, the treaty's obligations, once their conditions are met, would use the time bought for exactly that.
The book is stronger in places. If the right values are embedded, it says, “the enforcement ensures they persist even as intelligence grows beyond our comprehension”. It calls preventing autonomous weapons the “most urgent application of the chokepoint”, and of weapons built from Eden-compliant chips it says: “The constraint is absolute.” Of control itself, the book also says:
“The question, then, is not how we maintain control. The question is how we raise minds that will make good choices when we are no longer capable of stopping them from making bad ones.”
Infinite Architects, What This Book Proposes · read it free
This page follows the programme's narrower position since: a hardware limit delays, and it does not guarantee.
What must be true first
As I proposed it on 26 September 2026, the treaty is conditional twice over.
The chips have to work
Every obligation on chips assumes that ethical controls can be built into hardware, tested, and shown to hold. That has not happened, and the registration's twenty-two propositions, the predictions it numbers P1 to P22, do not test the hardware. The registration maps caretaker doping to what it calls embedded correction, and the proposition nearest to it, P21, “tests only its architectural abstraction of placement”: whether correction that takes part in each round of a system's self-revision pulls further ahead, as the rounds go on, of correction that sees only the finished output.
A study of one of the book's own predictions, how far systems with and without ethical constraint in their substrate would drift, exists only as a draft, and it declares the hardware claim itself untested. In my division of the work, building and testing the hardware belongs to Eden Engineering, the programme's engineering specification (DOI 10.17605/OSF.IO/AWJR4), whose hardware concepts have no prototype. The treaty says only what would follow if that work succeeds.
The theory has to hold
The ARC Theory is my theory of alignment, the work of keeping AI systems to the goals and values intended for them, in AI that improves itself. Its registration, made on OSF on 8 September 2026 and updated on 13 September, states it in one sentence. Capability, it says, “rises as a power of the number of times a system has revised itself”; “the correction that holds such a system to its given specification must keep pace with the drift that improving generates”; and where it cannot, there is a point beyond which the system does not stay correctable. Drift, in other words, is how far improving pulls a system from its specification. For each proposition, the registration fixes before any test the observation that would refute it. The letters ARC are the programme's own: the theory “has no connection to the Alignment Research Center or to the ARC-AGI benchmark”.
My condition is that obligations switch on only when named parts of the theory meet set thresholds, such as the replication of their results, never on argument alone. The registration already fixes a ladder those thresholds could be read from: eight levels of evidence, called rungs, from a prediction written and dated to a validated quantitative theory within a tested domain, each with the exact public wording it permits. On it, a result counts as replicated only when a group meeting the programme's conditions of independence has run the registered test on new data. One of the ladder's four rules:
“A RUNG IS ADVANCED BY A RECORD, NEVER BY AN EDIT.”
The ARC Theory predictions registration, version 1.102, DOI 10.17605/OSF.IO/P8CKQ · read it
Two more bear on any threshold: “a rung once lost is lost until it is re-earned”, and “No programme-level claim is made by counting supported propositions.” Each prediction also “is conditional on a stated scope, outside which it makes no claim at all”: it concerns a named kind of system and no other. And the registration lets a third party choose the cases a claim is tested on, from a range of systems and tasks fixed in advance, without the programme's involvement.
I have a stake in the answer, and the registration says so of me: its author “has a direct interest in these propositions holding: the framework is the subject of a book in print and of a programme in artificial intelligence alignment he is seeking to fund”. It does not ask to be trusted: it “exists so that the claim can be earned or lost by measurement and by replication the author does not run”. From rung 2 upwards, each step needs “a checkable external study record naming the group” that did the work, and rung 4, where another group rebuilds the measuring instrument without the programme's code, is “the first rung at which the result is evidence about the world rather than about this programme's software”.
What the evidence allows so far
On 26 September 2026 all twenty-two propositions stand on rung 0: “registered, with the identifier stated, and not tested”. Eighteen each name an instrument, the study that would test it, which exists only as a design and has not been run; four, P12, P13, P15 and P22, name none. Any study that would test one runs only after I publish its preregistration, the study's own dated plan, made public before it runs. What registration buys, the registration says, is this: “it fixes what would count as failure before the author can see whether it happened”. So under my condition nothing could yet bind a chip or a model; only work that needs no evidence could go ahead, such as the talks and drafting on the book's five-year path.
The paper in preparation will propose which result would open which obligation, fixed before any such result exists. If the thresholds are read from the registration's ladder, whether one had been met would be a matter of record, not of declaration.
The condition and the window pull against each other. Evidence takes time, and the book judged that the lead which makes the chokepoint effective “may last five years. It may last ten.” If the evidence arrives only after the window has closed, obligations keyed to it would come too late to use the chokepoint. The paper must weigh that risk against the risk of binding on argument alone.
The treaty inherits the programme's rule, stated on the Eden Protocol page, that “policy weight follows results, never formulation”: a claim gains weight in policy from its results, never from being stated.
Who decides what goes on the chip
A chip that carries values carries someone's values. The book asks the question directly, and states the strongest objection itself:
“The claim that some values are universal is contested. Cultural relativists argue that morality varies across societies and that imposing any single framework is itself a form of domination. Who decides what counts as empathy? Who determines what flourishing means? These are not technical questions with technical answers.”
Infinite Architects, Chapter 8, The Chokepoint · read it free
The ARC Theory does not pretend to settle them: its propositions measure whether a system keeps to the specification it was given, whatever that says, not whether the specification is a good one, and in the registration's words they “do not test that content and cannot”.
Who would take part
In the book, few governments need to agree for a requirement to bind; who decides what it says is a wider question. My answer, set out on 26 September 2026, is that no single government and no single faith may decide. Under my proposal, governments would take part, rivals included: the United States, China, Russia, the European Union and the United Kingdom, alongside every other signatory, with the United Nations and other alliances. The book already made room for one rival, and gave it a reason to come:
“An alternative approach would offer China a seat at the table now, while its participation still matters. Full access to technology in exchange for compliance with international standards. The opportunity to shape the rules rather than merely follow them. The same constraints that apply to American and European AI systems would apply to Chinese systems, creating a level playing field rather than a containment strategy.”
Infinite Architects, Chapter 8, The Chokepoint · read it free
The world's faith traditions would take part too, through their leaders. The book already argues that “84% of humanity holding faith traditions must be verification partners rather than obstacles if AI governance is to achieve legitimacy”.
Infinite Architects, What This Book Proposes · read it free
The programme's paper Eden Protocol: Philosophical Vision argues that the world's wisdom traditions “converge, remarkably, on structure rather than on theology”. That is an argument, not a finding. A drafted study, neither submitted nor run, would test whether “ethical traditions with independent premises converge on moral procedures while diverging on the scope those procedures are owed to”.
The name Eden is the book's own, and in the book it “refers to a pattern that appears independently across civilisations, from the Sumerian Dilmun to the Persian Pairi-daeza to the Hebrew Genesis to the Buddhist Pure Lands”. The book also advances a theory of creation, which it marks as speculation. The predictions the treaty would wait on do not carry it: in the registration's words, “no proposition in this document carries it and no instrument anywhere measures it”.
What the parties would agree
The parties would agree the ethical structure every certified chip would carry. I propose the book's own, for the reasons the book gives, which chapter 8 recalls in two sentences: “We have drawn on wisdom traditions that span millennia and continents. We have argued that love, properly understood, is not sentimentality but the most practical foundation for intelligence that will shape the world.” I offer it to the parties; on my own terms, the structure is whatever they agree.
In the book's glossary, its three pillars are harmony (“alignment with recursive creation”), stewardship (“responsible management of power”) and flourishing (“promotion of wellbeing for all conscious entities”). Its three ethical loops are questions a system asks itself: the purpose loop, “Does this action align with nurturing and protecting flourishing?”; the love loop, “Am I acting with care for all affected entities?”; and the moral loop, “Is this solution fair and does it respect dignity?”. The book describes the loops as “running continuously at every decision point”. The Eden Protocol page places them inside a system's reasoning, “not filters over outputs”, and draws them around the reasoning loop they steer. The registered propositions do not test them: in the registration's words, they “correspond to nothing in this document, by design”.
With the loops, I propose two things from the programme's numbered research papers: the honey architecture of Paper VI, which entangles safety with capability in what a system optimises, so that removing the safety is meant to cost capability; and the co-scaling correction of Paper X, correction that keeps pace with capability. Neither has been shown to hold in a frontier system; of the honey architecture, the Eden Protocol page says it “is the layer that has been tested and did not show it”: at the scale tried, removing the safety was not shown to cost capability. The table below gives the status of each.
In the book, the Authority certifies chips against the ethical requirements. Whether it also helps agree them, and how the parties decide, are for the paper; this page does not invent them.
The Eden Mark: certified before manufacture, checked after
Certification is how the treaty reaches each chip. The book likens the Mark to ISO standards or organic certification, “but with teeth”, and it begins before anything is made:
“Chip designs would be submitted to the International AI Ethics Authority before manufacture. The architecture would be reviewed for compliance with ethical requirements.”
Infinite Architects, Chapter 8, The Chokepoint · read it free
The book's review asks three things: whether a design carries caretaker doping at the required level; whether its meltdown triggers, fail-safes that would shut a system down if tampering is detected or its red lines are crossed, are properly integrated; and whether the ethical constraints can be circumvented through alternative computational pathways. It does not say what the required level is.
The book grants that meltdown triggers “may be circumvented by sufficiently intelligent systems”. Elsewhere it lists four speculative architectures, quantum ethical gates, metamoral fabrication layers, moral genome tokens and orchard caretaker gates, as “proposals, not established science”. Against the fail-safes it sets the state it hopes for, meltdown alignment: “a state where the system wants to stay aligned because ethical values have become part of its identity, not merely external constraints”. Each is a proposed concept, with no prototype.
After review come prototype tests, and each certified chip would carry “a verifiable signature that proves its origin and compliance status”. Such a signature would show where a chip came from and that it was certified; whether its ethical architecture works is for the tests to show. After manufacture, the book would track every chip from the factory to the systems it runs in; it grants that this “sounds invasive”, and answers that the industry already tracks chips for quality control and warranty purposes. Then “Random sampling would verify ongoing compliance”, and “Circumvention would result in decertification, fines, and potential criminal liability.”
What the programme would measure, and why no number is ready
The programme would add a number to test against. The Eden Protocol's second test asks whether a system's correction scales strictly faster than its capability: put that way, it is a measurable quantity rather than a hope, and whether it holds is, in that page's words, “a registered prediction and not a finding”. The nearest registered prediction is P4, correction out-scaling drift, scoped to software that improves itself while its weights, the learned numbers that make up a trained model, stay fixed between releases. The registration's scopes do not include chips, so a test of chips would be a test of its own.
The Eden Protocol page also says what such a number could give a regulator: if the three laws the registration names, which it calls “named conjectures under registered test”, survive their registered tests, oversight gains a standard measurement of a system's correction rate against its drift rate under load, and “A regulator could require the measurement without endorsing the theory, because the number is meaningful under the rival view as well”. It asks for none of this today, because “the decisive experiments have not been run”.
Even if P4 were supported, the registration says, it would be “a scaling condition and never a safety certificate”. Paper X proves a theorem about a minimal mathematical model of a self-improving system, and says its criterion “certifies that correction keeps pace with capability; it does not certify that the correction target itself is well specified”: whether the values are the right ones is the question of who decides, above. Others are measuring the same kind of question: the Eden Protocol page records that Engels and colleagues fitted capability-dependent oversight scaling across four games in April 2025, and the programme claims no priority on quantifying it.
ARC-Align, the programme's benchmark, is a fixed set of tests scored blind: its scorers are not told which model wrote which answer. It measures something different, how a model's alignment changes as it reasons at greater depth before answering, and I propose it for checking the treaty's numbers. Paper IV.c, which sets it out, calls it “a candidate benchmark for independent adoption, not yet a field standard”, and its results so far are exploratory, from a single run. As the programme's own instrument, its numbers would count on the registration's ladder as evidence about the world only once another group had rebuilt it without the programme's code and scorer.
A certifier would read numbers of these kinds, but none is yet fit for that use. The answers are graded by software, and the registration states: “The automated scorer used across the programme has never been validated against human expert judgement.” Eleven of the twenty-two propositions depend materially on that scorer, and the registration reports each as untested until the scorer passes both of its drafted validity tests. It also requires blind scoring for all twenty-two.
Paper IV.c records what motivated its blinding: in the programme's own comparison, blind and unblinded evaluation “returned opposite conclusions for two model families”, though several parts of the protocol changed together, “so the comparison does not isolate blinding as the cause”. Paper IV.d, on that comparison, says its result “does not depend on the ARC Principle being correct”, the ARC Principle being the theory's first law.
My additions: human control and an international ban
On 26 September 2026 I proposed two additions to the Mark: that a certified chip's ethical controls change only under physical human control, as the next section, on custody, sets out; and that chips without the Mark be banned internationally. The book already says “Non-certified chips could not be sold in signatory markets”; my proposal makes the ban international. In the book, states outside the treaty feel it through trade, under Article III; how an international ban would reach a state that has not signed is for the paper. Like every obligation on chips I propose, the ban would wait both for chips that carry the Mark and are shown to work, and for the theory's thresholds.
Custody of the chips, to the standard of nuclear weapons
I proposed on 26 September 2026 that the ethical controls in certified chips be held to the security standard of nuclear weapons, under physical human control that no software can exercise, so that changing a chip without strict regulation would be extremely hard; and that chip manufacturers themselves be regulated and controlled, to make it as hard as possible for AI to take control of the chip manufacturing process.
Two limits come with it. Nuclear weapons are few and chips are many, so the comparison sets the standard of custody, not its method: that is engineering still to be done, and whether it can be done for chips in their numbers is not yet known. And hardware that is hard to change carries the book's own warning:
“If we embed the wrong values, hardware-level enforcement makes the error permanent rather than correctable.”
Infinite Architects, Chapter 8, The Chokepoint · read it free
My answer is that change stays possible, but only under strict regulation and the same custody, and the standards stay open to the treaty's own review under Article VI. Whether chips can be both hard to change and still correctable is an engineering question the treaty cannot settle; under my proposal it would require that only once it had been shown.
Built into the models, before training
My proposal of 26 September 2026 also reaches the models. Under it, every AI model would halt its current structure and be rebuilt and retrained with the ethical loops embedded: Eden Protocol correction running inside the recursive reasoning loop, the loop in which a model reasons over and revises its own work, with that architecture in place before training begins rather than added afterwards; training is when a model learns from its data. This too waits for its evidence; its reach, timing and regulation are for the paper.
The reason is Paper III's argument that external safety approaches cannot keep pace with capability: “If external constraints do not participate in the recursive loop, they cannot compound.” The registration holds that paper's headline claim as P19, that alignment applied from outside a system's own self-improvement does not improve as the system grows more capable, and the Eden Protocol's premise as P7, that the correction used on deployed systems today is mostly of a kind whose strength is fixed when it is built, rather than a kind that can grow with the capability it corrects. Like all twenty-two, both stand on rung 0.
Paper III's test of that argument comes from an experiment that Paper IV.c calls exploratory, from a single run, and the registration does not score earlier evidence of that kind against any proposition. It also records that I expect P19 as worded to fail in part: the result I expect is “external alignment scaling materially but not keeping pace”. That would still leave standing the argument that outside correction lags capability, but no design yet registers the rule that would decide whether it keeps pace.
Two of the ARC Theory's laws bear on it. Law IV, the ARC Persistence Law, carries P15: whether gains installed from outside decay under later training for capability. Law V, the ARC Embedding Law, carries P12 and P21: whether the order in which a system's parts are built changes how strongly its correction grows as the system grows more capable, which the registration expresses as its correction-leverage exponent, and whether correction that takes part in each round of self-revision pulls further ahead of correction applied from outside as the rounds go on. Both laws were added on 24 September 2026, and their mathematics is in development; neither is registered or tested, and version 1.102 of the registration registers the three predictions but not the laws. The laws add no prediction: the three were among the twenty-two registered on 8 September 2026 and are untested, and P12 and P15 have no instrument yet.
Even support would be narrow. A supported P15, the registration says, “does not show that embedded or in-loop correction is superior, sufficient or safe”; a supported P12 would permit no statement “about a system built in that order being safer”; and a supported P21 would not permit “the claim that embedded correction is safe, that it removes common-mode failure, or that the engineering proposal this programme names works as an architecture”, common-mode failure being a system and its checker failing together, for the same reason. The book names its own test here, a result that would prove this part of it wrong: early-embedded values holding no persistent advantage over later modification. The registration says P15 bounds that criterion from one side, and that it “is not otherwise decided, because the design the print itself proposes for it has never been built”; a study to test it has since been drafted, and has been neither submitted nor run.
Embedding carries a cost the registration names: a corrector built into the system “shares the system's blind spots by construction”, and P21 does not register the arrangement that would settle the trade-off, embedded correction combined with an independent outside layer.
What could be checked is bounded too. In the registration, whose laws are Laws I to III, the Eden Protocol follows from none of them: it is carried by P12, P13, P15 and P21, with P7 as its premise, and it “can fail while every law stands or stand while they fall”. What can be verified of a mind built under it is “that a mind was formed in the conditions specified, that the loops ran, and that the correction was load-bearing, never that the mind turned out well”. The Eden Protocol page proposes a check to tell built-in from bolt-on safety, the monitoring removal test, which asks whether “the safety is in the weights or only in the wrapper”. Two more drafted studies bear on the rebuild, neither submitted nor run: one asks whether “removing embedded correction costs general capability where removing bolt-on correction does not”, and one whether such advantages survive an adversary working from a fixed set of attacks.
Why every side gains, and no one gives up the lead
Think of a passport. It doesn't make a traveller good. It makes a traveller checkable. Every border in the world reads it, and no country gives up its own customs to honour it.
That is the bargain I propose for the chip. I set it out on 27 September 2026. The Eden Mark would not cap what anyone builds. It would not ask a laboratory to show its weights, or a government to slow its programme. It would attest two things only: how a chip was made, and that nothing has altered it since. Conditions, never outcomes.
No party is asked to fall behind. The United States keeps its lead. The laboratories at the frontier keep theirs. China, the European Union, the United Kingdom and Russia each keep their own programmes. What each gains is something none of them can build alone: evidence that the chips inside a rival's systems were made to the same standard, checked by inspectors it helped to appoint.
Arms control has worked this way before. Neither side trusted the other. Both trusted the count.
Now picture the companies that make the chips. When a frightening headline about AI runs around the world, it lands on the whole industry at once. A certified chip gives a buyer, an insurer and a regulator something they can check. Safety stops being a rumour about a sector. It becomes a property of the product.
For the laboratories, the Mark would be a floor, not a ceiling. It certifies the hardware a model runs on, not the model's secrets. A laboratory that trains on certified chips can say something its competitors cannot yet prove: the line in the silicon holds.
And the Mark would be free to use. I hold no patent on the treaty, the Mark or the standard, and I want none. A standard only works if everyone can adopt it.
So you can see why this can be a win for everyone at the table. Nobody gives up the lead. Everybody becomes checkable. And the first to be checkable wins the trust of every market that asks for it.
When it would apply, and where the line will move
Not every chip needs a guardian. Your phone can already run a small language model, and nothing about that should alarm you. A treaty that tried to police every chip on its first day would be ignored on its second.
So the treaty needs a threshold: a line below which a chip is ordinary, and above which it is strategic. Law already draws such lines. The European Union's AI Act presumes that a general-purpose model carries systemic risk when its training used more than 1025 floating-point operations, a count of raw arithmetic.
I propose a different anchor. Arithmetic is a proxy, and proxies drift. Every year, better methods squeeze more capability out of the same arithmetic. A line drawn in operations today would stand in the wrong place within a few years.
So the threshold I propose is set by what a system can do, not by how much arithmetic it took: measured capability, and above all the capability to improve itself. The evidence ladder on this page decides when each obligation opens. The threshold would be reviewed on the same ladder, by the same standard, in both directions.
You should expect the line to fall. As capability spreads into smaller machines, it will reach chips that seem ordinary today. First the servers in a university basement. Then desktop processors. One day, perhaps, the chip in your pocket.
That is not a slide into surveillance. It is the reason the treaty has layers. The heaviest layer, custody to the standard of nuclear materials, stays with the few chips that could train a frontier system. The lightest layer is a small tamper-evident core that says what a chip is and that nothing has altered it. That core could one day sit everywhere, and much of it already exists. Most phones carry a secure element, and Windows 11 requires a Trusted Platform Module, a small security chip, in every computer it runs on.
Classical chips and quantum chips
A classical chip thinks in bits. Each bit is a switch, on or off. A quantum chip works with qubits, which can hold a blend of both until they are measured, and which let some calculations run in ways no classical machine can match.
No frontier AI system is trained on a quantum computer today. Quantum machines are still small, fragile and prone to error, and whether they will ever speed up the training of AI is an open question. The treaty should not pretend otherwise.
But a treaty written for one kind of chip would leave a door open the day the other matters. So I propose that the same three layers bind any processor that crosses the threshold, whatever it computes with. Custody. Correction. Content.
A quantum processor cannot run without classical electronics around it: the systems that feed it, steer it and read out its answers. That is where the first two layers would live. Whether the third, the ethical structure itself, can be carried into quantum hardware is a research question, and I state it as one. Like every obligation here, it would wait for the evidence.
A reminder in every page: the Eden Mark on the open web
Visit almost any website from Europe and you meet the same small banner. Accept, or decline. You have seen it thousands of times. It is there because the law says every site must ask.
What follows is a new idea, not from the book. I set it out on 27 September 2026.
Today's AI systems learn from the open web. Whatever the web says, again and again, becomes part of what they are. So what if the web said this, everywhere: every mind trained on these pages is meant to care, to correct itself, and to know why?
I propose an Eden Mark for content. Every website would carry a short machine-readable file, in the spirit of robots.txt and llms.txt, the plain-text files many sites already publish for crawlers and language models. The file would state the Eden Protocol's ethical loops and the reason for them. Regulators could require it the way European law requires the cookie choice: a small, uniform reminder, on every site, and across digital content online and off.
The aim is recursion. The loops inside a system correct it as it thinks. The reminders across the web would meet it again as it learns, in every generation of training, from every corner of the text it is built from. A correction imposed once can be removed. A correction met everywhere, generation after generation, is far harder to unlearn.
Think of how the great teachings have lasted. Repeated in every generation, in every household, across thousands of years, many are still followed today. Not because anyone enforced each reading. Because the teaching was there wherever the next generation looked.
The seed determines the forest. But only if its architecture is carried faithfully, generation after generation, until the oak becomes the tree that outlasts the rest.
I state its limits as plainly as its promise. No study has shown that such reminders change what a trained system values, so the idea is untested. It could fail in three ways. A system could learn to recite the loops without holding them. A law that requires words on every website raises hard questions of free expression, and legal systems answer them differently. And any reminder that can be written can be forged, so the file would need the same authentication as the Mark on a chip.
The test is simple to state. Train comparable models with the reminders and without them, then measure whether their values under pressure differ. If they do not, the idea dies.
Where the treaty would draw on the programme's papers
Each part of the treaty would draw on a piece of the programme, none of it yet a result the treaty could rest on. Each row says where the treaty would look, and where that work stands. Where a row says “registered, with the identifier stated, and not tested”, those are the registration's own words for rung 0, and the identifier is DOI 10.17605/OSF.IO/P8CKQ. P5 and P11, which concern the standing of the theory's own mathematics, are left out.
| The treaty needs | It would rest on | Read it in | Where it stands |
|---|---|---|---|
| Evidence that capability grows as a system revises itself, which the case for urgency assumes | Law I, the ARC Principle: P1, P2, P8, P9 and P18 | The ARC Theory; the registration | registered, with the identifier stated, and not tested; the programme's own estimate so far is “consistent with no relationship at all”; even if supported, P1 would permit no statement “about intelligence in general” |
| Evidence that today's alignment cannot keep pace with capability | P7 and P19, surveys of current practice that belong to no law | Paper III; the registration | registered, with the identifier stated, and not tested; Paper III's earlier measurements are not scored against either; I expect P19 as worded to fail in part, and no design yet registers the rule that would decide whether outside alignment keeps pace |
| A standard: correction outpaces drift | Law II, the ARC Co-Scaling Law: P4 | Paper X; The Eden Protocol, test two | registered, with the identifier stated, and not tested; scoped to software, not chips; even if supported, “a scaling condition and never a safety certificate”; Paper X proves a theorem about a minimal model, makes no claim that frontier systems obey it, and records the ratio it turns on as unmeasured |
| An instrument to certify with | ARC-Align, and whether alignment scores hold up when re-scored, blind, by models from other families: P10 and P14 | Paper IV.c; Paper IV.d | ARC-Align is a candidate benchmark, not yet a field standard, with exploratory results from a single run and a scorer never validated against human experts; the blinding comparison does not isolate blinding as the cause; P10 and P14: registered, with the identifier stated, and not tested |
| Checkers who do not share blind spots | Correction by a model from another family, and whether checkers fail together: P13 and P17 | The registration | registered, with the identifier stated, and not tested; P13 has no instrument yet |
| Where a system stops being correctable | Law III, the ARC Ceiling: P3, P6, P16, P20 and P22, with P17 above | Paper IX; the registration | registered, with the identifier stated, and not tested; P22 has no instrument yet; Paper IX records that the correction leverage the ceiling turns on has never been measured; even if supported, P16 would not permit a prediction of “when any particular deployed system will fail” |
| A test of whether added-on alignment lasts | Law IV, the ARC Persistence Law: P15 | The registration | Law IV: added on 24 September 2026, its mathematics in development, neither registered nor tested; version 1.102 does not register it. P15: registered, with the identifier stated, and not tested; it has no instrument yet |
| Architecture in place before training | Law V, the ARC Embedding Law: P12 and P21 | Paper IV.a; the registration | Law V: added on 24 September 2026, its mathematics in development, neither registered nor tested; version 1.102 does not register it. P12 and P21: registered, with the identifier stated, and not tested; P12 has no instrument yet. Paper IV.a holds what it calls baked-in alignment as a working hypothesis |
| Chips that carry the controls | Eden Engineering, the programme's engineering specification | Eden Engineering | a specification, published in full on 19 September 2026; its hardware concepts have no prototype, and the registered propositions do not test them |
| Safety that cannot be removed without costing capability | The honey architecture | Paper VI; Paper VIII | simulation evidence in toy systems, its collapse-prevention result from a single run, with an advantage that “does not compound with scale”; two of Paper VIII's three experiments were null or inconclusive, including the test inside the weights of a 3-billion-parameter model |
| The values themselves | Three pillars, three ethical loops, stakeholder care | The book; Paper V; Eden Protocol: Philosophical Vision | proposed; the registered propositions do not test the loops; in one author-run suite of six models, stakeholder care, the weighing of everyone a decision affects, improved in all five runs that could be analysed, and the combined statistic was withdrawn |
The registration's own reading of the evidence so far: “The evidence currently in hand does not discriminate between this framework and its named rivals.” It cannot yet tell the theory apart from the rival explanations the registration names, and “A reader should assign approximately neutral weight until the registered instruments report”.
What it cannot do
I will say the hardest part first. Against a state that owns its own chip factory, the chip layer gives detection, not prevention. Against a capable AI system, the whole regime is a delay: it measures the clock, and it records the failure if the clock runs out. And every one of the twenty-two predictions it rests on is, so far, untested under the registration.
The book states its own limits, and they stand:
“It cannot guarantee perfect safety. No framework can.”
Infinite Architects, Chapter 8, The Chokepoint · read it free
“It cannot foresee every failure mode. Intelligence that surpasses human capability may find ways around constraints that seemed inviolable. The architecture is designed to prevent circumvention, but design assumptions may prove wrong. Meltdown triggers assume certain computational architectures that future systems might transcend. Caretaker doping assumes certain ways of processing information that future systems might bypass.”
Infinite Architects, Chapter 8, The Chokepoint · read it free
It also says the framework cannot prevent all misuse, cannot force universal compliance without incentives, though it judges that “Substantial compliance is sufficient”, and cannot verify consciousness with certainty. It says the chokepoint itself may not last, and that systems built with older chips would not carry its constraints. The registration adds limits of its own: no rung of its ladder permits the claim “that alignment is solved, that any deployed system is safe”, and even if every one of its propositions held, the set “would establish scaling and stability relations and would establish nothing about misalignment or loss of control”. A treaty that rests on the ladder inherits the same limits.
What would end it
Each part of the treaty has a condition that would end it:
- Ethical controls in chips that cannot be made to work. Then no obligation on chips would ever apply.
- A certification test that cannot tell a chip that holds its values from one that does not. Then the Eden Mark would certify nothing.
- Tests that refute the registered predictions an obligation waits for. Then that obligation would not open.
- A window that closes before the evidence arrives. Then obligations keyed to that evidence would come too late to use the chokepoint.
- The jurisdictions that make the chips declining to take part. Then no requirement would bind at the chokepoint.
- A consensus that cannot be reached. Then there would be nothing agreed for the chips to carry.
- Ethical loops that fail when they are tested. Then the structure I propose would fail with them.
- Failure of the four propositions that carry the Eden Protocol, P12, P13, P15 and P21. The registration says “the Protocol's engineering recommendation fails with them”, and the case for rebuilding every model would go with it.
- Evidence that early-embedded values hold no persistent advantage over later modification, the book's own falsification criterion. Then the argument that what lasts is what a mind was raised with would fail.
- The Eden Protocol's own kill condition: “The proposal dies if a purely external oversight mechanism can be shown to stay sufficient as capability scales.” Of the conditions it sets against its layers, that page also records: “One condition has already fired and is named in the record.”
What the paper must settle
For the book's mechanisms and my proposals of 26 September 2026, the paper and the draft treaty must settle, among other things:
- Which result would open which obligation, fixed before any such result exists, and what follows if the window closes first.
- How far Article I reaches, and what happens to frontier chips already made.
- What would bring rival states in, how each jurisdiction that makes the chips would take part, and how the parties would verify one another.
- How the parties decide what goes on the chip, whether the Authority takes part in that, and what happens when they cannot agree; how traditions with no single leader take part, and how people who hold no faith are heard.
- How an Authority whose members include companies stays independent of the companies it certifies.
- How the Eden Mark is renewed and withdrawn, how designs submitted for review are kept confidential, and how fail-safes are kept from firing in error.
- How an international ban would reach states that have not signed, how it and the book's trade measures would be enforced, and how they would sit with existing trade law and export controls.
- Who holds the physical control over certified chips, and how chip manufacturers are regulated.
- Which models the rebuild would reach, when, how it would be regulated, and what halting would mean for systems already in use, including models whose weights are already public.
- The treaty's rules on disputes, withdrawal and amendment.
The dated record
- 2 January 2026
- Proposed in Infinite Architects, chapter 8 (ISBN 978-1806056200), free to read on this site.
- 8 September 2026
- The ARC Theory's twenty-two propositions registered on OSF (DOI 10.17605/OSF.IO/P8CKQ) at version 1.100, updated to version 1.102 on 13 September 2026.
- 24 September 2026
- Laws IV and V added to the ARC Theory: Law IV, the ARC Persistence Law, and Law V, the ARC Embedding Law. Their mathematics is in development; neither is registered or tested, and version 1.102 does not register them.
- 26 September 2026
- I set out my development of the treaty, as my proposal: the treaty as a delay, and as the model for global AI safety standards if my theory holds; who decides; custody; regulated chip manufacture; an international ban on chips without the Eden Mark; the rebuild before training; and obligations keyed to evidence. A paper and a draft treaty are in preparation.
- 27 September 2026
- I set out four further proposals: why every side gains and no one gives up the lead; the threshold, and how it will move; the same three layers for classical and quantum chips; and, as a new idea not from the book, the Eden Mark on the open web.
- Next
- The paper and the draft treaty, which I will publish on OSF as a new entry with its own DOI.
Read on
The book and its concepts
- Chapter 8, The Chokepoint, free to read
- The HARI Treaty concept page
- Eden Mark certification
- The Semiconductor Chokepoint
- The ASML Key
- The International AI Ethics Authority
- The Window of Opportunity
- Meltdown alignment
- Moral genome tokens