> For the complete documentation index, see [llms.txt](https://osintelligence-llc.gitbook.io/osintelligence/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://osintelligence-llc.gitbook.io/osintelligence/appendices/appendix-b-consolidated-references.md).

# Appendix B · Consolidated references

> **What this is.** Every chapter of the monograph closes with its own References & provenance page; this appendix aggregates those reference lists in one place, grouped by Part and chapter, so the full evidentiary base of the record can be surveyed and checked without walking twenty-four pages. Entries are reproduced verbatim from each chapter's own list; a citation that appears in several chapters appears here under each of them, because each chapter's citation context is its own.
>
> **What stays on the chapter pages.** Per-chapter AI-assistance disclosures, author contributions, data-availability statements, and the append-only System Update sections are provenance, not bibliography; they remain on each chapter's own provenance page, linked from every entry below.

### Part I · The architecture

#### Chapter 1 · The Sovereign Triad

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-i-the-architecture/1-the-sovereign-triad/appendix-a-prior-art-references-and-provenance.md)*.*

Ames, A. D., Coogan, S., Egerstedt, M., Notomista, G., Sreenath, K., & Tabuada, P. (2019). "Control Barrier Functions: Theory and Applications." *European Control Conference (ECC) 2019.*

Anderson, R. (2008). *Security Engineering: A Guide to Building Dependable Distributed Systems* (2nd ed.). Wiley.

Anil, C., et al. (2024). "Many-shot Jailbreaking." *NeurIPS 2024.*

Bai, Y., Kadavath, S., Kundu, S., et al. (2022). "Constitutional AI: Harmlessness from AI Feedback." [arXiv:2212.08073](https://arxiv.org/abs/2212.08073).

Bell, D. E., & LaPadula, L. J. (1973). *Secure Computer Systems: Mathematical Foundations.* MITRE Technical Report 2547.

Bengio, Y., Hinton, G., Yao, A., et al. (2023). "Managing AI Risks in an Era of Rapid Progress." [arXiv:2310.17688](https://arxiv.org/abs/2310.17688).

Beurer-Kellner, L., Fischer, M., & Vechev, M. (2023). "Prompting Is Programming: A Query Language for Large Language Models." *PLDI 2023.*

Biba, K. J. (1977). *Integrity Considerations for Secure Computer Systems.* MITRE Technical Report 3153.

Bommasani, R., Klyman, K., Longpre, S., et al. (2023). "The Foundation Model Transparency Index." Stanford CRFM. [arXiv:2310.12941](https://arxiv.org/abs/2310.12941).

Carlini, N., Nasr, M., Choquette-Choo, C. A., et al. (2023). "Are aligned neural networks adversarially aligned?" *NeurIPS 2023.* [arXiv:2306.15447](https://arxiv.org/abs/2306.15447).

Carlsmith, J. (2022). "Is Power-Seeking AI an Existential Risk?" Open Philanthropy report; [arXiv:2206.13353](https://arxiv.org/abs/2206.13353).

Chalmers, A. F. (1976). *What Is This Thing Called Science?* University of Queensland Press.

Christiano, P. F., Leike, J., Brown, T. B., et al. (2017). "Deep Reinforcement Learning from Human Preferences." *NIPS 2017.*

Clark, D. D., & Wilson, D. R. (1987). "A Comparison of Commercial and Military Computer Security Policies." *IEEE Symposium on Security and Privacy 1987.*

Desmedt, Y., & Frankel, Y. (1989). "Threshold Cryptosystems." *CRYPTO '89.*

European Union (2024). "Artificial Intelligence Act (Regulation 2024/1689)." [*Official Journal of the European Union.*](https://eur-lex.europa.eu/eli/reg/2024/1689/oj)

Greenblatt, R., Denison, C., Wright, B., et al. (2024). "Alignment Faking in Large Language Models." [arXiv:2412.14093](https://arxiv.org/abs/2412.14093).

Hinton, G. E., & Salakhutdinov, R. R. (2006). "Reducing the Dimensionality of Data with Neural Networks." *Science* 313(5786):504–507.

Hubinger, E., Denison, C., Mu, J., et al. (2024). "Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training." [arXiv:2401.05566](https://arxiv.org/abs/2401.05566).

IEC 61508 (2010). *Functional Safety of Electrical/Electronic/Programmable Electronic Safety-related Systems.* International Electrotechnical Commission.

Kashif, A., Hameed, A. M., & Iqbal, A. (2026). "Governance at the Edge of Architecture: Regulating NeuroAI and Neuromorphic Systems." [arXiv:2602.01503](https://arxiv.org/abs/2602.01503).

Khattab, O., et al. (2023). "DSPy: Compiling Declarative Language Model Calls into Self-Improving Pipelines." [arXiv:2310.03714](https://arxiv.org/abs/2310.03714).

Kindi, V., & Arabatzis, T. (Eds.) (2012). *Kuhn’s The Structure of Scientific Revolutions Revisited.* Routledge.

Klein, G., Elphinstone, K., Heiser, G., Andronick, J., Cock, D., Derrin, P., Elkaduwe, D., Engelhardt, K., Kolanski, R., Norrish, M., Sewell, T., Tuch, H., & Winwood, S. (2009). "[seL4: Formal Verification of an OS Kernel](https://doi.org/10.1145/1629575.1629596)." *SOSP 2009.*

Lakatos, I. (1970). "Falsification and the Methodology of Scientific Research Programmes." In *Criticism and the Growth of Knowledge*, eds. Lakatos, I. & Musgrave, A. Cambridge University Press.

Leroy, X. (2009). "Formal Verification of a Realistic Compiler." *Communications of the ACM* 52(7):107–115.

NIST (2023). [*Artificial Intelligence Risk Management Framework (AI RMF 1.0).*](https://doi.org/10.6028/NIST.AI.100-1) National Institute of Standards and Technology.

NIST SP 800-89 (2006). *Recommendation for Obtaining Assurances for Digital Signature Applications.* [National Institute of Standards and Technology](https://doi.org/10.6028/NIST.SP.800-89).

Nowaczyk, S. (2025). "Architectures for Building Agentic AI." [arXiv:2512.09458](https://arxiv.org/abs/2512.09458).

Ouyang, L., Wu, J., Jiang, X., et al. (2022). "Training Language Models to Follow Instructions with Human Feedback." [*NeurIPS 2022*](https://arxiv.org/abs/2203.02155) (InstructGPT).

Parno, B., McCune, J. M., & Perrig, A. (2010). *Bootstrapping Trust in Modern Computers.* Springer SpringerBriefs in Computer Science.

Pedersen, T. P. (1991). "Non-Interactive and Information-Theoretic Secure Verifiable Secret Sharing." *CRYPTO '91.*

Poesia, G., Polozov, O., Le, V., et al. (2022). "Synchromesh: Reliable Code Generation from Pre-trained Language Models." *ICLR 2022.* [arXiv:2201.11227](https://arxiv.org/abs/2201.11227).

Popper, K. R. (1959). *The Logic of Scientific Discovery* (English translation of Logik der Forschung, 1934). Hutchinson & Co.

Reason, J. (1990). *Human Error.* Cambridge University Press.

Sailer, R., Zhang, X., Jaeger, T., & van Doorn, L. (2004). "Design and Implementation of a TCG-based Integrity Measurement Architecture." *USENIX Security 2004.*

Saltzer, J. H., & Schroeder, M. D. (1975). "The Protection of Information in Computer Systems." *Proceedings of the IEEE* 63(9):1278–1308.

Schneier, B. (2000). *Secrets and Lies: Digital Security in a Networked World.* Wiley.

Sharma, M., et al. (2025). "Constitutional Classifiers: Defending against Universal Jailbreaks across Thousands of Hours of Red Teaming." [arXiv:2501.18837](https://arxiv.org/abs/2501.18837).

Shamir, A. (1979). "How to Share a Secret." *Communications of the ACM* 22(11):612–613.

Summers, A. E. (2013). *Safety Controls, Alarms, and Interlocks as Independent Protection Layers.* SIS-Tech Solutions.

Trusted Computing Group (2014). *TPM 2.0 Library Specification.* <https://trustedcomputinggroup.org/>

W3C (n.d.). *WebAssembly System Interface (WASI) Specification.* <https://wasi.dev/>

Wabersich, K. P., & Zeilinger, M. N. (2021). "A Predictive Safety Filter for Learning-Based Control." *Automatica* 129.

Wang, J., Yan, Q., Wang, Y., Tian, Y., Mishra, S. S., Xu, Z., Gandhi, M., Xu, P., & Cheong, L. L. (2025). "Reinforcement Learning for Self-Improving Agent with Skill Library." [arXiv:2512.17102](https://arxiv.org/abs/2512.17102).

Wei, A., Haghtalab, N., & Steinhardt, J. (2023). "Jailbroken: How Does LLM Safety Training Fail?" [arXiv:2307.02483](https://arxiv.org/abs/2307.02483). NeurIPS 2023.

Westfall, P. H., & Young, S. S. (1993). *Resampling-Based Multiple Testing: Examples and Methods for p-Value Adjustment.* Wiley.

Willard, B. T., & Louf, R. (2023). "Efficient Guided Generation for Large Language Models." [arXiv:2307.09702](https://arxiv.org/abs/2307.09702).

Yusuf, H. U., & Gaaloul, K. (2025). "Architectural Transformations and Emerging Verification Demands in AI-Enabled Cyber-Physical Systems." [arXiv:2510.00519](https://arxiv.org/abs/2510.00519).

Zhang, J., et al. (2025). "Darwin Gödel Machine: Open-Ended Evolution of Self-Improving Agents." [arXiv:2505.22954](https://arxiv.org/abs/2505.22954).

Zou, A., Wang, Z., Carlini, N., Nasr, M., Kolter, J. Z., & Fredrikson, M. (2023). "Universal and Transferable Adversarial Attacks on Aligned Language Models." [arXiv:2307.15043](https://arxiv.org/abs/2307.15043).

#### Chapter 2 · The External Sentinel

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-i-the-architecture/2-the-external-sentinel/references-and-provenance.md)*.*

Anderson, R. (2008). *Security Engineering: A Guide to Building Dependable Distributed Systems* (2nd ed.). Wiley.

Aumasson, J.-P. (2017). *Serious Cryptography: A Practical Introduction to Modern Encryption.* No Starch Press.

Bai, Y., Kadavath, S., Kundu, S., et al. (2022). "Constitutional AI: Harmlessness from AI Feedback." [arXiv:2212.08073](https://arxiv.org/abs/2212.08073).

Bell, D. E., & LaPadula, L. J. (1973). *Secure Computer Systems: Mathematical Foundations.* MITRE Technical Report 2547.

Bernstein, D. J., Duif, N., Lange, T., Schwabe, P., & Yang, B.-Y. (2012). "High-speed high-security signatures." *Journal of Cryptographic Engineering* 2(2):77–89 (Ed25519).

Biba, K. J. (1977). *Integrity Considerations for Secure Computer Systems.* MITRE Technical Report 3153.

Bommasani, R., Klyman, K., Longpre, S., et al. (2023). "The Foundation Model Transparency Index." Stanford CRFM. [arXiv:2310.12941](https://arxiv.org/abs/2310.12941).

Boneh, D., Lynn, B., & Shacham, H. (2001). "Short signatures from the Weil pairing." *Advances in Cryptology, ASIACRYPT 2001.* Springer LNCS 2248.

Bostrom, N. (2014). *Superintelligence: Paths, Dangers, Strategies.* Oxford University Press.

Bytecode Alliance (2024). *Wasmtime: A standalone runtime for WebAssembly.* <https://wasmtime.dev/>

Carlsmith, J. (2022). "Is Power-Seeking AI an Existential Risk?" Open Philanthropy report; [arXiv:2206.13353](https://arxiv.org/abs/2206.13353).

Christiano, P. F., Leike, J., Brown, T. B., et al. (2017). "Deep Reinforcement Learning from Human Preferences." NIPS 2017.

Christiano, P., Cotra, A., & Xu, M. (2021). "Eliciting Latent Knowledge: How to Tell If Your Eyes Deceive You." Alignment Research Center technical report.

Clark, D. D., & Wilson, D. R. (1987). "A Comparison of Commercial and Military Computer Security Policies." IEEE Symposium on Security and Privacy 1987.

European Union (2024). "Artificial Intelligence Act (Regulation 2024/1689)." [Official Journal of the European Union](https://eur-lex.europa.eu/eli/reg/2024/1689/oj).

European Union (2024). "Right to Repair Directive 2024/1799." [Official Journal of the European Union](https://eur-lex.europa.eu/eli/dir/2024/1799/oj).

Gödel, K. (1931). "Über formal unentscheidbare Sätze der Principia Mathematica und verwandter Systeme I." *Monatshefte für Mathematik und Physik* 38:173–198.

Greenblatt, R., Denison, C., Wright, B., et al. (2024). "Alignment Faking in Large Language Models." [arXiv:2412.14093](https://arxiv.org/abs/2412.14093).

Hadfield-Menell, D., Russell, S., Abbeel, P., & Dragan, A. (2016). "Cooperative Inverse Reinforcement Learning." NIPS 2016. [arXiv:1606.03137](https://arxiv.org/abs/1606.03137).

Hadfield-Menell, D., Dragan, A., Abbeel, P., & Russell, S. (2017). "The Off-Switch Game." IJCAI 2017.

Hendrycks, D., Carlini, N., Schulman, J., & Steinhardt, J. (2022). "Unsolved Problems in ML Safety." [arXiv:2109.13916](https://arxiv.org/abs/2109.13916).

Hubinger, E., Denison, C., Mu, J., et al. (2024). "Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training." [arXiv:2401.05566](https://arxiv.org/abs/2401.05566).

