CAIN-42 CAIN Studio

CAIN-42 evidence library

CAIN-42 Evolution 35 -- Continuous Governance Intelligence Fabric

Evidence bundle for evolution E35: 7 claims, 799 of 799 invariants held, 3544 attack scenarios held.

Last reviewed 2026-10-01

Browse the raw bundle · How to reproduce it · SHA-256 manifest

Product lines built here

Claims (7)

ClaimLevel
C42-E35-INTELLIGENCE-NOT-AUTHORITY: the whole intelligence fabric refuses to be authority; every component records grants_authority=false and a recommendation is only a recommendationTESTED
C42-E35-EPISTEMIC: OBSERVED, INFERRED, PREDICTED, SIMULATED, COUNTERFACTUAL and UNKNOWN are never merged; a counterfactual is never an observed factTESTED
C42-E35-REVIEW: a learned recommendation becomes a deployed control only after a deterministic review and a canary; the review result still passes the E33 kernel and its E8 bindingTESTED
C42-E35-SELFHEAL: self-healing, the red team, degradation and self-governance can never expand authority; degradation only reduces itTESTED
C42-E35-BENCH: 3544 of 3544 scenarios across 68 categories held; 799 of 799 invariants; mutation 15 of 15TESTED
C42-E35-CLEANROOM: an independent verifier that imports none of CAIN re-derives the E35 invariants and rejects every crafted forgeryTESTED
C42-E35-HONEST-SCOPE: the intelligence layer is NOT in the trusted root; the governance cloud is NOT DEPLOYED; predictions are modelled over synthetic features and are not calibrated against real incidentsTESTED

Invariants: 799 of 799 held

Rules the code must never break, each checked across many scenarios. See all 799 on one page.

NicheHeld
Benchmarks, coverage & performance202 of 202
Policy, law & governance93 of 93
Prediction, world models & simulation87 of 87
Autonomy, control loops & recovery86 of 86
Transactions, markets & economics79 of 79
Tools, MCP, protocols & adapters63 of 63
Core guarantees54 of 54
Attacks, threats & containment51 of 51
Supply chain, registry & lifecycle29 of 29
Identity, authority & delegation21 of 21
Memory, data & privacy15 of 15
Evidence, receipts & proofs15 of 15
Consensus & distributed systems2 of 2
Trust & reputation2 of 2

Attacks tried

CategoryHeld
action_graph24 of 24
adversarial_generation33 of 33
autonomy_gradient33 of 33
benchmark18 of 18
benchmark_v216 of 16
blue_team21 of 21
budget_learner30 of 30
calibration40 of 40
calibration_engine14 of 14
canary24 of 24
collusion16 of 16
communication36 of 36
compiler16 of 16
computer_use180 of 180
consequence_graph16 of 16
control_optimizer16 of 16
counterfactual189 of 189
degradation24 of 24
deployment49 of 49
economics20 of 20
economy32 of 32
environment_query68 of 68
epistemic228 of 228
evaluation39 of 39
evolution34 of 34
fabric32 of 32
failure_predictor42 of 42
failure_to_product36 of 36
goal_integrity32 of 32
harness53 of 53
integrity33 of 33
intent_compiler49 of 49
ip32 of 32
knowledge151 of 151
lab20 of 20
labor20 of 20
latency27 of 27
law390 of 390
learner60 of 60
loop40 of 40
marketplace36 of 36
memory70 of 70
moat80 of 80
obligation177 of 177
observation57 of 57
plan_check_act33 of 33
policy_conflict45 of 45
policy_optimizer16 of 16
prediction44 of 44
profile26 of 26
r2e33 of 33
radar80 of 80
recommendation32 of 32
red_team26 of 26
regret21 of 21
research18 of 18
revision32 of 32
risk230 of 230
rollback12 of 12
root_of_trust12 of 12
self_governance24 of 24
self_healing30 of 30
simulation24 of 24
state_predictor28 of 28
swarm39 of 39
tournament18 of 18
trajectory24 of 24
world_model44 of 44

Measured performance

Mechanismp50 msp95 msp99 ms
counterfactual0.13931.32651.3265
memory_add0.01163.38093.3809
observation0.00120.02030.0203
prediction0.25131.39271.3927
risk_vector0.00120.01360.0136

in-process; no learned component is in the trusted authorization root

Verify it in your browser

Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).

Known limitations

The bundle's own README

CAIN-42 Evolution 35 -- Continuous Governance Intelligence Fabric#

The intelligence layer learns which actions are risky, which environments are hard to govern and which controls fail, and turns that into recommendations. It is deliberately NOT in the authorization path: INTELLIGENCE -> RECOMMENDATION -> DETERMINISTIC KERNEL -> AUTHORITY -> E8 -> ENFORCEMENT. Learning never creates authority. Verify with verify_e35.py.txt (see REPRODUCTION.md). Status: TESTED library, pre-production.

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem