Research Corpus

FERZ research argues that AI governance is an enforcement problem, not a monitoring problem. The corpus develops this thesis across four areas: the impossibility of observability-based authorization, the authorization framework that follows from that result, the architectural substrates that make authorization work in practice, and the broader taxonomy of governance approaches and their failure modes. All papers are open-access through the Zenodo FERZ community.

Synthesis and Foundations

Begin with the unified monograph and synthesis paper. The sections below develop specific claims and provide standards and supporting materials.

Deterministic AI Governance

A Unified Derivation of the Runtime Authorization Boundary, Authorization Artifact, Integrity Model, and Five Tests Standard

Edward Meyman·Edition described: v1.2·September 2026Monograph

The unified monograph. Consolidates the corpus into one account of deterministic AI governance: the enforcement thesis, the runtime authorization boundary, the three-verdict space, the authorization artifact, and the Five Tests Standard, with a glossary of the corpus vocabulary.

DOI: 10.5281/zenodo.22017421

Symbolic Governance for Probabilistic Intelligence

Edward Meyman·Edition described: v3.0.0·September 2026Paper

Argues that governable AI requires separating proposal generation from authorization as distinct control functions, and that the properties authorization needs belong to the authorizing arrangement rather than to any technology label. Distinguishes authorization artifact validity from permission and states requirements for independent reconstruction under a declared replay mode.

DOI: 10.5281/zenodo.18072965

Impossibility

The theoretical foundation. Under the stated assumptions of the impossibility result, observability alone cannot produce an artifact that satisfies ex-ante authorization; the works here state that result, its operational test, and its general form.

On the Impossibility of Observability-Based Authorization

A Formal Impossibility Result for Ex-Ante AI Governance

Edward Meyman·Edition described: v1.4.0·June 2026Technical note

Establishes a formal impossibility result: under its stated assumptions, observability alone cannot produce an artifact that satisfies the ex-ante authorization requirement imposed by a regulatory regime. The theoretical foundation of the FERZ corpus.

DOI: 10.5281/zenodo.19647542

Observability Is Not Enforcement

A Doctrinal Framework for Distinguishing Compliance Instrumentation from Runtime Authorization in AI Governance Architectures

Edward Meyman·Edition described: v2.0.0·August 2026Paper

Names the structural conflation of compliance instrumentation with runtime authorization, and draws the doctrinal line between supervision-class and authorization-class systems.

DOI: 10.5281/zenodo.18663864

The Authorization Artifact Test

Applying the Impossibility Result to Ex-Ante Authorization Requirements

Edward Meyman·Edition described: v1.2·August 2026Paper

States the two-prong Authorization Artifact Test: before execution, whether a verdict exists; and whether that verdict can be reconstructed by an independent third party without access to the governed system. Operationalizes the impossibility result for ex-ante regulatory regimes.

DOI: 10.5281/zenodo.20013582

The Authorization Non-Substitution Principle

A General Result for Pre-Execution AI Governance

Edward Meyman·Edition described: v1.0·August 2026Paper

States a general non-substitution result for pre-execution AI governance and supplies a three-question screen for classifying mechanisms offered as substitutes for authorization.

DOI: 10.5281/zenodo.22017004

Authorization

The architectural framework. What authorization is, where it sits in the execution path, and what its required properties are.

Execution-Time Authorization for AI Agents

A Formal Framework for Deterministic Governance Boundaries

Edward Meyman·Edition described: v3.1·September 2026Paper

Defines execution-time authorization as a deterministic enforcement layer that evaluates canonicalized action instances against versioned policy and governed system state prior to execution, producing a replayable authorization verdict.

DOI: 10.5281/zenodo.18764561

From Monitoring to Authorization

The Structural Shift in Agentic AI Governance

Edward Meyman·Edition described: v1.2·August 2026Paper

Names the structural shift in AI governance as systems move from content generation to autonomous execution. The governance problem changes from observing behavior to authorizing action.

DOI: 10.5281/zenodo.18743974

The Authorization Threshold

Edward Meyman·Edition described: v1.1.0·July 2026Paper

Defines the threshold at which AI action requires authorization rather than supervision. Governance is a property of specific decisions made under specific constraints, and only derivatively a property of systems in general.

DOI: 10.5281/zenodo.19270986

Authorization Discipline

The Missing Link Between Governing Judgment and Runtime Authorization

Edward Meyman·Edition described: v2.0·August 2026Paper

Defines authorization discipline as the institutional practice of converting governing judgment into approved, versioned, authority-traced inputs consumed by a runtime authorization boundary. Locates the upstream obligation on which runtime authorization depends.

DOI: 10.5281/zenodo.19225391

The Override Asymmetry

Edward Meyman·Edition described: v2.2·September 2026Paper

Examines ABSTAIN with governed escalation and authorized human resolution. Human resolution supplies authority-bound input for evaluation; authority to emit the operative verdict remains with the runtime authorization boundary.

DOI: 10.5281/zenodo.19772248

The Authorization Boundary

What MCP and AI Gateways Do Not Establish for Regulated Agentic AI

Edward Meyman·Edition described: v3.1·2026Paper

Defines the authorization boundary for agentic AI systems in regulated environments and examines what MCP and AI gateways do not establish. They are execution-path components; they do not, on their own, satisfy the authorization requirement.

DOI: 10.5281/zenodo.18612065

The Authorization Boundary Integrity Model

Edward Meyman·Edition described: v1.2·September 2026Technical note

Defines three orthogonal integrity properties of an authorization boundary: output integrity, input integrity, and replay integrity, with input binding as the substrate beneath them. Orthogonality is load-bearing: holding one property implies nothing about the others.

DOI: 10.5281/zenodo.20929115

The Closed-World Bargain

Edward Meyman·Edition described: v1.1·August 2026Paper

Defines when authorization qualifies as infrastructure: a scoped threshold claim, not a maturity ladder. Specifies reconstruction under both 5TS replay modes, the material-consumption requirement of the Composition Test, and fail-closed behavior across a declared execution-path scope with mandatory scope disclosure.

DOI: 10.5281/zenodo.21643658

Authority versus Authorization

A Definitional Framework for AI Governance

Edward Meyman·Edition described: v1.0·July 2026Paper

A definitional framework separating Authority, Delegation, Policy, Authorization, and Enforcement. Authority determines who may authorize; authorization determines whether a specific proposed action is permitted; enforcement determines whether that authorization governs execution.

DOI: 10.5281/zenodo.21341907

Standing Eligibility versus Runtime Authorization

A Definitional Distinction for AI Governance

Edward Meyman·Edition described: v1.0·August 2026Paper

Distinguishes standing eligibility, the entitlement to act in general, from runtime authorization of a specific proposed action, and argues that the former cannot substitute for the latter at execution time.

DOI: 10.5281/zenodo.21941656

Evidence Projection

One Authorization Boundary, Many Jurisdictional Presentations

Edward Meyman·Edition described: v2.0.0·August 2026Paper

Derives jurisdiction-specific evidentiary presentations from a single authorization artifact, subject to the limits of the source decision: a projection must remain traceable to the artifact and its bound materials, versioned, reconstructable, and scoped to the regime and evidence question it addresses, and derivation alone confers none of the source artifact's integrity properties.

DOI: 10.5281/zenodo.20277841

Detection Is Not Provenance

Why an AI detector score is evidence about production, not a record of the production process

Edward Meyman·Edition described: v1.1·August 2026Paper

Distinguishes a detector's classification of a finished artifact from a record of how it was produced. Detection is posterior evidence about production; provenance is a record of the production process, and the one cannot stand in for the other.

DOI: 10.5281/zenodo.21881429

The Governing Question

Edward Meyman·Edition described: v1.0·July 2026Paper

Archival edition of the canonical web essay published at ferz.ai/articles/the-governing-question, cited by the monograph as a corpus source.

DOI: 10.5281/zenodo.21650448

Architecture

Research into the substrates authorization depends on: verification methods, audit-stable meaning, and cross-organizational alignment.

Cross-Agent Governance Alignment (CAGA)

Verifiable Coordination Across Private AI Governance Domains

Edward Meyman·Edition described: v2.0·August 2026Paper

A problem formalization for cross-organizational AI governance: how autonomous agents operating under distinct, private policy regimes can verify mutual governance compatibility without disclosing the underlying policies. The CAGA evidence artifact is not an authorization artifact; it enters authorization only through each domain's local runtime authorization boundary.

