The problem: planning at machine speed, committing at human speed

A staff conducting course-of-action (COA) analysis must enumerate what the adversary can do, test friendly responses against each, and recommend a plan. Automating that exploration is attractive: a machine can branch through far more enemy options, friendly counters, and second-order consequences than a planning cell working a map under time pressure. But automation introduces a failure that doctrine has no tolerance for. A planning aid that cannot keep its hypotheticals separate from ground truth may report a projected enemy disposition as observed fact, recommend an action predicated on a future that exists only inside its own model, or worst of all, take an action on that basis. DoDD 3000.09 exists precisely to keep human judgment over the use of force; a system whose internal state can blur the line between "what I imagined" and "what occurred" cannot satisfy it.

The requirement, then, is not faster planning alone. It is planning where breadth of exploration and discipline of commitment are enforced by the architecture itself, not by operator vigilance or a downstream review checklist that an exhausted watch floor may skip.

How the Forecasting Engine meets it

The Forecasting Engine disclosed in United States Patent Application 19/647,395 is structured so that speculation can be wide and commitment can be deliberate, and so that the two cannot be conflated. The relevant primitives map cleanly onto tactical planning.

Planning graphs as the COA exploration space. Each candidate line of action is a branch in a speculative planning graph. The engine simulates the hypothetical mutations a branch represents without writing any change to verified state. An adversary course of action, a friendly response, and the projected consequences of each are all branches, and they are generated and evaluated entirely inside the speculative domain.

Immutable speculative markers as the ground-truth firewall. Every element of a planning graph, every projected enemy position, every assumed effect of a friendly action, carries a speculative marker applied at construction. That marker cannot be removed, modified, or overridden by any operation inside the planning-graph domain. Only the promotion interface, on successful governance validation, strips it and re-tags content as verified before it reaches execution memory. This is the architectural answer to the COA-vs-reality problem: a projected enemy disposition is structurally incapable of being read by execution processes as an observed one.

Read isolation and lineage isolation. The containment layer enforces that execution processes querying current state receive verified values from execution memory, never projected values from an active branch. Speculative branches also produce no committed lineage entries until promoted, so the auditable record of what the system actually relied upon never silently absorbs a hypothesis. For a defense program these two invariants are what make after-action reconstruction trustworthy.

The delusion boundary as a named, monitored failure mode. The disclosure specifies containment collapse, the pathological state in which speculative content is treated as verified reality, as a formal condition with defined failure modes (marker corruption, breached read isolation, a promotion gate admitting unvalidated content). It pairs this with detection mechanisms, including periodic containment audits, boundary-crossing monitors, lineage consistency checks, and behavioral coherence monitors that flag an agent acting on outcomes that have not occurred, and a restoration protocol that suspends execution authority, quarantines the affected graphs, and reconstructs verified state. For a safety case under MIL-STD-882E this is directly usable: the hazard "system acts on an imagined battlefield state" has a named boundary, instrumented detection, and a defined response.

Branch classification as a recommendation discipline. The engine classifies each slope-validated branch as eligible (a realizable plan, ranked by composite score), introspective (retained for self-examination rather than action), delegable (better assigned to a subordinate or specialized element), or pruned (failed validation, policy, or resource thresholds, briefly retained with its rejection annotation). This maps onto staff practice: recommended COAs, discarded options the staff should still be able to explain, tasks to push down echelon, and rejected lines with a recorded reason.

Confidence-gated promotion as the commit control. No branch becomes action by accumulating a high score. It must pass the promotion interface under governance validation, and promotion is confidence-gated. This is the structural seat for human-on-the-loop authority: the gate is where an authorizing decision attaches, consistent with DoDD 3000.09's requirement for appropriate human judgment over force.

Personality and affective modulation as a planning posture. The same disclosure makes the engine's speculative breadth and temporal horizon deterministic functions of the personality field (including a temporal planning horizon trait and a delegation preference trait) and of the affective-state field. In tactical terms this is a configurable planning posture: a deliberate-planning configuration projects deeper with broader branching; a posture under elevated temporal pressure compresses horizons toward near-term, higher-confidence projections, exactly the behavior a staff adopts when the decision clock is short.

Executive-graph arbitration for the multi-echelon picture. Planning graphs from multiple agents feed through intersection detection and conflict resolution to produce a macro executive graph. Across a distributed force this is the mechanism for reconciling separately-developed plans into a deconflicted common picture, which is the integration problem CJADC2 and allied collaboration under AUKUS Pillar II are organized around.

Embodiments and deployment options

The design is not a single instance. It supports a range of grounded implementations:

  • Decision-support cell, human-on-the-loop. The engine populates a ranked set of eligible COAs with their introspective and pruned alternatives surfaced for explanation; the promotion gate is bound to a human authorizing decision. Nothing executes; the system recommends and records.
  • Wargaming and rehearsal. Adversary courses of action are instantiated as branches and run against friendly responses purely in the speculative domain, with the containment boundary guaranteeing that a rehearsal projection never leaks into the operational picture.
  • Red-team / blue-team adversarial modeling. Introspective branches let the system examine options it is disposed to avoid, supporting deliberate exploration of unattractive-but-possible enemy lines.
  • Distributed, multi-echelon planning. Subordinate elements develop planning graphs locally; executive-graph aggregation reconciles them, with delegable branches transferred down echelon through the disclosed delegation pathway.
  • Edge and degraded operation. A suppressed temporal-horizon posture compresses projection depth for low-latency, near-term planning at the tactical edge; a deliberate posture is used at higher echelon with more time.
  • Safety-instrumented configuration. Containment audits, boundary-crossing monitors, and the restoration protocol are enabled as the technical evidence base for a system-safety argument and for the auditability allied legal reviews expect under AP I Article 36 and NATO AJP-3.

A skilled implementer can build any of these from the disclosed primitives: represent COAs as planning-graph branches, apply speculative markers at construction, enforce read and lineage isolation between the speculative and verified domains, classify branches, gate promotion on governance validation and confidence, and bind that gate to the human authority the operational and legal frame requires.

Why this is the right foundation

Other planning automations bolt a separation-of-concerns policy on top of a model and trust operators and reviewers to maintain it. The Forecasting Engine makes the separation structural: speculation cannot be promoted to action except through a validated, confidence-gated, human-attachable interface, and the failure of that separation is itself a named, monitored, recoverable condition. That is the property defense doctrine actually demands, exploration that is exhaustive and commitment that is deliberate, expressed as architecture rather than procedure.

Disclosure Scope

This article describes a domain application of technology disclosed in United States Patent Application 19/647,395. The market problem, doctrinal and legal context, and deployment scenarios are illustrative application framing. The underlying mechanisms, planning graphs, immutable speculative markers, the containment boundary and delusion boundary, branch classification (eligible, introspective, delegable, pruned), personality- and affect-modulated branch expansion, executive-graph arbitration, and confidence-gated promotion, are disclosed in that application. Forecasting in the disclosed system is speculative and structurally contained; it does not execute. No specific branch counts, projection depths, or performance benchmarks are claimed here beyond what that application discloses.