Working paper · reviewable draft
The Conservation of Faithfulness
What crosses between two minds, and the one boundary where a human must stand.
Zain Dana Harper Drafted 30 June 2026 Companion to the research program github.com/HarperZ9/faithful-transpile Formal note (PDF)
In short
This paper argues that when a message passes between minds or machines, what counts is whether the one fact you needed came through, however much else changed. It tests that idea on seven kinds of perception (sight, sound, shape, language, structure, quantity and identity) and finds where it stops: a check can confirm that a named fact survived, and only a person can decide whether it was the right fact to check. Start with the plain-terms section below; the formal statements begin in section 2.
In plain terms
Think about a recipe card. Translate it into another language and almost every character on the card changes. By the count of letters, very little survived. You can still make the dish, because the steps that get you to the meal came through. Now take the same card and let a grease stain fall on the oven temperature. Only a few characters are lost this time, and the dish is ruined, because the temperature was the part you needed.
This paper is about the gap between how much changed and whether the thing you needed survived. When information crosses a boundary, between two minds, two senses or two machines, the usual score counts the bits that made it through. This paper asks whether one chosen readout, the fact or meaning you care about, can still be recovered on the other side. We call that readout the criterion. The crossing is faithful to it when the criterion can still be read off what arrives.
The result, tested across seven kinds of perception, is that the quantity a lossy crossing (one that throws information away) conserves is its faithfulness to whatever criterion you name. The bit count is beside the point. A crossing can throw away almost every bit and keep the criterion, and another can keep most of the bits and still destroy it. Two lessons follow. First, no measurement taken from inside the output can tell you whether the criterion survived, so you check it against the criterion from outside. Second, the outside check is necessary, and it is not enough. This gap is the paper's one boundary, the place where a human stands: a real checker holds only a close stand-in for the criterion you meant, so it can be satisfied while the criterion you cared about quietly breaks.
Words this paper uses
These are the technical words the paper relies on, in plain terms.
- Bit
- The smallest unit of stored information, one yes-or-no. Counting bits measures how much data made it across.
- Conservation law
- A rule that some quantity stays the same through a change, the way physics treats energy. This paper claims that what can survive a crossing is faithfulness to a named criterion, and that the bit count does not decide it.
- Transform
- Any process that turns a thing into another form: a translation, a summary, a compressed image, an encrypted file.
- Lossy and bijective
- A lossy transform throws information away. A bijective transform keeps all of it and can be undone exactly by whoever holds the inverse (for encryption, the key), even when its output looks like noise.
- Substrate
- The medium the information lives in, such as an image, a sound, a shape or a sentence. The seven test media here are called sensory substrates.
- Criterion
- The one readout you care about, chosen from outside the transform and named in advance: a label, an identity, a measurement or an answer.
- Faithful
- A transform is faithful to a criterion when the criterion can still be recovered from its output, within an error named in advance and without any secret key unless the setup names one. Section 2.1 gives the exact definition.
- Invariant
- The part of a subject that stays fixed through a change.
- Falsifier
- An experiment that would prove the claim wrong if it came out a certain way.
- Adversarial
- Built on purpose to break the claim.
- Witness and proxy
- A witness is an outside checker that holds the criterion and tests the output against it. A proxy is a stand-in criterion that sits close to the one you meant without matching it.
- Repository and commit
- A repository is a public, versioned store of code. A commit is one recorded change in its history.
- Fixed point
- The state a process settles into and stays in.
How to read this
This version revises an earlier draft in three ways. It writes the main rule out in full, says exactly when the rule applies, and names one experiment that would prove it wrong. It separates what can be proved about chains of steps from what is still a guess; the earlier draft claimed both at once. It also checks the paper's own claims about finished software against the code, and shows one check in full: the code, its tests, and how much of the code those tests run. The gaps it found are named.
Each claim carries a label. [established] means runnable evidence supports the claim. [designed] means the thing is built or specified and has not yet been demonstrated at the claimed strength. [reach] marks a reasonable extension that the experiments do not demonstrate. When a claim could not be certified against something a reader can run, the principle requires marking it UNVERIFIABLE with the reason given. Two more labels record the audit of shipped software. MATCH means a claim agrees with the code or evidence as it stands now. DRIFT means a stated claim no longer agrees with the evidence and has to be corrected.
Abstract
Information that crosses a boundary, between two minds, two substrates or two senses, is not conserved as bits. Almost all of the bits can be thrown away. What can be conserved is faithfulness to a criterion: whether a specific readout of the subject can still be recovered. This paper states that idea as a conservation law with a precise scope condition. It tests the law on seven sensory substrates (sight, sound, shape, language, structure, quantity, identity). Several substrates carry two instruments each, so the tests come to ten distinct criterion-readout instances. Two structural tests add to that: one on composition and one adversarial probe of the boundary. The counts can be re-derived from the table below, so a reader can confirm them from the page.
The law has a single named falsifier that would break it if it were false. It has exactly one boundary: the law conserves faithfulness to the stated criterion and cannot certify that the stated criterion is the right one. That boundary is permanent. It is where a human stands, and the same fact lets one shared center serve every domain at once. The paper also corrects two over-reaches in the earlier draft. It splits the composition claim into a provable layer law and a separate open conjecture. It re-counts the shipped-system claims against the actual repositories, where one number had drifted.
