Safety

Autonomy that earns each key and hands it back on request.

A Compute World Model does not only predict. It acts.

An AI compute engineer decides what runs where, on real machines, carrying real traffic. That is why safety here is architecture rather than policy.

We build the thing that says no before we build the thing that acts.

01 / Safety

Authority is granted in stages

Observe. Recommend. Shadow. Canary. Bounded action. Broader authority.

Each rung is gated on measured reliability. You set the rung, and you move it in either direction, at any moment, for any reason.

That is what autonomy means when it is built correctly. Not a system you hand the keys to.

A system that earns each key and hands it back on request.

02 / Safety

The boundary is independent by construction

Declared limits are enforced continuously, from outside the learned model, and anything leaving the envelope escalates immediately.

A model that is wrong about a machine is also wrong about its own safety margin. A boundary built inside the model fails in precisely the case it exists for.

Independence is the design.

03 / Safety

Every kernel is verified before it executes

Generated code is checked for semantic equivalence against a reference before it reaches silicon. The model proposes. An independent check decides, and it does not care how confident the model was.

Speed that changes the answer is not speed.

04 / Safety

Reversibility is what lets this move fast

Every action is bounded and undoable: a slice of traffic, measured against a preserved baseline, kept or reversed.

That is what makes trying unfamiliar hardware something you do casually rather than commit a quarter to. It is the same mechanism that makes the system safe to grant authority to.

Reversibility is not a brake on the vision. It is why the vision can be pursued at speed.

05 / Safety

Neutrality is a safety property

When frontier capability runs on one supply chain, a single decision anywhere in that chain becomes a decision about who is allowed to build.

Compute World Models run on whatever silicon exists. That turns a dependency into a choice.

We hold no silicon and take no vendor design seat.

A placement layer with a stake in the outcome is not a placement layer.

06 / Safety

What we are building toward

A compute layer understood the way we understand weather, or markets, or the structure of a protein. Modeled well enough to predict, predicted well enough to act.

Operated safely enough that no one who owns the machines has to wonder what it will do next.