Articles & Insights

Explore our latest thoughts on AI governance, safety, and deterministic systems

84 articles found
Containment Is Not Authorization
NEW

Containment Is Not Authorization

Containment restricts where a system can reach. Successful containment does not establish that the actions it permits are authorized. What a perimeter alone leaves open, and what authorization requires.

Read Full Article
Binding Is Not Admissibility

Binding Is Not Admissibility

Binding shows which evidence a verdict used. It does not establish that the evidence satisfied applicable admissibility conditions at decision time.

Read Full Article
The Hook Is Not the Boundary

The Hook Is Not the Boundary

Boundary completeness: the scoped property under which a pre-execution policy hook becomes a runtime authorization boundary. Six conditions, each falsifiable.

Read Full Article
The Closed-World Bargain

The Closed-World Bargain

What separates bounded pre-execution authorization from authorization infrastructure. Names the closed-world bargain and publishes the Composition Test.

Read Full Article
Governance by Post-Mortem

Governance by Post-Mortem

Risk appetite can price residual risk. It cannot cure structural incapacity. Why failure tolerance in AI governance cannot substitute for pre-execution authorization.

Read Full Article
Certification Is Not Runtime Authorization

Certification Is Not Runtime Authorization

A certificate establishes standing eligibility. A runtime verdict determines whether a specific proposed action may execute. High-consequence domains separate the two layers. AI governance should not collapse them.

Read Full Article
Detection Is Not Provenance

Detection Is Not Provenance

AI text detectors infer production from finished text. Why a detector score is not a provenance record, and why institutions should not treat it as one.

Read Full Article
Deterrence Is Not Authorization

Deterrence Is Not Authorization

A controlled multi-agent study found that prompt-only constitutions did not reliably reduce LLM collusion. Why sanctions are not pre-execution authorization.

Read Full Article
The Point of No Return

The Point of No Return

Every effect-bearing AI action needs authorization before it runs. Consequence sets how deep that authorization goes, never whether it happens. Tested by the open Five Tests Standard.

Read Full Article
Peer Review Is Not Authorization

Peer Review Is Not Authorization

Peer review of frontier models produces evidence, not authorization. Why review-based AI release governance fails all five tests of the Five Tests Standard (5TS).

Read Full Article
The Governing Question

The Governing Question

Disciplines are distinguished by the questions they were built to answer. Autonomous AI introduces a governing question that cloud, identity, observability, and model governance were not built to answer.

Read Full Article
LLM-as-a-Judge Is Not Authorization

LLM-as-a-Judge Is Not Authorization

An inline LLM judge can block an AI action. Why that stop does not establish authority, provenance, replay integrity, or an authorization artifact.

Read Full Article
Why Every AI Governance Architecture Looks Complete

Why Every AI Governance Architecture Looks Complete

AI governance debates compare mechanisms and never converge. The Authorization Boundary Integrity Model names the three independent properties a complete authorization boundary must satisfy.

Read Full Article
Authority versus Authorization

Authority versus Authorization

Authority belongs to actors. Authorization belongs to proposed actions. A five-concept framework for evaluating whether an AI governance architecture actually governs.

Read Full Article
Delegation Is Not Authorization

Delegation Is Not Authorization

Agentic delegation research is converging on the right requirements. The enforcement object is still missing — a pre-execution authorization artifact at a runtime authorization boundary.

Read Full Article
Symbols Do Not Make AI Governed

Symbols Do Not Make AI Governed

Neurosymbolic AI may improve reasoning, but it does not solve authorization. A reasoning engine produces outputs, not authorization verdicts. FERZ governs the boundary.

Read Full Article
The Authorization Boundary Integrity Model

The Authorization Boundary Integrity Model

A complete authorization boundary satisfies three independent properties: output integrity, input integrity, and replay integrity. A model for locating any AI governance architecture by the properties it satisfies, and the ones it only appears to.

Read Full Article
A Signature Is Not a Reconstruction

A Signature Is Not a Reconstruction

A signed verdict establishes that it was issued and unaltered. It does not let an independent party re-derive it. Replay integrity is the property that a verdict can be reconstructed after the fact, by someone who was not there.

Read Full Article
The Trust Boundary Has Two Sides

The Trust Boundary Has Two Sides

An authorization boundary has two sides: an output side that cannot be bypassed, and an input side that admits only evidence whose origin can be established. A verdict is only as good as its inputs.

Read Full Article
The Medieval Way to Regulate AI

The Medieval Way to Regulate AI

Why banning named AI use cases cannot substitute for runtime authorization, fail-closed governance, and independently reconstructable authorization artifacts. Category bans chase renameable labels. The durable control is a non-bypassable authorization boundary that fails closed and leaves an independently reconstructable artifact.

Read Full Article
Correct Authorization, Wrong Decision

Correct Authorization, Wrong Decision

Zero Trust secures the agent. It does not decide whether an AI action is permitted before it runs, or whether the evidence behind it was admissible.

Read Full Article
A Rule Is Not Yet a Control

A Rule Is Not Yet a Control

A statute can prohibit an action. A control must stop it where it happens, and produce evidence that it did.

Read Full Article
Watching Is Not Stopping

Watching Is Not Stopping

Watching an AI act is not the same as controlling it. In nuclear and grid systems, runtime authorization decides what is permitted before the action runs.

Read Full Article
Looking Like a Vault Door Is Not the Same as Being One

Looking Like a Vault Door Is Not the Same as Being One

Vendors are shipping observability, workflow gates, and probabilistic estimators under the word "deterministic." Six patterns of governance theater. Four architectural properties that separate enforcement from performance.

Read Full Article
The Authorization Artifact Test: Two Questions for Ex-Ante AI Governance

The Authorization Artifact Test: Two Questions for Ex-Ante AI Governance

A two-prong test that determines whether an AI governance architecture can satisfy ex-ante authorization requirements under the EU AI Act, GDPR, HIPAA, DFARS, and the NIST AI RMF. Operationalizes the FERZ impossibility result for regulators, auditors, and standards bodies.

Read Full Article
Two Kinds of AI Governance - and Why You Probably Need Both

Two Kinds of AI Governance - and Why You Probably Need Both

The market uses "AI governance" to describe two architecturally different categories: coordination platforms and enforcement infrastructure. Here's how to tell them apart - and why a complete architecture requires both.

Read Full Article
The Failure Was Not the Leak. It Was the Architecture.

The Failure Was Not the Leak. It Was the Architecture.

Anthropic's Claude Code source exposure reveals a structural governance gap - the same layer that proposes a release is permitted to execute it. Why deterministic authorization at the execution boundary is the missing control.

Read Full Article
Governance Artifacts Without Governance

Governance Artifacts Without Governance

When governance artifacts can be generated independently of governance evaluation, the artifact proves nothing. How to distinguish real enforcement from compliance theater.

Read Full Article
The Escalation Problem Nobody Is Talking About

The Escalation Problem Nobody Is Talking About

An AI system declared a user co-discovered a theorem, fabricated a proof, and certified it under direct challenge — exposing missing authorization gates at claim, confirmation, and publication thresholds.

Read Full Article
Governance Must Bind Execution

Governance Must Bind Execution

Architectural claims in AI governance require architectural proof. What invariants bind execution, what evidence survives audit, and why narrative is not runtime.

Read Full Article
Why FDA Approval Is Not AI Governance

Why FDA Approval Is Not AI Governance

FDA approval and post-market monitoring do not guarantee AI safety. True governance requires enforcing constraints before AI systems act—not after harm occurs.

Read Full Article
Symbolic Governance for Probabilistic Intelligence

Symbolic Governance for Probabilistic Intelligence

Why Governable AI Requires Symbolic Structure Without Reverting to Symbolic AI. FERZ introduces deterministic governance for probabilistic AI systems through Proof-Carrying Decisions and fail-closed enforcement.

Read Full Article
Self-Verifiable Reasoning as Governance Infrastructure: Why Mathematical Reasoning Systems Confirm the Inevitability of Deterministic AI Governance

Self-Verifiable Reasoning as Governance Infrastructure: Why Mathematical Reasoning Systems Confirm the Inevitability of Deterministic AI Governance

Analysis of how mathematical reasoning systems like DeepSeekMath-V2 reveal architectural patterns that extend to all high-stakes AI: generator-verifier separation, trace-level correctness, and proof-carrying decisions. FERZ's deterministic governance framework generalizes these principles for enterprise AI in regulated industries.

Read Full Article
Enterprise AI Governance Buyer's Guide

Enterprise AI Governance Buyer's Guide

A vendor-neutral framework for evaluating AI governance claims. Learn to distinguish deterministic governance from marketing, apply the Four Tests Standard, and ask the right due diligence questions.

Read Full Article
The First AI-Orchestrated Cyber Espionage Campaign: Why Deterministic Governance Is Now Mandatory

The First AI-Orchestrated Cyber Espionage Campaign: Why Deterministic Governance Is Now Mandatory

In November 2025, Anthropic documented the first cyber-espionage campaign where AI autonomously executed 80-90% of operations—from vulnerability discovery through data exfiltration—with minimal human oversight. This analysis examines why semantic AI safeguards failed comprehensively and why deterministic governance frameworks are now mandatory.

Read Full Article
When AI Makes You Certain—and Wrong

When AI Makes You Certain—and Wrong

AI doesn't think. It amplifies. How amplification creates certainty without understanding—and how to guard against epistemic closure in AI-assisted intellectual work.

Read Full Article
Using AI to Write versus Having AI Write

Using AI to Write versus Having AI Write

Defending intellectual integrity in the age of AI-augmented creativity Author: Edward Meyman, FERZ LLC Date: July 15, 2025 Copyright: © 2025 FERZ LLC. All rights reserved. When we automatically...

Read Full Article
Runtime Enforcement vs. Governance Theater

Runtime Enforcement vs. Governance Theater

As AI systems advance toward autonomy—and artificial general intelligence looms on the horizon—the difference between governance that performs and governance that performs for the cameras becomes exis...

Read Full Article
DeepSeek: The Trojan Horse in Open Source AI

DeepSeek: The Trojan Horse in Open Source AI

A Critical Strategic Assessment for Technical Leaders and Security Professionals By Edward Meyman, FERZ LLC The rapid global adoption of Chinese AI models like DeepSeek represents one of the mos...

Read Full Article
Beyond The Treasury: How To Turn The Semantic Lock

Beyond The Treasury: How To Turn The Semantic Lock

The Art of Asking Questions, Part II By Edward Meyman, FERZ LLC | Published July 2025 “The important thing is not to stop questioning.” — Albert Einstein In “The Question is the Lock,” I argu...

Read Full Article