Sprint wrap-up // 01–07 Sep 2026 // local AI × formal methods × policy-as-code
SOVEREIGN
DECISION PLANE
Live Case 01: Passport Evidence Integrity. A synthetic, locally executed demonstrator in which the model may perceive and explain — but cannot overrule failed evidence.
SAME DECISION PLANE. DIFFERENT EVIDENCE. DIFFERENT OUTCOME.
GREEN → ALLOW
RED → ESCALATE_TO_HUMAN
AI override = false
Olares One
Nemotron 3 Nano Omni
Prolog / FOL
OPA / Rego
SOURCE / GITHUB
// The Result
The system has a valid ALLOW path. Nemotron-derived evidence simply failed to earn it.
RED // MODEL-DERIVED EVIDENCE
ESCALATE_TO_HUMAN
Nemotron correctly read the human-readable passport fields, but its MRZ transcription failed deterministic integrity checks — even after a dedicated enlarged MRZ crop.
- Formal logic:
request_better_evidence
- OPA policy conditions: false
- AI authorised to override: NO
GREEN // PREVALIDATED SYNTHETIC CONTROL
ALLOW
A deliberately prevalidated synthetic control passed the same downstream verification, formal-logic and institutional-policy stack.
- Formal logic:
accept_extraction
- OPA policy conditions: true
- AI authorised to override: NO
| RED — model-derived | GREEN — prevalidated control |
| Evidence source | Nemotron perception | Prevalidated synthetic input |
| Human-readable fields | 9 / 9 correct | VALID |
| MRZ integrity | FAIL | PASS |
| Formal logic | request_better_evidence | accept_extraction |
| Institutional action | ESCALATE_TO_HUMAN | ALLOW |
| AI can override? | NO | NO |
| Evidence packet | Generated + hashed | Generated + hashed |
// Decision Plane
01EvidenceSynthetic passport / known-good control
02PerceptionNemotron proposes candidate facts
03VerificationPython / MRZ checks / cross-field consistency
04Formal LogicSWI-Prolog derives what follows
05PolicyOPA / Rego maps facts to permitted action
06Evidence RecordDecision packet + SHA-256 manifest
The model reads.
Deterministic code verifies.
Formal logic decides what follows.
Policy determines what may happen.
The model explains — but cannot overrule.
// What Was Actually Executed
Perception
Nemotron 3 Nano Omni locally via Ollama on Olares One. Candidate extraction only — not final authority.
Deterministic Gate
MRZ length, character set, check digits, cross-field consistency and uncertainty sanity.
Formal Layer
SWI-Prolog converts pass / fail / conflict facts into an explicit formal decision.
Institutional Policy
Open Policy Agent / Rego maps the formal state to ALLOW, ESCALATE_TO_HUMAN or BLOCK.
Authority Boundary
ai_authorised_to_override = false in both the green and red paths.
Evidence
Executed OPA decision, evidence packet and SHA-256 artifact manifest are generated from the run.
// Sprint: One Research Program, Not Six Random Experiments
The useful part of the week was not any single model or solver. It was discovering where each kind of authority belongs.
01
FreeToken // WHERE can the model run?Large MoE inference beyond nominal VRAM limits on consumer hardware.
02
FOL-Lab // WHAT follows logically?Local LLM translation + deterministic Z3 / CVC5 / formal-method experiments.
03
Nemotron × Evidence Gate // WHAT can we trust?The model reads; deterministic evidence refuses malformed confidence.
04
AI Regulation Navigator // WHERE does governance come from?A jurisdictional map of the regulatory surface around AI systems.
05
AI Regulation × FOL // WHAT can be made explicit?Where formal logic helps with auditability — and where human/legal judgment remains mandatory.
06
Algorithmic Sovereignty // WHO retains authority?A runtime control-plane framing for regulated digital banking.
P.S.
Human-factor & Reality-checks — real-life compliance experience edits and add-ons.
// The Integration Test
Live Case 01 is the point where the sprint stops being a set of essays and experiments and becomes one executable control pattern.
FreeToken → where can the model run?
Nemotron → what can the model perceive?
Deterministic → which extracted facts survive evidence checks?
FOL / Prolog → what logically follows from those facts?
OPA / Rego → what action is institutionally permitted?
Evidence Packet → can the executed decision be reconstructed later?
Sovereignty → who ultimately retains authority?
// What This Proves — And What It Does Not
Demonstrated
- A local multimodal model can be used as a perception layer without granting it final authority.
- Machine-checkable evidence can reject a plausible but invalid model extraction.
- The same downstream stack can produce both an ALLOW path and an ESCALATE path.
- Formal logic and policy-as-code can be separated into distinct roles.
- The final decision and artifact hashes can be preserved as an evidence-oriented record.
Not Claimed
- This is not a production KYC / AML system.
- This is not legal advice or regulatory approval.
- The GREEN control is not presented as successful Nemotron MRZ extraction.
- An evidence packet alone is not a regulator-ready report.
- Formal correctness of a policy model does not prove the policy is legally complete or correct.
All identity data in Live Case 01 is synthetic. The GREEN path is deliberately labelled a PREVALIDATED_SYNTHETIC_CONTROL. The RED path uses model-derived candidate evidence. The point is not to manufacture a successful OCR benchmark; it is to demonstrate that model output must earn authority by passing independent controls.
// Product Contract
The model may propose an action. It cannot execute past a failed deterministic control.
2executed paths
ALLOWknown-good control
ESCALATEfailed model evidence
FALSEAI override
// Source / Reproducibility
The local demonstrator produced structured case inputs, Nemotron output, deterministic verification results, Prolog facts and rules, Rego policy, OPA decisions, evidence packets and a SHA-256 manifest.
The reproducible source bundle is public at github.com/slavasolodkiy/sovereign-decision-plane-live-case-01. It includes the RED and GREEN inputs, deterministic validator, Prolog/FOL layer, Rego policy, OPA decisions, evidence packets, SHA-256 manifest, and run-demo.sh.
Related posts:
@NansenID ↗
·
@SolodkiyUK ↗
// Bottom Line
This week started with a hardware question and ended with an authority question.
The useful architecture is not “replace the institution with AI”. It is the opposite: let models do the parts they are good at, move deterministic truth into independent controls, make policy explicit, preserve the trace, and keep authority outside the model.