DOI: 10.5281/zenodo.18761409

Type-Theoretic Formal Methods in AI Governance

Edward Meyman·Edition described: v1.0·January 2026Paper

The role of dependent types, refinement types, and proof-carrying code in the governance of AI systems deployed in regulated industries. Type-theoretic methods are verification substrates within authorization frameworks, not authorization frameworks in themselves.

DOI: 10.5281/zenodo.18371224

Taxonomy and Failure Modes

The broader category. How to distinguish what is and is not governance, where governance is multi-dimensional, and how to identify the failure modes that compliance architectures exhibit.

A Taxonomy of AI Governance Approaches

Distinguishing Visibility, Alignment, and Authorization

Edward Meyman·Edition described: v1.7.1·August 2026Paper

Distinguishes three different problems collected under the label AI governance: operational visibility, behavioral alignment, and decision authorization. FERZ research addresses decision authorization.

DOI: 10.5281/zenodo.18275969

Layering Is Not Authorization

Edward Meyman·Edition described: v1.0·September 2026Technical note

Examines the claim that stacking guardrails, filters, and monitors amounts to authorization. Adding checks does not, by itself, establish a runtime authorization boundary: aggregated non-objection, a PASS from each participating layer, does not change PASS into ALLOW.

DOI: 10.5281/zenodo.22267761

The Hook Is Not the Boundary

Boundary Completeness in Pre-Execution Authorization

Edward Meyman·Edition described: v1.0·August 2026Technical note

Distinguishes an interception hook from the authorization boundary. A hook governs only the paths that pass through it; boundary completeness requires that every execution path to a governed effect is subject to pre-execution authorization.

DOI: 10.5281/zenodo.22180242

Governance by Post-Mortem

Why Risk Tolerance Cannot Substitute for Pre-Execution Authorization

Edward Meyman·Edition described: v1.0·August 2026Paper

Names governance by post-mortem: the pattern in which an organization relies on post-execution observation as the operative control for a requirement that depends on pre-execution authorization. States the control-sufficiency precondition that risk-appetite language cannot displace.

DOI: 10.5281/zenodo.21997073

Deterrence Is Not Authorization

Edward Meyman·Edition described: v1.1·August 2026Paper

Draws the category line between deterrence and authorization using a controlled study of governed LLM agents. A sanction prices a violation after the fact; authorization forecloses it before release of the proposed act.

DOI: 10.5281/zenodo.21825696

LLM-as-a-Judge Is Not Authorization

Locating the Inline-Judge Pattern under the Authorization Boundary Integrity Model and the Five Tests Standard

Edward Meyman·Edition described: v1.0·July 2026Technical note

Examines the use of a language model as an evaluator of proposed AI actions. A judge model produces an assessment; it does not constitute a runtime authorization boundary, and its output does not satisfy the authorization artifact requirement.

DOI: 10.5281/zenodo.21462978

Peer Review Is Not Authorization

Edward Meyman·Edition described: v1.0·July 2026Paper

Examines peer review offered in place of pre-execution authorization, as one of the corpus's non-substitution results. Review produces an assessment of the work; it does not produce a pre-execution verdict at a runtime authorization boundary.

DOI: 10.5281/zenodo.21722297

Standards and Technical Notes

The Five Tests Standard, its explanatory paper and conformance materials, and the authorization artifact advisory.

The Five Tests Standard (5TS)

FERZ, Inc.·Edition described: v1.2.0·2026Standard

The published standard and conformance repository, archived release. Specifies the five normative tests, Stop, Ownership, Replay, Escalation, and Provenance, and the proof-carrying decision object. Repository: github.com/edmeyman/4ts-standard.

DOI: 10.5281/zenodo.21040295

ABIM Evidence Requirements

Evidence for Output, Input, and Replay Integrity Conclusions. A Supplement to The Enterprise AI Governance Buyer's Guide

FERZ, Inc.·Edition described: v3.5·August 2026Supplement

The evidence procedure for ABIM property conclusions: scope declarations, thresholds, failure witnesses, and not-established states for Output, Input, and Replay Integrity.

DOI: 10.5281/zenodo.22117938