Intelligent Assets

Assets that Carry Their Own Rules, Compose Across Jurisdictions, and Act Autonomously

Author: Raeez Lorgat


Abstract. Standard valuation theory reduces every tradeable instrument to a probability-weighted discounted future cash flow: a claim. An intelligent asset is that claim plus its full lifecycle program. It is an object whose own state carries its rules, its proofs, and its programs, so it moves between jurisdictions and acts within its authorized envelope, with machine-checkable evidence for each step.

An intelligent asset has six parts: a genesis record, a claim program encoding the instrument’s contingent terms, a family of lifecycle programs, a portfolio of sovereign-signed attestations, an append-only receipt chain, and a persistent store. A lifecycle program can move the claim only along the authority gates the claim itself declares, and the genesis record fixes an invariant set and a single amendment gate outside the amendable surface, so no chain of amendments the runtime admits can rewrite either: an asset can never rewrite its own mandate. Admission of any action runs through a typed compliance function with three structural guarantees. A failing verdict in a required domain is final, and no other domain’s evidence compensates for it. Unattested domains block rather than pass. A change in one domain flags exactly its dependent domains for re-evaluation. The paper reads three further quantities off the claim program and that verdict, because the object is not complete without them: who may hold the asset, what a receiving jurisdiction may rely on in the evidence it carries, and what it is worth. Matching, settlement, risk reservation, dispute, and recovery over those three are an open specification the paper names and does not close.

The paper gives the Smart Asset Virtual Machine, a deterministic machine that admits an action only on a passing pre-flight verdict and appends a receipt to every execution. Delegated artificial-intelligence programs may propose an action and may not approve one. They act only where compliance-passing actions and delegated actions overlap, under monetary caps, and the delegation is revocable at any moment. Human judgment enters at declared decision points under signed authorization, and a supervisory halt order outranks every private delegation.

The taxonomy spans twelve classes, from payments operators, investment funds, sukuk, and intellectual-property indices through treasuries, physical infrastructure, consented data, stewarded natural systems, trade receivables, and commodities in transit. The economic effect is a lower cost of verification. An asset that carries its own attested compliance biography reduces the compliance-verification component of due diligence to a replay of its attested chain. Where a shortage of capital limits a trade corridor, the lower cost lets volume grow. The paper gives eight worked lifecycles, states its trust model, and names its open problems. Evaluator correctness is a scoped trust assumption, the legal force of attestations depends on external instruments, coalition formation remains political, and scenario numbers stand as declared parameters.


1. What Is Broken

A three-person cross-border payments company operating in the United States, the United Kingdom, Singapore, the United Arab Emirates, and Nigeria spends a large fraction of its revenue on compliance: outside counsel in five jurisdictions, one full-time hire, a licensing stack, the same know-your-customer question answered five times. Adding a sixth jurisdiction would cost half again as much. The company does not add jurisdictions. The product does not reach the customers it could serve.

A stewardship trust holding one hundred thousand hectares of the Amazon rainforest, established under a compact between three national environmental agencies, representatives of an indigenous council recognized under national constitutions, and a scientific advisory board, issues carbon-biodiversity credits under a voluntary-market methodology. Every sale must address additionality (would the forest have stood without this project), permanence (will it stand for the next hundred years), and leakage (does protecting this tract displace clearing elsewhere). The trust spends two years registering one vintage.

A Saudi electronics-components exporter ships to a Shenzhen-based manufacturer and receives payment forty-five to sixty days later. A letter-of-credit cycle at every step: know-your-customer on the buyer, continuous sanctions screening against the U.S. Office of Foreign Assets Control, European Union, and United Nations lists, export-control classification, bank-intermediated foreign-exchange hedging, customs and bill-of-lading reconciliation by hand. Institutional capital, pension funds, insurers, sovereign wealth vehicles holding trillions of dollars in short-duration credit, cannot buy the receivable, because the paper is unrated, the compliance chain is unverifiable without manual re-execution, and the per-receivable due-diligence cost exceeds the financing spread. In a bilateral trade flow on the order of four hundred billion dollars a year between the Arabian peninsula and China, the growth that exporters could ship and buyers could absorb, but that the receivables-financing cycle cannot carry, is gated by financing rather than by demand. Whether that gated fraction is large is the capital-gated diagnosis §18.2 sets out and leaves to corridor-level analysis.

These three situations, across three industries, share one structural pattern.

In each case, an institutional object, the company, the trust, the receivable, sits at the center of a web of rules enforced by different authorities under different frameworks in different jurisdictions. The rules carry legal force, and violating them is criminal. The rules do not travel with the object. Every cross-jurisdictional action rebuilds, from first principles, the compliance context that the last jurisdiction already established. Every new jurisdiction multiplies every existing obligation. Every attestation dies at the institutional boundary that produced it. Composition of rules across jurisdictions is reconstructed manually for each transaction.

This layer, what may be done, by whom, under which rules, in which jurisdictions, is still run by hand. Its latency is measured in months. The consequence is visible both in what exists (large institutions whose compliance departments consume on the order of ten to twenty per cent of operating cost) and in what does not exist: the three-person company that cannot reach its fifth market, the exporter whose volume is capped by the financing cycle rather than by demand, the stewardship structure that cannot close the gap between an indigenous council’s consent and a corporate buyer’s climate report.

The policy environment gives the problem its present shape. Sanctions fragmentation since 2022 has produced cascading secondary-sanctions designations whose compliance-reconciliation overhead exceeds the economic value of many of the cross-border flows they touch. De-risking, documented in the BIS Committee on Payments and Market Infrastructures’ correspondent-banking review and the Financial Stability Board’s data reports, has halved some small jurisdictions’ correspondent-banking base within a decade and left much of the developing world with reduced or absent correspondent access to the dollar and euro systems. Asymmetric adoption of the OECD’s Pillar-2 framework and Schrems-II-class data-transfer volatility have compounded cross-border operating cost for firms large enough to absorb it and made such operation uneconomic for the rest.

What would have to change for these situations to become tractable is a primitive that is intrinsic to the object (carried in its own state), machine-executable (evaluable in microseconds for the mechanical fragment), sovereignly attested (signed by named evaluators under named rule sets), composable across jurisdictions (combinable through algebraic operations with defined behavior at edge cases), operable by delegated programs (under scoped, revocable delegations), supervisable (exposing an operational surface the sovereign can touch), and explicit about its limits.

This paper supplies that primitive. It also specifies what it does not supply.

2. What Changes

An intelligent asset is an object, a fund, a bond, a treasury pool, a physical facility, a consented corpus, a stewardship trust, that carries six things at all times: the record of its creation, the claim program that encodes its terms, the programs that operate it inside an envelope authorized at its founding, the sovereign attestations that establish its current compliance state, the append-only history of everything that has been done to it or by it, and a store that persists between executions.

Before each intended action, a compliance function evaluates the proposed action against every regulatory domain the action requires. The evaluation composes attestations from every jurisdiction in whose territory the object operates. The composition uses an algebra that names its edge cases: when applicability disagrees across jurisdictions, the algebra returns a structured obstruction rather than silently coercing one side. When the composition’s verdict passes, the action executes, the effects settle, and a new receipt is chained to the history. When the verdict fails, the action halts, and the receipt records the failure’s cause.

The programs include compiled compliance gates whose behavior is a deterministic function of the attestation portfolio and the action’s required domains, rule evaluators compiled from the companion rule language Lex that produce verdicts with explicit provenance and admit typed discretion holes at the points where mechanical computation must stop, and delegated proposal programs operating under signed principal delegations. Those delegations specify exactly which tools the program may invoke, which resources it may touch, which limits it must respect, and which discretion holes it may attempt to fill versus escalate to principals. The programs read the compliance tensor; they do not write it. They propose actions; the compliance gate admits or refuses. They attach proposal rationales to the receipt chain; the receipt chain is the audit artifact.

When the object’s ownership changes, the receipt chain extends. When a sovereign revokes an attestation, the cells downstream of that attestation revert to pending, the propagation graph recomputes the set of cells requiring re-evaluation, and the object freezes or degrades its capabilities until fresh attestations arrive. When the object adds or retires a harbor, a bilaterally-agreed corridor specifies which attestations carry through under mutual recognition and which require fresh evaluation. Under the fail-stop and finality-certificate assumptions stated in the companion protocol papers, the transition is an atomic cross-zone operation; outside those assumptions it returns a typed obstruction or enters a bounded-blocking compensation path.

The argument is substrate-independent: the same algebra binds autonomy to compliance state whether the object is a bond, a data center, or a rainforest. What changes is that the compliance component of operating across jurisdictions becomes proof verification plus fresh evaluation of the domains a corridor names, the instruments that were uneconomic become economic, and the institutional forms that could not hold their shape across borders can.

What does not change, absent political adoption, is the legal force of the attestations. The architecture builds the infrastructure that legal regimes can reference; it does not create legal force on its own. The preconditions for its reach are named throughout the paper and concentrated in §17.

The architecture sits between two adjacent layers. The issuance and governance layer is the sovereign jurisdiction network (companion paper of the same name) that hosts the multi-harbored institution issuing the asset, evaluates the entity’s compliance state across jurisdictions, and supplies the corridor parameters (R, \mu, \gamma) of Definition 4.5 under which carried evidence enters the receiving jurisdiction. The clearing and settlement layer consumes the composed admissibility envelope, the corridor parameters, and the asset’s claim and lifecycle programs as typed inputs. Three further inputs the layer needs are constructed in this paper: the admissible holder set, the reliance class, and the clearing price, in Definitions 4.6 to 4.8. Matching, settlement, risk reservation, dispute, and recovery over them are an open specification, named with the other open problems in §17.4. Intelligent assets in this paper’s sense are the typed objects that flow between the two layers. The contribution of this paper is the typed object class itself; the contribution of the sovereign-jurisdiction-network paper is the substrate on which that object class operates.

3. Eight Worked Lifecycles

Before the formal object, eight compact lifecycles, each running from genesis to a consequential event. Three expand the situations of §1; the rest extend the same pattern to funds, treasuries, data centers, consented corpora, and cargo. Every number inside these lifecycles, costs, headcounts, timelines, spreads, is a declared scenario parameter, not an empirical claim; a live deployment would have to measure each one. The formalism that follows defines the primitives they already use.

3.1 A cross-border payments company (Class I, financial operator)

Three founders based in Lagos, London, and Singapore incorporate a payments company in Delaware with operating subsidiaries in the United Kingdom, the United Arab Emirates, Singapore, and Nigeria. They intend to move remittances and small-business working capital across five corridors. At creation, the company registers as an intelligent asset whose genesis document names five harbors (U.S., U.K., U.A.E., Singapore, Nigeria), the authoring principals (a three-signature quorum over the founders’ keys), and an initial program set: compiled compliance gates for anti-money-laundering, sanctions, and consumer-protection requirements, with foreign-exchange reporting recorded as methodology fields inside the canonical Payments, Banking, and Tax domains, a rule-evaluator program compiled from the company’s published terms of service, and a delegated proposal program authorized under a narrow delegation to read the tensor, propose onboarding actions for new customers, draft disclosures, and escalate to the founders on novel situations.

For three months the program proposes customer onboardings. Each proposal is gated: the sanctions cell of the destination harbor must be Compliant, the anti-money-laundering cell in the source harbor must be Compliant, and the corridor’s foreign-exchange reporting requirement must be satisfied inside its canonical domain. When a proposal passes, the customer is onboarded, the receipt carries the program’s rationale, the counterparty identity-check provider’s attestation, and a reference to the rule version under which the evaluation ran. When it fails, the receipt records the blocking domain and the program drafts a customer-facing explanation.

In month five, the company adds Brazil as a sixth harbor. The corridor between Brazil and the existing harbors is evaluated by the Brazilian central bank’s designated evaluator: consumer-protection and foreign-exchange reporting requirements require fresh evaluation because their rule sets differ from the existing harbors, Sanctions is re-evaluated locally under the general-purpose corridor rule, and the remaining domains carry through only where the corridor’s recognition maps and grade maps are defined. Fresh attestations are issued in two weeks. The company begins operating in Brazil.

In month eleven, a sanctions update adds a new designated party. The sanctions cells across harbors transition to Pending. Propagation flags customer-onboarding decisions that referenced the affected party as stale. Outstanding transactions to or from the affected party are blocked by the algebra before any manual review. The receipt chain records every block, its cause, and the rule version under which the block was decided.

In the scenario, the company’s compliance headcount over the first year is one, the compliance cost is one hundred twenty thousand dollars, and the company adds a seventh jurisdiction in month fifteen.

3.2 A cross-border private-equity fund (Class II, collective investment)

A private-equity fund with two billion dollars of committed capital restructures as an intelligent asset. Its genesis document names four harbors (Cayman, Delaware, Luxembourg, Singapore), the authoring principal (a four-signature quorum of the investment committee), and a program set: compiled Level-1 gates for securities, custody, tax, and sanctions across each harbor; a Level-2 rebalancing program bound to read the portfolio, compute target allocations under the mandate, propose trades with counterparties, and escalate to the investment committee on any trade exceeding a per-trade monetary cap; a Level-2 harbor-transition evaluation program authorized to propose (not execute) corridor operations when regulatory terms shift; and a Level-1 net-asset-value computation program keyed to monthly close.

Limited partners receive, in place of the quarterly letter, a read-only view over the receipt chain scoped to their partnership interest. The ratio of reconciliation hours to investment decisions falls by sixty per cent: attestations from the custodian, the fund administrator, and the prime brokerage each flow through the kernel’s watcher-attestation interface, and the receipt chain is the canonical reconciliation artifact. The administrator continues to compute and sign the net-asset-value, but the sign-off enters as a watcher-attestation against the tax and custody cells, rather than as an email to the general partner.

In year two, Luxembourg introduces a rule change that the fund’s board would call regulatory capture: certain alternative-investment-fund-manager disclosures are weakened in a manner incompatible with the fund’s stated investor-protection posture. The harbor-transition evaluation program identifies that Ireland offers terms the board would rather operate under, evaluates the corridor, proposes adding Ireland and retiring Luxembourg, and escalates to the investment committee with a draft limited-partner communication. The committee signs; the transition commits: the Irish jurisdiction evaluates the re-evaluation set (four domains whose rule sets differ), the remaining domains carry through the corridor, entry attestations issue. The receipt chain records every step, including the tax analysis that the committee’s tax counsel signed as a discretion-hole fill.

In the scenario, the harbor transition takes two weeks rather than nine months because the corridor is already negotiated, the re-evaluation set is narrow, and limited-partner consent is handled through a signed amendment to the partnership agreement that the program drafted and the committee reviewed. The tax implications (for U.S. feeders: the §367 analysis of the outbound deemed exchange) are worked by human counsel and signed as a principal-carried authorization; the receipt chain carries counsel’s signature alongside the transition.

3.3 A multi-jurisdictional treasury (Class VII, working-capital operator)

The in-house bank of a Fortune-500 multinational restructures as an intelligent asset. Its genesis document names eight harbors (the jurisdictions in which the group maintains functional banking relationships and material cash balances), a four-signature principal quorum (treasurer, group tax head, chief financial officer, chief accounting officer), and a program set dominated by Level-2 programs: cash-pooling and netting, transfer pricing, Pillar-2 top-up-tax calculation, country-by-country reporting, and Foreign Account Tax Compliance Act / Common Reporting Standard reporting. Level-1 gates enforce per-harbor sanctions, anti-money-laundering, and per-transaction monetary caps.

The transfer-pricing program reads intercompany loan rates, trade-pricing attestations signed by the operating subsidiaries’ local-file signers, and the Organization for Economic Cooperation and Development’s Multilateral Instrument-treaty lookups. Each quarter it drafts a master-file summary, signed by the group tax head as a principal-carried authorization, entering as attestations against the tax cells of every harbor. The Pillar-2 program drafts Global Anti-Base-Erosion top-up-tax computations from signed inputs, identifies possible safe-harbor opportunities (Transitional Country-by-Country Reporting Safe Harbor elections, Qualified Domestic Minimum Top-Up Tax elections), and escalates elections, treaty positions, and uncertain classifications to the treasurer and group tax head as typed discretion holes. Formal cross-harbor GloBE/treaty/tax-fiber composition is an open obligation, not a solved meet operation.