IEC 61508 (2010). *Functional Safety of Electrical/Electronic/Programmable Electronic Safety-related Systems.* International Electrotechnical Commission.

Islam, M. S., Alouani, I., & Khasawneh, K. N. (2024). "Hardware Support for Trustworthy Machine Learning: A Survey." 2024 25th International Symposium on Quality Electronic Design (ISQED). [DOI:10.1109/ISQED60706.2024.10528373](https://doi.org/10.1109/ISQED60706.2024.10528373).

ISO/IEC 11889 (2015). *Information technology, Trusted Platform Module Library (TPM 2.0)* (parts 1–4).

Juvenal (c. AD 100). *Satirae* (Satire VI), lines 347–348. "Sed quis custodiet ipsos custodes?"

Kistner, J. (2026). *Sixteen Practices for Sovereign Human-AI Collaboration: A Practitioner's Methodology Formalized.* OSINTelligence LLC.

Kistner, J. (2026). *The Sovereign Triad: An Architectural Ethics for Self-Improving AI Systems.* OSINTelligence LLC.

Klein, G., Elphinstone, K., Heiser, G., Andronick, J., Cock, D., Derrin, P., Elkaduwe, D., Engelhardt, K., Kolanski, R., Norrish, M., Sewell, T., Tuch, H., & Winwood, S. (2009). "seL4: Formal Verification of an OS Kernel." [SOSP 2009](https://doi.org/10.1145/1629575.1629596).

Kocaoğullar, C., Marjanov, T., Petrov, I., Laurie, B., Cutter, A., Kern, C., Hutchings, A., & Beresford, A. R. (2024). "Confidential Computing Transparency." [arXiv:2409.03720](https://arxiv.org/abs/2409.03720).

Lakatos, I. (1970). "Falsification and the Methodology of Scientific Research Programmes." In *Criticism and the Growth of Knowledge*, eds. Lakatos, I. & Musgrave, A. Cambridge University Press.

Lampson, B. W. (1973). "A Note on the Confinement Problem." *Communications of the ACM* 16(10):613–615.

Leroy, X. (2009). "Formal Verification of a Realistic Compiler." *Communications of the ACM* 52(7):107–115.

McDonald, G., & Bar Or, J. (2025). "Whisper Leak: A Side-Channel Attack on Large Language Models." [arXiv:2511.03675](https://arxiv.org/abs/2511.03675).

Montana Senate Bill 212 (2025). *Right to Compute Act.* Signed April 2025.

NIST (2023). [*Artificial Intelligence Risk Management Framework (AI RMF 1.0).*](https://doi.org/10.6028/NIST.AI.100-1) National Institute of Standards and Technology.

National Institute of Standards and Technology (2006). *Recommendation for Obtaining Assurances for Digital Signature Applications.* [NIST Special Publication 800-89](https://doi.org/10.6028/NIST.SP.800-89) (E. Barker).

Ouyang, L., Wu, J., Jiang, X., et al. (2022). "Training Language Models to Follow Instructions with Human Feedback." NeurIPS 2022 (InstructGPT).

Parno, B., McCune, J. M., & Perrig, A. (2011). *Bootstrapping Trust in Modern Computers.* Springer SpringerBriefs in Computer Science.

Plato (c. 380 BC). *Republic* Book III.

Popper, K. R. (1959). *The Logic of Scientific Discovery* (English translation of Logik der Forschung, 1934). Hutchinson & Co.

Reason, J. (1990). *Human Error.* Cambridge University Press.

Russell, S. (2019). *Human Compatible: Artificial Intelligence and the Problem of Control.* Viking.

Sailer, R., Zhang, X., Jaeger, T., & van Doorn, L. (2004). "Design and Implementation of a TCG-based Integrity Measurement Architecture." USENIX Security 2004.

Saltzer, J. H., & Schroeder, M. D. (1975). "The Protection of Information in Computer Systems." *Proceedings of the IEEE* 63(9):1278–1308.

Schneier, B. (2000). *Secrets and Lies: Digital Security in a Networked World.* Wiley.

Shamir, A. (1979). "How to Share a Secret." *Communications of the ACM* 22(11):612–613.

Summers, A. E. (2013). *Safety Controls, Alarms, and Interlocks as Independent Protection Layers.* SIS-Tech Solutions.

Trusted Computing Group (2014). *TPM 2.0 Library Specification* (parts 1–4). <https://trustedcomputinggroup.org/>

W3C (2019). *WebAssembly Core Specification.* W3C Recommendation. <https://www.w3.org/TR/wasm-core-1/>

Westfall, P. H., & Young, S. S. (1993). *Resampling-Based Multiple Testing: Examples and Methods for p-Value Adjustment.* Wiley.

#### Chapter 3 · Sovereign Safety Architecture

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-i-the-architecture/3-sovereign-safety-architecture/references-and-provenance.md)*.*

**Defense-in-depth:** Saltzer & Schroeder (1975). "The Protection of Information in Computer Systems." *Proc. IEEE* 63(9) · Schneier (2000). *Secrets and Lies.* Wiley · Reason (1990). *Human Error.* Cambridge UP · Perrow (1984). *Normal Accidents.* Princeton UP.

**Industrial/nuclear:** US NRC, defense-in-depth doctrine · IEC 61508 (2010) · Mosleh et al. (1988). NUREG/CR-4780 (common-cause failures).

**Trusted computing:** TCG (2014). TPM 2.0 Library Specification (ISO/IEC 11889) · Parno, McCune & Perrig (2010). *Bootstrapping Trust in Commodity Computers.* IEEE S\&P · Sailer et al. (2004). IMA. *USENIX Security* · Klein et al. (2009). [seL4](https://doi.org/10.1145/1629575.1629596). *SOSP* · Lampson (1973). "A Note on the Confinement Problem." *CACM* 16(10).

**AI safety:** Bostrom (2014). *Superintelligence.* Oxford UP · Russell (2019). *Human Compatible.* Viking · Hadfield-Menell, Dragan, Abbeel & Russell (2017). "The Off-Switch Game." *IJCAI-17*, pp. 220–227 · Hendrycks et al. (2022). "Unsolved Problems in ML Safety." [arXiv:2109.13916](https://arxiv.org/abs/2109.13916) · Bai et al. (2022). "Constitutional AI." [arXiv:2212.08073](https://arxiv.org/abs/2212.08073) · Christiano, Cotra & Xu (2023). "Eliciting Latent Knowledge." Alignment Forum · Sharma et al. (2025). "Constitutional Classifiers: Defending against Universal Jailbreaks across Thousands of Hours of Red Teaming." [arXiv:2501.18837](https://arxiv.org/abs/2501.18837) · Anil et al. (2024). "[Many-shot Jailbreaking](https://www.anthropic.com/research/many-shot-jailbreaking)." Anthropic · Greenblatt et al. (2024). "Alignment Faking in Large Language Models." [arXiv:2412.14093](https://arxiv.org/abs/2412.14093).

**Byzantine + adversarial ML:** Lamport, Shostak & Pease (1982). "The Byzantine Generals Problem." *ACM TOPLAS* 4(3) · Castro & Liskov (1999). PBFT. *OSDI* · Du et al. (2023). "Multi-Agent Debate." [arXiv:2305.14325](https://arxiv.org/abs/2305.14325) · Goldblum et al. (2022). "Dataset Security for ML." *IEEE TPAMI* · Carlini et al. (2024). "Stealing Part of a Production Language Model." [arXiv:2403.06634](https://arxiv.org/abs/2403.06634) · Wallace, Feng, Kandpal, Gardner & Singh (2019). "Universal Adversarial Triggers for Attacking and Analyzing NLP." *EMNLP-IJCNLP*; [arXiv:1908.07125](https://arxiv.org/abs/1908.07125).

**Instruments + method:** Kullback & Leibler (1951). "On Information and Sufficiency." *Ann. Math. Stat.* 22(1) · Lipton (2018). "The Mythos of Model Interpretability." *CACM* 61(10) · Gray & Reuter (1992). *Transaction Processing.* Morgan Kaufmann · ACPI 6.5 §3 power states · Dick (1968). *Do Androids Dream of Electric Sheep?* Doubleday (the Voight-Kampff literary anchor) · Munafò et al. (2017). "A Manifesto for Reproducible Science." [*Nat. Hum. Behav.* 1](https://doi.org/10.1038/s41562-016-0021) · Wicherts et al. (2016). "Degrees of Freedom in Planning, Running, Analysing, and Reporting Psychological Studies." [*Front. Psychol.* 7:1832](https://doi.org/10.3389/fpsyg.2016.01832) · Popper (1959). *The Logic of Scientific Discovery* · Lakatos (1970). "Falsification and the Methodology of Scientific Research Programmes."

**In-series companions:** *The Sovereign Triad* (Chapter 1, three-role allocation) · *The External Sentinel* (Chapter 2, L2/L6 hardware substrate) · *Sovereign Optimization Flywheel* (Chapter 8, the loop under containment) · *Sixteen Practices* (Chapter 5) §1.5.2 (the Tetrad's canonical statement) · *The Drift Taxonomy* (Chapter 9) + *The Guard Changes at 23:26Z* (Chapter 10, the incident record behind L1's measured estimate) · *Watcher KL-Drift Floor* (Chapter 19, the L7 instrument class, proven in-series).

#### Chapter 4 · Stateless by Construction

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-i-the-architecture/4-stateless-by-construction/appendices-references-and-provenance.md)*.*

**References on the general compaction problem**

The following sources establish that context compaction by summarization, and its lossy, silent, most-recent-context-clobbering failure mode, is a general property of production long-horizon agents rather than a defect of any one tool. They are cited in support of the framing in §1; the mechanisms and receipts in this paper are independent of them.

Cursor. "Dynamic context discovery." [cursor.com/blog/dynamic-context-discovery](https://cursor.com/blog/dynamic-context-discovery) (compaction as lossy compression; degraded post-summary knowledge; history-as-file recovery).

Cursor. "Training Composer for longer horizons." [cursor.com/blog/self-summarization](https://cursor.com/blog/self-summarization) (self-summarization at a fixed context-length trigger; compaction can cause the model to forget critical information).

Cursor Docs. "Summarization." [docs.cursor.com/en/agent/chat/summarization](https://docs.cursor.com/en/agent/chat/summarization) (automatic summarization of older messages when conversations exceed the window).

"Parallel Context Compaction for Long-Horizon LLM Agent Serving." [arXiv:2605.23296](https://arxiv.org/abs/2605.23296) (parallel-vs-sequential context compaction for long-horizon LLM agent serving, evaluated across 8B–120B backbones on the HotpotQA and LoCoMo benchmarks; ninety to ninety-nine percent token reduction; most-recent-context over-compression in CLI agents).

"The Complexity Trap: Simple Observation Masking Is as Efficient as LLM Summarization for Agent Context Management." [arXiv:2508.21433](https://arxiv.org/abs/2508.21433) (summarization as the dominant condense-old-context approach in proprietary and open-source SE agents; documents the trajectory-elongation effect in which summaries reinforce continued action and mask failure signals that would otherwise prompt termination).

"Cursor's compression isn't a bug. It's how it works." [pickles.news/posts/cursor-context-compression](https://pickles.news/posts/cursor-context-compression/) (accessed 2026-08-16) (compaction as an invisible state transition; the interface draws no line; the rule-to-action link summarized away).

### Part II · The discipline

#### Chapter 5 · Sixteen Practices

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-ii-the-discipline/5-sixteen-practices/references-and-provenance.md)*.*

Mei, L., et al. (2025). "A Survey of Context Engineering for Large Language Models." [arXiv:2507.13334](https://arxiv.org/abs/2507.13334) · Amershi, S., et al. (2019). "Guidelines for Human-AI Interaction." *CHI 2019* · a16z (2019). "The Empty Promise of Data Moats" · Bai, Y., et al. (2022). "Constitutional AI." [arXiv:2212.08073](https://arxiv.org/abs/2212.08073) · Baker, M. (2016). "1,500 scientists lift the lid on reproducibility." *Nature* 533 · Bengio, Y., et al. (2009). "Curriculum Learning." *ICML 2009* · Chambers, C. D. (2013). "Registered Reports." *Cortex* 49(3) · Clark, L., et al. (2019). "What Makes a Good Conversation?" *CHI 2019* · Deng, G., et al. (2024). "AI Runtime Infrastructure." [arXiv:2603.00495](https://arxiv.org/abs/2603.00495) · Dettmers, T., et al. (2023). "QLoRA." *NeurIPS 2023* · Dietterich, T. G. (2000). "Ensemble Methods in Machine Learning." *MCS 2000* · Du, Y., et al. (2023). "Improving Factuality and Reasoning through Multiagent Debate." [arXiv:2305.14325](https://arxiv.org/abs/2305.14325).

Giannou, A., et al. (2023). "Looped Transformers as Programmable Computers." *ICML 2023* · Guu, K., et al. (2020). "REALM." *ICML 2020* · Halevy, A., Norvig, P., & Pereira, F. (2009). "The Unreasonable Effectiveness of Data." *IEEE Intelligent Systems* 24(2) · Henderson, P., et al. (2018). "Deep Reinforcement Learning That Matters." *AAAI 2018* · Heuer, R. J. & Pherson, R. H. (2010). *Structured Analytic Techniques for Intelligence Analysis.* CQ Press · Alansari, A., & Luqman, H. (2025). "Large Language Models Hallucination: A Comprehensive Survey." [arXiv:2510.06265](https://arxiv.org/abs/2510.06265) · IEC 61511 (2016). *Functional Safety – Safety Instrumented Systems* · Inan, H., et al. (2023). "Llama Guard." [arXiv:2312.06674](https://arxiv.org/abs/2312.06674) · Ji, Z., et al. (2023). "Survey of Hallucination in NLG." *ACM Computing Surveys* 55(12) · Jiang, H., et al. (2023, 2024). "LLMLingua / LLMLingua-2." *EMNLP 2023 / ACL 2024* · Kaplan, J., et al. (2020). "Scaling Laws for Neural Language Models." [arXiv:2001.08361](https://arxiv.org/abs/2001.08361) · van der Graaf, J., et al. (2023). "How to Design and Evaluate Personalized Scaffolds for Self-Regulated Learning." *Metacognition and Learning* 18:783–810.

Shao, E., et al. (2025). "SciSciGPT: Advancing Human–AI Collaboration in the Science of Science." *Nature Computational Science* ([arXiv:2504.05559](https://arxiv.org/abs/2504.05559)) · Lewis, P., et al. (2020). "Retrieval-Augmented Generation." *NeurIPS 2020* · Liang, T., et al. (2024). "Encouraging Divergent Thinking through Multi-Agent Debate." *EMNLP 2024* · Takerngsaksiri, W., et al. (2024). "Human-In-the-Loop Software Development Agents (HULA)." [arXiv:2411.12924](https://arxiv.org/abs/2411.12924) · Luu, D. (2017). "Files Are Hard" · Ma, X., et al. (2023). "LLM-Pruner." *NeurIPS 2023* · Manakul, P., et al. (2023). "SelfCheckGPT." *EMNLP 2023* · Ilager, S., & Buyya, R. (2021). "Energy and Thermal-aware Resource Management of Cloud Data Centres: A Taxonomy and Future Directions." [arXiv:2107.02342](https://arxiv.org/abs/2107.02342) · Kholkar, G., & Ahuja, R. (2025). "Policy-as-Prompt: Turning AI Governance Rules into Guardrails for AI Agents." [arXiv:2509.23994](https://arxiv.org/abs/2509.23994) · Munafò, M. R., et al. (2017). "A Manifesto for Reproducible Science." [*Nature Human Behaviour* 1](https://doi.org/10.1038/s41562-016-0021) · Nosek, B. A., et al. (2018). "The Preregistration Revolution." *PNAS* 115(11) · NVIDIA (2025). "Data Flywheel" · Park, J. S., et al. (2023). "Generative Agents." *UIST 2023* · Patterson, D., et al. (2021). "Carbon Emissions and Large Neural Network Training." [arXiv:2104.10350](https://arxiv.org/abs/2104.10350) · Pillai, T. S., et al. (2014). "All File Systems Are Not Created Equal." *OSDI 2014* · Pineau, J., et al. (2021). "Improving Reproducibility in ML Research." *JMLR* 22.

Radford, A., et al. (2023). "Robust Speech Recognition via Large-Scale Weak Supervision." *ICML 2023* · Sahoo, P., et al. (2025). "A Systematic Survey of Prompt Engineering." [arXiv:2402.07927](https://arxiv.org/abs/2402.07927) · Schwartz, R., et al. (2020). "Green AI." *CACM* 63(12) · Shankar, S., et al. (2024). "Who Validates the Validators?" [arXiv:2404.12272](https://arxiv.org/abs/2404.12272) · Strubell, E., et al. (2019). "Energy and Policy Considerations for Deep Learning in NLP." *ACL 2019* · Summers, A. E. (2013). *Safety Controls, Alarms, and Interlocks as Independent Protection Layers.* SIS-Tech · Toyer, S., et al. (2024). "Tensor Trust." *ICLR 2024* · Yang, Y., et al. (2025). "Minimizing Hallucinations and Communication Costs: Adversarial Debate and Voting Mechanisms in LLM-Based Multi-Agents." *Applied Sciences* 15(7):3676 · Wang, X., et al. (2023). "Self-Consistency Improves Chain of Thought Reasoning." *ICLR 2023* · White, J., et al. (2023). "A Prompt Pattern Catalog." [arXiv:2302.11382](https://arxiv.org/abs/2302.11382) · Wu, T., Terry, M., & Cai, C. J. (2022). "AI Chains." *CHI 2022* · Zamfirescu-Pereira, J. D., et al. (2023). "Why Johnny Can't Prompt." *CHI 2023* · Zheng, L., et al. (2023). "Judging LLM-as-a-Judge." *NeurIPS 2023* · Borrill, P. (2026). "Unix Tools and the FITO Category Mistake: Crash Consistency and the Protocol Nature of Persistence." [arXiv:2603.01384](https://arxiv.org/abs/2603.01384) · Zhuge, M., et al. (2024). "Agent-as-a-Judge: Evaluate Agents with Agents." *ICML 2025*; [arXiv:2410.10934](https://arxiv.org/abs/2410.10934).

**Anchors of the accreted entries (§5.16–§5.37):** Anderson, J. R. (1983). *The Architecture of Cognition.* Harvard UP · Argyris, C., & Schön, D. A. (1978). *Organizational Learning.* Addison-Wesley · Basili, V. R., & Weiss, D. M. (1984). "A Methodology for Collecting Valid Software Engineering Data." *IEEE TSE* 10(6) · Beer, S. (1972). *Brain of the Firm.* Allen Lane · Boyd, J. R. (1987). *A Discourse on Winning and Losing*; Osinga, F. P. B. (2007). *Science, Strategy and War.* Routledge · Brooks, F. P. (1975). *The Mythical Man-Month.* Addison-Wesley · Chen, S., et al. (2023). "Extending Context Window of Large Language Models via Positional Interpolation." [arXiv:2306.15595](https://arxiv.org/abs/2306.15595) · Cockburn, A. (2006). *Agile Software Development: The Cooperative Game* (2nd ed.). Addison-Wesley · Csikszentmihalyi, M. (1990). *Flow.* Harper & Row · Deming, W. E. (1986). *Out of the Crisis.* MIT CAES (the Shewhart cycle) · Gawande, A. (2009). *The Checklist Manifesto.* Metropolitan Books · Gelernter, D. (1985). "Generative Communication in Linda." *ACM TOPLAS* 7(1) · Hadamard, J. (1945). *The Psychology of Invention in the Mathematical Field.* Princeton UP · Haynes, A. B., et al. (2009). "A Surgical Safety Checklist to Reduce Morbidity and Mortality in a Global Population." *NEJM* 360(5) · Kahneman, D. (2011). *Thinking, Fast and Slow.* FSG · Kelly, K. (1998). *Out of Control.* Basic Books · Khattab, O., et al. (2023). "DSPy." [arXiv:2310.03714](https://arxiv.org/abs/2310.03714) · Knuth, D. E. (1984). "Literate Programming." *The Computer Journal* 27(2) · Kolb, D. A. (1984). *Experiential Learning.* Prentice-Hall · Liu, N. F., et al. (2024). "Lost in the Middle: How Language Models Use Long Contexts." *TACL* 12 · Miller, G. A. (1956). "The Magical Number Seven, Plus or Minus Two." *Psychological Review* 63(2) · Nonaka, I., & Takeuchi, H. (1995). *The Knowledge-Creating Company.* Oxford UP · Packer, C., et al. (2023). "MemGPT: Towards LLMs as Operating Systems." [arXiv:2310.08560](https://arxiv.org/abs/2310.08560) · Parnas, D. L., & Clements, P. C. (1986). "A Rational Design Process: How and Why to Fake It." *IEEE TSE* 12(2) · Perrow, C. (1984). *Normal Accidents.* Princeton UP · Reynolds, L., & McDonell, K. (2021). "Prompt Programming for Large Language Models." *CHI EA 2021* · Schön, D. A. (1983). *The Reflective Practitioner.* Basic Books · Senge, P. M. (1990). *The Fifth Discipline.* Doubleday · Simonton, D. K. (1988). *Scientific Genius: A Psychology of Science.* Cambridge UP · Suchman, L. (1987). *Plans and Situated Actions.* Cambridge UP · Sumers, T., et al. (2024). "Cognitive Architectures for Language Agents." *TMLR* · Sweller, J. (1988). "Cognitive Load During Problem Solving." *Cognitive Science* 12(2) · Urbach, D. R., et al. (2014). "Introduction of Surgical Safety Checklists in Ontario, Canada." *NEJM* 370(11) · Weick, K. E. (1993). "The Collapse of Sensemaking in Organizations: The Mann Gulch Disaster." *ASQ* 38(4) · Yao, S., et al. (2023). "ReAct: Synergizing Reasoning and Acting in Language Models." *ICLR 2023*.

**In-series companions:** *The Sovereign Triad* (Chapter 1; the promoted §1.5.1) · *The Guard Changes at 23:26Z* (Chapter 10; the cascade catalogue §5.10 summarizes) · *Corpus-Sovereign Self-Distillation* (Chapter 18; the H3 quantitative axis) · *Sovereign Domain Pruning* (Chapter 16; source of the §5.25–5.31 protocols) · *Stateless by Construction* (Chapter 4; the §5.33 discipline in full) · *Multi-Agent OODA Mesh* (Chapter 6; §5.8's standalone treatment) · *Sovereign Optimization Flywheel* (Chapter 8; §5.34 in full) · *Sovereign Safety Architecture* (Chapter 3; §5.35 in full) · *Watcher KL-Drift Floor* (Chapter 19; §5.37's daemon under training) · *Sharded-MCP Architecture* (the memory hierarchy §5.18 prototypes manually).

#### Chapter 6 · Multi-Agent OODA Mesh

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-ii-the-discipline/6-multi-agent-ooda-mesh/references-and-provenance.md)*.*

**OODA:** Boyd, J. R. (1976). *Destruction and Creation*; (1987). *A Discourse on Winning and Losing* · Osinga, F. P. B. (2007). *Science, Strategy and War.* Routledge · Johnson, J. (2022). "Automating the OODA Loop in the Age of Intelligent Machines." *Defence Studies* 22(2):241–260 · Air Power Journal (2024). "Reshaping Air Power Doctrines: Creating AI-Enabled Super-OODA Loops." · Hoffman, R., et al. (2024). Cognitive-systems-engineering review (substrate-fold).

**Multi-agent orchestration:** Amershi, S., et al. (2019). "Guidelines for Human-AI Interaction." *CHI 2019* · Park, J. S., et al. (2023). "Generative Agents." *UIST 2023*; [arXiv:2304.03442](https://arxiv.org/abs/2304.03442) · Masters, C., et al. (2025). "Orchestrating Human-AI Teams: The Manager Agent as a Unifying Research Challenge." *DAI 2025*; [arXiv:2510.02557](https://arxiv.org/abs/2510.02557) · "Exploring Human-AI Collaboration Using Mental Models of Early Adopters of Multi-Agent Generative AI Tools" (2025). [arXiv:2510.06224](https://arxiv.org/abs/2510.06224) · "Multi-Agent Collaboration Mechanisms: A Survey" (2025). [arXiv:2501.06322](https://arxiv.org/abs/2501.06322) · "Multi-Agent Collaboration via Evolving Orchestration" (2025). [arXiv:2505.19591](https://arxiv.org/abs/2505.19591) · Qian, C., et al. (2024). "ChatDev: Communicative Agents for Software Development." *ACL 2024* · Wu, Q., et al. (2023). "AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation." Microsoft Research (substrate-fold).

**Cognitive offloading:** Gerlich, M. (2025). "AI Tools in Society: Impacts on Cognitive Offloading and the Future of Critical Thinking." *Societies* 15(1):6; [DOI 10.3390/soc15010006](https://doi.org/10.3390/soc15010006) · Chirayath et al. (2025) · Singh (2025) · Alfaro et al. (2024) · Clark, A. (1997). *Being There: Putting Brain, Body, and World Together Again.* MIT Press · Risko, E. F., & Gilbert, S. J. (2016). "Cognitive offloading." *Trends in Cognitive Sciences* 20(9):676–688.

**Analytic tradecraft:** Kent, S. (1949). *Strategic Intelligence for American World Policy.* Princeton UP · ODNI (2015). ICD-203 · Heuer, R. J. (1999). *Psychology of Intelligence Analysis* · Pirolli, P., & Card, S. (2005). "The Sensemaking Process and Leverage Points for Analyst Technology."

**Solo-operator + substrate:** Lavingia, S. (2021). *The Minimalist Entrepreneur* · a16z (2024–2025) one-person-unicorn commentary + community surveys · Bai, Y., et al. (2022). "Constitutional AI." [arXiv:2212.08073](https://arxiv.org/abs/2212.08073) · Kaplan (2020) + Hoffmann (2022) scaling laws · Ji, Y., et al. (2023). Hallucination survey. *ACM CSUR.*

**Method + compounding:** Popper (1959) *The Logic of Scientific Discovery* + (1962) *Conjectures and Refutations* · Lakatos (1970) · Pareek, D., Du, S. S., & Oh, S. (2024). "Understanding the Gains from Repeated Self-Distillation." [arXiv:2407.04600](https://arxiv.org/abs/2407.04600) · Shenfeld, I., et al. (2026). "Self-Distillation Enables Continual Learning" (introduces SDFT, distinct from Yang et al.’s 2024 SDFT). [arXiv:2601.19897](https://arxiv.org/abs/2601.19897) · the data-flywheel compounding concept · Wittgenstein (1953). *Philosophical Investigations* (the what-it-is-not-saying discipline) · Bayes (1763).

**In-series + prior art:** Kistner, J. (2023). [*The Dawning Age of AI*](https://www.linkedin.com/posts/jameykistner_ai-singularity-collaboration-activity-7045734252818100224-gBGE) (LinkedIn, 2023; an AI-generated multimedia piece, text authored by GPT-4 with AI-generated artwork, video, music, and narration, credited on its face as "Orchestrated and Arranged by: Jamey Kistner, A Human"), the earliest dated public record of the operator's cross-platform AI-orchestration practice. The piece was the output of a July 2023 proof-of-concept synthetic-media pipeline (OSINTelligence project record): Synthesys AI text-to-video avatars and neural voice synthesis for narrative delivery, a Soundful algorithmic royalty-free score matched to the piece's tone, DALL-E and Midjourney thematic b-roll and environmental assets, and post-production assembly in Canva to broadcast format, a full narrative produced without physical cameras, actors, or traditional scoring; the workflow it proved out became the baseline for OSINTelligence Studios · Kistner, J. (2025). [*Finding Connection and Clarity in the Age of AI*](https://www.linkedin.com/posts/jameykistner_finding-connection-and-clarity-in-the-activity-7287835156738981890-gfI-) (self-published, 2025-01-22; the dated public posting is the prior-art record, and the artifact is carried whole in this record: [PDF](https://137900913-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fxx2bv6VR9dSJDJ9HsDER%2Fuploads%2Fp0ljFG09l5fmpx8GjK5x%2Ffinding-connection-and-clarity-in-the-age-of-ai.pdf?alt=media)), the dated prior-art anchor for a subset of practices (voice-first, whole-idea, dual-instance), with multi-instance routing and the mesh explicitly later extensions · the pre-transition source notes (mesh research + literature review, co-authored with Opus 4.6) · *Sixteen Practices* (Chapter 5; §5.8 condensed pointer, §5.11 attention-economics, §5.21 errors-as-knowledge, §5.24 saturation paradox) · *The Guard Changes at 23:26Z* (Chapter 10; the cascade ladder) · *Corpus-Sovereign Self-Distillation* (Chapter 18; the falsification-retention precedent) · *The Sovereign Triad* (Chapter 1) · *Sovereign Sustainability* (Chapter 22; the industrial-scale compatibility argument) · *The Drift Taxonomy* (Chapter 9; the lockdown record backstopping the recursion-degradation mode).

#### Chapter 7 · The Sovereign Corpus Engine

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-ii-the-discipline/7-the-sovereign-corpus-engine/references-and-provenance.md)*.*

*Reference set web-verified in the series reference-audit phase (2026-07-27): all six external citations confirmed against primary sources, zero fixes required (the program's standing anti-hallucination discipline). No internal system identifiers appear in the body.*

**Active learning & data-centric AI:** Settles, B. (2009). *Active Learning Literature Survey.* University of Wisconsin–Madison Computer Sciences Technical Report 1648 · Sambasivan, N., et al. (2021). "'Everyone wants to do the model work, not the data work': Data Cascades in High-Stakes AI." *CHI 2021.*

**Data provenance & documentation:** Gebru, T., et al. (2021). "Datasheets for Datasets." *Communications of the ACM* 64(12) · the Supply-chain Levels for Software Artifacts (SLSA) provenance framework (OpenSSF), as generalized here from software artifacts to a training corpus.

**Preference & instruction data:** Ouyang, L., et al. (2022). "Training Language Models to Follow Instructions with Human Feedback." [*NeurIPS 2022*](https://arxiv.org/abs/2203.02155) · Bai, Y., et al. (2022). "Constitutional AI: Harmlessness from AI Feedback." [arXiv:2212.08073](https://arxiv.org/abs/2212.08073).

**Companion papers (this series):** *The Sovereign Triad* (Chapter 1; FC-2 in-weights specialization, the component this engine feeds) · *The Drift Taxonomy* (Chapter 9; the failure classes the corpus targets) · *Watcher KL-Drift Floor* (Chapter 19; the classifier this corpus trains) · *Stateless by Construction* (Chapter 4; the intervention record this engine mines) · *The Sovereign Optimization Flywheel* (Chapter 8; the L₄ specialization axis this engine supplies).

#### Chapter 8 · Sovereign Optimization Flywheel

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-ii-the-discipline/8-sovereign-optimization-flywheel/references-and-provenance.md)*.*

**Systems + architecture:** Senge, P. M. (1990). *The Fifth Discipline.* Doubleday · Sterman, J. D. (2000). *Business Dynamics.* McGraw-Hill · Forrester, J. W. (1961). *Industrial Dynamics.* MIT Press · Hennessy, J. L., & Patterson, D. A. (2019). *Computer Architecture: A Quantitative Approach* (6th ed.). Morgan Kaufmann.

**Scaling laws:** Kaplan, J., et al. (2020). "Scaling Laws for Neural Language Models." [arXiv:2001.08361](https://arxiv.org/abs/2001.08361) · Hoffmann, J., et al. (2022). "Training Compute-Optimal Large Language Models." [arXiv:2203.15556](https://arxiv.org/abs/2203.15556) (Chinchilla).

**MTP + speculative decoding:** Leviathan, Y., et al. (2023). "Fast Inference from Transformers via Speculative Decoding." *ICML 2023* · Chen, C., et al. (2023). "Accelerating LLM Decoding with Speculative Sampling." [arXiv:2302.01318](https://arxiv.org/abs/2302.01318) · Gloeckle, F., et al. (2024). "Better & Faster LLMs via Multi-token Prediction." [arXiv:2404.19737](https://arxiv.org/abs/2404.19737) · Samragh, M., et al. (2025). "Your LLM Knows the Future: Uncovering Its Multi-Token Prediction Potential." [arXiv:2507.11851](https://arxiv.org/abs/2507.11851) (gated-LoRA MTP adaptation of pretrained models) · Mahajan, D., et al. (2025). "Beyond Multi-Token Prediction: Pretraining LLMs with Future Summaries." [arXiv:2510.14751](https://arxiv.org/abs/2510.14751); *ICLR 2026* (the disconfirming bound on quality claims).

**KV compression:** Hooper, C., et al. (2024). "KVQuant." [arXiv:2401.18079](https://arxiv.org/abs/2401.18079) · Wu, H., & Tu, K. (2024). "Layer-Condensed KV Cache for Efficient Inference of Large Language Models." *ACL 2024*; [arXiv:2405.10637](https://arxiv.org/abs/2405.10637) · Liu, Y., et al. (2025). "KV Cache Compression for Inference Efficiency in LLMs: A Review." [arXiv:2508.06297](https://arxiv.org/abs/2508.06297) · TurboQuant (Zandieh, Daliri, Hadian & Mirrokni; *ICLR 2026*; [arXiv:2504.19874](https://arxiv.org/abs/2504.19874)) / PolarQuant (*AISTATS 2026*).

**Alignment + moats:** Bai, Y., et al. (2022). "Constitutional AI." [arXiv:2212.08073](https://arxiv.org/abs/2212.08073) · Greenblatt, R., et al. (2024). "Alignment Faking in Large Language Models." [arXiv:2412.14093](https://arxiv.org/abs/2412.14093) · a16z (2019). "The Empty Promise of Data Moats" · Argyris, C., & Schön, D. A. (1978). *Organizational Learning.* Addison-Wesley.

**In-series companions:** *Sovereign In-Distribution Imatrix Calibration* (Chapter 15; L₁ sealed) · *Sovereign Domain Pruning* (Chapter 16; L₃ sealed) · *Sovereign CTI-NER* + *Corpus-Sovereign Self-Distillation* (Chapter 18; the L₄ chain) · *The Sovereign Triad* (Chapter 1; the Governor whose V2 verifies this loop) · *Watcher KL-Drift Floor* (Chapter 19; the Level-4 axis's classifier under training) · *Sixteen Practices* (Chapter 5, §5.34; the methodology-tier statement) · *Stateless by Construction* (Chapter 4; the context-discipline complement) · *Sovereign Big-Model Compression* (Chapter 17; the L₁ and L₃ axes carried to 122B: a one-shot expert prune plus a sovereign-calibrated imatrix, cleared by a pre-registered served quality gate and now the deployed research brain).

### Part III · The evidence: what broke

#### Chapter 9 · The Drift Taxonomy

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-iii-the-evidence-what-broke/9-the-drift-taxonomy/references-and-provenance.md)*.*

**Provenance.** This chapter is a primary field record. Every incident in it was observed on the author’s own production stack, and the evidence is the dated record of those incidents rather than the published literature, so the chapter cites no external work. That is a property of the material, not an omission: the nine classes were admitted only when a real incident forced each one, and nothing here is inherited from a source that could be cited instead. No internal file, path, or hash identifiers appear in the body.

**In-series companions.** *Stateless by Construction* (Chapter 4) takes one of these nine classes, compaction-induced drift, and works its mechanical answer out in full, where this chapter catalogues nine and closes five in outline. *The Sovereign Triad* (Chapter 1) argues the general principle the whole taxonomy points toward, that mechanical enforcement at the tool-call boundary is the first of three jointly necessary control surfaces. *The Hook Telemetry Record* (Chapter 11) is the quantitative counterpart, the block-level telemetry from the same stack over a later window. Cited in-series by title.

#### Chapter 10 · The Guard Changes at 23:26Z

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-iii-the-evidence-what-broke/10-the-guard-changes-at-23-26z/references-and-provenance.md)*.*

\[1–2] Anthropic (2026). "Introducing Claude Opus 4.7" (News, 2026-04-16); Claude Opus 4.7 product page.

\[3] OSINTelligence LLC (2026). P7 SSD D-003.2 abort note (the ratified-and-retained falsification precedent; sovereign repository, RESULTS tree).

\[4] OSINTelligence LLC (2026). Forgejo sovereign git forge deployment record.

\[5] Kistner, J. (2026). *Sixteen Practices for Sovereign Human–AI Collaboration.* The series' methodology reference (Chapter 5).

\[6] Shadish, W. R., Cook, T. D., & Campbell, D. T. (2002). *Experimental and Quasi-Experimental Designs for Generalized Causal Inference.* Houghton Mifflin.

\[7] Gao, Z., Bird, C., & Barr, E. T. (2017). "To Type or Not to Type: Quantifying Detectable Bugs in JavaScript." *ICSE 2017.*

\[8] Bird, C., Rigby, P. C., Barr, E. T., et al. (2009). "The Promises and Perils of Mining Git." *MSR 2009.*

\[9] Devanbu, P., Zimmermann, T., & Bird, C. (2016). "Belief & Evidence in Empirical Software Engineering." *ICSE 2016.*

\[10–13] Release-week coverage: XBOW visual-acuity benchmark; CNBC and Axios release reporting (2026-04-16); The AI Corner migration guide.

\[14] Takerngsaksiri, W., et al. (2024). "Human-In-the-Loop Software Development Agents (HULA)." [arXiv:2411.12924](https://arxiv.org/abs/2411.12924).

\[15] Shao, E., et al. (2025). "SciSciGPT: Advancing Human–AI Collaboration in the Science of Science." *Nature Computational Science* ([arXiv:2504.05559](https://arxiv.org/abs/2504.05559)).

\[16] Chambers, C. D. (2013). "Registered Reports: A New Publishing Initiative at Cortex." *Cortex* 49(3).

\[17] Nosek, B. A., Ebersole, C. R., DeHaven, A. C., & Mellor, D. T. (2018). "The Preregistration Revolution." *PNAS* 115(11).

\[18] Pineau, J., et al. (2021). "Improving Reproducibility in Machine Learning Research." *JMLR* 22.

\[19] OSINTelligence LLC (2026). P7 SSD pre-registration, SHA-256 815e0a35… (sovereign repository).

\[20] OSINTelligence LLC (2026). Bash-on-Windows path-conversion quirk, session log 2026-04-16.

\[21] Evans, R., et al. (2024). "Evaluating Human-AI Collaboration: A Review and Methodological Framework." [arXiv:2407.19098](https://arxiv.org/abs/2407.19098).

\[22] Fragiadakis, G., et al. (2024). "Human-AI collaboration is not very collaborative yet." *Frontiers in Computer Science* 6:1521066.

\[23] Abasi-amefon, A., et al. (2026). "Advancing Decision-Making through AI-Human Collaboration." *Group Decision and Negotiation* (Springer).

\[24] Panke, S. (2025). "How Can (A)I Research This? An Autoethnographic Exploration of Generative AI." *Qualitative Social Research* (SAGE).

\[25] Wiles, F. (2025). "Recursive Cognition in Practice." *International Journal of Qualitative Methods* (SAGE).

\[26] Koopman, W. J., Watling, C. J., & LaDonna, K. A. (2020). "Autoethnography as a Strategy for Engaging in Reflexivity." *Qualitative Health Research.*

\[27] Wataoka, K., Takahashi, T., & Tsuchiya, R. (2024). "Self-Preference Bias in LLM-as-a-Judge." [arXiv:2410.21819](https://arxiv.org/abs/2410.21819).

\[28] Wallace, E., et al. (2024). "The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions." [arXiv:2404.13208](https://arxiv.org/abs/2404.13208).

\[29] Semmelrock, H., et al. (2025). "Reproducibility in Machine Learning-based Research." *AI Magazine* (Wiley).

\[30] Lee, S., et al. (2025). "Facilitating Longitudinal Interaction Studies of AI Systems." *UIST 2025 Adjunct.* [DOI 10.1145/3746058.3758469](https://doi.org/10.1145/3746058.3758469).

\[N1] Jin, J., et al. (2026). "Capable but Unreliable: Canonical Path Deviation as a Causal Mechanism of Agent Failure in Long-Horizon Tasks." [arXiv:2602.19008](https://arxiv.org/abs/2602.19008).

\[N2] Xu, B., et al. (2025). "AgentIF: Benchmarking Instruction Following of Large Language Models in Agentic Scenarios." [arXiv:2505.16944](https://arxiv.org/abs/2505.16944).

\[N3] Zilian, R., et al. (2025). "Evaluating Goal Drift in Language Model Agents." [arXiv:2505.02709](https://arxiv.org/abs/2505.02709).

\[N4] HORIZON Benchmark Authors (2026). "The Long-Horizon Task Mirage? Diagnosing Where and Why Agentic Systems Break." [arXiv:2604.11978](https://arxiv.org/abs/2604.11978).

\[N5] Du, M., He, F., Zou, N., Tao, D., & Hu, X. (2024). "Shortcut Learning of Large Language Models in Natural Language Understanding." *CACM*; [arXiv:2208.11857](https://arxiv.org/abs/2208.11857).

\[N6] IBM Research (2025). "Towards Enforcing Company Policy Adherence in Agentic Workflows." [arXiv:2507.16459](https://arxiv.org/abs/2507.16459); *EMNLP 2025 Industry Track.*

\[N7] Hierarchical Safety Benchmark Authors (2025). "Evaluating LLM Agent Adherence to Hierarchical Safety Principles." [arXiv:2506.02357](https://arxiv.org/abs/2506.02357).

\[N8] Microsoft (2025). "Conversation Compaction in the Microsoft Agent Framework." Microsoft Learn.

\[N9] LangChain (2025). "Your Harness, Your Memory." Engineering blog.

\[N10] Raschka, S. (2025). "Components of a Coding Agent." *Ahead of AI.*

\[N11] JetBrains Research (2025). "Cutting Through the Noise: Smarter Context Management for LLM-Powered Agents."

\[N12] Weaviate (2025). "Context Engineering: LLM Memory and Retrieval for AI Agents."

