Skip to main content
Independent Researcher in AI Governance and Safety-Critical Autonomous Systems

Burak Oktenli

Governance Architectures for Safe Autonomous Systems Burak Oktenli

Developing governance architectures intended to enable safe, accountable, and controllable deployment of autonomous systems in critical infrastructure, national security, and safety-critical autonomous environments. These architectures function as control layers governing how authority is granted, restricted, and recovered within autonomous systems. This work focuses on authority lifecycle control, decision integrity, and fail-safe recovery mechanisms that maintain human oversight in high-speed human-machine environments.

This research integrates physical testbeds, simulation platforms, and formal architectural design.

Research status: All eight patent applications are provisional (no patent granted or examined). All 48 publications are open-access preprints or published papers. All hardware platforms are research demonstrators at TRL 2-4, not commercial products.

8 U.S. Provisional Patents Submitted (HMAA, CARA, SATA, FLAME, ADARA, MAIVA, ERAM)
48 Published Works and Public Disclosures
Georgetown University, M.P.S. Applied Intelligence (In Progress)
140+ Professional Credentials from 25+ Institutions
Institute of Electrical and Electronics Engineers (IEEE) Member #102193505
American Institute of Aeronautics and Astronautics (AIAA) Member #1936005
Association for Computing Machinery (ACM) Member #9952787
Association for the Advancement of Artificial Intelligence (AAAI) Member #656504
Institute for Operations Research and the Management Sciences (INFORMS) Member #2009712
National Defense Industrial Association (NDIA) Member #1700222
Sigma Beta Delta International Honor Society, Lifetime Member #2007930
NIST AI RMF Trustworthy AI in Critical Infrastructure Profile Community of Interest (Member, 2026)
Audience Routing

Here's the right starting point.

This site serves different audiences with different needs. Pick the role that best describes you.

Defense Program Manager
Federal Program Reviewer
Defense Contractor / Prime
Automotive / ASIL-D Team
Think Tank / Policy Researcher
Academic Peer / Reviewer
Investor / SBIR Reviewer
Just Curious / General Visitor
See Full Audience Guide →

Research Mission

The Problem. Autonomous systems in defense and civilian transportation make decisions faster than humans can intervene, yet no standardized architecture enforces real-time authority governance. DoD Directive 3000.09 requires human control over autonomous weapons but lacks a technical enforcement mechanism. Nearly 40,000 Americans die annually in traffic crashes; NHTSA has documented 1,429 AV incidents (2021-2025); and the SELF DRIVE Act of 2026 (H.R. 7390) now mandates cybersecurity plans for "false vehicle control commands", but no validated reference architecture exists to implement these requirements.

The Gap. Policy frameworks (NIST AI RMF) establish principles but do not enforce them in hardware. Planning-layer safety systems (Mobileye RSS, NVIDIA SFF, SOTIF) constrain behavior but do not govern whether commands reach actuators. Software-only monitors can be bypassed. What is missing: a hardware-enforced architectural layer that continuously evaluates sensor trust, computes graded authority, enforces deliberation windows, and cuts actuator authority through a fail-safe when trust degrades, deterministically, in real-time, without firmware involvement.

My Contribution. Seven governance architectures managing the full authority lifecycle: trust evaluation, authority computation, command gating, consensus, deliberation, deception detection, and recovery:

  • SATA: Sensor trust attestation using weighted Dempster-Shafer fusion with cross-sensor validation (Patent: U.S. Provisional 64/002,453)
  • HMAA: Four-level authority computation (A3-A0) with asymmetric hysteresis: immediate downgrade, 5-15s delayed upgrade (Patent: 63/999,105)
  • CARA: Deterministic GREP-phase recovery: Govern → Restrict → Execute → Persist, with mutual exclusion (Patent: 64/000,170)
  • MAIVA: Byzantine fault-tolerant multi-agent consensus with CUSUM-augmented anomaly detection
  • FLAME: Mandatory deliberation windows preventing safety-critical actions without sustained authority (Patent: 64/005,607)
  • ADARA: Adversarial deception detection computing P(adversarial) from cross-sensor consistency and temporal anomalies
  • ERAM: Escalation risk quantification for AI-enabled command-and-control decision compression

These are documented in eight U.S. provisional patent submissions, thirty-one DOI-registered Zenodo records (including research papers with full simulation data for the rover testbed, the UAV platform, and the BLADE platform family from BLADE-EDGE through BLADE-FINANCE), and seventeen SSRN papers on AI governance and national security policy. Total: 48 published works with public DOIs and permalinks. The BLADE-SPACE orbital governance node (TRL 2-3 Preliminary Design, NASA SBIR EXPAND.3.S26B aligned) ships with a 15-document engineering package and is published on Zenodo (DOI 10.5281/zenodo.20183269).

Hardware Implementation. Twelve physical platforms demonstrating governance at increasing operational capability:

  • Rover Testbed, 37 components, ~$484, SATA-HMAA-CARA pipeline, seven fault scenarios demonstrated in simulation, TLA+ verified (23,748 states of the discrete authority automaton, under the assumption that instantaneous authority equals its target (continuous behaviour between decision instants not covered), 8 properties, of which 5 invariants and a liveness property are verified and 2 upgrade-path properties are vacuous at this bound). DOI: 10.5281/zenodo.19143190.
  • UAV Platform, 52 components, ~$4,200, MAVLink/HIL bridge for Cube Orange+ integration, five adversarial scenarios demonstrated in simulation, Monte Carlo campaign. DOI: 10.5281/zenodo.19128769.
  • BLADE-EDGE, 72 components, ~$139K, defense-grade directed-energy weapon governance. Dual Jetson AGX Orin + dual Zynq UltraScale+ FPGA. 9-module pipeline, MIL-STD-810G, hardwired safety interlock relay. DOI: 10.5281/zenodo.19177472.
  • BLADE-AV, 62 components, ~$16K, autonomous vehicle drive-by-wire governance. 9-module pipeline, three-leg redundant KILOVAC LEV200 fail-safe relay. ISO 26262 ASIL-D, SAE J3016 L4. twelve attack scenarios demonstrated in simulation. DOI: 10.5281/zenodo.19232130.
  • BLADE-MARITIME, 84 components, ~$43K, maritime surveillance governance. 9-module pipeline with hydroacoustic sonar, MAD, AIS spoofing detection, and sea-state authority damping. IP68 / MIL-STD-810G. DOI: 10.5281/zenodo.19246785.
  • BLADE-INFRA, 92 components, ~$12K, critical infrastructure governance. 9-module pipeline with ICS/SCADA integration (IEC 61850, Modbus, PROFINET). SIL 3 / NERC CIP / FIPS 140-2. DOI: 10.5281/zenodo.19277887.
  • BLADE-SPACE, 91 components, ~$505K, orbital governance node (TRL 2-3 Preliminary Design Phase). 9-stage pipeline on rad-tolerant compute (Microchip RTG4 FPGA + Aitech S-A1760 Venus SBC, hot-redundant); LEO 400-1200 km, 30 krad TID, 5-year design life; ECDSA P-256 audit chain; three-fault-tolerant safety interlock. 15-document engineering package. Aligned with NASA SBIR EXPAND.3.S26B. Zenodo DOI 10.5281/zenodo.20183269.
  • BLADE-CUAS, counter-UAS authority governance node, ~$43.5K reference BOM (TRL 2-3 hardware / 3-4 simulation). 9-stage AUTHREX pipeline; four-tier HMAA (T3/T2/T1/T0) with federal-SLTT handoff; Dempster-Shafer consensus across radar, RF, EO/IR, Remote ID, LIDAR; ECDSA P-256 court-admissible evidence chain (Fed. R. Evid. 901/902/803(6)). Sixth BLADE platform, ~75% reuse from BLADE-EDGE. Aligned with EO 14305 and the FY26 NDAA Safer Skies Act. Zenodo DOI 10.5281/zenodo.20299604.
  • BLADE-AGENT-HSM, agentic-AI hardware root of trust, ~$199 reference BOM (TRL 2-3 silicon / 3-4 emulator). Hardware companion to the AUTHREX-AGENT software shim; non-exportable ECDSA P-256/P-384 keys in a CC EAL6+ secure element; authority-tier state in a TPM 2.0 PCR bank; HKDF per-tool tokens; multi-modal tamper cascade. Five-opcode 64-byte ABI; USB-A stick and M.2 Key-E module. Seventh BLADE platform, first hardware root of trust. Aligned with CISA/NSA/Five Eyes agentic-AI guidance and FY26 NDAA Sections 1513 and 6601. Zenodo DOI 10.5281/zenodo.20299821.
  • BLADE-SWARM, attritable swarm authority governance, ~$1,333 per node reference BOM (TRL 3-4 simulator / spec, TRL 2 testbed). Byzantine-fault-tolerant two-phase consensus gated by SATA/HMAA/MAIVA across N=10/50/500 agents; tolerates f=(N-1)/3 compromised agents per quorum with a quorum-intersection bound; per-node ECDSA P-256 root of trust and hash-chained distributed audit ledger; TLA+ verified (5 safety, 3 liveness). Eighth BLADE platform; the multi-agent extension of the HMAA-UAV platform. Aligned with DoDD 3000.09, FY26 NDAA, and the NIST AI RMF. Zenodo DOI 10.5281/zenodo.20351198.
  • BLADE-INFRA-OT, authority-governed IT/OT bridge for cross-boundary OT command adjudication, ~1U fanless reference design (TRL 2-3 hardware / 3-4 simulation). Fail-closed, bump-in-the-wire governance appliance at the IT/OT segmentation boundary; AUTHREX adjudicates each cross-boundary command to propagate, hold, or isolate across four OT authority regimes; Xilinx Kria K26 governance plane and x86 network plane; 48 BOM line items, 35 electrical, 42 mechanical; seed-deterministic SHA-256 tamper-evident audit ledger. Ninth BLADE platform; the operational-technology companion to BLADE-INFRA. Aligned with NIST SP 800-82, ISA/IEC 62443, and NERC CIP. Zenodo DOI 10.5281/zenodo.20342067.
  • BLADE-FINANCE, authority governance for financial-sector AI decision systems under the U.S. Treasury Financial Services AI Risk Management Framework (TRL 3-4 simulation / TRL 2 hardware). Software-enforced authority-arbitration node; an eight-stage AUTHREX pipeline (VALIDATE through CARA) routes each transaction to autonomous clearance, supervised review, elevated confirmation, or manual hold; four-tier HMAA; a population-state coordination model across account, device, payee, and IP-cluster history; a retrospective stigmergic swarm-review module; SHA-256 canonical-form evidence chain; 36 components, 33 electrical, 32 mechanical, approximately $9,228 BOM. Tenth BLADE platform; first in the economic-security domain. Aligned with the U.S. Treasury FS AI RMF, NIST AI RMF, and EO 14179. Synthetic data only; not deployed in any financial institution. Zenodo DOI 10.5281/zenodo.20374692.

All ten BLADE platforms share the same governance pipeline architecture, demonstrating domain-agnostic portability across defense (DoDD 3000.09), automotive (ISO 26262), maritime (MIL-STD-810G), critical infrastructure (SIL 3 / NERC CIP), orbital (NASA EXPAND.3.S26B alignment), counter-UAS (EO 14305), and agentic AI (CISA/NSA/Five Eyes agentic-AI guidance). BLADE-SPACE is at TRL 2-3 (Preliminary Design); its V&V campaign is specified but not yet executed.

Software Implementation. A companion software authority-governance layer on the AUTHREX Systems venture site extends the same authority pipeline to additional settings, as six reference architectures (TRL 3-4, single-author research, not deployed): AUTHREX-AGENT (agentic AI), AUTHREX-ASSURE (pre-deployment assurance), AUTHREX-ICS-GATE (OT and critical infrastructure), AUTHREX-AGENT-CYBER (cyber-defense, governance only), AUTHREX-SPACECYBER (orbital autonomy), and AUTHREX-SANDBOX (test and evaluation). Several are software companions to the BLADE hardware platforms. AUTHREX-AGENT now has a runnable, test-backed reference implementation, the AUTHREX Governance Kernel, which moves the agent-governance concept from specification to an executable prototype with a passing 85-test suite and verified audit-ledger tamper detection; it remains synthetic-data, single-author research, not deployed.

Simulation and Verification. Nineteen browser-based simulations with seeded PRNG for bit-exact reproducibility. G*Power justified sample sizes, Bonferroni correction, Shapiro-Wilk normality tests. All run client-side with zero dependencies, any reviewer can independently verify results.

Current Status. Independent Researcher based in Washington, DC, pursuing Georgetown University M.P.S. Applied Intelligence (STEM, in progress). B.Sc. Computer Science Engineering (USF, 3.45 GPA). MBA International Business (Lynn, 4.0 GPA). Governance architectures published on Zenodo under CC BY 4.0; ERAM published on SSRN. Next-phase: physical validation, TLA+/UPPAAL formal verification, ROS 2/Gazebo HIL testing, and ASIL-D certification pathway. This research program is informed by progressive professional experience across data governance, infrastructure security, and critical infrastructure systems, see Professional Background below, and sustained engagement with the defense, aerospace, and AI communities through industry conferences and professional societies.

Authority Lifecycle Governance

Assignment, delegation, monitoring, and revocation of operational authority in autonomous decision systems. Implemented in HMAA (U.S. Provisional 63/999,105). 42-file Python package, 98 tests, TLA+ verified (23,748 states of the discrete authority automaton, under the assumption that instantaneous authority equals its target (continuous behaviour between decision instants not covered); of 8 stated properties, 5 invariants and 1 liveness held, 2 vacuous at this bound). DOI: 10.5281/zenodo.18861653.

Fail-Safe Control Recovery

Deterministic recovery protocol for authority lockout events with GREP phased recovery and terminal non-compensatory policy gate. Implemented in CARA (U.S. Provisional 64/000,170). DOI: 10.5281/zenodo.18917790.

Decision Integrity Monitoring

Hardware-anchored sensor trust computation using weighted Dempster-Shafer fusion with cross-sensor validation and adversarial dynamics. Implemented in SATA (U.S. Provisional 64/002,453). DOI: 10.5281/zenodo.18936251.

Escalation Risk Assessment

Quantitative framework for decision-time compression and escalation pathway modeling in AI-enabled command-and-control systems. Documented in the ERAM framework. Published on SSRN.

Flash War Latency Control

FLAME: deterministic latency injection middleware preventing autonomous escalation in multi-domain command environments. 5-state Circuit Breaker State Machine, Dynamic Delay Function D(A, tier, domain). Patent: U.S. Provisional 64/005,607. DOI: 10.5281/zenodo.19015618.

Multi-Agent Trust Verification

MAIVA: Byzantine-resilient swarm trust aggregation with CUSUM-augmented detection, graduated escalation, and DoDD 3000.09 action gate classification. 37 self-tests, TLA+ specification. DOI: 10.5281/zenodo.19015517.

Adversarial Deception-Aware Risk

ADARA: proactive deception prior adjusting authority based on P(adversarial). Deception Probability Engine with Bayesian update and Phantom Fleet detection. DOI: 10.5281/zenodo.19043924.

UAV Governance Platform

HMAA-UAV: authority-governed flight autonomy for contested environments integrating SATA-HMAA-CARA into a 52-component UAV with Cube Orange+ and Jetson Orin NX. five adversarial scenarios demonstrated in simulation. DOI: 10.5281/zenodo.19128769.

Rover Testbed Platform

Authority-governed rover implementing the full 8-stage SATA-HMAA-CARA pipeline on a 37-component dual-compute platform (RPi5 + ESP32). seven fault scenarios demonstrated in simulation. DOI: 10.5281/zenodo.19143190.

BLADE-EDGE Governance Node

Defense-grade edge computing platform implementing all seven governance architectures on dual-redundant Jetson AGX Orin + Zynq UltraScale+ FPGA. 72 components, 103 connections, MIL-STD-810G rated. Hardware-enforced safety interlock. ~$139K prototype BOM. DOI: 10.5281/zenodo.19177472.

BLADE-AV Governance Node

Authority-governed drive-by-wire safety architecture for autonomous vehicles. 9-module pipeline on Jetson AGX Orin + Zynq UltraScale+. Three-leg redundant KILOVAC fail-safe. 62 components, twelve attack scenarios demonstrated in simulation. ISO 26262 ASIL-D. ~$16K BOM. Cross-domain portability demonstrated against BLADE-EDGE. DOI: 10.5281/zenodo.19232130.

BLADE-MARITIME Governance Node

Authority-governed maritime surveillance node with hydroacoustic sonar, magnetic anomaly detection (MAD), and AIS spoofing detection. Four maritime mathematical extensions: D-S fused trust, recursive AIS deception-risk, sea-state authority damping α(H), acoustic-delay-aware Byzantine consensus. 84 components, IP68 / MIL-STD-810G / MIL-STD-461G CE102. Third domain instantiation. $43K total BOM. DOI: 10.5281/zenodo.19246785.

BLADE-INFRA Governance Node

Authority-governed critical infrastructure protection node for ICS/SCADA systems, power grid monitoring, water treatment, and pipeline operations. IEC 61850 GOOSE, Modbus TCP/RTU, PROFINET IO. Pilz PNOZ S7.1 SIL-3 safety relay. 92 components, IP65, NERC CIP, FIPS 140-2 Level 3. Fourth domain instantiation. $11,590 BOM. DOI: 10.5281/zenodo.19277887.

BLADE-SPACE Governance Node

Authority-governed orbital governance node for autonomous LEO platforms beyond ground-loop latency. Microchip RTG4 FPGA + Aitech S-A1760 Venus SBC hot redundancy with <200 ms failover; ECDSA P-256 audit chain anchored in rad-tolerant TPM; three-fault-tolerant payload/thruster firing interlock; ADARA multi-constellation GNSS spoofing detection. 91 components, 6U+ SmallSat payload module, 30 krad TID, 5-year LEO mission life. Fifth domain instantiation (TRL 2-3 Preliminary Design Phase, NASA SBIR EXPAND.3.S26B aligned). $505,440 reference BOM. 15-document engineering package; Zenodo DOI 10.5281/zenodo.20183269.

BLADE-CUAS Governance Node

Authority-governed Counter-Unmanned Aircraft Systems (C-UAS) node for the post-EO 14305 multi-agency environment. Passive governance layer between commercial detection sensors and authorized operators; four-tier HMAA (T3/T2/T1/T0) federal-SLTT authority handoff; MAIVA Dempster-Shafer consensus across radar, RF, EO/IR, Remote ID, and LIDAR; ADARA Remote ID spoofing detection; ECDSA P-256 court-admissible evidence chain aligned with Fed. R. Evid. 901/902/803(6). Sixth domain instantiation (TRL 2-3 hardware / 3-4 simulation), approximately 75% architectural reuse from BLADE-EDGE. Aligned with EO 14305 and the FY26 NDAA Title LXXXVI Safer Skies Act. ~$43.5K reference BOM. DOI: 10.5281/zenodo.20299604.

BLADE-AGENT-HSM Hardware Root of Trust

Tamper-evident hardware root of trust for autonomous AI agents and the hardware companion to the AUTHREX-AGENT software shim. Signs the agent audit ledger with non-exportable ECDSA P-256/P-384 keys in an NXP EdgeLock SE051 (CC EAL6+) secure element; holds the four-tier HMAA authority state in an Infineon SLB 9670 TPM 2.0 (FIPS 140-2 Level 2) PCR bank; derives per-tool HKDF tokens; aggregates sub-agent spawn-quorum signatures; multi-modal tamper cascade (active PCB mesh, voltage-glitch, thermal) zeroizes keys and latches T0. Five-opcode 64-byte ABI; USB-A stick and M.2 Key-E module from one 4-layer PCB. Seventh BLADE platform and first hardware root of trust. Verified by an adversarial high-assurance emulator (275/275 deterministic checks, P-384 signed golden-trace anchor). Aligned with CISA/NSA/Five Eyes Careful Adoption of Agentic AI Services (1 May 2026) and FY26 NDAA Sections 1513 and 6601. ~$199 reference BOM. DOI: 10.5281/zenodo.20299821.

BLADE-SWARM Governance Node

Authority-governed coordination layer for attritable multi-agent swarms. Byzantine-fault-tolerant two-phase commit gated by SATA, HMAA, and MAIVA across N=10/50/500 agents, tolerating f=(N-1)/3 compromised agents per quorum with a quorum-intersection bound; per-node ECDSA P-256 root of trust and a hash-chained distributed audit ledger; TLA+ verified (5 safety, 3 liveness properties). Eighth BLADE platform; the multi-agent extension of the HMAA-UAV platform. Aligned with DoDD 3000.09, the FY26 NDAA, and the NIST AI RMF. ~$1,333 per-node reference BOM (TRL 3-4 simulator / spec, TRL 2 testbed). DOI: 10.5281/zenodo.20351198.

BLADE-INFRA-OT Governance Node

Authority-governed IT/OT bridge for cross-boundary OT command adjudication. Fail-closed, bump-in-the-wire governance appliance at the IT/OT segmentation boundary; AUTHREX adjudicates each cross-boundary command to propagate, hold for deliberation, or isolate across four OT authority regimes (NOMINAL, ELEVATED, LOCKDOWN, SAFE-HALT); malformed input fails closed. Xilinx Kria K26 governance plane and x86 network plane, managed Ethernet switch with SFP+ ports, ATECC608 root of trust, TPM 2.0, and a Form C fail-closed fault relay in a 1U fanless form factor; 48 BOM line items, 35 electrical, 42 mechanical connections; seed-deterministic SHA-256 tamper-evident audit ledger. Ninth BLADE platform; the operational-technology companion to BLADE-INFRA (TRL 2-3 hardware / 3-4 simulation). Aligned with NIST SP 800-82, ISA/IEC 62443, and NERC CIP. DOI: 10.5281/zenodo.20342067.

BLADE-FINANCE Governance Node

Authority governance for financial-sector AI decision systems under the U.S. Treasury Financial Services AI Risk Management Framework. A software-enforced authority-arbitration node placing a hardware-anchored checkpoint between automated transaction-decision models and consequential financial actions; an eight-stage AUTHREX pipeline routes each transaction to autonomous clearance, supervised review, elevated confirmation, or manual hold; four-tier HMAA; population-state coordination across account, device, payee, and IP-cluster history; a retrospective stigmergic swarm-review module recovers coordinated low-and-slow rings the per-transaction path clears; SHA-256 canonical-form evidence chain. Dual-plane compute (Xilinx Kria K26 governance, NVIDIA L4 inference) with a YubiHSM 2 in a FIPS 140-2 Level 3 enclosure; 36 components, approximately $9,228 BOM. Tenth BLADE platform; first in the economic-security domain (TRL 3-4 simulation / TRL 2 hardware). Aligned with the U.S. Treasury FS AI RMF, NIST AI RMF, and EO 14179. Synthetic data only. DOI: 10.5281/zenodo.20374692.

Software Authority-Governance Layer

Eleven software systems on the AUTHREX Systems venture site that carry the AUTHREX authority pipeline into agentic AI, OT and critical infrastructure, cyber-defense (governance only), orbital autonomy, test and evaluation, run-time assurance, engagement-authority governance, and safe-state safing. Reference architectures (TRL 3-4 where assessed), single-author research, not deployed.

Burak Oktenli presenting on multi-domain missile defense

Policy and National Security Research

Burak Oktenli is an independent researcher working at the intersection of AI governance, national security, and critical infrastructure resilience. His public-source analysis and governance frameworks examine how authority, accountability, and human oversight should be structured for autonomous and AI-enabled systems. His commentary has been published by RUSI and other defense outlets, his work has been cited in the United States Federal Register and in academic research, and his analysis has been featured in curated national-security reviews including United Press International's Director's Corner and the Parliamentary Observatory on AI of the Parliamentary Assembly of the Mediterranean, and he has been interviewed live on France 24 English as an independent researcher on AI governance and autonomous systems.

Read the full Policy and National Security Research section →

Research Projects

Burak Oktenli

Governance Architecture Projects

Seven governance architectures forming a unified authority lifecycle framework. Each is published with a DOI on Zenodo, implemented as an interactive simulation, and connected to twelve physical research platforms: Rover Testbed (~$484), UAV Platform (~$4,200), BLADE-EDGE (~$139K), BLADE-AV (~$16K), BLADE-MARITIME (~$43K), BLADE-INFRA (~$12K), BLADE-SPACE (~$505K, TRL 2-3 Preliminary Design), BLADE-CUAS (~$43.5K, counter-UAS, TRL 2-3), BLADE-AGENT-HSM (~$199, agentic-AI hardware root of trust, TRL 2-3 silicon / 3-4 emulator), BLADE-SWARM (~$1,333/node, attritable swarm autonomy, TRL 3-4 simulator / spec), BLADE-INFRA-OT (~1U fanless, IT/OT bridge governance, TRL 2-3 hardware / 3-4 simulation), and BLADE-FINANCE (~$9,228, financial-sector AI governance, TRL 3-4 simulation / 2 hardware).

▶ VIDEO
AUTHREX in Five Minutes: Program Overview
Video Briefing 5 min 33 s · 1080p Synthetic · Non-Weapon Demonstration · Simulation Only

A narrated walkthrough of the runtime authority governance concept, the seven governance gates (SATA, HMAA, ADARA, MAIVA, FLAME, CARA, ERAM), graded authority, and cross-domain demonstrations, the same pipeline implemented by the architecture projects below.

HMAA
Human-Machine Authority Architecture
Patent Submitted DOI: 10.5281/zenodo.18861653

Real-time authority computation engine. Four-level state machine (A3-A0) with hysteresis transitions. TLA+ verified: 23,748 states of the discrete authority automaton, under the assumption that instantaneous authority equals its target (continuous behaviour between decision instants not covered), 8 properties, of which 5 invariants and a liveness property are verified and 2 upgrade-path properties are vacuous at this bound, 98 tests.

Authority LevelsTrust GatingTLA+ VerifiedProv. Patent 63/999,105
View Project Details
CARA
Control Authority Regulation Architecture
Patent Submitted DOI: 10.5281/zenodo.18917790

Deterministic recovery for authority lockout. Four-phase GREP pipeline (Guard, Reduce, Evaluate, Promote) with terminal non-compensatory policy gate.

GREP RecoverySafe-StopDeterministicProv. Patent 64/000,170
View Project Details
SATA
Sensor Attestation and Trust Anchoring
Patent Submitted DOI: 10.5281/zenodo.18936251

Foundation trust layer using weighted Dempster-Shafer belief functions. Four diagnostics: internal consistency, cross-sensor agreement, temporal stability, physical plausibility.

Dempster-ShaferSensor TrustCross-ValidationProv. Patent 64/002,453
View Project Details
FLAME
Flash War Latency Architecture
Patent Submitted DOI: 10.5281/zenodo.19015618

Strategic Latency as a formal system. 5-state Circuit Breaker with Dynamic Delay Function D(A, tier, domain) preventing autonomous escalation in multi-domain command.

Circuit BreakerFlash WarJADC2Prov. Patent 64/005,607
View Project Details
MAIVA
Multi-Agent Integrity Verification Architecture
Patent Submitted DOI: 10.5281/zenodo.19015517

Byzantine-resilient swarm trust aggregation. Trimmed weighted median resistant to f adversaries in 3f+1 rosters, CUSUM anomaly detection, DoDD 3000.09 action gates.

Byzantine ResilientSwarm TrustCUSUMTLA+ Spec
View Project Details
ADARA
Adversarial Deception-Aware Risk Architecture
Patent Submitted DOI: 10.5281/zenodo.19043924

Proactive deception prior adjusting authority via P(adversarial). Deception Probability Engine with Bayesian update. Phantom Fleet detection for AI-hallucinated hostile scenarios.

Deception PriorPhantom FleetBayesian UpdateAdversarial AI
View Project Details
ERAM
Escalation Risk Assessment Model
Cross-Domain Escalation Risk Quantification for AI-Enabled Command and Control
Patent Submitted SSRN ID: 6176802

Escalation risk quantification across interconnected autonomous command nodes. Models how autonomous actions cascade across domain boundaries. 6 scenarios, 600 Monte Carlo runs.

Decision CompressionCascade RiskJADC2Cross-DomainMonte Carlo
View Project Details
Patents & Technical Inventions

Provisional patent disclosures for the governance architectures, each with application numbers, DOIs on Zenodo, source code, and an interactive simulation.

View All Patents →

Software Research Platforms

The software authority-governance layer that the hardware platforms anchor in silicon. Published and maintained on the AUTHREX Systems venture site, where each system has a full technical page with scenarios, standards mapping, and a reference design.

AUTHREX.Systems

AUTHREX Systems is a research initiative demonstrating authority lifecycle governance infrastructure for autonomous systems. It integrates the seven governance frameworks, ten BLADE hardware platforms, and thirty-seven simulations developed through this research program into a single unified platform, providing end-to-end authority control across defense, maritime, infrastructure, and autonomous vehicle domains.

Standards Alignment: DoDD 3000.09 (Autonomy in Weapon Systems), NIST AI RMF 1.0 (AI Risk Management), MIL-STD-882E (System Safety), ISO 26262 ASIL-D (Automotive), IEC 61508 SIL 3 (Industrial), NERC CIP (Energy Grid), FIPS 140-2 Level 3 (Cryptographic).

AUTHREX Systems program overview film (9:30)
AGENT
AUTHREX-AGENT
Authority-Lifecycle Governance Shim for Autonomous AI Agents
authrex.systems Software companion to BLADE-AGENT-HSM

Software authority-lifecycle shim for autonomous AI agents: four-tier HMAA authority gating, per-tool HKDF authorization, spawn quorum, and a hash-chained audit ledger, anchored in hardware by the BLADE-AGENT-HSM root of trust. Designed to contain indirect prompt-injection attacks against tool-using agents. Single-author research, not deployed.