The country-by-country-reporting receipt is produced continuously rather than annually. When the external auditor needs to test the report, the test is a re-execution of the receipt chain’s computations against the underlying attestations, not a three-week reconciliation.

The integration with the existing enterprise-resource-planning and treasury stack is adjacent rather than replacive. Finance-document events flow from the incumbent systems into the kernel’s oracle surface as signed watcher-attestations; kernel-emitted attestations flow back into the general ledger as typed journal entries the ledger’s reconciliation routine recognizes. The intelligent-asset layer wraps the existing stack.

In the scenario, the treasury’s reconciliation headcount falls from forty-three to fourteen over eighteen months. The annual cost of compliance and reporting falls from eighteen million dollars to five million, with the remainder concentrated in the residual human judgments the discretion-hole mechanism surfaces.

3.4 A hyperscale data-center operator (Class VIII, physical infrastructure)

A data-center operator restructures as an intelligent asset, specifically, each site is a sub-asset under a parent-entity intelligent asset. Each site’s genesis document names the physical-jurisdiction harbor (the jurisdiction of the land), the operating-entity harbor (often a separate-purpose vehicle in a different jurisdiction), and the grid-interconnect harbor (the market operator’s authority over the interconnect). The program set includes Level-1 gates for environmental-impact reporting as a methodology field inside Licensing and Trade obligations, labor-law compliance inside Employment, and U.S. Export Administration Regulations / European Union dual-use export-control classifications inside Trade and Sanctions; Level-2 sensor-fusion programs that consume the site’s telemetry under a Byzantine quorum across four independent sensor-vendor feeds before any attestation is signed; and an operations program bound to the incumbent facility-management stack via typed tool interfaces.

When a tenant proposes a new workload, the operations program reads the tenant’s declared workload type, computes the export-control classification under the current rule version, identifies the canonical-domain cells that must pass (Sanctions on tenant and end-customer, Trade/Sanctions for workload classification, Licensing/Trade for additional power draw, Employment for any on-site service requirement), and produces an attestation-bundle proposal. Approval is automatic if every cell is Compliant and the workload is within the tenant’s standing delegation; manual if the workload is a novel classification that requires a discretion-hole fill by the export-control officer.

Continuous power-usage-effectiveness attestation, signed by the sensor-fusion program under a quorum of four vendors, feeds the environmental-impact methodology field inside the relevant Licensing and Trade cells. The site’s annual environmental audit, previously a six-figure exercise per site, becomes a verifying re-execution against the receipt chain. Insurance premium negotiations with the business-interruption insurer reference the receipt-chain quality; any premium change remains an underwriting outcome.

When the grid operator behind a Brazilian site’s interconnect declares a demand-response event, the grid-interconnect harbor’s evaluator signs an attestation, the operations program proposes the prescribed load reduction, the Level-1 gate confirms it is within operational limits, the action executes within the grid operator’s deadline, and the demand-response payment is settled through the receipt chain as a cross-referenced attestation with the grid operator.

The operator’s per-site compliance cost falls from eight million to one million dollars within eighteen months. It opens two additional sites in the window during which its prior cost structure would have admitted none.

3.6 A stewardship trust for the Amazon rainforest (Class X, natural-system steward)

A stewardship trust for one hundred thousand hectares of Amazon rainforest restructures as an intelligent asset under a multi-sovereign compact. Its harbor set spans three national jurisdictions (Brazil, Peru, Colombia) and a recognized indigenous-council harbor established under the three nations’ constitutional and international obligations (the council’s recognition is the precondition; the architecture does not substitute for it). Its authoring principal is a six-signature quorum: three national environmental agencies, two indigenous-council representatives (a structural minimum, not a maximum, the council’s own delegation rules determine how these representatives are chosen), and a scientific advisory board. The program set includes Level-1 gates for environmental-impact reporting, carbon-accounting methodology adherence, and indigenous-rights compliance as methodology fields inside the canonical Licensing, Trade, ConsumerProtection, Arbitration, DataPrivacy, and Ip domains, plus sanctions screening on buyers; Level-2 programs for monitoring (satellite imagery, ground sensors, auditor attestations, community-report channels), credit issuance, buyer negotiation, and remediation response.

Free, prior, and informed consent is a structured process, not a signature event. The architecture represents it as follows: every consequential action requiring community consent (credit-vintage issuance, addition of a new buyer jurisdiction, methodology change, response to a major oracle event) is routed to a deliberation window specified by the council’s own governance rules, in the council’s working language, with the information the council requires to deliberate. Consent is captured only at the close of the deliberation window; withdrawal remains available until the vintage closes; key custody for the council’s signing authority follows the council’s own constitution, threshold-signed, rotated, recoverable, with non-digital fallback paths for moments when digital infrastructure fails.

Permanence is enforced through a cross-asset buffer pool: a reserve share of every vintage is held against reversals, composable across stewardship trusts within the same methodology, sized under the methodology’s risk model. Leakage is accounted through adjacent-tract monitoring and methodology-level tracts: the trust’s tensor is a node in a methodology-level graph whose nodes share observations that price regional displacement. Additionality is evaluated at vintage registration by the methodology’s evaluator; it is not claimed by the trust, it is attested by the evaluator under the methodology’s rule set.

Credit sales to corporate buyers occur as inter-asset negotiations: the buyer (itself an intelligent asset representing a corporate treasury or a compliance pool) evaluates its tensor; the trust evaluates its tensor; under the corridor finality assumptions, mutual pass lets settlement commit and the buyer’s claim flows under the receipt chain of both assets. Where the buyer is in a jurisdiction that has signed on to Article 6 of the Paris Agreement and requires a corresponding adjustment against the host jurisdiction’s nationally-determined contribution, the corresponding-adjustment attestation is a distinct first-class object signed by the host jurisdiction’s designated authority.

A deforestation event detected by the monitoring program transitions the relevant Licensing/Trade methodology field to NonCompliant. Propagation invalidates downstream methodology fields for carbon accounting and biodiversity claims. Active vintages enter the buffer-pool replacement protocol: affected tonnes are replaced from the buffer, the buyer’s claim is made whole from the buffer pool rather than clawed back, the revocation-and-replacement mechanics flow through the receipt chain. The scientific advisory board receives a disclosure. The indigenous council, on its own deliberation, decides whether to invoke an emergency-response clause. Its decision is a discretion-hole fill.

The trust is not the rainforest; the trust is the credit-issuing steward. The rainforest is physical, its territory does not move, and national environmental sovereignty over it does not move. What changes, when regime conditions change, is the trust’s operating harbor, which is legitimate only under the receiving jurisdiction’s willingness to engage.

3.7 A trade-receivables pool across the Arabian-Chinese corridor

Consider a Saudi electronics-components exporter selling to a Shenzhen-based manufacturer. Before intelligent-asset infrastructure, the invoice cycle runs forty-five to sixty days from shipment to settlement. At each step there is compliance friction: buyer know-your-customer takes two weeks; sanctions screening against the evolving U.S. Office of Foreign Assets Control, European Union, and United Nations lists runs continuously against shifting designations; export-control classification under the Kingdom of Saudi Arabia’s General Authority for Foreign Trade and the receiving jurisdiction’s import-control regime runs five to seven business days; the foreign-exchange hedge across the United States dollar-renminbi pair adds bank-intermediation spreads; customs, bill-of-lading, and carrier attestations arrive through uncoordinated channels and are reconciled by hand. Institutional capital, pension funds, insurers, sovereign wealth vehicles, that could finance these receivables mostly cannot, because the paper is unrated, the compliance chain is unverifiable without manual re-execution, and the per-receivable due-diligence cost exceeds the financing spread. The receivables sit on exporters’ balance sheets or are financed by banks at three-to-four-per-cent spreads. In a capital-gated bilateral Arabian-Chinese trade corridor, working-capital velocity rather than demand can become the binding constraint: an exporter who could turn cash in days rather than months may ship more, and a buyer who could extend payment under a bounded-cost instrument may order more.

Under the architecture, each trade receivable is wrapped at origination as an intelligent asset. Its genesis names four harbors: the exporter’s jurisdiction (Saudi Arabia, with corridor agreements through the Abu Dhabi Global Market’s financial-services regime), the buyer’s operating jurisdiction (the People’s Republic of China, via Shanghai or Shenzhen), an intermediary operating harbor (Abu Dhabi Global Market or the Dubai International Financial Centre, each with their own established bilateral corridors), and a settlement harbor (Hong Kong, under its specific cross-boundary arrangements). The authoring principal is a threshold-signature over the exporter’s treasurer and the buyer’s enterprise-resource-planning system’s watcher-attestation. Initial attestations load immediately: the buyer’s Chinese correspondent bank signs a know-your-customer attestation; the Abu Dhabi Global Market’s designated evaluator signs a sanctions-clearance attestation; the General Authority for Foreign Trade’s designated export-control evaluator signs a classification attestation; the maritime carrier signs a shipment attestation chained to the bill-of-lading digest. The compliance tensor passes on every required domain within hours rather than weeks, because the attestations are produced in parallel under the existing legal infrastructure and composed algebraically rather than reconciled manually.

A pool of such receivables, say, the next quarter’s Saudi-Shenzhen electronics-components flow, is itself an intelligent asset, a trade-receivables pool operating under a published methodology for aggregation, concentration limits, and expected-loss computation. Institutional investors acquire tranches of the pool through Op’s signed commitment protocol: their capital is locked against the pool’s tranche; the pool’s receivables are locked against the tranche’s coverage; under the protocol’s finality assumptions, settlement commits on shipment-attestation confirmation or compensates on failure. The pool’s compliance state is a receipt-chain projection the investor’s risk team can re-execute; the pool’s rating is assigned by credit-rating agencies that run their own evaluator against the chain rather than consuming an issuer’s self-report. Under a financing model in which verification cost is the binding spread component, the spread compresses.

The pool becomes investable by allocators who previously could not buy trade paper only when the conditions of §18.1 align; algebraic verifiability removes one exclusion. The architecture supplies the verification surface; the investment decision remains the allocator’s.

The trade-volume consequence is conditional arithmetic of working-capital velocity. If a receivable turns in two days rather than forty-five, the same working capital can finance twenty times as many shipments per year before other constraints bind; if receivables become investable by institutional capital rather than only by bank credit, the pool of financing can expand; if compliance friction across the corridor falls, some exporters previously excluded by cycle cost can enter. Whether the corridor’s throughput constraint shifts from working-capital velocity to real-economy capacity is an empirical question about ports, manufacturing throughput, shipping availability, demand, and policy. The same mechanism is relevant to other corridors only where bilateral trade is constrained primarily by the reconciliation cost of bilateral compliance rather than by underlying commercial demand.

What the architecture does not do: it does not generate demand, does not substitute for the political preconditions of bilateral trade (recognition, visa regimes, physical logistics), and does not override U.S., E.U., or Chinese export-control and sanctions regimes. What it does is define the conditions under which per-transaction compliance composition can move from manual reconciliation to algebraic verification, which is one bottleneck on the receivables-financing mechanism where trade-volume growth is capital-gated.

The integration with incumbent rails is adjacent rather than replacive. The exporter’s letter-of-credit cycle continues to flow through SWIFT MT700 issuance and MT710 advising where the buyer’s bank requires it; under UCP 600 Article 14’s documentary-examination standard, attestation-signed documents from the carrier, surveyor, and customs evaluator enter as electronic equivalents under eUCP version 2.1 or as Bolero electronic bills of lading. Documentary discrepancies, the twenty-to-thirty per cent of presentations in which the Saudi General Authority for Foreign Trade’s HS-code attestation diverges from the Chinese General Administration of Customs’ HS-code attestation, or in which the bill-of-lading’s shipment date drifts from the surveyor’s quality-certificate date, trigger a structured discrepancy-resolution discretion hole under UCP 600 Article 16 rather than an obstruction that halts reconciliation; the resolver (typically the applicant’s bank’s documentary team) signs a principal-carried authorization carrying a named waiver, and the receipt chain records the waiver’s substance. The architecture does not eliminate documentary-discrepancy resolution; it gives it a machine-auditable protocol. Settlement of the dollar leg runs through SWIFT gpi where that is the parties’ choice or through a regulated digital-cash settlement path where both parties admit it; settlement of the renminbi leg runs through the Cross-Border Interbank Payment System where one party prefers it. The intelligent-asset pool coexists with treasury platforms, supply-chain-finance platforms, and bank-internal portals as the programmable-compliance substrate; each can originate into the pool, and the pool can issue to their investor channels where the paper is admissible.

3.8 A commodity cargo across the Persian Gulf-East Asia corridor

A merchant trading house loads a very-large crude carrier at Ras Tanura bound for Ningbo with two million barrels of Arabian Light under a charter party and an open-account sales agreement. The cargo sails as an intelligent asset of Class XII, a physical-commodity-in-transit whose state assembles, as an algebraic object rather than a manual file, the attestations every sovereign and non-sovereign party already issues. The harbor set is the physical-custody graph’s authority set: Saudi Arabia’s General Authority for Foreign Trade signs the export-clearance attestation; the vessel’s flag-state maritime authority signs the shipping-registry attestation; the People’s Republic of China’s General Administration of Customs signs the import-clearance attestation; Ningbo Port Authority signs the port-of-discharge attestation. Non-sovereign evaluators include SGS or Bureau Veritas for cargo-quality inspection (metal content, moisture, chemistry, bill of quantities) and the Lloyd’s Register of Shipping for vessel-class attestation. The compliance tensor composes across canonical domains such as Sanctions, Trade, KYC, Custody, Insurance, and Arbitration, with export-control, origin-declaration, cargo-quality, counterparty identity, and chain-of-custody integrity recorded as methodology fields inside those domains.

Dispute resolution, arbitration under the London Maritime Arbitrators Association or under the rules of GAFTA, FOSFA, LME, LCIA, ICC, or SIAC depending on the contract’s clauses, or High Court jurisdiction in London or New York, is encoded as a process-typed discretion hole: the forum is named at genesis, the procedural rules are attested, and a dispute’s resolution appends to the receipt chain as a principal-carried authorization under the named arbitral-institution’s process type. Possession risk distinct from payment risk, the vessel arrested in the Strait of Hormuz, cargo detained at discharge, war-risk-zone diversion, is handled through a separate class of discretion-hole escalation and through the insurance binder’s attestation conditions.

A secondary-sanctions event propagates along a chain-of-custody graph orthogonal to the regulatory-domain graph of §7: when a downstream counterparty is designated, the sanctioned party’s cell transitions, the propagation engine identifies every cargo whose custody-state has ever crossed the sanctioned party’s custody, and every affected cargo’s compliance state is flagged for re-evaluation before any further downstream transfer clears. This is how secondary-sanctions propagation operates in merchant trading; its formalization as a graph orthogonal to §7 is what distinguishes Class XII from Class XI’s purely-financial receivables. The freight derivative paired with the voyage, the forward-freight agreement, the futures hedge on Brent or West Texas Intermediate, an options position on the time spread, is a paired intelligent asset composed with the cargo under Op’s multi-asset signed commitment; under finality assumptions, unwinding the physical leg unwinds the hedge through the same settlement evidence.

What changes for the merchant: seventy-two hours of manual reconciliation on a secondary-sanctions event become a propagation-engine query and a bounded set of gated actions; the compliance-reconciliation overhead compresses; the hedge and the physical leg compose rather than rely on desk-side reconciliation; and the cargo’s documentation becomes a single algebraic object the merchant’s auditor, the regulator, and the buyer can each re-execute independently.


These eight lifecycles use a shared vocabulary. We now define the primitive that binds them.

4. The Object

We treat the intelligent asset as a typed record whose fields carry the interfaces other fields and the runtime rely on. The unifying observation, used throughout this section and §15, is that an intelligent asset is a programmatic contingent claim: a typed object whose state carries a claim program (the term-level encoding of the instrument’s contingent claim under the probability-weighted discounted-cash-flow reduction) coupled to a lifecycle program family (the typed transitions in that claim’s lifecycle that the asset’s runtime is authorized to execute), together with the compliance, attestation, and receipt machinery that makes both clearable across jurisdictions.

Definition 4.1 (Intelligent asset). An intelligent asset is a six-tuple

A = (g, \Phi, \Lambda, \pi, \sigma, s)

whose fields are:

  • Genesis document g \in \mathrm{Genesis}, the immutable record of creation, content-addressed by digest h_g. The genesis names the asset class (its placement in the contingent-claim taxonomy of §15), the institutional-identity pointer (to a multi-harbored institution whose harbor set is time-varying and lives outside g), the authoring principal (a public-key identifier or a threshold-signature scheme over multiple keys), the initial digests of \Phi and \Lambda, the initial storage schema, and the initial attestation-portfolio specification. Amendments to the harbor set, the program set, and, under specified governance rules, the authoring principal itself, are not edits to g; they are signed amendment records appended to \sigma and resolved dynamically when the asset is read. Two further genesis fields bound that amendable surface from outside it: an invariant set \mathcal{I} of decidable predicates on the amendable record, the triple of claim program, program family, and authoring principal that amendment records leave resolved, and an amendment gate \theta_\ast, the single authority gate (Definition 4.9) wrapping every amendment-kind transition. Neither \mathcal{I} nor \theta_\ast lies in the range of any amendment record, and both are fixed by h_g: “immutability of g” is the immutability of \mathcal{I} and \theta_\ast, while time-varying state is the province of the other fields and the institutional pointer. The construction, and the invariance it buys, close this section (Proposition 4.1).

  • Claim program \Phi \in \mathrm{ClaimProgram}, the term-level encoding of the instrument’s contingent claim under the probability-weighted discounted-cash-flow reduction. \mathrm{ClaimProgram} is the contract-combinator grammar of Peyton Jones and Eber (2003), descending from their 2000 paper with Seward, with terms c ::= \mathbf{zero} \mid \mathbf{one}(k) \mid \mathbf{give}(c) \mid \mathbf{and}(c_1, c_2) \mid \mathbf{or}(c_1, c_2) \mid \mathbf{cond}(o, c_1, c_2) \mid \mathbf{scale}(o, c) \mid \mathbf{when}(o, c) \mid \mathbf{anytime}(o, c) \mid \mathbf{until}(o, c), extended with the two constructors this architecture requires, \mathbf{gate}(\theta, c) and \mathbf{hole}(\eta, c), where k ranges over currencies, o over observables the asset’s oracle surface signs, \theta over the authority gates of Definition 4.9, and \eta over the typed discretion holes of Definition 11.1. The denotation \mathcal{V}(c) is the value process the combinator semantics assigns under a model for the observables. On the two added constructors it reads the asset’s own state: \mathcal{V}(\mathbf{gate}(\theta, c)) is \mathcal{V}(c) on the branch where \theta admits the transition attempted there (Definition 4.9: a passing §6 verdict on that action over \theta’s domain scope, together with a PCAuth under \theta’s process type) and the zero process otherwise, and \mathcal{V}(\mathbf{hole}(\eta, c)) is \mathcal{V}(c) on the branch where \sigma carries a PCAuth valid for \eta under Definition 11.2 and the zero process otherwise. So \Phi specifies when cash flows, in what amount, to which counterparty, under what authority gates, on default what happens, on dispute what happens, and on amendment what happens, and a lifecycle transition can be attempted at a lifecycle state only where \Phi’s gate and hole constructors leave a live branch there, which makes the coupling stated below a computation on \Phi’s denotation rather than a stipulation about \Lambda; Definition 9.3 then decides admission on the domains the handle requires. \Phi is the financial reading of the asset: the admissible holder set, the reliance class, and the clearing price are read off \mathcal{V}(\Phi) and the compliance function in Definitions 4.6 to 4.8. Concrete instances of \Phi correspond to claim classes in §15: a BondClaim \Phi encodes coupon schedule + face + covenants + default waterfall; a SukukClaim \Phi encodes Ijara/Murabaha/Musharaka/Mudaraba structure under Sharia certification; a ParametricInsuranceClaim \Phi encodes trigger event + payout schedule + reinsurer reserve; a RwaClaim \Phi encodes off-chain custody binding + receivable schedule. \Phi is content-addressed by digest h_\Phi recorded in g.

  • Lifecycle program family \Lambda, a finite set of typed program handles authorized by the genesis document. Each handle is a quadruple (h_p, \tau_\mathrm{in}, \tau_\mathrm{out}, D_\mathrm{req}) where h_p is the content-digest of the program artifact, \tau_\mathrm{in} and \tau_\mathrm{out} are input and output type signatures, and D_\mathrm{req} \subseteq \mathcal{D} is the statically declared set of compliance domains the program’s invocation requires. Each \lambda_i \in \Lambda admits a typed state transition in \Phi’s lifecycle (issuance, attestation, transfer, partial settlement, dispute, recovery, revocation, amendment, termination); the typed authority gates and discretion holes of \Phi govern which \lambda_i is admissible at each lifecycle state. Artifacts include Level-1 compiled compliance gates, Op-bytecode programs compiled from Lex rules (under the companion Op paper’s admissible-compilation theorem), and Level-2 delegated proposal-program configurations (see §10). Additions to \Lambda are signed amendments recorded in \sigma.

  • Attestation portfolio \pi \subseteq \mathrm{Att}, the set of currently valid sovereign attestations. The runtime maintains \pi under the invariant: for every \alpha \in \pi, the attestation’s validity window includes the current time and the attestation has not been revoked. Expired or revoked attestations are removed eagerly.

  • Receipt chain \sigma = (r_0, r_1, \ldots, r_n), a hash-linked sequence of execution receipts. r_0 is the genesis receipt; every r_{i+1} carries the digest of r_i in its parent field. Appends are serialized per asset by a compare-and-swap against the current chain head. On integrity failure (parent-digest mismatch, signature invalid), the runtime transitions the asset to a fault state and emits a runtime-signed fault receipt.

  • Persistent store s, a typed key-value map under a schema declared in g, surviving between program executions.

The pair (\Phi, \Lambda) is the load-bearing structure. \Phi is the financial reading; \Lambda is the operational reading; the two are coupled through \Phi’s typed authority gates and discretion holes. Without \Lambda, the asset is a record with signed metadata. With \Lambda, the asset observes external events, applies the compliance gate, and acts within the envelope its lifecycle programs are authorized for. Everything outside that envelope requires a signed amendment, itself not an autonomous act. The coupling between \Phi and \Lambda bounds one transition: \Lambda may transition \Phi only along the typed-discretion-hole and authority-gate structure that \Phi itself declares. The claim that an intelligent asset cannot rewrite its own mandate is a statement about every chain of such transitions, and the one-step coupling does not carry it, because amendment is itself among the transitions \Lambda admits. What carries it is the invariant set and the amendment gate of g; Proposition 4.1, at the close of this section, proves it.

The terminal transition. An institutional object needs a first-class end as much as a first-class beginning. Without one, a matured bond, a fully settled receivable, a dissolved company decays under the fail-closed discipline into a permanently Pending object indistinguishable on the record from abandonment, and the entity whose history a court will want is exactly the one whose record ends unsigned. Termination is therefore a lifecycle kind of its own, admissible only as a declared transition under an authority gate \Phi names, never inferred from attestation decay, so completion and abandonment are distinguishable from the record alone. A well-formed terminal transition discharges four obligations. Extinguishment: \Phi’s outstanding obligations are settled, discharged, or assigned to a named successor claim, with any residual value carried by a named assignee. Lawful exit: the final filings and deregistrations each harbor’s rules require; where the asset is the institution itself, this is the retirement of the last harbor, the one transition the corridor grammar of §12 cannot express, because exit-prepare presumes a receiving jurisdiction. Record custody: a named custodian and retention term for \sigma, kept verifiable after the runtime stops by the re-anchoring construction given with Definition 4.4. The terminal receipt: a signed terminal digest over the chain head that closes \sigma, after which any append is invalid by construction; a post-mortem append is detectable as forgery, and the absence of closure is itself legible, since a chain without a terminal receipt is silent, not ended. The terminal receipt records the sovereign acts of dissolution or deregistration; it does not constitute them (§17.1).

Definition 4.2 (Jurisdiction). A jurisdiction J = (E_J, L_J, K_J) consists of an evaluator function E_J that maps an asset state and a proposed action to a cell value on a named domain, a content-addressed lawpack L_J of type \mathrm{Lawpack} that E_J consults, and a signing key K_J under an epoch-rotation schedule. Because E_J takes the proposed action as an argument, a passing cell is in general a verdict about a class of actions rather than a standing fact about the asset. When E_J returns a passing cell on an action’s required domains, J emits an attestation recording the cell together with the scope of action parameters over which the evaluation holds (Definition 4.4). An attestation that omitted that scope would serialize an action-specific verdict as a standing one.

Definition 4.3 (Compliance domain). \mathcal{D} is a finite, evaluation-time-fixed set of regulatory domains. Every proposed action is indexed by a required subset D_\mathrm{req} \subseteq \mathcal{D}. The reference deployment instantiates \mathcal{D} with exactly twenty-three domains: anti-money-laundering, know-your-customer, sanctions, tax, securities, corporate governance, custody, data privacy, licensing, banking, payments, clearing, settlement, digital assets, employment, immigration, intellectual property, consumer protection, arbitration, trade, insurance, anti-bribery, and Sharia compliance. Asset methodologies may define subdomains, oracle fields, and methodology-specific labels inside those domains; adding a new top-level domain is a coordinated schema-evolution event across participating jurisdictions.

Definition 4.4 (Attestation). An attestation \alpha = (J, d, v, P_\alpha, t_\mathrm{issue}, t_\mathrm{expire}, \epsilon, A_\mathrm{bind}, s_J) records that jurisdiction J evaluated domain d and assigned cell value v for asset A_\mathrm{bind} over the action scope P_\alpha, valid from t_\mathrm{issue} to t_\mathrm{expire} under cryptographic epoch \epsilon, signed by K_J with signature s_J over every preceding field.

The scope predicate P_\alpha is a decidable predicate on an action’s declared parameters, counterparty class, amount band, instrument type, and corridor, recording the conditions under which E_J reached the verdict v. Setting P_\alpha = \top, the identically-true predicate, marks a genuinely standing determination, one that holds for every action on A_\mathrm{bind} in domain d within the validity window; any narrower scope binds the verdict to the actions it was reached for. The asset-binding field A_\mathrm{bind} is the digest h_g of the intended asset’s genesis document: an attestation issued for one asset is not valid for another. Because amendments append to \sigma without changing h_g, the binding identifies the asset, not the asset’s current program state. In the companion Sovereign Jurisdiction Network paper’s terms, an attestation is a W3C Verifiable Credential under the eIDAS profile with these fields. The signing key is a composite under a specified combiner: an Ed25519 signature and an ML-DSA-65 post-quantum signature, verifying iff both component signatures verify.

Epoch policy and scheme retirement. The epoch \epsilon indexes a per-jurisdiction, append-only table of cryptographic policies: which signature schemes are acceptable, and over what period. Retirement of a scheme is a new row rather than an edit, and the verification rule follows: an attestation verifies under the policy in force when it was signed, not under the policy in force at verification. The table is never empty for a jurisdiction with live attestations, since an attestation whose epoch indexes nothing is unverifiable in a way indistinguishable from forgery.

The tag resolves a tension between two load-bearing commitments. The receipt chain is append-only: entries are never rewritten. Signature schemes break, and when one does, every historical record signed under it becomes unverifiable, while the obvious remedy, re-signing the archive under a new scheme, is exactly what append-only forbids. The resolution is that a record can be re-anchored without being re-signed. Append a fresh witness over the digest of the old record, signed under the new generation: the historical entry is untouched, its original signature stands as the artifact it always was, and a verifier who no longer trusts the old scheme has a chain to a signature it does trust. The construction recurses, each generation anchoring the previous one, so an archive outlives any particular scheme without rewriting a byte. What it cannot do is repair a record whose signature was forged before the bridge was laid, so the bridging witness must be appended while the retiring scheme is still sound, which makes scheme retirement a scheduled operation rather than an emergency one.

Definition 4.5 (Corridor). A corridor C(J_1, J_2) = (R, \mu, \gamma, P_\mathrm{commit}) between jurisdictions specifies a destination-side re-evaluation set R \subseteq \mathcal{D}, a partial domain-recognition map \mu, grade-recognition maps \gamma, and a commitment protocol P_\mathrm{commit} that stages, finalizes, and compensates cross-zone operations: the companion Op paper’s signed commitment protocol operated under the companion Sovereign Jurisdiction Network paper’s finality-certificate obligations. Corridors are asymmetric in general; \mu and \gamma may be defined under a mutual-recognition agreement or under a regional body’s standing authorization.

Axiom 4.1 (Recognition floor). For every corridor, \gamma maps no cell that is non-passing under §6 to a passing one: a NonCompliant or Pending cell on the sending side is NonCompliant or Pending on the receiving side. Sanctions lies in R of every corridor formed without an explicit shared-authority instrument over sanctions lists; this is the general-purpose corridor rule under which §3.1 re-evaluates Sanctions locally, and where such an instrument exists the first clause still binds.

The claim program is the source of three quantities the paper has so far named without constructing: who may hold the asset, what a receiving jurisdiction may rely on in the evidence it carries, and what it is worth. All three are read off \mathcal{V}(\Phi) and the compliance function of §6, and they belong in this section: an intelligent asset is not fully specified until they are fixed. Fix an asset A at time t, issued by an institution with harbor set H, and let \mathcal{N} be the population of candidate counterparties, each an institution with its own harbor set and attestation portfolio.

Definition 4.6 (Admissible holder set). The admissible holder set \mathrm{Hold}_t(A) is the set of e \in \mathcal{N} such that the transfer action a_e moving A to e has a passing verdict at t: every domain in D_\mathrm{req}(a_e) is passing in A’s action-scoped tensor T_{a_e}, every domain in D_\mathrm{req}(a_e) is passing in e’s, and the corridor joining e’s harbors to H admits the transfer under Definition 4.5 without obstruction. It is the image of \Phi’s transfer transition under that filter: computed, not declared, and moving whenever either side’s tensor moves. A sanctions transition in one harbor removes counterparties from \mathrm{Hold}_t(A) before any manual review, which is the formal content of the flag narrated in §3.8: a cargo that has crossed a designated party’s custody clears no further downstream transfer until re-evaluated.

Definition 4.7 (Reliance class). For a receiving jurisdiction J_2 and a corridor C(J_1, J_2) = (R, \mu, \gamma, P_\mathrm{commit}), the reliance class \mathrm{Rel}_t(A, J_2) is the image under \gamma of the attestations A carries at t on the domains \mu maps, together with the domains of R marked as requiring fresh evaluation on the receiving side. It records what a party in J_2 may rely on without re-executing the evaluation, and at what grade, and what it may not. Domains outside both \mu and R carry no reliance: by the fail-closed discipline of §6 they stand at Pending in J_2.

Definition 4.8 (Clearing price). Let Q be a pricing measure on the observables \Phi names and let D be a discount process, both supplied by the model under which the holder population prices. The clearing price \mathrm{Price}_t(A) is the value process \mathcal{V}(\Phi) at t under (Q, D): the Q-expectation of the discounted future cash flows, conditional on the information available at t, taken on the branches \Phi’s gate and hole constructors leave live at t. The holder set enters the price twice: a branch whose continuation requires a transition the §6 verdict refuses, a transfer to a counterparty outside \mathrm{Hold}_t(A) among them, is a branch some gate constructor zeroes; and Q prices over the population \mathrm{Hold}_t(A), the only counterparties who can lawfully take the other side of a trade. The channel by which a shrinking holder set moves the price through Q is the liquidity question the companion Pricing the Compliance Tensor takes up.

Definition 4.8 is a definition, not an existence theorem. It does not assert that Q is unique, that the market over \mathrm{Hold}_t(A) is complete, or that any price is attained in trade; those are questions about the holder population, not about the object, and the order structure of the conditioning is the subject of the companion Pricing the Compliance Tensor. What the construction fixes is the direction of dependence. A tensor transition can shrink \mathrm{Hold}_t(A) and can zero a branch of \mathcal{V}(\Phi), and both effects are computable from signed state; a price movement does neither. That is the sense in which compliance state is an input to the valuation rather than a disclosure printed beside it.

Matching, settlement, risk reservation, dispute, and recovery over these three objects are the clearing layer, which this paper does not construct; they are named among the open problems of §17.4.

The section closes with the object the genesis bullet and the claim-program grammar have been using: the gate through which every consequential transition, amendment above all, is admitted.

Definition 4.9 (Authority gate). An authority gate is a triple \theta = (D_\theta, \pi_\theta, \tau_\mathrm{proc}): a domain scope D_\theta \subseteq \mathcal{D}, an identity predicate \pi_\theta on authorized signers, and a process type \tau_\mathrm{proc} in the sense of Definition 11.1. The gate admits a proposed transition a at time t iff the verdict of §6 on a over D_\theta is passing in the action-scoped tensor T_a, and \sigma carries a PCAuth for the gate, an authorization site in the sense of Definition 11.2, whose signer satisfies \pi_\theta and whose process-provenance record is consistent with \tau_\mathrm{proc}. A gate is stricter than the compliance gate of Definition 9.3, which independently requires the action’s own D_\mathrm{req}(a), in exactly two ways: it may require domains beyond the action’s own, and it always requires a signature. A passing verdict alone admits nothing through a gate.

The genesis bullet of Definition 4.1 can now be discharged. The amendment rule fixed by g is: a transition of amendment kind, one whose successor state resolves a new amendable record (\Phi', \Lambda', p') of claim program, program family, and authoring principal, is admitted only when \theta_\ast admits it under Definition 4.9 and every predicate in \mathcal{I} holds on (\Phi', \Lambda', p'). Both conjuncts are mechanical: \theta_\ast’s admission is a §6 verdict plus a signature check, and \mathcal{I} is a set of decidable predicates. The rule is keyed to h_g, neither \mathcal{I} nor \theta_\ast lies in the range of any amendment record, and \pi_{\theta_\ast} names principal keys, never the runtime’s receipt-signing key.

Proposition 4.1 (Mandate invariance). Let A have genesis g with invariant set \mathcal{I} and amendment gate \theta_\ast, and let the genesis record (\Phi_0, \Lambda_0, p_0) satisfy \mathcal{I}. Then every amendable record (\Phi_n, \Lambda_n, p_n) reachable from genesis by runtime-admitted transitions satisfies \mathcal{I}; the rule under which amendments are admitted is the same at every n; and no admitted chain of transitions installs an authoring principal without a signature satisfying \pi_{\theta_\ast}, which no program handle in any \Lambda_i can produce.

Proof. Induction on the length of the admitted chain. The base case is the hypothesis on (\Phi_0, \Lambda_0, p_0). For the step, assume (\Phi_i, \Lambda_i, p_i) satisfies \mathcal{I} and consider the next admitted transition. If it is not of amendment kind, it leaves the amendable record fixed, since only amendment records resolve a new (\Phi, \Lambda, p) (Definition 4.1). If it is of amendment kind, the amendment rule admits it only if (\Phi_{i+1}, \Lambda_{i+1}, p_{i+1}) satisfies \mathcal{I}, which is the inductive claim. The rule itself is invariant along the chain: it is keyed to h_g, amendments append to \sigma and do not edit g (Definition 4.1), and \mathcal{I} and \theta_\ast lie outside the range of every amendment record, so no admitted transition reaches a state governed by a different rule. For the last clause, an amendment installing p_{i+1} \neq p_i requires a PCAuth whose signature satisfies \pi_{\theta_\ast}. Program handles are content digests with type signatures (Definition 4.1); they hold no signing keys, and the runtime signs receipts under its own key, which \pi_{\theta_\ast} does not name. A chain of admitted transitions can extend \Lambda, but each extension passes the same amendment rule and equips \Lambda only with handles, never with a key satisfying \pi_{\theta_\ast}. So the witness for principal succession is produced outside the asset’s own program family at every link of the chain. \square

The proposition is a statement about admission, not about key custody. A compromised principal key (Assumption 5.2) can author any amendment the rule admits; it cannot author one that violates \mathcal{I}, and it cannot replace \mathcal{I} or \theta_\ast, which no amendment reaches. What compromise costs is bounded by what the invariant set leaves amendable. The quorum, timing, and veto discipline above \theta_\ast is a governance choice (§17.4); the invariance is not.

5. Adversary and Trust Model

Assumption 5.1 (Cryptographic). The adversary is computationally bounded and cannot forge signatures under the composite scheme, find hash collisions, or compromise current-epoch private keys of sovereign evaluators.

Assumption 5.2 (Adversary powers). The adversary may delay messages within bounded asynchrony \Delta (in the sense of a partial-synchrony model); compromise a bounded subset of oracle feeds; propose malformed actions; cause a single evaluator to equivocate, presenting conflicting attestations for the same jurisdiction, domain, and asset to different observers; attempt to replay expired or revoked attestations; inject adversarial content into a delegated proposal program’s context via controlled oracle channels; influence the authoring of a lawpack prior to its content-addressing; compromise an authoring principal’s key post-genesis; and equivocate as a hosted-execution provider against pinned runtime-identity attestations.

Definition 5.3 (Scoped trust). Accepting an attestation signed by J under lawpack version L for domain d and asset A means: trusting that J’s designated evaluator correctly decided d under L for A within the validity window. No statement about J’s correctness outside this scope is implied. Scoped trust is a definition of acceptance in this architecture, not an assumption about the world.

Against this model the paper establishes: no forgery of attestations (5.1), no rewrite of historical receipts (chain structure), no silent override of NonCompliant composition on required domains (Remark 6.1), no execution of an action without a passing preflight verdict (§9 Proposition 9.1), no admitted chain of amendments that violates the invariant set or replaces the amendment gate (§4 Proposition 4.1), no cross-asset PCAuth replay (Definition 11.2 binding), no re-authorization of a suspended delegation without a fresh signed delegation (§10 monotonic-suspension). Against this model the paper does not establish: correctness of evaluators (scoped trust is a definition, not a guarantee), resistance to evaluator collusion (§17), resistance to model-provider silent substitution in the absence of verifiable weights commitments (§17), resistance to lawpack-corruption at authoring (§17), or elimination of race conditions in non-monotone channels outside the specified invariants.

6. The Compliance Function

The compliance function is a typed object on the asset’s state: a static composition of cell values, and a dynamic propagation on a labeled directed acyclic graph of domains (§7). The static algebra is the composition algebra of the companion Multi-Harbored Institution paper, imported here in the form the runtime uses.

Each compliance domain carries a cell with two axes. Applicability takes Applicable, NotApplicable, or Exempt; compliance applies only when Applicable and takes NonCompliant < Pending < Compliant. On cells whose applicability agrees, composition is the meet: the strictest verdict binds, and NonCompliant absorbs. When applicability disagrees across jurisdictions, composition is an n-ary reduction, not a lattice meet: it returns the meet of the Applicable grades with the non-applicable inputs retained as provenance flags, or a named obstruction when no input is Applicable and the inputs mix NotApplicable with Exempt. Obstructions are absorbing under further reduction and are surfaced, never coerced.

Remark 6.1 (Non-overridability). A required domain that is NonCompliant in any harbor cannot be outvoted by other domains’ or other harbors’ evidence: NonCompliant absorbs under the meet, and by Axiom 4.1 no corridor carries it into a receiving harbor as passing. The floor is structural: a fact of the meet and of the recognition maps, holding in every harbor set.

The runtime’s write discipline on the compliance state is fail-closed. At instantiation, every domain not declared out-of-scope by a genesis attestation stands at (Applicable, Pending). The runtime admits a cell write only when a valid attestation justifies it, binding the asset, domain, value, action scope, validity window, cryptographic epoch, and signature (Definition 4.4). At validity-window expiry the attestation leaves the standing state, any cell it alone justified reverts to Pending, and propagation (§7) enqueues. The consequence is that ignorance blocks: a domain no valid attestation covers stands at Pending, and any operation requiring that domain has a non-passing verdict.

Fix a proposed action a. The action-scoped tensor T_a assigns to each pair (J, d) the meet of the cell values of those \alpha \in \pi issued by J on domain d for which P_\alpha(a) holds, and (Applicable, Pending) when no such attestation is held. Several attestations by one jurisdiction on one domain under different scopes therefore coexist in \pi without T_a ceasing to be a function of (J, d), and where two scopes both cover a the strictest applicable verdict binds, under the same meet that composes across harbors. Standing determinations (P_\alpha = \top) enter every action’s tensor; narrower ones enter only the actions whose parameters they were issued against, so a verdict reached for one counterparty class and one amount band is never silently reused for another.

Write T for the state each T_a is read off: the assignment sending a pair (J, d) to the scoped cells \pi currently holds there, every cell carried with the predicate P_\alpha it was issued under. Issuance, expiry, revocation, and the propagation of §7 move T; a preflight (Definition 8.1) obtains T_a from T by selecting the scopes the action satisfies and taking the meet. T is the asset’s standing evidence; only T_a is a verdict about an action.

A cell is passing for an operation if it is Applicable-and-Compliant, NotApplicable, or Exempt. The verdict on an action a over a required domain set composes the cells of T_a domain-by-domain and is passing iff every cell is passing and no obstruction occurred. For an asset owned by an institution with harbor set H = \{J_1, \ldots, J_n\}, the verdict is a two-step reduction: compose across harbors per domain, then verdict across domains.

The residual on the in-scope fragment is Heyting implication, not remediation: because meet is restrictive, no cell can be met with the current state to make it more compliant. The practical planning object is a remediation operator that identifies which attestations, proof refreshes, or discretion-hole fills must replace stale or failing cells by authorized state transition.

7. The Propagation Graph

The dynamic half of the compliance function records the causal dependencies among compliance domains.

Definition 7.1 (Propagation graph). A propagation graph is a triple G = (\mathcal{D}, E, \lambda) with \mathcal{D} a finite domain set, E \subseteq \mathcal{D} \times \mathcal{D} a set of directed edges, and \lambda a labeling assigning to each edge the cell-transitions that trigger target-side re-evaluation. An edge (u, v) \in E_J records that J’s evaluator for v reads the value of u composed across harbors under §6, not J’s own cell at u alone, so a transition of u in any harbor moves an input of the cell (J, v), and E_J holds an edge for every source J’s evaluator for v reads: E_J is that evaluator’s read relation. Each per-harbor graph G_J is required to be acyclic. The institutional graph G_H is the labeled edge union across harbors after a validation pass that rejects harbor sets whose edge-union cycles; the composed-source reading is what lets the union carry a dependency from one harbor into another and makes a cycle in the union a cycle in fact. When a cycle is detected, the corridor-formation protocol requires negotiation or strongly-connected-component quotienting.

Proposition 7.1 (Propagation closure). Fix a finite DAG G_H and let domain d transition in at least one harbor. Let \mathrm{reach}(d) = \{d' : d \preceq d' \text{ in } G_H\}, and let the re-evaluation set be the set of cells (J, d') with (u, d') \in E_J for some u \in \mathrm{reach}(d): in each harbor, the targets of that harbor’s own edges whose source lies in \mathrm{reach}(d). Re-evaluating exactly this set, in rounds that follow a topological order of G_H, yields a tensor in which every cell’s justification reads the post-transition composed value of every source its rule names, and touches no cell outside \mathrm{reach}(d). Reach is computable in time O(|\mathcal{D}| + |E_H|) and the re-evaluation set in one further pass over the per-harbor edge lists. Re-evaluation terminates in at most |\mathcal{D}| closure rounds; each round’s operational cost is the evaluator-response latency for the touched cells.

Proof. Re-evaluate the cells of the re-evaluation set one topological level of G_H per round: every domain at the same longest-path distance from d, in all harbors, in one round. A source in \mathrm{reach}(d) of a domain at distance k lies at a distance below k, since any path from d to the source extends along the edge into the domain, so every cell is re-evaluated after every source its rule reads has settled. Let (J, x) be any cell and u any source its rule reads, so (u, x) \in E_J by the edge-label semantics of Definition 7.1. If the composed value of u is unchanged, the justification of (J, x) stands. If it changed, then either u = d or some cell (J', u) was re-evaluated in this pass, which happens only when (w, u) \in E_{J'} for some w \in \mathrm{reach}(d); in both cases u \in \mathrm{reach}(d), since E_{J'} \subseteq E_H. Then (u, x) \in E_J with u \in \mathrm{reach}(d) places (J, x) in the re-evaluation set, and it was re-evaluated after u settled. The harbor J is selected by its own edge into x, whether or not it carries any edge at d: with G_{J_1} = \{d \to e\} and G_{J_2} = \{e \to f\}, the cell (J_2, f) reads the composed value of e that (J_1, e) moves, and it is re-evaluated because (e, f) \in E_{J_2} with e \in \mathrm{reach}(d). Conversely a cell (J, x) with x \notin \mathrm{reach}(d) has no source in \mathrm{reach}(d), since an edge (u, x) \in E_J \subseteq E_H with u \in \mathrm{reach}(d) would place x in \mathrm{reach}(d); it is untouched. Reachability on G_H is linear, and the re-evaluation set is one pass over the per-harbor edge lists testing membership of each source in \mathrm{reach}(d). A pass by level has exactly as many rounds as the longest directed path from d has edges, which in a DAG on \mathcal{D} is at most |\mathcal{D}| - 1, so at most |\mathcal{D}| rounds. \square

Complexity is a type-level bound. Operational cost is dominated by evaluator-response times: a reach set of 15 domains touching 4 harbors is at most 60 evaluator calls, each with legal-process latency in the minutes-to-days range. Liveness under bounded evaluator latency requires timeout semantics: after a configurable timeout, the tensor reverts unanswered cells to Pending; the asset degrades to frozen or obstructed states until the evaluator responds.

Concurrent transitions are serialized per-asset by the receipt-chain append lock; cross-asset transitions have their own ordering through P_\mathrm{commit} of Definition 4.5, the companion Op paper’s signed commitment protocol operated under the companion Sovereign Jurisdiction Network paper’s finality-certificate obligations.

8. Preflight and Postflight

The compliance gate operates at two moments bracketing every execution.

Definition 8.1 (Preflight snapshot). At the preflight instant for action a, the runtime produces a preflight snapshot: a content-addressed record capturing T_a over D_\mathrm{req}(a), the chain head, the relevant delegation state, and a monotonic logical clock value. Admission is atomic in the snapshot: either the snapshot is consumed to admit a, or a is rejected. Because T_a is assembled from the attestations whose scope predicate a satisfies, the snapshot records the scope under which admission was granted, not only the domains it cleared.

Discipline 8.1 (Monotone observation). Within a single execution, the runtime observes the tensor at the preflight snapshot and does not re-consult the live tensor during execution. Changes between preflight and postflight update the live tensor without retroactively altering the snapshot.

Discipline 8.2 (Postflight attribution). Every transition of the standing state T carries its provenance: the attestation, expiry, revocation, or receipt event that caused it (§6, §7). At the postflight instant the runtime re-reads the verdict on the live tensor. A non-passing domain is attributed to a when the transition that moved it lies in the propagation reach (Proposition 7.1) of an effect recorded in a’s own receipt, and is external otherwise. The response is fixed: an external failure leaves a’s effects standing and freezes the asset; a failure attributed to a appends a compensating receipt reverting a’s effects. Both responses append; neither rewrites history.

Proposition 8.1 (Preflight-postflight safety). If the preflight verdict is passing and a’s effects are deterministic in the snapshot, then a executes exactly once; the attribution of any postflight failure is decidable from \sigma, the attestation log, and G; and \sigma records which of Discipline 8.2’s two responses ran.

Proof. Admission consumes the preflight snapshot atomically (Definition 8.1), so a is admitted at most once, and a passing admitted a with snapshot-deterministic effects runs to a unique successor state; the receipt append is a compare-and-swap on the chain head (Definition 4.1) that commits exactly one receipt or transitions the asset to a fault state with no partial append. Attribution is a reachability question on G from the transitions a’s receipt records, decidable in O(|\mathcal{D}| + |E_H|) by Proposition 7.1 over the provenance the write discipline of §6 retains. The response receipts are appends under the same chain discipline, so the case that ran is legible from \sigma. \square

A frozen asset permits only re-evaluation programs (Level-1 gates clearing obstructions) that do not effect Level-2 state changes. This avoids the deadlock wherein an asset in freeze cannot receive fresh attestations because further program executions are blocked.

9. The Smart Asset Virtual Machine

The execution layer is a deterministic virtual machine, the SAVM. The SAVM is the companion Op paper’s evaluator specialized to asset-resident programs; Level-1 compliance gates are Op-bytecode programs compiled from Lex rules under that paper’s admissible-compilation theorem, and Level-2 programs are Op programs principals author or delegated tooling generates under amendment governance.

Definition 9.1 (SAVM state). A SAVM state is \Sigma = (A, T, H, B, G), where A is the asset record, T is the standing evidence state of §6 over the current \pi projected through the current harbor set, from which every preflight reads the action-scoped tensor T_a the gate decides on, H is the harbor set resolved from the institutional pointer in g, B is the budget triple (gas, external calls, wall-clock) and G is the propagation graph for H. The asset record carries \Phi, and the machine consults it: the set of \lambda_i \in \Lambda the machine may attempt at a given lifecycle state is the set whose transition kind lies on a branch that \Phi’s gate and hole constructors leave live at that state, read under T and \sigma. Definition 9.3 then decides the attempt.

Definition 9.2 (SAVM transition). An invocation of program p with input x at state \Sigma computes

\mathrm{Step}_p : (\Sigma, x) \mapsto (\Sigma', r, y)

where \Sigma' is the successor state, r is the execution receipt, and y is the output. \mathrm{Step}_p is deterministic conditional on (i) the oracle-attestation vector supplied as preconditions to the call and (ii) the wall-clock deadline enforcement that may halt execution when the deadline is exceeded. The paper’s claim is therefore “deterministic in the oracle-attestation vector up to deadline-termination”; replay of a receipt requires preserving both the oracle vector and the termination boundary.

Definition 9.3 (Compliance-gated invocation). Let a be the action an invocation of p on input x proposes. Gated invocation admits the step only when, for every d \in D_\mathrm{req}(p), the composed cell of the preflight action-scoped tensor T_a at d is passing; otherwise it emits a reject receipt with no state change. An attestation whose scope predicate a fails contributes nothing to that verdict, so a determination reached for a different counterparty or a different amount band cannot admit a.

Proposition 9.1 (Gate witness). If gated invocation produces a non-\bot output, the preflight verdict was passing and the execution is recorded in \sigma with a chain-integrity receipt.

Proof. By Definitions 9.3 and 4.1: the only path to a non-\bot output runs through the passing branch; the receipt-chain append is a compare-and-swap against the chain head that either commits or triggers the runtime’s fault handling. \square

This is a witness property, not an end-to-end safety theorem. It does not assert correctness of the verdict, scope-containment of the output under delegation, or freshness of T at the preflight instant. Those are separate properties: §10 specifies scope containment under delegation; §11 gives principal-carried authorization its uniqueness discipline (Axiom 11.1, Proposition 11.1); §17 documents the gap between verdict validity and verdict correctness.

The budget triple is a first-class safety mechanism. Gas bounds deterministic-computation cost; call budgets bound external-service invocation cost; wall-clock budgets bound evaluator-response and real-time operations. Termination holds under exhaustion of the weakest of the three.

9.1 Level structure

Level-1 programs are compiled compliance-enforcement primitives bound to the asset by content-digest. Level-2 programs are the action logic, rebalancing, harbor-transition proposals, reporting, negotiation, and delegated proposal execution, that executes only after Level-1 verdicts pass. The runtime runs Level-1 first; a Level-2 program that attempts to alter compliance state fails structurally because tensor updates require sovereign-signed attestations, which Level-2 programs cannot forge.

9.2 Negotiation (via Op’s signed commitment protocol)

Two intelligent assets negotiating an exchange run the signed commitment protocol specified in the companion Op and Sovereign Jurisdiction Network papers: one phase locks terms and resources, one phase collects verdicts, and finality evidence determines commit or compensation. Op’s Locked<T, ω, ε> typestate carries each asset’s lockable interest through the commit window; failure on either side triggers compensation or a typed obstruction. The full cross-zone atomicity statement is an open protocol obligation under the finality assumptions stated in those papers.

10. Delegated Proposal Programs as Bound Programs

Delegated proposal programs are bound programs under the Level-2 class. Their integration requires specific additions to the handle type, the authorization model, the execution broker, and the receipt discipline.

10.1 Proposal-program handle

Definition 10.1 (Delegated proposal-program handle). A delegated proposal-program handle content-addresses a quintuple (r, q, \mathcal{T}, \delta, \beta) with:

  • r a runtime binding: a signed statement pinning the execution provider, runtime family, version, policy hash, and the provider’s current-attested integrity commitment where such a commitment is exposed. The architecture uses a provider attestation when bit-exact runtime commitments are unavailable; when verifiable commitments become available, the binding is strengthened without changing the surface. An equivalence-class predicate is permitted, trading bit-exact reproducibility for operational tractability against provider deprecation cycles.
  • q a frozen instruction and scaffold, content-addressed.
  • \mathcal{T} a typed tool scope: the finite set of operations the program may invoke, each with parameter types and required-domain sets.
  • \delta the principal’s signed delegation to this program instance.
  • \beta the budget triple (gas, external calls, wall-clock) governing this program’s invocations.

A change to r, q, \mathcal{T}, \delta, or \beta is a new handle and requires a signed amendment. Equivalence-class predicates reduce the frequency of principal-signature ceremony under provider deprecation; under an equivalence-class binding, provider deprecation within the class is a valid continuation; deprecation outside the class requires a signed amendment.

Model identity in the verdict path. The runtime binding pins what acted. The same discipline is owed to what judged. Where a verdict is produced with the help of a model rather than by a deterministic rule alone, the verdict must pin that model’s identity, a content digest of the weights and the decode parameters, at the moment of commit, exactly as an evaluation pins the lawpack version it was decided under. The reason is the same in both cases: a verdict is a claim about what the rules required at a time, and a rule set that has silently changed underneath it makes the claim unfalsifiable. Two consequences follow. First, re-running an old case under a newer model does not produce a corrected verdict; it produces a new observation, advisory unless an authority adopts it, because the original verdict was a statement about the state of the art at its own date and nothing later revises what that was. This is the same structure as re-evaluation under a superseding lawpack, which produces a new derived consequence and leaves the frozen historical fact untouched. Second, the verdict path itself must be deterministic: whatever a model contributes belongs on the evidence side, as an input a human or a rule then acts on, not inside the function that computes the verdict. A stochastic component in that function makes replay impossible, and replay is what the receipt chain exists to support.

10.2 Delegation and revocation

The delegation \delta uses macaroon-style capabilities (biscuits) with caveats. It names the program’s public-key identity, the permitted operations, the permitted resources, per-action and per-window monetary limits, the admissible discretion holes, the validity window, and the revocation state. The revocation state is monotone in suspension: an active delegation may transition to cooling, suspended, or revoked; it may not transition back. Returning to active requires a fresh signed delegation. Revocation propagates to admission-time checks within the bounded asynchrony of Assumption 5.2; any in-flight program state terminates at the broker on revocation and is not resumed.

Every program action produces an entry in a capability-id-keyed forensic index (append-only, with idempotent inserts) denormalizing the canonical receipt for regulator-grade forensic query. The index is a discovery feature, not a structural defense; the structural defenses are the tool scope, the delegation caveats, and the compliance gate.

10.3 Authorization graded by rollback cost

Role, scope, and monetary size are three axes of the authorization model. The cost of undoing an action is a fourth, orthogonal to the other three. Every operation in a tool scope \mathcal{T} carries a rollback class: reversible when a kernel action undoes its consequences and no effect crosses the asset’s boundary; hard to reverse when a compensating action recovers the position at a cost; irreversible when no kernel action undoes it, as with an external payment, a dismissal, a signed merger, a published filing. An operation whose class is undeclared is treated as irreversible.

The class grades admission asymmetrically between principals and programs. A human principal executes an irreversible action on role and scope alone. A machine-initiated irreversible action requires, in addition, either a per-action human counter-signature bound into the action’s receipt, or an explicitly granted unilateral capability, intended to carry a short validity window, for operations where waiting on a counter-signature costs more than the risk it retires. The grading is additive: it downgrades nothing, and the sanctions, licensure, role, monetary, and scope checks run independently and must also pass.

As specified, the gate verifies the presence of the counter-signature artifact, not its cryptographic validity against the principal’s registered key; per-action cryptographic binding, a cooling period after delegation issuance, and dual control for the most sensitive irreversible classes are open engineering obligations, in the same standing as the provider-attestation binding of §10.1.

10.4 Execution broker, context assembly, and the proposer-gate relationship

The execution broker handles all program-kernel interactions. The program reads through typed tools (including a read-only tensor view, a residual-computation tool, a corridor-listing tool, an attestation-request tool, and an escalation tool for discretion holes) and writes through typed tools whose execution is subject to admission. Every tool invocation is scope-checked against \delta before admission. The program has no direct database access; the broker holds delegations and presents only the public summary to the program.

The program is the proposer; the compliance gate is the admission filter. When a proposal is admitted, the program is the proximate programmatic cause of the action; when it is refused, the refusal is recorded with the proposal. This framing is epistemic, not causal: the gate does not trust program outputs to set compliance state, it treats them as inputs to a test on the tensor computed from sovereign-signed attestations. The kernel’s world model is not updated from proposal outputs; the receipt records the proposed rationale only as an input artifact scoped by the selected disclosure profile. The compliance gate cannot prevent compliance-passing-but-substantively-unwise proposals; it prevents compliance-failing ones. Liability for the former lies with the authoring principal whose delegation the program acted under.

10.5 Adversarial input and multi-step workflow defenses

Adversarial input is a realistic channel (Assumption 5.2). The architectural mitigations are:

  • Input partitioning: attacker-controlled content (counterparty inputs, oracle payloads derived from user content) is rendered in the program context with a structural marker that both the program and the broker can enforce; tool calls that reference content from attacker-controlled partitions carry a taint bit that propagates.
  • Dual-parser separation for high-stakes flows: a quarantine parser extracts structured facts from attacker-controlled content; a privileged program reasons only over the extracted structured facts.
  • Scope-narrowing against injected directives: the tool scope \mathcal{T} and the per-action caps in \delta bound the damage of a successful injection to the intersection of (compliance-passing actions) \cap (delegated actions); the size of this intersection is a deployment design parameter.

Multi-step workflows (search -> summarize -> draft -> review -> settle) admit a choice between per-step gates (safer, higher latency) and settlement-only gates (lower latency, admits mid-chain information leakage). The architecture admits both; the paper does not prescribe a policy. The delegation \delta may require per-step gating for high-stakes tool classes and settlement-only gating for low-stakes classes.

10.6 The rationale record on the receipt chain

A proposal rationale may contain confidential information, and it is not the whole record. Beyond the model identity and decode parameters of §10.1, the rationale record binds the digest of the stated plan and a per-step binding from each plan step to the range of the executed program that step produced. The record is capture, not reproducibility: a stochastic invocation is not replayable, so the auditable relation is between the frozen stated plan and the frozen executed program, and the receipt admits the per-step comparison without verifying conformance, the open problem §17.4 names as proposal-program specification conformance. The receipt chain supports three rationale-disclosure profiles: plaintext (publicly verifiable), regulator-only encrypted-at-rest with supervisor-key disclosure (see §13), and commit-and-reveal via zero-knowledge accumulator for scenarios requiring selective disclosure. The default is regulator-only.

11. Typed Discretion Holes and Principal-Carried Authorization

A compliance rule is rarely algorithmic in its entirety. A typed discretion hole is the formal object carrying the escalation to a human or a collective principal.

Definition 11.1 (Discretion hole). A typed discretion hole \eta = (\tau_q, \tau_a, \pi_\mathrm{req}, \tau_\mathrm{proc}) is a query type, an answer type, an identity-predicate on authorized signers, and a process type specifying the governance procedure, single-signer, quorum-signed, deliberation-windowed, ongoing-withdrawable, or a specified conjunction thereof. The process type is essential: the architecture distinguishes discretion holes filled by a licensed officer’s single-signature (e.g., a tax-election signature) from those filled under a structured consent process (e.g., Institutional Review Board approval, indigenous-council free-prior-informed consent, or a board vote with named quorum). A single cryptographic signature at a moment captures a stamp; the process type captures the deliberative protocol that makes the stamp legitimate under the relevant governance regime.

Definition 11.2 (Principal-carried authorization). A PCAuth is a tuple (k, \eta, a, t, A_\mathrm{bind}, \Pi, s_k) where k is the signing principal’s identifier (which may itself be a threshold-signature expression over multiple keys under the process type), \eta the authorization site, a discretion hole of Definition 11.1 or an authority gate of Definition 4.9 (a gate \theta authorizes as a site whose query is the proposed transition, whose answer type is approval, and whose identity predicate and process type are \pi_\theta and \tau_\mathrm{proc}), a : \tau_a(\eta) the answer, t the validity timestamp, A_\mathrm{bind} the asset digest, \Pi the process-provenance record (deliberation-window boundaries, consultation records, witness signatures where the process type requires them), and s_k the signature over (\eta, a, t, A_\mathrm{bind}, \Pi). Validity at time t_\mathrm{now} requires: the site’s identity predicate holds of k, s_k verifies, t_\mathrm{now} lies within the validity window, and \Pi is consistent with \eta’s process type.

Axiom 11.1 (At-most-once resumption). A discretion-hole encounter suspends the invocation that reached it. The runtime resumes a suspended invocation at most once; resumption consumes the encounter, and a second resumption of the same encounter is refused at admission.

Proposition 11.1 (PCAuth uniqueness per encounter). A discretion-hole encounter admits at most one PCAuth, and the resumption it authorizes is a distinct receipt in \sigma.

Proof. A PCAuth is checked and consumed only at resumption, where Definition 11.2’s validity conditions are evaluated. By Axiom 11.1 the encounter resumes at most once, so at most one PCAuth is consumed for it, and the resumption receipt records which. \square

The A_\mathrm{bind} field forecloses cross-asset PCAuth replay: a signed hole-fill for asset A is not a valid fill for asset B. The process-provenance record \Pi makes the procedural requirements of complex consent frameworks first-class: FPIC under Convention 169 of the International Labour Organization and the United Nations Declaration on the Rights of Indigenous Peoples, Institutional Review Board review under national research-ethics regulations, quorum-voting records for board actions, and Nagoya-Protocol benefit-sharing arrangements all have a place on the receipt chain and a formal check on the SAVM’s admission path.

12. Corridors, Composition, and Harbor Transitions

When an asset adds a harbor J_2 or retires a harbor J_1 under a lawful transition, the corridor determines what happens: domains in the re-evaluation set R are freshly evaluated; domains mapped by \mu and accepted by \gamma carry under mutual recognition; domains outside both default to Pending. The transition runs under P_\mathrm{commit} of Definition 4.5, the companion Op paper’s signed commitment protocol operated under the companion Sovereign Jurisdiction Network paper’s finality-certificate obligations: the sending jurisdiction emits an exit-prepare when an existing harbor is being retired, the receiving jurisdiction emits an entry-prepare, evaluating R and producing fresh attestations, a corridor-finality receipt appears in both chains when the finality evidence is present, and on failure the transition is compensated, obstructed, or aborted according to the signed terminal state.

Across mixed-axis cells, composition is partial: obstructions halt the reduction and are reported. Route coherence of corridors is an explicit check over the re-evaluation masks, domain-recognition maps, grade-recognition maps, pack-version windows, and legal-instrument clauses. The working examples of §3 assume only those corridor behaviors for which the relevant route-coherence checks pass.

The corridor protocol interoperates with existing multilateral mechanisms at the level of attestation recognition:

  • Treaty composition: Multilateral Instrument treaty look-ups are evaluator inputs for tax domains; an attestation’s image under the grade-recognition map \gamma on a mapped tax cell carries through only when the relevant bilateral treaty recognizes the corresponding tax fact.
  • Information exchange: Common Reporting Standard and Foreign Account Tax Compliance Act reports are attestation-projection operations on the receipt chain’s financial-account view; an intelligent-asset treasury operating under these regimes produces compliant reports as a receipt-chain projection rather than as a separate pipeline.
  • BEPS Pillar-2: Global Anti-Base-Erosion top-up tax is handled by a tax-fiber workflow rather than ordinary compliance meet. The country-by-country-reporting cell, the Qualified Domestic Minimum Top-Up Tax cell, and the Income Inclusion Rule cell supply signed inputs; GloBE interactions, safe-harbor elections, treaty positions, and top-up-tax allocation remain a formal tax-composition obligation. The Transitional Country-by-Country Reporting Safe Harbor election is a discretion-hole fill by the group tax head.
  • Paris Agreement Article 6: corresponding-adjustment attestations for internationally-transferred mitigation outcomes are attestations signed by the host jurisdiction’s designated national authority; they are first-class objects in the receipt chain, not derived.
  • EU eIDAS: attestations follow the W3C Verifiable Credential profile specified in the companion Sovereign Jurisdiction Network paper; eIDAS cross-border recognition under Regulation (EU) 2024/1183 (eIDAS 2.0) flows to these credentials.

When harbor-transition compliance cost is proof verification plus corridor-required re-evaluation, the time-constant of regulatory-quality signals shortens. Cheaper exit sharpens whatever competition jurisdictions are already running, toward quality or toward laxity. The architecture sets the floor: under Remark 6.1 and Axiom 4.1 a failing Sanctions cell never composes away, across harbors or through a corridor. Politics sets the direction (§17).

13. The Supervisor’s Control Surface

We require the architecture to expose operational authority to the sovereign. The supervisor’s control surface is a set of primitives that are ordered above any principal delegation.

Definition 13.1 (Supervisory order). A supervisory order \omega = (K_\mathrm{sup}, \kappa, \tau, \Psi, s_\mathrm{sup}) is an order of kind \kappa (among: halt, unhalt, freeze-class, impose-requirement, reclassify-asset, mandate-disclosure, require-attestation-from) with parameters \Psi, addressed to a set of assets \tau in harbors under the supervisor’s authority K_\mathrm{sup}, signed by s_\mathrm{sup}.

Axiom 13.1 (Supervisor seniority). Supervisory orders are monotone over principal delegations: an authoring-principal delegation cannot override a supervisory halt. A supervisory unhalt can lift a supervisory halt; no principal authorization can.

Definition 13.2 (Late-binding requirement). When a supervisor requires compliance with a requirement not present at an asset’s genesis (an emergency regulation, a new sanctions list, a newly enforced right), the late-binding-requirement primitive: (1) attaches the requirement to one or more of the fixed twenty-three compliance domains, (2) injects initial tensor cells at (Applicable, Pending) for every affected asset inside those domains, (3) triggers propagation from the injected cells to downstream requirements, and (4) enforces the fail-closed default until sovereign evaluators issue attestations. Adding a new top-level domain to \mathcal{D} is a network schema-evolution event, not a per-asset supervisor order.

Definition 13.3 (Liability map). Every bound program’s execution receipt carries a liability tag identifying the responsible parties for each failure mode: the authoring principal (for program-authorship decisions), the evaluator (for attestation correctness within scoped trust), the oracle signer (for feed content), the hosted-execution provider (for proposal outputs within provider-attested-binding scope), and the corridor operator (for cross-zone commitment integrity). The failure modes, with their detection, loss bounds, and remedies, are enumerated in §17.5.

The supervisor’s read view spans the harbor’s full asset set. Supervisory reads carry the supervisor’s signature and are recorded in an audit log separate from the asset’s receipt chain; asset-holders can verify which reads touched their asset. The supervisor cannot read plaintext rationale from proposal receipts except under a specific disclosure order.

15. An Object Taxonomy

We enumerate twelve object classes. Each is characterized by what it observes, which domains its actions require, how it settles, how it fails, and which programs it carries; three classes, I, XI, and XII, are worked in full because the lifecycles of §3 turn on them.

  • Class I. Cross-border financial operator. Payments, remittance, working-capital provisioning across jurisdictions. It observes identity-verification feeds, sanctions lists, and transaction-monitoring feeds; its actions require AML, Sanctions, ConsumerProtection, Payments, Banking, and Tax, with foreign-exchange reporting a methodology field inside the Payments/Banking/Tax domains; it settles continuously; it carries compiled AML/sanctions gates plus a delegated proposal program for novel onboarding.
  • Class II. Collective investment vehicle. Fund, structured product, revenue-linked note. Observes portfolio marks, revenue attestations, and index feeds; requires securities, tax, custody, and sanctions; settles continuously with distribution events.
  • Class III. Contingent-rights instrument. Options on regulatory conditions, exercise on attested outcomes; requires IP, licensing, and trade.
  • Class IV. Islamic-finance instrument (sukuk). Sharia-certified structured cash flows; the required domains must include Sharia.
  • Class V. IP index instrument. Weighted index of IP-backed cash flows; requires IP and Trade, with withholding-tax treatment recorded as Tax-domain methodology fields.
  • Class VI. Experiential claim. Right to a named service at a specified time and identity; requires consumer protection and data privacy; retail exposure flags for supervisory review.
  • Class VII. Multi-jurisdictional treasury / in-house bank. Cross-harbor working-capital operations under BEPS Pillar-2, CRS, FATCA, and treaty regimes. Adjacent to incumbent enterprise-resource-planning and treasury systems via typed watcher-attestations and journal-entry projections.
  • Class VIII. Physical infrastructure asset. Data center, port, transmission line, generation facility. Sensor-fusion oracle under Byzantine quorum; split between physical-jurisdiction harbor (land) and operating-entity harbor; export-control domain for workload-bearing facilities; grid-interconnect harbor for energy-market participation.
  • Class IX. Consent-governed scientific or cultural corpus. Genomic database, music catalog, research dataset. Participant-as-principal (§14); structured-consent cells; IRB-integrated discretion holes; withdrawal propagation on the derivative-use graph; Nagoya-Protocol benefit-sharing for applicable genetic resources.
  • Class X. Natural-system steward. Rainforest, fishery, aquifer, coral reef, mangrove belt. Multi-sovereign compact including recognized indigenous-council harbor under the council’s own governance; FPIC as process-typed discretion hole; buffer-pool-backed permanence across the methodology’s asset pool; leakage accounting through adjacent-tract monitoring; Article-6 corresponding-adjustment attestations for cross-border credit flows.
  • Class XI. Trade-finance receivable and receivables pool. Origination-time-wrapped bilateral trade instruments and their aggregated pools. The class observes shipment and bill-of-lading attestations, customs attestations, sanctions and export-control feeds, counterparty identity-verification attestations, and bank-signed letter-of-credit chains. Its actions require AML, Sanctions, Trade, Payments, Banking, Tax, and KYC; export-control, foreign-exchange reporting, customs, and counterparty-identity are methodology fields inside those domains. Settlement is finality-on-shipment-confirmation at origination and tranched-with-continuous-distribution at the pool layer. The class carries compiled Level-1 gates for the seven required domains plus Level-2 pool-management programs for concentration-limit enforcement, expected-loss computation under the methodology, and investor-tranche settlement via Op signed commitment. Pool tranching, senior / junior / first-loss waterfalls, over-collateralization, concentration limits per obligor and per corridor, dilution protection for investor entries and exits, capacity caps, is expressed through Level-2 programs composed over the pool’s receipt chain; credit-event semantics are explicit: a receivable in default transitions to a NonCompliant compliance state under the pool methodology’s domain, subordination is enforced at distribution-computation time, and recovery flows append to the pool’s receipt chain as attested proceeds. The class is structurally distinct from Class II (collective investment) in its origination-time attestation discipline and from Class III (contingent-rights instrument) in its settlement pattern; it is the specific instantiation on which §3.7 and §18.2 turn.
  • Class XII. Physical commodity in transit. A cargo, oil, metals, grain, LNG, petrochemicals, as an intelligent asset whose state carries origin, quality, custody-chain, shipping, insurance, and dispute-resolution documentation. The class observes independent-surveyor feeds (SGS, Bureau Veritas, Intertek), bill-of-lading chains and their electronic equivalents under eUCP version 2.1 or Bolero, customs attestations at load and discharge, flag-state registry, port authorities, marine-insurance-binder attestations from Lloyd’s syndicates, voyage-tracking from AIS, and sanctions and export-control feeds. Its actions require Sanctions, Trade, KYC, Custody, Insurance, and Arbitration; export-control, origin declaration, cargo quality, counterparty know-your-customer, and chain-of-custody integrity are methodology fields inside those domains. Settlement is structured against delivery milestones (load, in-transit, discharge, final-acceptance) with settlement conditioned on each milestone’s attestation; paired hedges (forward freight agreements, futures, options) compose under Op’s multi-asset signed commitment. On failure the class freezes on sanctions or chain-of-custody transition, compensates where the hedge’s reconciliation closes independently, and reverts on pre-discharge failure; it carries Level-1 gates for the six required domains plus Level-2 monitoring and dispute-resolution programs. The class operates under a chain-of-custody propagation graph orthogonal to the regulatory-domain graph of §7; transitions in either graph can flag the other for re-evaluation, and secondary-sanctions propagation runs through the custody graph rather than only through the domain graph. Arbitration-forum selection is a process-typed discretion hole under the admissible forum set (GAFTA, FOSFA, LMAA, LME, LCIA, ICC, SIAC, English High Court, New York Supreme Court). Class XII is structurally distinct from Class XI’s purely-financial receivables.

The classes are not disjoint: a hyperscale data center under a consented-telemetry regime for environmental claims is both Class VIII and Class IX at different layers; a trade-receivables pool financing a Belt-and-Road infrastructure project combines Class VIII and Class XI; a commodity cargo paired with a forward-freight derivative is Class XII composed with Class III. The taxonomy is a vocabulary, not a partition.

16. Prior Art

The architecture sits in several traditions. We engage each.

Institutional economics. Douglass North’s Institutions, Institutional Change and Economic Performance (1990) establishes that institutions reduce transaction costs and that institutional change compounds over generations. The intelligent asset is an operational realization of North’s thesis at the instrument layer: the algebra is designed to lower cross-jurisdictional transaction costs; the receipt chain makes institutional change auditable at a finer time-constant than North’s empirical record admitted. Oliver Williamson’s transaction-cost economics frames cross-organization coordination friction as the core explanandum; the architecture offers a computational substrate for Williamson’s hierarchies-vs-markets distinction. Elinor Ostrom’s Governing the Commons (1990) identifies eight design principles for common-pool-resource institutions; the architecture instantiates seven of them as formal primitives (boundaries as harbor set, congruent rules as composed tensor, monitoring as oracle surface and propagation graph, graduated sanctions as the lattice ordering and obstruction semantics, conflict-resolution via discretion-hole escalation, recognition to organize via authoring-principal delegation, nested enterprises via multi-harbor composition). The eighth (collective-choice arenas) remains institutional and exogenous.

Hirschman’s exit-voice framework. Exit, Voice, and Loyalty (1970) frames the dynamic of organizational decline and recovery. Cheap exit across jurisdictions sharpens the exit channel; voice remains in the deliberative mechanisms the architecture makes possible (amendment governance, discretion-hole fills, participant-principal trees). Loyalty is the rate of exit discounted by institutional attachment; the architecture changes the price of exit, not the institutional attachment. Tiebout’s model of local-jurisdiction choice (1956) is the priced counterpart of the exit channel: mobile constituents sort across jurisdictions on the quality of their rules, and cheaper exit sharpens the sorting.

Smart contracts and their verification. Lessig’s Code and Other Laws of Cyberspace and the smart-contract-verification literature (KEVM; F* translation of Solidity; Sergey and Hobor on concurrent interactions) address code-as-law and code-safety-in-isolation. The intelligent asset inverts the obligation: isolated-code safety is necessary but insufficient; execution must additionally clear a composed compliance verdict. Necula’s proof-carrying code is the closest precedent: an artifact is accompanied by a proof of a property its consumer cares about. The receipt chain itself descends from Haber and Stornetta’s hash-linked time-stamping. Recent work (Move’s linear resources, Cairo’s ZK-provable execution, Vyper’s verification push) continues the tradition; the intelligent asset’s typed discretion holes and PCAuth sit alongside Move’s resource types as adjacent formalizations.

Financial-contract description languages. The term structure of \Phi is not new, and naming its ancestor makes the actual contribution precise. Peyton Jones, Eber, and Seward’s contract combinators (ICFP 2000), in the revised grammar of Peyton Jones and Eber (2003), give a small compositional algebra, zero, one, give, and, or, cond, scale, when, anytime, until, whose denotation is a value process under a model for the observables; \mathrm{ClaimProgram} in §4 is that algebra plus two constructors. Its commercial line of descent runs through LexiFi’s contract-description language and the pricing systems built on it. The lifecycle kinds each \lambda_i \in \Lambda ranges over, issuance, attestation, transfer, partial settlement, dispute, recovery, revocation, amendment, and termination, map into the ISDA Common Domain Model’s lifecycle-event vocabulary where the two vocabularies share ground: issuance to contract formation, transfer to transfer, amendment to terms change, termination to termination. Attestation, revocation, dispute, and recovery have no Common Domain Model counterpart, and they are the entries that carry the sovereign layer. FpML supplies the corresponding product representation in industrial use. Two things are this architecture’s own and are in neither predecessor. First, a lifecycle transition is gated on a jurisdiction-indexed attestation state: in the combinator tradition a term’s admissible transitions are fixed by the term and the observables it names, and here they are additionally fixed by the action-scoped tensor of §6. Second, admissibility is decided by an external sovereign signature rather than by a party to the contract or by the term’s own semantics, which is what makes one term portable across jurisdictions. The contribution at the claim layer is the gating, not the algebra.

Programmable securities. ERC-1400, ERC-1404, ERC-3643 (T-REX) implement transfer restrictions through on-chain compliance modules. Zetzsche, Arner, and Buckley, and Cong and He, and the DeFi literature (Harvey, Ramachandran, Santoro) map the product layer above these standards. Central Bank Digital Currency experiments (mBridge, Project Agora, Project Helvetia) prototype multi-jurisdictional programmable money. Tokenized real-world-asset platforms (Centrifuge, Ondo, RealT) instantiate specific asset classes. The intelligent asset operates at the primitive layer below these: the compliance surface composes sovereign attestations directly, not per-token compliance modules.

Delegated automation. Capability-security systems, proof-carrying code, workflow engines, and typed effect systems supply the conceptual frame for scoped delegated programs. The architecture treats every such program as a proposer whose outputs enter the same admission filter as any other caller.

Environmental governance. The Integrity Council for the Voluntary Carbon Market’s Core Carbon Principles and the Voluntary Carbon Markets Integrity Initiative’s Claims Code of Practice define the integrity frameworks that contemporary voluntary carbon markets converge on. Article 6 of the Paris Agreement (6.2 ITMOs, 6.4 centralized mechanism) governs international transfers of mitigation outcomes with corresponding-adjustment requirements on nationally-determined contributions. The UNFCCC REDD+ framework (project-scale and jurisdictional-scale) specifies the institutional machinery for forest-carbon. The Nagoya Protocol on Access and Benefit-Sharing governs benefit flows for genetic resources. The architecture’s Class X is an engagement with this governance stack, not a substitute for it.

Legal theory. H. L. A. Hart’s Concept of Law (open texture of rules; primary and secondary rules) frames the boundary between what law can specify and what requires judicial interpretation; the architecture’s typed discretion holes are an engineering formalization of the boundary Hart names. Dworkin’s Taking Rights Seriously and Law’s Empire (principles vs rules; constructive interpretation) are outside the admissible fragment the architecture operates on and inform the limits of §17. Luhmann’s systems theory of law and Teubner on reflexive law supply the frame for understanding the architecture’s interaction with legal sub-systems; Kelsen on the pure theory of law is the reference for rule-hierarchy formalization that the lawpack-versioning discipline echoes.

High-risk automated systems regulation. Regulation (EU) 2024/1689 classifies automated systems deployed in financial decisioning and critical infrastructure as high-risk, with obligations around human oversight (Article 14), transparency (Article 13), risk management, and incident reporting. The architecture’s delegated-program integration sits within these obligations: scope-gating and forensic-indexing implement technical transparency and human-oversight hooks; receipt-chain rationales and delegation-revocation discipline support incident reporting. Singapore’s Monetary Authority Veritas framework (fairness, ethics, accountability, transparency) maps onto the same surface.

Prior-period compliance frameworks. Financial Action Task Force Recommendation 16 (travel rule); Basel Accords; EU passporting (investment-services and banking); e-Estonia X-Road; Cosmos Inter-Blockchain Communication; Schrems II and transatlantic data-transfer frameworks (Privacy Shield, Data Privacy Framework). Each of these is a partial or adjacent construction of pieces the intelligent asset composes; the architecture is distinguished by its algebraic treatment of composition across these regimes rather than by operating within any single one.

17. Limitations and Open Problems

The architecture’s limitations partition into admissibility preconditions, permanent features, political preconditions, and engineering tradeoffs. The distinction matters: some conditions are external bindings without which the object cannot have legal force; others are permanent boundaries of what cryptography and formal methods can certify.

17.1 Admissibility Preconditions

Legal force. The architecture builds infrastructure legal regimes can reference; in the absence of sovereign legal recognition of the attestation chain, signatures prove provenance but do not alter legal status. Legal force is an external binding condition, not an engineering residual. Deployment pilots must begin with no-action letters, regulatory-sandbox participations, or treaty instruments that reference the attestation format.

Mixed-axis structure remains open. The composition operation is algebraically complete on the in-scope fragment; across mixed-axis cells, the algebra returns named obstructions rather than lattice points. Whether the product admits a categorical generalization (a partial-Heyting structure with named obstruction classes, a distributive-lattice quotient under obstruction-absorption) is an open formal problem. The worked examples in §3 assume corridor behavior within the established region and annotate the assumption where it is load-bearing.

Bootstrapping coordination. The architecture is deployable only if a coalition of jurisdictions of some minimum size N, a deployment parameter this paper does not estimate, adopts compatible evaluator implementations. A single-jurisdiction deployment is a demonstration, not operational infrastructure. Historical precedents for such coalitions (Hague Apostille Convention, IBAN, SWIFT, ISO 20022, eIDAS) took years to decades to form. The architecture does not accelerate coalition formation; it provides the object the coalition can coalesce around.

17.2 Permanent features

Correctness non-verifiability. Sovereign evaluators produce cryptographic provenance, not cryptographic correctness. A faithfully-recorded incorrect attestation is indistinguishable from a correct one within the system. Mitigations (audit rights, independent re-execution, cross-jurisdictional challenge, reputational accountability) are institutional: they are the pre-existing substrate, not novel mechanisms.

Proposal-program epistemic limits. The compliance gate bounds the program’s blast radius to the intersection of (compliance-passing actions) \cap (delegated actions). It does not bound the program to the set of wise actions within that intersection. Proposal outputs may be wrong; the architecture’s structural defenses are the scope-gating of \delta, the monetary caps within \delta, the per-step gating of high-stakes workflows, the principal oversight at discretion holes, and the receipt-chain reviewability. These defenses constrain failure modes; they do not eliminate judgment risk.

Evaluator collusion. Collusion among evaluators of different jurisdictions to issue consistent-but-wrong attestations is not detectable cryptographically. Detection requires external audit, independent re-execution, or a whistleblower, the same institutional mechanisms that currently partially catch cross-jurisdictional fraud. The algebraic structure preserves every attestation with its signer, making collusion observable after-the-fact; it does not prevent it.

Hosted-execution silent substitution. Until verifiable runtime commitments are published by hosted-execution providers, pinning execution identity relies on vendor attestation. A provider who silently substitutes a different runtime than attested produces proposal outputs that pass the gate but may behave unexpectedly. The architecture’s structural response is equivalence-class bindings (reducing substitution’s domain), rationale-recording (making substitution’s behavioral signature detectable), and multi-provider execution for critical flows (reducing dependence on a single provider). The vulnerability is reduced, not eliminated.

Lawpack corruption at authoring. An adversary who corrupts a lawpack prior to its content-addressing produces signed-valid, substantively-wrong attestations thereafter. Lawpack integrity depends on the authoring jurisdiction’s processes.

17.3 Political preconditions

Race-to-the-bottom. The architecture lowers jurisdictional exit costs. Whether this produces quality-competition or laxity-competition is a political-economy question of participating jurisdictions. Remark 6.1 with Axiom 4.1 provides an algebraic floor on the in-scope fragment; corridor designs can mandate fresh evaluation of any domain the receiving jurisdiction does not trust. Fraudulent attestations and capture-at-source remain open to the same political-economy dynamics that drive current regulatory arbitrage.

Legitimacy of novel principals. Class IX’s participant-as-principal tree, Class X’s indigenous-council harbor, and multi-sovereign compacts all require legitimacy that the architecture cannot produce. The architecture provides the structural hooks (Merkle-rooted trees, process-typed discretion holes, multi-sovereign harbor sets); the legitimacy must come from the participants, the communities, and the sovereigns involved, under processes the architecture does not prescribe.

Policy environment. The architecture does not oppose transatlantic flows, substitute for the U.S. dollar, or bypass OFAC secondary-sanctions authority over participating parties. Where U.S.-led sanctions regimes apply, it makes compliance with those regimes more auditable, not less; where EU frameworks apply, it supports their enforcement wherever their reach is legitimate. The political-economic bet is that cheap, verifiable compliance is positive-sum for many participants, including the United States and the European Union, when the regimes involved value auditable compliance more than friction as leverage. Near-term corridors form where political will and corridor economics align; the mechanism is not specific to any corridor.

17.4 Engineering tradeoffs

Temporal drift, bounded-asynchrony windows admit stale-snapshot actions; monotone observation ensures in-flight consistency at the cost of postflight freeze for externally-driven tensor changes.

Privacy, zero-knowledge proofs cover predicates expressible as arithmetic circuits; graduated disclosure under encrypted-at-rest supervisor-disclosure keys handles the common regulatory-disclosure cases; many compliance determinations involve unstructured evidence that admits no clean cryptographic privacy regime.

Program-authoring governance, the quorum, timing, and veto discipline above the amendment gate \theta_\ast is a governance choice; what is architectural is the immutability of \theta_\ast and of the invariant set \mathcal{I} it protects, and the reachability bound Proposition 4.1 draws from them. Multi-signature quorum, time-delayed governance, and participant-veto mechanisms are composable options above the gate.

Negotiation atomicity under adversarial failure, the companion Op paper’s session-typed commit gives local resource safety and bounded blocking under fail-stop assumptions; the companion Sovereign Jurisdiction Network paper states the finality-certificate and accountable-disagreement obligations needed for cross-zone atomicity. The Byzantine-adversarial case remains open in the interaction between them.

Corridor functoriality (full mixed-axis), proposal-program specification conformance, evaluator mechanism-design under incentive-compatibility, and withdrawal-propagation completeness on the derivative-use graph are the principal open formal problems. Clearing-layer specification is the principal open specification: matching, settlement including the binding of a reliance class to a relying party, risk reservation, dispute, and recovery over the admissible holder set, the reliance class, and the clearing price of Definitions 4.6 to 4.8. This paper constructs the clearing layer’s typed inputs and does not construct the layer, and no companion paper in this programme does either.

17.5 Failure modes and remedies

The architecture’s failure modes are enumerated with their detection, loss bounds, and remedies. The loss bounds follow from the construction: scoped trust under Definition 5.3, the delegation caps and rollback classes of §10, and the fail-closed default of §6. Detection runs on replay of the receipt chain under Definition 9.2, on postflight attribution under Discipline 8.2, and on the institutional substrate of §17.2. Where a detection path or a remedy names a mechanism this paper does not construct, a standing replayer network, a challenge protocol, an evaluator bond, a rollback procedure, it is a design option over that substrate, and its incentive design is the evaluator mechanism-design problem of §17.4.

  • Kernel bug admits a non-compliant action. Detection: the runtime fault handler, and replay of the receipt chain by any party holding it (Definition 9.2); a standing network of independent replayers is a design option. Loss bound: the admitted action’s settlement size, capped by the acting delegation’s monetary limits where the action ran under a delegation. Remedy: a compensating receipt reverting the action’s effects (Discipline 8.2), invalidation of the proofs that depended on it, lawpack or kernel refinement, and recovery flows for downstream operations; rollback of settled downstream state is a governance option. Insurance or indemnity may cover operational handling costs; proof/admission correctness itself remains outside indemnity.
  • Evaluator silently mis-signs an attestation. Detection: re-execution of the evaluation by an external auditor or a second jurisdiction, the institutional challenge of §17.2; a challenge protocol in which any party disputes an attestation by filing a structured counter-attestation is a design option over it. Loss bound: the affected asset’s exposure to the mis-signed domain; scoped trust (Definition 5.3) limits contagion to attestations from that evaluator under that lawpack for that domain within the validity window. Remedy: scoped trust restricts the blast radius; an evaluator bond posted at onboarding, paying verified loss, is a design option whose incentive-compatibility is the open problem of §17.4.
  • Lawpack corrupted at authoring. Detection: independent attestation of the lawpack at content-addressing, by the authoring sovereign’s legal department and a technical auditor, is a design option over the authoring jurisdiction’s processes; downstream consumers may challenge a lawpack. Loss: every attestation issued under the corrupted version is substantively wrong until detection. Remedy: lawpack republish, re-execution of affected evaluations, and recovery flows for any settled transaction whose verdict depended on the corruption.
  • Delegated program proposes a compliance-passing-but-substantively-unwise action. Loss bound: the program’s delegation monetary cap and per-window limits, differentiated by rollback class (§10.3): under a counter-signature-scoped delegation an unwise irreversible action cannot execute machine-solo, and the monetary caps bound the reversible and hard-to-reverse residue. Remedy: principal review at discretion holes; rationale review on the receipt chain admits forensic analysis in which each step of the stated plan is compared against the executed program range bound to it (§10.6); systematic patterns trigger amendment to the handle’s tool scope or the principal’s suspension of the delegation.
  • Sovereign revocation mid-settlement. The postflight gate catches external transitions and freezes the asset; in-flight settlements either complete under finality evidence, return a recorded obstruction, or compensate through the signed-commitment failure branch. Remedy: the compensation record is a first-class asset whose claim against the counterparty runs under the corridor’s agreed fallback rules.
  • Hosted-execution silent substitution. Detection: rationale-signature pattern analysis admits detection of behavioral drift; equivalence-class bindings (§10.1) reduce the substitution’s admissible scope. Loss bound: the program’s delegation monetary cap. Remedy: multi-provider execution for critical deployments; vendor-attestation audit.

Losses are scoped by delegation, by attestation, and by the algebra’s fail-closed default; recovery procedures are named per failure mode.

18. Implications at Scale

The architecture’s consequences depend on adoption. This section states conditional mechanisms, not forecasts: it traces how the worked lifecycles in §3 aggregate into population-level outcomes when their named preconditions hold.

18.1 Investment attraction as a structural property

We model the exclusion of previously-inaccessible asset classes from allocator portfolios as driven by verification cost rather than by return. Trade-finance paper can yield three-to-four per cent over sovereign reference rates. What excludes it from pension, insurance, and sovereign-wealth allocation is often the cost of compliance-chain verification per asset: when the per-receivable due-diligence cost exceeds fifty basis points, the instrument can fall below the allocator’s net-of-fees floor and remain on bank balance sheets. The architecture’s investment-attraction mechanism is verification-cost compression: when the compliance chain is content-addressed, verifiable by re-execution, and signed by evaluators under rules the allocator’s risk team can independently read, the per-asset verification cost can compress toward signature checking, proof-bundle replay, and sampled re-execution. Instruments that previously priced their verification overhead as a floor on spreads can price verification more like a commodity only when the legal, rating, performance, and mandate conditions align.

The §3.7 trade-receivables pool is the canonical case. A pool of Arabian-Chinese trade receivables operating as an intelligent asset is designed to become admissible to allocators that previously held only developed-market investment-grade credit, because the compliance state is a receipt-chain projection the allocator’s risk team can re-execute, a rating agency could produce the rating by running its own evaluator against the chain rather than reading an issuer’s self-report, and the tranche’s settlement runs under Op’s signed commitment protocol rather than a bare counterparty-trust assumption. The same structural move applies to other previously bespoke financing categories when their bottleneck is verification cost: infrastructure finance, consented scientific-corpus licensing, and jurisdictional-scale carbon stewardship. In each case, the candidate inflow is existing capital currently excluded by verification-cost floors.

The mechanism is structural. It does not depend on a new return premium or a promised cash flow; it depends on compressing the verification tax that currently walls investable yield off from capital that may be authorized to buy it.

18.2 Trade-volume expansion as receivables-financing unlock

For any bilateral trade corridor, the growth frontier is either demand-gated (the real-economy side cannot produce or consume more), capital-gated (the real-economy side can, but the financing cycle cannot), policy-gated, or infrastructure-gated. The corridors this paper targets, Arabian-Chinese trade, Association of Southeast Asian Nations-China trade, Belt-and-Road infrastructure-finance relationships, and Regional Comprehensive Economic Partnership inter-member flows, are candidates for capital-gated diagnosis, not assumed examples. The relevant test is whether exporters who could ship more cannot finance the working-capital gap, buyers who could order more cannot extend payment terms under a bounded-cost instrument, and institutional capital that could finance the gap is excluded by the verification-cost argument of §18.1.

The architecture’s trade-volume expansion mechanism is the one §3.7 shows concretely: wrap each receivable as an intelligent asset at origination; aggregate into pools under published methodologies; admit institutional capital through Op’s signed commitment protocol; and reduce the time and cost of verification where those are the binding financing constraints. The arithmetic of working-capital velocity is conditional: a receivable turning in two days rather than forty-five can finance twenty times as many shipments from the same working-capital base before other constraints bind. Whether the corridor’s throughput constraint shifts from financing velocity to real-economy capacity is empirical.

For the Arabian-Chinese trade corridor, the receivables-financing mechanism is a plausible near-term scale mechanism only if the corridor is capital-gated rather than demand-gated. Infrastructure finance is a medium-term complement; consented-data and scientific-exchange flows are separate long-term categories. The architecture does not generate demand, substitute for the political preconditions of bilateral trade, or override any party’s export-control or sanctions authority. It addresses the specific bottleneck on the receivables-financing mechanism where capital-gated trade growth is stalled. Where demand is the binding constraint, the receivables-financing mechanism is not the active constraint; other intelligent-asset mechanisms may still matter.

The same mechanism generalizes. The Korea-China corridor, the Japan-China corridor, the ASEAN-China set of bilateral and plurilateral flows, the inter-member flows within the Regional Comprehensive Economic Partnership, the cross-border components of Eurasian Economic Union and African Continental Free Trade Area flows, and the Belt-and-Road infrastructure-finance relationships are each candidates. The architecture provides the primitive; corridor-level economic analysis determines where it applies.

18.3 Methodology-level compounding

When a population of intelligent assets operates under a common methodology, a voluntary-carbon methodology, a programmable-claims standard, a treasury-operations framework, a trade-receivables-pool methodology, observations from every asset feed the methodology’s world model through the mechanisms specified in the compounding-intelligence companion paper. Anomaly-detection can improve as the observation base grows; precedent-retrieval can become evidence-based; rule-authoring proposals can be evaluated against the empirical distribution of admitted assets under the methodology. The feedback loop is empirically conditional: more assets can produce more observations, sharper methodologies, better-rated assets, more investable capital, and then more assets when adoption and data-quality assumptions hold. Under the proposer/admission-filter discipline of §10.4, proposal-program observations enter the world model through a sanitized channel that preserves epistemic separation while admitting their information content.

18.4 Trust at population scale

The participant-principal tree (§14) changes the cost structure of consent from many-to-many to many-to-infrastructure. Absent an infrastructure intermediary, N participants and M relying parties, licensees, downstream researchers, buyers of derived products, hold on the order of N \times M consent relationships, each renegotiated when a participant withdraws or a use changes. Under the tree, each participant consents once into the tree and each relying party relies once on the tree’s composed consent cells, on the order of N + M relationships, and a withdrawal propagates along the derivative-use graph instead of through M renegotiations. For a two-million-participant genomic consortium, for a ten-million-member platform cooperative, for a population-scale basic-income experiment, for a nation-scale electronic-identity system, the difference between N \times M and N + M can be the difference between unworkable and workable if identity, delegation, withdrawal, and dispute procedures are accepted. The mechanism is the Merkle-rooted tree plus structured-consent cells plus derivative-use-graph withdrawal propagation; the outcome is that participant consent becomes a first-class property of the asset at scales current bilateral-legal mechanisms struggle to reach.

18.5 Corridor-network equilibrium

At a mature corridor network with negotiated mutual recognition across dozens of harbor pairs, multi-harbored institutions face four separable cost surfaces: local-only operation cost, the cross-harbor meet constraint for operations touching multiple harbors, corridor friction, and non-computational switching cost. Laxity can attract local-only operations when floor constraints are weak; it cannot relax a cross-harbor operation while a stricter harbor remains in the meet. The equilibrium outcome is a continuing negotiation between jurisdictions over which corridors to form, what mutual recognition to grant, and what domains to maintain as sovereign. The architecture does not determine this negotiation; it provides the shared object the negotiation can operate on. The direction of corridor-network evolution, quality-seeking versus laxity-seeking, remains the political-economy residual of §17.

18.6 What follows without preconditions

None of §18.1-18.5 follows without the preconditions §17 names: legal recognition of attestations, a coalition of participating jurisdictions, operational evaluator deployments, bilateral corridor agreements, established methodologies, and the political will to admit the receipt chain as evidence. The architecture is the object around which a deployment can coalesce; the deployment is the political-economic act the architecture does not perform. Where the preconditions hold, the mechanisms of §18.1-18.5 operate. Where they fail, nothing happens.

19. Conclusion

An intelligent asset carries six things: its founding record, the claim program that encodes its terms, the lifecycle programs that let it observe, plan, and act, its sovereign-attested compliance state, its append-only history, and its persistent store. The compliance function composes attestations pointwise in the static direction, a meet where applicability agrees and a named-obstruction reduction where it does not, and propagates transitions on a labeled DAG in the dynamic direction. The claim program is a contract-combinator term with two added constructors, an authority gate and a typed discretion hole; its denotation under the composed verdict is what the admissible holder set, the reliance class, and the clearing price are read off, and the invariant set and amendment gate fixed at genesis bound every chain of amendments the runtime admits. The SAVM realizes the compliance-gated state-transition function; typed discretion holes with principal-carried authorization bridge machine evaluation and procedurally-structured human judgment; the supervisor’s surface installs the sovereign’s operational authority above principal delegations; the participant-principal tree scales consent to populations.

The object generalizes from financial instruments to multi-jurisdictional treasuries, physical infrastructure, consent-governed scientific corpora, and stewarded natural systems. The record shape is shared across classes; what varies, consent structure, custody graphs, settlement milestones, is carried in class-specific fields.

The paper’s claims are: provenance, not evaluator omniscience; forensic observability, not collusion prevention; legal-reference infrastructure, not legal force; a coordination object, not coalition formation; blast-radius bounds, not substantive judgment. The architecture makes compliance a first-class property of the object itself, makes cross-jurisdictional composition algebraic, and makes an object’s history cryptographically auditable. It gives first-class form to the boundary between machine computation and procedurally-structured human judgment and to the sovereign’s operational surface, and it makes many-to-infrastructure trust tractable at populations that many-to-many trust cannot reach.

The worked lifecycles of §3 are the argument for these claims. The formal apparatus of §§4-14 is the construction. The limitations of §17 are the declared perimeter.


Appendix A: Glossary

Term One-sentence meaning
Intelligent asset An object whose state carries its genesis, its sovereign-attested compliance state, its append-only history, its storage, and the programs authorized to act on it.
Genesis document (g) The immutable record of an asset’s creation, content-addressed, naming the authoring principal, the invariant set \mathcal{I} that every admitted amendment must preserve, and the amendment gate \theta_\ast under which an amendment record may be admitted at all.
Attestation portfolio (\pi) The set of currently valid sovereign attestations about an asset’s compliance state, indexed by jurisdiction and domain.
Receipt chain (\sigma) The hash-linked append-only history of everything that has been done to or by an asset.
Claim program (\Phi) The term-level encoding of the instrument’s contingent claim: when cash flows, in what amount, under what authority gates, and what happens on default, dispute, and amendment.
Lifecycle program family (\Lambda) The typed programs authorized to transition the claim’s lifecycle; includes compiled gates, Op-bytecode from Lex rules, and delegated proposal-program configurations.
Jurisdiction A sovereign authority with an evaluator function, a content-addressed lawpack, and a signing key.
Lawpack The versioned rule set a jurisdiction’s evaluator consults; content-addressed.
Compliance domain One of the fixed twenty-three canonical domains: AML, KYC, Sanctions, Tax, Securities, Corporate, Custody, DataPrivacy, Licensing, Banking, Payments, Clearing, Settlement, DigitalAssets, Employment, Immigration, Ip, ConsumerProtection, Arbitration, Trade, Insurance, AntiBribery, and Sharia.
Cell value A pair (applicability, compliance) whose applicability is Applicable/NotApplicable/Exempt and whose compliance (when Applicable) is NonCompliant/Pending/Compliant.
Compliance tensor (T_a) A function from jurisdiction-domain pairs to cell values, for a given asset and a given proposed action a, computed from those attestations in the portfolio whose scope predicate a satisfies. The standing evidence state T it is read off is a fact about the asset; T_a alone is a verdict about an action.
Propagation graph A labeled DAG recording the causal dependencies among compliance domains; a transition in one domain flags downstream domains for re-evaluation.
Corridor An asymmetric bilateral arrangement between two jurisdictions specifying what attestations carry through under mutual recognition and what requires re-evaluation.
SAVM The Smart Asset Virtual Machine; the deterministic state-transition runtime that executes bound programs under the compliance gate.
Authority gate A domain scope, an identity predicate, and a process type; it admits a transition only on a passing verdict over its scope together with a signed authorization under its process type.
Preflight / postflight The moments bracketing every execution at which the compliance gate evaluates verdicts on the proposed and effected states.
Typed discretion hole A formal object representing a point where machine computation stops and a structured human-procedural decision fills in.
Principal-carried authorization (PCAuth) A signed tuple filling a discretion hole under the required process type (single-signer, quorum-signed, deliberation-windowed, etc.).
Supervisory order A signed sovereign-authority order, senior to principal delegations, directing assets in the supervisor’s harbor.
Participant-principal tree A Merkle-rooted tree making individual participants first-class principals of a participant-governed asset.
Late-binding requirement A supervisor-injected requirement attached to one or more fixed canonical domains; adding a new top-level domain is a network schema-evolution event.
Object class A classification of intelligent assets by what they observe, which domains their actions require, how they settle, how they fail, and which programs they carry.

Appendix B: Prerequisites and Companion Reading

The paper draws on six background areas. Readers who are not specialists may consult the following orientations.

  • Lattice theory and order theory. Birkhoff, Lattice Theory; Davey and Priestley, Introduction to Lattices and Order. The compliance axis is a three-element chain; applicability is a three-element antichain; the product structure is the subject of §6.
  • Type theory and programming-language semantics. Pierce, Types and Programming Languages. Typed discretion holes, content-addressing, and the SAVM’s determinism claims all use standard PL machinery.
  • Capability security and macaroon-style delegation. The delegation model uses macaroon/biscuit-style capability chains; Birgisson et al., “Macaroons” (NDSS 2014) is the foundational paper.
  • Distributed systems asynchrony and commit protocols. Dwork, Lynch, and Stockmeyer, “Consensus in the Presence of Partial Synchrony” (JACM 1988) for the bounded-asynchrony model; Gray and Lamport, “Consensus on Transaction Commit” (TODS 2006) for the transaction-commit background against which the signed commitment protocol’s finality-certificate discipline is specified.
  • Sovereign regulatory concepts. BEPS Pillar-2 (OECD GloBE rules); Paris Agreement Article 6; FATF Recommendations; eIDAS Regulation; Regulation (EU) 2024/1689; the ICVCM Core Carbon Principles; the Nagoya Protocol; ILO Convention 169.
  • Companion papers in this programme. Programmable Institutions (Paper 0) establishes the thesis; The Multi-Harbored Institution (Paper 1) defines the institutional object; Lex (Paper 2) specifies the rule language and the typed discretion-hole calculus; Op (Paper 3) specifies the typed bytecode and the signed commitment protocol; The Sovereign Jurisdiction Network (Paper 4) specifies the decentralized-kernel construction and the cross-zone finality obligations; Compounding Intelligence (companion) specifies the world-model compounding architecture that intelligent-asset observations contribute to; Pricing the Compliance Tensor (companion) constructs the map from a composed compliance constraint surface to a price and states the mixed-axis price obligation Definition 4.8 leaves open.

References.

  1. North, D. C. (1990). Institutions, Institutional Change and Economic Performance. Cambridge University Press.
  2. Williamson, O. E. (1985). The Economic Institutions of Capitalism. Free Press.
  3. Ostrom, E. (1990). Governing the Commons: The Evolution of Institutions for Collective Action. Cambridge University Press.
  4. Hirschman, A. O. (1970). Exit, Voice, and Loyalty. Harvard University Press.
  5. Tiebout, C. M. (1956). A pure theory of local expenditures. Journal of Political Economy, 64(5):416-424.
  6. Hart, H. L. A. (1961). The Concept of Law. Oxford University Press.
  7. Dworkin, R. (1977). Taking Rights Seriously. Harvard University Press.
  8. Dworkin, R. (1986). Law’s Empire. Harvard University Press.
  9. Kelsen, H. (1967). Pure Theory of Law, 2nd ed., trans. M. Knight. University of California Press.
  10. Luhmann, N. (2004). Law as a Social System. Oxford University Press.
  11. Teubner, G. (1983). Substantive and reflexive elements in modern law. Law & Society Review, 17(2):239-285.
  12. Birkhoff, G. (1967). Lattice Theory, 3rd ed. American Mathematical Society.
  13. Davey, B. A. & Priestley, H. A. (2002). Introduction to Lattices and Order, 2nd ed. Cambridge University Press.
  14. Pierce, B. C. (2002). Types and Programming Languages. MIT Press.
  15. Necula, G. C. (1997). Proof-carrying code. POPL, pp. 106-119.
  16. Haber, S. & Stornetta, W. S. (1991). How to time-stamp a digital document. Journal of Cryptology, 3(2):99-111.
  17. Merkle, R. C. (1980). Protocols for public key cryptosystems. IEEE Symposium on Security and Privacy, pp. 122-134.
  18. Birgisson, A., Politz, J. G., Erlingsson, Ú., Taly, A., Vrable, M. & Lentczner, M. (2014). Macaroons: Cookies with contextual caveats for decentralized authorization in the cloud. NDSS.
  19. Dwork, C., Lynch, N. & Stockmeyer, L. (1988). Consensus in the presence of partial synchrony. Journal of the ACM, 35(2):288-323.
  20. Gray, J. & Lamport, L. (2006). Consensus on transaction commit. ACM Transactions on Database Systems, 31(1):133-160.
  21. Lessig, L. (1999). Code and Other Laws of Cyberspace. Basic Books.
  22. Hildenbrandt, E. et al. (2018). KEVM: A complete formal semantics of the Ethereum Virtual Machine. IEEE CSF, pp. 204-217.
  23. Bhargavan, K. et al. (2016). Formal verification of smart contracts. ACM PLAS, pp. 91-96.
  24. Sergey, I. & Hobor, A. (2017). A concurrent perspective on smart contracts. Financial Cryptography and Data Security Workshops, LNCS 10323, pp. 478-493.
  25. Peyton Jones, S., Eber, J.-M. & Seward, J. (2000). Composing contracts: an adventure in financial engineering. ICFP, pp. 280-292.
  26. Peyton Jones, S. & Eber, J.-M. (2003). How to write a financial contract. In Gibbons, J. & de Moor, O. (eds.), The Fun of Programming. Palgrave Macmillan.
  27. International Swaps and Derivatives Association (2019). ISDA Common Domain Model, version 2.0.
  28. International Swaps and Derivatives Association. FpML: Financial products Markup Language, version 5.
  29. ERC-3643 (2023). T-REX: Token for Regulated EXchanges. Ethereum Improvement Proposal.
  30. Zetzsche, D. A., Arner, D. W. & Buckley, R. P. (2020). Decentralized Finance. Journal of Financial Regulation, 6(2):172-203.
  31. Cong, L. W. & He, Z. (2019). Blockchain disruption and smart contracts. Review of Financial Studies, 32(5):1754-1797.
  32. Harvey, C. R., Ramachandran, A. & Santoro, J. (2021). DeFi and the Future of Finance. Wiley.
  33. Committee on Payments and Market Infrastructures (2016). Correspondent Banking. Bank for International Settlements.
  34. Financial Stability Board (2017). FSB Correspondent Banking Data Report.
  35. Organization for Economic Cooperation and Development (2021). Tax Challenges Arising from the Digitalisation of the Economy: Global Anti-Base Erosion Model Rules (Pillar Two).
  36. UNFCCC (2015). Paris Agreement, Article 6. United Nations Framework Convention on Climate Change.
  37. Integrity Council for the Voluntary Carbon Market (2023). Core Carbon Principles and Assessment Framework.
  38. Voluntary Carbon Markets Integrity Initiative (2023). Claims Code of Practice.
  39. International Labour Organization (1989). Convention 169: Indigenous and Tribal Peoples Convention.
  40. United Nations (2007). Declaration on the Rights of Indigenous Peoples.
  41. Secretariat of the Convention on Biological Diversity (2011). Nagoya Protocol on Access to Genetic Resources and the Fair and Equitable Sharing of Benefits Arising from their Utilization.
  42. European Parliament and Council (2024). Regulation (EU) 2024/1689.
  43. Court of Justice of the European Union (2020). Case C-311/18, Schrems II.