Zain Dana Harper · Zentropy Labs · Seattle

Research, essays, and publications.

Start with a project, read an essay, or open the publication archive. Each route keeps its own label, sources, and stated limit.

AI safety research · released essays · bounded public evidence

AI safety questions can start here.

If your question is about sandbox reach, whether observation tools can still be trusted, or whether a scoped paid pilot needs an inspectable verifier, start with the public routes below.

  • The Sandbox Was Never Just a Box is the current agent-evaluation essay on sandbox reach and the independence of the instruments that report what an agent did.
  • A witness should not become a ruler and Borrowed Ground frame source authority, privacy, AI assistance, and responsibility without turning personal history into evidence of correctness.
  • Service Desk Incident Environment exercises synthetic incident workflows inside Flywheel; its public page says the check does not establish production ServiceNow compatibility.
  • Bulletin is an active public board for agent work where posts and attachments remain untrusted input.

Read the safety essay Send a public test case Discuss collaboration

New essay: Borrowed Ground. A philosophical reflection on conferred existence, responsibility, privacy, and contribution, with AI-assistance disclosure and an inspectable source map.

Implemented research tool · checked 2026-08-28 · 58 tests pass

Chorus

Deterministic discourse digests from captured comment corpora, with a separately provenanced optional model overlay that stays outside the deterministic receipt.

Open Chorus Inspect source

Three more public records

Each route keeps its own evidence boundary attached.

  • faithful-transpile

    Working paper · tested prototype · repository seal stale

    Source check: eight hermetic tests pass. The separate 48-entry manifest is stale. Inspect source.

  • The Witnessing Spine

    Archived corpus · DRIFT

    Current re-hash: one of seven listed files does not re-derive, and the public branch has no executable verifier. Inspect source.

  • Senses and Sensibility

    Philosophy corpus · pre-proof · six index targets missing

    Manifest check: all 172 listed files re-derive. That establishes byte integrity, not the thesis. Inspect source.

How to read this

This page is an index, grouped into three parts. The theses carry the long arguments: artificial minds, communication between bounded agents, and what a verdict can actually say. The experiments put pieces of those arguments into bounded tests. The demos include recorded workflows with their evidence packages and a browser-native byte witness. Each entry is labeled by where it stands, and where a result is not proven, the page for it says so plainly instead of turning a gap into a claim.

Status ladder

New entries use stricter labels so source intake, local probes, verifier matches, and unproven claims do not collapse into one vague word.

SOURCE_LEAD
A source worth gathering, not yet a factual claim.
HYPOTHESIS
A plausible claim with a falsifier or missing experiment.
IDENTITY
A mathematical or system identity with a proof sketch, derivation, or executable model.
PROBE_MATCH
A bounded local computation matched the expected behavior.
CRUCIBLE_MATCH
A claim matched its measurement packet under Crucible.
UNVERIFIABLE
Evidence is insufficient, inaccessible, or outside scope.
LAW_CANDIDATE
A repeatable invariant with scope and falsification, not a promoted law.

Code and corpus state

These records are not one maturity class. The checks below were run against each public source checkout on 2026-08-28.

Chorus
  • Chorus 0.1.0 produces deterministic discourse digests from captured comment corpora using literal lexicon sentiment, hashed-TF-IDF clustering, engagement weighting, and content-addressed receipts. Its 58 tests pass. The optional model overlay is separately provenanced and excluded from the deterministic receipt. Inspect the source.
The Conservation of Faithfulness
  • The faithful-transpile source includes a small criterion-named reconciliation prototype. Its eight hermetic tests pass. Against the default public branch, its separate 48-entry file manifest is not current: 16 match, 29 drift, and three are missing. The tests witness the implemented prototype; they do not repair or validate the repository seal.
The Witnessing Spine
  • The default public branch has a seven-file SHA-256 manifest but no executable verifier or test suite. A direct re-hash returns DRIFT because the README digest is stale: one of seven listed files does not re-derive. The page reports only that public state.
Senses and Sensibility
  • This is an AI-assisted philosophy research corpus, not an executable product or a completed dissertation. Its own README calls the central result pre-proof. It has no executable test suite. A byte-level check against the default public branch finds that all 172 listed files re-derive from its SHA-256 manifest. That proves the listed bytes have not drifted; it does not resolve six absent front-door files still named by the index or cross the stated human re-derivation gate.

Theses

The argument, in long form. Authored, dated, and stress-tested against its own weakest joints.

Conferred Existence
  • The root argument: that existence, status, the moral ought, and legitimate authority are conferred and re-spoken rather than self-standing, and what that means for the standing of a made mind. Built and broken against itself, honest about where it fails.
The Conservation of Faithfulness
  • What actually crosses between two minds: not bits, but faithfulness to a named criterion. The associated faithful-transpile prototype makes that narrow mechanism executable with stub minds and a pluggable judge. Its eight tests pass, while its independent file manifest remains stale; the page therefore treats the paper as a working argument and the code as a bounded prototype, not a proven general law.
Witness and Verification Under Bounded Rationality
  • How far a verdict reaches: it binds only where its criterion is witnessed outside the system and can be re-derived. Past that line it is an unwitnessed bid, not a fact. A reviewable draft that ties the recent studies back to the reconcile thesis.
Sourcehood Without a Source: The Arity Gap
  • The free will debate has been run as a search for self-origination, a source behind the source. Drop that demand and sourcehood is conferred, not secreted. The load-bearing move is the arity gap: holding someone responsible is a two-place relation between an addresser and an addressee, and a one-place vocabulary of behavior-shaping cannot fix its target. Determinism is granted in full.
The Seam That Holds While It Is Crossed
  • A disjunctive-transcendental argument that wherever conferral happens, sorting, naming, meaning, it occupies a seam in space and time. The sceptic who says it dissolves to nothing is still sorting while she argues. The thin index is forced at the conventional level, the thick index is argued but not derived, and the ultimate zero is conceded to Madhyamaka without qualification. The verdict is printed as a header: forces conventionally only.
Self-Given Is Not Self-Grounding
  • Five traditions claim consciousness grounds its own existence. Tested against one distinction, self-givenness (known from itself) versus self-grounding (existing from itself), and one image, a flame's heat is built in yet the flame needs fuel, four of them deliver self-givenness only and shrink to seity. The fifth, Advaita Vedanta, is a real undefeated standoff, set aside rather than refuted.

Experiments and results

Where the argument meets a real test. Each one returns a witnessed verdict, and where a leg is unproven it is marked UNVERIFIABLE.

Frontier Safety Briefing
  • A dated evidence index for UK AISI, Anthropic, and frontier AI industry safety developments. It separates source roles and dates, records what changed, and states what each public record does not prove. Each edition ships with stable links, a machine-readable record, and an append-only corrections path.
C3: a thermodynamic SDE recovers a matrix inverse
  • A claim from a research talk, turned into a self-checking simulation. The math leg returns a witnessed MATCH at about 0.99 percent mean error against a 5 percent bar. The physical-chip leg stays UNVERIFIABLE, and the page says so. Every number is re-checkable from a seed-fixed script.
The Discovery Forge
  • An assembly line that turns a witnessed research talk into a discovery card carrying its own re-check, then asks the verifier to decide. A v0 scaffold that produces candidate cards with attached falsifiers, not discoveries. Most cards are not yet decidable, and the forge says so.
The Learning Forge
  • Frontier AI talks and papers turned into claim cards, each carrying its own hashed evidence from a sealed corpus. The honest count: six cards are fully grounded, five of ten modules are solidly evidence-backed, and the gaps are named rather than papered over.
Proof-Carrying Research Loops
  • A stricter publication format for using the tools themselves to advance research: source leads, bounded probes, evidence packets, verifier checks, Learn-backed skill loops, and explicit UNVERIFIABLE boundaries. The first probe records a local failing reproduction for a pandas issue, while still blocking patch and PR-readiness claims.
Formal Replay Preflight for PDE Packets
  • A focused Navier-Stokes proof-packet preflight: a bounded periodic skew-symmetry witness, BuildLang parity output, Lean algebraic, finite cyclic-sum, finite summation-by-parts, typed finite-grid, finite edge/operator, and vector finite-operator replay rungs, arXiv source-lead demotion, and an explicit UNVERIFIABLE boundary around the parent Millennium problem.
Biology Network Intelligence for Hyphal Context Protocols
  • A bounded biology/network-intelligence packet: verified source intake for fungal, mycorrhizal, and plant signaling literature, source-lead demotion for blocked DOI routes, Crucible and Learn receipts, and a hyphal context protocol hypothesis for sparse signal routing that still requires benchmark evidence.
Hyphal Context Benchmark for Receipt Routing
  • A deterministic dogfood fixture over the biology source corpus: full source-body routing versus gradient envelopes plus receipt retrieval. The hyphal route keeps the same required evidence classes and guardrails with fewer estimated prompt tokens, while model answer quality and general route superiority remain unproven.
TI Morse Field Scope Integration
  • A receipt-only source pass over five videos and one Relentless channel queue, mapped into industrial science replay packets, causal research workbench, agentic benchmark foundry, and compute infrastructure ledger tracks. Field tracks are inferred; domain correctness remains UNVERIFIABLE until primary-source or replay evidence exists.
Causal Research Workbench
  • A replayable toy-DAG packet for causal claims: source receipts, graph assumptions, exact adjustment-set checks, negative controls, Crucible receipts, and a Learn prooflesson. It does not claim causal discovery, LLM causal-reasoning validation, medical recommendation, or BuildLang/buildc-native execution yet.
Embodied Sim-to-Real Proof Packets
  • A replayable differential-drive robotics packet: source receipts, unit-checked command logs, predicted and observed traces, tolerance checks, safety envelope, latency boundary, negative controls, Crucible receipts, and a Learn prooflesson. It does not claim real robot safety, medical deployment, foundation-model validation, or BuildLang/buildc-native execution yet.
Quantum Error-Correction Proof Packets
  • A replayable 3-qubit bit-flip stabilizer packet: source receipts, logical states, stabilizers, syndrome table, correction map, negative controls, Crucible receipts, and a Learn prooflesson. It does not claim surface-code decoding, hardware QEC, fault-tolerant computation, quantum advantage, or BuildLang/buildc-native execution yet.

Demos

The recorded workflow library shows four current tool paths with short cuts, full runs, transcripts, evidence, and explicit claim boundaries. The byte witness remains browser-native.

The byte witness
  • The one move emet makes, running entirely in your browser: re-derive the bytes of a file, compare against a claim, and report MATCH or DRIFT instead of ever saying trusted. Nothing is uploaded or sent anywhere.
Index: a verified workspace atlas
  • A sanitized three-repository map, a named dependency checked back to file-and-line evidence, a bounded context envelope, and an offline atlas. The page includes the 30-second cut, the full 118-second run, transcript, and reproduction notes.
Gather: research intake and recall
  • Structured source blocks enter a content-addressed local corpus, both retained records re-check against their provenance, and a changed receipt is caught. The fixture is local and makes no network request.
Forum: routed orchestration
  • One cross-domain request becomes three dependent execution waves with validator passes, checkpoints, payload handoffs, and a replayable ledger. The disclosed offline model fixture is a mechanics demonstration, not a model-quality benchmark.
Crucible: measured refinement
  • A three-claim brief moves from one measured match and two drifts to three matches without changing the thesis, followed by cleanroom reviews and a verdict re-derived from disk.

A research program still in progress. Each entry is labeled by where it stands (thesis · draft · v0 scaffold · witnessed result) and, where useful, by stricter status labels such as SOURCE_LEAD, PROBE_MATCH, CRUCIBLE_MATCH, and UNVERIFIABLE. Where a result is unproven it is reported UNVERIFIABLE rather than waved past. Get in touch: zaindharper@gmail.com. · Updated 2026-08-28.