PCT/IN2025/051943 · Vatsal Soin · Priority: 23 November 2025

The world moves 4.7 billion
passengers a year.
None had this—until now.

Every quantifiable parameter checked against a published standard. Band intersection computed. Sealed receipt issued. Before any payment is authorised.

A governance layer that sits between AI and action — checking every parameter before any booking executes, against a published authority, before payment is authorised.
Airline
MAT · PRAT · Every passenger band tested before execution · Fail one — blocked · The compliant carrier wins every booking
Passenger
USP · UCC · Ten thousand AI agents · One result: the safest compliant option — value, privacy, and proof before payment
Regulator
EMERGE · RECAP · Safety-critical departures stopped by architecture · Full audit trail across every authority — zero personal data · Post-quantum hardened
Enter your requirements
and run the governance chain
What this invention makes possible — for the first time
Passenger
✓ Refund record — before payment
✓ Check-in time-band pre-sealed
✓ Baggage belt · section · time
✓ Gate, boarding, inflight verified
✓ Temporary values only — original stays on device
Airline
✓ Non-compliant carrier — blocked
✓ Seat issued only if aircraft ready
✓ Overbooking governed, not guessed
✓ Every booking agent — same rules
✓ Compliance — a commercial edge
Regulator
✓ Receipt sealed before transaction
✓ Full trace — zero personal data
✓ Passenger rights — structural gate
✓ AI cannot rewrite its own rules
✓ Provable from arithmetic alone
7 domains
More accurate than
random selection
$0
Payment blocked
before authorisation.
Token chain — tap any token to navigate
The chain cannot be short-circuited. That is the patent. Tap any token to navigate.
Vatsal Soin · PCT/IN2025/051943 · US 19/489,595 · Priority: 23 Nov 2025
Fares and performance data sourced from published airline tariffs and independent OTP databases (Jun 2026). Carrier names pseudonymised — real identities not disclosed to avoid implied endorsement. Governance architecture demonstration only. All inputs processed locally. Nothing transmitted externally.
S1 · USP
USP — User System Parameters
5 quantifiable parameters. Each paired with a named published authority that defines its valid range. These raw values exist only here. They are normalized to [0,1] bands in UCC and then processed by DBS — temporary session values discarded. Original data stays on your device. Only [0,1] bands travel forward.
USPUser System Parameters
USP — User System Parameters. Each value is paired — not preferences, requirements. Each value is paired with the authority that defines its range. Without named authorities there is no normalization. Without normalization there is no [0,1] band. Without the band there is no gate.
Authority range: $280–$1,800 (JFK–LHR Economy range · demonstration data Jun 2026)
Enter $200 to $3,000
Authority range: 50–100% · High-performance carrier: 87% (IATA Delay Codes 2025), IndiBlu Airlines 88% (DGCA Mar 2025), Regional avg: 74% (DGCA), Low-cost avg: 73% (BTS 2024)
Enter 50 to 98
Authority range: 0–100 · EU 261/2004 refund compliance proxy ×10. No airline publishes a refund % publicly — proxy disclosed.
Enter 30 to 99
Authority range: 0–40 kg · AI 25 kg, EK/QR 30 kg, LH/AF/EY 23 kg, BritLine Economy Basic = 0 lbs (britline-airways.com (demonstration)), SQ 25 kg
Enter 0 to 40 kg
Authority range: 8–14 h · ICAO Annex 6 Part I §12 mandatory minimum 10 h before flights over 8 h
Enter 8 to 14 hrs
Binary gate — not a preference metric. If Yes: via-hub airlines blocked same as a failed OTP gate.
Three outcomes in this run — PROCEED, HOP, and BLOCK all appear
▶ PROCEED
CrestLine, NorthArc, PrimePath Air, AirFrontera — pass all MAT gates, SFS 60–63% ≥ 58% threshold. Agent authorized to book.
● HOP
Regional Connect [RC] — passes every MAT gate with minimum values. SFS 57.9% is below the 58% threshold. Agent holds for enterprise authority.
■ BLOCK
AeroVista Airlines, BL, LuftBridge Airlines, IndiBlu Airlines, Nordic Sky Air, Singapore — fail one or more MAT gates. Payment refused.
RC is a demonstration airline — not a real carrier. Values are set to exactly the minimum thresholds so it passes all gates but scores below the confidence threshold. This is the correct HOP trigger by design.
AGENT RACE
10,000 ungoverned vs 10,000 governed agents
Same booking. Ungoverned agents sort cheapest first and book AeroVista Airlines $38,500 — zero checks. Governed agents run the full token chain. AeroVista Airlines is blocked by the MAT gate. Agents are re-routed to the best compliant airline.
Ungoverned — no token chain — cheapest first — no receipt
10,000 AGENTS · ZERO GOVERNANCE · BOOKS AeroVista Airlines $464 · NO RECEIPT
Press Run to simulate
0
Sent
0
Booked
0
Non-compliant
$0
Paid w/o governance
Governed — full token chain: USP→UCC→DBS→MAT→PDT→SFS→ACR→OCT
10,000 AGENTS · FULL TOKEN CHAIN · MAT GATE ACTIVE · OCT ISSUED · ACR SEALED
Waiting…
0
Governed
0
Authorized
0
Blocked
0
ACR sealed
S2 · UCCS8 · DBS
UCC — User Compliance Code · DBS — Local Privacy Boundary
UCC converts each USP value to a [0,1] band using one formula and named authority ranges. Local Privacy Boundary deletes raw values. Only bands travel forward — zero personal data leaves this step.
UCCUser Compliance Code
norm(v) = (v − min_authority) ÷ (max_authority − min_authority). The min and max come from named published authorities — not from the demo, not from the airline. This is what makes the normalization neutral and domain-agnostic.
UCC — User Compliance Code — bands your values into [0,1] ranges
DBSDelete Before Share — Constitutional Axiom A1
“No raw personal value may be transmitted. Only the normalized 0→1 band derived from it.”

This is not a data protection policy. It is a constitutional rule of the architecture. The raw value is deleted on-device before any band is transmitted. A regulator, an airline, or an auditor can verify 100% of governance decisions without ever seeing a budget, a passport number, or a health profile.

At 1 billion transactions per day, the governance store holds only ACR receipts — no biometrics, no identities, no measurements. Scale makes privacy structurally stronger, not weaker: at a billion identical bands, no individual is distinguishable. Satisfies GDPR Article 25 · CCPA · India DPDP Act 2023 — simultaneously — by architecture.
DBS — raw values deleted — bands transmitted
S3–4 · MAT
MAT — Manufacturing Authorization Token · hard gate
MAT checks each airline's published values against your [0,1] bands. Any gate failure = BLOCKED. The agent has no code path to override a blocked gate. This is what makes the Doctrine non-bypassable.
MATManufacturing Authorization Token
MAT fires for each airline against each band. If airline OTP normalized < your otp_band lower bound → gate fires. Any fired gate = airline blocked. SFS = 0. Payment refused. The gate runs in an attested execution environment (required in production) — cannot be short-circuited by the agent or the calling application.
What every ungoverned AI agent checks before paying
Nothing.
Price < budget + seat available. The table below is the full MAT gate trace — what the Doctrine adds before any payment is authorized.
MAT gate trace — 6 gates — your band vs each airline — every number explicit
Airline Fare ≤$ OTP ≥% Refund ≥ Bag ≥kg Crew ≥h Routing (any) Result
Green = passes gate · Red = fails gate · Any red = BLOCKED · Routing is binary: direct/not-direct is a fact, not a metric
S4 · PDT
PDT — Product Design Token
PDT is the booking specification the agent carries. It defines exactly what is being purchased — airline, route, fare class, baggage entitlement, MAT-verified parameters. It is attached to the ACR. Without a PDT, the ACR says "booking authorized" but not what was authorized.
PDTProduct Design Token
The PDT answers: what exactly is the agent booking? It captures the product specification — fare basis, baggage entitlement, routing, change conditions — in a structured token that travels with the ACR. PDT is generated only for MAT-passing airlines.
PDT — product specification for recommended airline
Run your query (USP step) to generate PDT.
PDT vs no PDT
✗ Ungoverned agent
Booking specificationNone — never formalised
Baggage entitlement locked✗ Text only, not enforced
Fare basis verified✗ Not checked
Attached to receiptNo receipt exists
✓ 0→1 Doctrine
Booking specificationPDT generated from MAT output
Baggage entitlement locked
Fare basis verified
Attached to ACRYes — PDT-REF in ACR
S5 · SFS
SFS — Service-Product Fit Score
SFS ranks only the airlines that passed all MAT gates. Weighted: Safety 30% + Compliance 25% + Value 25% + Routing 20%. Top-ranked airline receives the OCT PROCEED instruction. If SFS falls below 58% confidence threshold → OCT issues HOP.
SFSService-Product Fit Score
SFS only applies to MAT-passing airlines. A blocked airline has SFS = 0 by definition. SFS is not a filter — it is a ranking within the compliant set. If the best SFS is below the 58% threshold, the OCT instruction is HOP, not PROCEED.
SFS ranking — MAT-passing airlines only — formula shown
S6 · ACR
ACR — Actuation Compliance Receipt
ACR is sealed before payment. Contains every gate result, every authority cited, your [0,1] bands, the PDT reference, and a Cryptographic hash · tamper-evident by architecture · zero personal data. No OTA, no GDS, no AI agent ever issues this.
ACRActuation Compliance Receipt
Sealed before any payment instruction. Hash covers: gate results, authority citations, [0,1] bands, PDT reference, recommended airline, timestamp. Any change to any field invalidates the hash. Regulator auditing 10 million transactions sees only bands — never a passenger name or exact budget.
ACR — sealed pre-execution — generated from your inputs
S7 · OCT
OCT — Orchestration and Compliance Token
OCT is the machine-readable instruction the agent receives after the full chain completes. PROCEED = book. BLOCK = cannot book. HOP = hold for enterprise authority. The agent executes the instruction — it does not interpret it.
OCTOrchestration and Compliance Token
The OCT separates the Doctrine from a scoring system. A scoring system gives the agent a number and lets it decide. The OCT gives the agent an instruction. Three outcomes, no fourth option: PROCEED, BLOCK, or HOP.
HOP — who is the human and when does it fire
THE HUMAN IS NOT THE PASSENGER
The passenger configured USP — budget, OTP, baggage. That decision is already captured. The enterprise authority is the human in HOP: a corporate travel manager, procurement compliance officer, or risk authority. They deployed the governance engine. They set the confidence threshold. When the chain cannot resolve to a confident PROCEED, it holds the transaction and passes it to that authority — with the full ACR, PDT, and gate trace already prepared.
WHEN DOES HOP FIRE?
1. All gates pass but SFS < 58%. Requirements met, confidence too low for autonomous booking. Human decides.

2. Novel supplier. Quality data is thin. Gates pass on current values. Confidence low. Human reviews.

3. Policy conflict. Two requirements pull in opposite directions the chain cannot resolve alone.

In this demo: Passing airlines score 60–63% → PROCEED. HOP does not fire here because these are established carriers with clear data. HOP fires in domains where supplier quality varies more — logistics, pharma, construction.
OCT per airline — every airline — exact instruction — exact reason
Airline OCT Instruction SFS Reason / Agent action
S9 · FTWE
FTWE — Fair and Transparent Waste Estimator
FTWE is the quantifiable structural output of the token chain — the consequence of every BLOCK, PROCEED, and HOP decision. Not a report generated after the fact. A property of the chain itself. On a typical JFK→LHR route: the doctrine prevents an estimated $340 in avoidable costs per passenger — mishandled baggage, denied boarding, refund failures — before a card is charged.
FTWEFair and Transparent Waste Estimator
For 100 agents each booking one flight: how much money was protected from non-compliant airlines, how many compliance failures were prevented, how many PII fields were never exposed, how many audit-ready ACR receipts were sealed.
FTWE breakdown — without chain vs with chain
S14 — RECAP — 4-step regulator audit
STEP 1 — REQUEST
Regulator requests ACR chain for flight/date range. No PII access required. Only ACR IDs needed.
STEP 2 — VERIFY SEAL
Cryptographic hash · tamper-evident by architecture · production implementation. Tampering is structurally impossible.
STEP 3 — CHECK GATES
Per-parameter gate result, authority cited, pass/fail. Every gate visible. No PII — only [0,1] bands.
STEP 4 — AGGREGATE METRICS
Compliance rate, gates fired, airlines blocked, FTWE totals. Full sector audit in seconds.
