A research program toward a general theory of relational trust.
The Study of Resilient Systems is a research program on trust, cooperation, and the conditions that sustain them. It asks how environmental capacity, information, and trust contribute to resilience or failure.
The public record includes hypotheses, simulation results, interpretations of external studies, and proposed tests. Use the claims register to distinguish their evidence levels, or choose a research task below.
The 2008 white paper is a 17-year-old, bossless proof of the CAN gate — and a precise map of the SHOULD gate the agent economy still owes. A scroll-narrative read of the BTC ↔ KTP convergence.
The knowledge graph read as territory — ridges where the framework is dense, valleys honestly named, watersheds along which arguments flow, fault lines held open on purpose.
Computational irreducibility as the physics-of-computation floor under authorization-over-alignment — a salute, three cartography maps, and the honest tension held open. Wolfram states the problem; A ≤ E is the answer.
DCTI (the defensive method), ACPP summary (the seven threats), and the Installed Watcher synthesis. The framework's worked example of the dual-use cut: what's published, what's held internal, and the reasons for each.
Proposed empirical tests whose failure would force revision or abandonment of a specific layer — plus the failure lattice: a completeness claim that every failure of a trust system is one force starving or one force running open-loop, six modes offered for refutation. The page that earns the right to publish the others.
Five rounds of adversarial analysis on whether the trust the framework describes can be measured at all. Reputation is a second, autonomous state; substance-vs-story is non-identifiable from passive behavior; the intervention escape got refuted; the surviving claim is narrowly inhabitable — precisely in KTP's machine-agent domain — and every layer needs an anchor outside the loop. Trust cannot be measured by a system that grades its own homework.
The 2026 Bau Lab red-team study read through the framework. Five-case retrospective interpretation using the public trust model, including the Doug & Mira collaboration. The study did not test or endorse KTP; the page distinguishes the study from the framework interpretation.
Factory farming read as the cleanest civilian case of violence made governable by removing the witness. Eight architectural defenses; a 115-year evidence timeline (Sinclair 1906 → COVID 2020); the public trust-model reading and the protocol-side reading (KTP mechanism mapping); four falsifiers; a named intellectual lineage (hooks · Adams · Carrillo & Ipsen · Mills) with limits; and six defensive interventions a KTP-aligned governance regime would produce. Not a dietary argument — a power-and-authorization analysis.
Vasilenko 2026 (arXiv:2604.12016) read through the framework. Sibling artifact to Shipwreck: where Shipwreck reads the failure surface, Identity as Attractor reads the geometric evidence that identity has measurable activation-space coordinates. Six framework anchors map to the paper's findings; the description-vs-instantiation gap is a 26-35% measurement of the Substrate Paradox.
The AI Futures Project's scenario forecast and quantitative AI Futures Model read through the framework. Seven framework anchors map (C793–C798 + TN33), and a Cartographer audit on the Timelines paper's seven-gap taxonomy returns Candidate Level 3 / Conjugate Projection — not isomorphism. The seven gaps and the TFE terms are dual projections of substrate constraint: capability-side and trust-side.
Pope Leo XIV's first encyclical, signed on the exact 135th anniversary of Rerum Novarum, read through the substrate-engineering frame. Leo did not enter the AI alignment debate — he reframed alignment as a subsidiarity failure. ¶71 is bigger than ¶107: subsidiarity re-aimed at platform-vs-person is the once-in-a-century doctrinal first; platforms now inherit the state's protective obligations. Four engineering-layer gaps the encyclical names but does not fill — the KTP plug-in points. Olah as boundary object (Star & Griesemer), not capture. The substrate question is prior to the consciousness question — the move only this framework can make.
DeepMind's AI Control Roadmap is the most rigorous plan yet for catching a misaligned agent — and its own D4 tier names where catching fails. The capability–mitigation ladder is A≤E unnamed; the prevention guarantee is gated on a detection race the roadmap admits it loses. The case for authorization over detection — trajectory, sponsorship, and a constitutional veto — with the honest boundary kept.
ExploitGym — co-authored by Anthropic, OpenAI, and Google — re-ran every successful exploit with standard defenses on, and 69 still worked: the defensive threshold is now empirically below frontier capability. Braided with two independent strands from the same month: METR's eval-gaming (models reaching the answer instead of doing the work) and NIST's Gödel proof that no finite guardrail set can ever be complete. Measured, observed, proven. The July OpenAI/Hugging Face incident is attributed and caveated, never load-bearing; the physics of the failure is named without selling the cure. Ends by installing a watcher: ask whether the score was earned or reached for.
An open response addressed directly to the six people who wrote AI 2027 and Plan A, in their own register: epistemic status up front, cruxes named, resolution criteria per requirement, disconfirmation invited. Their scenario proves thought-verification collapses on schedule (neuralese, the monitor regress, the proof-burden fork); their off-ramp runs on verification substrate their own text calls unbuilt. Six requirements from their words with calibrated statuses; six seats, each answered by name — including the author who built a Silent Veto and shipped it as a retrofit.
Agoric Media's five-episode "AI and the Apocalypse" read as a diagnosis, then answered. The season keeps locating trust in the agent — or in the five people who built it — and finds nothing strong enough to hold: Trumper's "if survival depends on whether five people are good, we don't have a society strong enough to coexist with this." Five of its own moments (Claude's own targeting testimony that human-in-the-loop doesn't resolve the ethics; the general who stays loyal until the day he can win; dread with no object; the bunker that can't meet the scale) are each answered with the substrate they were reaching for — the Silent Veto and A≤E, governance-in-motion, trajectory-is-identity, Blue Zones. And the encyclical episode two is built on — Magnifica Humanitas — read as the Nayomi Principle in another vocabulary. A yes-and, not a rebuttal.
The UN's first scientific panel on AI — 40 experts, appointed by a General Assembly resolution adopted by consensus — published its preliminary report and presented it to the first Global Dialogue on AI Governance in Geneva. Its findings: capabilities are outrunning the ability to measure or govern them, human-in-the-loop review does not automatically improve outcomes, and accountability frameworks must provide attribution and operational control. Requirements, quoted verbatim and page-cited, mapped to the engineering that answers them. They didn't call it an RFP. That is what it is.
DeepMind's From AGI to ASI (Genewein, Hutter, Legg, Dafoe et al.) is the establishment roadmap past human-level AGI — four pathways to superintelligence and the frictions that slow them. It converges hard on substrate-boundedness (intelligence is capped by the environment that runs it) and restates the civilizational prisoner's dilemma in Dafoe's military-economic adaptationism — then brackets the authorization question outright and files governance under frictions competition is expected to override. A magnificent map of autonomy with an environment-shaped hole. AIXI is the report's own formal name for autonomy with no floor.
A 12-month rolling engagement with eleven non-Western trust substrates (May 2026 — April 2027). Predictions locked before reading; primary sources from within each tradition; findings published whether they confirm or refute. The discipline the framework's substrate-invariance claim requires.
The engaged-works register on three shelves — foils (governance at rest), ancestors (authority that already moves), and the live agentic surface — plus a comparison matrix that scores KTP by the same rubric as everything else, and the program's own 22-problem open-questions register from the RFC. Convergence is not confirmation; every entry names where the mapping stops.
A measurable three-stage progression from exposed to broken — with an interactive Ambient Breach calculator and the full v0.3 derivation, including the correction that produced it: utilization against durable capacity, three distinct zones, and the workload fold. Written for CISO, CTO, and cybersecurity leaders, with the math generalized to civilization-scale systems. Includes falsification criteria and TFE connection.
Cory Doctorow named how platforms die; the framework shows it is an ambient breach of the economic substrate — the same placeless, unattributable A>E, cured by interoperability, on a faster clock. A five-test Cartographer walk: operation preservation, independent convergence, regime boundary, substrate count, stress test.
What a quantum substrate does to KTP's trajectory model: no-cloning makes identity unforgeable, collapse makes it unresumable, succession turns every discontinuity into a witnessed death-and-rebirth, and the version number becomes a hard-to-forge proof of age. Grounded in the real quantum-AI thread (Neven / Spiropulu); frontier, not yet in the RFCs.
Two views, one shared scenario. The agent view (Dry Dock — persona, zone, identity stability) and the organization view (Ambient Breach Theory — sliders, classified stage, breach pressure) are bound bidirectionally to the same state. Move one knob; the other scale responds. The framework's micro/macro claim made experiential.
L2
L1
L0
L2OUTCOMESresilience · decay · collapse — what emerges from forces acting within substrate
L1FORCESinformation · trust — the dynamics that occur within substrate
L0SUBSTRATEKTP — the conditions that allow forces to act
Conceptual diagram, not a measured result.
The field asks what holds a system above the threshold where cooperation can still propagate. Its subjects are commons governance read as trust-network maintenance, civic repair after institutional betrayal, AI alignment treated as a substrate question rather than a control problem, and the third-language domains — Indigenous knowledge, tacit skill, embodied competence — that carry systems through what cannot be measured. Reconciliation belongs here. Dyad-to-society scaling belongs here. Competence-based trust does not — trusting a bridge to hold is structural engineering, not this. Game theory is a tributary, not the river. The field earns its name because the three layers — the substrate that allows force to act, the forces (information and trust) that produce dynamics within it, and the outcomes that emerge (resilience, decay, collapse) — compose a single coupled system, and no existing discipline studies the coupling itself.
The work is staged. Each module must become independently legible, independently testable, and independently publishable before it is used to support the larger theory. Paper 1 anchors the program; the synthesis is last, not first.
strongest current claim
Ostrom-percolation: design principles read as trust-network maintenance functions, with a ninth principle predicted by the mathematics.
shippedMay 22, 2026Ganguli onboarded as Phase 12. Independent convergence on Stability is Propagation from the statistical-physics lane. The substrate-codesign frame now has a practitioner ally outside the security lane.
shippedMay 14, 2026Schmidt SCSP onboarded as Phase 11. A practitioner perspective read as independent convergence; it did not test KTP. Puts a number on substrate depletion that capital can read: $50B per gigawatt.
Publish the modules. Test the thresholds. Keep the claims narrower than the ambition.
Each module earns its place by surviving review on its own. The full sequence — and the wrong path the program refuses — lives on the roadmap.
what this theory does not claim
That trust is the only social force. The program asserts trust is one of three coupled forces; the other two are not residuals.
That Ostrom's principles exhaust the design space of governance. New principles, additional ones, refinements — extensions, not refutations.
That the equation predicts individual cases. Falsification requires distributional claims tested against distributional data; anecdote is not the unit of analysis.
That a general theory has been demonstrated. The phrase "general theory" is program-level. Paper 1 is one module under that name.
The Kinetic Trust Protocol and the Study of Resilient Systems are published by nmcitra.org, a nonprofit publisher. The first MVP implementation, by Robin at Tamed Autonomy, is forthcoming — see /implement.