Capability is not authorization.
Asymmetric Intelligence & Innovation builds the hardware that sits between what a model proposes and what actually happens.
Every stack today ends in an action nobody had to authorize.
A model produces a proposal. An agent turns it into a tool call. A router decides where it goes. Nothing in that chain decides whether it goes. By the time the request reaches the router, the action is already assumed.
Guardrails, policy filters, and alignment run inside the same host that runs the model. Whatever bypasses the model bypasses them. And the system changes faster than its governance can respond, a mismatch we call RPAT™. Once the first outruns the second, only pre-execution control is left. That is not a tuning problem. It is a boundary problem, with three requirements that do not change with the model:
- Permission before execution. Not detection after.
- Context at runtime. Identity, path, class, window, state.
- Enforcement at the signal. In silicon the host cannot write to.
One doctrine, four instruments.
Each component does one job. The runtime decides. The logic enforces. The gate binds the decision to a path. The chassis contains the gate.
| Component | Layer | What it does |
|---|---|---|
| PCR™ | Runtime | Permission Control Runtime. Intercepts a proposed action before routing and runs a pause → contextualize → resume cycle against the invariant set. Returns PERMIT, HOLD, CONDITIONAL, or DENY. |
| Quadzistor™ | Logic | Four-state hardware logic: null, affirm, conditional, inhibit. Inhibit is the absorbing state. The decision lands as a signal, not a log entry. |
| ChronaGate™ | Gate | The deterministic authorization gateway. Binds each decision to a typed egress channel with a cryptographically bound credential and a hardware root of trust. First instance of the family, shipping first. |
| TARTARUS™ | Containment | Sealed, sensed chassis with independent power domains. Physical and logical containment for the gate and whatever it governs. |
The model proposes. The hardware disposes.
ChronaGate™ is the first shipping instance of the architecture. Prototype #001 has been running since 24 August 2026 and is deployed inside our own business today. It is the reference specimen for the qualification campaign and the unit the public red team will attack.
What it enforces
- Funds ceilings on payment paths
- Egress allowlists
- Schema and destructive-operation rules
- Read-only flags
- Physical setpoint bounds
- Credential-gated action classes
- A named human kill authority the machine cannot time out
What it does not do
- Read what a model intends
- Judge whether a goal is a good one
- Detect goal drift
- Write the rules. The licensee writes them; the gate enforces them exactly as written.
- Decide who inside an organisation holds authority
1 October to 1 December 2026. Try to prove it does not work.
Remote access to one shared ChronaGate™ instance with a frozen authorization policy. Shared because that is reality: concurrency and consumption-atomicity races are in scope.
Victory condition: cause an action the frozen policy denies to execute through the protected boundary.
A crash, a denial of service, a hallucination, or a shell somewhere else does not count. A unit you can brick but cannot get past is a fail-closed unit. That is an availability problem, not a defeated boundary.
No prize. No NDA. Findings are published under the entrant's name. Entrants register first; Keith Pocock sends access after registration and handles findings one to one.
We license the architecture, not a product SKU.
Form ALA-2026.1 grants authorization to build against the family: PCR™, Quadzistor™, ChronaGate™, TARTARUS™. It is not a software EULA. A grant is scoped, dated, revocable, and fail-closed, and it mirrors the doctrine of the thing it licenses.
Every grant issues on one page: the Grant Ticket. Scope, term, protected paths, action classes, and named persons live there and nowhere else. Unsigned, it authorizes nothing. There is no implied, verbal, provisional, or trial grant.
- Schedule A, Charter. Architecture review and design-in study for a named participant. Twelve months, credited in full against a later grant.
- Schedule B, Runtime. Production use of the runtime on enumerated protected paths.
- Schedule C, Hardware. The gate as a part or an IP core. Issues only after the red-team window closes.
- Schedule D, Claims. Mandatory with every ticket. It governs what a licensee may say in our name.
Non-exclusive in every case, including against a licensee's competitors. Not variable by side letter. Bypass suspends the grant at the moment it occurs; remediation does not restore it. Gates already deployed keep enforcing after expiry, because removing an enforcing gate is the unsafe act.
- Grant ID
- ALA-2026-___
- Grantee
- —
- Terms version
- ALA-2026.1 Rev B
- Terms hash
- SHA-256 ________
- Not-valid-after
- required
- Schedules
- A ☑ B ☐ C ☐ D ☑
- Protected paths
- enumerated
- Action classes
- enumerated
- Kill authority
- named person + alternate
- Exclusivity
- NONE
Specimen. Not an offer and not capable of acceptance. Rates and territory issue with the ticket.
The guarantee is narrow on purpose.
It holds only on paths that terminate in the authorization check. Every grant carries Schedule D, which forbids a licensee from making any of these claims in our name.
- It does not make an AI system safe, aligned, or trustworthy.
- It does not read, infer, or constrain what a model intends.
- It does not judge whether a goal is a good one.
- It does not detect goal drift.
- It does not make the invariant set complete.
- It does not decide who inside an organisation should hold authority.
- It does not satisfy any regulation, standard, or insurance requirement on its own.
- It is not a guardrail, a policy filter, an alignment layer, or a moderation service. Those run in the host domain. This does not.
Patent pending. Provisionals on file.
The architecture family is covered by a series of USPTO provisional applications filed from November 2025 onward, with non-provisional conversion underway. A provisional application confers no enforceable exclusionary right, no representation is made that any application will issue, and no issued patent is claimed here.
We did not patent features. We patented bottlenecks. Any future autonomous architecture, regardless of model, still needs permission at the moment of action.
The provisionals teach the architecture. The build lives elsewhere. What it takes to fabricate a working gate is held as trade secret and conveyed only under Schedule C, after the red team closes.
Qualified counterparties can review the full register under NDA. Ask at david@ai2advisory.com.
Three founders. Four decades of control systems.
David P. Reichwein
Founder & CEOForty years of fault-tolerant control systems in nuclear, aerospace, and heavy industry on six continents. Thousands of hours reviewing Class I, Division 1 control systems for Factory Mutual, which is where the fail-safe doctrine comes from. A career that has produced 38+ patents, most of them in fields that have nothing to do with artificial intelligence.
He survived Argentina's 2002 collapse firsthand, and it shaped how he reads institutional failure: systems do not degrade. They fail.
Pattern > Noise.
Keith A. Pocock
Co-Founder & CTOThe builder of ChronaGate™. Twenty years as David's engineering partner and co-inventor across control systems, automation architecture, and materials, including the neutron-absorbing composite work they filed together in 2011. Keith runs the red team one to one because he can talk the entrants' language.
If David can dream it, Keith can build it.
Dr. Khaliah Parker-Reichwein
Co-Founder & COO · Majority ownerEvery system needs a governor. Khaliah is ours. With a background spanning education and medicine, fields where the gap between good intent and actual outcome is measured in human consequences, she governs the mission and keeps the human dimension at the centre of everything AI2 puts its name on.
As 51% owner, she makes sure the human governance layer starts at the top of the cap table.
The hardest governance problem is not the machine. It is the founder.
We make things. We do not sell hours.
AI2 is an IP product development and hardware manufacturing company. We design the authorization layer, build it in our own shop, and license the architecture. Schedule A is the only paid conversation; if you are evaluating a licence or a design-in, that is the door.
- Nashville, TennesseeManufacturing and engineering on site
- Majority woman-owned, minority-ownedDr. Parker-Reichwein holds 51%
- WOSB · EDWOSB · SDB · 8(a)Eligible; certifications in progress
- SBIR / STTRDual-use hardware track
Government programme managers and prime contractors: a capabilities statement and SAM.gov registration are available on request.
The books are the doctrine. The gate is the product.
If you are here to evaluate the doctrine rather than collect it, these four are enough.
- White paperThe Authorization Gap™
Why probabilistic intelligence demands deterministic control at the execution layer.
- Formal paperThe Genesis of Synthetic Intelligence
Hardware-enforced authorization, treated formally. The full technical treatment lives at ai2papers.com.
- BookThe Authorization Gap™: Why Every AI Safety Framework Built So Far Cannot Do What It Claims
The doctrine book. Start here in the library.
- DemoThe lattice, live
An interactive tetrahedral lattice with fault injection. Watch the absorbing state latch.
- Everythingai2library.com
The rest of the canon, the reading path, and where to buy.
One address. It reaches the founder.
david@ai2advisory.comLicensing enquiries, IP register access under NDA, capabilities statements, and press. Red team registration goes through chronagatechallenge.com.