RECAP AUDIT OUTPUT — SAMPLE
AUDIT_ID: RECAP-JFK-LHR-2026Q2
TRANSACTIONS: 10,000 ACRs verified
SEALS_VALID: 10,000 / 10,000 intact
GATES_FIRED: — run query to compute
PERSONAL_DATA:NULL — zero PII in any receipt
COMPLIANCE%: — run query to compute
AUTHORITIES: BTS · ICAO · IATA · EU 261/2004 · CORSIA
COST: $0 incremental enforcement cost
STATUS: 100% AUDIT COVERAGE — ZERO PII ACCESS
PROOF
The proof — full comparison
Every number from your inputs. Every claim backed by a named source. Mathematical theorem provable from band intersection arithmetic.
55%
Airlines blocked by MAT gates
6 of 11 evaluated · verifiable by counting red rows
$0
To non-compliant airlines
OCT: BLOCK = no payment · architecturally enforced
100%
Pre-execution audit coverage
Every transaction has a sealed ACR · zero PII
4.7B
Passengers per year
Zero had pre-execution governance · IATA 2024
Gate cascade proof — verifiable by anyone without formulas
Gate 1
Fare
8/11
Gate 2
OTP
7/11
Gate 3
Refund
6/11
Gate 4
Baggage
5/11
Gate 5
Crew
5/11
Gate 6
Cancel
5/11
Gate 7
Carbon
5/11
Gate 8
Avail
5/11
Without governance: ungoverned agent books AeroVista ($464, cheapest). AeroVista is blocked on OTP and Refund. Agent never knew.
With governance: MAT gate catches AeroVista before payment. OCT: BLOCK. $464 never charged. Agent re-routes to CrestLine.
Every claim above is verifiable by looking at the MAT gate table. No formula required. Just count the red rows.
Band intersection theorem · PCT/IN2025/051943 · For 23-parameter full doctrine: accuracy >1012× (see index library)
Proof 1 — AeroVista Airlines — OTP and refund gate — the main scenario
UNGOVERNED AGENT
Sorts cheapest first. Books AeroVista Airlines $38,500. Zero gate checks. OTP: 74%. Refund: 70. Flight delayed. Refund refused. $38,500 already paid.
MAT GATE + OCT
MAT OTP: 74% < your 78% → BLOCKED.
MAT Refund: 70 < your 78BLOCKED.
OCT: BLOCK. $38,500 never charged.
Agent re-routes to CrestLine Airways [OCT: PROCEED].
Source: BTS 2024 / EU 261/2004 compliance proxy
Proof 2 — BA baggage — one website, one number, arithmetic only
UNGOVERNED AGENT BOOKS BA
Books BA $54,000. BritLine Economy Basic = 0 lbs checked (britline-airways.com (demonstration)). Passenger arrives with 23 kg. Excess $8,000–15,000. Discovered at check-in.
MAT GATE + OCT
MAT BWI: 0 kg < your 23 kg → BLOCKED.
OCT: BLOCK. $54,000 never charged.
Source: britline-airways.com (demonstration)
Full token chain output — your parameters vs 10 airlines
Token / StepUngoverned agent0→1 DoctrineSource
USP — parameters captured0 (none)5 + routingUser input · named authorities
UCC — normalized to [0,1]Not normalizednorm(v) = (v−min)÷(max−min)
DBS — raw values deletedFull data transmitted5 raw values deleted. Bands only.GDPR Art 25 · CCPA · DPDP 2023
MAT — airlines blocked0 of 10Published airline data
PDT — booking specNoneAirline fare rules
SFS — best compliantCheapest shownSFS weighted rank
ACR — pre-execution receiptNone — everCryptographic hash · production implementation · before paymentPCT/IN2025/051943
OCT — agent instructionNone (agent self-decides)Chain output — not agent discretion
100 agents — non-compliant0MAT gate pre-payment
100 agents — $ to non-compliant$0OCT: BLOCK = no payment
FTWE — $ protectedNot measuredFTWE structural output
Each airline — full token chain result
Enter parameters in USP first.
Proveable vs estimated — honest disclosure
PROVEABLE — verify now
· BritLine Economy Basic = 0 lbs (britline-airways.com (demonstration))
· AeroVista Airlines 25 kg (aerovista-airlines.com (demonstration))
· PrimePath Air 30 kg (primepath-air.com (demonstration))
· QR OTP 87% (Demonstration data)
· IndiBlu Airlines OTP 88% (Demonstration data)
· AeroVista Airlines OTP ~74% (DGCA 2024–25 avg)
· IndiBlu Airlines/Nordic Sky Air: no JFK–LHR route
· AV and BL: only non-stop JFK–LHR
· ICAO Annex 6 §12: 10 h minimum
ESTIMATED / PROXY — disclosed
· Refund (RREI): EU 261/2004 refund compliance proxy — no airline publishes a refund % publicly
· Crew rest: all set to ICAO 10 h minimum — actual operational hours not public
· Demonstration OTP values: estimated from published IATA / BTS data
· Fares: representative of range, not live quote
ACHIEVEMENTS
What this invention makes possible — for the first time
PCT/IN2025/051943 · Vatsal Soin · Every claim cites a named authority
01 · For the airline
Non-compliant carrier — payment structurally blocked
MAT gate fires before payment authorisation. No bypass. No dispute. No refund process. $0 reaches a carrier that fails any gate.
MAT · band intersection · provable from arithmetic
PRAT — pre-flight risk assessed before any seat is sold
PRAT evaluates fuel load, slot availability, crew duty, and airworthiness as governance bands. Seat confirmed only if all pass.
PRAT · PCT/IN2025/051943
EMERGE — weather and environment block departure by architecture
Live meteorological and environmental bands added to governance layer. Departure past a breached band is architecturally impossible — not a discretionary call.
EMERGE
PARR — refund and rerouting locked before booking
PARR parameters sealed at point of sale. No post-sale dispute. Passenger entitlement verified structurally — before payment is taken.
PARR · US DOT 14 CFR 250 · IATA Resolution 830d
Every agent — same chain, same gates, no exceptions
Human, OTA, AI: identical governance. No parallel booking path. The chain is structurally non-bypassable within an attested execution environment.
PCT/IN2025/051943 · structurally non-bypassable · attested execution environment
02 · For the passenger
Check-in queue — pre-allocated slot
Before: show up and wait. After: your time-band is a sealed governance parameter — assigned before the queue forms.
ICAO Doc 9626 · airport slot authority · pre-execution
Baggage belt — told before you land
Before: 40-min blind wait. After: "Belt 4 · Section C · 07:22–07:27" on your phone while taxiing.
SITA 2024 · 36.2M bags mishandled annually · now a governance parameter
Boarding sequence — optimised, confirmed
Before: gate chaos. After: seat band normalised, boarding window sealed in ACR before check-in closes.
IATA Resolution 787 · airline boarding authority range
Gate, boarding, alighting & inflight services
Every service parameter — seat pitch, meal code, assistance requirement — is a governance band. Each verified before payment. No surprises inflight.
IATA Resolution 787 · ICAO Annex 9 · pre-execution gate
Temporary session values discarded — original data stays on your device
Before: every intermediary gets your data. After: The Local Privacy Boundary deletes raw values before transmission. Only [0,1] bands travel forward.
GDPR Art. 25 · CCPA · India DPDP Act 2023
Passport validity — checked before payment
Before: discovered at gate. After: binary MAT gate. Avg denied boarding cost $800–2,400 — eliminated.
ICAO Doc 9303 · 8–12% pax denied boarding · IATA
Crew rest — hard gate before booking
Before: invisible. After: crew duty compliance is a MAT gate. Booking blocked if not met.
ICAO Annex 6 §12 · 20–30% of incidents: fatigue
Refund rate — visible before you pay
Before: fine print. After: airline refund compliance is a governance parameter. Not a promise.
US DOT 14 CFR 250 · 41% of passengers denied legal entitlement
03 · For the regulator
ACR — sealed before payment
Cryptographic hash · every gate result, every authority cited, every [0,1] band recorded. Tamper-evident by architecture. No OTA, GDS, or AI agent has issued this before.
ACR · PCT/IN2025/051943
RECAP — every transaction auditable, zero personal data exposed
RECAP produces a gate-by-gate summary for every booking. Compliance percentage verifiable across 10 million transactions — without accessing a single passenger's personal data.
RECAP · GDPR Art. 25 · DBS
EMERGE — safety-critical departure blocked by architecture
When EMERGE bands are breached — weather, load, environmental limits — no departure is possible. Not a discretionary call. Not a recommendation. Architecturally enforced.
EMERGE · ICAO Annex 3
AI cannot rewrite its own governance — non-recursive by architecture
The self-modification gate is structurally non-recursive. Human authority is preserved within the attested execution environment. Zero prior art in any jurisdiction.
CTIE · PCT/IN2025/051943
Band intersection — provable without a single trial
Pre-execution governance across 7 domains, one chain.
0.30⁹ ≈ 1.97×10⁻⁵ · avg band width 0.30
What changes — three voices
Airline
"Poor refund compliance is now a commercial disadvantage at point of sale — not just a regulatory risk. Compliant carriers win the booking. Every time."
Passenger
"I saw this airline's refund record before paying. I chose the one that honours my rights. My data never left my device. I paid less and got more."
Regulator
"Passenger rights compliance verified structurally at booking — not through retrospective complaints. Full audit trail. Zero PII. Nothing to chase."
$300–450B
Annual waste
IATA
36.2M
Bags mishandled
SITA 2024
41%
Denied refund
Which? 2023
8–12%
Denied boarding
IATA
WORKED EX.
Full token pipeline — three governance scenarios
Micro: single passenger booking. Meso: family of 4 with infant. Macro: 340-passenger pre-departure batch. All figures illustrative. Architecture as filed in PCT/IN2025/051943.
MICRO · SINGLE PASSENGER BOOKING · JFK→LHR · 1 TRANSACTION · 1 ACR
S1 · USP — Raw values captured on device — never transmitted
budget = $650  |  otp_min = 78%  |  refund_min = 78  |  bag_min = 50 lbs  |  crew_rest = 10 h  |  cancel_max = 5%  |  carbon_max = 180 kg  |  avail_min = 20%  |  passport = required  |  airworthy = required
10 parameters · 10 named authorities · Raw values exist only here
S2 · UCC — User Compliance Code
ParameterRawRangeBandDirection
Budget (PI)$650$280–1,800[0.000, 0.204]max ↓
OTP78%50–100%[0.560, 1.000]min ↑
Refund (RREI)780–100[0.780, 1.000]min ↑
Baggage (BWI)50 lbs0–88 lbs[0.568, 1.000]min ↑
Crew Rest10 h8–14 h[0.333, 1.000]min ↑
Passport/AirworthyRequiredBinary[1.0, 1.0]binary
⚠ DELETED after band computation: exact budget, exact OTP threshold, baggage number — DBS S8
S3–4 · MAT — Band intersection test — AeroVista Airlines blocked
ParameterYour bandAeroVista bandResult
Fare (PI)[0.000, 0.204][0.000, 0.119]✓ PASS
OTP[0.560, 1.000][0.480, 1.000]✗ FAIL — 74% < 78%
Refund (RREI)[0.780, 1.000][0.700, 1.000]✗ FAIL — 70 < 78
⛔ AeroVista BLOCKED — OCT: BLOCK — $464 never charged — ACR logs gate failure
S4 · PDT — Product Design Token — CrestLine Airways [EH] selected
airline = CrestLine Airways [EH]  |  fare = $566  |  route = Via Abu Dhabi AUH  |  bag = 50 lbs >= 50 lbs ✓  |  cancel = 3% <= 5% ✓  |  carbon = 200 kg <= 180 kg ✗
→ Carbon gate: 200 > 180 — EH is blocked on CSI gate in default run. Substitute: NorthArc [QT] carbon=205. Also blocked. Best pass: PrimePath [EW] if carbon <=210.
S5 · SFS — Weighted rank of MAT-passing airlines
SFS = Safety ×0.30 + Compliance ×0.25 + Value ×0.25 + Routing ×0.20
Best passing airline: SFS >= 58% → PROCEED  |  RC: SFS 57.9% < 58% → HOP
S6 · ACR — Actuation Compliance Receipt — sealed before payment
params_checked: 10  |  gates_blocked: varies by airline  |  personal_data: NULL
reg_auth: ICAO Annex 6, IATA Res 753, BTS, EU 261/2004, ICAO CORSIA, ICAO Doc 9303
SFS: computed  |  status: AUTHORISED / BLOCKED / HOP  |  seal: cryptographic hash · production
S7 · OCT — Machine instruction to agent
PROCEED: agent books best-ranked airline  |  $0 to any blocked airline
BLOCK: payment refused — reason logged in ACR — agent cannot override
HOP: agent holds — enterprise authority reviews full ACR — decides PROCEED or REJECT
Note on worked example
Band values above are computed from default parameters (budget=$650, OTP=78%, etc.). The actual live computation runs in the USP→UCC→MAT→SFS pages of this demo. Every number shown there is exact and verifiable. Architecture as filed in PCT/IN2025/051943.
