Experimental evaluation demonstrates deterministic artifact governance blocks invalid state transitions in AI workflows, indicating feasible enforcement of policy boundaries.
An AI-enabled workflow can process a source record, compute a result, draft a notice, and update an external record. Service placement does not determine which artifacts have accepted standing, which are derived, which are communicative, or which may authorize a consequence. We organize these artifacts into five state classes: accepted evidence or assertions (K), derived results (I), communicative artifacts (C), effects (E), and observed outcomes (O). Policy, adjudication, enforcement, assurance, and remedy functions (G) govern transitions among them. The central constraint is that no artifact silently acquires another class’s standing, permissions, or downstream effect. A structured analysis of legislation, federal policies, audit guidance, technical guidance, management standards, and scholarly literature identifies recurring operational concerns without treating the sources as equivalent or claiming compliance. We implement the transition rules in a deterministic, standard-library Python kernel. The kernel operates in one process with typed HMAC-authenticated artifacts, a bounded decision-context digest, separate logical issuer roles, and hash-chained transition receipts. All 250 seeded valid workflows completed with verified receipt chains and recovery of all 12 context artifacts. The strict profile blocked or detected all 2,250 attempts across nine invariant-directed mutation classes; each targeted ablation admitted its corresponding prohibited path. Within the finite abstract transition relation, the strict profile reached 51 states and no catalogued bad state, whereas the collapsed profile reached 6,729 states and all nine. In one 2,000-case benchmark per profile, the strict-to-collapsed median runtime ratio was 1.076, and the strict ledger used 10,722 serialized receipt bytes per case. These results establish constructive feasibility and guard behavior for the implemented paths, but not production security, regulatory compliance, decision quality, institutional legitimacy, or superiority over other designs.
No takes yet. Share an insight, caveat, or question.
Lewis et al. (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: