Mechanism
The infrastructure embodiments are not a new subsystem. They are the disclosure that every application domain instantiates the same platform primitives, affect, integrity, forecasting, confidence, capability, biological identity, skill gating, inference governance, training governance, and discovery, differing only in domain-specific parameterization, policy configuration, and governance bounds. An autonomous vehicle's confidence governor and a therapeutic agent's confidence governor are the same subsystem with different threshold configurations. A defense system's integrity engine and a social platform's integrity engine are the same subsystem tracking deviation against different declared norms. A surgical robot's capability envelope and a trading system's capability envelope are the same subsystem computing structural executability against different substrate conditions.
The architectural consequence is that deployment to a new application domain does not require development of new subsystems. It requires only the configuration of domain-specific policies, thresholds, and governance profiles for the existing primitives. The platform is substrate-agnostic: the same affect modulation, confidence gating, integrity tracking, biological identity, and governance machinery operates whether the substrate is a vehicle, a weapon system, a companion agent, a therapeutic tool, a robot, an educational platform, a secure facility, a trading desk, a content creation engine, or a social network.
The Parameterization Step
The disclosure represents the cross-domain instantiation as a parameterization engine. Platform primitives feed into the parameterization engine, which outputs to domain-specific instantiation targets. Each path from the parameterization engine to a domain target represents the application of domain-specific thresholds, policies, and governance bounds to the common primitives, producing domain-appropriate behavior from a single architectural substrate. The figure for the autonomous-vehicle, defense, companion, and therapeutic targets makes the pattern explicit: one set of primitives, one configuration step, distinct domain behaviors.
Parameterization is what distinguishes domains, not the underlying machinery. The confidence governor in the defense domain computes confidence from target identification, rules-of-engagement compliance, collateral damage assessment, and chain-of-command authorization. The same governor in the autonomous-vehicle domain computes confidence from perception, prediction, planning, and localization. The same governor in the therapeutic domain computes confidence from patient state assessment, therapeutic trajectory, intervention appropriateness, and crisis detection. The structured inputs change with the domain; the governing subsystem does not.
Domains With Physical and Irreversible Consequence
Several disclosed domains share the requirement that motor or actuation execution has physical, potentially irreversible consequences. In the autonomous-vehicle embodiment, the capability envelope is recomputed continuously from sensor, actuator, environmental, and energy conditions, and a sensor degraded by rain spray produces a narrower envelope that reduces authorized speed and maneuver repertoire through the capability-to-confidence pathway. In the embodied-robotics embodiment, the capability envelope computes reach, force, payload, energy, and surface capability, and a robot that could safely grasp a heavy object earlier may no longer be able to do so after battery depletion has reduced available motor current.
In these domains, speculative plans are structurally separated from committed action. The forecasting engine produces speculative trajectory or engagement branches in a containment layer, and a branch is not promoted to motor execution until it passes the full governance pipeline. A trajectory that would produce a predicted integrity deviation, such as a lane change creating an unsafe gap, is pruned before promotion. Safety-critical actions in the robotic domain require quorum-based validation analogous to the defense domain's engagement authorization, and hazard-prevention overrides such as emergency stops take precedence over all other governance mechanisms, producing immediate, unconditional motor suspension.
Quorum Authorization and Revocable Permission
In the defense embodiment, engagement actions require quorum-based authorization in which multiple independent governance channels must independently confirm before the action is committed: the confidence governor, the integrity engine, and the chain-of-command authorization channel. For lethal engagement the quorum is maximally strict, all channels must independently authorize, and any single channel veto produces unconditional prohibition. The channels do not share evaluation state, which prevents a confident but integrity-compromised system from biasing the integrity evaluation through shared state.
Authorization in these domains is a revocable permission, not a one-time gate. The confidence governor operates continuously during engagement, re-evaluating at each computational cycle from updated sensor data, environmental changes, and target behavior changes. If confidence drops below a re-evaluation threshold during execution, the governor can revoke authorization mid-execution and return the system to the observation state. Authorization obtained at one moment does not persist if the conditions that supported it change.
Human-Facing and Continuity Domains
Other disclosed domains share the requirement of persistent, evolving interaction with a human across sessions and devices. The companion AI embodiment maintains relational memory and affective continuity, governs progressive relationship depth through a narrative unlock engine built on the skill gating engine, recognizes and adapts to user attachment patterns, and pauses interaction when uncertain about the user's emotional state rather than guessing. The therapeutic embodiment operates as a tool used by clinicians or as a guided self-help system, not as an independent medical provider, tracking therapeutic relationship integrity, pausing before irreversible clinical interventions at a clinical authorization threshold set higher than the standard interaction threshold, and deferring to the supervising clinician on uncertain assessments.
Across these domains, the biological identity architecture provides cross-session and cross-device continuity without storing raw biometric or health data, validating biological hashes against the user's established trust-slope. A user who moves from a smartphone to a desktop to a tablet presents different sensor modalities at each device, but trust-slope continuity is constructed from overlapping behavioral signals such as typing cadence, language patterns, interaction timing, and session structure, so the agent maintains the full relational or therapeutic context across the device boundary rather than treating it as a new relationship.
Lineage and Accountability Across Domains
Every domain records its governed decisions in the lineage field. In the vehicle domain, each confidence-governed driving decision is recorded with the confidence computation that triggered it, producing a deterministic record of every threshold transition. In the defense domain, the confidence computation at each escalation threshold is deterministically recorded, producing a complete accountability chain from sensor data through confidence evaluation through escalation decision. In the financial domain, every trading decision, risk assessment, position change, and policy evaluation is recorded as a cryptographically sealed governance event, providing the regulatory accountability that financial regulators require.
The lineage field is the same primitive in each case. It stores the complete history of proposed mutations, admissibility determinations, and cognitive domain field updates such that the agent's behavioral trajectory is deterministically reconstructible from the lineage record alone. This single mechanism supplies post-action accountability for engagement decisions, an audit trail for clinical escalations, and a tamper-evident record of trading actions, without a per-domain accountability subsystem.
Regulatory Conformity Embodiment
The disclosure includes a regulatory embodiment mapping platform subsystems to the requirements of the European Union Artificial Intelligence Act for high-risk AI systems. The five-axis diagnostic framework, evaluating deviation likelihood, integrity alignment, confidence readiness, capability sufficiency, and affective stability, with its early warning system, provides the lifecycle risk management of Article 9. The training governance architecture, with depth-selective routing and provenance tracking, provides the data governance of Article 10. The lineage field provides the technical documentation of Article 11 and the transparency of Article 13 through deterministic behavioral reconstruction and a tamper-evident record of every state transition.
Human oversight under Article 14 is provided by the confidence governor's policy-defined thresholds below which the agent cannot commit state changes without human authorization, the non-executing cognitive mode that suspends committed execution while continuing speculative reasoning, and biological identity verification that authenticates oversight actions through trust-slope validation rather than transferable credentials. Accuracy, robustness, and cybersecurity under Article 15 are provided by the cross-domain coherence engine, the integrity field, and trust-slope validation. The quality management system of Article 17 is provided by the self-diagnosis subsystem and its compliance scoring. The regulatory embodiment is not a new mechanism either: it is the same primitives, mapped to obligations.
Distinction From Per-Domain Engineering
Conventional autonomous-systems engineering builds each domain as a separate stack: a separate decision authorization mechanism for vehicles, a separate escalation controller for defense, a separate relational engine for companions, a separate clinical safety layer for therapeutic tools. Each stack carries its own accountability, its own oversight surface, and its own safety governance, developed and validated in isolation. Cross-domain reuse is limited because the governing subsystems are domain-specific rather than parameterized.
The disclosed mechanism departs by identifying one set of primitives that governs all of these domains and by treating the domain as a configuration of policies, thresholds, and governance bounds over those primitives. The confidence governor, integrity engine, capability envelope, forecasting engine, affective state field, biological identity module, skill gating engine, inference governance, training governance, and discovery traversal are each a single subsystem reused across domains. This substrate-agnostic uniformity is the structural property: a new domain is reached by parameterization, not by building new subsystems, and the same lineage, oversight, and accountability machinery carries across every domain unchanged.
Disclosure Scope
The cross-domain application embodiments, comprising the instantiation of a single set of platform primitives, affect, integrity, forecasting, confidence, capability, biological identity, skill gating, inference governance, training governance, and discovery, across application domains through domain-specific parameterization of policies, thresholds, and governance bounds, together with the quorum-based and revocable-permission authorization in physical-consequence domains, the trust-slope continuity that carries relational and clinical context across sessions and devices without stored raw biometric or health data, the lineage field that supplies deterministic accountability in every domain, and the mapping of these subsystems to high-risk AI regulatory obligations, are disclosed in United States Patent Application 19/647,395 in the application domains chapter. This article describes that disclosed mechanism. The scope extends to application domains not separately enumerated, provided the domain is reached by parameterizing the disclosed primitives rather than by introducing a new governing subsystem, so that the same confidence, integrity, capability, identity, and lineage machinery governs the new domain under its own policy configuration.