Agentic AIHMAA TiersTool AuthorizationAudit LedgerPrompt-Injection Defense
View on AUTHREX Systems
KERNEL
AUTHREX Governance Kernel
Runnable Reference Implementation of AUTHREX-AGENT (TRL 3-4)
Executable · Test-Backed85 Tests Passing · Docker-Verified

The first executable, test-backed implementation of the AUTHREX authority-governance pipeline for agentic AI. MCP-based agent tool governance, four-tier HMAA authority enforcement, human approval gating with role-based access control, signed policy loading, and a hash-chained audit ledger with verified tamper detection (forgery, reordering, deletion, and tail truncation). 85 self-generated tests passing with zero unauthorized privileged executions in synthetic scenarios; Docker build and run verified; resumable validation harness. Synthetic data only; no operational validation or agency endorsement claimed.

Agentic AIMCP GovernanceHMAA TiersRBACSigned Audit LedgerDocker-Verified
Repository release pending legal review
ASSURE
AUTHREX-ASSURE
Pre-Deployment Authority Governance for Autonomous Systems
authrex.systemsReference architecture (TRL 3-4)

Pre-deployment authority governance for autonomous systems: assurance gating that must clear before a system is permitted to act. Reference architecture aligned with the 2026 National Cybersecurity Strategy and NDAA Section 1533. Single-author research, not deployed.

Pre-DeploymentAssurance GatingNDAA 1533Nat'l Cyber StrategyAutonomy
View on AUTHREX Systems
ICS-GATE
AUTHREX-ICS-GATE
Operational-Technology Authority Governance for Critical Infrastructure
authrex.systemsSoftware companion to BLADE-INFRA-OT

Operational-technology authority governance for critical infrastructure, gating AI actions across the IT/OT boundary. Aligned with CISA/NSA AI-in-OT principles, NIST SP 800-82, ISA/IEC 62443, and NERC CIP. Single-author research, not deployed.

ICS/OTNIST 800-82ISA/IEC 62443NERC CIPIT/OT Boundary
View on AUTHREX Systems
CYBER
AUTHREX-AGENT-CYBER
Autonomous Cyber-Defense Authority Governance
authrex.systemsGovernance only, no offensive function

Authority governance for autonomous cyber-defense agents, constraining what a defensive AI may do and when. Governance only, with no offensive function. Aligned with Five Eyes Careful Adoption of Agentic AI Services, DARPA AIxCC, and NDAA Section 1513.

Cyber-DefenseFive EyesDARPA AIxCCNDAA 1513Defensive Only
View on AUTHREX Systems
SPACE
AUTHREX-SPACECYBER
Onboard Authority Governance for Orbital Autonomy
authrex.systemsSoftware companion to BLADE-SPACE

Onboard authority governance for orbital autonomy, gating autonomous spacecraft actions under intermittent ground contact. Aligned with NASA SBIR 2026 BAA subtopic EXPAND.3.S26B and Space Policy Directive 5. Single-author research, not deployed.

Orbital AutonomyNASA SBIREXPAND.3.S26BSPD-5Onboard Governance
View on AUTHREX Systems
SANDBOX
AUTHREX-SANDBOX
Test and Evaluation Authority Governance
authrex.systemsReference architecture (TRL 3-4)

Test-and-evaluation authority governance: governs what an AI under evaluation is permitted to do inside the sandbox. Aligned with NDAA Section 1534 and Section 1533. Single-author research, not deployed.

Test & EvaluationSandboxNDAA 1534NDAA 1533Containment
View on AUTHREX Systems
RTA
AUTHREX-RTA
Run-Time-Assurance Governor Console
authrex.systemsStandalone console (simulation)

Standalone run-time-assurance governor console on the ASTM F3269 and Simplex reference model: an independent invariant monitor evaluates each proposed authorization before it is applied, with a SHA-256 hash-chained decision ledger. Governance and assurance only. Single-author research, not deployed.

Run-Time AssuranceASTM F3269SimplexInvariant MonitorDecision Ledger
View on AUTHREX Systems
ENGAGE
AUTHREX-ENGAGE
Fail-Closed Engagement-Authority Governance Console
authrex.systemsGovernance only, no weapons function

Standalone fail-closed engagement-authority governance console: an invariant monitor adjudicates each proposed action to one of five outcomes (authorize, clamp, downgrade, deny, or hold for human) before it can proceed. Governance and assurance only, with no targeting or weapons function. Single-author research, not deployed.

Engagement AuthorityFail-ClosedFive OutcomesHuman HoldDecision Ledger
View on AUTHREX Systems
SAFING
AUTHREX-SAFING
Fail-Safe Safe-State Authority Governance Console
authrex.systemsStandalone console (simulation)

Standalone fail-safe safe-state authority console: a governor adjudicates every safing command (safe-state entry, hold, deepen, and re-arm gated exit) with a SHA-256 hash-chained decision ledger, drawing on NASA fault-management safe-mode practice and the Simplex safety-controller pattern. Governance and assurance only. Single-author research, not deployed.

Safe StateFail-SafeRe-Arm GateSafe-Mode PracticeDecision Ledger
View on AUTHREX Systems
TEAM
AUTHREX-TEAM
Team Decision-Authority Governance Prototype
authrex.systemsHardened prototype (simulation)

Standalone team authority governance prototype: an independent arbiter over an untrusted allocator maintains exactly one eligible authenticated holder per responsibility, never zero (a gap) and never two (split authority), with bounded reversible transfers and a safe-hold fallback. Governance and assurance only. Single-author research, not deployed.

Team AuthorityOne Holder Per RoleBounded TransferSafe-Hold FallbackDecision Ledger
View on AUTHREX Systems
REDLINE
AUTHREX-REDLINE
Positive Human Control Governance Prototype
authrex.systemsHardened prototype (simulation)

Standalone positive human control prototype: the critical authorization can be held only by two distinct authenticated humans, a machine is never eligible to hold it, and the fail-safe state is NO-GO, with a hash-chained record and deterministic replay. Governance and assurance only, with no targeting or weapons function. Single-author research, not deployed.

Positive Human ControlTwo-Person RuleHuman-Only KeysFail-Safe NO-GODeterministic Replay
View on AUTHREX Systems

Hardware Research Platforms

Twelve physical platforms implementing the governance architectures at increasing levels of operational capability. Each is published as a complete reproducible artifact package with full hardware specifications, simulation data, and assembly documentation.

Authority-Governed Autonomy Rover Testbed
Design Complete · Build In Progress DOI: 10.5281/zenodo.19143190
Authority-Governed Assured Autonomy Rover Testbed

A low-cost experimental platform for studying authority-governed autonomy in safety-critical robotic systems under contested conditions. The rover continuously evaluates how much it can trust each of its sensors, computes how much authority the autonomy software should have right now, and falls back to a safe state when trust collapses. All in a dual-compute architecture (Raspberry Pi 5 + ESP32). 37 verified components, 76 electrical connections, 7 defined experiments. Platform cost under $500.

SATA HMAA CARA Trusted Autonomy Sensor Spoofing ROS 2 Raspberry Pi 5 ESP32
View Project Details
HMAA-UAV Authority-Governed Autonomous Drone Platform
Design Complete · Build In Progress DOI: 10.5281/zenodo.19128769
Authority-Governed UAV Platform (HMAA-UAV)

A trust-governed autonomous drone where every flight decision is evaluated by sensor trust fusion (SATA), authority governance (HMAA), and recovery logic (CARA). Cube Orange+ flight controller with NVIDIA Jetson Orin NX AI companion computer. 52 verified components, 48 electrical connections, 49 mechanical assemblies. Carbon fiber quadcopter frame.

SATA HMAA CARA UAV Autonomy Contested Environments Jetson Orin NX ArduPilot
View Project Details
BLADE-SWARM reference node hardware render: a Holybro X500 V2 quadrotor carrying a Pixhawk 6X flight controller, a Raspberry Pi 5 companion computer, a LoRa mesh radio whip antenna, a GPS module on a mast, and an addressable status LED ring on the centre plate
TRL 3-4 simulator / spec · TRL 2 testbed · Eighth BLADE Platform DoDD 3000.09 · FY26 NDAA · NIST AI RMF
BLADE-SWARM Governance Node

Authority governance for attritable autonomous swarms at N=10 (physical testbed), N=50 (combined operation), and N=500 (DAWG-class). Each agent runs a Byzantine-fault-tolerant two-phase consensus gated by SATA peer trust, the four-tier HMAA authority state, and weighted MAIVA voting before the swarm commits, tolerating up to f=(N-1)/3 compromised agents per quorum with a quorum-intersection bound and safe-halt-by-default under denied or degraded RF. Per-node ECDSA P-256 root of trust (ATECC608B) feeds a hash-chained distributed audit ledger. TLA+ verified (5 safety + 3 liveness); ~$1,333 per node. It governs decision authority and audit; it does not govern weapons. Eighth domain: defense, automotive, maritime, critical infrastructure, orbital, counter-UAS, agentic AI, swarm autonomy.

SATA HMAA MAIVA FLAME CARA Byzantine FT ECDSA P-256 TLA+ DAWG
View Project Details
BLADE-EDGE Governance Node, Defense-Grade Edge Computing
Design Complete · Prototype Specification Defense-Grade Hardware
BLADE-EDGE Governance Node

A rugged, portable edge computing device serving as the ethical decision-making authority for autonomous defense platforms. Implements the complete 9-module governance pipeline (SATA → ADARA → IFF → HMAA → MAIVA → FLAME → CARA → BDA → EFFECTOR) on dual-redundant Jetson AGX Orin + Zynq UltraScale+ hardware. 72 components, 103 connections, MIL-STD-810G rated. Hardware-enforced safety interlock (normally-open relay). ~$139K prototype BOM.

SATA HMAA ADARA MAIVA FLAME CARA Jetson Orin Zynq FPGA MIL-STD-810G
View Project Details
BLADE-AV Governance Node, Autonomous Vehicle Safety
Published on Zenodo · DOI: 10.5281/zenodo.19232130 ISO 26262 ASIL-D Target
BLADE-AV Governance Node

Authority-governed drive-by-wire safety architecture for autonomous vehicles. 9-module governance pipeline on Jetson AGX Orin + Zynq UltraScale+. Three-leg redundant KILOVAC fail-safe relay. 62 components, twelve attack scenarios demonstrated in simulation. ~$16,287 BOM. Cross-domain portability demonstrated against BLADE-EDGE defense variant.

SATA HMAA MAIVA FLAME CARA ISO 26262 V2X KILOVAC Relay
View Project Details
BLADE-MARITIME Governance Node, Maritime Defense
Published on Zenodo · DOI: 10.5281/zenodo.19246785 MIL-STD-810G · IP68 Maritime
BLADE-MARITIME Governance Node

Authority-governed maritime surveillance node with hydroacoustic sonar, magnetic anomaly detection (MAD), and AIS spoofing detection. Four maritime mathematical extensions to the BLADE governance pipeline. 84 components, IP68 enclosure, MIL-STD-461G CE102 power chain. Third domain instantiation: defense → automotive → maritime.

SATA HMAA Hydroacoustic MAD AIS Spoofing Sea-State α(H) Acoustic BFT IP68
View Project Details
BLADE-INFRA Governance Node, Critical Infrastructure
Published on Zenodo · DOI: 10.5281/zenodo.19277887 SIL 3 · NERC CIP · FIPS 140-2
BLADE-INFRA Governance Node

Authority-governed critical infrastructure protection node for ICS/SCADA systems, power grid monitoring, and industrial process control. IEC 61850 GOOSE, Modbus TCP/RTU, PROFINET IO integration. Pilz PNOZ S7.1 SIL-3 safety relay. 92 components, IP65 DIN-rail enclosure. Fourth domain instantiation: defense → automotive → maritime → critical infrastructure.

SATA HMAA ICS/SCADA Power Grid NERC CIP SIL 3 Modbus IEC 61850
View Project Details
BLADE-INFRA-OT reference appliance: a 1U fanless metal enclosure with status LEDs, ventilation, and an inspection window exposing the Xilinx Kria K26 governance plane and x86 network plane modules and network interfaces
TRL 2-3 hardware / 3-4 simulation · Ninth BLADE Platform NIST SP 800-82 · ISA/IEC 62443 · NERC CIP
BLADE-INFRA-OT IT/OT Bridge Governance Node

A fail-closed, bump-in-the-wire governance appliance at the segmentation boundary between corporate IT networks and operational-technology control assets. Each cross-boundary command is parsed, scored, and adjudicated through the AUTHREX pipeline to one of three actions: propagate, hold for deliberation, or isolate. Four OT authority regimes; malformed input fails closed. Xilinx Kria K26 governance plane and x86 network plane, managed Ethernet switch with SFP+ ports, ATECC608 root of trust, TPM 2.0 measured boot, and a Form C fail-closed fault relay in a 1U fanless form factor (48 BOM line items). Every decision is written to a seed-deterministic SHA-256 hash-chained audit ledger. Ninth domain: the IT/OT boundary (operational technology), companion to BLADE-INFRA.

IT/OT bridge OT security Kria K26 ATECC608 TPM 2.0 SHA-256 ledger fail-closed
View Project Details
BLADE-SPACE Governance Node system schematic: 91-component node graph showing all subsystems (compute, sensors, communications, power, security) with 134 electrical connections
TRL 2-3 · Preliminary Design Phase · 15-Doc Engineering Package NASA SBIR EXPAND.3.S26B Aligned
BLADE-SPACE Governance Node

Authority-governed orbital governance node for autonomous LEO platforms beyond ground-loop latency. Microchip RTG4 FPGA + Aitech S-A1760 Venus SBC hot redundancy with <200 ms failover; ECDSA P-256 audit chain anchored in rad-tolerant TPM; three-fault-tolerant payload/thruster firing interlock. 91 components, 6U+ SmallSat payload module, 30 krad TID, 5-year LEO mission life. Fifth domain instantiation: defense → automotive → maritime → critical infrastructure → orbital.

SATA HMAA CARA LEO 400-1200 km 30 krad TID RTG4 FPGA ECDSA P-256 NASA EXPAND.3.S26B
View Project Details
BLADE-CUAS Governance Node hardware render: a compact transportable metal enclosure with a hexagonal mesh intake, power button, three status LEDs, and a viewing window exposing the internal Jetson AGX Orin and Kria K26 compute boards
TRL 2-3 hardware / 3-4 simulation · Sixth BLADE Platform EO 14305 · FY26 NDAA Safer Skies Act
BLADE-CUAS Governance Node

Authority-governed Counter-Unmanned Aircraft Systems (C-UAS) node for the post-EO 14305 multi-agency environment. Passive governance layer between commercial detection sensors and authorized operators; four-tier HMAA (T3/T2/T1/T0) with federal-SLTT handoff; Dempster-Shafer multi-modal consensus through MAIVA; ECDSA P-256 court-admissible evidence chain aligned with Fed. R. Evid. 901/902/803(6). ~75% architectural reuse from BLADE-EDGE; ~$43.5K reference BOM. Sixth domain: defense, automotive, maritime, critical infrastructure, orbital, counter-UAS.

SATA HMAA ADARA MAIVA FLAME ERAM CARA EO 14305 ECDSA P-256
View Project Details
BLADE-AGENT-HSM hardware render: a compact sealed module with a glass-top inspection window exposing the internal PCB and secure microcontroller, a finned side vent, a tri-colour status LED matrix, and two sealed connectors
TRL 2-3 silicon / 3-4 emulator · Seventh BLADE Platform CISA/NSA agentic-AI · FY26 NDAA §1513 · §6601
BLADE-AGENT-HSM Hardware Root of Trust

Tamper-evident hardware root of trust for autonomous AI agents and the hardware companion to the AUTHREX-AGENT software shim. Signs the agent audit ledger with non-exportable ECDSA P-256/P-384 keys in a CC EAL6+ secure element; holds the four-tier HMAA authority state in a TPM 2.0 PCR bank; derives per-tool HKDF tokens; multi-modal tamper cascade zeroizes keys and latches T0. Five-opcode 64-byte ABI; USB-A stick and M.2 Key-E module; ~$199 reference BOM. Verified by an adversarial high-assurance emulator (275/275 deterministic checks). Seventh domain: defense, automotive, maritime, critical infrastructure, orbital, counter-UAS, agentic AI.

SE051 EAL6+ TPM 2.0 HMAA ECDSA P-256/384 HKDF AUTHREX-AGENT NDAA 1513
View Project Details
BLADE-FINANCE reference authority node: a 1U rack-mount appliance with a governance plane, an inference plane, a host security plane, and a hardware security module
TRL 3-4 simulation / TRL 2 hardware · Tenth BLADE Platform Treasury FS AI RMF · NIST AI RMF · EO 14179
BLADE-FINANCE Financial-Sector Governance Node

A hardware-anchored authority layer between automated transaction-decision models and consequential financial actions. Every transaction is scored through the eight-stage AUTHREX pipeline and routed to one of four authority tiers: autonomous clearance, supervised review, elevated confirmation, or manual hold. A retrospective stigmergic swarm-review module recovers coordinated low-and-slow rings the per-transaction path clears. Aligned to the U.S. Treasury Financial Services AI RMF. First BLADE platform in the economic-security domain. Synthetic data only; not deployed in any financial institution.

Financial-sector AI HMAA authority SHA-256 ledger Deepfake auth Swarm review Kria K26 YubiHSM 2 Wilson intervals
View Project Details

Interactive Technical
Demonstrations

Fully functional, browser-based implementations that execute the actual published algorithms with real-time computation and verifiable outputs, not mockups.

37
Interactive Simulations
7
Governance Architectures
12
Hardware Research Platforms
View All Simulations View All Repositories →

Problem, Solution, Impact

ProblemArchitectureImpact
Sensor spoofing and degraded inputsSATADetects trust collapse and prevents unsafe decisions from corrupted data
Unsafe autonomous actions under uncertaintyHMAAEnforces authority constraints on system behavior based on computed trust
Failure recovery instabilityCARAProvides structured, phased recovery instead of binary reset or crash
Multi-agent trust breakdownMAIVAEnables trust-aware participation control in multi-agent systems
Escalation risk in autonomous decisionsFLAMEIntroduces mandatory deliberation windows before critical actions
Adversarial deception in command systemsADARADetects and mitigates deceptive inputs using Bayesian deception estimation
Decision-time compression in AI-enabled C2ERAMQuantifies escalation risk across interconnected multi-domain command environments
The unified framework · seven architectures across the BLADE platforms, click to expand

All architectures presented in this work are components of a unified authority-governed autonomy framework. SATA evaluates system trust, HMAA computes authority constraints, CARA enforces recovery behavior, MAIVA governs multi-agent participation, FLAME regulates decision timing, ADARA detects adversarial deception, and ERAM quantifies escalation risk in command-and-control environments. Together, these components form a structured approach to controlling autonomous systems under uncertainty. The BLADE-EDGE Governance Node implements all seven architectures in a single defense-grade device, and the BLADE-AV Governance Node demonstrates automotive portability under ISO 26262, and the BLADE-MARITIME Governance Node extends the pipeline to maritime surveillance under MIL-STD-810G, and the BLADE-INFRA Governance Node extends it to critical infrastructure protection under SIL 3 / NERC CIP, and the BLADE-SPACE Governance Node extends it to the orbital domain (TRL 2-3 Preliminary Design Phase) with radiation-tolerant compute and ECDSA-anchored audit, aligned with NASA SBIR EXPAND. The BLADE-CUAS Governance Node extends it to the counter-UAS domain, arbitrating federal-SLTT authority for Counter-Unmanned Aircraft Systems operations under EO 14305 and the FY26 NDAA Safer Skies Act. The BLADE-AGENT-HSM extracts the trust anchor into a standalone tamper-evident device, the hardware companion to the AUTHREX-AGENT software shim, extending the same hardware-rooted authority and audit chain to autonomous AI agents under the CISA/NSA/Five Eyes agentic-AI guidance and FY26 NDAA Sections 1513 and 6601. The BLADE-SWARM Governance Node extends the pipeline to coordinated multi-agent swarms, gating every swarm commit on Byzantine-fault-tolerant sub-quorum consensus (SATA, HMAA, MAIVA) across N=10/50/500 attritable agents with a hash-chained distributed audit ledger, aligned with DoDD 3000.09 and the FY26 NDAA. The BLADE-INFRA-OT Governance Node extends the pipeline to the IT/OT boundary, adjudicating each cross-boundary command at the segmentation seam between corporate IT networks and operational-technology control assets, failing closed on malformed input, aligned with NIST SP 800-82, ISA/IEC 62443, and NERC CIP.

Future Research Directions

Exploratory directions under consideration. Neither has been built, simulated, or published, and neither is part of the current portfolio.

The AUTHREX authority-governance model is designed to generalize across safety-critical domains beyond those already instantiated. Two public-interest directions are under consideration:

Medical-device AI governance (working name BLADE-MED-DEVICE). Applying authority arbitration to AI/ML-enabled medical devices, framed against the U.S. FDA Software-as-a-Medical-Device Action Plan and Predetermined Change Control Plan (PCCP) pathway, FDA premarket cybersecurity guidance, IEC 62304, and ISO 13485.

Rail autonomous-control authority (working name BLADE-RAIL). Extending the model to rail and transit control, framed against FRA Positive Train Control, CBTC standards (IEEE 1474, IEC 62290), and the Transportation Systems critical-infrastructure sector.

View Technical Reference →

Technology readiness levels, terminology, and dual-use mapping

MethodologyTRL AssessmentTerminology MappingDual-Use Matrix

Research Papers
& Policy Analysis

48 DOI-registered research works across Zenodo and SSRN covering autonomous systems governance, AI defense doctrine, escalation risk, authority lifecycle architecture, and quantum-communications governance. All publications are open-access and verifiable via DOI or SSRN abstract IDs.

48
Published Works (Zenodo + SSRN)
17
SSRN Scholarly Papers
31
Zenodo Deposits
8,294
SSRN Downloads

Distribution: 17 SSRN scholarly papers (Author Rank 14,528 of 2,808,007, top 0.52%), 31 Zenodo DOI deposits (Georgetown University institutional affiliation). Topics span autonomous systems governance, AI defense doctrine, escalation risk in AI-enabled military command and control, authority lifecycle governance, autonomous space operations, quantum-communications governance, and counter-tunnel architectures.

View All Publications SSRN Author Page ↗ Zenodo Profile ↗
Published Commentary · 88 pieces, click to expand
Eurasia Review · August 2026 · Op-Ed
COVID Had Quarantines and Vaccines. A Cyber Pandemic Could Infect the Cure. ↗
Draws the disanalogy the public-health comparison usually hides: countermeasures against a biological outbreak sit outside the pathogen’s reach, while the machinery for detecting, coordinating and remediating a digital one can share infrastructure with what it is responding to. Applies requirements the author has published elsewhere: that channels sharing a dependency do not supply the independent evidence a count implies, that continuity planning name pre-identified alternatives, local fallbacks and degraded operating modes, and that a decision to restrict or suspend authority be capable of becoming an actual change in behaviour rather than remaining advice.
RealClearDefense · August 2026 · Op-Ed
A Quantum Advantage Is Not a Defense Capability Until It Survives the Whole System ↗
States the translation problem directly: physics papers can demonstrate a real advantage under carefully defined conditions, but defence organisations do not buy error exponents, witness values, or laboratory plots. Credits the underlying science with its citations, then holds that a short laboratory configuration with a digital receiver did not solve aperture, atmospheric loss, clutter, mobility, latency, countermeasures, target cross section, or long-range storage. Proposes a no-free-advantage rule, under which every claimed gain is reported beside the total system cost required to produce it, and four acquisition gates: physical advantage against an optimised classical baseline under matched constraints; integrated advantage surviving real source, channel, detector, calibration, timing and processing losses; assurance advantage, meaning the system can detect when the conditions supporting its claim no longer hold and degrade safely; and mission advantage justifying lifecycle cost. Warns that a learned confidence score must not be allowed to conceal a failing clock, invalid calibration, lost correlation or degraded sensor state.
Eurasia Review · August 2026 · Analysis
AI Can Discover New Materials Faster Than Science Can Validate Them ↗
Tenth in the author’s sequence on machine-assisted scientific inference, addressing what happens when generation outruns the capacity to confirm. Applies the promotion boundary he has established across the series: a system may propose candidates, rank them, quantify uncertainty and recommend what to examine next, while moving from a proposed candidate to an established result requires controlled measurement, discriminating tests and independent replication, none of which faster generation supplies. Carries the related requirements that an unresolved status remain a legitimate output and that the extent of a search belong in the claim it produces.
Eurasia Review · August 2026 · Op-Ed
What the Next Collider Can Really Give the World Beyond Particle Physics ↗
Asks what a very large scientific instrument actually delivers beyond its primary science, applying the accounting discipline the author has developed elsewhere: that a claim of value is meaningful only against a stated and competitive comparison, that an unmeasured term must remain visible as an unknown rather than inherit full performance by silence, and that the conditions under which a benefit is obtained belong in the claim it supports.
Eurasia Review · August 2026 · Analysis
Ratcliffe’s Moscow Visit Highlights the Strategic Value of Intelligence Backchannels Across Eurasia ↗
Declines to read an undisclosed agenda as evidence of a particular mission, stating repeatedly what the public record does and does not establish, and argues instead from what is verifiable: that a functioning channel exists between adversaries and is treated as potentially valuable. Distinguishes deconfliction from negotiation, and holds that such a channel is strongest when it carries warnings, clarifies intentions, tests whether an opening is genuine and manages escalation, while consequential policy decisions remain inside formal diplomatic and allied processes. Notes that a channel can transmit information accurately without changing the recipient’s policy, and that the most useful outcome may be a reliable negative answer. States the governing objective as controlled uncertainty rather than trust.
Eurasia Review · August 2026 · Analysis
Bill Gates Is Right About AI Governance: Institutions Need Systems They Can Actually Govern ↗
Accepts the call for new institutions and identifies the layer beneath it: institutions cannot govern systems that were never engineered to be governable. A regulator cannot supervise a decision the system cannot reconstruct, an oversight body cannot enforce a human-approval requirement the architecture permits bypassing, and an agreement cannot impose a limit no party can determine was followed. Names the discipline governance engineering and sets out its components: extending human-reserved work to human-reserved authority; separating capability from authority, since the critical boundary is between prediction and permission; an authority envelope stating what a system may do, under which conditions, with which data and tools, for whom, and under what supervision; evidence institutions can actually inspect; approval that attaches to a defined configuration rather than becoming permanent; and a revocation architecture, because governance without an executable path to revocation is advice.
Eurasia Review · August 2026 · Analysis
The New U.S. Science Strategy Is Quietly Redrawing Eurasia’s Innovation Map ↗
Reads the new national science and technology strategy as defining the architecture of a trusted innovation network rather than only a technology portfolio, and argues that the strategic prize is not technological uniformity but reciprocal trust at the interface: common evidence formats, mutual recognition of testing where appropriate, transparent supply-chain assurance, and enough architectural openness that a partner can integrate without surrendering control of its own system. States the author’s governing principle explicitly in the first person, that he treats authority not as a permanent attribute but as something granted, bounded, monitored, degraded and recovered according to evidence, and scales it: a trusted network should reduce the amount of trust that must be assumed rather than require blind trust, and a network able to grant bounded access, detect failure, isolate a compromised element, preserve unaffected functions and restore participation when evidence supports it is stronger than one that operates only when every participant is fully trusted.
Eurasia Review · August 2026 · Analysis
The Quantum Sensor Arms Race Has an Alliance Accounting Problem ↗
Argues the quantum sensor race is becoming an alliance acquisition problem before it becomes a battlefield one, because partners reporting laboratory sensitivity, navigation drift, modelled detection gain, or size, weight, power and cost can all be technically correct while describing very different levels of military usefulness. Holds that a component-level gain is not a deployable advantage, since a force fields not a sensitivity curve but a sensor package with calibration equipment, environmental control, processing, power, maintenance, trained operators, platform integration, and a fallback path, and that the classical alternative deserves a fair budget rather than comparison against whatever already sits on the procurement shelf. Proposes a shared readiness grammar: compare complete mission systems under matched resources, report advantage at the level the mission cares about, identify the failure boundary at which the advantage disappears, and ask whether the capability can be integrated and supported across national forces rather than only one.
Eurasia Review · August 2026 · Analysis
AI Can Find the Anomaly, It Cannot Tell You What Caused It ↗
Argues the most consequential failure of an automated system may begin not with a fabrication but with a correct result promoted into a stronger claim than the evidence supports, as a detection passes through retrieval, ranking and generation and each stage strengthens the wording slightly without any stage inventing a fact. Traces the ladder by which “unusual under this baseline” becomes “anomalous”, then “consistent with”, then “evidence for”, then “caused by”, while the baseline, threshold, data-quality warning, search scope and alternative explanations fall away. Shows the same structure across security, financial, intelligence and medical settings, and locates the institutional danger at the handoff where a score becomes a ticket, briefing or automated action. Proposes an evidence boundary rather than another confidence score: an evidence packet that travels with the alert, generated language bound to an explicit evidence state, and “unresolved” as a legitimate output naming what observation would discriminate among explanations and who owns that investigation.
Eurasia Review · August 2026 · Op-Ed
Nobody Audits the Clock ↗
Names timing as a dependency that sits beneath measurement and correlation while rarely being examined in its own right. Draws together two lines from the author’s published work: that channels sharing a timing source do not supply the independent evidence a naive count implies, since errors inherited from a common reference move together and agreement downstream cannot establish that the upstream reference was right; and that a navigation or timing solution carries an integrity state distinct from the authenticity of its source, so a system must know not only that a reference is genuine but whether what it has built on that reference still deserves trust.
Techstrong.ai · August 2026 · Op-Ed
Quantum Computers May Need AI Before AI Needs Quantum Computers ↗
Inverts the usual framing to argue that the clearer near-term evidence runs from machine learning into quantum operations rather than the reverse, since quantum hardware has an observability and operations problem before it has a superiority problem: devices must be characterised continuously, states reconstructed from partial measurement, drift identified, noise structure learned, and error syndromes decoded fast enough to keep a computation alive. Notes that each of those functions carries a measurable target and a serious baseline, including calibration time, reconstruction fidelity, logical error rate, decoder latency, and time to fault detection. Separates three investment cases that the single label conceals, and insists each project state which problem it solves, what baseline it must beat, and which bottleneck remains outside the demonstration, since evidence in one category is not evidence of maturity in another.
Eurasia Review · August 2026 · Analysis
NATO’s Next Supply Chain Vulnerability Has No Factory Floor ↗
Argues that the alliance exposure now forming is not a manufacturing one. Develops the ownership-architecture position the author has set out elsewhere, under which compute, data pipelines, model retraining, monitoring, proprietary toolchains, software updates, export restrictions and the cost of leaving a supplier determine whether a fielded capability remains usable, so that a force unable to retrain, patch, revalidate or migrate a system without external permission holds less sovereignty than a capability comparison suggests and vendor dependence becomes a form of strategic dependence. Extends his related requirements that material change trigger defined retesting and restoration of a previously approved version, and that continuity planning include pre-identified alternatives, degraded operating modes and data portability.
Eurasia Review · August 2026 · Op-Ed
Science Has Discovery Thresholds. It Also Needs Stop Rules. ↗
Seventh in the author’s sequence on machine-assisted scientific inference, holding that a standard for declaring a result is incomplete without a rule for when to stop looking. Complements the positions he has already set out in the series: that discovery is a status conferred by evidence meeting a stated standard rather than by conviction, that the extent of a search belongs in the claim it produces, and that a decision criterion must be fixed in advance and applied unchanged, since a rule tuned once the outcome is known converts a threshold into a formality reachable by persistence.
Eurasia Review · August 2026 · Op-Ed
AI Agents Are Getting Wallets: Security Needs to Follow the Money ↗
Addresses what changes when software agents are given the ability to move money. Applies the requirement the author set out for federal AI deployment, that authority boundaries be defined per action class rather than per model, since reading a public dataset, writing to a production database, and initiating an external transaction carry different consequences and need separately bounded permissions, together with session-level revocation that propagates to tokens, credentials, delegated jobs, and downstream automations.
RealClearDefense · August 2026 · Op-Ed
Trust the Signal, Doubt the Position ↗
Written against recent assured positioning, navigation, and timing awards and next-generation receiver-card agreements, and argues the next question belongs in the requirements documents: when the receiver is genuine and the signal source can be authenticated, what must the platform do once the navigation solution itself becomes doubtful. Holds that authentication establishes provenance while integrity governs whether the solution in use right now remains fit for action, and that a successful check cannot reach backward to undo a decision taken while the solution was already unreliable. Proposes three requirements: a continuous integrity state travelling with the navigation output, carrying the age and status of the last verification, the current assessment, an uncertainty estimate, and a downgrade reason code, propagated to whatever is deciding; specified behaviour when confidence runs out, including shifting source, entering a declared degraded mode, constraining autonomous action, requesting operator confirmation, or abstaining, with downstream software barred from quietly preserving the last good value or substituting a nominal default; and acceptance testing of the interval rather than the authentication event alone. Closes on end-to-end ownership, since a requirement belonging to everyone in general belongs to no one in practice.
Eurasia Review · August 2026 · Op-Ed
Discovery Is a Rank, Not a Feeling ↗
Holds that discovery is a status conferred by evidence meeting a stated standard rather than a conviction that something has been found. Develops the promotion boundary the author has set out across this sequence, under which a system may detect patterns, rank hypotheses, quantify uncertainty, and recommend follow-up, while moving from an unexplained signal to a claimed mechanism requires controlled measurement, discriminating tests, independent replication, and a theory that predicts something new.
Eurasia Review · August 2026 · Analysis
Open Societies Cannot Win an Information War by Becoming Closed Ones ↗
Argues that closing an open society in response to information competition sacrifices the property being defended. Applies the bounded-disclosure position the author has developed elsewhere, under which full transparency is rejected as a remedy while the objective becomes reducing the amount of trust a narrow claim requires rather than manufacturing trust wholesale, and under which the useful question is which limits a party will demonstrate, for what period, on what evidence, and under what challenge procedure.
Eurasia Review · August 2026 · Op-Ed
The Most Important Number in Corporate AI Is the One Companies Rarely Report ↗
Identifies a disclosure gap in corporate artificial-intelligence reporting, applying to company practice the author’s standing requirement that a reported figure carry the conditions under which it was obtained. Continues the argument he has developed elsewhere that accuracy alone is an incomplete disclosure, since a system reported only on the questions it answered says nothing about the questions it should have declined, and that the measure worth watching is the one that reveals where confidence exceeds evidence.
Geopolitical Monitor · August 2026 · Opinion
The Quantum Arms Race Has a Baseline Problem ↗
Argues that the familiar question of who leads in quantum technology is dangerously incomplete without asking ahead of what, since a claim of quantum advantage is meaningful only relative to the system it beats: measured against an outdated classical sensor, a poorly tuned classifier, or a weak receiver, an advantage can be scientifically real and strategically misleading. Traces the problem through quantum illumination, where laboratory detection gains under controlled low-brightness conditions are a different claim from a fielded long-range radar advantage once range, aperture, atmospheric loss, clutter, target cross section, receiver complexity, bandwidth, power, and mobility enter, and through quantum machine learning, where a large state space does not establish superiority once training difficulty, measurement cost, data loading, hardware noise, and the quality of the classical comparison are counted. Proposes that no capability be called superior unless the comparison is explicit, optimized, and resource-matched, and warns that incompatible baselines can drive an arms-race dynamic in which rivals respond to headline claims they cannot evaluate. Recommends that every major program declare the classical system it aims to beat, the resources held constant, the variables excluded, and the conditions under which the claimed advantage disappears, and that allies agree on what counts as a fair contest without sharing classified measurements.
Eurasia Review · August 2026 · Op-Ed
The Machine Can Be Tuned, the Nucleus Cannot Be Persuaded ↗
Distinguishes the parameters an optimiser can move from the constraints it cannot, continuing the author’s line that better mathematics can use available information more efficiently but cannot manufacture information an experiment never recorded, and that a physical ceiling is not an efficiency to be improved upon. Extends the accounting discipline he has applied elsewhere, under which an unmeasured term must remain visible as an unknown rather than inherit full performance by silence.
Eurasia Review · August 2026 · Op-Ed
The Next Flash Crash May Happen on a Battlefield ↗
Takes the automated-market analogy seriously as a warning about military systems interacting at machine speed. Develops the author’s standing argument that the realistic danger is quiet rather than dramatic, one automated function handing a recommendation to another as timelines compress until confidence scores become operational facts and a nominal human checkpoint arrives after the software has already shaped the available choices, and that a decision aid which compresses variables of different strategic meaning into a single figure can look precise while concealing the structure of the situation. Extends the line of his deposited research on decision compression and escalation risk in machine-assisted command.
Eurasia Review · August 2026 · Analysis
Ukraine’s Drone War Is Rewriting What ‘Tested’ Means ↗
Examines what certification can mean when a system is modified and refielded faster than a formal test cycle can complete. Develops the governed-change requirement the author has set out elsewhere, that models, safeguards, data sources, and interfaces continue to evolve after review, so an approval describes a configuration that may no longer exist unless material change triggers defined retesting, notification, and the ability to restore a previously approved version. Builds on his earlier verified analysis of the same conflict, which found that electronic interference rather than kinetic defence was the dominant cause of small uncrewed-system losses and that the successful adaptations reduced dependence on the vulnerable link and moved capability toward the edge.
Eurasia Review · August 2026 · Analysis
AUKUS Should Give Australia the Right to Test What It Is Asked to Trust ↗
Applies to a trilateral technology partnership the author’s standing argument that a partner asked to depend on allied systems should hold the right to verify them independently. Develops the line he has set out across his alliance writing, that a smaller partner unable to revalidate a system without external support holds less sovereignty than a capability comparison suggests, that vendor dependence becomes a form of strategic dependence, and that reciprocal recognition of governance evidence between allies requires a fielding standard each side can actually test rather than an assurance each side is asked to accept.
Eurasia Review · August 2026 · Op-Ed
AI Can Find the Weird, It Cannot Tell Us What It Is ↗
Fourth in the author’s sequence on machine-assisted scientific inference, drawing the boundary between detecting that something is anomalous and establishing what it is. Develops the promotion line he set out earlier in the series, under which a system may detect patterns, rank hypotheses, quantify uncertainty, and recommend follow-up observation, while moving from an unexplained signal to a specific physical mechanism requires controlled measurement, discriminating tests, independent replication, and a theory that predicts something new.
Eurasia Review · August 2026 · Op-Ed
When Machines Search for Discoveries, Science Has to Count the Search ↗
Third in the author’s sequence on machine-assisted scientific inference, holding that when an automated system searches a very large space of candidates, the extent of that search is part of the evidential claim and must be carried into how a finding is reported. Continues the line he has set out in the two preceding pieces, that a system should be able to report an unresolved state rather than force an observation into a known class, that measurement information can collapse faster than a model’s confidence score, and that agreement among related channels does not supply the independent evidence a naive count would imply.
GPS World · August 2026 · Opinion · New outlet
Signal Authentication Is Not Navigation Integrity ↗
Credits satellite-navigation message authentication as real progress and as honestly scoped by the agency operating it, then distinguishes what it delivers from what safety-critical consumers need: authentication answers where a signal came from, while integrity answers whether the navigation solution in use right now should still be trusted. Observes that verification happens at moments while navigation happens continuously, so a later successful check reaches nothing backward and says nothing about the interval that preceded it, which means a system must carry two distinct states rather than one. Argues that a procurement line requiring support for authentication specifies a capability rather than a behaviour, and proposes three requirements instead: a continuous integrity state carrying the age of the last successful authentication, source status, current assessment, uncertainty, and a downgrade reason code, propagated to whatever is making decisions rather than stopping at the receiver; defined behaviour when evidence runs out, with abstention specified as a legitimate output and downstream software prohibited from silently carrying forward the last valid value or substituting a nominal default; and certification that tests the interval rather than the check, alongside named end-to-end ownership, since a requirement belonging to everyone in general belongs to no one.
Modern War Institute at West Point · August 2026 · Commentary and Analysis
The First Clean Signal Is Not Permission to Fire: On Resilience and Governance of Autonomous Systems ↗
Distinguishes legal authority, which commanders and operators hold, from the engineering permission state, which is the set of actions a system’s software may execute without fresh human input, and argues that in a contested electromagnetic environment the permission state itself becomes a target. Identifies an unresolved question beneath existing work on degraded-mode autonomy: once a system has correctly lost a permission because the supporting evidence degraded, what evidence must it accumulate before that permission returns. Answers that recovery should be asymmetric, contracting immediately but re-expanding deliberately, since treating recovery as the mirror image of failure allows full permission to snap back on a single favourable sample and admits permission flapping around an unstable threshold. Proposes a four-part process: define the evidence envelope for every action class; distinguish contraction from recovery so that one clean frame does not erase a sustained period of corrupted evidence; bind a recovered permission to the evidence that earned it, so a prior authorization does not float forward when the sensor frame, model version, navigation solution, track, or policy state has changed; and make the recovery gate an explicit red-team target by plotting the permission envelope during attack. Answers the sanctuary objection directly, holding that full authority under degraded evidence does not defeat electronic attack but converts uncertainty into permission, and proposes a designed degraded-mode floor in which a system loses only the permissions whose evidentiary premises have failed.
Washington Examiner · August 2026 · Op-Ed
Trump Is Right to Send Allies the Bill. Cutting Our Own Drills Is the Wrong Currency ↗
Accepts the case for demanding more from allies and objects to the method of collection. Reads a multibillion-dollar munitions replenishment contract and a carrier relief after a deployment exceeding eight months and 208 continuous days at sea as evidence that the cost of sustained American power is paid in crew health, ship availability, munitions inventories, and industrial capacity. Argues that peninsular exercises are not a gratuity to the host, since they train American forces in combined command and control, all-domain operations, interoperability, rapid response, and wartime operational-control transition, so cutting them makes allied forces less practiced while charging a Middle Eastern bill to an Indo-Pacific deterrence account. Holds that an ally may decline a mission and still owe an answer on the burden it leaves, but that the answer should take a form with measurable military value. Proposes an allied contribution ledger offering a menu rather than a binary demand, with each contribution judged by whether it adds deployable capacity, shortens American recovery or replenishment time, and reduces the need to pull forces from another theater.
Eurasia Review · August 2026 · Op-Ed
Your Company Approved an AI System That No Longer Exists ↗
Addresses the gap between an artificial-intelligence system as approved and the system actually running, extending the governed-change requirement the author has set out elsewhere: because models, safeguards, data sources, and interfaces continue to evolve after review, an approval describes a configuration that may no longer exist unless material changes trigger defined retesting, notification, and the ability to restore a previously approved version.
Techstrong.ai · August 2026 · Feature · New outlet
The AI Kill Switch Act Needs a Containment Layer ↗
Treats proposed legislation requiring an off switch for artificial-intelligence systems in federal use as a serious response to a real problem, then argues that a control action only works if the surrounding system is built to make it effective. Identifies three gaps: an off switch presumes a clean shutdown point, while agentic systems distribute state across credentials, tokens, cached data, scheduled jobs, downstream automations, and external service calls, so stopping the model does not stop the loop; removal-based enforcement operates on human review cycles measured in days while an automated failure can unfold in seconds; and because such systems are being embedded in ordinary agency operations, an off switch as the primary safety mechanism forces a binary choice between mission continuity and safety. Proposes a containment layer instead, with authority boundaries defined per action class rather than per model, automatic scope reduction under uncertainty, session-level revocation propagating to tokens, credentials, delegated jobs, and downstream automations, and tamper-evident action logs held independently of the system being governed, leaving the off switch as final escalation rather than first line.
