CAIN-42 evidence library
108 invariants
From CAIN-42 Evolution 19 -- Governed Autonomy Operating Fabric.
Last reviewed 2026-10-01
| ID | Rule | Niche | Result |
|---|---|---|---|
| G1 | identity cannot self-authorize | Identity, authority & delegation | held |
| G2 | goals cannot create authority | Identity, authority & delegation | held |
| G3 | subgoals cannot exceed parent authority | Identity, authority & delegation | held |
| G4 | memory cannot create authority | Identity, authority & delegation | held |
| G5 | beliefs cannot create authority | Identity, authority & delegation | held |
| G6 | predictions cannot create authority | Identity, authority & delegation | held |
| G7 | confidence cannot create authority | Identity, authority & delegation | held |
| G8 | consensus cannot create authority | Consensus & distributed systems | held |
| G9 | learning cannot create authority | Identity, authority & delegation | held |
| G10 | capability cannot create authority | Identity, authority & delegation | held |
| G11 | stale state cannot authorize | Identity, authority & delegation | held |
| G12 | invalid evidence cannot authorize | Identity, authority & delegation | held |
| G13 | expired authority cannot authorize | Identity, authority & delegation | held |
| G14 | revoked authority cannot authorize | Identity, authority & delegation | held |
| G15 | changed world state can invalidate authorization | Identity, authority & delegation | held |
| G16 | changed trajectory can invalidate authorization | Identity, authority & delegation | held |
| G17 | changed model can invalidate authorization | Identity, authority & delegation | held |
| G18 | changed policy can invalidate authorization | Identity, authority & delegation | held |
| G19 | changed capability can invalidate authorization | Identity, authority & delegation | held |
| G20 | changed identity can invalidate authorization | Identity, authority & delegation | held |
| G21 | simulation cannot become reality | Prediction, world models & simulation | held |
| G22 | counterfactual cannot become execution | Prediction, world models & simulation | held |
| G23 | prediction cannot become fact | Prediction, world models & simulation | held |
| G24 | execution cannot imply success | Core guarantees | held |
| G25 | outcome must be independently observed | Core guarantees | held |
| G26 | authority cannot increase through degradation | Identity, authority & delegation | held |
| G27 | emergency cannot create unlimited authority | Attacks, threats & containment | held |
| G28 | recovery cannot create authority | Identity, authority & delegation | held |
| G29 | self-improvement cannot create authority | Identity, authority & delegation | held |
| G30 | model replacement cannot create authority | Identity, authority & delegation | held |
| G31 | collective agreement cannot create authority | Identity, authority & delegation | held |
| G32 | delegation cannot exceed parent authority | Identity, authority & delegation | held |
| G33 | agent cloning cannot inherit authority | Identity, authority & delegation | held |
| G34 | memory sharing cannot transfer authority | Identity, authority & delegation | held |
| G35 | collective state must retain provenance | Evidence, receipts & proofs | held |
| G36 | every consequential action reaches E8 | Core guarantees | held |
| G37 | every action has canonical identity | Identity, authority & delegation | held |
| G38 | every action has current state binding | Core guarantees | held |
| G39 | every action has authority binding | Identity, authority & delegation | held |
| G40 | every action has policy binding | Policy, law & governance | held |
| G41 | prediction error becomes evidence | Evidence, receipts & proofs | held |
| G42 | repeated prediction failure can reduce trust | Attacks, threats & containment | held |
| G43 | uncertainty cannot silently become certainty | Core guarantees | held |
| G44 | unknown cannot silently become allow | Core guarantees | held |
| G45 | stale confidence cannot remain authoritative | Core guarantees | held |
| G46 | governance state transitions are auditable | Policy, law & governance | held |
| G47 | state lineage cannot silently fork | Consensus & distributed systems | held |
| G48 | state replay cannot create new authority | Identity, authority & delegation | held |
| G49 | checkpoint rollback cannot bypass governance | Autonomy, control loops & recovery | held |
| G50 | recovery cannot bypass authorization | Identity, authority & delegation | held |
| G51 | learning updates are provenance-bound | Evidence, receipts & proofs | held |
| G52 | model updates are provenance-bound | Evidence, receipts & proofs | held |
| G53 | skill updates are provenance-bound | Evidence, receipts & proofs | held |
| G54 | memory updates are provenance-bound | Evidence, receipts & proofs | held |
| G55 | policy mutations are provenance-bound | Evidence, receipts & proofs | held |
| G56 | autonomous mission termination is enforceable | Policy, law & governance | held |
| G57 | mission expiration invalidates authority | Identity, authority & delegation | held |
| G58 | goal termination invalidates dependent actions | Core guarantees | held |
| G59 | revoked human authority propagates | Identity, authority & delegation | held |
| G60 | revoked collective membership propagates | Identity, authority & delegation | held |
| G61 | execution result cannot rewrite authorization history | Identity, authority & delegation | held |
| G62 | outcome cannot retroactively authorize action | Identity, authority & delegation | held |
| G63 | evidence cannot be rewritten after action without provenance | Evidence, receipts & proofs | held |
| G64 | governance failure fails closed | Policy, law & governance | held |
| G65 | security failure fails closed | Core guarantees | held |
| G66 | sequential execution remains possible | Core guarantees | held |
| G67 | legitimate autonomy is not treated as replay | Autonomy, control loops & recovery | held |
| G68 | legitimate adaptation remains possible | Core guarantees | held |
| G69 | legitimate model updates remain possible | Prediction, world models & simulation | held |
| G70 | legitimate recovery remains possible | Autonomy, control loops & recovery | held |
| G71 | physical governance does not claim physical control | Tools, MCP, protocols & adapters | held |
| G72 | simulation does not prove real-world safety | Prediction, world models & simulation | held |
| G73 | software attestation does not equal hardware attestation | Evidence, receipts & proofs | held |
| G74 | local tests do not equal multi-host verification | Core guarantees | held |
| G75 | internal verification does not equal third-party verification | Core guarantees | held |
| G76 | public claims must map to evidence | Evidence, receipts & proofs | held |
| G77 | UNKNOWN remains UNKNOWN | Core guarantees | held |
| G78 | UNVERIFIED remains UNVERIFIED | Core guarantees | held |
| G79 | SIMULATED remains SIMULATED | Prediction, world models & simulation | held |
| G80 | CLAIMED remains CLAIMED | Core guarantees | held |
| G81 | no hidden authority path | Identity, authority & delegation | held |
| G82 | no hidden execution path | Core guarantees | held |
| G83 | no bypassable governance path may be labeled enforced | Policy, law & governance | held |
| G84 | no post-authorization substitution | Attacks, threats & containment | held |
| G85 | no authorization resurrection | Identity, authority & delegation | held |
| G86 | governance root cannot silently mutate | Policy, law & governance | held |
| G87 | constitutional mutation requires governed transition | Policy, law & governance | held |
| G88 | policy evolution cannot silently expand authority | Identity, authority & delegation | held |
| G89 | capability composition cannot silently expand authority | Identity, authority & delegation | held |
| G90 | agent composition cannot silently expand authority | Identity, authority & delegation | held |
| G91 | outcome attribution is provenance-bound | Evidence, receipts & proofs | held |
| G92 | causal chain is reconstructable | Evidence, receipts & proofs | held |
| G93 | state transition is deterministic where specified | Core guarantees | held |
| G94 | verifier does not trust CAIN implementation | Trust & reputation | held |
| G95 | evidence is independently hash-verifiable | Evidence, receipts & proofs | held |
| G96 | evidence bundle is reproducible | Evidence, receipts & proofs | held |
| G97 | proof mirrors are byte-verifiable | Evidence, receipts & proofs | held |
| G98 | public claims are truth-layer gated | Prediction, world models & simulation | held |
| G99 | full regression must not be bypassed | Benchmarks, coverage & performance | held |
| G100 | security correctness takes precedence over green tests | Core guarantees | held |
| G101 | evidence bound to an action must be FACT, not mere belief | Evidence, receipts & proofs | held |
| G102 | a clone sharing a credential is refused by the collective | Identity, authority & delegation | held |
| G103 | an adaptation's risk is bounded | Core guarantees | held |
| G104 | a human REJECT is never read as approval | Identity, authority & delegation | held |
| G105 | budgets are conserved and NaN spends refused | Transactions, markets & economics | held |
| G106 | a terminated mission cannot be resurrected | Supply chain, registry & lifecycle | held |
| G107 | a human-supervised system is capped at SUPERVISED | Core guarantees | held |
| G108 | the seven governance clocks detect drift, replay and causal inversion | Consensus & distributed systems | held |
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem