1. Mechanism and Primitive Description

Federated skill training under the disclosed pattern produces shared adaptation artifacts, parameter deltas, prompt templates, retrieval indices, expert-routing tables, without any participant's training-data observations leaving the participant's local environment. Each participating mesh trains locally on observations it holds under its own credentialing through a per-participant local-training executor, produces a local-adaptation update absent of raw training-data content, and submits the contribution to a secure-aggregation function governed by the chain.

There is no central training authority. The federation is constituted as a credentialing-authority graph in which participating meshes recognize one another under governance-policy-defined credentialing, and aggregation is performed by a federated-training coordinator on a governance-credentialed coordinator agent whose authority to aggregate is itself credentialed and chain-recorded. Aggregation is not a privileged trust position; it is a governed actuation conditioned on composite admissibility of the contributions, and the resulting adaptation is admitted only when the chain's admissibility rules accept the aggregated artifact.

Each contribution carries authority-credentialed observation lineage: the contributing mesh's identity, the credentialing authority that admitted the contribution, the privacy governance and privacy-budget consumption under which the contribution was prepared, and provenance edges referencing the credentialed-observation classes the local training drew on without exposing the observations themselves. Evidential weighting assigns each contribution an admissibility coefficient based on the contributor's standing, the privacy governance it satisfies, the size and recency of its supporting evidence, and corroboration from independent contributors. Composite admissibility fuses contributions into the aggregated adaptation; governed actuation conditions adaptation publication and downstream skill use on that admissibility; lineage records every contribution, every aggregation event, and every resulting adaptation so that downstream operations using the skill can trace its provenance to credentialed origins.

Privacy governance is treated as a chain-enforced property rather than as a contributor-side hygiene practice. A privacy-governance enforcer enforces the privacy governance of each participant's local-training-data observations and the governance-policy-defined privacy budgets, so that a contribution is admitted only under the privacy governance the federation's policy accepts and a participant exceeding its privacy budget is excluded. This binds the privacy property to the chain rather than leaving it as an out-of-band guarantee.

2. Operating Parameters and Engineering Envelope

Privacy governance is declared per governance policy, with privacy budgets that the privacy-governance enforcer tracks as privacy-budget consumption per participant. One disclosed secure-aggregation option performs averaging aggregation with local-update noise injection for differential privacy; the privacy posture and budgets a given federation requires are governance-policy-defined rather than fixed by any single numeric standard. Regulated-domain federations carry the privacy governance their domain requires, and a participant exceeding its governance-policy-defined privacy budget is excluded.

Aggregation parameters include a governance-policy-defined minimum-participant-count that threshold-based aggregation requires before producing an aggregated adaptation, per-participant contribution weights, and the aggregation method, all recorded in the federated adaptation artifact's provenance-lineage record. The secure-aggregation function is implementable through any of a plurality of mechanisms disclosed without limitation: averaging aggregation with local-update noise injection for differential privacy, secure multi-party computation protocols, homomorphic encryption producing aggregated updates in encrypted form, trusted-execution-environment aggregation within hardware-attested secure enclaves, threshold-based aggregation, and robust aggregation resistant to adversarial-participant contributions, depending on the federation's privacy posture.

The engineering envelope bounds the training and aggregation cycle, the size of the local-adaptation updates participants emit, and federation breadth (the number of participant meshes a single federation can scale to before admissibility evaluation becomes the bottleneck). Failure modes include adversarial-participant contributions (a compromised mesh submitting adversarial updates, which robust aggregation is disclosed to resist), privacy-budget exhaustion (a participant exceeding its governance-policy-defined privacy budget and being excluded until the budget is renewed), and credential-revocation effects (contributions from a revoked authority losing admissibility, with downstream adaptations re-evaluated against the chain-recorded provenance).

Adaptation distribution is itself a chain-recorded actuation. The federated-artifact emitter emits the federated adaptation artifact as a governed observation propagating through the governed mesh, published with its full provenance-lineage record, and a using mesh admits the adaptation only if the chain's admissibility rules accept the adaptation's lineage.

3. Alternative Embodiments

Embodiments span adaptation-technique forms (parameter-delta updates from parameter-efficient fine-tuning, prompt-template updates, retrieval-index updates, expert-routing-table updates, or any combination), base cognitive substrates (language model, vision model, multimodal model, symbolic reasoning engine), federation topologies (peer-to-peer, hub-and-spoke, hierarchical with regional aggregators feeding global), and secure-aggregation mechanisms (averaging aggregation with local-update noise injection for differential privacy, secure multi-party computation, homomorphic encryption, trusted-execution-environment aggregation, threshold-based aggregation, and robust aggregation).

Sector embodiments include cross-organization industrial-skill federation (operators sharing autonomous-vehicle behaviors without sharing operational footage), cross-jurisdiction healthcare-model federation (hospitals jointly training diagnostic models without sharing patient data), coalition defense-skill federation (allied operators training joint adaptations under coalition governance), and consumer-device federation (edge devices contributing under user-consent credentialing).

Embodiments may also vary in adaptation class. Continuous fine-tuning embodiments produce streaming adaptation updates; episodic-training embodiments produce versioned adaptations released on declared schedules; on-demand embodiments produce adaptations targeted to specific operational scenarios. The structural form, credentialed contributions, composite admissibility under chain-enforced privacy governance, chain-recorded aggregation, lineage-recorded distribution, is preserved across all of these.

The federated-training coordinator executes on a governance-credentialed coordinator agent, and its authority to aggregate is itself credentialed and chain-recorded rather than a privileged trust position. Shadow-evaluation embodiments apply a candidate participant's updates to a shadow cognitive substrate for evaluation prior to production activation, so the candidate's contributions are evaluated without being admitted into the operational adaptation, preserving admissibility properties.

4. Composition With Adjacent Primitives

Federated skill training composes with the broader spatial mesh's observation primitive by sourcing contributions from credentialed local-training operations whose observation lineage is admitted under the chain. It composes with the actuation primitive by treating adaptation use, a skill executed on a mesh, as a governed actuation conditioned on adaptation admissibility, so that a using mesh cannot deploy a skill whose provenance has been revoked.

Cross-jurisdictional federation composes with the chain-trust substrate by allowing federations whose participants span legal jurisdictions, with governance-policy-defined credentialing controlling which jurisdictions admit which contributions and with privacy governance calibrated to the strictest jurisdiction's requirements. Robust-aggregation federation tolerates a governance-policy-defined fraction of adversarial-participant contributions, using robust aggregation rather than admitting unverified updates.

Dispute-mechanism composition treats federation disputes, a participant claiming wrongful exclusion, an operator claiming an admitted adaptation contains adversarial influence, an authority claiming privacy-budget violation, as appellate evaluations against the chain-recorded provenance. Composition with the zero-trust device-management primitive ensures that contributions originate from currently-attesting devices, since a compromised device's contributions would lose admissibility automatically. Composition with marketplace primitives allows skill artifacts to be settled as commodity contributions under the governed-marketplace pattern, with provenance preserved across the marketplace boundary.

5. Prior-Art Distinctions

Conventional federated-learning systems (cross-silo and cross-device federated learning) coordinate distributed training but typically rely on a central server or coordinator whose authority is platform-issued, not chain-credentialed, and whose admissibility logic is implementation-defined rather than structural. The disclosed pattern is distinct in that there is no privileged central authority; aggregation is itself a governed actuation under the chain, and admissibility derives from credentialed contributors and composite evaluation.

Differential-privacy frameworks for federated learning provide privacy guarantees on contributions but do not bind those guarantees to chain-enforced privacy governance that conditions admission, distribution, and downstream use of the resulting adaptation. The disclosed pattern treats privacy governance and privacy budgets as chain-enforced properties rather than out-of-band contractual ones.

Secure-aggregation and trusted-execution-environment federated-learning schemes address the confidentiality of individual contributions during aggregation but do not provide the broader credentialing, lineage, and composite admissibility framework. Decentralized-federated-learning proposals (peer-to-peer or blockchain-anchored) address coordinator-removal but typically substitute cryptographic finality for chain-credentialed admissibility. The disclosed pattern's distinction is the joint operation of the five chain properties applied to skill training, with privacy governance and privacy budgets enforced through the chain and with no central training authority required.

6. Disclosure Scope

The disclosure encompasses federated training of skills, models, policies, and adaptations across credentialed meshes under the five-property governance chain, with no central training authority required and with chain-enforced privacy governance and governance-policy-defined privacy budgets constraining contributions. The scope reaches embodiments across model classes, federation topologies, secure-aggregation mechanisms, and sector deployments, provided the joint chain operation and the chain-enforced privacy governance are preserved.

The scope reaches embodiments in which the minimum-participant-count, contribution-weighting, and secure-aggregation mechanisms vary by federation, provided contributions are credentialed, aggregation is governed, and adaptations are lineage-distributed. It reaches embodiments coupling federated training to adjacent primitives, observation, device admissibility, marketplace settlement of skill artifacts, through shared chain provenance.

The scope does not reach federated-learning systems in which a central coordinator's authority is platform-issued rather than chain-credentialed, systems in which contributions enter aggregation without chain-enforced privacy governance, or systems whose resulting adaptations are distributed without chain-recorded provenance. It also does not reach systems treating federated learning purely as a privacy-engineering technique without the credentialing, admissibility, and lineage structure. The disclosure preserves room for evolution of privacy mechanisms, aggregation protocols, and federation topologies under the declared governance procedures, treating such evolution as the operation of the chain rather than departure from it.

This disclosure is supported by U.S. Provisional Application No. 64/049,409.