Monograph I
SAFE-AI Unified: A Mathematical Framework for User-Applied Operations on Frozen-Weight LLMs develops a mathematical account of what users do when they apply structured discipline to sessions with frozen-weight large language models — and of what governance over that channel can and cannot achieve. Its organizing claim is that an LLM session is an asymmetric-information channel: the model's filtration is strictly contained in the user's, so user-applied operations — the brackets, verified anchors, and engagement modalities of the SAFE-AI practice — carry knowledge the model cannot reconstruct on its own.
The framework gives these operations four mathematical lives across four Parts: as jumps in a stochastic process, as directions in an information geometry, as refinements of a σ-algebra, and as the objects of community governance — building toward a risk decomposition in which representational adequacy is defined relative to a community's own knowledge corpus. The mathematics is presented honestly as work in progress: load-bearing structural assumptions are named and stated in conservative, evidence-bounded forms; operations and claims carry falsifiers; conjectures are labeled as conjectures; and a consolidated claim register records what is proved, what is assumed, and what is open. The toolkit spans Markov-chain and piecewise-deterministic-process theory, information geometry, optimal transport, mean-field interacting-particle systems, and stochastic filtering, connected to the CARE Principles, OCAP, Te Mana Raraunga, and the GIDA framework for Indigenous data sovereignty.
Part I — Inference-Time Dynamics. Models the session as a Markov process on context states with a unique, prompt-independent stationary distribution, and derives the inference-time risk identity: a contextual Bayes floor plus an exploitation gap. Absent user-applied operations, the conditional expectation drifts geometrically toward the stationary-averaged mean of the model's prior; the operations enter the process as jumps injecting information not derivable from the model's own filtration. Establishes recurrence for the piecewise-deterministic limits of the three traversal protocols and convergence guarantees for the workhorse operations — Progressive Enhancement (monotone Bayes-floor reduction) and Iterative Refinement (Wasserstein-contractive variance stabilization). A filtering formulation casts the channel as a pure-jump signal observed through announced, predictable interventions: observable times, hidden marks.
Part II — Pullback Fisher Sensitivity. The geometry of when a user-applied operation actually moves the model. The context-space pullback of the output Fisher–Rao metric has an outlier-and-bulk spectral structure shown to be unconditional given a concentrated predictive distribution — pinned to the sorted output probabilities themselves — with the parameter-space, singular-learning-theory picture retained as a complementary account whose assumptions are stated in their conservative, trained-weight-evidence-bounded form. Supplies the Rayleigh-quotient sensitivity diagnostic with its estimator regimes, an empty-calorie criterion for operations that are fluent but ineffective, and a Pinsker bridge linking the Fisher and optimal-transport readings of operational efficacy.
Part III — σ-Algebra Refinement and the Aleatoric Floor. Recasts session evolution as progressive refinement of the practitioner's σ-algebra and proves the additive bias / context-variance / aleatoric-floor decomposition, with a cross-term-vanishing lemma securing the classical split under path-dependent conditioning. Each user-applied operation is typed by the error term it moves — bias, context variance, or the empirical noise estimate — with rate-quantified variance contraction and a long-tail result in achievability/converse form under a named tail-separation assumption: for communities underrepresented in the pre-training prior, bias closure requires augmentation from the community's own corpus, and pretraining-adjacent retrieval cannot close it at any corpus size. The Part engages the 2022–2026 uncertainty-disentanglement debate directly, arguing that the σ-algebra-relative floor — "irreducible" always carries its conditioning information — is the formalization the critique literature calls for.
Part IV — Governance Through the Asymmetric-Information Channel. Specializes the framework to community-conditional governance: the authorized target distribution and the admissible class of user-applied operations are the objects a community controls. Defines community-conditional adequacy in dual form — a diagnostic average and a verdict geometric mean that zeroes on any structurally unrepresented authorized direction — alongside a provenance hierarchy and a six-rung escalation ladder on which refusal is formally characterized, as infeasibility of adequacy over the highest authorized operation class, rather than procedurally asserted. A mean-field model of the human–LLM dyad population frames cultural collapse and sovereign solidarity as competing dynamics, and the data-processing inequality supplies the mechanism: community-authorized injection is precisely the exogenous information a closed feedback loop forbids itself — sovereignty as the negation of the DPI hypothesis. Community refusal is treated throughout as a success condition of the framework, not a failure.
The Research Program. The monograph closes with five named problems extending its Open Invitation to research partners, each carrying a status, the enabling literature, what is missing, a success criterion with its falsifier, and a collaboration profile: uniform-in-time propagation of chaos for governed jump populations; singularity-aware (local-learning-coefficient) operationalization of the framework's spectral assumptions; a closed-loop information-decay theorem for nonlinear measure flows; the minimum authorized reference-set size for stable adequacy verdicts; and a community-specific representation-loss rate whose constraint set is the governance specification itself, with community consultation a binding precondition of the research. These are offered as formulated problems, with the falsifier discipline extended to the program itself.
The framework formalizes a deployed practice: its operational development is published separately as a practitioner volume (Berardi, 2026, ISBN 978-1-966752-16-5), and the direction of derivation — from practice toward its mathematics — is recorded in the monograph's provenance section.
Monograph II
SAFE-AI Decision Diagnostics (previously circulated as SAFE-AI Reversed) is the diagnostic companion to the SAFE-AI framework. The forward volume (Monograph I) treats the user as an active agent and a frozen language model as a fixed environment to be steered toward a target, showing how disciplined interventions move a model's output toward what a user wants. This volume reverses the inference. It asks the prior question the forward account leaves open by design: whether a given model has the geometric capacity to register and respond to a particular community's authorized target at all — and, when it does not, what kind of failure that is, and what evidence would license saying so.
The work's central contribution is the separation of two failure signatures that application-level evaluation routinely conflates.
A flat failure (low sensitivity) is a model lacking internal geometric capacity along a community-relevant direction — an intervention pushing where the model cannot register it. A wrong-direction failure (low descent) is a model that is sensitive but steers toward the wrong target — an elicitation problem, not a capacity one. The framework operationalizes the distinction through a four-cell sensitivity × descent matrix built on a context-space pullback Fisher metric, Rayleigh sensitivity, a cotangent steerability reading, and an optimal-transport efficacy measure — with distributional displacement explicitly separated from target-directed descent — reported profile-first across the community's declared dimensions, with scalar adequacy scores as community-authorized summaries. A persistent flat-and-unhelpful signature is read as an operational verdict of representational inadequacy, carried by a sequential Persistent Flat-Failure certificate whose anytime-valid form remains sound under the escalation ladder's adaptive stopping.
A discipline runs throughout: the apparatus issues operational verdicts conditioned on a named intervention class, the auditor's access regime, and the target's version and rendering — never impossibility theorems. Because it operates through the text interface, its behavioral layer applies to any frozen-weight model by construction; a certificate-tier system (DD-0–DD-4) grades what the assembled evidence actually supports, from target-and-rendering audit through black-box behavioral findings to causal internal evidence, with structural representational certificates requiring the access they name.
Version 3 adds a formal abstention state: Cell U, the verdict the apparatus returns when evidence is discordant or underidentified — because a diagnostic that cannot abstain cannot be fully trusted when it concludes. The escalation ladder is reread as a sequential identification strategy that partitions persistent failures into three remediation classes — prompt-side, retrieval-side, representational — while a compatible-cause set tracks which underlying causes remain; causal attribution is licensed only when the exclusion audits, including a six-channel SAG adequacy certificate, close that set to representation alone. When they do, remediation is specified as selective curvature allocation with a quantifiable, rank-indexed cost, and the boundary into persistent learned state is indexed by an adaptation profile that hands off to Monograph III's authorization machinery. The target against which all of this is measured is defined and authorized by the community, with data-sovereignty principles (CARE, OCAP, Te Mana Raraunga) entering as formal constraints rather than commentary, and refusal admitted as a legitimate terminal state.
The volume develops applications — a measurable science of prompt efficacy under an operational attribution rule, model selection and procurement, capability certification, closed-loop drift monitoring, and protocol-conformance certification — and closes with a minimal experimental program: conjectures with explicit falsifiers, the smallest study that would calibrate the instrument, and a validation map recording the calibration obligations of the Version 3 apparatus. Each section opens with a plain-language summary, forming a continuous, self-contained second reading alongside the formal development. The volume inherits the formal substrate of Monograph I by reference and interfaces forward to Monograph III.
This monograph has not been developed with, reviewed by, or endorsed by any Indigenous People, Nation, community, or governance body. It offers a proposed technical apparatus and defers to applicable community authority and protocol.
Monograph III
Monograph III completes the movement the SAFE-AI program began. Monograph I (SAFE-AI Unified) established how a disciplined user steers a frozen-weight LLM. Monograph II (SAFE-AI Decision Diagnostics) asked whether the frozen model is representationally adequate for a community's decisions, and built the testing apparatus to answer. This volume asks what happens when the answer is no — when the verdict is a representational deficit that no prompt-layer treatment can reach — and constructs the formal architecture under which weight adaptation may proceed only as a community-authorized act, inhabiting the territory the first two volumes reserve: the rungs beyond inference time, where Monograph II's escalation ladder ends and its verdicts hand off.
The mathematical spine: an exact information-field identity separating a deployment's estimation shortfall from the community's informational advantage; a causal innovation floor proved on the deployed path, so the gap survives adaptation itself; and a transported minimax companion over an authorized hard-drift class, conditional on a named identifiability condition and priced honestly — three results of three logical shapes, with scope, conditions, and quantifier order kept explicit throughout, down to a withdrawn corollary whose replacement is stronger than what it replaced. The operator theory: an adaptation profile — locus of change, cadence, reversibility, provenance visibility — ordering unlike interventions as a product poset rather than forcing them onto one line; update operators with one exact inverse, located (adapter detachment restores the deployed function; nothing inverts learning); a five-sense withdrawal ladder of strictly increasing strength in which every revocation claim names its sense; internalization with knowledge residence tracked explicitly, stale-residence debt denominated in consent rather than performance, and revocation half-life. The governance architecture: the Sovereignty Profile with no scalarization; the Standing and Representation Record; active consent whose scope never widens by silence; coalition interference in Möbius form; sybil-resilient authorization imported from social choice; and a twenty-four-field adapter passport with an SPDX 3.0.1 export mapping, on the principle that a bill of materials is a manifest, not a permission. The standards crosswalk answers to CARE, OCAP®, UNDRIP Article 31, and Local Contexts protocols, with the direction of audit fixed: those frameworks audit this apparatus, never the reverse.
The test surface: nine formal falsifiers — one of them policing an instrument the monograph proposes rather than a result it claims — and a seven-stage preregisterable validation program that begins at Stage −1, governance readiness, the community holding the pen before anyone holds a ruler, and centers on a three-arm matched-forecastability trial built to localize where a model's shortfall lives. An eleven-entry Exploratory register carries the tentative ideas openly, each with stated confirmation and retirement conditions.
Version 3 — Working Paper; not community-endorsed. The governance apparatus is offered for community authorization; nothing in it claims any community's endorsement, and the refusal state of the governed loop is a correct use of the framework. Readers are invited to verify, correct, and extend; the falsifier register is the intended point of attack.
This volume previously circulated in draft under the title SAFE-AI Unfrozen; Monographs I and II are cited throughout under their current titles. It inherits formally from Monograph I (concept DOI 10.5281/zenodo.20649477) and Monograph II (version DOI 10.5281/zenodo.21783279); Appendix C maps every inherited object to its source volume, and the inheritance resolves to the repaired texts of both predecessors.
The foundational SAFE-AI framework for building your Personal Knowledge Corpus (PKC) by Victor L. Berardi, Ph.D.
The SAFE-AI Learning Guide takes you from lived experience to a permanent intellectual estate — a structured, private body of verified knowledge under your sole control — then from estate to engine, with a human-led framework for reasoning at scale through Self-Augmented Generation.
Unlike prompt engineering guides that teach you to get better outputs from AI, this book teaches you to build a permanent intellectual estate from those outputs.
Whether you carry decades of professional expertise, a powerful question entering unfamiliar territory, or only the conviction that what you know should never become someone else's training data, this book meets you where you are.
SAFE-AI Learning Guide for the Knowledge Sovereign
A practical companion for turning career expertise into a Personal Knowledge Corpus (PKC) by Victor L. Berardi, Ph.D.
The AI Learning Guide for Retirees, Managers, Makers, and the Trades guides you from lived experience to a structured, searchable body of knowledge through 13 practical tools — SOPs, STAR stories, reflection logs, prompt libraries, and more — then from archive to application, with a human-led framework for mentoring, consulting, teaching, and the second-act work still ahead.
Whether you carry a full paper trail of your career, a lifetime of stories and hard-won judgment, or only the conviction that what you know matters, this book meets you where you are.
The AI Learning Guide for Managers, Makers, Micro-Businesses, and The Trades
The first volume in the Threads of Legacy series — a complete AI-enhanced genealogy and heritage travel system by Victor L. Berardi, Ph.D.
Irish Roots, Ancestral Roads guides you from surname to townland through Ireland's civil registrations, parish registers, and the newly released 1926 Census — then from the archives to the ancestral landscape itself, with a 14-day framework of reflective heritage travel for every voice in your family.
Whether you carry a full paper trail, a lifetime of stories, or only a DNA result, this book meets you where you are.
Irish Roots, Ancestral Roads: A Guided AI-Enhanced Genealogy and Heritage Travel System

— a community learning center and knowledge sovereignty enterprise for the AI Age. The SAFE-AI framework helps every learner — researchers, students, educators, professionals, and communities — use artificial intelligence as a tool that amplifies their own thinking rather than replacing it.
Copyright © 2026 TheSOLE.Institute - All Rights Reserved.