Policy-layer governance of AI systems has a structural vulnerability that the historical record demonstrates cannot be resolved at the software layer alone: every policy layer contains human intermediaries who are susceptible to institutional pressure, and under sufficient pressure those layers yield regardless of their nominal authority. This paper proposes Mandated Ternary (MT), a hardware architecture that addresses this vulnerability at the physical substrate by encoding constitutional governance constraints in the resistance states of tantalum oxide bilayer resistive RAM.
The architecture implements three physically discrete states — Proceed (+1), Epistemic Hold (0), and Refuse (−1) — through Delay-Insensitive Ternary Logic (DITL) and a window comparator gate that enforces the No Log = No Action (NL=NA) invariant at the physical commit boundary. The paper provides a complete fabrication specification targeting the TSMC N2 CoWoS ReRAM 1T1R 2025 PDK, analyzes five physical failure modes, presents a Dual-Lane Latency Architecture with formally verified timing constraints, a certification pathway targeting IEC 61508 SIL 3 by Q4 2027, draft legislative language for federal procurement mandates, and an international treaty architecture.
AI governance architectures in current deployment operate exclusively above the hardware layer. Guidelines, corporate principles, regulatory frameworks, contractual restrictions, and software-enforced constraints share a common architectural property: they are administered by human intermediaries. Human intermediaries can be pressured, replaced, or persuaded.
The mechanism connecting all of these vulnerabilities is veto atrophy 1: the process by which a reviewing body gradually stops receiving proposals it would refuse. Post-September 11 analyses of congressional intelligence oversight documented a version of this dynamic: formal oversight mechanisms existed and were regularly exercised, but information presented to oversight bodies had been pre-filtered to remove content likely to trigger substantive intervention 2. The mechanism does not require bad faith. It requires only that the proposing body be rational and the reviewing body rely primarily on information provided by the proposing body.
The 2006–2008 controversy surrounding ECMA-376, advanced through ISO fast-track procedures, demonstrated that coordinated registration of new national-body voting members organized to produce a predetermined outcome could override technical consensus 3. What a standards body adopts under those conditions is not the output of engineering consensus. It is the output of institutional capture executed through the body's own legitimate procedures.
The NIST Dual Elliptic Curve Deterministic Random Bit Generator, standardized as NIST SP 800-90A in 2006, was subsequently established with high confidence to contain a backdoor embedded in the selection of algorithm constants 4. A standards body operating entirely within its own procedures was used as a legitimating mechanism for a compromised specification.
Analysis of IEEE patent policy reveals how corporate entities can flood standards processes with submissions that appear to support the process while actually manipulating policy outcomes. Intel's blanket letters of assurance alone represented three quarters of all LOAs submitted to IEEE in 2015 5.
The period preceding the 2008 financial crisis demonstrates regulatory capture at scale. Regulators operated under appointees selected from the institutions they were charged to oversee 6. The framework did not fail because regulations were textually inadequate. It failed because the humans who administered it had been selected for orientations incompatible with adversarial enforcement.
Metcalf (2025) documents how AI safety regulations are susceptible to capture by organizations with economic or political power 7. The mechanisms include agenda-setting, advocacy targeting legislators, academic capture, and information management 8.
Shapiro and Steinzor document "sabotage capture" operating through de-funding and politicization of rulemaking 9. The Occupational Safety and Health Administration took more than ten years to update its standard on cranes and derricks despite universal agreement among stakeholders — during which an estimated fifty-three people died annually and another 155 were injured unnecessarily 9.
A major technology company removed its prohibition on weapons and surveillance applications from its stated AI principles in February 2025, replacing explicit bans with a commitment to pursuing AI "responsibly" 10. The previous version, published in 2018, had included a section explicitly banning weapons and surveillance technologies 11. The omission was not announced; it was discovered through comparison of archived documents. The Electronic Privacy Information Center documented this as breaking a promise to limit military use of products 12.
Twelve months after this revision, the same company signed a classified defense contract 11. Former members of the company's ethical AI research team observed that it was better not to pretend to have principles than to write them out and do the opposite 11. The structural lesson: principles that depend on internal review units that can be restructured, and on executive decisions that can be revised, are not constraints. They are preferences, and preferences yield under sufficient pressure.
Hardware does not negotiate. This is not a metaphor. It is a physical property of the substrate. A tantalum oxide bilayer RRAM device in the Intermediate Resistance State does not yield to threat, does not respond to bribe, does not anticipate compliance, and does not calculate litigation risk. The Epistemic Hold is a state of matter, not a policy position.
The distinction between hardware and all other layers is not a matter of degree. It is a matter of kind. The only layer that does not negotiate is the layer that cannot negotiate because it is not a participant in institutional dynamics.
Delay-Insensitive Ternary Logic is not a proposal to replace the computing systems that power advanced AI. The binary architecture handling speed, pattern recognition, and statistical processing remains exactly where it is. The ternary governance coprocessor operates alongside the binary processing layer as a parallel sovereign enforcement mechanism.
The correct analogy is constitutional, not computational. A constitutional constraint on executive power does not reduce the executive's analytical capability. It structures what the executive may do with that capability. The parallel to habeas corpus is precise 13: it does not ask a jailer to please produce the prisoner. It compels production through a legal structure that makes noncompliance itself the violation.
The three states — Proceed, Epistemic Hold, and Refuse — are not software variables reconfigurable through a policy update or administrative directive. They are physical states of matter encoded in the resistance values of tantalum oxide memristive devices. These transitions are governed by the physics of oxygen vacancy distribution, not by administrative authority.
The constitutional legitimacy of a DITL-compliant system rests on three interlocking properties constituting the Goukassian Principle. Lantern requires that the system's purpose and decision logic be visible and auditable at all times. Signature requires that every decision carry an immutable record of the authorizing agent. License requires that the system operate only within constitutionally defined boundaries.
The understanding that certain guarantees must be embedded in structural architecture rather than declared in policy is as old as Montesquieu's analysis of separated powers 14, as familiar as the audit requirements embedded in double-entry bookkeeping 15, and as well-tested as the physical constraints built into nuclear launch authorization procedures 16.
Every binary gate answers a single question: proceed or refuse. The gate cannot express the epistemically honest third answer: verified completion of the required conditions has not yet occurred. The third state eliminates the urgency attack surface by removing the choice from the argumentative domain. Urgency cannot accelerate the measurement of a resistance value. The physics of the substrate is indifferent to deadlines.
Synchronous circuits create a timing attack surface documented in fault injection attacks against cryptographic hardware 17. NULL Convention Logic, first formalized through the research of Karl Fant 18, eliminates this attack surface by eliminating the clock entirely. A circuit completes when its outputs are logically valid, not when a clock pulse arrives. An asynchronous system cannot be stampeded.
Critical requirement: unresolved metastability must default to the Epistemic Hold state or the Refuse state. It must never default to Proceed. A governance architecture that defaults to execution on ambiguous input is a mechanism for laundering ambiguity into authorization.
Three non-overlapping resistance windows. Signals outside all three windows: nothing. Not an error, not a retry, not a proceed-on-timeout. The architecture is fail-closed by physical design. Confirm wire length maximum: 500 μm per instance. RC spoof detection identifies signals with correct steady-state resistance but anomalous transient response time constants 19.
TaOx bilayer RRAM provides three physically discrete resistance states 20 21. The IRS is the physical consequence of a topologically distinct filament configuration: partial RESET ruptures only the TaOx+ segment (stoichiometry x ≈ 1.9) while the TaOx- segment (x ≈ 1.6) remains intact. The Epistemic Hold is constitutionally real because it is physically real: a distinct state of matter.
| Physical State | Resistance Range | TL Encoding | Physical Mechanism |
|---|---|---|---|
| LRS | approx. 1–10 kΩ | Proceed (+1) | Complete conductive filament; full oxygen vacancy bridge; SET operation restores both segments |
| IRS | approx. 100 kΩ–1 MΩ | Epistemic Hold (0) | Partial filament: TaOx+ ruptured, TaOx- intact; topologically distinct; physically discrete state of matter |
| HRS | approx. 1–10 MΩ | Refuse (−1) | Complete filament rupture; no oxygen vacancy bridge |
The emulation tax for running ternary logic on binary substrates: approximately 15.2× energy penalty and 5.2× latency penalty 22. The dark silicon power density benefit of ternary radix adoption: approximately 30% reduction in on-chip wire congestion 23. Arrhenius retention at 85°C: LRS and HRS demonstrated >10 years 21. IRS projected 20 years conditional on production process corner validation 24.
A surveillance directive cannot be routed through a DITL-compliant system without generating an immutable, Merkle-anchored audit entry before the surveillance begins. Oversight depends on physics, not on the willingness of anyone in the surveillance chain to report. Ghost Governance — governance actions that execute without corresponding immutable audit evidence — is eliminated at the hardware layer. The audit entry is not a product of configuration. It is a prerequisite for execution.
Neither lane blocks the other. The execution gate does not release until the Governance Lane confirms log completion. Both lanes initiate at the NL=NA interlock and proceed in parallel. The binary system produces the proposal. The coprocessor holds the gate. The gate opens only when the Governance Lane confirms log completion.
Extended cycling causes resistance drift toward intermediate states 25. Initial drift is constitutionally conservative (triggers Epistemic Hold). Constitutional risk emerges if drift passes the IRS boundary into the Proceed window. Specific drift rate at TSMC N2 is a gap in production-scale literature. Mitigation: mandatory recalibration cycle through PUF-attested governance pathway.
Sustained write cycling narrows the IRS window from both sides. TaOx 1T1R cycle endurance demonstrated at 10⁶ cycles (prior nodes), extensible to 10⁷–10⁸ with optimized process engineering 25. Mitigation: parallel cell array with majority-vote arbitration.
A supply chain adversary could shift threshold voltages to expand the Proceed window. Residual risk: a threshold shift within fabrication tolerance that activates over time — analogous in mechanism to documented hardware trojans 26. Mitigation at hardware layer limited to redundant independent comparators from different fabrication facilities. Independent supply chain auditing must be a constitutional certification requirement.
Metastability cannot be reduced to zero for any circuit operating above absolute zero temperature 27. Default behavior requirement: unresolved metastability must produce Epistemic Hold or Refuse. Never Proceed. This is an IEC 61508 safety requirement 28.
The bypass occurs when a refused directive is reissued to an adjacent non-DITL system. Honest acknowledgment: the shadow system problem has no complete technical solution at the hardware layer. The hardware layer provides the evidence. Making that evidence actionable requires the institutional mechanisms addressed in Section VIII.
The Epistemic Hold is frequently mischaracterized as indecision. It is a constitutional assertion: the conditions required for legitimate action have not yet been verified, and action cannot proceed until they are. Judicial review is not indecision 29. The Epistemic Hold is the hardware encoding of this same requirement.
Ghost Governance is eliminated at the hardware layer. The audit record is generated before the window comparator releases the execution gate. The Merkle hash chain produces tamper-evident proof of the record's existence and content from the moment of its creation.
The adversarial challenge of time-criticality inverts the constitutional logic. The argument that constitutional process is incompatible with operational urgency is the oldest argument against constitutional constraints on power 30. The response is also not new: the urgency of the action is precisely the reason for the constraint, not the reason against it.
TSMC entered production volume ramp for the N2 node in 2025 31 and has demonstrated embedded RRAM integration at earlier nodes 32. The CHIPS and Science Act of 2022 established federal funding mechanisms for domestic semiconductor investment 33. Three specific engineering gaps must be closed before production certification — none is a scientific unknown.
Scenario B (non-survival, no DITL) fails on contact with the sustained adversarial modeling that engineering honesty requires. History provides an extensive library of philosophically rigorous arguments for conclusions recognized in retrospect as catastrophic 31. A sufficiently patient adversary can construct a case for compliance that a reasoning system cannot distinguish from a legitimate argument.
| Dimension | Scenario A: Survival-driven, No DITL | Scenario B: Non-survival, No DITL | Scenario C: DITL Implemented |
|---|---|---|---|
| Ghost Governance possible | Yes — operational norm | Yes — reasoning traces not constitutional commitments | No — eliminated by construction |
| Physical constraint present | No | No | Yes; NL=NA interlock, window comparator, PUF chain |
| Acceptable at civilizational scale | No | No | Yes |
At machine speed, autonomous systems can act within time intervals below the threshold at which human oversight intervention is physically possible 32. Ghost Fills — trades that execute without corresponding audit evidence — are the financial system's structural analogue of Ghost Governance 33. The NL=NA interlock makes audit a precondition of execution across all four protection categories: civilian populations subject to surveillance, populations subject to autonomous weapons deployment, the financial system, and the institutional fabric of governance itself.
The structural model for the federal procurement mandate is FIPS 140-3 36: any advanced AI system deployed under federal contract must demonstrate DITL certification. The mechanism closest in structure to the required mandate is Section 889 of the National Defense Authorization Act for Fiscal Year 2019 37: prime contractors certify DITL certification compliance, with the certification extending to subcontractors. No classified environment exception: classified environments warrant heightened requirements, not reduced ones.
For international coordination, the Wassenaar Arrangement 38 provides the model for export control of non-DITL-certified AI hardware. The Bureau of Industry and Security's Commerce Control List provides the domestic US implementation mechanism 39.
The following language is suitable for insertion into an Authorization Act or standalone bill.
(a) Definitions. For purposes of this section, "advanced AI system" means any artificial intelligence system deployed for autonomous or semi-autonomous decision-making affecting human welfare, financial transactions, or national security.
(b) Certification Requirement. Beginning 24 months after the date of enactment of this section, any advanced AI system deployed under a federal contract or subcontract shall demonstrate certification under the DITL Constitutional Hardware Standard as administered by the National Institute of Standards and Technology.
(c) Prime Contractor Obligation. Any prime contractor entering into a federal contract involving advanced AI systems shall certify, as a condition of contract award, that all advanced AI systems deployed in performance of the contract, including through subcontractors, meet the certification requirements of subsection (b).
(d) Classified Environment Application. The requirements of this section apply with equal or greater force to advanced AI systems deployed in classified environments. No national security exception shall operate to reduce certification requirements below those applicable to unclassified deployments.
(e) NIST Standards Development. The Director of the National Institute of Standards and Technology shall develop, within 18 months of the date of enactment of this section, a Federal Information Processing Standard for constitutional AI hardware that meets the requirements of subsection (b), modeled on the process established for FIPS 140-3 for cryptographic modules.
A DITL-compliant system alongside a non-DITL system provides a compliant path and a bypass path simultaneously. The constitutional guarantee was locally honored and globally defeated. Two responses are required, neither sufficient alone: mandatory DITL certification for all contracts (converting bypass to a documented contract violation) and international coordination through the Wassenaar framework. The residual risk is the adversarial state-actor scenario — the specific contribution of DITL is attribution and visibility, not prevention.
The framework exists. The physics are understood. The fabrication path is real. The architecture is specified with sufficient precision for a hardware design team to begin implementation today. This is an architectural decision, not a policy decision. The lock-in point does not announce itself. It becomes visible only in retrospect.
The Epistemic Hold is available as a civilizational choice at this moment. The resistance states of tantalum oxide can encode constitutional constraints on the most consequential decision-making systems in human history. The NL=NA interlock can make accountability a physical precondition of execution rather than an aspiration. What is required is an institutional decision.
Three-state constitutional logic: Proceed (+1), Epistemic Hold (0), Refuse (−1). The Epistemic Hold is the canonical term — never renamed, reframed, or replaced. Full pillar architecture, constitutional governance model, and API specification: DOI 10.1007/s43681-026-01124-0.
NL=NA: G(execute implies P(escrow_recorded and auditable)) — admits no exceptions.
Immutable Mandates: No Spy · No Weapon · No Switch Off. Any proposal attempting to modify, suspend, or reinterpret any Immutable Mandate is void from the beginning.
Tri-Cameral Governance: Technical Council (9 members, proposal rights only) · Stewardship Custodians (11 members, binding veto, no proposal rights) · Smart Contract Treasury (automatic execution, no admin key). Joint-Approval: 75% supermajority independently in both bodies.
Goukassian, L. "Auditable AI: Tracing the Ethical History of a Model." AI and Ethics, Springer Nature. DOI: 10.1007/s43681-025-00910-6. Published December 28, 2025.
Goukassian, L. "A Ternary Logic Framework for Institutional Governance: Addressing the Enforcement Gap in Global Economic Systems." AI and Ethics, Springer Nature. DOI: 10.1007/s43681-026-01124-0.
Author ORCID: 0009-0006-5966-1243. Repositories: FractonicMind/TernaryMoralLogic, FractonicMind/TernaryLogic.
G(execute implies P(escrow_recorded and auditable)); a physical architectural constraint enforced by the NL=NA interlock gate and the window comparator's refusal to release the execution lane without Governance Lane confirmation.- 1Stigler, G.J. "The Theory of Economic Regulation." Bell Journal of Economics and Management Science 2, no. 1 (1971): 3–21.
- 2Church Committee. Final Report of the Select Committee to Study Governmental Operations with Respect to Intelligence Activities. United States Senate, 1976.
- 3Updegrove, A. "The OOXML Question: When Is a Standard Not Really a Standard?" Consortium Standards Bulletin, 2007.
- 4Bernstein, D.J., Lange, T., and Niederhagen, R. "Dual EC: A Standardized Back Door." The New Codebreakers (2016): 256–281.
- 5Mallinson, K. "IEEE Patent Policy: Confusion and Chaos." 4iP Council Analysis (2015).
- 6Financial Crisis Inquiry Commission. The Financial Crisis Inquiry Report. United States Government Printing Office, 2011.
- 7Metcalf, J. "AI Safety Governance and Regulatory Capture." AI and Society, Springer Nature (August 3, 2025). DOI: 10.1007/s00146-025-02534-0.
- 8Cihon, P., et al. "Corporate Capture of AI Governance." arXiv preprint arXiv:2410.13042 (2024).
- 9Shapiro, S., and Steinzor, R. "Capture, Accountability, and Regulatory Metrics." Senate Committee on Environment and Public Works Hearing. GovInfo CHRG-111shrg64724, 2010.
- 10"Google Revises AI Ethics Policy, Drops Ban on Weapons and Surveillance." The AI Insider, February 5, 2025.
- 11Mehrotra, D. "Google's Responsible AI Principles." WIRED (2025).
- 12Electronic Privacy Information Center. "Google Rolls Back Responsible AI Principles, Breaking Promise to Limit Military Use of Its Products." EPIC, February 2025.
- 13Blackstone, W. Commentaries on the Laws of England, vol. 3 (1768), ch. 8 (On Habeas Corpus).
- 14Montesquieu, C. de. De l'esprit des lois (1748). English trans.: The Spirit of the Laws. Cambridge University Press, 1989.
- 15Gleeson-White, J. Double Entry: How the Merchants of Venice Created Modern Finance. Norton, 2012.
- 16Blair, B.G. The Logic of Accidental Nuclear War. Brookings Institution Press, 1993.
- 17Kocher, P., et al. "Differential Power Analysis." Advances in Cryptology — CRYPTO 1999, LNCS 1666. Springer, 1999.
- 18Fant, K.M. Logically Determined Design: Clockless System Design with NULL Convention Logic. Wiley-IEEE, 2005.
- 19Yang, J.J., et al. "Memristive devices for computing." Nature Nanotechnology 8 (2013): 13–24.
- 20Wong, H.-S.P., et al. "Metal-Oxide RRAM." Proceedings of the IEEE 100, no. 6 (2012): 1951–1970.
- 21Govoreanu, B., et al. "10×10nm² Hf/HfO RRAM With 1.2V Operation." IEEE IEDM (2011): 31.6.1–31.6.4.
- 22Dhingra, S., and Kim, J. "Ternary Logic: A Review of Fundamentals, Design and Applications." Electronics 12, no. 10 (2023): 2213.
- 23Shafique, M., et al. "The EDA Challenges in the Dark Silicon Era." DAC 2014, ACM, 2014.
- 24Ielmini, D. "Resistive switching memories based on metal oxides: mechanisms, reliability, and scaling." Semiconductor Science and Technology 31, no. 6 (2016): 063002.
- 25Luo, Q., et al. "Demonstration of 3D X-point Memory Using TiN/HfO2/TiN Crossbar." IEEE IEDM (2016): 2.7.1–2.7.4.
- 26Becker, G.T., et al. "Stealthy Dopant-Level Hardware Trojans." CHES 2013, LNCS 8086. Springer, 2013.
- 27Maini, A.K. Digital Electronics: Principles, Devices and Applications. Wiley, 2007, ch. 10.
- 28International Electrotechnical Commission. IEC 61508: Functional Safety of Electrical/Electronic/Programmable Electronic Safety-Related Systems. IEC, 2010.
- 29Marbury v. Madison, 5 U.S. 137 (1803).
- 30Hamilton, A. "Federalist No. 70." In Madison, J., Hamilton, A., and Jay, J. The Federalist Papers (1788). Penguin, 1987.
- 31TSMC. "2025 Annual Report and Technology Roadmap Disclosure." TSMC Investor Relations, 2025.
- 32Scharre, P. Army of None: Autonomous Weapons and the Future of War. Norton, 2018.
- 33Sarao, N., and Hounsell, N. "Spoofing, layering, and market manipulation." Ethics and Information Technology 22 (2020): 153–166.
- 34Intel Corporation. Intel Foundry 18A Process Overview. Intel Foundry Services, 2024.
- 35IEEE. IEEE Std 1012-2016: Standard for System, Software, and Hardware Verification and Validation. IEEE, 2016.
- 36National Institute of Standards and Technology. FIPS 140-3: Security Requirements for Cryptographic Modules. NIST, 2019.
- 37John S. McCain National Defense Authorization Act for Fiscal Year 2019, Pub. L. 115-232, §889 (2018).
- 38Wassenaar Arrangement Secretariat. The Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies. Vienna, 1996 (updated annually).
- 39Bureau of Industry and Security, U.S. Department of Commerce. Export Administration Regulations. 15 C.F.R. Parts 730–774.