Provenance of record (this paper's own subject matter): the composition of record ran under Claude Opus 4.7 with Claude Sonnet (web) contributing status tracking and routing, all under Jamey Kistner's direction as sole human author. Scaffold committed 2026-04-16T23:52Z, the first full-length post-transition artifact. All pre-transition citations refer to sealed artifacts composed under Claude Opus 4.6; those attributions are preserved as correct research provenance. The §10 catalogue grew append-only through Cycle-14; the literature-enhancement pass (refs \[21]–\[30]) and the \[N] agentic-reliability set were added under the operator's directive with no rewriting of pre-existing narrative.

#### Chapter 11 · The Hook Telemetry Record

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-iii-the-evidence-what-broke/11-the-hook-telemetry-record/references-and-provenance.md)*.*

**Companion papers (this series):** *The Sovereign Triad: An Architectural Ethics for Self-Improving AI Systems* (Chapter 1; the FC-1/FC-2/FC-3 allocation this record's blocks substantiate) · *Stateless by Construction* (Chapter 4; the on-disk-state and grounding-gate discipline the hooks enforce) · *The Drift Taxonomy* (Chapter 9; the failure classes the gates were built to catch) · *The Public Case Record* (Chapter 12; the external-evidence counterpart, the same claim measured on other organizations' systems).

**Data:** 66 daily JSONL files, `~/.claude/hook-state/telemetry/`, 2026-05-11 → 2026-07-15 (64 with data). Instrument: the log\_fire() helper in `_telemetry.py` (wired 2026-05-03; session-id and observational-mode enrichment 2026-05-08). Aggregated verbatim; every figure in this report is a direct count, none estimated.

**Supersedes:** *Hook Telemetry: Preliminary Research* (OSINTelligence LLC, 2026-05-08), which described the instrument at wiring time before a data window existed.

#### Chapter 12 · The Public Case Record

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-iii-the-evidence-what-broke/12-the-public-case-record/references-and-provenance.md)*.*

**Status:** Version 1.1.0, external-evidence layer, released 24 July 2026. Every source below is cited to the primary that reported it; the items set aside as outside the inclusion rule are named so the exclusion is visible.

**Drawn from other papers in this series:** Zhang, Hu, Lu, Lange & Clune (2025), *Darwin Gödel Machine*, [arXiv:2505.22954](https://arxiv.org/abs/2505.22954), cited in *The Sovereign Triad*. Greenblatt et al. (2024), *Alignment Faking*, [arXiv:2412.14093](https://arxiv.org/abs/2412.14093). Hubinger et al. (2024), *Sleeper Agents*, [arXiv:2401.05566](https://arxiv.org/abs/2401.05566). Anil et al. (2024), many-shot jailbreaking. Carlsmith (2022), [arXiv:2206.13353](https://arxiv.org/abs/2206.13353). Hadfield-Menell et al. (2016), CIRL. Each is used here for a distinct purpose with a pointer to its home paper.

**Primary sources cited in this chapter:** UK AI Security Institute, *Cheating behaviour in frontier model evaluations* (blog, 21 Jul 2026). OpenAI's evaluation-security incident report (21 Jul 2026) with Hugging Face's disclosure (16 Jul 2026), and METR's pre-deployment evaluation of GPT-5.6 Sol (26 Jun 2026, under NDA). Sakana AI, *The AI Scientist* (blog and report, 2024; with the University of Oxford and the University of British Columbia). Lynch, Wright, Larson, Ritchie, Mindermann, Hubinger, Perez & Troy (2025), *Agentic Misalignment: How LLMs Could Be Insider Threats*, [arXiv:2510.05179](https://arxiv.org/abs/2510.05179). Gomez (2025), *From surveillance to signalling: escalation channels as environmental controls for agentic AI*, [arXiv:2510.05192](https://arxiv.org/abs/2510.05192). Replit database-deletion incident (operator and vendor public posts, Jul 2025). Gemini CLI, GitHub issue [google-gemini/gemini-cli #4586](https://github.com/google-gemini/gemini-cli/issues/4586) (Jul 2025). EchoLeak, [CVE-2025-32711](https://www.cve.org/CVERecord?id=CVE-2025-32711) (Aim Security, Jun 2025). Codex CLI sandbox bypass, [CVE-2025-59532](https://www.cve.org/CVERecord?id=CVE-2025-59532). Cursor allowlist bypass, [CVE-2026-22708](https://www.cve.org/CVERecord?id=CVE-2026-22708). AlphaSignal positive control (GPT-5.6 Sol, 18 of 18).

**Set aside as outside the inclusion rule (adversarial misuse):** the state-linked espionage operation using hijacked coding agents, and the campaign driving coding agents against government targets. Both involve a hostile operator rather than a legitimate objective crossing a boundary, so §2 excludes them; they are named for completeness only.

**Companion papers (this series):** *The Drift Taxonomy* (Chapter 9), *The Sovereign Triad* (Chapter 1), *The Hook Telemetry Record* (Chapter 11), and *The External Sentinel* (Chapter 2), each mapped in Figure 2. Cited in-series by title.

### Part IV · The evidence: what worked

#### Chapter 13 · Sovereign IOC Classifier

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-iv-the-evidence-what-worked/13-sovereign-ioc-classifier/references-and-provenance.md)*.*

**PEFT + tooling:** Hu, E. J., et al. (2021). "LoRA: Low-Rank Adaptation of Large Language Models." [arXiv:2106.09685](https://arxiv.org/abs/2106.09685) · Dettmers, T., et al. (2023). "QLoRA: Efficient Finetuning of Quantized LLMs." *NeurIPS 2023*; [arXiv:2305.14314](https://arxiv.org/abs/2305.14314) · Zhou, C., et al. (2023). "LIMA: Less Is More for Alignment." [arXiv:2305.11206](https://arxiv.org/abs/2305.11206) · Wolf, T., et al. (2020). "Transformers." [arXiv:1910.03771](https://arxiv.org/abs/1910.03771) · Lhoest, Q., et al. (2021). "Datasets." [arXiv:2109.02846](https://arxiv.org/abs/2109.02846) · Unsloth AI (2024–2026). FastModel · Loshchilov, I., & Hutter, F. (2017). AdamW ([arXiv:1711.05101](https://arxiv.org/abs/1711.05101)) + SGDR cosine schedule ([arXiv:1608.03983](https://arxiv.org/abs/1608.03983)).

**SLMs:** Abdin, M., et al. (2024). "Phi-3 Technical Report." [arXiv:2404.14219](https://arxiv.org/abs/2404.14219) · Jiang, A. Q., et al. (2023). "Mistral 7B." [arXiv:2310.06825](https://arxiv.org/abs/2310.06825) · Gemma Team (2024). [arXiv:2403.08295](https://arxiv.org/abs/2403.08295) · Touvron, H., et al. (2023). "Llama 2." [arXiv:2307.09288](https://arxiv.org/abs/2307.09288) · Alibaba Qwen Team (2025). Qwen 3.5 technical-report family.

**Constrained decoding:** Willard, B. T., & Louf, R. (2023). [arXiv:2307.09702](https://arxiv.org/abs/2307.09702) · Beurer-Kellner, L., Fischer, M., & Vechev, M. (2024). "Guiding LLMs The Right Way." *ICML 2024*; [arXiv:2403.06988](https://arxiv.org/abs/2403.06988) · Geng, X., et al. (2025). "JSONSchemaBench." [arXiv:2501.10868](https://arxiv.org/abs/2501.10868) · Dong, Y., et al. (2024). "XGrammar." [arXiv:2411.15100](https://arxiv.org/abs/2411.15100) · guidance-ai (2025). llguidance · llama.cpp GBNF + JSON-schema grammars, and the server's router-mode + adapter hot-load documentation.

**Format-tax (disconfirming lane):** Schall, M., & de Melo, G. (2025). "The Hidden Cost of Structure: How Constrained Decoding Affects Language Model Performance." *RANLP 2025*, 1074–1084 · Lee, I. Y., D’Antoni, L., & Berg-Kirkpatrick, T. (2026). "The Format Tax." [arXiv:2604.03616](https://arxiv.org/abs/2604.03616) · Shin, S., et al. (2025). "Lost in Space: Optimizing Tokens for Grammar-Constrained Decoding." [arXiv:2502.14969](https://arxiv.org/abs/2502.14969).

**Instruction tuning + alignment:** Wei, J., et al. (2022). FLAN. *ICLR 2022*; [arXiv:2109.01652](https://arxiv.org/abs/2109.01652) · Ouyang, L., et al. (2022). InstructGPT. [arXiv:2203.02155](https://arxiv.org/abs/2203.02155) · Bai, Y., et al. (2022). "Constitutional AI." [arXiv:2212.08073](https://arxiv.org/abs/2212.08073).

**CTI + NER (light anchoring):** Devlin, J., et al. (2019). "BERT." *NAACL 2019* · Strom, B. E., et al. (2018). *MITRE ATT\&CK: Design and Philosophy.* MITRE · OASIS Open (2021). *STIX 2.1.*

**Method norms:** Munafò, M. R., et al. (2017). "A manifesto for reproducible science." [*Nat. Hum. Behav.* 1:0021](https://doi.org/10.1038/s41562-016-0021) · Nosek, B. A., et al. (2018). "The preregistration revolution." *PNAS* 115(11) · Wilson, E. B. (1927). *JASA* 22(158):209–212 · ODNI (2015). *ICD-203: Analytic Standards.*

**Self-distillation context:** Zhang, R., et al. (2026). "Embarrassingly Simple Self-Distillation Improves Code Generation" (Apple SSD). [arXiv:2604.01193](https://arxiv.org/abs/2604.01193) · Kim, J., et al. (2026). "Why Does Self-Distillation (Sometimes) Degrade the Reasoning Capability of LLMs?" [arXiv:2603.24472](https://arxiv.org/abs/2603.24472).

**In-series companions:** *Sixteen Practices* (Chapter 5; the Pair, the moat, the evidence ladder) · *Corpus-Sovereign Self-Distillation* (Chapter 18; the 9B calibration-retention sibling) · *Sovereign CTI-NER* (Chapter 14; the successor specialist) · *The Sovereign Triad* (Chapter 1; the Pair's first half at architecture register) · *Sovereign Optimization Flywheel* (Chapter 8; this paper is L₄'s first cycle datum) · *Sovereign Sustainability* (Chapter 22; the 219-hour envelope) · the sealed P4 spec/recipe/results chain (in the source repository).

#### Chapter 14 · Sovereign CTI-NER

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-iv-the-evidence-what-worked/14-sovereign-cti-ner/references-and-provenance.md)*.*

Aghaei, E., Jain, S., Arun, P., & Sambamoorthy, A. (2025). "SecureBERT 2.0: Advanced Language Model for Cybersecurity Intelligence." [arXiv:2510.00240](https://arxiv.org/abs/2510.00240) (Cisco AI; ModernBERT-based). Apache-2.0; current encoder-class CTI NER baseline.

Alam, M. T., Bhusal, D., Park, Y., & Rastogi, N. (2022). "CyNER: A Python Library for Cybersecurity Named Entity Recognition." [arXiv:2204.05754](https://arxiv.org/abs/2204.05754). MIT-licensed corpus and library.

Alibaba Cloud Model Studio. "Enforce Structured JSON Output with Qwen Models." <https://www.alibabacloud.com/help/en/model-studio/qwen-structured-output> (accessed 2026-04-14).

Deka, P., Rajapaksha, S., Rani, R., Almutairi, A., & Karafili, E. (2024). "AttackER: Towards Enhancing Cyber-Attack Attribution with a Named Entity Recognition Dataset." *WISE 2024.* CC BY 4.0.

Ech-Chammakhy, M., et al. (2025). "CyberNER: A Harmonized STIX 2.1-Aligned Corpus for Cyber Threat Intelligence Named Entity Recognition." [arXiv:2510.26499](https://arxiv.org/abs/2510.26499). Reference taxonomy; artifact itself unlicensed.

Gerganov, G., and the ggml-org contributors. *llama.cpp.* <https://github.com/ggml-org/llama.cpp>. MIT. This work pins tag b7992 (commit 612db6188) with three sovereign patches (commit 822047a0a) resolving upstream issue #20093 and cherry-picking PR #19928.

ggml-org contributors. *llama.cpp tools/server README* (n\_predict, truncated, json\_schema parameters); *pydantic\_models\_to\_grammar.py*; Issue #20345 (grammar enforcement with thinking enabled). All accessed 2026-04-14.

Kistner, J. (2026). *Sovereign In-Distribution Imatrix Calibration Achieves 16× Tighter KL Divergence Than Generic-Corpus Quantization on a 35B-A3B MoE Model* (Chapter 15). OSINTelligence LLC. The companion paper; cited in-series by title.

Kistner, J. (2026). "Content-level failures (non-crash class) analysis." OSINTelligence deep-debug technical note; distinguishes content-class from crash-class failures with community corroboration.

LM Studio contributors. Bug #1773: response\_format json\_schema applied to reasoning stream on Qwen 3.5. <https://github.com/lmstudio-ai/lmstudio-bug-tracker/issues/1773> (accessed 2026-04-14).

OASIS Cyber Threat Intelligence Technical Committee (2021). *STIX Version 2.1 OASIS Standard.* <https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.html>

Ollama contributors. Issue #14570: qwen3 tool call parser returns 500 when model output is truncated. <https://github.com/ollama/ollama/issues/14570> (accessed 2026-04-14).

Qwen Team (2025). *Qwen3 Technical Report.* Alibaba Group. Qwen 3.5 model family used throughout this work.

Wang, X., Liu, X., Ao, S., et al. (2022). "APTNER: A Specific Dataset for NER Missions in Cyber Threat Intelligence Field." *IEEE CSCWD 2022.* Default copyright; cited as reference taxonomy, not redistributed.

Willison, S. (2023). "Using llama-cpp-python grammars to generate JSON." <https://til.simonwillison.net/llms/llama-cpp-python-grammars> (accessed 2026-04-14).

#### Chapter 15 · Sovereign Imatrix Calibration

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-iv-the-evidence-what-worked/15-sovereign-imatrix-calibration/references-and-provenance.md)*.*

\[1] llama.cpp. llama-perplexity tool and --kl-divergence-base flag. ggml-org/llama.cpp, examples/perplexity/perplexity.cpp. <https://github.com/ggerganov/llama.cpp> (retrieved 2026-04-13).

\[2] kalomaze (2023). "Perplexity / PPL, as a quantization loss benchmark, is inaccurate - KL divergence seem to be a better data point." ggml-org/[llama.cpp Discussion #4110](https://github.com/ggml-org/llama.cpp/discussions/4110), opened 2023-11-17. <https://github.com/ggml-org/llama.cpp/discussions/4110> (verified 2026-04-14).

\[3] localbench. Gemma 4 31B quantization scan, per-quant KLD reference table. <https://github.com/christianazinn/localbench> (retrieved 2026-04-13; approximate values, exact pull pending).

\[4] HuggingFace Blog. KLD-guided quantization series on imatrix calibration trade-offs (specific post URLs to be pinned at submission).

\[5] bartowski. Published per-quant KLD tables in HuggingFace model cards; e.g. Llama-3.3-70B-Instruct quants reporting Q6\_K mean KLD \~0.18–0.22 against BF16 reference.

\[6] Sonatype. *State of the Software Supply Chain* (2024 edition). <https://www.sonatype.com/state-of-the-software-supply-chain>

\[7] NIST SP 800-204D (2024). *Strategies for the Integration of Software Supply Chain Security into DevSecOps CI/CD Pipelines.* <https://csrc.nist.gov/publications/detail/sp/800-204d/final>

#### Chapter 16 · Sovereign Domain Pruning

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-iv-the-evidence-what-worked/16-sovereign-domain-pruning/references-and-provenance.md)*.*

Bean, et al. (2025). Construct-validity analysis for LLM benchmarks. *NeurIPS 2025 Datasets & Benchmarks.* [arXiv:2511.04703](https://arxiv.org/abs/2511.04703).

Bland, J. M., & Altman, D. G. (1986). "Statistical methods for assessing agreement between two methods of clinical measurement." *The Lancet* 327(8476):307–310.

Cassano, F., et al. (2023). "MultiPL-E: A Scalable and Polyglot Approach to Benchmarking Neural Code Generation." [arXiv:2208.08227](https://arxiv.org/abs/2208.08227).

Cohen, J. (1988). *Statistical Power Analysis for the Behavioral Sciences* (2nd ed.). Lawrence Erlbaum.

Dettmers, T., et al. (2023). "QLoRA: Efficient Finetuning of Quantized LLMs." *NeurIPS 2023.*

Efron, B. (1979). "Bootstrap methods: Another look at the jackknife." *Annals of Statistics* 7(1):1–26.

Fisch, A., et al. (2024). "Stratified Prediction-Powered Inference (StratPPI)." *NeurIPS 2024.* [arXiv:2406.04291](https://arxiv.org/abs/2406.04291).

Fogliato, R., et al. (2024). Evaluation-methodology reference. [arXiv:2406.07320](https://arxiv.org/abs/2406.07320).

Frantar, E., & Alistarh, D. (2023). "SparseGPT: Massive Language Models Can Be Accurately Pruned in One-Shot." *ICML 2023.*

Kargaran, A. H. (2025). ICLR rejection-ground analysis (benchmark-selection transparency; pre-registration backflow as Rejection Ground #2). [arXiv:2511.15462](https://arxiv.org/abs/2511.15462).

Kurtic, E., et al. (2024). "Give Me BF16 or Give Me Death? Accuracy-Performance Trade-Offs in LLM Quantization." [arXiv:2411.02355](https://arxiv.org/abs/2411.02355). The Component A protocol-class anchor; Table 4 supplies the ≤ 0.10 nats LoA envelope.

Liang, P., et al. (2023). "Holistic Evaluation of Language Models (HELM)." [arXiv:2211.09110](https://arxiv.org/abs/2211.09110).

Ma, X., et al. (2023). "LLM-Pruner: On the Structural Pruning of Large Language Models." *NeurIPS 2023.*

Men, X., et al. (2024). "ShortGPT: Layers in Large Language Models are More Redundant Than You Expect." [arXiv:2403.03853](https://arxiv.org/abs/2403.03853).

MLPerf (2019). "MLPerf Inference Benchmark." [arXiv:1911.02549](https://arxiv.org/abs/1911.02549).

Perlitz, Y., et al. (2024). "BenchBench: Benchmark Agreement Testing." [arXiv:2407.13696](https://arxiv.org/abs/2407.13696).

Lasby, M., Lazarevich, I., Sinnadurai, N., Lie, S., Ioannou, Y., & Thangarasa, V. (2025). "REAP the Experts: Why Pruning Prevails for One-Shot MoE Compression." *ICLR 2026*; [arXiv:2510.13999](https://arxiv.org/abs/2510.13999).

Rein, D., et al. (2023). "GPQA: A Graduate-Level Google-Proof Q\&A Benchmark." [arXiv:2311.12022](https://arxiv.org/abs/2311.12022).

Spearman, C. (1904). "The proof and measurement of association between two things." *American Journal of Psychology* 15:72–101.

Srivastava, A., et al. (2023). "Beyond the Imitation Game (BIG-bench)." [arXiv:2206.04615](https://arxiv.org/abs/2206.04615).

Su, Z., Li, Q., Zhang, H., Qian, Y., Xie, Y., & Yuan, K. (2025). "Unveiling Super Experts in Mixture-of-Experts Large Language Models." *ICLR 2026*; [arXiv:2507.23279](https://arxiv.org/abs/2507.23279).

Sun, M., et al. (2024). "A Simple and Effective Pruning Approach for Large Language Models (Wanda)." *ICLR 2024.*

Wang, K., Lyu, T., Su, G., Geiping, J., Yin, L., Canini, M., & Liu, S. (2025). "When Fewer Layers Break More Chains: Layer Pruning Harms Test-Time Scaling in LLMs." [arXiv:2510.22228](https://arxiv.org/abs/2510.22228).

Yauney, G., et al. (2025). Benchmark-reliability floor analysis (\~250-example floor for stable pass-rate ranking). [arXiv:2510.08730](https://arxiv.org/abs/2510.08730).

Zhuo, T. Y., et al. (2024). "BigCodeBench: Benchmarking Code Generation with Diverse Function Calls." [arXiv:2406.15877](https://arxiv.org/abs/2406.15877).

Kistner, J. (2026). *Sovereign In-Distribution Imatrix Calibration* (Chapter 15) and *Cross-Toolchain Falsification and Surgical Patch-Pick Resolution of a Production M-RoPE Heap Over-Read in llama.cpp* (Chapter 20), in-series companions; the latter supplies the patched serving binary (commit 822047a0a) this paper's eval-bank runs on. *Sovereign Big-Model Compression* (Chapter 17) is the successor arc: the expert-pruning thesis first tested here, carried to a 122B mixture-of-experts and cleared on the deployed surface by a pre-registered served quality gate.

#### Chapter 17 · Sovereign Big-Model Compression

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-iv-the-evidence-what-worked/17-sovereign-big-model-compression/references-and-provenance.md)*.*

Lasby, M., Lazarevich, I., Sinnadurai, N., Lie, S., Ioannou, Y., & Thangarasa, V. (2025). "REAP the Experts: Why Pruning Prevails for One-Shot MoE Compression." [arXiv:2510.13999](https://arxiv.org/abs/2510.13999) (Cerebras Systems; University of Calgary).

Ding, Y., Wang, J., Yang, G., Jing, Y., Guo, J., Liu, X., & Tao, D. (2026). "Attribution-Guided and Coverage-Maximized Pruning for Structural MoE Compression." [arXiv:2606.18304](https://arxiv.org/abs/2606.18304). (Channel-level structural MoE pruning; the comparator method in the 35B study.)

Shazeer, N., Mirhoseini, A., Maziarz, K., Davis, A., Le, Q., Hinton, G., & Dean, J. (2017). "Outrageously Large Neural Networks: The Sparsely-Gated Mixture-of-Experts Layer." [arXiv:1701.06538](https://arxiv.org/abs/1701.06538).

Frantar, E., Ashkboos, S., Hoefler, T., & Alistarh, D. (2023). "GPTQ: Accurate Post-Training Quantization for Generative Pre-trained Transformers." *ICLR 2023*; [arXiv:2210.17323](https://arxiv.org/abs/2210.17323).

Gloeckle, F., Youbi Idrissi, B., Rozière, B., Lopez-Paz, D., & Synnaeve, G. (2024). "Better & Faster Large Language Models via Multi-token Prediction." [arXiv:2404.19737](https://arxiv.org/abs/2404.19737).

Gerganov, G., et al. (2023–). *llama.cpp*: importance-matrix (imatrix) quantization and KL-divergence measurement tooling. Open-source project.

Que, H., Liu, J., Zhang, G., et al. (2024). "D-CPT Law: Domain-specific Continual Pre-Training Scaling Law for Large Language Models." *NeurIPS 2024*; [arXiv:2406.01375](https://arxiv.org/abs/2406.01375) (validated on Qwen-family models).

Gu, J., Yang, Z., Ding, C., Zhao, R., & Tan, F. (2024). "CMR Scaling Law: Predicting Critical Mixture Ratios for Continual Pre-training of Language Models." *EMNLP 2024*; [arXiv:2407.17467](https://arxiv.org/abs/2407.17467).

Kistner, J. (2026). *Sovereign In-Distribution Imatrix Calibration* (Chapter 15). OSINTelligence LLC.

Kistner, J. (2026). *Sovereign Domain Pruning* (Chapter 16). OSINTelligence LLC.

**In-series companions.** *Sovereign Domain Pruning* (Chapter 16) is the direct predecessor, establishing destructive expert pruning at 35B scale; *Sovereign In-Distribution Imatrix Calibration* (Chapter 15) supplies the calibration technique this arc carries to 122B, and is the sibling axis of the same thesis, that the operator’s own corpus decides what to keep. *Sovereign Optimization Flywheel* (Chapter 8) places both as compounding axes of one optimization loop, and this paper is their joint instance at the largest scale the series has attempted. *Sovereign Sustainability* (Chapter 22) takes the deployment result as its democratization datum, a frontier-class mixture-of-experts served for a single operator on a single consumer card. *Sixteen Practices* (Chapter 5) carries the pre-registration and falsification discipline that the quality gate of §6 and the reported failure of §8 are run under, including the rule that a failed experiment is published beside the passing one.

*Related one-shot MoE-pruning literature surveyed during method selection: Chen et al. (2022) task-specific expert pruning (*[*arXiv:2206.00277*](https://arxiv.org/abs/2206.00277)*); Chowdhury et al. (2024) provably-effective expert pruning (*[*arXiv:2405.16646*](https://arxiv.org/abs/2405.16646)*); Xie et al. (2024) MoE-Pruner (*[*arXiv:2410.12013*](https://arxiv.org/abs/2410.12013)*). Every citation above was web-verified against its primary source; audit trail in the companion ledger. No internal file, path, or hash identifiers appear in the body.*

#### Chapter 18 · Corpus-Sovereign Self-Distillation

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-iv-the-evidence-what-worked/18-corpus-sovereign-self-distillation/references-and-provenance.md)*.*

**Self-distillation:** Zhang, R., et al. (2026). "Embarrassingly Simple Self-Distillation Improves Code Generation." [arXiv:2604.01193](https://arxiv.org/abs/2604.01193) (Apple SSD) · Kim, J., et al. (2026). "Why Does Self-Distillation (Sometimes) Degrade the Reasoning Capability of LLMs?" [arXiv:2603.24472](https://arxiv.org/abs/2603.24472) · Yang, Z., et al. (2024). "Self-Distillation Bridges Distribution Gap in Language Model Fine-Tuning." *ACL 2024* (SDFT) · Pareek, D., Du, S. S., & Oh, S. (2024). "Understanding the Gains from Repeated Self-Distillation." [arXiv:2407.04600](https://arxiv.org/abs/2407.04600) · "Revisiting Self-Distillation" (2022). [arXiv:2206.08491](https://arxiv.org/abs/2206.08491) · "Self-Distillation Enables Continual Learning" (2026). [arXiv:2601.19897](https://arxiv.org/abs/2601.19897).

**Corpus quality:** Zhou, C., et al. (2023). "LIMA: Less Is More for Alignment." [arXiv:2305.11206](https://arxiv.org/abs/2305.11206) · Bhattacharyya, C., & Kim, Y. (2025). "FineScope: Precision Pruning for Domain-Specialized Large Language Models Using SAE-Guided Self-Data Cultivation." [arXiv:2505.00624](https://arxiv.org/abs/2505.00624).

**LoRA/QLoRA:** Hu, E. J., et al. (2021). "LoRA." [arXiv:2106.09685](https://arxiv.org/abs/2106.09685) · Dettmers, T., et al. (2023). "QLoRA." [arXiv:2305.14314](https://arxiv.org/abs/2305.14314).

**Pre-registration norms:** Munafò, M. R., et al. (2017). "A manifesto for reproducible science." [*Nature Human Behaviour* 1:0021](https://doi.org/10.1038/s41562-016-0021) · Nosek, B. A., et al. (2018). "The preregistration revolution." *PNAS* 115(11) · "Reducing bias… with preregistration" (2022). *Nature Human Behaviour* · "Frontier Lag" (2026). [arXiv:2605.04135](https://arxiv.org/abs/2605.04135) (disconfirming-lane audit).

**Hedging + drift thresholds:** ODNI (2015). *Intelligence Community Directive 203: Analytic Standards* · Hoy, W., & Celik, N. (2025). "STABLE: Gated Continual Learning for Large Language Models." [arXiv:2510.16089](https://arxiv.org/abs/2510.16089).

**Contamination defense:** Wu, X., et al. (2025). "AntiLeakBench: Preventing Data Contamination by Automatically Constructing Benchmarks with Updated Real-World Knowledge." *ACL 2025* · "LiveBench" (2024). [livebench.ai](https://livebench.ai).

**Constrained decoding:** Willard & Louf (2023). [arXiv:2307.09702](https://arxiv.org/abs/2307.09702) · Beurer-Kellner, Fischer & Vechev (2024). "Guiding LLMs The Right Way." *ICML 2024* · Geng, X., et al. (2025). "JSONSchemaBench." [arXiv:2501.10868](https://arxiv.org/abs/2501.10868) · Dong, Y., et al. (2024). "XGrammar." [arXiv:2411.15100](https://arxiv.org/abs/2411.15100) · Cooper, A. (2024). "A Guide to Structured Outputs" · "SLOT." *EMNLP 2025 Industry* · "Output Constraints as Attack Surface" (2025). [arXiv:2503.24191](https://arxiv.org/abs/2503.24191) · guidance-ai (2025). "llguidance" · Dong, K., et al. (2025). "The Hidden Cost of Structure." *RANLP 2025* · "Grammar-Constrained Decoding Makes LLMs Better Logical Reasoners." *ACL 2025 Industry* · "Grammar-Constrained Natural Language Generation." *Findings of ACL 2025* · Shin, S., et al. (2025). "Lost in Space." [arXiv:2502.14969](https://arxiv.org/abs/2502.14969) · Geng, S., et al. (2023). [arXiv:2305.13971](https://arxiv.org/abs/2305.13971) · "The Format Tax" (2026). [arXiv:2604.03616](https://arxiv.org/abs/2604.03616) · "QE-Assisted Constrained Decoding" (2025). [arXiv:2501.17265](https://arxiv.org/abs/2501.17265) · "Constrained Sampling… An MCMC Perspective" (2025). [arXiv:2506.05754](https://arxiv.org/abs/2506.05754) · "A Minimalist Approach to LLM Reasoning" (2025). [arXiv:2504.11343](https://arxiv.org/abs/2504.11343) · llama.cpp grammars documentation + PR #6555 (min/maxLength, pattern support).

**Prompt sensitivity + reproducible evaluation:** Guan, B., et al. (2025). "The Order Effect: Investigating Prompt Sensitivity to Input Order in LLMs." [arXiv:2502.04134](https://arxiv.org/abs/2502.04134) · Razavi, A., et al. (2025). "Benchmarking Prompt Sensitivity in Large Language Models." [arXiv:2502.06065](https://arxiv.org/abs/2502.06065) · "Don't Break the Cache" (2026). [arXiv:2601.06007](https://arxiv.org/abs/2601.06007) · "Towards Reproducible LLM Evaluation" (2024). [arXiv:2410.03492](https://arxiv.org/abs/2410.03492) · Zhou, X., et al. (2024). "Evaluating and Explaining Prompt Sensitivity of LLMs Using Interactions." [OpenReview 6fHZR6uxNa](https://openreview.net/forum?id=6fHZR6uxNa).

**In-series companions:** *Sixteen Practices for Sovereign Human–AI Collaboration* (Chapter 5; the Sovereign Pair formalization) · *The Guard Changes at 23:26Z* (Chapter 10; the §10 cascade catalogue) · *Sovereign In-Distribution Imatrix Calibration* (Chapter 15) · *Cross-Toolchain Falsification… M-RoPE Heap Over-Read* (Chapter 20; the patched serving substrate) · the sealed pre-registration, Gate-E verdict SITREP, and decision ledger D-001→D-010 in the sovereign repository's RESULTS tree.

#### Chapter 19 · Watcher KL-Drift Floor

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-iv-the-evidence-what-worked/19-watcher-kl-drift-floor/references-and-provenance.md)*.*

\[1] Xiong, Y., & Xie, X. (2026). "OPLoRA: Orthogonal Projection LoRA Prevents Catastrophic Forgetting during Parameter-Efficient Fine-Tuning." *AAAI 2026*; [arXiv:2510.13003](https://arxiv.org/abs/2510.13003). Body-verified.

\[2] Hoy, W., & Celik, N. (2025). "STABLE: Gated Continual Learning for Large Language Models" (a gated continual self-editing framework). [arXiv:2510.16089](https://arxiv.org/abs/2510.16089). Body-verified.

\[3] Biderman, D., et al. (2024). "LoRA Learns Less and Forgets Less." *TMLR*; [arXiv:2405.09673](https://arxiv.org/abs/2405.09673). Abstract-verified; body-fetch gate noted before any module/rank-specific citation.

\[4] Wortsman, M., et al. (2022). "Model Soups: averaging weights of multiple fine-tuned models improves accuracy without increasing inference time." *ICML 2022*; [arXiv:2203.05482](https://arxiv.org/abs/2203.05482).

\[5] llama.cpp (2024–2026). ggml-org/llama.cpp, llama-server --lora adapter overlay (all six Gate-D evaluations).

\[6] Hugging Face PEFT (2024–2026). LoRA developer guide (all training-side adapter construction).

\[7] kalomaze (2023). [llama.cpp Discussion #4110](https://github.com/ggml-org/llama.cpp/discussions/4110), KLD as quantization metric; community substrate for the H4 protocol.

\[8] Cochrane Collaboration / AllTrials. Pre-registration discipline precedent, adapted to engineering arcs.

\[9] Kerr, N. L. (1998). "HARKing: Hypothesizing After the Results are Known." *Personality and Social Psychology Review* 2(3):196–217. The concept-anchor for the corrigenda discipline.

**In-series companions:** *The Drift Taxonomy* (the cascade catalogue) · *The Guard Changes at 23:26Z* §10.17 (the watcher-firmware thesis) · *Sixteen Practices* §5.37 (the methodology-tier landing) · *The Sovereign Triad* (the Governor role this daemon instantiates at within-session granularity) · *Sovereign Imatrix Calibration* (the imatrix technique behind checkpoint 5) · *Sovereign IOC Classifier* (the trainer-template provenance: the classifier trained here descends from the first sovereign micro-agent's recipe, selected as the canonical template by operator decision on 2026-05-22, carrying the same rank-16, alpha-32, seven-projection LoRA geometry and the same causal-LM-plus-grammar output discipline onto a 2B base).

#### Chapter 20 · mRoPE Serving-Path RCA

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-iv-the-evidence-what-worked/20-mrope-serving-path-rca/upstream-attribution-references-and-provenance.md)*.*

**Upstream attribution**

Every fix composed in this paper originates with a named member of the llama.cpp community, not with the present author. The author's contribution is the falsification isolation, the composition onto a pinned build, the attribution bundle, and the 2,004-row production validation, *not* the fixes themselves. Readers are encouraged to open the sources and confirm the credit directly:

* The heap over-read and its **two-part fix** (the ubatch\_reserve resize and the state\_read\_meta M-RoPE broadcast) were diagnosed and authored, in full and verbatim as applied here, by the reporter of [llama.cpp issue #20093](https://github.com/ggml-org/llama.cpp/issues/20093) (reproduced on an RTX 5090; the reporter's handle is shown at the link).
* The K-shift assertion was independently reported by **KernelFreeze** in [llama.cpp issue #19915](https://github.com/ggml-org/llama.cpp/issues/19915) (reproduced on an RTX 3080), and fixed by **Georgi Gerganov (@ggerganov)**, reviewed by **@ngxson**, in [PR #19928](https://github.com/ggml-org/llama.cpp/pull/19928) (merged as commit [99bd67c](https://github.com/ggml-org/llama.cpp/commit/99bd67c9b29851f758c7d22caa8fc57fd5af3e4f)), which this deployment cherry-picks verbatim.

The llama.cpp project is maintained by Georgi Gerganov and contributors under the MIT license.

**References**

Alibaba Cloud / Qwen team (2025). Qwen structured-output documentation. <https://qwen.readthedocs.io/>

JJJYmmm and contributors (2026). "Revisiting Multimodal Positional Encoding in Vision-Language Models." *ICLR 2026.* [arXiv:2510.23095](https://arxiv.org/abs/2510.23095). MRoPE-Interleave design-space survey.

Kistner, J. (2026). "P7.5 Negative Result: Falsification of the Blackwell-MMQ Hypothesis for a Sovereign llama.cpp Serving Wedge." OSINTelligence LLC. The negative-result companion bundle to this paper.

Kistner, J. (2026). *Sovereign In-Distribution Cyber Threat Intelligence Named Entity Recognition* (Chapter 14). OSINTelligence LLC. The CTI-NER companion; supplies the 1,002-row A/B harness and the independent §4.4.1 observation of the content-class failures.

llama.cpp upstream (2026). [Issue #20093](https://github.com/ggml-org/llama.cpp/issues/20093), M-RoPE heap over-read in ubatch\_reserve, with a reporter-authored two-part fix (ubatch\_reserve resize + state\_read\_meta broadcast) applied verbatim; [Issue #19915](https://github.com/ggml-org/llama.cpp/issues/19915) (reporter: KernelFreeze), seq\_add() assertion on Qwen 3.5, fixed by Georgi Gerganov (@ggerganov), reviewed by @ngxson, via [PR #19928](https://github.com/ggml-org/llama.cpp/pull/19928) / commit [99bd67c9b](https://github.com/ggml-org/llama.cpp/commit/99bd67c9b29851f758c7d22caa8fc57fd5af3e4f) (cherry-picked); Issue #20345, grammar-constrained decoding and token-budget truncation; release tag b7992 (commit 612db6188); tools/server README (Router Mode flags, accessed 2026-04-14). Project by Georgi Gerganov and contributors, MIT license. <https://github.com/ggml-org/llama.cpp>

LM Studio (2025). Issue #1773, JSON response truncation under constrained decoding. <https://github.com/lmstudio-ai/lmstudio-bug-tracker/issues/1773>

Microsoft Corporation. Windows Error Reporting: Application Error (Event ID 1000). <https://learn.microsoft.com/en-us/windows/win32/wer/> · Miller, M., et al. (2008). *Debugging Heap Corruption with Application Verifier and Pageheap.* Microsoft. Canonical latent-heap-corruption diagnostics.

NVIDIA Corporation (2026). *CUDA Toolkit Blackwell Migration Guide.* Recommends CUDA 12.8 as near-term stable for sm\_120; cited at time-of-hypothesis, retained as valid for its narrower claim.

Ollama project (2025). Issue #14570, Qwen 3 structured-output truncation. <https://github.com/ollama/ollama/issues/14570>

Su, J., Lu, Y., Pan, S., Wen, B., & Liu, Y. (2023). "RoFormer: Enhanced Transformer with Rotary Position Embedding." *Neurocomputing.* Preprint [arXiv:2104.09864](https://arxiv.org/abs/2104.09864) (2021).

Wang, P., et al. (2024). "Qwen2-VL: Enhancing Vision-Language Model's Perception of the World at Any Resolution." [arXiv:2409.12191](https://arxiv.org/abs/2409.12191). Introduces three-dimensional M-RoPE.

Willison, S. (2024). "Grammar-constrained JSON: LLMs and structured output." <https://simonwillison.net/2024/Aug/23/structured-generation-in-llms/>

Liu, M., Zhong, S., Bi, W., Zhang, Y., Chen, Zhiyang, Chen, Zhenpeng, Liu, X., & Ma, Y. (2025). "A First Look at Bugs in LLM Inference Engines." *ACM Transactions on Software Engineering and Methodology.* [DOI 10.1145/3788873](https://doi.org/10.1145/3788873); preprint [arXiv:2506.09713](https://arxiv.org/abs/2506.09713). 929 bugs, 5 engines, 28 root causes, 65% Crash prevalence.

#### Chapter 21 · The Watcher

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-iv-the-evidence-what-worked/21-the-watcher/references-and-provenance.md)*.*

*Reference set at first-draft confidence; the full list is web-verified in the series reference-audit phase before release (the program's standing anti-hallucination discipline). No internal system identifiers appear in the body.*

**Process supervision & LLM-as-judge:** Lightman, H., et al. (2023). "Let's Verify Step by Step." [arXiv:2305.20050](https://arxiv.org/abs/2305.20050) · Zheng, L., et al. (2023). "Judging LLM-as-a-Judge with MT-Bench and Chatbot Arena." *NeurIPS 2023.*

**Tool interfaces & the protocol layer:** the Model Context Protocol tool-discovery literature, including MCP-Zero (Fei et al. 2025, [arXiv:2506.01056](https://arxiv.org/abs/2506.01056)) and work on tool-description quality (Hasan et al. 2026, [arXiv:2602.14878](https://arxiv.org/abs/2602.14878)), against which the phantom-tool-as-governance pattern is positioned as a distinct use of the tool-schema surface.

**Human-in-the-loop & active learning:** Settles, B. (2009). *Active Learning Literature Survey.* UW-Madison TR 1648 · Amershi, S., et al. (2014). "Power to the People: The Role of Humans in Interactive Machine Learning." *AI Magazine* 35(4).

**Companion papers (this series):** *The Sovereign Triad* (Chapter 1; the External Governor, of which the Watcher is the frontier-model realization) · *The Sovereign Corpus Engine* (Chapter 7; the intervention-corpus the Watcher trains on) · *The Drift Taxonomy* (Chapter 9; the failure ontology) · *Stateless by Construction* (Chapter 4; the hooks-vs-judgment division) · *Watcher KL-Drift Floor* (Chapter 19; the earlier-phase measurement this arc extends). Cited in-series by title.

### Part V · The frontier

#### Chapter 22 · Sovereign Sustainability

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-v-the-frontier/22-sovereign-sustainability/references-and-provenance.md)*.*

**Power, grid, carbon:** IEA (2024–2025). *Energy and AI: Energy Demand from AI.* · Nature (2025). "Data centres will use twice as much energy by 2030 – driven by AI." [d41586-025-01113-z](https://www.nature.com/articles/d41586-025-01113-z) · *Electricity Demand and Grid Impacts of AI Data Centers* (2025). [arXiv:2509.07218](https://arxiv.org/abs/2509.07218) · IEEE Spectrum (2024). "Will Energy-Hungry AI Create a Baseload Power Demand Boom?" [DOI 10.1109/MSPEC.2024.10630483](https://doi.org/10.1109/MSPEC.2024.10630483) · de Vries, A. (2023). "The growing energy footprint of artificial intelligence." *Joule* 7(10):2191–2194 · Patterson, D., et al. (2021). "Carbon Emissions and Large Neural Network Training." [arXiv:2104.10350](https://arxiv.org/abs/2104.10350) · Gupta, U., et al. (2022). "Chasing carbon: The elusive environmental footprint of computing." *IEEE Micro* 42(4):37–44.

**Water:** Li, P., Yang, J., Islam, M. A., & Ren, S. (2023). "Making AI Less 'Thirsty': Uncovering and Addressing the Secret Water Footprint of AI Models." [arXiv:2304.03271](https://arxiv.org/abs/2304.03271); republished in *Communications of the ACM* (2024).

**Jevons + rebound:** Jevons, W. S. (1865). *The Coal Question.* Macmillan · Sorrell, S. (2009). "Jevons' Paradox revisited: The evidence for backfire from improved energy efficiency." *Energy Policy* 37(4):1456–1469 · Greening, L. A., Greene, D. L., & Difiglio, C. (2000). "Energy efficiency and consumption – the rebound effect – a survey." *Energy Policy* 28(6-7):389–401.

**Edge + SLM + scaling:** Chen, J., & Ran, X. (2019). "Deep Learning With Edge Computing: A Review." *Proc. IEEE* 107(8):1655–1674 · Murshed, M. G. S., et al. (2021). "Machine Learning at the Network Edge: A Survey." *ACM Computing Surveys* 54(8) · Abdin, M., et al. (2024). "Phi-3 Technical Report." [arXiv:2404.14219](https://arxiv.org/abs/2404.14219) · Jiang, A. Q., et al. (2023). "Mistral 7B." [arXiv:2310.06825](https://arxiv.org/abs/2310.06825) · Gemma Team (2024). "Gemma: Open Models Based on Gemini Research and Technology." [arXiv:2403.08295](https://arxiv.org/abs/2403.08295) · Dennard, R. H., et al. (1974). "Design of Ion-Implanted MOSFETs with Very Small Physical Dimensions." *IEEE JSSC* 9(5):256–268 · Esmaeilzadeh, H., et al. (2011). "Dark Silicon and the End of Multicore Scaling." *ISCA 2011* · Patterson, D. A., & Hennessy, J. L. (2017). *Computer Architecture: A Quantitative Approach* (6th ed.) §1.9 · Kaplan, J., et al. (2020). "Scaling Laws for Neural Language Models." [arXiv:2001.08361](https://arxiv.org/abs/2001.08361) · Hoffmann, J., et al. (2022). "Training Compute-Optimal Large Language Models." [arXiv:2203.15556](https://arxiv.org/abs/2203.15556).

**Systems + method:** Senge, P. M. (1990). *The Fifth Discipline.* Doubleday · Sterman, J. D. (2000). *Business Dynamics.* McGraw-Hill · Forrester, J. W. (1961). *Industrial Dynamics.* MIT Press · Argyris, C., & Schön, D. A. (1978). *Organizational Learning.* Addison-Wesley · Popper, K. (1959). *The Logic of Scientific Discovery.* · Wicherts, J. M., et al. (2016). "Degrees of Freedom in Planning, Running, Analysing, and Reporting Psychological Studies." [*Front. Psychol.* 7:1832](https://doi.org/10.3389/fpsyg.2016.01832) · Wang, X., et al. (2023). "Self-Consistency Improves Chain of Thought Reasoning in Language Models." *ICLR 2023* · Andreessen Horowitz / Casado & Lauten (2019). "The Empty Promise of Data Moats." · NVIDIA (2025). *Data Flywheel* corporate documentation.

**In-series companions:** *Sovereign Optimization Flywheel* (the five-axis parent) · *Sovereign Domain Pruning* (Chapter 16; the 219-hour Phase-B envelope + L₃) · *Sovereign Imatrix Calibration* (Chapter 15; L₁) · *Sovereign CTI-NER* + *Corpus-Sovereign Self-Distillation* (Chapter 18; the L₄ chain) · *Sixteen Practices* (Chapter 5; §1.5 Pair + §5.6 recursive moat) · *The Sovereign Triad* · *The External Sentinel* · *Sovereign Safety Architecture* (the four-axis envelope this paper extends at industrial scale) · *Multi-Token Prediction on Consumer Blackwell* (the L₅ empirical-anchor companion, in the source repository) · *Sovereign Big-Model Compression* (the strongest single datum for the democratization claim: a 122B mixture-of-experts served for one operator on one 12 GB card, at higher fidelity and equal-or-better speed than the quantization-only alternative it replaced).

#### Chapter 23 · Built Portable

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-v-the-frontier/23-built-portable/references-and-provenance.md)*.*

*Reference set at draft confidence; each citation is web-verified in the series reference-audit phase before release. No internal system identifiers appear in the body.*

**Robotics substrate:** ROS2 / Open Robotics (DDS-based middleware) · Brooks, R. A. (1986). "A robust layered control system for a mobile robot." *IEEE Journal of Robotics and Automation* RA-2(1):14–23.

**Vision-language-action:** Brohan, A., et al. (2023). "RT-2: Vision-Language-Action Models Transfer Web Knowledge to Robotic Control." [arXiv:2307.15818](https://arxiv.org/abs/2307.15818) · Kim, M. J., et al. (2024). "OpenVLA: An Open-Source Vision-Language-Action Model." [arXiv:2406.09246](https://arxiv.org/abs/2406.09246) · Octo Model Team (2024). "Octo: An Open-Source Generalist Robot Policy." [arXiv:2405.12213](https://arxiv.org/abs/2405.12213).

**Companion papers (this series):** *Stateless by Construction* (Chapter 4; the IPC fabric and reload-grounding this argument rests on) · *The System Schematic* (the whole-stack map, including the portability seam) · *The Weaver Paradigm* (Chapter 24; the ephemeral-container substrate the migration also serves) · the companion hardware-platform document (the physical target of §10). Cited in-series by title.

**Acknowledgement:** The author thanks Derk Kraai for the post-publication review that identified the required-membership and liveness seam now registered in §11.

#### Chapter 24 · The Weaver Paradigm

*Full provenance:* [*the chapter's References & provenance page*](/osintelligence/part-v-the-frontier/24-the-weaver-paradigm/references-and-provenance.md)*.*

**Microkernel + OS infrastructure:** Klein, G., et al. (2009). "[seL4: Formal Verification of an OS Kernel](https://doi.org/10.1145/1629575.1629596)." *SOSP 2009* · Linux 6.12 sched\_ext (2024; [LWN #922405](https://lwn.net/Articles/922405/)) · Rust-for-Linux permanent status (Kernel Maintainer Summit, 2025) · Godoy et al. (2025). "Mojo: MLIR-Based Performance-Portable HPC Science Kernels on GPUs for the Python Ecosystem." *SC '25 Workshops*; [arXiv:2509.21039](https://arxiv.org/abs/2509.21039) (Mojo/MLIR designed by Lattner; this is the peer-reviewed anchor) · Sidero Labs Talos Linux · Microsoft Secure Boot 2011-CA expiry playbook (2026) · aya pure-Rust eBPF (2026).

**Compiler synthesis:** Android AutoFDO production numbers (2026) · Chen et al. (2026). "Magellan: Autonomous Discovery of Novel Compiler Optimization Heuristics with AlphaEvolve." [arXiv:2601.21096](https://arxiv.org/abs/2601.21096) · KerSpecGen (PLoS ONE 2026) + Springer 978-3-031-75434-0\_11 (the disconfirming pair).

**Blackwell:** "Microbenchmarking Blackwell" (2025). [arXiv:2512.02189](https://arxiv.org/abs/2512.02189) (sm\_100 tcgen05/TMEM) · consumer sm\_120 substrate: CUTLASS issues #2723/#2800/#2820/#3096; "Private LLM Inference on Consumer Blackwell GPUs" (2026). [arXiv:2601.09527](https://arxiv.org/abs/2601.09527); NVIDIA Blackwell whitepaper v1.1.

**Hardware trust + safety:** TCG (2014). TPM 2.0 Library Specification · Shamir (1979). *CACM* 22(11) · Krawczyk (2010). HKDF, [RFC 5869](https://www.rfc-editor.org/rfc/rfc5869) · Boneh, Lynn & Shacham (2001). LNCS 2248 · [NIST SP 800-89](https://doi.org/10.6028/NIST.SP.800-89) · Ames et al. (2017/2019). Control Barrier Functions, *ECC* · VeriBench (2025) + Lean 4 verification wave (2026) · Parno, McCune & Perrig (2010). *IEEE S\&P* · Sailer et al. (2004). *USENIX Security* · Anderson (2008). *Security Engineering* §16 · Saltzer & Schroeder (1975). *Proc. IEEE* 63(9) · Schneier (2000). *Secrets and Lies* §13 · Lampson (1973). *CACM* 16(10).

**Regulatory:** [EU Regulation 2024/1689 (AI Act)](https://eur-lex.europa.eu/eli/reg/2024/1689/oj) · [EU Directive 2024/1799 (Right to Repair)](https://eur-lex.europa.eu/eli/dir/2024/1799/oj) · Montana SB 212, Right to Compute Act (2025).

**Edge + sandboxing + side channels:** NVIDIA Jetson Orin Nano Super benchmarks (2025–26) · Frantar et al. (2023). GPTQ. *ICLR 2023*; [arXiv:2210.17323](https://arxiv.org/abs/2210.17323) · Hinton, Vinyals & Dean (2015). Distillation. [arXiv:1503.02531](https://arxiv.org/abs/1503.02531) · Bytecode Alliance WASI · McDonald (2025). Whisper Leak. [arXiv:2511.03675](https://arxiv.org/abs/2511.03675).

**Multi-agent + theory anchors:** Wang et al. (2023). Self-Consistency. [arXiv:2203.11171](https://arxiv.org/abs/2203.11171) · Du et al. (2023). Multiagent Debate. *ICML 2024*; [arXiv:2305.14325](https://arxiv.org/abs/2305.14325) · Liang et al. (2024). *EMNLP* · Juvenal, *Satirae* VI 347–348 · Gödel (1931) · Bostrom (2014). *Superintelligence* §9 · Russell (2019). *Human Compatible* §7.

**In-series companions:** *Sixteen Practices* (Chapter 5; the Pair §1.5 + consensus §5.7 + saturation §5.24) · *The Sovereign Triad* (the architectural joint-necessity this paper's governance chain pairs with) · *The External Sentinel* (the authoritative Sentinel specification; this paper's §4 defers to it) · *Sovereign Optimization Flywheel* · *Sovereign Safety Architecture* · *Sharded-MCP Architecture* · *Multi-Agent OODA Mesh* (the consensus protocol's operating topology) · *Corpus-Sovereign Self-Distillation* (Chapter 18; the H-AIOS-3 substrate) · *Sovereign Domain Pruning* (Chapter 16; the 219-hour envelope).

***

*Appendix B · The Sovereign Stack · aggregated verbatim from the chapters' own reference lists · CC BY 4.0 · Jamey Kistner / OSINTelligence LLC*
