Safety
Autonomy that earns each key and hands it back on request.
A Compute World Model does not only predict. It acts.
An AI compute engineer decides what runs where, on real machines, carrying real traffic. That is why safety here is architecture rather than policy.
We build the thing that says no before we build the thing that acts.
Authority is granted in stages
Observe. Recommend. Shadow. Canary. Bounded action. Broader authority.
Each rung is gated on measured reliability. You set the rung, and you move it in either direction, at any moment, for any reason.
That is what autonomy means when it is built correctly. Not a system you hand the keys to.
A system that earns each key and hands it back on request.
The boundary is independent by construction
Declared limits are enforced continuously, from outside the learned model, and anything leaving the envelope escalates immediately.
A model that is wrong about a machine is also wrong about its own safety margin. A boundary built inside the model fails in precisely the case it exists for.
Independence is the design.
Every kernel is verified before it executes
Generated code is checked for semantic equivalence against a reference before it reaches silicon. The model proposes. An independent check decides, and it does not care how confident the model was.
Speed that changes the answer is not speed.
Reversibility is what lets this move fast
Every action is bounded and undoable: a slice of traffic, measured against a preserved baseline, kept or reversed.
That is what makes trying unfamiliar hardware something you do casually rather than commit a quarter to. It is the same mechanism that makes the system safe to grant authority to.
Reversibility is not a brake on the vision. It is why the vision can be pursued at speed.
Neutrality is a safety property
When frontier capability runs on one supply chain, a single decision anywhere in that chain becomes a decision about who is allowed to build.
Compute World Models run on whatever silicon exists. That turns a dependency into a choice.
We hold no silicon and take no vendor design seat.
A placement layer with a stake in the outcome is not a placement layer.
What we are building toward
A compute layer understood the way we understand weather, or markets, or the structure of a protein. Modeled well enough to predict, predicted well enough to act.
Operated safely enough that no one who owns the machines has to wonder what it will do next.