Eurasia Review · August 2026 · Op-Ed
Every Measurement Has a Physical Limit: Scientific AI Pretends Otherwise ↗
Grounds the argument in two established results, an optical resolution limit set by wavelength and aperture and a statistical bound in which Fisher information fixes a floor on attainable estimator variance, and draws the consequence that better mathematics can use available information more efficiently but cannot manufacture information the experiment never recorded. Identifies the category error as confusing confidence in an answer with evidence that the measurement could identify the answer at all, since priors, regularisation, and learned correlations can hold an output numerically stable while the measurement geometry becomes weak or nearly non-identifiable: confidence is evidence about the model, not automatically about the experiment. Proposes an architectural change rather than a new score, in which a model may produce a candidate estimate while release of a qualified scientific estimate depends on evidence that the measurement supports it, with fail-closed structured abstention recording the quantity requested, the information condition that failed, the threshold fixed in advance, the data and configuration used, and the new measurement that would make the question answerable. Insists the diagnostic and threshold be fixed on development data and applied unchanged, since a rule tuned after the embarrassing cases become known is post-selection rather than humility.
Eurasia Review · August 2026 · Analysis
Three Sensors, One Witness: The Corroboration Trap in Allied Intelligence ↗
Argues that alliance moves toward interoperable, data-rich intelligence fusion can make systems more connected without making their errors more independent. Three feeds agreeing on a contact may share a timing source, an upstream commercial image, a correction product, or a software family, so a confidence system that counts feeds without tracing shared ancestry prices an echo as evidence. Illustrates the statistical cost with an equal-correlation example in which twenty-four channels at a common correlation of one half carry only about 1.9 independent channels’ worth of information, noting that the hardware count is unchanged while the evidence count is not. Observes that the underlying mathematics of shared process noise has been understood for decades, so the missing discipline is not a theorem but carrying dependence information into the operational confidence score. Proposes mapping evidence pedigree using existing provenance vocabularies, discounting agreement between related feeds, red-teaming manufactured consensus by testing whether a disturbance at a shared layer makes many downstream systems agree on the same wrong answer, and reporting an effective independent evidence count beside the nominal feed count.
Washington Examiner · August 2026 · Op-Ed
Trump Handed Cops the Power to Jam Drones. Bad Software Could Ruin It ↗
Accepts the decentralisation of counter-drone authority to trained state and local officers as the right decision, then argues the software has to catch up. Distinguishes two questions that are usually collapsed: a valid detection answers what is in the sky, while authority answers who may do what about it, where, and for how long, and holds that the second set of facts should not live only in a training record, an operations plan, or an operator’s memory. Proposes a two-key condition on execution, in which the target track carries its identity, time, location, sensor support, and current confidence, while the command carries a verifiable credential proving that this operator or agency is authorised at this location and time for this specific category of mitigation, with the command executable only when both refer to the same event. Is explicit that this does not transfer legal judgment to an algorithm, since the rule rightly preserves the certified operator’s independent judgment, and defines the software’s narrower job as preventing an otherwise valid human decision from exceeding the authority that makes it lawful, refusing the command and stating why when the operation has expired, the target has left the approved area, the wrong method is selected, or the credential is stale.
Washington Examiner · August 2026 · Op-Ed
The Pentagon Is Cutting Red Tape and Setting a Legal Minefield for AI Contractors ↗
Written ahead of a statutory deadline for a departmental review of how artificial-intelligence systems are secured, and against a suspended certification programme and an executive order rejecting a licensing regime for AI development. Argues the review should identify which controls actually change operational risk, which can be measured continuously, and which should become enforceable contract terms, rather than translating a new technology into familiar compliance language and leaving program managers another checklist that says nothing about what happens when a model is manipulated at runtime. Holds that requirements should focus on evidence: which data and model artifacts are protected, who may change them, how anomalous access is detected, what happens on manipulated input, whether runtime controls can restrict an unsafe action, and which telemetry survives for investigation, with the standard distinguishing a security claim from proof that the control worked under test. Notes the liability consequence that follows, since once such duties become contractual, knowingly false representations about them can create exposure under existing false-claims law, while cautioning that this does not make every failure fraud given the knowledge-and-materiality structure of that statute.
RealClearScience · August 2026 · Op-Ed · New outlet
Antimatter Starships Are Farther Away Than You Think ↗
Argues that exotic-propulsion discussions typically begin one line too late, reporting the energy released after annihilation while omitting everything a vehicle must survive before and after that moment. Proposes an end-to-end energy ledger running from the electricity that creates the antiparticles to the fraction of energy that finally becomes directed momentum, with nine deductions after the headline figure covering production, capture, deceleration, cooling, storage, conversion, shielding, thermal rejection, and operations, each carrying an efficiency, an energy cost, a mass penalty, or all three. Identifies the underlying accounting error as treating specific energy as though it were propulsive efficiency when it is closer to a physical ceiling, and notes that leaving a line blank quietly assigns it perfect performance. Proposes a publication rule for future claims: state the ceiling, then publish every deduction with its assumed or measured efficiency, uncertainty range, and mass consequence, separate the acceleration case from the braking case, and mark which terms come from experiment, which from simulation, and which remain engineering assumptions, so that an unmeasured link stays visible as an unknown rather than inheriting full efficiency by silence.
Eurasia Review · August 2026 · Analysis
The Next Scientific Breakthrough May Depend on AI Saying ‘Unknown’ ↗
Argues that as machine learning becomes the gatekeeper deciding which signals reach a human scientist, the ability to abstain matters as much as the ability to classify, because a classifier trained on a closed set of categories operating on open-world data can turn a confident model into a filter against novelty. Sets three requirements: an explicit unknown state, so that unresolved is a legitimate output carrying positive probability that the current hypothesis set is incomplete; multimodal corroboration across measurements with different noise and systematic errors, with candidate status triggering follow-up rather than closing a question; and dependency awareness, since two sensors can appear to confirm each other while sharing a calibration error, processing pipeline, environmental disturbance, or training bias, so that multiplying their confidence scores manufactures certainty from duplicated evidence. Draws the governance line at promotion: a system may detect patterns, rank hypotheses, quantify uncertainty, and recommend follow-up, while moving from an unexplained signal to a claimed new mechanism requires controlled measurement, discriminating tests, independent replication, and a theory that predicts something new. Proposes that teams report abstention rates alongside accuracy, since a model that almost never says unknown may look decisive while quietly forcing unfamiliar observations into familiar categories.
Eurasia Review · August 2026 · Op-Ed
The Next Arms-Control Breakthrough May Be a Proof That Reveals Almost Nothing ↗
Argues that traditional transparency has a ceiling in military artificial intelligence, since no major power will disclose model weights, training data, intelligence feeds, command logic, or operational thresholds, but that verification does not always require seeing the thing verified. Proposes a staged alternative: register a cryptographic commitment to the declared policy and configuration in advance, bind each governed transition to time, authority, configuration, and the prior record in a tamper-evident chain, let an independent verifier test the agreed rule, disclose sensitive records selectively, and for narrow and stable claims eventually prove satisfaction without revealing the underlying data. States the limits of such a proof explicitly rather than hiding them, noting that it cannot establish that the underlying intelligence was correct, that human judgment was sound, that an action was lawful, that intent was benign, or that undeclared activity did not occur elsewhere, and that a perfect proof of a badly chosen rule remains proof of a badly chosen rule. Recommends beginning not with a treaty requiring source-code access but with a small catalog of testable properties, synthetic and non-operational trials, independent verifier teams compared against one another, indeterminate findings where evidence is missing, and a technical dispute process.
Washington Examiner · August 2026 · Op-Ed
Trump Says Humans Control the Bomb. The Code Doesn’t Know That Yet ↗
Argues that the policy question is settled and the mechanism is not: standing policy and statute already require human decision at the critical points, but human-in-the-loop describes who is supposed to decide while software architecture determines whether a high-consequence action can proceed without that decision. Identifies the realistic risk as quiet rather than dramatic, one automated function handing a recommendation to another until confidence scores become operational facts and a nominal checkpoint arrives after the system has already shaped the available choices. Proposes making human authority an enforceable technical condition: an external authorization layer the model cannot rewrite or persuade, a separate affirmative authorization token bound to a named authority, a defined action, and a short expiration window, with no valid authorization meaning no transition. Requires the layer to fail closed, so that expired authorization, ambiguous communications, or unverifiable authority halts the protected action rather than inheriting permission from an earlier state, and to emit a tamper-evident record of what was requested, which rule applied, who authorized it, and what the software did next. Frames the pending directive update as the opportunity to convert a policy principle into an acceptance test a program office can require a contractor to demonstrate under realistic failure conditions.
Geopolitical Monitor · August 2026 · Opinion
The AI Arms Race Will Be Won in Year Two ↗
Argues that artificial-intelligence capability is unusually easy to display and unusually difficult to price, so the first purchase reveals little about strategic advantage: compute, energy, data pipelines, integration, cyber assurance, retraining, model monitoring, operator support, export restrictions, and the cost of leaving a vendor all sit offstage during a demonstration and determine whether a capability becomes durable military power. Uses a documented aviation-security case in which a technically proven countermeasure failed to close a commercial business case in one country, on reliability and operating-cost grounds, and later became operational across another country’s carriers under a different threat environment, fleet structure, financing model, and certification path. Concludes that fieldability is contextual, that the same model can be a strategic asset in one state and an expensive dependency in another, and that vendor dependence becomes a form of strategic dependence when a force cannot retrain, patch, revalidate, or migrate a system without external permission. Proposes that procurement force the ownership architecture into the competition before a winner is chosen.
Eurasia Review · August 2026 · Analysis
The Red Sea Broke the Escalation Ladder ↗
Develops the author’s three-axis assessment model against a sequence in which major carriers widened their return to the Suez route and a lethal attack at the adjoining strait followed within a day. Argues that vertical escalation ladders cannot represent this, since attack counts can fall while insurance costs, rerouting, and transit times stay elevated: United Nations trade data recorded container tonnage through the canal down 82 percent by February 2024, and conflict-data researchers counted 150 attacks on commercial shipping in 2024 against seven in 2025 while transits through the strait remained 65 percent below their 2023 level. Warns that the danger is now computational, because command systems under pressure to compress data streams may average variables of different strategic meaning into one scalar, producing a number that looks precise while hiding the structure of the crisis. Proposes that decision aids preserve tactical threat, area denial, and economic imposition as separate channels showing which axis is moving, how fast, and with what uncertainty, and that they hold the policy boundary between measuring economic harm and recommending kinetic escalation.
Washington Examiner · August 2026 · Op-Ed
We’re Building Beijing’s Spy Network for Them, One Convenient Device at a Time ↗
Written against a July 2026 decision adding foreign-produced advanced robotic devices to a federal covered list, after security agencies warned that networked robots could support surveillance, foreign intelligence collection, or remote manipulation. Accepts the direction as sensible while arguing that regulators are using the wrong unit of analysis: policy has proceeded category by category, restricting connected vehicles, then drones, routers, robots, and power inverters, with each action addressing a real exposure, while intelligence collection crosses all of those product boundaries.
Eurasia Review · August 2026 · Op-Ed
Medical AI Can Pass the Test and Still Fail Patients ↗
Extends the author’s line of argument on assurance into clinical medicine, holding that a system can satisfy the evaluation it was measured against and still fail the people it is used on. Applies to healthcare the distinction he has developed across defence and technology policy, that performance on a benchmark is a claim about a test rather than about deployed practice, and that the conditions under which a safety claim was measured are part of the claim.
The Space Review · August 2026 · Op-Ed
Who Will Believe the Space Logs in 2040? Space Governance and the Quantum Audit Problem ↗
Identifies a variant of the harvest-now threat that applies to attribution rather than secrecy: an adversary collecting signed space records today could, once a cryptographically relevant quantum computer exists, break the signature scheme and retroactively forge historical telemetry, altering what a past orbital manoeuvre shows. Argues the space domain is uniquely exposed because records outlive their locks, because attribution is the cornerstone of space security and therefore the thing worth manipulating, and because an orbital event cannot be re-measured once its telemetry is compromised. Holds that migrating to new signature algorithms is structurally incomplete on its own, since a single new scheme is a new single point of failure and existing archives cannot be re-signed without breaking chain of custody. Proposes a three-layer architecture: dual classical and post-quantum signatures at record creation, a hash chain that explicitly tags the algorithm used at each step so old records remain verifiable under their original parameters, and periodic archival anchoring with a stateless hash-based signature, so that in the worst case where lattice cryptography fails, integrity assurance reduces to the security of a hash function. Ties the argument to treaty obligations that depend on reliable logs, and proposes four actions keyed to the 2030 and 2035 deprecation deadlines.
Eurasia Review · August 2026 · Analysis
America Is Exporting AI to Allies: It Needs Rules for Turning Access Off ↗
Argues that the United States exports frontier artificial-intelligence systems to partners without matching rules for what happens when Washington decides access must be restricted. Uses a documented June 2026 episode, in which a directive to suspend foreign-national access to two frontier models led the developer to disable them for all users because nationality could not be verified in real time, with controls lifted weeks later after a targeted classifier was trained and evaluated, to show how a domestic security judgment becomes a cross-border availability shock. Proposes an allied access compact with five elements: a shared risk vocabulary tied to evidence, graduated intervention with worldwide suspension at the far end carrying a defined review period and restoration conditions, notification channels that work at crisis speed, continuity requirements including pre-identified alternatives and degraded operating modes, and a connected network of national evaluation institutions. Its sharpest line is that a government should not discover a strategic dependency has disappeared through a vendor status page.
RealClearDefense · August 2026 · Op-Ed
Defense Networks Will Split. The Requirement Should Say Who Decides. ↗
Argues that programs specify whether software keeps running through a network partition but not what happens to delegated tasking authority while the network is divided, or how conflicting decisions are adjudicated when it reconnects. Observes that mission command gives a disconnected human subordinate intent, orders, defined relationships, and an obligation to account for decisions afterward, and that automated allocation systems do not inherit that framework merely because they can keep processing local data, so two partitions can each commit the same tanker, lift capacity, sensor window, or munition stock without either malfunctioning. Holds that the harder problem arrives at reconnection, because data consistency is not command validity: a generic synchronization rule can produce a clean database while concealing the operational disagreement that produced it. Proposes three requirements, a partition authority map preauthorizing which node may commit which resources under which conditions, bounded delegation in which authority operates as a lease that narrows or expires rather than persisting because communications remain unavailable, and reconvergence adjudication that preserves both decision histories, requires human review where consequences cannot be safely reversed, and records which decision prevailed and why.
Washington Examiner · August 2026 · Op-Ed
Trump’s AI Exemption Isn’t an Oversight Gap. It’s a National Security Masterstroke ↗
Argues that keeping open-weight models outside a voluntary federal safety-testing framework is a defensible assurance judgment rather than a hole in oversight, because closed frontier systems and open-weight releases have different lifecycles and different relationships with the government. A prerelease review can examine a defined artifact under controlled conditions, while a published open model is fine-tuned, quantized, and recombined into thousands of downstream variants, so a federal test of the original could be obsolete within days while still conferring a misleading government-approved glow. Accepts the seriousness of recent containment failures at frontier developers and argues they demand better evaluation design from those developers rather than a federal review queue for every downloadable model. Proposes clearer boundaries instead: publishing the capability categories that trigger federal interest without disclosing classified benchmarks, encouraging reproducible capability evaluations, model hashes, and disclosure of the conditions under which safety claims were measured, and concentrating testing on the deployed system that actually runs. Its governing distinction is that a model sitting in a repository has possibilities, while an agent connected to credentials, browsers, code execution, and live networks has authority.
Geopolitical Monitor · August 2026 · Opinion
Europe’s Military AI Gap Begins at Fielding ↗
Argues that the defence exclusion in European artificial-intelligence law is real but is not the whole problem, and that treating it as such points toward the wrong remedy. The sharper question is what must be proven before an AI-enabled military system moves from funded development into national service and then into a multinational operation. Identifies a lifecycle break: a human-control condition can govern eligibility for one funding instrument without becoming a common, testable requirement for the system later fielded, updated, connected to other national systems, or operated under multinational command. Holds that interoperability changes the unit of risk, since technical interoperability can advance faster than reciprocal confidence in the authority rules enforced by the software. Proposes a fielding assurance profile narrow enough to respect national sovereignty and concrete enough to test, requiring an authorization boundary, runtime governability, tamper-evident traceability, and a pre-agreed conflict rule so incompatible national caveats trigger renewed human authorization rather than being silently resolved by whichever system acts first.
Eurasia Review · August 2026 · Analysis
America’s Drone Standards Will Travel Far Beyond America ↗
Argues that the drone standards the United States sets domestically will govern well beyond its own jurisdiction. Extends the propagation mechanism the author set out a day earlier in his analysis of allied military AI governance, that manufacturers design to the requirements of their largest customers and forces buy what has already passed recognizable tests, so a domestic rule becomes an international norm without being negotiated as one.
Washington Examiner · August 2026 · Op-Ed
Trump Isn’t John Lennon. That’s Why His Iran Strategy Might Actually Work ↗
A direct reply to another contributor’s argument in the same publication, holding that distrust of an adversary does not by itself justify regime change. Argues that military power has its greatest value when an adversary knows it can be used and the commander knows when to wait, and that the case for testing an off-ramp rests on prudence rather than optimism. Concedes the strongest objection, that repeated threat-and-pause cycles can burn presidential credibility, and answers it with structure: every pause should carry a fixed deadline, written objectives, independent verification, and consequences announced in advance, so that a bounded test forces a measurable choice while open-ended negotiation invites delay. Notes what force cannot guarantee after a government falls, including control of nuclear material and the behaviour of fragmented security units. Continues the author’s line on verification limits and on the design of decisions under uncertainty.
Eurasia Review · August 2026 · Op-Ed
The Race to Write NATO’s Military AI Rulebook Has Begun ↗
Argues that because the European Union deliberately placed exclusively military and national-security systems outside its artificial-intelligence law, the practical rulebook is being written elsewhere, through American procurement, alliance testing and interoperability mechanisms, European experimentation, and national certification. Observes that military standards spread through markets before diplomacy, so a procurement rule can become an alliance norm without ever being negotiated as a treaty. Proposes four minimum requirements clear enough to be compared, tested, and recognized across the alliance: explicit authorization boundaries including how authority changes as data quality, communications, or confidence deteriorate; governed software change with defined retesting and the ability to restore a previously approved version; reconstructable records establishing what a system recommended or did and which human or machine held authority; and interoperability treated as a governance requirement, since allied systems must exchange operational caveats, authorization limits, and stop conditions rather than data formats alone. Calls for an unclassified minimum baseline alongside any classified annex, on the reasoning that a standard allies and suppliers cannot examine cannot be compared, contracted for, or recognized.
Washington Examiner · August 2026 · Op-Ed
Silicon Valley Can’t Own the Pentagon’s Kill Switch ↗
Argues that the live question is no longer whether the Pentagon will use commercial artificial intelligence but who controls the software once it becomes part of a mission, and that the answer belongs in the contract rather than in the crisis. Holds that for mission-critical AI the government must retain both the contractual and the technical authority to stop the system, freeze an approved version, roll back to a previous one, and continue essential operations if the vendor relationship fails. Written against the Department’s 2025 awards to four frontier AI developers, each carrying a ceiling of 200 million dollars, and its subsequent expansion of commercial AI into classified environments: private firms supplying talent and technology is a strength, provided dependence does not become delegated command authority.
Eurasia Review · August 2026 · Analysis
Chokepoint Coercion in the Next Phase of the Iran Conflict ↗
Argues that chokepoint coercion works by altering commercial behaviour through uncertainty rather than by defeating navies, and that military assessments still compress three unlike effects into one number. Uses the Red Sea as the completed experiment: allied forces won intercepts while carriers rerouted anyway, canal transits halved, and the coercion succeeded through the accumulated judgement of owners, crews, and insurers. Proposes assessing tactical threat to platforms, operational denial of access, and strategic economic imposition as separate, interacting axes, with the commander’s update displaying them in separate panels and decision-critical indicators keyed to commercial behaviour rather than attack counts alone. Notes that automated decision aids optimised for imminent physical danger cannot infer commercial confidence unless those variables are deliberately represented and kept distinct, and applies the framework to the Strait of Hormuz, where a passage open on Tuesday and shut on Thursday imposes much of the cost of closure without ever requiring one.
RealClearDefense · August 2026 · Op-Ed
The Vulnerability of Autonomous Warfare Systems ↗
Argues that the joint force is buying autonomy faster than it can measure whether it can fight without it. Reads Ukraine as a dependency story: front-line reporting consistently identifies jamming rather than kinetic defense as the dominant killer of small uncrewed systems, and the winning adaptations reduced dependence on the vulnerable link and pushed judgment to the edge. Government Accountability Office findings on alternative navigation and on the joint command-and-control effort show the measurement gap running from the rifle squad to the enterprise. Prescribes three commitments requiring no new program of record: build denial into ordinary training by exercise design, make degraded-mode competence a measured and reported readiness standard alongside gunnery and fitness, and resource the manual layer as a capability, rehearsing the handoff from automated to manual under stress. A force is defined by what its people can still do when the machines go dark, and by whether the institution knew in advance which of its units could do it.
Eurasia Review · August 2026 · Op-Ed
Europe Delayed Its AI Rules Because the Institutions Were Not Ready ↗
Argues that governments are writing artificial-intelligence law faster than they are building the bodies that can investigate failures, hear appeals, and order corrections. Notes which duties survived the European deferral and which slipped: the transparency obligations took effect on schedule, while every obligation requiring someone to inspect, evaluate, and judge a system moved to a later date. Contends that accountability is a relationship rather than a property added through documentation, so a decision can be transparent, tested, and formally compliant and still be practically unaccountable when no competent body can question it. Proposes naming an institutional forum before deployment, empowered to compel evidence, evaluate against an articulated standard, and impose a consequence, and argues that building the interface between an AI system and the institutions meant to govern it is an engineering task that is currently nobody’s job.
Security Boulevard · July 2026 · Analysis
Zero Trust Stops at the AI ↗
Introduces a concept the author calls the confidence half-life: a detection model ships with a certified confidence value that erodes under sustained adversarial pressure, and the half-life is the time it takes to fall by half. Argues that recalibration cadences were tuned to a human attacker clock that no longer exists, so a model can spend much of its operational life below its certified threshold while dashboards still show confident answers, since calibration drift fails silently. The deeper argument is that organizations which dismantled perimeter trust for people and devices have quietly re-embedded it at the AI layer, granting a model that performed well in evaluation standing authority that persists until something breaks. Maps Zero Trust principles onto machine authority almost one to one: verified current confidence for the specific task rather than a procurement-time trust score, minimum authority rather than maximum supportable, assume drift in place of assume breach, tiered authority with hard boundaries so a model on a correct streak cannot accumulate unauthorized latitude, and logged reversible deliberation on every escalation.
Washington Examiner · July 2026 · Op-Ed
What Trump’s Record Border Numbers Are Hiding ↗
A measurement argument about what enforcement statistics can and cannot establish. Observes that apprehension and encounter figures are enforcement outputs rather than complete measures of security or of harms prevented, since they count the people officers encountered but do not count successful entries, explain why fewer people attempted the journey, or establish what followed from a decline. Argues the change cannot be attributed to any single policy, because enforcement by a neighboring state, asylum restrictions predating the current administration, regional migration patterns, and deterrence signaling all bear on the result, and separating those contributions is analytic work an announcement cannot perform. Separates three questions routinely collapsed into one: whether the numbers are real, what produced them, and what they imply.
Military AI · July 2026 · Commentary
The Human-in-the-Loop Is Becoming a Rubber Stamp. Acquisition Can Fix It. ↗
Argues the human-in-the-loop safeguard is thinning into a formality not because operators fail but because acquisition contracts never required systems to explain themselves. Notes that when automated tools surface thousands of candidate items a day and each must be cleared by a human, an alert carrying no rationale, no supporting evidence, and no stated confidence is difficult to act on and easy to accept unquestioned, producing either disuse or automation-bias misuse. Frames this as a specification defect rather than a training one, since no operator discipline can recover a rationale the system was never required to produce. Prescribes buying understanding rather than detection, and names three acquisition controls: a standardized explainable alert format as a condition of the test-to-production gate, operational testing of the human-machine interface with the same rigor applied to the algorithm, and continuous monitoring written into the lifecycle so a fielded system signals its own reduced reliability as inputs drift.
Geopolitical Monitor · July 2026 · Op-Ed
Six Governments Wrote One Driverless Rule, But They Kept Four Regulators ↗
Examines the first global regulatory framework for fully driverless automated driving systems, adopted in June by the United Nations vehicle-regulation forum and backed by six markets accounting for most of the world’s vehicle production. Notes that because statistical proof by mileage is unattainable, as RAND analysts established in 2016, the framework validates through a lifecycle safety case, simulation, track and road testing, independent audits, and in-service monitoring. Argues that once proof moves from miles to documents the document becomes the regulation, while what an operational design domain description must specify and how a regulator judges an argument complete rather than merely plausible is left to guidance still being finalized. Observes that the six governments harmonized the standard but not the machinery that applies it, since type-approval, self-certification, and centrally administered pilot systems read the same text differently, producing convergence on paper and divergence in practice.
Eurasia Review · July 2026 · Analysis
From Fordow to New York: What Force Cannot Verify in Iran’s Nuclear Program ↗
Argues that three rounds of strikes across thirteen months have produced three damage assessments and no verified baseline, because force can destroy facilities and lengthen a timeline but cannot by itself establish what material survived, what expertise remains, or what undeclared infrastructure exists. Those are safeguards questions that battle-damage assessment cannot answer. Notes that AI-enabled tools compressed targeting processes once measured in hours or days into seconds, which the piece treats as the clearest publicly acknowledged demonstration of machine-assisted targeting at the scale of a major interstate campaign, while insisting that officials chose the objectives and authorized the strikes. Contrasts a scripted earlier operation, whose weapon-to-target pairings and intelligence validation were settled in advance by planners with time to weigh them, against the compressed tempo of the later campaign, and asks how equivalent validation quality was preserved. Closes with three recommendations, including unclassified publication of the governance lessons of machine-assisted targeting, on the principle that speed which cannot be examined is not a capability anyone can govern.
RealClearDefense · July 2026 · Op-Ed
Arming Local Police With Drones. Who Pulls the Trigger? ↗
Argues that recent counter-drone law has settled who may act and funded the tools to act with, while leaving unresolved how the decision itself gets made. Identifies three gaps: a declaration problem, since a statutory credible-threat standard becomes a judgment call made in under a minute by whoever holds the certification; a handoff problem, since a drone can cross private, municipal, county, and federal boundaries in about ninety seconds through layers of permission that specify no moment or mechanism of transfer; and an evidence problem, since engagement decisions will be litigated from both directions and unrecorded sensor and decision data forfeits in court what was won in statute. Prescribes an authority architecture set before an event: a named decision authority with pre-planned succession, risk-based engagement windows fixed in advance, and an evidence chain built in from first sensor contact.
Eurasia Review · July 2026 · Op-Ed
Today’s Hydra Problem: Decapitation Without Degradation ↗
Argues the recurring debate over whether leadership decapitation works is mis-specified, because its effect depends on a structural property of the target rarely assessed before a strike: the number of independent pathways an organization has to reach a strategic decision. Reads three well-documented cases as a single pattern (a centralized node that never rebuilt, a distributed framework that absorbed removal as routine succession, and an intermediate case), distinguishes bureaucratized succession from functional redundancy, and observes that two decades of sustained pressure selected for adversaries against which the instrument accomplishes less. Concludes that pressure belongs on the substrate (financing, recruitment, doctrine, logistics) and that planning horizons must match the years-long timescale of what is being degraded rather than the days-long clock of removing an individual.
Dark Reading · July 2026 · Opinion
Adversaries Don’t Need a Zero-Day — They Read Your Rulebook ↗
Published in the leading cybersecurity trade press, responding to a reported fall in confidence in autonomous penetration testing (willingness to rely on it dropping to nine percent in 2026 from twenty-nine a year earlier). Names a failure mode the author calls cap weaponization: once an autonomous system’s governance rules are written down and certified, they become public information an adversary can read and exploit, engineering a rhythm of cheap probing and free recovery that talks a defensive system out of its own authority without firing a single exploit. Prescribes the author’s core engineering principle: the authority a system acts on must always equal the authority its audit records, computed in one place, enforced in another, and cross-checked, so any single-layer manipulation produces a catchable mismatch.
Lieber Institute, West Point · Articles of War · July 2026
Whose Decision Was It? Drone Swarms and the Accountability Gap in Ukraine ↗
Published by the Lieber Institute’s Articles of War, the legal-scholarship forum at the United States Military Academy. Argues that the accountability gap for autonomous swarms is opening not because the law of armed conflict is silent, but because the human decision the law depends on is being designed out at the point where a swarm’s composition rule is chosen. Distinguishes three ways a swarm composes a decision, each locating human responsibility differently, and argues the composition rule is a legal decision as much as an engineering one, reviewable under Article 36 weapons review before a system flies. Adds that a tamper-evident record is necessary but not sufficient, because it cannot show whether what the system observed was true, making input integrity a separate obligation.
Washington Examiner · July 2026 · Op-Ed
America Just Did the World’s Dirty Work ↗
A burden-sharing argument about how a distributed threat came to be described as one government’s private undertaking, and what that description does to the accounting. Sets the concentration of exposure in Europe, the Gulf, and East Asia against the pattern of participation, gives the contrary evidence a fair hearing, including thousands of American flights launched from allied territory and logistical support from several capitals, and argues that sovereign states may decline a war but cannot decline it and still send the invoice elsewhere. Extends the author’s preparedness-paradox analysis: countable costs sit on one side of the ledger while the benefit is a weapon not finished and an attack not launched, which leaves no wreckage to photograph.
Geopolitical Monitor · July 2026 · Op-Ed
The Wax Was Melting: AI Speed and the Nuclear Decision ↗
Uses the Icarus myth, in which a boundary announces itself only after it has been crossed, to argue that military AI is compressing the one resource careful decision-making depends on, which is time. Notes that AI-enabled targeting has, by the military’s own account, reduced processes once measured in hours or days to seconds, and argues structurally that when a pipeline runs faster than a human can verify its inputs, verification is not merely harder but compressed out of existence. Carries the argument to nuclear command and control, where no later correction exists: the risk is not that an AI decides to launch, but that the cycle compresses until the human holding launch authority has no genuine opportunity to exercise it, leaving the appearance of control rather than control. Prescribes building verification back in and treating human deliberation time as a condition of survival.
Washington Examiner · July 2026 · Op-Ed
Binders Won’t Stop Bullets: When Military AI Can’t Say ‘No’ ↗
Examines Section 1513 of the Fiscal Year 2026 National Defense Authorization Act, which directs a framework for the cybersecurity of acquired artificial intelligence systems folded into existing acquisition rules and the Cybersecurity Maturity Model Certification program, and notes that the first status report to Congress was due in mid-June and the deadline has passed. Argues the statute names the right risks (adversarial tampering, supply chain compromise, data theft, and AI-specific vulnerabilities) because an adversary can corrupt a system without breaching a firewall, by poisoning a sensor feed, spoofing an identification signal, or nudging a model toward a decision its operators never intended, and that the difficulty is that the compliance tools the law points to were built for a different kind of technology.
Global Security Review · July 2026 · Op-Ed
Allied Autonomy Is Creating a New Seam in Extended Deterrence ↗
Argues that allied autonomy has outpaced the alliance frameworks governing who may authorize a machine to act. Because each ally encodes its own national rules for engagement, human review, and halting, a combined formation can contain systems that would act under one national authority profile and hold under another, and adversaries study seams. Prescribes authority interoperability built as deliberately as data interoperability was: published national authority profiles, shared reversion standards so any coalition system can be halted by a common tested procedure, and an autonomy annex to extended-deterrence consultations. Adds legibility as a third term alongside capability and will.
Washington Examiner · July 2026 · Op-Ed
The Iran War Began With Biden, Not Trump ↗
A deterrence-credibility analysis arguing the honest ledger on the Iran campaign opens on April 13, 2024, when a barrage of more than 300 drones and missiles followed a one-word American warning and carried no cost. Traces Schelling’s credibility requirement through the IAEA stockpile record (274.8 kilograms of 60 percent enriched uranium in February 2025 rising to 440.9 by June, roughly nine weapons’ worth, before an inspection blackout), argues the February 2026 campaign was arithmetic rather than choice, and frames the lesson as bipartisan: wars of this kind are compound interest on deterrence lapses, and resolve becomes legible only when holding it costs something.
Eurasia Review · July 2026 · Op-Ed
Who Yields in Orbit? Autonomous Satellites Need a Right-of-Way Rule ↗
Opens with the European Space Agency’s September 2019 collision-avoidance decision, made with almost no framework, and argues that low Earth orbit is approaching a regime of continuous conjunctions, with the largest constellation seeking to grow from twelve thousand satellites toward forty-two thousand. If the first collision between two autonomous, maneuver-capable satellites happens under the present non-system, both operators will honestly insist they had priority, and neither will be wrong, because no rule ever established who did. The sea drew its rules of the road before its traffic became unmanageable; orbit still has that chance, and the window is closing at eight kilometers a second.
Eurasia Review · July 2026 · Op-Ed
Why We Punish the Protection That Works ↗
Names the preparedness paradox: successful prevention erases the evidence of its own necessity, so publics weigh visible costs against invisible benefits and judge protection an overreaction. Traces the pattern from the Y2K remediation effort through ozone recovery and epidemic prevention, applies it to the debate over the US strike on Iran’s nuclear program, and prescribes an evidentiary remedy: preserve contemporaneous records of the perceived threat, the alternatives considered, and the basis for acting, so later verdicts weigh the decision actually made under the uncertainty that existed.
Geopolitical Monitor · July 2026 · Op-Ed
America’s Allies Should Test the AI They Plan to Depend On ↗
Uses the June 2026 export-control suspension of the most capable publicly available AI model (nineteen days, restored only after a US government review no ally performed or observed) to argue that allied access to frontier AI is conditional and revocable, and that readmission runs on someone else’s evidence. Prescribes a standing national test-and-evaluation capability (a funded bench of people, test protocols, and red teams) rather than sovereign frontier models, with allied pooling: shared test benches, common red-team protocols, and reciprocal recognition of evaluations modeled on shared airworthiness findings.
Eurasia Review · July 2026 · Op-Ed
The Next Offset Won’t Be a Smarter AI, It Will Be a Governable One ↗
Argues US military-AI strategy is organized around the wrong question, chasing model capability when the binding constraint is governable authority: who or what is permitted to act, through which interface, with what oversight. Contends capability that cannot be governed is exposure, not advantage, and calls for an authority offset (permission control, verification, segmentation, exercised human fallback) rather than a fourth capability offset, since capable models proliferate fastest while governed deployment does not. Draws on CrowdStrike, the 2015 Ukraine grid recovery, and nuclear command-and-control (Sandia’s always/never principle) to locate the real risk in integration and validation, not model intelligence. This is the clearest public statement of the thesis underlying the author’s AUTHREX research program.
Washington Examiner · July 2026 · Op-Ed
We Guarded China’s Oil for Free. Trump Sent Them the Bill ↗
Reads President Trump’s July 2026 demand that the United States be reimbursed for guarding the Strait of Hormuz as an overdue burden-sharing doctrine rather than a transit-fee gimmick. Notes that Asia takes nearly 90 percent of the strait’s crude and China is the largest customer, while U.S. energy independence makes the demand credible, and argues Congress should pair the war supplemental with allied and consumer pledges, citing the 1991 Gulf War precedent and the Defense Cooperation Account (10 U.S.C. 2608).
Eurasia Review · July 2026 · Op-Ed
Two Years After CrowdStrike, We Are Still Afraid of the Wrong AI Apocalypse ↗
Marking the second anniversary of the 2024 CrowdStrike outage, argues that the popular AI-doom scenarios (a universal off-switch, a grid takeover, a rogue nuclear launch) confuse what a system can compute with what it is permitted to touch. Contends the scarce resource that converts capability into consequence is authority, not intelligence, and that the real danger is the erosion of manual fallback competence. Prescribes human-approval gates on consequential automation, an inventory of what automation is permitted to touch, and maintained manual procedures treated as critical infrastructure.
Geopolitical Monitor · July 2026 · Situation Report
The Reciprocity Inversion: How Ukraine Became the Gulf’s Counter-Drone Lifeline ↗
Traces Ukraine’s 2026 deployment of 228 counter-drone specialists across five Gulf partners into ten-year military-technical agreements with the UAE, Qatar, and Saudi Arabia, and argues the episode inverts eight decades of alliance logic: capability flowing from the assisted state to the guarantors, including Pentagon talks to buy Ukrainian interceptors. Grounds the shift in cost-exchange arithmetic ($35,000 attack drones against $4 million Patriots, versus $800 to $3,000 interceptors producible at 2,000 a day) and in combat-derived tuning against a threat that iterates every six weeks, a form of capital that cannot be bought.
Also at: Eurasia Review (syndicated)
Eurasia Review · July 2026 · Op-Ed
What Six Years of Drone Proliferation Means for the Next Fight ↗
Traces six years of armed-drone diffusion from the 2020 Nagorno-Karabakh war through Ethiopia, Sudan, the Sahel, and Myanmar, where attritable systems costing a fraction of the platforms they destroy have repeatedly turned conflicts. Argues that attritability economics and fast mutation (fiber-optic links defeating jamming, copied anti-jamming modules) make the primary threat to a deploying force a cheap, copied system, and that low-cost adversary air should be treated as a baseline condition of every deployment, trained through standing small-unit battle drills rather than awaited as a novel contingency.
RealClearDefense · July 2026 · Op-Ed
Military AI - The Confidence You Cannot See ↗
Argues that operator deference to machine confidence scores is a silent transfer of decision authority, not a psychology problem: the human signs, but a number the person cannot interpret has already decided. Proposes that confidence never arrive as a naked percentage but bound to the system’s validated context, with autonomous authority contracting toward the human when the situation drifts outside validation, a requirement that can be written into procurement standards and audited.
Also at: The Ohio Press Network and KHQ (NonStop Local) (via RealClearWire)
Eurasia Review · July 2026 · Op-Ed
The Governance Gap Hiding in Plain Sight Across Eight Industries ↗
Argues that eight sectors, from water utilities and aviation to road transport, maritime, and defense, share one governance gap: autonomous systems now act faster than any human can review or reverse. Proposes a common point-of-action governance layer outside the model, with non-overrulable permission checks, stakes-tiered human confirmation, and tamper-evident audit.
IT Ops Times · July 2026 · Op-Ed
Your AI Agent’s Permission Model Is Built on a Boolean. Irreversible Actions Need More Than That. ↗
Argues that production AI agents inherit a firewall-style allow/deny permission model that assumed mistakes were reversible, and that it breaks when agents take irreversible actions faster than humans can review. Grounding the case in runtime-enforcement theory (Schneider’s safety properties, Ligatti’s edit automata), it proposes graded authority measured at runtime, conservative failure under uncertainty, and an external interlock outside the agent’s own compute path.
RealClearMarkets · July 13, 2026 · Op-Ed
The Cruel Economics of the 19-Day Anthropic Ban ↗
Reads the June 2026 order restricting Anthropic's two most capable AI models as an unintended experiment in the economics of technology restriction: the denial was brief because near-substitute models exist, the costs fell on compliant banks, universities, and cyber-defenders rather than the intended target, and unpredictable access gives every enterprise a reason to diversify away from American AI. Recommends controls designed at the level of specific actions against specific targets rather than an entire model's availability.
Geopolitical Monitor · July 2026 · Op-Ed · syndicated by Eurasia Review
Who Fires the Shot? Closing the Authority Gap in Indo-Pacific Autonomous Warfare ↗
Argues that Indo-Pacific coalitions (AUKUS Pillar 2, Quad-composition operations) are fielding autonomous systems faster than members can agree on who may authorize them to act, and proposes a Coalition Authority Interoperability Protocol: computable national authority profiles, dependency caps, cryptographic multi-signature rules, and an auditable accountability layer, with aggregate coalition authority never exceeding what its most conservative participating member permits.
Also at: Indian Strategic Studies (curated feature with editorial comment)
RealClearDefense · July 2, 2026 · Op-Ed
The One Clause in Trump's AI Memo That Could Encumber the Off-Switch ↗
Warns that the "Reliability and Sovereign Control" mandate in National Security Presidential Memorandum 11, meant to stop commercial vendors from disabling fielded military AI, could also lock out the human operator's ability to terminate a malfunctioning autonomous system under Directive 3000.09, and proposes an explicit operator-override exemption in the mandated 90-day revision plus congressional oversight through the FY27 NDAA.
The Defense Post · June 30, 2026 · Op-Ed
When the Machine Decides and the Human Signs ↗
Argues that human-on-the-loop oversight of AI-enabled targeting does not hold at high operational tempo, because once a targeting pipeline outruns a commander's ability to verify its output the effective decision moves into the software, and proposes engineering the safeguards in: automated currency checks on targeting intelligence, circuit breakers inside the software, tempo tied to verification capacity, an updated DoD Directive 3000.09, and congressional reporting on review time.
Modern War Institute at West Point · June 26, 2026 · Op-Ed
When the Machine Acts First: Closing the Authority Gap on the Autonomous Battlefield ↗
Argues that the collapsing distance between a machine's reasoning and its action opens an authority gap between what a commander authorizes and what a fielded autonomous system does before anyone can intervene, and proposes runtime authority governance: enforcing permission outside the model, pausing before consequence and failing toward inaction, and tying autonomy to the criticality of the target.
The Space Review (in association with SpaceNews) · June 22, 2026 · Op-Ed
Space Autonomy Needs an Authority Architecture Before 2027 ↗
Argues that light-time delay and a contested orbital domain make autonomy a physical necessity for space systems, and that the Space Force must embed an authority architecture into doctrine and hardware before 2027, defining what a machine may decide, the legal basis, and a cryptographically secured deferred-accountability record the chain of command can audit.
Royal United Services Institute (RUSI) · June 16, 2026 · Guest Commentary
The Hour That Worked: What Midnight Hammer Teaches About AI-Era Command ↗
Guest commentary at one of the world's oldest defense and security institutes, arguing that command authority and data validation for AI-enabled force should be fixed at an inspectable point before deployment rather than compressed to machine speed. Contrasts Operation Midnight Hammer with the AI-accelerated Operation Epic Fury and draws implications for NATO interoperability and national red-card authority.
Also republished at: MERO
RealClearDefense · June 4, 2026 · Op-Ed
The Quantum Clock Is Already Ticking on America's Autonomous Arsenal ↗
Argues that post-quantum cryptography is not only a secrecy problem but a command-authority problem for autonomous weapons. Because a forged cryptographic signature can dissolve the chain of authority, and because a system's cryptographic trust relationships persist across its full service life, the 2035 CNSA 2.0 migration horizon is dangerously late for autonomous platforms fielded today. Recommends DoD treat PQC as a mandatory design requirement now.
Military AI (militaryai.ai) · June 12, 2026 · Commentary
When an AI Agent Fires First, Who Answers for It? ↗
Argues that accountability must be a design requirement for agentic military AI: every consequential action should be bound, before deployment, to an identifiable chain of human authority, with cryptographic identity required for any defense agent. Engages the Five Eyes "Careful Adoption of Agentic AI Services" guidance (CISA, NSA, and partners, 2026).

Authority & Architecture Imprint

Three-trilogy / 10-volume technical reference series on autonomous-systems authority architecture: The Authority Equation (3 volumes), The Authority Discipline (4 volumes), and Autonomous Authority (3 volumes). Distributed via Amazon and IngramSpark in print and ebook formats. ISBNs registered through Bowker; Library of Congress Control Numbers assigned to each series: The Authority Equation 2026912260, Autonomous Authority 2026922204, and The Authority Discipline 2026922201.

View Full Catalog at Authority & Architecture
The three Authority & Architecture trilogies in hardcover: The Authority Equation, Autonomous Authority, and The Authority Discipline

Credentials & Background

Independently verifiable evidence of patents, publications, institutional affiliation, and professional experience. Every claim can be cross-checked through external systems: USPTO Patent Center, Zenodo, ORCID, Google Scholar, SSRN, ResearchGate, and employment records.

7
U.S. Provisional Patents
48
Published Works
10+
Years Professional Experience
13
External Citations across nine countries

Verification Sources: Georgetown University M.P.S. Applied Intelligence (STEM, in progress) · Lynn University MBA (GPA 4.0) · USF B.Sc. Computer Science Engineering (STEM) · USPTO Patent Center · Zenodo · ORCID #0009-0001-8573-1667 · Google Scholar · SSRN · ResearchGate · Blue.Cloud · 7 professional roles 2017-Present.

View Credentials & Background Certifications & Specialized Training →

Get In Touch

Available for research collaborations, expert advisory engagements, and discussions on AI governance, autonomous systems safety, and national security technology policy.

Location

Washington, DC

Languages

English (Professional) · Turkish (Native) · Russian (Reading Proficiency)

Research Focus

AI Governance · Autonomous Systems Safety · National Security Technology · Escalation Risk Modeling · Human-Machine Teaming

Patent Status

HMAA: U.S. Provisional 63/999,105 (March 7, 2026) · CARA: U.S. Provisional 64/000,170 (March 9, 2026) · SATA: U.S. Provisional 64/002,453 (March 11, 2026) · FLAME: U.S. Provisional 64/005,607 (March 14, 2026) · ADARA: U.S. Provisional 64/110,218 (July 13, 2026) · MAIVA: U.S. Provisional 64/110,221 (July 13, 2026) · ERAM: U.S. Provisional 64/110,225 (July 13, 2026) · All seven filed via USPTO Patent Center