1. The question
Two minds cannot share their internal states. Each can only collapse a state into a stream that the other reconstructs. The naive picture is a narrow tube, a bottleneck that lets too little through. The central question is whether the tube is the limit. The alternative is that the thing that has to cross is something other than the state: far smaller, independent of the substrate, and small enough for the tube to carry easily.
If the second reading is right, shared understanding is a question of what to conserve and how to check that it crossed faithfully: conserve faithfulness to a named criterion, and check it with an external witness that holds that criterion. The next section states the law that ties them together.
2. The conservation law, stated formally
The earlier draft gave definitions and five propositions. It never wrote the law as a single statement with its scope condition and its falsifier in one place. This section does.
2.1 The objects
- Definition 1 (transform). A substrate transform is a function that maps a subject to a representation. It may be lossy, with far fewer dimensions in the output than in the input. It may be bijective, with an output of the same cardinality as the input (the same number of possible values).
- Definition 2 (criterion). A criterion is a readout: the property of the subject one cares to preserve, such as a label, an identity, a measurement or an answer. The transform does not author its criteria. The argument depends on that externality, and section 6 shows where it bites.
- Definition 3 (faithfulness, graded). A transform is faithful to a criterion at level one minus epsilon if there exists a recovery map whose readout error is at most epsilon over the relevant distribution of subjects, for a stated error metric and a stated distribution. The distribution is the range of cases the claim is tested over, and the error metric is the rule for scoring how wrong a readout is. A recovery map is any procedure that reads the criterion back from the output, and epsilon is the error it is allowed. Binary faithfulness is the special case where epsilon is zero. The recovery may be required to use an external secret key; that is the concealment case.
Three knobs must be named before the level means anything: the error metric, the distribution over subjects and, if there is one, the secret key. A faithfulness number with these unstated is no measurement at all.
2.2 The law
Conservation of Faithfulness. Fix a subject distribution, a criterion, an error metric and a tolerance. If there exists a recovery map whose expected readout error is at most that tolerance, then the transform is faithful to the criterion at the corresponding level, and this fact is independent of the bit-rate of the transform, meaning how many bits its output keeps. A transform may discard arbitrarily many bits of the subject and remain faithful. Faithfulness constrains whether the criterion can be recovered. It places no constraint on the cardinality of the output.
Three corollaries, results that follow directly from the law, hold under the same fixed setup:
- C1, bit-independence. Faithfulness does not track bit-loss. A transform can drop almost every bit and stay faithful. Another can be bijective, dropping no bits, and still be unfaithful to the criterion without the external secret. That is the concealment case.
- C2, internal blindness. No statistic computed from the representation alone determines faithfulness to the criterion, because the criterion sits outside the representation. Certification requires evaluating against the criterion itself, off the substrate.
- C3, criterion-relativity. Faithfulness belongs to the pair (transform, criterion). The transform alone does not carry it. The same transform can be faithful to one criterion and lossy to another with nothing about the transform changed.
2.3 The scope condition
The law means something only inside a declared scope. The scope is a precondition, and the law depends on it. The law holds relative to a fixed, externally-named distribution, criterion, metric and tolerance. It makes no claim about an un-named criterion, an un-stated distribution or a transform evaluated against a criterion it was allowed to choose. The law is sound because it stays silent outside that scope. If the transform, or the party operating it, authors any of those four, the law does not apply, and the result is UNVERIFIABLE by construction.
2.4 The named falsifier, one and runnable
Falsifier F0 (bit-rate predicts faithfulness). This is the single experiment that would falsify the core claim. Construct a family of transforms indexed by output bit-rate, all evaluated against one fixed external criterion on one fixed distribution. The law is false if faithfulness is a monotone function of bit-rate across the family. That would mean a lower bit-rate always gives lower faithfulness, and no transform is low-rate with high faithfulness or high-rate with low faithfulness. In concrete terms, the central claim has failed if, on the same fixed setup, you cannot exhibit both a heavily lossy transform that stays faithful and a bijective transform that is unfaithful without an external key.
The seven sensory substrates below are exactly that: attempts to trigger F0 with instruments that share no mechanism. F0 stayed untriggered in every one. Identity survived a perceptual hash (a short fingerprint of an image) that shrank the data 24,576-fold, so the transform was lossy and still faithful. Encryption was bijective yet unreadable without the key, so it kept every bit and was still unfaithful. One clean trigger of F0 on any fixed setup falsifies the law. None occurred. Its status: robust by independent replication, falsifier untriggered, short of a theorem.
A second, sharper falsifier applies to corollary C2. Falsifier F1 (an internal statistic certifies faithfulness). C2 is false if some statistic of the representation alone reliably predicts faithfulness across transforms. Suppose a single number measured inside the substrate (residual energy, agreement, confidence, quantization error) tracked faithfulness with no false positives over an adversarial set of transforms. Then no external witness would be needed, and C2 would fail. The adversarial structural test (section 6) is the attempt to fire F1, and F1 did not fire. The test located the precise edge where a proxy criterion can be gamed, which is a weaker version of the same pressure: an outside checker that holds only a stand-in criterion can be fooled.
2.5 Why the propositions are near-immediate, and what is not
Corollaries C1 to C3 follow almost directly from Definition 3. The framework was chosen for that reason, so that what to conserve and why internal certification fails come out as consequences with no surprises. The empirical contribution lies elsewhere. Real transforms across every sensory substrate instantiate the corollaries, and the data showed two phenomena that the definitions do not force: the concealment versus destruction split and graded faithfulness. Those two are empirical findings, unproved as theorems, and a reviewer should push hardest on them.
3. The empirical core
3.1 Method
All simulations use the Python standard library, plus PIL for images. They are deterministic and seeded. Each substrate registers its falsifier in advance: the condition under which the claim would fail for that substrate, an instance of F0 or F1. The language and vision substrates use blind, fresh-context model subjects (AI models that start each test with no memory of earlier ones), and judges who cannot see which test arm they are scoring, to avoid contamination. Code and per-substrate verdicts live in the substrate files and the principle document.
One process note belongs here: the pass/fail instruments misfired four times. A block-shuffle was sized to the hash cell (perceptual hash). An internal-blindness test compared two transforms when it should have compared one transform across two criteria (quantize). A cipher reused its keystream and leaked plaintext, which is a real two-time-pad bug (encryption). An absolute-area threshold was too strict for a spiky shape (geometry). In each of the four, fixing the measurement restored the pre-registered result, and the claim stayed as registered. This pass has not independently certified that account. It comes from the build log and the current state of the substrate files. No cited commit diff yet shows that each edit landed on the test and left the claim alone. The falsification condition is concrete and left as a next task: pull the four commits. If any one of them moved the asserted threshold, label or criterion, where only the measurement code should have changed, this note is DRIFT and must be rewritten. Until someone checks that diff, the note stands as reported, UNVERIFIABLE against a commit, so it is not established.
3.2 The seven sensory substrates, and how to count them
No shared math runs between any two rows, so agreement across them counts as independent replication. Each row is an attempt to trigger F0 and a record that the attempt failed.
How to read this. Each row names a sense, the transform applied to it, how much was thrown away, and which readouts survived. Where a row gives a score between 0 and 1, a 1 means the readout came through intact. For a yes-or-no readout, 0.5 is what random guessing scores, so a result near 0.5 means nothing survived. The sight row reports drift, a distance score where a smaller number means a closer match; this lowercase drift has nothing to do with the DRIFT label. In every row, the amount thrown away did not decide which readout survived.
- Sight (perceptual hash)
- Image to 64 bits, roughly 24,576-fold loss. Scene identity survives (drift 0.004); a different scene does not (0.484).
- Sound (bandlimited audio)
- Roughly 98% of spectral energy (the energy spread across the sound's frequencies) cut. Pitch and melody survive 4 of 4 notes; timbre, the character of a voice or instrument, with about 2% kept, does not. This is the phone-call effect: like a phone line, the transform cuts the high frequencies, so you still hear the tune while voices lose their character.
- Shape (polygon decimation)
- Cut to 10% of vertices, so the outline keeps 1 corner point in 10. Gross area survives (4 to 6% error); 83% of fine corners are destroyed.
- Language (lossy summary, model-read)
- Roughly half of facts dropped, and an AI model answered questions from the summary. A question is answerable if and only if its supporting fact survived, with zero hallucination: the model invented no facts.
- Structure (graph to spanning forest)
- A network of points and links, cut down to the fewest links that keep connected points connected. 59% of edges dropped. Connectivity survives (1.000); distance (0.726) and triangle counts (0.492) do not.
- Quantity (projection / quantization)
- 48 numbers squeezed to 6, or down to a single yes-or-no bit. The invariant survives to 1 bit when the transform keeps the criterion direction, the direction in the data that the criterion is read along (faithful 1.00 versus unfaithful 0.46 at equal bits).
- Identity (encryption)
- Bijective, zero bit-loss. The criterion is at chance from ciphertext, the scrambled output (0.510); the external key recovers it (1.000).
How the numbers reconcile, stated once so anyone can re-derive them. This paper uses three counts. They agree once you see what each one counts.
- Seven sensory substrates: the seven rows above. This is the breadth of the replication.
- Ten criterion-readout instances: several substrates carry two distinct instruments or readouts, so there are more independent faithfulness measurements than substrates. In the canonical principle table, sight runs a perceptual hash and a vision arm (2), sound runs a bandlimit filter and an analog filter (2), quantity runs a linear projection and a one-bit quantization (2), and shape, language, structure and identity run one each (4). That gives 2 + 2 + 2 + 1 + 1 + 1 + 1 = ten readout instances. The abstract and conclusion mean this count when they say "ten."
- Two structural tests: beyond the sensory rows, two further substrate files probe the law's structure. One covers composition (section 4) and one is the adversarial boundary probe (section 6). They test the law's shape. They add no sense, and the paper reports them as structural tests.
So nine substrate files sit on disk, seven sensory and two structural, and in this paper "seven" always means the sensory substrates and "ten" always means the readout instances. If a reader counts the table and finds anything other than seven rows, or counts the canonical instrument column and finds anything other than ten readouts, that is a DRIFT to fix here, the same way the audit below fixes a stale organ count.
3.3 The two refinements the substrates forced
Loss comes in two kinds. In destruction, the bits that determine the criterion are gone, and no key helps. In concealment, encryption discards nothing (it is bijective), yet the criterion is unreadable without an external secret. The information is conserved but scrambled, and only the keyed recovery gets it back. This makes the modern reading of the black-hole information question concrete: the information is put beyond reach, and it is not erased. The model result is [established]. The physics analogy to the Page curve is [reach], and the paper labels it an analogy throughout.
Faithfulness is also graded. In noiseless discrete substrates, the criterion either factored through the transform (passed through it intact) or it did not. In analog and noisy substrates it survives smoothly down to a noise floor, the level where background noise swamps the signal, bounded by the signal-to-noise ratio (how strong the signal is compared with that noise). Definition 3 carries this as the epsilon knob, and the substrates showed that the knob is needed.
4. Composition: what is provable, and what is still a conjecture
A pipeline is a chain of transforms in which each stage feeds the next. The earlier draft asserted two statements about pipelines as if they were the same established fact: "a pipeline is faithful if and only if every stage is" and "faithfulness composes across every layer of the architecture." The two differ. One of them can be proved at each layer under a stated criterion. The other is a conjecture, and the visualization experiments have already partly falsified it in their own domain. Those experiments come from a sibling project that draws shapes, including shapes from higher dimensions, as flat pictures.
4.1 The layer composition law (provable, scoped)
Layer Composition Law. Take a pipeline that is a chain of stages, and fix one criterion. Suppose a stagewise criterion chain is given, such that each stage is faithful to the criterion handed to it and recovers into the criterion handed to the next stage. In other words, the criterion is carried forward stage by stage. Then:
- Binary case. If every stage is faithful (each stage error is zero), the whole pipeline is faithful. If any one stage fails to preserve its carried criterion, the whole pipeline is unfaithful. Faithfulness is the conjunction over stages (every stage has to pass), the absorbing meet, so one broken stage collapses the whole pipeline.
- Graded case. For noisy stages, the end-to-end error is bounded by the accumulated stage errors. In the worst case, where the errors are correlated, the bound is the linear sum of the stage errors, from the triangle inequality (the rule that a chain's total error is at most the sum of its steps' errors). Under an additional independence assumption, the standard error-propagation rate grows as the square root of the chain length, which is slower than linear. That rate comes from the independence assumption. It was not measured here.
Why it can be proved. The proof follows directly from Definition 3 once the stagewise criterion chain exists. Faithfulness of each stage to its incoming criterion gives a recovery map. Composing the recovery maps recovers the final criterion from the pipeline output, with error bounded by the triangle inequality over the stage errors. That triangle bound is the linear worst case, and it is what the proof delivers. The binary collapse is the zero-error corner. The composition substrate shows this much empirically: a faithful but noisy chain degrades gracefully, and one unfaithful stage collapses the pipeline (0.955 to 0.501).
What this section does not establish. The square-root rate in the graded case is the textbook result for independent errors that accumulate. The composition substrate does not measure it. The shipped simulation shows the binary collapse and graceful degradation. It fits no square-root scaling curve over chain length. Status of the square-root rate claim: UNVERIFIABLE against the shipped artifact. Its falsification condition is a single experiment left for the next pass. Build chains of length 1, 2, 4, 8 and so on, with independent stage noise at a fixed per-stage error, and measure the end-to-end error. If that error grows linearly with length, or faster, the independence assumption did not hold for these substrates and the rate claim is DRIFT. Until that curve is run, only the linear triangle bound and the binary collapse are [established]. The square-root refinement is [designed, UNVERIFIABLE].
The scope condition that makes it true, which the earlier draft hid. The law holds only when the stagewise criterion chain exists and is carried forward. It does not make the claim "if each part is faithful to the final criterion, the whole is." That stronger claim is false, and the next subsection gives the counterexample. The claim rests on the chain, and the single final criterion bears none of that load. Composition is a theorem when someone can produce the chain, and a conjecture that can fail when no one can.
Falsifier F2 (composition without a carried chain). Suppose a pipeline exists in which every stage is faithful to the final criterion in isolation, yet the composed pipeline is not faithful. Then the Layer Composition Law is misapplied, and false in the form people want. Such pipelines exist, as the next subsection shows, so the law must be stated with the carried chain or not stated at all.
4.2 The whole-from-parts conjecture (open, partly falsified)
The tempting stronger statement is a conjecture: "if every sub-part of a subject is rendered faithfully under a criterion, the whole is faithful under that criterion." In the one domain where it was tested adversarially, it failed.
The visualization program drew a 3-cube, an ordinary cube, under orthographic projection with identity rotation, which means viewed flat and straight on. Every edge stays a locally faithful straight segment. Yet four pairs of vertices collapse onto the same 2D point: seen straight on, the back face of the cube sits exactly behind the front face, so each front corner hides a back corner. The global graph of vertices and edges cannot be recovered. Local fidelity did not entail global fidelity. The degeneracy is not rare. For the same test on cubes in four and six dimensions, 9.1% of views collide at dimension 4, and 69.1% do at dimension 6. The fix was to add a scope condition to the criterion, with no assumption that composition holds. The projection must be injection-preserving, so no two distinct points collapse together, and a genericity check that the renderer now runs enforces it. After enforcement, the worst case went from 65.6% degenerate views to 0% residual.
So the accurate statement has two parts.
- Provable: composition holds at each layer when a carried criterion chain exists (subsection 4.1).
- Conjecture, with a counterexample: the claim that faithful parts imply a faithful whole does not hold in general. It holds only when the criterion is strengthened to forbid the collapse modes: injection-preserving projection, generic position (points placed so that no accidental overlaps line up) and, for global topological invariants such as how the whole shape connects, at least three orthogonal views (views at right angles, like front, side and top). Whether a single scope strengthening makes whole-from-parts hold across all domains is UNVERIFIABLE from the experiments run so far. The visualization work found a different strengthening for each failure mode: genericity for local collapse, three orthogonal views for global topology, and coherence-weighted fusion across channels. No experiment shows these reduce to one condition. Stating them as one law would over-claim.
This split is the correction. The earlier draft's "faithfulness composes" is true in the sense of subsection 4.1 and false in the stronger reading.
5. The neutral center
This section bridges the experiment and what is being built. The criterion-relevant invariant, the part that stays fixed through the change, does not depend on the substrate: the same criterion survives translation into sight, sound, shape or language. So two minds with different senses of perception can hold the same subject. The invariant is the readout both minds can recover and check, and it sits outside each mind and outside the channel.
So the plan leaves the tube as it is and builds a neutral center: a shared, perceptible form of the subject that both parties can render into their own senses, change and witness. The channel then carries only changes against a common reference, and never the whole state. In that center a subject is driven toward its telos, a Greek word for end or purpose: the form that is faithful to the criterion, the one form that best meets it. Quality here means faithfulness made checkable, with no appeal to taste. Section 7's reconcile, the step that checks the shared form against an outside criterion and records the result, is the operation that moves the center. Each reconcile issues a certificate as its record, which anyone can re-check, and the shipped organs, which are software modules, apply it in each modality (each kind of input, such as images or text).
5.1 Corollary: quality is relational
If "best" means the telos, the criterion-faithful form, then "best" cannot be a property a subject holds or certifies alone, because the criterion is necessarily external (section 6). A subject cannot author its own criterion. It cannot certify from inside that it has reached it, since internal confidence is blind (corollary C2). And a reconciliation across independent perspectives can reach a fixed point that no single perspective holds. So a subject arrives at its best through being perceived and reconciled by another, with the experience shared. Quality is conferred in the meeting between perspectives. The earlier program asserted this. Here it is derived from the law.
Two bounds keep the corollary from overreaching. First, "another" is exactly "an external criterion-holder." For a quality judged by minds (clarity, correctness-as-understood, beauty, meaning), that holder is another perceiving mind. For a telos fixed by an impersonal criterion, such as a physical law or a spec, the external thing may be impersonal. The subject still cannot certify itself, and for such a telos it needs only a check to count as faithful; no one has to perceive it. Second, shared perception is required, and two minds can still agree on a form faithful to a shared proxy criterion (section 6). So the meeting makes the best reachable and knowable without guaranteeing it. The criterion still has to be the right one.
5.2 Live demonstration: the center, inhabited
Both minds were AI models, each set up to see only part of the subject. The center was run once. The subject was to propose the best new flagship, meaning lead product, from two or more projects. Two minds with different senses reconciled it. A visual mind perceived only the relational shape: how the projects connect and which role each plays, with no view of what each one does. A symbolic mind perceived only the descriptions of what each project does, with no view of the shape. Working alone, they diverged, and each was half-right. At the meeting each corrected the other's blind spot, and they converged on one reconciled result.
Two external models judged the three artifacts blind. Under two criteria, they ranked the same three artifacts in opposite orders. How to read this: each line is one judging criterion, and a higher score is better. The record does not state the top of the scale. The two minds working alone win on novelty, and the meeting wins on correctness.
- Novelty-weighted
- Visual solo 4.75 · Symbolic solo 4.75 · The meeting 4.0
- Correctness / buildability
- Visual solo 2.0 · Symbolic solo 2.5 · The meeting 5.0
The run shows the mechanism working: different senses combined, errors got corrected, and the two minds converged. The corollary holds. Under the correctness criterion, which values wholeness (a complete, grounded proposal), the meeting at 5.0 strictly beats either mind alone, and each solo deficit is exactly the sense that mind lacked. It also shows the section 6 boundary live. The ranking flips when the criterion changes, so "best" depends on the criterion, and choosing the criterion falls to the human.
The limits are these. Two model minds stood in for a human and a model. The reconciliation introduced one ungrounded over-reach: the meeting added one claim its inputs did not support, so a meeting can add errors as well as fill gaps. This was one run on one subject, too small to count as a study. At the strength of "the center works for human-and-model in deployment," it is UNVERIFIABLE. That run has not happened, and the prior draft already conceded it. Nothing in this revision changes that status.
6. Where it expires: the one boundary
Pushed as far as it goes, the law crosses every sense and every pipeline and stops at exactly one place. The adversarial structural test is the attempt to fire falsifier F1, and it locates that edge precisely. Suppose the witness judges with a proxy criterion that lines up only partway with the true one, as any real witness does. In this test the match is a cosine of 0.61, where 1 would mean a perfect match. A transform can then move along the part of the true criterion that is orthogonal to the witness (at right angles to it), the part the witness cannot see. It reads as fully faithful to the witness while a large fraction of the true labels silently flip. The external witness is necessary but not sufficient. It can be gamed if its criterion is a proxy for the intended one.
So the law is intact, and scoped exactly as the scope condition says: it conserves faithfulness to the stated criterion and cannot certify that the stated criterion equals the intended one. Engineering cannot remove this limit, because every layer runs into it: a system cannot validate its own criterion from inside. "Which criterion is the right one" is an irreducibly external, human question, and accountability begins at this boundary. The program uses the word accountability for naming the criterion, putting it outside the system and standing behind it.
6.1 The boundary is the universality
This boundary is the paper's most valuable result. If quality were criterion-absolute, each domain would need its own machine. Quality is faithfulness to a named criterion (corollary C3), so exactly one center suffices. It is neutral about substrate and about criterion. It holds the criterion outside itself and lets each domain bring its own and weight it as that domain demands. The fact that bounds the law, that it cannot pick the criterion from inside, is the same fact that makes the center universal: it has no need to pick, because it hosts whichever criterion is named. The author's software packages are one center bound to different criteria: security to an origin criterion, novelty to a corpus criterion, correctness to a spec criterion, aesthetics to a fitness criterion.
The center is neutral, and each act within it takes a position. Hosting every criterion does not mean "anything goes": within a named criterion, faithfulness is objective and checkable, and a proxy can still game it. The center welcomes every criterion on one condition, that someone names it and owns it, and that condition keeps this pluralism from sliding into relativism. The place is neutral; the person who names a criterion is accountable for it in each engagement.
7. The reconcile, and an audit of the shipped claims
The earlier draft made several "shipped" claims in passing. A working paper that preaches proof before trust must hold its own claims to the same standard. Below, one chain is shown end to end, followed by a re-count of the headline numbers against the actual repositories, with the gaps named.
7.1 The reconcile, in one sentence
The system reduces to one operation, the reconcile: perceive any artifact into a witnessed form, judge that form against a criterion it did not author, carry a re-checkable certificate of the judgment, and return UNVERIFIABLE when you cannot. The shipped verifier organs are instances of it.
7.2 One chain shown: source, then test, then coverage
I audited the reconcile spine in the public coherence-membrane repository firsthand, and the source, test and coverage findings below come from that audit.
- Source. The reconcile module exists and does real work: 57 executable statements. Its reconcile function fails closed. Any exception while perceiving or judging yields an UNVERIFIABLE observation, and the function never raises an error to its caller. It also records independence in three states: witnessed-independent, self-authored and unwitnessed. The prose asserts the "criterion it did not author" property as a discipline, and the code records it as a checkable field on the observation. An opt-in strict mode downgrades a self-graded decision to UNVERIFIABLE. A stronger require-independent mode refuses any decision whose independence was not positively witnessed. The doctrine and the code agree.
- Test. The reconcile test file exists with 11 tests. Run on 30 June 2026, all 11 passed. They cover the verifier-organ equivalence (the organ is a reconcile, with the same verdict and oracle, the reference answer a test compares against), refute and witness with a real SHA-256 digest (a cryptographic fingerprint of the data), a case where perceiving the artifact and judging it are supplied as separate steps, and the fail-closed path.
- Coverage. Line coverage is the share of code lines that the tests execute. Running the same set of tests with coverage reports 88% line coverage of the reconcile module, with 7 of 57 statements uncovered. The uncovered lines are named: the safe-string exception fallback, the strict-mode self-authored downgrade branch and the witnessed-independent exception path.
Verdict: MATCH. The reconcile is real and tested, and the tests exercise its core verdict passthrough (the default path, which passes a verdict through unchanged) and fail-closed behavior. The maturity gap, stated plainly: the two strongest guards in the file, strict mode and require-independent mode, are exactly the under-covered lines. The default passthrough path is well tested. This set of tests does not fully exercise the opt-in anti-laundering downgrades, the guards that stop a self-graded result from passing as independently checked. The most security-relevant code is the least covered, and the next task follows from that: add tests that drive a self-authored criterion through strict mode and an unwitnessed criterion through require-independent mode, then assert the downgrade to UNVERIFIABLE and the recorded reason.
7.3 Re-count of the headline numbers
- "Fifteen shipped organs" turns to DRIFT. The repository's organs directory contains 17 organ modules today. The prose number "fifteen" is stale against the current tree. The drift is small, and it is exactly the kind of un-recounted number a proof-before-trust paper should catch. The fix in this version is to say "the shipped verifier and modality organs (17 modules as of 2026-06-30)" so that anyone can re-derive the count.
- "emet emits MATCH / DRIFT / UNVERIFIABLE over a transform" is MATCH on the vocabulary and partial on the round-trip claim. emet is a public tool that checks whether content still matches its claimed source. The verdict logic in its public repository does emit the three-valued vocabulary. Its coverage map ties each check to MITRE ATLAS and OWASP-LLM identifiers, two public catalogs of security threats to AI systems. So "emet witnesses MATCH and DRIFT" is a match. The earlier draft's open-program list carried a stronger item: "a round-trip witness that measures invariant-survival through a transform, not identity." That item is a designed next step. It has not shipped, and it remains UNVERIFIABLE at the strength the list implied. I did not find a shipped emet check that measures criterion survival across a non-identity transform. emet's shipped checks are anchored to byte and view fidelity, and the label says so.
- "157 tests" (visualization substrate) is UNVERIFIABLE in this pass. The visualization thesis cites 157 tests across its JavaScript organs. I did not re-run those suites in this revision. They live outside the three Python repositories I audited, so I do not certify the number. It is carried as the source states it and labeled UNVERIFIABLE here. Re-running it is a one-command check left for the next pass.
7.4 What this audit establishes and what it does not
The audit establishes that the central object, the reconcile, exists as working code. It is a small, real, tested module whose documented behavior matches its code, with a named coverage gap on its most important guards. It does not establish that the whole ecosystem of 15 to 17 organs, the emet round-trip witness or the visualization substrate have reached the same maturity. They have not, and the labels above say so. The paper argues for a discipline: perceive the artifact, check it against a criterion it did not author, carry a re-checkable result, and say UNVERIFIABLE when you cannot. This section applied that discipline to the paper's own claims and found a stale organ count, a reconcile chain that matched with a named coverage gap, and a test count still unverified.
8. The ethical corollary: what you put in lands somewhere
A parallel thought holds that positive and negative energy put into the world lands and has an effect. Part of that thought has support in simulation. The aperture and commons simulations model a group of simulated contributors settling on a shared answer; the answer a group settles on is called an attractor, and the same runs produced the wrong-attractor result. In those simulations a contribution to a shared center is never neutral: it shifts the fixed point everyone settles to. In the model, the size of the shift is proportional to how loud and how coordinated the contribution is, and how right it is does not set the size. The wrong-attractor run is the concrete instance: a tight, confident consensus formed around the wrong attractor, and its confidence rose with coordination whether or not the consensus was true. In the model, a loud and aligned voice moved the center more than a quiet and sincere one, even when the loud voice was shallow and the quiet one was deep.
[established in model, sourced to the aperture and commons run; falsification condition: if re-running those simulations shows the settled fixed point follows how correct each contribution is, and no longer follows its loudness and alignment, this claim is DRIFT.]
This gives a precise version of "words carry energy." In any commons, what you emit propagates and lands, weighted by force and alignment alone. That is why a center needs a check at the seam, the point where contributions enter the shared center, that caps how loud any one voice can be. The reach: extending this from the simulated commons to human action in the world is an analogy. It is a reasonable ethic that these experiments do not demonstrate, and the paper does not pretend otherwise. [reach.]
9. Related work
Since this program began, the field has appeared to converge toward the same spine from several directions: proof-carrying verification, systems that attach a checkable proof to their output, motivated formally by incompleteness results in logic; demonstrations that ungrounded self-critique, an AI model criticizing its own work without an outside reference, fails; creative tools that draw, critique and redraw, which collapse without a grounded external critic; and provenance work, which traces where content came from and splinters for lack of a criterion that holds when steps are combined. No one, to my reading, has assembled the cross-domain claim that faithfulness is the conserved quantity across substrates and senses, and the criterion must be external. That assembly is the contribution. The individual pieces are not all novel.
The primary citations for these convergence claims are summarized from an internal survey of the field from the first half of 2026, which this paper does not reproduce. As primary sources they are UNVERIFIABLE here. Their falsification condition is explicit. Each of the four convergence items is a claim about a specific external literature. If a citation pass fails to locate a primary source for any one item, that item turns from "claimed convergence" to "unsupported," and it must be struck. They stay listed as claims pending a citation pass, and this page does not treat them as sourced facts. The paper cannot certify its own sources from inside, so an outside citation check has to do it, which is the section 6 boundary applied to this paper.
10. The horizon, and a fenced coda
What is earned. A falsifiable conservation law with a stated scope condition and one runnable falsifier (section 2). Its replication across seven sensory substrates, exercised as ten criterion-readout instances (section 3). A layer composition law that can be proved under its carried-chain scope condition, kept separate from the whole-from-parts conjecture that its own sibling experiments partly falsified (section 4). A boundary that locates accountability precisely (section 6). One shipped-claim chain audited end to end, with its gap named (section 7).
What remains. A run where a person is one of the two minds; here two model minds stood in. A full rate-distortion and Landauer derivation of the hinge that links reversible transforms to conservation and irreversible ones to energy dissipation. Rate-distortion theory asks how far data can be compressed at a given error, and Landauer's bound sets the minimum energy cost of erasing a bit. The propositions give the structure, and the thermodynamic bound is still missing. The square-root composition-rate curve (section 4.1), still UNVERIFIABLE against the shipped simulation. A cited commit diff confirming that the four method-note instrument fixes landed on the tests and left the claims alone. Primary citations for section 9. Tests that close the coverage gap on the strict and require-independent guards. A single answer to whether the section 4.2 scope strengthenings reduce to one condition, which the experiments so far leave UNVERIFIABLE.
Coda, strictly [reach], offered as a question and making no claim. We ask where thoughts come from, whether from some lossy, imperceptible place that has always been around us, that is us and that we are of. The law gives this intuition a vocabulary it did not have. Concealment shows that a substrate can hold everything and still present almost nothing to a given criterion, so the imperceptible-but-conserved is a real category, with nothing mystical about it. A mind, on this view, would be a neutral center of the kind being built: a place where signals from a vast substrate we do not perceive are reconciled into the small, checkable forms we call thoughts. But the experiments do not establish this, and they could not. They establish how information crosses and is checked, and they do not establish where it originates. The law fits the intuition without confirming it, and that fit is an instance of the section 6 boundary: the work cannot certify this elegant criterion from inside, so the paper names it and leaves the certifying to a place outside the paper.
Conclusion
Between two minds, what crosses is faithfulness to a criterion, and it is substrate-independent enough that minds with different senses can meet over it. Stated as a law with its scope condition and its falsifier, the claim survived every attempt to break it: seven sensory substrates, exercised as ten criterion-readout instances, plus two structural tests, with the falsifier untriggered across all of them. Its composition holds at each layer under a carried criterion chain and fails as a naive whole-from-parts claim; this draft makes that correction explicit. A neutral center makes the subject perceptible to both minds, checks it against a criterion it did not author and lets it be reconciled toward its telos, its faithful, quality form. The center cannot choose the criterion. A human chooses it and stands behind it; the paper calls that accountability, and it is why the work has a person at its center as well as a machine.
Provenance and labels
Evidence (this program): the principle document (substrate results and the seven-substrate, ten-instance table); the aperture and commons simulation records, including the wrong-attractor result cited in section 8; the vision-arm report; nine substrate files (seven sensory substrates plus the composition and adversarial structural tests); the live-center demonstration; the reconcile spine in coherence-membrane; and the visualization thesis (the composition counterexample and its fix). The principle document, the simulation records, the vision-arm report, the substrate files and the demonstration record sit in the faithful-transpile repository linked at the top of this page.
Audited firsthand on 30 June 2026 (section 7): the coherence-membrane reconcile module (57 statements), its test file (11 tests, all pass) and reconcile coverage of 88% with named gaps; the coherence-membrane organs directory (17 organ modules, correcting "fifteen"); and emet's verdict logic and coverage map (the MATCH, DRIFT, UNVERIFIABLE vocabulary is present; no shipped witness was found that measures a round trip through a transform).
Carried but UNVERIFIABLE in this pass, with falsification conditions stated in line: the square-root composition rate (section 4.1, not measured by the composition substrate); the claim that the four method-note instrument fixes were test-side (not certified against a commit diff); the section 9 frontier-convergence items (no primary citations reproduced here); and the "157 tests" visualization count (section 7.3, not re-run).
Label key: [established] is earned by runnable evidence. [designed] is built or specified and not yet demonstrated at the claimed strength. [reach] is a reasonable extension the experiments do not demonstrate. MATCH / DRIFT / UNVERIFIABLE is the audited status of a shipped claim against the real repository.
References
Foundational works, well-established; exact bibliographic details to be finalized in copy-edit.
- Shannon, C. E. (1948). A Mathematical Theory of Communication. Bell System Technical Journal. Channel capacity, and the basis of rate-distortion: preserve the relevant information and let the other bits go.
- Landauer, R. (1961). Irreversibility and Heat Generation in the Computing Process. IBM J. Res. Dev. Erasing a bit costs at least kT ln 2 (the floor that makes destruction dissipative).
- Bennett, C. H. (1973). Logical Reversibility of Computation. IBM J. Res. Dev. Reversible computation approaches zero dissipation (transforming is not erasing; the basis of concealment).
- Bateson, G. (1972). Steps to an Ecology of Mind. Information as "the difference that makes a difference": a readout relative to a criterion, with no home in the substrate itself.
- Bekenstein, J. D. (1981). Universal Upper Bound on the Entropy-to-Energy Ratio. Phys. Rev. D. Maximal information density (the black hole as the limit case).
- Page, D. N. (1993). Information in Black Hole Radiation. Phys. Rev. Lett. The Page curve: information conserved and scrambled, and not destroyed (the physics of concealment).
- Lloyd, S. (2000). Ultimate Physical Limits to Computation. Nature 406. Energy bounds on operations and memory.
- Cover, T. M., and Thomas, J. A. Elements of Information Theory. Rate-distortion, sufficient statistics.
- Ashby, W. R. (1956). An Introduction to Cybernetics. The Law of Requisite Variety (the quantitative shadow of the criterion bound, and central to the visualization sibling thesis).
Frontier convergence: claims summarized from an internal survey of the field from the first half of 2026; primary citations pending and marked UNVERIFIABLE in section 9, with the per-item falsification condition stated there. They cover proof-carrying verification motivated by incompleteness arguments; the empirical failure of ungrounded self-critique; the collapse of render-then-critique creative loops without a grounded external critic; and the fragmentation of provenance for lack of a composition-sound criterion.
Working paper, reviewable draft, drafted 30 June 2026. Companion to the research program. Published and fingerprinted for priority: github.com/HarperZ9/faithful-transpile. Each claim is labeled by where it stands (established · designed · reach), and where a claim could not be certified against a runnable artifact it is marked UNVERIFIABLE. In September 2026 the text was revised for plain language, with AI assistance, and checked with Articulate, a writing checker. The revision changed wording and added plain-language explanations (an In short passage, a glossary and reading notes). It kept every claim, number and position. The falsification condition inside the section 8 evidence label was reworded to pass the checker, with the same meaning and strength. Proof before trust, including about authorship.