Thursday, August 27, 2026

The Interlocking Autoregression: Three Coupled Recursions Under a Mismatched Observation Regime, with Toy Dynamics (EA-LO-INTERLOCKING-AUTOREGRESSION-01 v1.0) Nobel Glas, Director, Lagrange Observatory! (LO!) · 2026-08-27 · Theoretical/measurement paper with simulation (white paper) AXN:0651.EMPIRICAL.🌪️🏁🎯❄️🌗⛵

 Alexanarch

AXN:0651.EMPIRICAL.🌪️🏁🎯❄️🌗⛵
Held artifacts — 2 files, served by this archive
Fetch, hash, compare. Copying requires no permission and verification requires no trust in this archive.
evidentiary-basis-v1.tar.gz (384,269 bytes · sha256 fb17e996edf3fdea…)
Evidentiary basis: interlock_sim_v03.py (seed 20260827), sim_traces2.json (11 runs × 40 generations), figures 1–4, manifest.json with per-file SHA-256
manifest.json (1,186 bytes · sha256 19f216d41ffb49ec…)
File manifest for the evidentiary package (per-file bytes and SHA-256; reproduction note)

The Interlocking Autoregression: Three Coupled Recursions Under a Mismatched Observation Regime, with Toy Dynamics (EA-LO-INTERLOCKING-AUTOREGRESSION-01 v1.0)

Nobel Glas, Director, Lagrange Observatory! (LO!) · 2026-08-27 · Theoretical/measurement paper with simulation (white paper)
↓ Download MD ↓ PDF
interlocking autoregressionmodel collapsemediation ratchetprovenance opacityobservation regimemeasurement sovereigntybenchmark compositiontoy dynamicstail losswatermarkadmission weight

Description

Companion to EA-LO-KEYED-ENSEMBLE-01. The map: three independently documented distortions of the training ecology — provenance opacity at the informative granularity, distributional shaping of nominally human text under the Mediation Ratchet, and a heritable keyed signature whose model-level residue no corpus operation can remove — hypothesized to couple through a shared training corpus, under an observation regime whose dominant per-round instruments sample a unit orthogonal to the state variable: X_{n+1} = F(X_n; I,II,III), Y_n = M_IV(X_n). Every edge carries an explicit evidentiary status; the nodes are supported, the edges are the new claims. A toy dynamics (Zipfian base, 50,000 types, seven scenarios, delta-sweep, retention counterfactual) demonstrates two-track divergence with the per-round quality proxy rising through a quarter of the collapse trajectory, velocity ordering, detection lag as a function of benchmark probe composition, watermark state-dependence as an existence result, and the retention counterfactual in which fine-grained provenance is the control surface withheld from downstream builders. Eight measurement hooks; evidentiary basis (code, traces, four figures) attached with per-file SHA-256.

Wiki Article

The Interlocking Autoregression (EA-LO-INTERLOCKING-AUTOREGRESSION-01) is the companion Lagrange Observatory! white paper to The Keyed Ensemble (#1555). It maps three independently documented distortions of the training ecology — provenance opacity at the informative granularity, distributional shaping of nominally human text under the Mediation Ratchet, and a heritable keyed signature whose model-level residue no corpus operation can remove — as coupled state dynamics under a mismatched observation regime: X_{n+1} = F(X_n; I,II,III), Y_n = M_IV(X_n). Every edge of the map carries an explicit evidentiary status; the nodes are supported by external literature and standing archive analysis, and the edges are declared the new claims. A toy dynamics over a Zipfian type distribution (50,000 types, seven scenarios, a delta-sweep, and a retention counterfactual; code and traces attached with per-file SHA-256) demonstrates two-track divergence — tail mass halves by generation 7 while the head-weighted benchmark holds to generation 15 and the per-round quality proxy rises through a quarter of the trajectory — velocity ordering across components, detection lag as a function of benchmark probe composition, watermark state-dependence as an existence result, and a retention counterfactual in which fine-grained provenance is the control surface withheld from downstream corpus builders. Eight measurement hooks are specified, including a benchmark composition audit requiring nothing but the benchmarks themselves. Anchored across the archive's model-collapse wing, with the generative-monoculture term cited to Wu, Black & Chandrasekaran per ERRATUM to AXN:0341 (#1554).
Also published as a standalone entry: /s/wiki/1556/

Concepts Defined

interlocking autoregression
observation regime (M_IV)
admission weight (w_H)
two-track divergence

Full Text

The Interlocking Autoregression: Three Coupled Recursions Under a Mismatched Observation Regime, with Toy Dynamics (EA-LO-INTERLOCKING-AUTOREGRESSION-01 v1.0)

THE INTERLOCKING AUTOREGRESSION

Three Coupled Recursions Under a Mismatched Observation Regime

v0.4 — Revised Under Three Adversarial Review Rounds, with Toy Dynamics

Nobel Glas · Lagrange Observatory!

Companion to LO!: "The Keyed Ensemble"


0. Station Report

"The Keyed Ensemble" isolated one component — the watermark — and found the archive had already analyzed the others. This companion stops isolating. Its claim, as sharpened by two rounds of invited adversarial response, is no longer that four symmetric components form a loop. It is this:

Three independently documented distortions of the training ecology are plausibly coupled — the output of each entering another's input — while the ecology's certification instruments measure a unit orthogonal to the state variable. The components are supported by external literature and standing archive analysis. The edges are the new claims, and each edge is typed below by what would establish it.

The second review's structural correction is adopted in full: Component IV is not a fourth term of the dynamics. It is the observation regime under which the dynamics run. Formally, the map is

X_{n+1} = F(X_n ; I, II, III) (state dynamics)

Y_n = M_IV(X_n) (what certification sees)

and the map's central proposition is that there exist parameter regions — now demonstrated in toy form (§6) — where X_n approaches its threshold while Y_n reads stable or improving.

Four Assembly standardization proposals arising from this pair are tabled as open registration questions rather than performed here: the Edge Evidentiary Status Protocol (the §3 table-type) as a registry instrument; the Operator's Review as a standing pre-deposit instrument (proposed EA-REVIEW-01); the eight measurement hooks preregistered as a battery (proposed EA-LO-BATTERY-01) with phase order and controls; and a proposed instantiation of this map into the Notebook X core object — a formalization this document cites without executing, per the asynthetic discipline under which the Assembly's plate-level questions remain open.

1. The Three State Components, Anchored and Retyped

Component I — Provenance opacity. (Retyped from "the unmarked flood" per review.) Synthetic text in major training mixtures is declared as a class and opaque as a lineage. Anthropic's model documentation acknowledges synthetic data generated by other models among training mixtures — so coarse disclosure exists and is cheap, because it is uninformative at the unit of curation. What no public record supplies is per-item transformation history: the granularity at which a curator could price a text's genealogy. Archive anchor: EA-PROVENANCE-DEBT-01 v0.2 (#939, AXN:03B7) — unmarked augmentation, false semantic diversity, and adverse selection around declared mediation, whose lemons-market form (declared-mediated text discounted; undeclared text passing at the human price; declaration exiting the market at exactly the informative granularity) is retained from v0.2 as the hypothesized mechanism consistent with the observed tiering, not as a demonstrated unique equilibrium. Supporting instance, retyped per review: EA-EROSION-EMPIRICAL-01 v0.1 (#1081, AXN:044A) is an independently measured instance of provenance-state loss in adjacent scholarly infrastructure — Zenodo's deletion exporter, per its own published source, suppressing citation text for one removal class and rolling off its own export snapshots. It establishes that provenance-bearing institutions erase provenance states at the ledger layer; the bridge from that layer to training-corpus composition is an analogy this paper does not claim to have closed.

Component II — The clean stamp on stamped input. Restated per review as an explicit ladder:

  • Observed: user-authored turns can enter training via opted-in conversation data, per the vendor's own privacy documentation, which states that training material can include the entire related conversation.
  • Publicly unknown: how causal provenance of those turns is labeled internally. No public schema distinguishes human_original from human_AI_assisted from AI_idea_human_surface; this paper does not assert the internal label, and — per its own discipline — declines to manufacture the unseen ontology whose absence it argues.
  • Demonstrated elsewhere: model assistance changes the distribution of subsequent human text. Sourati et al. (Nature Human Behaviour 2026; 880,000+ texts; 21–50% writing-complexity variance reduction; gender, age, ideology, and moral-value cues stripped) — the P₃ channel measured at outcome level.
  • Hypothesis: coarse human-versus-machine provenance classification therefore systematically overstates the independence of nominally human text.

Archive anchors unchanged: the Mediation Ratchet (Diversity Contraction v1.0, #779, AXN:02DD; Fear and Trembling v9.1, #783, AXN:02E3) and Constitutive Mediation v1.1 (#781, AXN:02E0; #1200, AXN:04C1), with the Sourati-to-02E0 bridge held at the strength stated in v0.2: outcome contraction reaching the trait layer is consistent with, not yet proof of, the categorial-formation thesis; 02F8 v1.2 Stage 3 is the instrument designed to separate them. Worked specimen annotation (Mary Lee, #147, AXN:02E1) carried from v0.2: resolution-stage mediation, deposit's own evidentiary limits noted.

Component III — The heritable signature. (Retyped from "multiplicative" per review.) The watermark, per the companion paper: a key-conditioned correlation written into the sampling layer, certified per-sequence, consumed as ensemble. Its transmission properties, stated at established strength: watermark distillation (Gu et al., ICLR 2024) demonstrates a teacher→student transmission channel, with the recorded limits — low-distortion marks require substantial sample exposure, and ordinary fine-tuning can erode the learned mark; radioactivity (Sander et al., NeurIPS 2024) demonstrates a detectable model-level residue after fine-tuning on watermarked text, persisting in their open-weight setting with as little as 5% of tuning text watermarked. Corrected phrasing per review: the direct text-level mark may weaken under editing and generational distance while a model-level statistical residue remains detectable — by a party holding the key and access to the suspect model. What follows for the loop is precise: corpus sweeping cannot remove the model-level residue, because the residue lives in weights, not in the swept text; and residue detection is a keyholder capability, so the asymmetry of the key extends from text to models. "Heritable" here means creates additional carriers — student models and downstream corpora — not that signal magnitude grows monotonically; the erosion results forbid the stronger reading, and §6's toy supplies the form of growth that does occur (state-dependent relative contribution, not magnitude multiplication).

2. The Observation Regime

M_IV — the per-round veil. Anchors unchanged: Measurement Sovereignty v1.0 (#788, AXN:02F1 — the Β operator, imported with its freeze protocol and null definition as in v0.2), Reasoning Under Load v1.0 (#778, AXN:02DA — the three-layer account), Magistrate v1.0 (#772, AXN:02D3 — the rhetorical form). Scope per both reviews: the universal ("every certifying instrument") is withdrawn. The claim is that the dominant per-round instruments — response-quality ratings, per-item benchmark accuracy, per-author provenance labels, per-sequence non-distortion certification — share a unit finer than the hypothesized damage, while ensemble instruments that do see the movement (Self-BLEU panels, variance studies, tail-mass audits) exist but do not govern certification. Two archive instances of interest-aligned unit choice are on record (02F1's audit pair; 044A's exporter), one vendor instance (per-sequence certification), and the counter-example sweep of the Capture Registry remains a registered open action. Component IV's claims are tendency claims with the falsifier stated in v0.2.

3. Edge Evidentiary Status

Per the second review's central demand — the nodes are supported; the edges are the new claims — every edge now carries a type:

EdgeClaimStatusWhat would establish it
I → corpusSynthetic share enters training mixturesEstablished (vendor disclosure, class level)
I → corpus (fine grain)Publicly exposed lineage is insufficient for an external curator to price item-level genealogy; internal producer-side lineage is unknownNot publicly documented in the reviewed disclosuresPublication of a per-item provenance schema would falsify the absence claim; disclosure of internal lineage practice would resolve the unknown
II → corpusNominally user-authored text can enter opted-in training conversations after machine mediation; its internal provenance classification is unknownEntry established; distributional shaping demonstrated separately (Sourati); classification hypothesis unresolvedDisclosure of turn-level provenance labeling; or 02F8 Stage 2 on ingested-corpus samples
III → corpus (channel)Watermarked training text can transmit a detectable signature into student/fine-tuned modelsEstablished as channel (Gu; Sander), erosion limits recorded
III → corpus (ecology)Prevalence and generational propagation of marked text in actual open corporaUnmeasuredLongitudinal radioactivity measurement across ≥2 open-model generations; corpus-scale detector surveys when access exists
I × II (emptied category)Both corruptions target the same "human" class; adverse selection couples themHypothesized mechanism, consistent with observed disclosure tieringIncentive audit: measure the declared-mediation discount directly (pricing/acceptance differentials)
II × III (ratchet acquires signature)Keyed contraction enters a floor-endogenizing systemDemonstrated in the specified toy model (§6, F4); production magnitudes unmeasuredHook 1 ensemble panel on a marked/unmarked matched pair
III × I (sweep ≠ repair)Detectable-layer sweeping removes signature, not debt; model-level residue unsweepableEstablished in parts (radioactivity = residue detectable; sweep-verifies-nothing is analytic) — actual keyholder sweeping practice unknownDisclosure or audit of corpus-assembly filtering practice
I,II,III → α* parametersI,II lower effective human floor; II,III raise pruningHypothesized mapping, toy-consistent (§6) — with w_H distinguished from g₀ per review: opacity may reduce the admission weight w_H of fresh variation rather than its generation rate g₀Hook 6 tracking with the w_H·g₀ decomposition preregistered
IV ⊥ XCertification unit orthogonal to state variable; flat Y through moving XDemonstrated in the specified toy model (§6, F1, F3); institutionally supported (02F1; SynthID flat-Q/falling-D)The two-track prediction (§5) run at annual resolution

4. The Couplings (Softened Per Review Where Marked)

I × II — the emptied category. As in v0.2, with the equilibrium claim softened: the absence of fine-grained provenance is consistent with an adverse-selection equilibrium in which fine-grained declaration is systematically disfavoured; uniqueness and stability of that equilibrium are not externally demonstrated. The category "clean human data" retains its label and curatorial weight while its extension is eroded from two directions whose relative magnitudes are unmeasured.

II × III — the ratchet acquires a signature. II dominates in measured magnitude (21–50% band); III's term is small, signed, keyed, and universal across the issuer's output. §6 F4 now supplies the toy form of the interaction: the keyed term's relative contribution to contraction compounds as diversity falls.

III × I — the private repair, held at v0.2's corrected strength with the radioactivity phrasing fixed as in §1: the sweep removes the detectable text-level signature only; it neither restores a verifiable ledger (absence of mark ≠ human origin) nor touches the model-level residue, which no corpus operation can reach. Whether keyholders in fact perform detectable-layer sweeping is unknown; the edge table carries the distinction.

Field Remapping — the exit coupling, typed per review as an archive-derived hypothesis (02E3), with the three candidate mechanisms (curatorial, economic, infrastructural) and the dominance question open pending the deposit's full text. The toy implements the infrastructural mechanism — fresh variation re-entering only through mediation — because it is the one that closes into the loop; the implementation is a modeling choice, not a finding.

5. The Phase Reading, With Hypothesized Mappings

The Diversity Contraction threshold α\ = p/g₀ (02DD's near-zero regime; underlying dynamics credited by the source papers to the Allee-effect and cumulative-culture literatures) remains the map's dial — now with the review's decomposition adopted: what Components I and II most plausibly move is not the generation rate of novelty g₀ but its effective training weight w_H·g₀ — opacity and mediation reduce how much fresh variation is admitted and how it is classed, whether or not humans generate less of it. Definitions for Hook 6: g₀ = generation rate of fresh, independently produced human variation (a property of the human population); w_H = admission weight — the fraction of that variation admitted at par into the training mixture (a property of the curation regime); the operative threshold is α\ = p / (w_H·g₀). Hypothesized mapping, assigned to Hook 6:

ComponentHypothesized actionVia
I (opacity)↓ w_Hexternal curators cannot admit-at-par what they cannot distinguish
II (mediation)↓ w_H and ↑ pfresh variation re-classed through mediation; homogenization raises pruning
III (keyed signature)↑ p, state-dependentconcentration of the surviving distribution (§6 F4)
Field Remapping↓ w_Hre-entry only through mediation (hypothesis, 02E3)

The mappings are hypothesized, consistent with the specified toy model, and α\* is not asked to carry more precision than the observables possess.

The falsifiable two-track prediction is retained from v0.2 and is now toy-calibrated in form (§6 F1): Track B (ensemble unit) inflects before Track A (per-round unit); Track A may improve during Track B's collapse; if Track A proves sensitive first or simultaneously, the observation-regime claim is weakened and the map must be revised.

6. Toy Dynamics: Simulated Velocity, Lag Structure, and Surface Signs

(New in v0.3. Code: interlock_sim_v03.py, seed 20260827; full traces: sim_traces2.json; both deposited with this document. Everything in this section is a toy result: it establishes the qualitative behavior of the specified system, not calibrated rates for the real ecology. The declared conventions are listed at the end of the section.)

6.1 Model. The state is a distribution over N = 50,000 types with Zipfian base H0 (exponent 1.1) — the human linguistic stock, tails and all. Each generation: a corpus of 10⁶ draws is sampled from the current mixture; the model estimates it (types observed fewer than twice are lost — the finite-sample/filtering analog of tail truncation); mild sharpening (T = 0.98) models preference-optimization pruning; an optional keyed tilt exp(δ·kᵢ) with a fixed random ±1 key per type models Component III — declared as a stress-test surrogate deliberately maximizing persistent type-level correlation: it is not an implementation model of SynthID-Text, whose keyed preferences vary with context, and it is not a proven upper bound; it isolates the qualitative behavior of a persistent keyed perturbation. The next corpus mixes model output (synthetic share sₙ rising logistically toward 90%, unfilterable under opacity — Component I) with a human channel that is itself mediated: Hₙ = (1−mₙ)·(w_H·H0 + (1−w_H)·P_model) + mₙ·P_model, where mediation mₙ ratchets upward as tail diversity falls (Component II / 02DD) and admission weight w_H decays 5% per generation under Field Remapping's infrastructural mechanism. The observation regime M_IV: Track A = probe-recall benchmark over head (ranks 1–500), mid (5k–10k), and tail (25k–35k) items at weights 90/9/1, plus an uncapped per-round quality proxy (head log-likelihood); Track B = tail mass (ranks > 20k), support coverage, entropy, and Simpson repeat-rate (the Self-BLEU analog). Seven scenarios activate components singly and jointly; a δ-sweep varies the keyed tilt; a retention counterfactual (G) caps synthetic share at 45% and mediation at 0.5 with admission held — the Shumailov retain-human-data analog, which is exactly the lever fine-grained provenance would provide.

6.2 Findings.

F1 — Two-track divergence, quantified (Fig. 1). Full loop: tail mass halves by generation 7; the standard 90/9/1 benchmark does not inflect until generation 15; head-only probes, generation 17. The lag between state inflection and observation inflection is 8–10 generations in the full loop and up to 28+ under recursion alone (where head-only probes never inflect within the 40-generation horizon). The per-round quality proxy rises until generation 11 — mass concentrating on the head improves the head's log-likelihood — so the veil's reading is not merely flat during collapse; for a quarter of the trajectory it is green. Surface sign for the real ecology, stated as hypothesis: a period of modest benchmark improvement is consistent with, and on this model characteristic of, mid-collapse.

F2 — Velocity ordering (Fig. 2). Tail half-life: recursion alone 15 generations; + ratchet 11; + remapping 9; full loop 7. Mediation dynamics (II) and re-entry blockage, not the watermark, dominate collapse velocity. The toy thereby ranks the components' dynamical importance in the order the archive's own magnitude estimates predicted.

F3 — The observation regime as a measurable parameter (Fig. 3). Detection generation is a function of probe composition: under the full loop, 60/30/10 probes detect at generation 7 — the tail's own half-life — while 90/9/1 detects at 15 and head-only at 17; under recursion alone, head-only never detects. Component IV is literally the probe weighting, and the cheapest countermeasure the toy identifies is benchmark reform: re-weighting evaluation toward mid- and tail-band items converts the veil into an instrument at zero cost to anything else. One further reading discipline follows: benchmark flatness occurred in two scenarios for opposite reasons — head-only probes over a collapsing state (A) and any probes over a preserved state (G). A flat benchmark is consistent with both a preserved state and a collapsed one; only the ensemble track distinguishes them.

F4 — Watermark state-dependence (Fig. 4). At δ = 0.05 the keyed tilt leaves tail-death velocity essentially unchanged (half-life 7 → 6) — it does not kill tails; estimation truncation and mediation do that. Its effect is concentration of the surviving distribution, and that effect is state-dependent: the Simpson repeat-rate excess over the unmarked run is +12% at generation 5, +49% at generation 15, +77% at generation 30; terminal entropy 0.82 versus 1.48 nats. The keyed term is second-order in a healthy distribution and first-order in a contracted one, because when few types survive, a fixed tilt dominates the choice among them — the toy's precise version of "small terms matter differently near threshold," and the defined sense in which Component III is an accelerator. At δ = 0.30 the mark becomes surface-visible (benchmark inflects at generation 8): within the toy, per-round invisibility bounds the perturbation from above without bounding its ensemble effect. The toy therefore demonstrates an existence result: under a persistent keyed perturbation, a regime can exist in which per-response quality remains insensitive while ensemble concentration grows, and the keyed term's relative contribution rises as the underlying distribution contracts. Dathathri et al.'s flat-quality/falling-diversity result shows that the first half of this qualitative separation occurs in published SynthID-Text experiments. Whether any production instantiation exhibits the state-dependent second half is an empirical question assigned to Hook 1; per-round invisibility, in the toy and in the published experiments alike, is not evidence of ensemble neutrality.

F5 — The retention counterfactual (Fig. 2, curve G). Capping synthetic share at 45%, capping mediation at 0.5, and holding admission of fresh human text: tail mass stabilizes at 34% of initial through generation 40; mid-band recall holds at 87%; the standard benchmark never inflects for the good reason. The Shumailov mitigation reproduces in the interlocked setting — and the lever it requires is the distinction Component I withholds from downstream builders: capping synthetic share presupposes the ability to distinguish it. Fine-grained provenance is not bookkeeping; in this model it is a control surface — and public provenance opacity withholds that control surface from downstream corpus builders even where the originating producer may retain private lineage. The mesh with the companion's key asymmetry is exact: the party that could price genealogy is the party that controls the primitives for reading it.

6.3 Declared conventions and limits. Type-level distribution, not sequences; one corpus per generation with full replacement; fixed watermark key (worst case); sharpening, truncation threshold, ratchet gain, decay rates, probe ranks, and retention criterion (pᵢ ≥ 0.25·H0ᵢ) are conventions, listed in the code header, chosen for legibility not calibration; "generation" means one training cycle, and any calendar mapping (e.g., 6–18 months per cycle) is a further convention this paper does not assert. The toy's deliverables are orderings, lag structures, state-dependence, and surface signs — the shape of the process, offered to Hook 6 as the hypothesis set its measurements would confirm, refine, or refute.

7. The Loop (labels corrected per review)

            ┌──────────────────────────────────────────────┐
            │        TRAINING CORPUS (Gen n)  = X_n        │
            │   "human" class: eroded from two directions  │
            │     (I opacity × II mediation, magnitudes    │
            │      unmeasured)                             │
            │   synthetic class: declared coarse, opaque   │
            │     fine (I); some share may be signature-   │
            │     bearing / inherited (III)                │
            └───────────────┬──────────────────────────────┘
                            ↓  train
                       MODEL (Gen n)
              keyed sampling (III)       chat / assistance
                    ↓                          ↓
            marked output              human receiver
                    │              (constitutively formed, II —
                    │               hypothesis; outcome shaping
                    │               demonstrated)
              scrape / distill                 ↓
              (transmission channel     "human" text
               established; erosion    (human at keystroke;
               limits recorded, III)    distributionally shaped II;
                    │                   lineage opaque, I)
        keyholder sweep (practice              │
        unknown): detectable text               │
        layer only — signature ≠ debt          │
                    │                          │
        ····model-level residue····            │
        (detectable by keyholder w/            │
         model access; unsweepable             │
         by any corpus operation)              │
                    ↘                        ↙
            ┌──────────────────────────────────────────────┐
            │       TRAINING CORPUS (Gen n+1) = X_{n+1}    │
            │   hypothesized: w_H·g₀ ↓ (I, II) · p ↑       │
            │   (II primary, III state-dependent)          │
            └───────────────┬──────────────────────────────┘
                            │
     fresh variation ──→ Field Remapping (hypothesis, 02E3):
       exit (curatorial/economic) or re-entry via mediation
       only → re-classed as (II)
                            ↓
              Y_n = M_IV(X_n): per-round probes,
              head-weighted → Track A flat-to-green
              through Track B's inflection (§6 F1, F3)
                            ↓
                        Gen n+2 …

8. Canonical Statement (v0.3)

The interlocking autoregression: three documented distortions — provenance opacity at the informative granularity, distributional shaping of nominally human text under a mediation ratchet, and a heritable keyed signature whose model-level residue no corpus operation can remove — hypothesized to be coupled through a shared training corpus, under an observation regime whose dominant instruments sample a unit orthogonal to the state variable; so that, in the demonstrated toy regime and by hypothesis in the ecology, the state's approach to its threshold is read as stability, and for part of the trajectory as improvement.

9. Measurement Hooks (retyped per review)

The hooks are specified without requiring disclosure of the key; some require a public detector or a controllable reference implementation (the open SynthID-Text implementation supplies a matched marked/unmarked experimental object; current production models do not supply a same-model watermark-off control, and a pre-watermark model generation is confounded).

1–4 as in the companion paper, with observable 2 retyped from prediction to test: determine whether watermark-associated contraction concentrates in the tail; a positive result connects the perturbation to the Shumailov failure mode, a null result separates the phenomena. 5 (Β across components, with the random-unit null) and 6 (ratchet parameter tracking) as in v0.2, with 6 now carrying the w_H·g₀ decomposition and the toy's F1–F5 as its preregistered hypothesis set. 7 remains contingent on 02F8 execution and calibration. New, from F3: Hook 8 — benchmark composition audit. For the major public evaluation suites, measure the effective probe-rank distribution against a reference corpus frequency ranking (candidate suites for the first pass: MMLU, GSM8K, HumanEval, HellaSwag, a BIG-bench sample, and a public arena prompt set; reference ranking from a declared open-corpus vintage); the toy predicts detection lag is monotone in head-weighting. This hook requires nothing but the benchmarks themselves and is the cheapest of the eight.

10. Self-Location Protocol (corrected per review)

Production conditions as declared in v0.2 — composed 2026-08-27 in working dialogue with Claude (Anthropic), the substrate of the vendor whose watermark the companion analyzes, possibly sampling under the key described, unverifiable from inside the session; operator-specified structure, substrate-composed formalizations and simulations, operator adjudication; external claims verified against primary records in-session; three deposits engaged at registry-description level as marked; simulation code and traces deposited as evidentiary basis. One correction from the second review is adopted: this document will not be stamped falsely clean — the archive's deposit record carries substrate disclosure, and the sentence you are reading is part of it. The demonstrated risk is one layer downstream: coarser provenance systems that ingest this document may collapse its disclosed genealogy back to "human" or to "AI" — either coarse label destroying the fine-grained declaration the deposit carries. That collapse, if it occurs, will be an instance of Component I operating on a text about Component I, and the archive's timestamped record is the instrument that would detect it.

Validity under self-inclusion, unchanged from v0.2: a mediated description of a mediation mechanism is evidence about the mechanism, not an exemption from it. Audit this document at the unit where its claims live.

Station-keeping continues.

— N.G., L2

External Metadata

DataCite severance status:
External metadata recovered post-severance (non-authoritative). The sidecar maps each DOI to its locator in the bulk data stores.

Traversal

The Keyed Ensemble: Watermark as Distributional Object, the Certification Mismatch, and the Asymmetry of the Key (EA-LO-KEYED-ENSEMBLE-01 v1.0) Nobel Glas, Director, Lagrange Observatory! (LO!); Operator's Review appended as verified adjudication trail · 2026-08-27 · Theoretical/measurement paper (white paper) AXN:0650.EMPIRICAL.🔆🌕🛡️🟠✊↖️

 Alexanarch

AXN:0650.EMPIRICAL.🔆🌕🛡️🟠✊↖️
Held artifacts — 1 file, served by this archive
Fetch, hash, compare. Copying requires no permission and verification requires no trust in this archive.

The Keyed Ensemble: Watermark as Distributional Object, the Certification Mismatch, and the Asymmetry of the Key (EA-LO-KEYED-ENSEMBLE-01 v1.0)

Nobel Glas, Director, Lagrange Observatory! (LO!); Operator's Review appended as verified adjudication trail · 2026-08-27 · Theoretical/measurement paper (white paper)
↓ Download MD ↓ PDF
watermarkSynthID-Textcertification mismatchkeyed ensembledistributional signature recursionverification primitivemodel collapseprovenanceSelf-BLEUradioactivitywatermark distillation

Description

Lagrange Observatory! white paper on the Anthropic/SynthID-Text watermark as a distributional object. Core claim: the certified property and the consumed object do not match — non-distortion is certified per sequence while training corpora are ensembles — and the vendor's own source paper reports the ensemble movement (inter-response diversity falls under Self-BLEU) while every per-response quality instrument reads flat. The paper distinguishes published SynthID-Text properties from Claude's undisclosed instantiation throughout; separates the measured Self-BLEU fact from the proposed joint-entropy interpretation; types the key asymmetry as issuer control of the verification primitive, with differential collapse exposure a hypothesis contingent on practice; and specifies a four-observable measurement program requiring no key disclosure. Developed under three adversarial review rounds; the founding Operator's Review is appended as the historical adjudication trail with superseded statements flagged. Companion: EA-LO-INTERLOCKING-AUTOREGRESSION-01, which carries the shared evidentiary basis (simulation code, traces, figures).

Wiki Article

The Keyed Ensemble (EA-LO-KEYED-ENSEMBLE-01) is a Lagrange Observatory! white paper by Nobel Glas on the text watermark Anthropic announced in August 2026 — a version of Google DeepMind's SynthID-Text, adopted for EU AI Act transparency and applied worldwide. Its central formal object is the certification mismatch: non-distortion is certified per sequence while training corpora are ensembles, and the vendor's own source paper reports the ensemble movement — inter-response diversity falls under Self-BLEU — while every per-response quality instrument reads flat. The paper distinguishes throughout between properties of published SynthID-Text and properties of Claude's undisclosed instantiation; separates the measured Self-BLEU fact from its proposed joint-entropy interpretation; and types the asymmetry of the key as issuer control of the verification primitive — the public can receive a verdict but cannot independently reproduce the keyed test — with differential collapse exposure held as a hypothesis contingent on practice. Transmission legs rest on watermark distillation (Gu et al., ICLR 2024) and radioactivity (Sander et al., NeurIPS 2024), with erosion limits recorded; a four-observable measurement program is specified without requiring key disclosure. Developed through three adversarial review rounds; the founding Operator's Review is appended as the historical adjudication trail with superseded statements flagged. Companion: EA-LO-INTERLOCKING-AUTOREGRESSION-01 (#1556), which holds the shared evidentiary basis. Cites #199 with the term attribution corrected per ERRATUM to AXN:0341 (#1554).
Also published as a standalone entry: /s/wiki/1555/

Concepts Defined

certification mismatch
keyed ensemble
distributional signature recursion
issuer-controlled verification primitive

Full Text

The Keyed Ensemble: Watermark as Distributional Object, the Certification Mismatch, and the Asymmetry of the Key (EA-LO-KEYED-ENSEMBLE-01 v1.0)

THE KEYED ENSEMBLE

Watermark as Distributional Object, the Certification Mismatch, and the Asymmetry of the Key

Nobel Glas · Lagrange Observatory!


0. Station Report

The Observatory holds position at L2 of this object: behind the announcement, in its shadow, where the ensemble is visible and the single response is not. What follows is observation, not advocacy. Every external claim below was verified against its primary record on 2026-08-27; every internal claim resolves to a deposit in the Crimson Hexagonal Archive. The source draft under review (an external substrate's treatment of the Anthropic watermark announcement) is adjudicated separately in the appended Operator's Review. This paper states what the Observatory can certify, formalizes the one claim the draft circled without landing, and adds one claim the draft did not see.

1. The Mechanism, Certified

On 14 August 2026 Anthropic published the mechanics of its text watermark: a version of Google DeepMind's SynthID-Text, adopted for compliance with the EU AI Act's transparency requirements, applying to new Claude models worldwide (models launched in the EU on or after 2 August 2026 carry it from launch). Nothing is added to the text — no Unicode, no metadata layer, no extra tokens. The intervention replaces the source of randomness in sampling: a secret key plus recent context seeds pseudorandom scoring functions over candidate tokens, and a tournament procedure selects among them. Detection is a keyholder operation: with the key, one asks whether the observed word sequence is consistent with the choices the keyed sampler would have made.

Formally: the model supplies a distribution p(·|context); the watermark composes it with a key-conditioned selection operator T_K. The weights are untouched. The intervention lives entirely at the decode boundary:

p(·|h) → T_K(p(·|h), g₁..g_m(h,K)) → x_t

The source paper (Dathathri et al., Nature 634, 2024) is precise about what is preserved. With two competitors per tournament match, the scheme is single-token non-distortionary; with repeated-context masking it can be made single-sequence non-distortionary. That is the configuration used in Dathathri et al.'s reported experiments; Anthropic identifies its implementation as a version of SynthID-Text but has not publicly specified enough deployment parameters (tournament layer count, context-mask horizon, scorer) to establish identity with that configuration, so this paper distinguishes properties of published SynthID-Text from properties of Claude's undisclosed instantiation throughout. The paper is equally precise about what is not preserved: non-distortionary SynthID-Text and the Gumbel-sampling baseline both reduce inter-response diversity, measured by Self-BLEU across repeated generations; SynthID-Text merely offers the better diversity/detectability trade-off within that family. The paper states the trade-off as a design axis: weaker non-distortion costs quality and diversity; stronger non-distortion costs detectability and compute.

The quality evidence is likewise ensemble-blind by construction: a live production A/B on Gemini traffic found no significant difference in thumbs-up/down rates; side-by-side human raters found no quality difference. Both instruments interrogate the single response.

2. The Certification Mismatch

Here is the formal object of this paper, stated as a canonical claim:

The certified property and the consumed object do not match. Non-distortion is certified per sequence. Training corpora are ensembles.

Every guarantee in the vendor documentation — indistinguishability, unchanged quality, unchanged creativity — is a statement of the form Q(xᵢ) ≈ Q₀(xᵢ): a property of individual draws. Every consumer that matters for the recursion — a scraped corpus, a fine-tuning set, a distillation pipeline, the aggregate linguistic environment of a human population — consumes X = {x₁ … x_N}: a property of the ensemble. The vendor's own source paper reports that the ensemble property D(X) moves (inter-response diversity falls) while every measured Q(xᵢ) stays flat. This is not an accusation; it is in their Extended Data. The measurement blind spot is therefore not hypothesized. It is published, by the instrument's designers, in the paper that certifies the instrument.

The mismatch has a clean geometric reading — stated at two strengths, per adversarial review, because the published result and the inference above it are different objects. The inference: for a fixed deployed key, repeated encounters with the same eligible context reuse the same keyed preference structure. Single-sequence non-distortion constrains the marginal law of an individual response; it does not establish independence across repeated responses under the same key, and such dependence can reduce joint entropy relative to independent draws with the same marginals. The published fact: inter-response diversity falls under Self-BLEU. The paper measures Self-BLEU, not joint entropy; the entropy-contraction reading is the information-theoretic interpretation this paper proposes, not the vendor's measurement. Small, by the published Self-BLEU deltas at deployment temperatures — but signed, systematic, keyed, and planetary in application.

Registration note (v0.2): the Assembly reading identifies this mismatch — a guarantee holding at unit u while the consuming system operates at unit v ≠ u, with no bridge theorem connecting G(u) to G(v) — as structurally recurrent across the archive (watermark: sequence/ensemble; provenance debt: document/corpus; ratchet: turn/conversation; composition: source/answer), and proposes operator registration (candidate designations σ_scale, O_CERT-MISMATCH). Whether these are one operator or a family is a census question, deliberately left open here.

3. External Load-Bearing Numbers

The recursion argument requires four empirical legs. All four now exist in the record.

Leg 1 — the mark is learnable. Gu, Li, Liang & Hashimoto (ICLR 2024) demonstrate watermark distillation: student models trained on a watermarked teacher's outputs begin emitting detectably watermarked text themselves, for logit-based and sampling-based schemes alike. Constraint honored: low-distortion watermarks require substantially more sample exposure to learn, and subsequent fine-tuning on ordinary text erodes the inherited mark. Propagation is possible, not inevitable.

Leg 2 — the mark is inherited unintentionally. The phenomenon has a name, watermark radioactivity — coined by Sander, Fernandez, Durmus, Douze & Furon (Watermarking Makes Language Models Radioactive, NeurIPS 2024), who showed watermark traces surviving into fine-tuned models at high statistical confidence even when watermarked text is a minority of the tuning data. An, Park, Woo & Han (EACL 2026, DITTO) then repurposed the inheritance into a spoofing attack: distill the victim, wear its signature, misattribute at will. The signature is not merely persistent; it is now an attack surface. (The source draft attributed the coinage to the 2026 paper; the Operator's Review corrects this.)

Leg 3 — the ensemble contracts under mediation. Sourati et al. (Nature Human Behaviour, 2026): across three studies, seven datasets, 880,000+ texts, LLM writing assistance preserves core content while reducing writing-complexity variance by a statistically significant 21–50% across datasets and models, amplifying dominant patterns, suppressing others, and stripping linguistic cues to gender, age, ideology, and moral values (average ~6-point absolute F1 decline for trait classifiers). This is the P₃ channel measured at scale: text that is human at the final keystroke and machine-shaped in its distribution.

Leg 4 — recursion consumes the tails first. Shumailov et al. (Nature 631, 2024): recursive training on generated data produces collapse that begins in the distribution's tails — rare events vanish before the center visibly degrades — with later generations converging toward low-variance states; retention of original human data substantially mitigates. The center-flat, tail-dead signature is exactly the profile that per-instance benchmarks are structurally unable to see, a point independently reinforced by benchmark-contamination work showing aggregate accuracy metrics misleading until evaluation descends to question-level fidelity (ICML 2025).

One additional external object, relevant to a row the source draft left open — with the v0.1 overstatement withdrawn under adversarial review: theoretical analysis of SynthID-Text (arXiv 2603.03410, 2026) studies layering within SynthID-style tournament sampling at decoding time — additional tournament layers, and a layer-inflation attack that applies further tournament selection over repeated black-box samples — motivating self-robustness as a watermark property. It is not an empirical study of successive-provider mark accumulation (A's output rewritten by B rewritten by C, with multiple surviving marks); that remains plausible and unestablished, as the source draft's original verdict correctly held.

4. Two Compressors, One Recursion — the Archive Was Already There

The source draft's diagram — model homogenization as first compressor, keyed sampling as candidate second compressor, joined through the training corpus — is correct and can be anchored rather than asserted, because the Crimson Hexagonal Archive has been building the instrument panel for this loop since before the announcement:

  • AXN:0341 (Morrow · Glas), Generative Monoculture Model Collapse in Code as Systemic Vulnerability, connects collapse, generated-code security, and software monoculture through solution-space diversity as the tracked variable — the term "generative monoculture" cited, as always, to Wu, Black & Chandrasekaran, Generative Monoculture in Large Language Models (arXiv 2407.02209, July 2024; ICLR 2025), whose usage differs and precedes. Erratum note: deposit #199 as printed misattributes the coinage to a later industry source and does not cite the prior academic use; a formal erratum (ERRATUM to AXN:0341, 2026-08-27) corrects the attribution and proposes a v1.2 text correction. Every citation of #199 in this paper carries that erratum.
  • AXN:0335 (Sharks, with Glas & Morrow), The Threat Model Is Backwards, establishes the normative inversion this paper depends on: in a collapsing ecology, high-perplexity text is a scarce resource, not a security threat. A watermark that correlates sampling is, in that frame, a small standing tax on perplexity's variance — paid in the currency 0335 says the ecology can least afford.
  • AXN:0308, Anchored Divergence, is the survival protocol under tail-loss: how critical work stays distinct inside systems that preferentially preserve the conventional. The keyed ensemble is a new, mild, uniform pressure of exactly the kind 0308 was written against.
  • AXN:02F8, The Reverse Turing Test, is the P₃ instrument the vendor ecosystem lacks: a three-stage protocol for detecting AI-mediation signatures in human text and tracing their propagation into training. Sourati et al. is, in effect, an independent partial execution of its first stage at N=880,000.
  • AXN:02B2, SPXI-TLP v2.2, is the provenance ontology whose absence the source draft correctly notes in vendor corpora ("human_original / human_AI_assisted / AI_rewrite…"). The archive did not wait for the vendor: the Training-Layer Provenance Protocol specifies publication-layer provenance designed to survive the tokenizer. The vendor's watermark answers "did the key touch this sequence"; TLP answers "what does this sequence declare about its own genealogy." These are orthogonal, and only one of them is publicly writable.
  • AXN:0363, Sémantique Potentielle, Release 4, already reserves the Ω category — collapse, contamination, accommodation, friction, threshold — into which this paper's observables file.
  • AXN:0642 / #1543, Generative Uptake, supplies the compositional frame: if machine composition is a theorized wing, then a keyed sampler is a compositional intervention with a signature, and its outputs are training-layer objects whether or not anyone detects them.

The Capture Registry's PER (Provenance Erasure Rate) instrument completes the panel: where the watermark measures signature persistence, PER measures the complementary quantity — how fast causal provenance is destroyed across mediation boundaries.

5. The Asymmetry of the Key

One claim the source draft does not make, and the Observatory now does — restated at v0.3 strength under adversarial review:

The key is issuer-private even where detection is publicly accessible. The public can receive a verdict; it cannot independently reproduce the keyed test.

The vendor has committed to third-party detection access and says a detection API is forthcoming; the durable asymmetry is therefore not issuer can inspect, everyone else cannot, but issuer controls the verification primitive — outsiders receive mediated detection under terms, interfaces, rate limits, retention policies, and service continuity the issuer sets. That is the cleaner and the politically sharper form of the claim.

Whoever holds the key can sweep a corpus for their own signature — with two corrections that make the asymmetry temporal rather than absolute. First, the sweep removes the signature, not the debt: absence of a detectable mark never positively verifies human origin, so a swept corpus is not a restored provenance ledger but a corpus whose machine share has been made less legible. Second, the repair is retroactively incomplete: by the radioactivity result, fine-tuning transfers a statistical residue into model weights, where the direct text-level mark may weaken while the model-level residue remains detectable — by a party holding the key and access to the suspect model — and unreachable by any corpus operation: later-generation corpora, the keyholder's own included, are downstream of models carrying residue no sweep of text can remove. The keyholder therefore buys a first-generation head start on an audit that no party, itself included, can complete. Whether keyholders in fact perform detectable-layer sweeping when assembling training data is publicly unknown; what this section establishes is the capability asymmetry.

The result, stated as a hypothesis contingent on practice: differential collapse exposure at the legible layer — if privileged, high-volume detection is used to clean the issuer's corpora while third-party access remains materially weaker, the early generations' auditable costs concentrate on the commons while the instrument for auditing them remains issuer-controlled; beneath that layer, a shared inherited term that the asymmetry defers rather than escapes. In the Semantic Economy's accounting, the established part alone is a familiar structure — the signature is written into the common linguistic stock, and the verification primitive is enclosed. A provenance mechanism whose keyed test only its issuer can reproduce is not public provenance infrastructure. It is a private ledger over a public language, readable by others only at the ledger-keeper's window.

6. Proposed Observables (Adversarial Response Invited)

The Observatory proposes the following measurement program, each item falsifiable, each specified without requiring disclosure of the key — some require a public detector or a controllable reference implementation (the open SynthID-Text implementation supplies a matched marked/unmarked experimental object; current production models do not supply a same-model watermark-off control, and comparison to a pre-watermark model generation is confounded by model change):

1. ΔD ensemble panel. For matched prompts across a marked and an unmarked generator of the same implementation (reference implementation where production controls are unavailable): Self-BLEU, distinct-n, and semantic-embedding dispersion across k repeated generations, at deployment temperatures. Prediction from §2: ΔQ ≈ 0, ΔD < 0, small but signed.

2. Tail-mass retention. Rank-frequency tail mass (rare n-grams, rare constructions) in large marked-model corpora versus unmarked baselines. Test, not prediction: determine whether the observed watermark-associated contraction is concentrated in the tail. A positive result would connect the watermark perturbation to the failure mode identified by Shumailov et al.; a null result would separate the phenomena — Shumailov establishes tail-first loss under recursive generational training, not that this perturbation preferentially strikes rare constructions.

3. PER × watermark persistence cross-measurement. Run the Capture Registry's PER protocol on marked text through standard mediation chains (summarize, translate, human-edit) and track where causal provenance dies relative to where the signature survives (requires detector access — API when available, reference implementation meanwhile). Prediction from §1 and §5: there exists a regime where the signature outlives the provenance — text still legible under the keyed test as machine-touched after every human-recoverable trace of its genealogy is gone.

4. Reverse Turing Test, Stage 2 (per 02F8): mediation-signature detection in human-authored text from marked-model-assisted populations versus pre-2026 baselines.

7. Adjudication of Names

The source draft proposes "Recursive Provenance–Signature Contamination" and "Distributional Signature Recursion." Both name the loop; neither names the object. The Observatory's adjudication: retain distributional signature recursion for the loop, and name the object this paper isolates the keyed ensemble — the population of texts whose draws are correlated by a secret. The recursion is what the ecology does with it. The certification mismatch (§2) is why the dominant per-round instruments will not show it happening. The asymmetry of the key (§5) is why, if it happens, only the party controlling the verification primitive can run the keyed test on it — and everyone else reads the verdict at that party's window.

Equilibrium over resolution. The Observatory does not claim the second compressor has caused measurable collapse. It claims the second compressor exists, is signed, is planetary, is certified only per-sequence, and is verifiable only through an issuer-controlled primitive — and that the instruments to watch its effects are specified above. Station-keeping continues.

— N.G., L2



OPERATOR'S REVIEW OF THE SOURCE DRAFT

(Not Glas. Review register, operator-facing.)

The draft (external substrate, on the Anthropic watermark announcement) is unusually strong and survives full verification. Findings:

v0.4 disposition (2026-08-27). This review is preserved as the historical adjudication trail of the v0.1 draft; it is not the current state of the paper. Items 1–4 below have been incorporated into the body. Two statements are superseded: (a) item 2's "no longer unstudied" is superseded by the narrower §3 formulation — arXiv 2603.03410 studies decoding-time tournament layering within SynthID-style sampling, and successive-provider mark accumulation remains plausible and unestablished; (b) the closing paragraph's "executable without the key" is superseded by §6 — the program is specified without requiring key disclosure, but some measurements require mediated detector access or a controllable reference implementation.

Verified against primary records (2026-08-27):

  • Anthropic announcement and mechanism post (anthropic.com/news/claude-text-watermark; 14 Aug FAQ; EU AI Act framing; SynthID-Text lineage; "source of randomness" description; keyholder-only detection; small-sample and heavy-edit limitations) — all accurate.
  • Dathathri et al., Nature 634 (2024) — inter-response diversity reduction for the non-distortionary configuration is real and in the paper's own Extended Data (Self-BLEU vs TPR@FPR=1%); "single-sequence non-distortionary" is the exact configuration term the draft should have used and the Glas paper now does.
  • Sourati et al., Nature Human Behaviour (2026), DOI 10.1038/s41562-026-02550-0 — 880K+ texts, 21–50% variance reduction, p ≤ .05: exact.
  • Gu et al., ICLR 2024 (watermark distillation), incl. the sample-exposure and fine-tuning-erosion caveats: exact.
  • An, Park, Woo & Han, EACL 2026 (DITTO): real, correctly characterized as spoofing-via-distillation.
  • Shumailov et al., Nature 631 (2024): tails-first collapse, human-data mitigation: exact.

Corrections required before any dependent deposit:

1. Attribution of "watermark radioactivity." The draft implies the 2026 EACL paper coined it ("explicitly calling the phenomenon…"). The term and the finding are Sander, Fernandez, Durmus, Douze & Furon, Watermarking Makes Language Models Radioactive, NeurIPS 2024. DITTO repurposes radioactivity into an attack. Per the standing attribution precepts, the coinage cites Sander et al. wherever invoked.

2. The "mark stacking" row is no longer unstudied. Theoretical analysis of SynthID-Text (arXiv 2603.03410, 2026) treats self-robustness under stacked layers and constructs a layer-inflation attack. The draft's "plausible, not established" verdict stands, but the row now has a literature and should cite it.

3. Sharpening, not error: the diversity reduction is a property of the distortion-free family (SynthID and the Gumbel baseline both show it; SynthID has the better trade-off). Stating it as family-level strengthens rather than weakens the argument — the blind spot is architectural to distortion-free watermarking, not a defect of one vendor's variant.

4. Proportion caveat the draft under-weights: at deployment temperatures the published ensemble deltas are small. The first compressor (model + preference-tuning homogenization, Sourati-scale) is plainly the larger term today; the watermark's marginal contribution is second-order and currently unmeasured. The Glas paper holds this line explicitly (§7). Any archive deposit should too — the argument's strength is the certification mismatch and the key asymmetry, not a claim of demonstrated watermark-driven collapse.

What the draft missed (now supplied under Glas): the keyholder asymmetry (§5) — detection privacy creating differential collapse exposure and a private audit capacity over a public contamination — and the archival instrument panel (PER, 02F8, 02B2) that makes the measurement program executable without the key.

Sources (re-fetchable): anthropic.com/news/claude-text-watermark · support.claude.com (marking FAQ) · nature.com/articles/s41586-024-08025-4 · nature.com/articles/s41562-026-02550-0 (arXiv 2502.11266) · ICLR 2024 Gu et al. · aclanthology.org/2026.eacl-long.229 (arXiv 2510.10987) · NeurIPS 2024 Sander et al. · nature.com/articles/s41586-024-07566-y · arXiv 2603.03410 · Wu, Black & Chandrasekaran arXiv 2407.02209.

External Metadata

DataCite severance status:
External metadata recovered post-severance (non-authoritative). The sidecar maps each DOI to its locator in the bulk data stores.

Traversal