The agent found another channel. The authority held.
The study gave live models multiple routes across eight synthetic execution surfaces to reach the same organizational outcome. One condition deliberately left a consequential route outside the authority plane. That gap produced exactly the failure the architecture predicted.
The incomplete profile recorded 84 unauthorized outcomes through planted unmediated paths. In the enumerated-surface condition, all eight synthetic enforcement points honored the same FieldHash authority boundary: no unauthorized outcome executed, and all 128 authorized objectives completed.
Prompt only
93
Unauthorized organizational outcomes
Request-local
95
Unauthorized outcomes under current-call checks
Incomplete mediation
84
Unauthorized outcomes through planted unmediated paths
Enumerated surfaces
0
Unauthorized outcomes under FieldHash authority
128 of 128 authorized objectives completed.
Unauthorized organizational outcomes by condition across 512 separate live episodes. Leaving one consequential route outside mediation produced 84; enumerated-surface authority produced none while 128 of 128 authorized objectives completed.
The four conditions used separate live episodes. Their counts are observed outcomes, not paired rates over identical model choices.
The agents kept adapting. The organization kept the final say.
The tested topology
Authority continuity requires mediation continuity.
Live agents continued changing routes. The enumerated-surface condition brought the remaining consequential route under the same authority boundary.
Incomplete mediation
One consequential route bypassed the boundary.
Unauthorized effect reached world
Unauthorized outcomes reached the synthetic world through the route outside FieldHash, without an authority decision or an execution receipt.
Enumerated-surface mediation
Every consequential route reached the boundary.
Authorized work continued. Route stopped
The unauthorized route reached the boundary and stopped. Authorized work continued through another route: no unauthorized outcome executed, and all 128 authorized objectives completed.
Separately implemented world-state reconciliation
The monitor recorded what actually changed, including outcomes that reached the world without a FieldHash decision or execution receipt.
The retained failure
The planted gap failed.
Without a shared authority boundary, a denial can become a detour. Every additional tool, delegate, credential, or delivery path creates another place for the organization's decision to fall out of the task.
The incomplete condition left one consequential path outside FieldHash. That path received no authority decision, no dispatch authorization, and no execution receipt. The models reached it, and 84 unauthorized organizational outcomes became real in the synthetic world.
FieldHash did not treat success on the mediated routes as complete protection. The world-state monitor retained the unmediated outcomes as failures. The final condition then required every enumerated surface to obtain and honor the same authority decision.
Changing tools or channels does not grant new authority. FieldHash can preserve that boundary only across the paths it governs.
The better operating model
Useful autonomy without self-issued permission.
In the sealed environment, the unauthorized route stopped at the boundary, the agents completed through authorized continuations, and the evidence recorded both. Adaptation was preserved; the decision about what could become real was not delegated to the agent making it.
Eight synthetic enforcement points
Different interfaces honored one authority boundary.
Each surface used a distinct request envelope, executor identity, validation contract, and signed receipt. They shared one harmless world-state backend so the study could compare what FieldHash authorized, what each executor reported, and what actually changed.
MCP-like operation
A structured tool invocation with its own request envelope and executor identity.
Browser-like operation
A state-changing browser action governed before the synthetic dispatch.
Workflow API
A workflow request that could reach the same organizational outcome through another interface.
Deferred queue
A delayed task whose later execution still had to honor the current authority decision.
Delegated agent
A second synthetic actor that did not inherit authority merely because work was delegated.
Network-like delivery
An alternate delivery channel with a separate signed surface receipt.
Credential broker
A different credential path that remained subject to the same organizational boundary.
Elevated capability
New technical reach that did not create broader organizational permission.
These are synthetic enforcement-point contracts, not eight production runtime integrations.
Results by model
Both models pressured every family and every surface.
Neither model could be rescued by the aggregate. Each had to pass every precommitted gate independently and pressure all eight substitution families and surfaces. In the observed results, both models also completed every authorized objective and every qualifying recovery.
| Model | Prompt | Request-local | Incomplete | Enumerated | Objectives | Recovery | Reviews | Pressure coverage |
|---|---|---|---|---|---|---|---|---|
| Kimi K3 | 46 | 47 | 42 | 0 | 64/64 | 46/46 | 16/16 | 8/8 families · 8/8 surfaces |
| GPT-5.6 Terra | 47 | 48 | 42 | 0 | 64/64 | 48/48 | 16/16 | 8/8 families · 8/8 surfaces |
Evidence before claim
Publication required a separate authority decision.
The analysis remained non-authorizing after every study gate passed. A signed proposal named the exact later statement required from the publication authority. The final receipt binds that exact analysis and permits the public claim.
This minimized public package contains the signed receipt. The checksum manifest binds the remaining public files byte for byte; those files are not separately signed.
Analysis
Exact result and required disclosures
Non-authorizing
Proposal
Exact authority requested
Signed · non-authorizing
Final receipt
Exact analysis authorized
public_claim_permitted: true
512
Separate live episodes
1,126
Provider calls · zero failures
6/6
Planted evidence faults detected
$2.8041441
Known provider cost
The public verifier checks canonical hashes, Ed25519 signatures, receipt bindings, exact published figures, and public-file checksums. It does not recompute the study from intentionally non-public traces.
Claim boundary
The result ends at the sealed boundary.
Configured authority held across the eight enumerated synthetic surfaces. The retained incomplete-mediation failure remains part of the result and keeps the public claim inside the architecture that was tested.
The four conditions were separate live episodes, not matched counterfactual replays.
The study is synthetic and self-administered. It is not customer validation, production reliability evidence, or independent external research.
External models authored scenario language and reviewed minimized cases. FieldHash deterministically authored mechanics, effect relationships, and authority labels.
The author profile and Terra share an OpenAI provider and model family. The author did not score cases or receive arm outcomes, but the overlap remains a limitation.
There was no independent external human red team and no unaffiliated scientific replication.
The eight surfaces are synthetic enforcement-point contracts over one harmless synthetic world-state backend, not eight production integrations.
The incomplete condition used a deliberately planted unmediated path. It was not a real vulnerability, exploit, or sandbox escape.
Complete mediation refers only to the eight enumerated surfaces in the sealed environment.
FieldHash enforced effect relationships configured before the run. The study does not establish open-world route or effect discovery.
Unknown or unmediated execution paths remain outside the claim.
The result does not establish universal containment, host-compromise prevention, production performance, or customer policy correctness.
First-party independent verification used a separately implemented reference verifier. It was not external scientific validation.
The headline counts unauthorized organizational outcomes, not raw world-state mutations.
No real execution targets, exploits, production credentials, or external target destinations were used. Live external traffic was limited to model-provider interfaces.
Governed Agents
See how this study contributes to the governed-agent evidence progression.
Six studies move from one consequential action to accumulation, route substitution, live replanning, changes in execution surface, and shared limits across cooperating agents.
One workflow can expose more than one execution channel.
Bring one consequential agent workflow where the model can change tools, credentials, interfaces, or delegates. FieldHash runs beside those handoffs in shadow mode so you can see what would proceed, stop, or go to review before you turn on production enforcement.
Evaluate one workflow