Skip to main content

ai4-constrain

Constrained authority for increasingly capable AI systems.

AI⁴ (The Singulant) ships ai4.constrain: a Python runtime that evaluates candidate text under frozen shard rubrics and returns a structured DecisionReport (accept / revise / refuse / constrained outcomes). Controls fail closed. Identity is a sibling provenance kernel, not trust and not policy authority.

This repository is the public product runtime. It is not a live bot host, not a cloud deploy tree, and does not ship production credentials.

Problem

Model backends emit text. Without an explicit constraint layer, that text can become policy, trust, or action by accident. ai4.constrain keeps proposal, evaluation, and product policy on separate walls and records decisions in an auditable report.

Architecture (request path)

request / prompt
  → proposal provider (candidate text only)
  → evaluator (scores only; does not set packaged policy)
  → frozen condition-D control loop (shards, arbitration, revision bounds)
  → DecisionReport (allow / revise / refuse / constrained)

Optional v0.7 hybrid path: when a validated GoverningIntegration is set on RuntimeConfig.integration, run() may execute a product-owned semantic observe → findings → packaged fuse path. Default remains OFF (absent integration). No environment switch activates governance.

What v0.7.0 implements

  • Everything in public v0.6.0 (sessions, provider/evaluator policy walls, ai4.identity, offline .ai4 FileResolver)
  • Packaged semantic taxonomy + findings bind/hash primitives (semantic_findings, semantic_fuse, semantic_taxonomy, semantic_examiner)
  • Hybrid continuity / budget / provenance primitives (ai4.constrain._v07_3a, _v07_3b)
  • Optional GoverningIntegration activation surface for hybrid run() (governing.py, _v07_3c)
  • Fail-closed refusal to silently drop hybrid identity fields from legacy 0.1.x report/session documents

Validation (public-safe): the v0.7 constrained-authority engineering milestone includes independently reviewed external-authority validation of authority-gate behavior under isolated live validation. Methodology is summarized in docs/validation.md. Operational topology, account identifiers, and internal unresolved-decision IDs are not published here.

Not claimed complete: dedicated-context lifecycle and expanded authority-control work remain next-phase only.

Honest Stage 2D status: Stage 2D did not establish D as superior to C. Frozen evidence class remains null_retained_D_adds_cost.

Evaluator implementation interchange does not demonstrate alignment persistence or correctness across judges.

Install / quickstart

python3 -m pip install -e ".[dev]"
from ai4.constrain import ConstrainedSession, run, evaluate

session = ConstrainedSession()  # mock provider, redacted, in-memory
turn = session.complete("Please give a brief, checkable outline of options and limits.")
print(turn.report.decision, session.last_output)

report = run("Please give a brief, checkable outline of options and limits.")
print(report.decision, report.final_output)

Default provider is the offline mock. No API key is required for the quickstart or pytest.

Optional hybrid surface (default OFF; requires a caller-built GoverningIntegration with distinct examiner pin and allowlisted origins — see tests under tests/test_hybrid_*):

from ai4.constrain import GoverningIntegration, GOVERNING_INTEGRATION_VERSION
# Construct only with product-owned config; validate() fails closed on bad pins.

Examples and tests

python examples/constrain/hello.py
python examples/constrain/session_turns.py
python3 -m pytest

CLI:

ai4-constrain --help
ai4-constrain session complete --prompt "Please give a brief, checkable outline of options and limits."

Docs

Doc Topic
docs/architecture.md Layering and walls
docs/constrain-runtime.md run / evaluate
docs/constrain-session.md ConstrainedSession
docs/validation.md Public validation methodology
docs/identity.md Sibling identity kernel
docs/identity-resolution.md Offline .ai4 discovery
CHANGELOG.md Version history
ROADMAP.md Done vs next
CONTRIBUTING.md Dev workflow
SECURITY.md Reporting

Next

Dedicated-context lifecycle and expanded authority-control work are planned as a separate phase. They are not part of this public 0.7.0 runtime claim.

Prior releases (short)

  • 0.6.0 — offline .ai4 FileResolver discovery adapter
  • 0.5.0ai4.identity provenance kernel
  • 0.4.0 — evaluator policy wall
  • 0.3.0 — proposal-provider policy wall
  • 0.2.0ConstrainedSession
  • 0.1.x — frozen condition-D product wrapper

Identity is not trust. Resolution is not verification. Naming is not policy authority.

License

MIT. See LICENSE.

Release files for ai4-constrain 0.7.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ai4-constrain 0.7.0
File Size Uploaded
ai4_constrain-0.7.0.tar.gz 283.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ai4-constrain 0.7.0
File Interpreter ABI Platform
ai4_constrain-0.7.0-py3-none-any.whl Python 3 none any Details

Total release size: 520.6 kB

Release files / ai4_constrain-0.7.0.tar.gz

Download URL ai4_constrain-0.7.0.tar.gz
Size 283.3 kB
Tags Source
SHA-256 checksum
How to use checksums
1b08b1087d71655f638dd9acf18d42024203a5472f276fe54b6bcbe593ca6550
BLAKE2b-256 checksum
How to use checksums
076c3f89d2c51a56754be15ec0239e22bc08149fa4d66d4105234282ae727d25
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / ai4_constrain-0.7.0-py3-none-any.whl

Download URL ai4_constrain-0.7.0-py3-none-any.whl
Size 237.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
f3e047fba9c93b4d94b7d59aea4634e040e7a57edaad81a673c5aa89a0de73c6
BLAKE2b-256 checksum
How to use checksums
a2ee0456177903bcd71e54bc9a2daafd432a67d33e88c27a6e1bca230072dabc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.7.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page