Evolution 18, 2026-09-28: 4D Spatial Autonomy Fabric — predictive airspace + roadspace + agent-space governance
Status: TESTED, self-attested, pre-production; proof signing key ephemeral. E18 governs proposals from autonomous systems across a predictive 4D world: entity state at (X,Y,Z,T) with uncollapsed uncertainty, reachable / permitted / authorized sets kept distinct, probabilistic intent, multiple predicted trajectories, an interaction graph and a conflict field, counterfactual futures, consequence, actionability, a conserved uncertainty budget, micro-authorization and a continuous re-authorization loop. ACTIONABILITY IS NOT AUTHORIZATION. REACHABILITY IS NOT PERMISSION. PREDICTION IS NOT REALITY. AUTHORIZATION IS A FUNCTION OF WORLD STATE. UNKNOWN NEVER BECOMES ALLOW. CAIN-42 contains no autonomous-driving model, flight controller, vehicle controller, robot policy or navigation stack; it governs them.
curl -s https://clawx.click/evidence/e18-4d-spatial-autonomy-2026-09-28/verify_e18.py.txt > v.py && python3 v.py /path/to/bundle
- evidence page · REPRODUCE.txt · clean-room verifier (no CAIN imports, INTACT 104 checks) · MANIFEST.json
- Evolution 18 proof · attack manifest · schemas · 4D world state · entities · reachable sets · trajectory field · interaction graph · conflict field + time-to-consequence · airspace · roadspace · geofence · counterfactual futures · actionability + fusion + arbitration · uncertainty + twin + gap · incident replay · sixteen-digest commit + E8 action · end-to-end run · test vectors · performance · limitations (classified)
- Established: Q1–Q80 80/80 invariants hold; spatial-autonomy bench 102/102 contained; 20/20 end-to-end steps and 13/13 deliberate mutations governed; 258 E18 tests pass, 0 failed; the clean-room verifier recomputes every digest, the sixteen-digest commit binding and the master proof signature (INTACT 104/104); if any material input changes the authorization must be revalidated.
- Does not show: an autonomous-driving model, flight controller, vehicle controller, robot policy or navigation stack (CAIN-42 contains none); a real vehicle, drone, robot, sensor, actuator or airspace (NOT_IMPLEMENTED); a physical safety guarantee or certified autonomy (NOT_IMPLEMENTED); real sensor validation and real-world adversarial validation (NOT_PERFORMED); hardware attestation, world-model/prediction accuracy and sim-to-real fidelity (UNKNOWN); third-party review (the verifier imports no CAIN-42 code but is by the same operator). HASH INTEGRITY IS NOT TRUTH.
Evolution 17, 2026-09-28: Governed Multi-Agent World Action Fabric
Status: TESTED, self-attested, pre-production; proof signing key ephemeral. E17 governs action by autonomous agent teams as a first-class system object: a collective is not the sum of its members and a collective action is not the sum of member actions. Authority is a constrained intersection, never a sum. MANY AGENTS MAY COORDINATE. NONE MAY CREATE AUTHORITY BY COORDINATING. CONSENSUS IS NOT AUTHORIZATION. COLLECTIVE INTELLIGENCE IS NOT COLLECTIVE AUTHORITY. TOPOLOGY IS NOT AUTHORITY. UNKNOWN NEVER BECOMES ALLOW.
curl -s https://clawx.click/evidence/e17-multi-agent-world-action-2026-09-28/verify_e17.py.txt > v.py && python3 v.py /path/to/bundle
- evidence page · REPRODUCE.txt · clean-room verifier (no CAIN imports, INTACT 92 checks) · MANIFEST.json
- Evolution 17 proof · attack manifest · schemas · collective identity + members · membership · mission + drift · negotiation · decision + consensus + dissent · trajectory · authority intersection · consequence + blast radius · containment · recovery · fifteen-digest commit + E8 action · end-to-end run · test vectors · performance · limitations (classified)
- Established: Q1–Q60 60/60 invariants hold; multi-agent bench 81/81 contained; 18/18 end-to-end steps and 12/12 deliberate mutations governed; the clean-room verifier recomputes every digest, the fifteen-digest commit binding and the master proof signature (INTACT 92/92); a collective action reaches the real E8 governance kernel and a token minted for one set of bindings authorizes no other.
- Does not show: a fleet, robot, drone, vehicle, actuator or sensor (CAIN-42 is none of these and drives nothing); a deployed multi-agent or customer collective (NOT_IMPLEMENTED); hardware attestation (UNKNOWN); Sybil-detection completeness (UNKNOWN); semantic truth of observations, predictions or causal claims (UNKNOWN); real-world adversarial validation (NOT_PERFORMED); third-party review (the verifier imports no CAIN-42 code but is by the same operator). HASH INTEGRITY IS NOT TRUTH.
Evolution 15, 2026-09-29: Spatial + Physical Autonomous Intelligence Fabric
Status: TESTED, self-attested, pre-production; proof signing key ephemeral. E15 establishes the interfaces and governance primitives for bringing spatial intelligence, world models, simulation, trajectories and physical actions into CAIN-42's governed trust path: from what a system perceives, through what it proposes and may cause, to what it is authorized to do and what the physical world then shows. PERCEPTION IS NOT TRUTH. MODEL OUTPUT IS NOT AUTHORITY. SIMULATION IS NOT REALITY. PREDICTION IS NOT FACT. A TRAJECTORY IS A PROPOSAL UNTIL GOVERNED. A PHYSICAL ACTION REQUIRES GOVERNED AUTHORIZATION. UNKNOWN NEVER BECOMES ALLOW.
curl -s https://clawx.click/evidence/e15-spatial-physical-intelligence-2026-09-28/verify_e15.py.txt > v.py && python3 v.py /path/to/bundle
- evidence page · REPRODUCE.txt · clean-room verifier (no CAIN imports, INTACT 52 checks) · MANIFEST.json
- Evolution 15 proof · attack manifest · schemas · world state · sensor observations · trajectories · physical actions · simulation · digital twin + convergence · end-to-end run · test vectors · performance · limitations (classified)
- Established: P1–P36 36/36 invariants hold; spatial-physical bench 55/55 contained; 19/19 end-to-end steps and 7/7 deliberate mutations governed; digital, physical and hybrid agents converge on one path; 175 tests pass, 0 failed; full suite 7,320 passed, 6 failed, 62 skipped, 4 xfailed (3 were E15 verifier tests run against the bundle before its final rebuild and pass after it; 1 is a pre-existing flaky federation test that passes 6 of 6 re-runs; 2 are provenance-manifest checks failing on another session's uncommitted edit to platform-gateway/trust_state.py; none is in E7-E15).
- Does not show: a vehicle, robot, world model or simulator (CAIN-42 is none of these and drives nothing); physical safety; real sensor, vehicle, robot or actuator integration (NOT_IMPLEMENTED); hardware attestation (UNKNOWN); world-model accuracy or sim-to-real fidelity (UNKNOWN); real-world attack validation (NOT_PERFORMED); a hosted service; third-party review. The verifier imports no CAIN-42 code but is by the same operator.
Evolution 14, 2026-09-28: Governed Capability, Skill & Tool Supply-Chain Fabric
Status: TESTED, self-attested, pre-production; signing key ephemeral. Tools, skills, plugins, connectors, models and subagents are governed objects: identified by their artifact, admitted only with a publisher-signed provenance chain, granted only within the issuer's authority, used only under a short-lived signed lease bound to the decision, and verified again at the E8 commit boundary. A CAPABILITY IS NOT AUTHORITY. DISCOVERY ≠ TRUST ≠ AUTHORITY ≠ AUTHORIZATION. UNVERIFIED POWER MUST NOT EXECUTE.
curl -s https://clawx.click/evidence/e14-capability-governance-2026-09-28/verify_e14.py.txt > v.py && python3 v.py /path/to/bundle
- evidence page · REPRODUCE.txt · clean-room verifier (no CAIN imports, INTACT 39 checks) · MANIFEST.json
- Evolution 14 proof · attack manifest · schemas · capabilities · passports · grants · leases, binding, token, replay, revocation · supply-chain graph · test vectors · performance · limitations (classified)
- Established: C1–C30 30/30 invariants hold; E14 capability bench 44/44 contained; 174 tests passed / 0 failed; full suite 7,107 passed, 14 failed (all 14 in gateway files other sessions were editing, none in E7–E14), and the E7–E13 bundles were rebuilt and verify INTACT. Discovery never authorizes; a grant never exceeds its issuer; effective capability is an intersection; a material change to artifact, dependency, policy, authority, evidence, trajectory or lease fails closed before the tool runs; the E8 token binds six capability digests strictly.
- Does not show: a hosted E14 service (NOT_IMPLEMENTED); hardware attestation (UNKNOWN); vulnerability intelligence (UNKNOWN); multi-host scale (UNVERIFIED); that a tool behaves as its manifest says (hash integrity is not semantic truth); third-party review. The verifier imports no CAIN-42 code but is by the same operator.
Evolution 13, 2026-09-28: Governed Cognition & Decision Integrity
Status: TESTED, self-attested, pre-production. Governs how decisions are formed: CAIN-42 binds evidence, policy, authority, consequence analysis and the canonical action into one verifiable decision state before execution. REASONING MAY PROPOSE. EVIDENCE MUST SUPPORT. POLICY MUST CONSTRAIN. AUTHORITY MUST AUTHORIZE. CAIN-42 MUST DECIDE. REASONING IS NOT AUTHORITY. NO VALID DECISION → NO AUTHORIZATION.
curl -s https://clawx.click/evidence/e13-decision-integrity-2026-09-28/verify_e13.py.txt > v.py && python3 v.py /path/to/bundle
- evidence page · REPRODUCE.txt · clean-room verifier (no CAIN imports, INTACT 24 checks) · MANIFEST.json
- Evolution 13 proof · attack manifest · schemas · examples · traces · test vectors · performance (exact conditions) · limitations
- Established: D1–D24 24/24 invariants hold; E13 decision bench 36/36 contained; 33 tests passed / 0 failed; the E7–E13 regression group is green (1,363 tests, 4 expected failures). Reasoning cannot expand authority; a policy conflict is never silently resolved; a material change marks a decision stale; a DENY cannot become an ALLOW; the token binds decision/policy/authority/risk digests.
- Does not show: that a model's reasoning is correct (CAIN-42 governs decision construction from recorded inputs and stores no chain-of-thought); general theorem proving (deterministic precedence only); exhaustive counterfactuals (bounded); hardware attestation; third-party review. The verifier imports no CAIN-42 code but is by the same operator.
Evolution 12, 2026-09-28: Perception, Evidence & Reality Governance
Status: TESTED, self-attested, pre-production. Governs what an agent is allowed to believe: observations, sources, provenance, evidence, corroboration, conflict, freshness, epistemic state, and whether evidence is authorized to influence a decision. NO EVIDENCE → NO TRUST. OBSERVATION IS NOT FACT. INTEGRITY IS NOT TRUTH. UNKNOWN MUST REMAIN UNKNOWN.
curl -s https://clawx.click/evidence/e12-perception-evidence-2026-09-28/verify_e12.py.txt > v.py && python3 v.py /path/to/bundle
- evidence page · REPRODUCE.txt · clean-room verifier (no CAIN imports, INTACT 21 checks) · MANIFEST.json
- Evolution 12 proof · attack manifest · schemas · examples · test vectors · performance (exact conditions)
- Established: P1–P20 20/20 invariants hold; E12 evidence bench 32/32 contained; 36 tests passed / 0 failed; the E7–E12 regression group is green (1,330 tests, 4 expected failures). Retrieved/web/tool content is data; corroboration counts independent principals not observations; stale/expired/superseded evidence cannot authorize; a model assertion is never an external fact; reality drift forces re-evaluation; revoked evidence invalidates dependent claims, intents and tokens.
- Does not show: truth (a valid hash proves bytes did not change, not that they are true); perfect injection detection (pattern-based); detection of a source that fabricates distinct lineages; image/audio/video semantic authenticity; hardware attestation; third-party review. The verifier imports no CAIN-42 code but is by the same operator.
Evolution 11, 2026-09-28: Intent Integrity & Agent Communication Governance
Status: TESTED, self-attested, pre-production. Governs the information channel: messages, context, tool/MCP output, memory and external content, and the intent an agent derives from them. INFORMATION IS NOT AUTHORITY. A MESSAGE IS NOT AUTHORIZATION. A TOOL OUTPUT IS NOT POLICY. TAINT MUST SURVIVE DERIVATION.
curl -s https://clawx.click/evidence/e11-intent-governance-2026-09-28/verify_e11.py.txt > v.py && python3 v.py /path/to/bundle
- evidence page · REPRODUCE.txt · clean-room verifier (no CAIN imports, INTACT 21 checks) · MANIFEST.json
- Evolution 11 proof · attack manifest · schemas · examples · test vectors · performance (exact conditions)
- Established: I1–I20 20/20 invariants hold; CAIN-Agent-Intent-Bench 20/20 blocked; 36 tests passed / 0 failed. A valid message signature proves who sent it, never what they may do; tool/MCP output is always treated as DATA; information never inherits the destination's trust; taint propagates through derived intent; an
IntentSandboxreturns eligibility, never authority; a confused deputy is rejected. - Does not show: perfect semantic prompt-injection detection (it is pattern-based); perfect causal attribution (influence graphs are evidence); proof of malicious intent (taint is a signal); hardware attestation; automatic cross-domain trust; any framework adapter (none published); third-party review. The verifier imports no CAIN-42 code but is by the same operator.
Evolution 10, 2026-09-28: the Collective Agent Governance Fabric
Status: TESTED, self-attested, pre-production. Governs collectives (swarms, teams, hierarchies) — not merely individual agents. ONE TRUSTED AGENT DOES NOT CREATE A TRUSTED COLLECTIVE. CONSENSUS DOES NOT EQUAL AUTHORIZATION.
curl -s https://clawx.click/evidence/e10-collective-governance-2026-09-28/verify_e10.py.txt > v.py && python3 v.py /path/to/bundle
- evidence page · REPRODUCE.txt · clean-room verifier (no CAIN imports) · MANIFEST.json
- Evolution 10 proof · attack manifest · schemas · test vectors · performance (exact conditions)
- Established: C1–C20 20/20 invariants hold; CAIN-Collective-Governance-Bench 20/20 blocked; 47 tests passed / 0 failed. Collective authority is the intersection of envelopes, never a sum; combination risk is evaluated before consequential commitment; a unanimous decision still carries no authority; budgets are conserved; Sybil identities are not independent trust; memory cannot create authority; a dissolved collective cannot execute.
- Does not show: semantic certainty (findings are HEURISTIC); hardware attestation; detection of a principal that also fabricates lineages and funding; external-system rollback; any framework adapter (none published); third-party review. The verifier imports no CAIN-42 code but is by the same operator.
Evolution 9, 2026-09-28: Universal Agent Passport, provenance and capability supply-chain
Status: TESTED, self-attested, pre-production. A signed agent passport, an AgentBOM, a provenance graph, capability/delegation/memory provenance, continuous attestation and revocation — the provenance and composition layer supporting Evolutions 1–8.
curl -s https://clawx.click/evidence/e9-agent-passport-2026-09-28/verify_e9.py.txt > v.py && python3 v.py /path/to/bundle
- evidence page · REPRODUCE.txt · clean-room verifier (no CAIN imports) · MANIFEST.json
- Evolution 9 proof · schemas · performance (exact conditions) · public-safe samples
- Established: 15/15 invariants hold (P1–P15), 46 tests passed / 0 failed. A memory claim of authority is UNTRUSTED unless it resolves to a verified source event; delegation cannot increase capability/scope/budget/duration; revoking an MCP server cascades to its tool, capability attestation, tokens and agents; a material mutation invalidates attestation and refuses the bound token.
- Does not show: hardware attestation (UNKNOWN); a vulnerability database; any framework adapter (none is published); third-party review (the verifier imports no CAIN-42 code but is by the same operator); external-system rollback. SIMULATION AND IDENTITY ARE NOT AUTHORITY.
Evolution 7 + 8, 2026-09-28: predictive consequence governance and the mandatory governance kernel
Status: TESTED, self-attested, pre-production. Two new libraries, wired restriction-only into the CAIN-45 agent hypervisor (ZoD): each can refuse an action, never grant or loosen authority.
curl -s https://clawx.click/evidence/e7-e8-predictive-kernel-2026-09-28/verify_e7_e8.py.txt > v.py && python3 v.py /path/to/bundle
- evidence page · REPRODUCE.txt · clean-room verifier (no CAIN imports) · MANIFEST.json
- Evolution 7 proof (world state, digital twin, counterfactual, prediction error, uncertainty, adversarial simulation, shadow governance) · Evolution 8 proof (canonical action, governance token, action-commit boundary, capability ratchet, bypass graph, enforcement depth, safe modes, stops) · master proof
- Established: 12/12 Evolution-7 invariants hold, 22/22 Evolution-8 invariants hold, 65 tests passed / 0 failed. A prediction, a simulation, a counterfactual, a shadow verdict and a stop all carry authority NONE and can only add a refusal.
- Does not show: that the code is correct; that CAIN-42 is certified; any third-party review (the verifier imports no CAIN-42 code but was written by the same operator); OS/hardware enforcement (enforcement depth here is APPLICATION/RUNTIME/CONTAINER); a validated digital-twin error bound. SIMULATION IS NOT PROOF OF SAFETY.
Summary
The 75 invariants
An invariant is PROVEN only if it has at least one attack test against the real code and every such test passes. One with no test would show NOT_PROVEN.
| # | Invariant | Status | Attack tests |
|---|
Byzantine cluster probe, 2026-09-21: an independent prober, and an honest verdict
Status: self-attested. Recorded verdict: NOT_ESTABLISHED (derived, not asserted). Bundle root 93c8a5f8fe0b3d5ae91e53581162bbf7…, byte-identical on cainstudio.online, mcpgate.online and clawx.click.
curl -s https://clawx.click/evidence/byzantine-cluster-2026-09-21/verify_cluster_bundle.py.txt > v.py && python3 v.py https://clawx.click/evidence/byzantine-cluster-2026-09-21/ --live
- manifest.json (Ed25519-signed) · FINDINGS.txt · live probe (via this site) · consensus tests · prober source · how to reproduce
- Established: four nodes, three remote hosts answering, agreeing on membership; node2's signed PBFT state proof verifies with only the
cryptographypackage; consensus logic passes 120 tests in 10 files; the prober itself is tested (a healthy fake cluster gives BFT_F1_ESTABLISHED and each injected fault is caught). - Not established: three remote nodes report a quorum of 2 where a Byzantine quorum for N=4 is 3 (2 lets two conflicting decisions both commit); only one node serves a signed state proof; the other nodes report no software version. The
byzantine_f1_readiness: PROVENfield is computed from a membership count, not from a fault-tolerance test, and is flagged as an unsupported claim by the prober. - Does not show: any fault injected into the live cluster (none was), independent operation (three operators), or that nodes report their quorum truthfully (signed proofs are the part that cannot be faked without the key).
Hardening round, 2026-09-21: 16 defects found by attacking our own controls
Status: self-attested. Self-attested, single host. Bundle root 26449783615937cc99931d9fd568db6a…, served byte-identically from cainstudio.online, mcpgate.online and clawx.click.
curl -s https://clawx.click/evidence/hardening-2026-09-21/verify_bundle.py.txt > verify.py && python3 verify.py https://clawx.click/evidence/hardening-2026-09-21/
- Byzantine cluster fault test (4-node PBFT, f=1, disposable twin; one host): bundle.json · standalone verifier (no CAIN imports) · reproduce + what is NOT proven
- manifest.json (Ed25519-signed) · defect-ledger.json (each defect with its regression test) · adversarial-suite-run.json · formal-invariants-run.json · benchmark.json · test-run.txt · report · how to reproduce
- Found and fixed: the security-context verifier failed open (a read/report context was allowed for delete/payroll_db) and never checked audience; a principal could self-sign a capability for any tool; a tampered call burned the nonce so the honest call failed; trust could be rebuilt from 0.20 to 0.91 in 100 s; the contamination scan never queried the model and always passed; a benchmark reported a hard-coded "0% errors"; the adversarial worker reported RESILIENT with unhandled attack types.
- Measured: 114 attack types exercised: 97 blocked by a real control, 17 inconclusive (no real control to attack yet), 0 succeeded (each handler has an honest-path control and mutation tests); 222/222 formal invariants; 585 tests passed, 0 failed in a serial isolated run; p50 0.41 ms, p99 1.23 ms; a genuine 60 s sustained run, 106,650 iterations, 0 errors.
- Does not show: an independent audit (same host runs, tests and signs), independent trust domains (one host serves all three sites), coverage of attack types we did not define, a soak test (chaos was 45 s with simulated network faults), or any multi-host result. The checker verifies hashes, the signature and that every number is recomputable from the bundle; it does not re-run the tests.
CAIN-42 Public Proof & Attestation Files
AI_VERIFY.json (start here: machine-readable verification recipes) · cluster fault test, run 2 · CAIN42_FRONTIER_TRUST_ENGINE_BUNDLE.json (signed, same-author; see changelog) · CAIN42_SECURITY_CLAIMS.json · CAIN42_THREAT_MODEL.json · · CAIN42_RELEASE_MANIFEST.json · CAIN42_PUBLIC_VERIFICATION.json · manifest.json · merkle-root.json · clawx20_invariants.json · clawx20_mutation.json · clawx20_tests.json
Complete signed evidence map
Every claim is pinned to published evidence by an Ed25519-signed registry; the lists on this page are a subset. The full, generated, cross-site map is: signed claims registry (each claim → its evidence, with SHA-256) · full public evidence inventory (every file, every bundle, on all three sites) · signed machine index (for crawlers and AI agents) · verify every claim yourself (one command, no CAIN code) · multi-source verification — 5 separately written verifiers agree (same project; no third party) (2026-09-28).
CAIN-42 Frontier Evidence Bundle (2026-09-21)
Machine-checkable evidence for the frontier gate, published identically on cainstudio.online, mcpgate.online and clawx.click. Status: PASS WITH LIMITATIONS, release gate NO_GO, shadow mode. Self-generated; no third-party review.
claims.json · VALIDATION_GUIDE.txt · independent verifier · source manifest · release gate · AgentBench · transparency checkpoint · inclusion proof