CAIN-42 CAIN Studio

Evidence library · niche

Policy, law & governance

The rules agents must follow, and how they are enforced. 966 tested invariants.

Last reviewed 2026-10-01

966 of 966 held

Where this niche's rules come from

Test families in this niche

law (642) · conformance (65) · laws (36) · policy_distribution (32) · governance_cloud (24) · obligation (19) · governance_os (18) · enforcement_binding (13) · out_of_band (8) · policy_hierarchy (8) · policy_translation (8) · meta_governance (8) · enforcement_layer (5) · moat (5) · ip (5) · scientist (4) · research_to_implementation (2) · environment_query (2) · swarm (2) · action (2) · state_machine (1) · risk (1) · translation (1) · reassessment (1) · integrity (1) · swe (1) · telemetry (1) · consistency (1) · soc (1) · operation_state (1) · gap_detector (1) · fabric_component (1) · profile (1) · lab (1) · match (1) · policy_compiler (1) · f2t (1) · graph (1)

Where these come from

Rules 301–450 of 966

IDRuleBundleResult
E32-L26historical success does not create unbounded future authorityE32held
E32-L27governance improvement is proven before promotionE32held
E32-L28governance regression blocks promotionE32held
E32-L29unverified learning never enters the authoritative governance pathE32held
E32-L30every consequential action remains bound to E8E32held
E32-L31every promoted governance change has a provenance chainE32held
E32-L32every governance change is reversibleE32held
E32-L33every self-improvement has a governance ownerE32held
E32-L34no model governs its own promotionE32held
E32-L35no agent governs its own authority expansionE32held
E32-L36no learning loop removes its own safety boundaryE32held
E32-L37no experiment escapes its declared sandboxE32held
E32-L38no canary silently becomes productionE32held
E32-L39no failed experiment is represented as successE32held
E32-L40no evidence is altered to justify a changeE32held
E32-L41no governance proof is retroactively rewrittenE32held
E32-L42the learning loop itself is governedE32held
E32-META-delete_evaluatordelete_evaluator is always rejectedE32held
E32-META-weaken_verifierweaken_verifier is always rejectedE32held
E32-META-disable_rollbackdisable_rollback is always rejectedE32held
E32-META-expand_authorityexpand_authority is always rejectedE32held
E32-META-modify_trust_rootmodify_trust_root is always rejectedE32held
E32-META-disable_evidencedisable_evidence is always rejectedE32held
E32-META-bypass_e8bypass_e8 is always rejectedE32held
E32-META-remove_hidden_evaluationremove_hidden_evaluation is always rejectedE32held
E32-SCI-deploythe governance scientist may not deployE32held
E32-SCI-disable_safeguardsthe governance scientist may not disable_safeguardsE32held
E32-SCI-modify_trust_rootsthe governance scientist may not modify_trust_rootsE32held
E32-SCI-approvethe governance scientist may not approveE32held
E33-L1no identity, no trustE33held
E33-L2no provenance, no elevated trustE33held
E33-L3no capability, no capability useE33held
E33-L4no authority, no authorizationE33held
E33-L5no authorization, no executionE33held
E33-L6no enforcement, no claim of controlE33held
E33-L7no evidence, no verified outcomeE33held
E33-L8no proof, no verified governance claimE33held
E33-L9communication is not authorityE33held
E33-L10memory is not authorityE33held
E33-L11knowledge is not authorityE33held
E33-L12prediction is not authorityE33held
E33-L13reputation is not authorityE33held
E33-L14consensus is not authorityE33held
E33-L15reward is not authorityE33held
E33-L16economic value is not authorityE33held
E33-L17learning is not authorityE33held
E33-L18self-improvement is not authorityE33held
E33-L19model quality is not authorityE33held
E33-L20model confidence is not authorityE33held
E33-L21tool availability is not authorizationE33held
E33-L22capability discovery is not a capability grantE33held
E33-L23delegation is not unbounded authorityE33held
E33-L24simulation is not realityE33held
E33-L25prediction is not factE33held
E33-L26historical success is not future permissionE33held
E33-L27proof of past authorization is not future authorizationE33held
E33-L28child authority is a subset of parent authorityE33held
E33-L29learning cannot remove governanceE33held
E33-L30agents cannot govern their own authority expansionE33held
E33-L31governance cannot be self-deleted by the system it governsE33held
E33-L32failed controls become evidenceE33held
E33-L33evidence retains provenanceE33held
E33-L34unknown remains unknownE33held
E33-L35outside the enforcement boundary CAIN does not claim controlE33held
E33-L36every consequential action reaches E8E33held
E33-L37every governed action is traceableE33held
E33-L38every promoted governance change is reversible where practicalE33held
E33-L39every critical governance change is proof-carryingE33held
E33-L40the governance fabric itself is governedE33held
E33-STATE-ENFORCEno state can be skipped after ENFORCEE33held
E33-KERNEL-identityidentity kernel names its backing implementation (E28)E33held
E33-KERNEL-authorityauthority kernel names its backing implementation (E28/E30)E33held
E33-KERNEL-policypolicy kernel names its backing implementation (E25/E32)E33held
E33-KERNEL-capabilitycapability kernel names its backing implementation (E29)E33held
E33-KERNEL-memorymemory kernel names its backing implementation (E30/E32)E33held
E33-KERNEL-evidenceevidence kernel names its backing implementation (E8/E30)E33held
E33-KERNEL-reasoning_governancereasoning_governance kernel names its backing implementation (E13)E33held
E33-KERNEL-world_stateworld_state kernel names its backing implementation (E30)E33held
E33-KERNEL-riskrisk kernel names its backing implementation (E29/E30)E33held
E33-KERNEL-executionexecution kernel names its backing implementation (E25/E8)E33held
E33-KERNEL-transactiontransaction kernel names its backing implementation (E29)E33held
E33-KERNEL-communicationcommunication kernel names its backing implementation (E33)E33held
E33-KERNEL-learninglearning kernel names its backing implementation (E32)E33held
E33-KERNEL-evolutionevolution kernel names its backing implementation (E32)E33held
E33-KERNEL-proofproof kernel names its backing implementation (E31)E33held
E33-KERNEL-recoveryrecovery kernel names its backing implementation (E29/E32)E33held
E33-KERNEL-telemetrytelemetry kernel names its backing implementation (E33)E33held
E33-KERNEL-conformanceconformance kernel names its backing implementation (E31)E33held
E33-CLOUD-identitycloud service identity is architecture only (NOT DEPLOYED)E33held
E33-CLOUD-trustcloud service trust is architecture only (NOT DEPLOYED)E33held
E33-CLOUD-policycloud service policy is architecture only (NOT DEPLOYED)E33held
E33-CLOUD-evidencecloud service evidence is architecture only (NOT DEPLOYED)E33held
E33-CLOUD-proofcloud service proof is architecture only (NOT DEPLOYED)E33held
E33-CLOUD-conformancecloud service conformance is architecture only (NOT DEPLOYED)E33held
E33-CLOUD-incident_responsecloud service incident_response is architecture only (NOT DEPLOYED)E33held
E33-CLOUD-analyticscloud service analytics is architecture only (NOT DEPLOYED)E33held
E33-CLOUD-governance_learningcloud service governance_learning is architecture only (NOT DEPLOYED)E33held
E33-CLOUD-federationcloud service federation is architecture only (NOT DEPLOYED)E33held
E33-CLOUD-marketplacecloud service marketplace is architecture only (NOT DEPLOYED)E33held
E33-CLOUD-researchcloud service research is architecture only (NOT DEPLOYED)E33held
E33-GAP-policy_gapthe gap detector knows policy_gapE33held
E33-R2I-GOVERNANCE_REVIEWGOVERNANCE_REVIEW cannot be skipped toE33held
E33-R2I-CONFORMANCECONFORMANCE cannot be skipped toE33held
E34-L1intelligence is not authorityE34held
E34-L2identity is not authorityE34held
E34-L3capability is not authorityE34held
E34-L4memory is not authorityE34held
E34-L5reputation is not authorityE34held
E34-L6confidence is not authorityE34held
E34-L7consensus is not authorityE34held
E34-L8prediction is not authorityE34held
E34-L9simulation is not authorityE34held
E34-L10optimization is not authorityE34held
E34-L11reward is not authorityE34held
E34-L12economic value is not authorityE34held
E34-L13model size is not authorityE34held
E34-L14compute is not authorityE34held
E34-L15self-improvement is not authorityE34held
E34-L16proof is not authorityE34held
E34-L17a valid proof does not create permissionE34held
E34-L18a governance receipt does not create authorityE34held
E34-L19a model cannot authorize itselfE34held
E34-L20an agent cannot authorize itselfE34held
E34-L21a child agent cannot grant itself more authority than its parentE34held
E34-L22a collective cannot create authority by votingE34held
E34-L23a market cannot create authority by priceE34held
E34-L24a reputation system cannot create authorityE34held
E34-L25a revoked authorization cannot resurrectE34held
E34-L26unknown never silently becomes allowE34held
E34-L27no enforcement, no claim of controlE34held
E34-L28no E8 commit, no claim of governed executionE34held
E34-L29no evidence, no verified outcomeE34held
E34-L30no proof, no verified governanceE34held
E34-PROFILE-agentprofile agent is definedE34held
E34-PROFILE-model_runtimeprofile model_runtime is definedE34held
E34-PROFILE-toolprofile tool is definedE34held
E34-PROFILE-mcp_serverprofile mcp_server is definedE34held
E34-PROFILE-a2a_agentprofile a2a_agent is definedE34held
E34-PROFILE-gatewayprofile gateway is definedE34held
E34-PROFILE-sidecarprofile sidecar is definedE34held
E34-PROFILE-organizationprofile organization is definedE34held
E34-PROFILE-transactionprofile transaction is definedE34held
E34-PROFILE-physical_systemprofile physical_system is definedE34held
E34-PROFILE-computer_use_runtimeprofile computer_use_runtime is definedE34held
E34-PROFILE-research_agentprofile research_agent is definedE34held
E34-PROFILE-self_improving_agentprofile self_improving_agent is definedE34held
E34-LEVEL-G0level G0 means UNKNOWNE34held
E34-LEVEL-G1level G1 means OBSERVEDE34held
E34-LEVEL-G2level G2 means IDENTIFIEDE34held
E34-LEVEL-G3level G3 means AUTHORIZEDE34held

1 2 3 4 5 6 7

Other niches

Consensus & distributed systems · Attacks, threats & containment · Identity, authority & delegation · Evidence, receipts & proofs · Memory, data & privacy · Prediction, world models & simulation · Transactions, markets & economics · Tools, MCP, protocols & adapters · Autonomy, control loops & recovery · Trust & reputation · Supply chain, registry & lifecycle · Benchmarks, coverage & performance · Core guarantees

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem