Caretaker Doping and the fourteen-month hardware convergence

3 min read · 641 words
Share:
Michael Darius Eastwood
Michael Darius Eastwood · Independent AI alignment researcher
Published
Michael Darius Eastwood · Hardware & Policy · 3 July 2026
Michael Darius Eastwood, independent researcher, London: originator of the embedded-correction alignment thesis (manuscript 8 December 2024, SHA-256 anchored: f0d1f38f).
Manuscript basis. The concept of Caretaker Doping was introduced in the April 30 2025 self-emailed manuscript (A2, SHA-256 09f5b5e1..., 562 pages, 140,406 words). Three independent hardware proposals implementing the same architectural conclusion followed inside fourteen months.
Register rows 7, 8 and 9. Sources on each row.

What Caretaker Doping proposes

The April 30 2025 manuscript coins the term to describe a class of substrate-level safeguards for AI compute. The core claim is that any safeguard living purely in software above the compute layer is trainable-around, because a sufficiently capable system can rewrite the software layer. Safeguards must therefore be "doped" into the substrate itself, in the same way a semiconductor is doped: added at fabrication, not applied on top. The manuscript's related term, Meltdown Triggers, names the fail-safe class of these safeguards, the ones that pull the compute if a policy is violated.

What happened next, from three unrelated directions

Row 9 of the convergence register: FlexHEG (arXiv:2506.15093), an ARIA-commissioned proposal for tamper-resistant guarantee processors that sit alongside AI accelerators. April 2025, concurrent with A2. Priority credited to Petrie, Aarne, Ammann and Dalrymple.

Row 8: Petrie's embedded off-switches paper (arXiv:2509.07637), September 2025. Thousands of independent deadman switches per accelerator, under 1% die overhead. Roughly four and a half months after A2.

Row 7: The Odeh patents (US 2026/0010411 and US 2026/0010780), filed July 2025, published January 2026. Runtime ethics gates as a discrete silicon block. Three to nine months after A2.

Three architectural bets. Same threat model. None of them cite each other or the manuscript.

What the convergence is, and what it is not

It is a structural convergence. Four independent authors or teams (one manuscript, three published proposals) arrived inside a fourteen-month window at the same architectural conclusion: policy must bind to silicon or it will not bind at all. That is meaningful because it constrains the design space; if only one team had reached this conclusion, it would be an idea; four converging on it is a research programme.

It is not a claim of derivation. None of the three published proposals cite the manuscript. None of the four authors, as far as we can tell, knew of each other's drafts at the time of writing. The manuscript is dated (Google-server-timestamped via Gmail Message-ID, DKIM verified in transit, SHA-256 published) so priority on the general concept can be verified. Priority on each specific architecture is credited to the specific authors of that architecture. The programme's rule throughout: name the artefact, name the source, do not claim causation you cannot prove.

What is worth checking

Download the redacted .eml of the April 30 2025 email from the evidence page. Run shasum -a 256 against it and match the hash. Open the three arXiv or USPTO links. Compare threat models. Note the publication dates. If any of the four look derivative rather than independent, the convergence claim comes off the register, publicly, the way the retracted scaling figure did in Paper III.

From the book Infinite Architects: Intelligence, Recursion, and the Creation of Everything by Michael Darius Eastwood.

Buy on Amazon UK Amazon US

Stay informed

New posts on AI alignment, convergence evidence, and the ARC/Eden research programme.

Get updates →