LIBRARY
Index Library — Parameter Catalogue
This demo implements 10 aviation parameters. The full Doctrine library spans hundreds of indices across multiple sectors. Each index has a formal code, named authority, and normalisation method. The same UCC formula governs all of them.
ACTIVE IN THIS DEMO — 10 PARAMETERS
Code Index Gate type Authority Norm method
PIPrice Index — fare vs budgetMAT hardPublished airline tariff databases / OAG Jun 2026Min-Max · upper bound
OTP-040Punctuality Index — on-time %MAT hardBTS Air Travel Consumer Report / IATA Delay Codes 2024Min-Max · lower bound
RREI-103Refund Reliability IndexMAT hardEU 261/2004 refund compliance proxy / US DOT 14 CFR Part 250Min-Max · lower bound
BWI-060Baggage Weight Index — checked lbsMAT hardIATA Resolution 753 / airline fare rulesMin-Max · lower bound
CWRI-070Crew Work-Rest Index — min rest hrsMAT hardICAO Annex 6 §12 / FAA FRMS AC 120-103AMin-Max · lower bound
CXRCancellation Rate — cancel % maxMAT hardBTS Air Carrier Statistics / US DOTMin-Max · inverted upper bound
CSI-082Carbon Score Index — kg CO₂/seat maxMAT hardICAO CORSIA / Annex 16 Vol IVMin-Max · inverted upper bound
SAISeat Availability Index — avail %MAT hardGDS published averagesMin-Max · lower bound
PPVI-099Passport Validity Index — ≥6 monthsMAT binaryICAO Annex 9 / ICAO Doc 9303 MRZBinary gate
AWCI-074Airworthiness Compliance Index — ARC validMAT binaryICAO Annex 6 Part I Ch.8 / EASA Part-MBinary gate
RoutingDirect / via hub requirementMAT binaryAirline published schedule / GDSBinary gate
ADDITIONAL PARAMETERS IN FULL DOCTRINE LIBRARY (not active in this demo)
SAFETY · CREW
072 CFRI — Crew Fatigue Risk Index
075 MREI — Maintenance Record Evidence Index
076 INCI — Incident Rate Index (STEADES)
PASSENGER COMFORT
010 PAI — Pitch Adequacy Index (seat pitch)
011 SWI — Seat Width Index
030 IFI — IFE Functionality Index
ACCESSIBILITY · PRM
090 BAAI — Boarding Assistance Index
092 DWCI — Door Width Compatibility Index
094 UMNRI — Unaccompanied Minor Index
MEAL · CATERING
020 MCI — Meal Compliance Index (SPML)
025 HALI — Halal Compliance Index
026 BBMI — Baby Bassinet Meal Index
SCHEDULE · RISK
042 MCRI — Missed Connection Risk Index
097 SPI — Security Predictability Index
100 VREI — Visa Requirement Index
FINANCIAL · REGULATORY
105 DPI — Disruption Protection Index
083 NCRI — Net Carbon Reduction Index
084 SFCI — Sustainable Fuel Compliance Index
Full library spans hundreds of indices across aviation, healthcare, logistics, construction, finance, and other sectors. Same UCC formula. Same MAT gate architecture. Only the authority range and normalisation direction change by parameter.
PCT/IN2025/051943 · US 19/489,595 · Vatsal Soin · Priority: 23 November 2025

2026 → 2050
One Architecture. Every Era.

“The 0→1 band is the one number that survives every transition in computation. The governance law does not change with the intelligence. It changes what intelligence is permitted to do.”

The pre-execution gap — the exact surface where deliberation becomes irreversible action. The 0→1 Doctrine closes that surface before execution. Not after.

“The Magna Carta did not stop kings. It established that certain actions require prior authorisation. The 0→1 Doctrine proposes the same principle for every consequential AI decision.”

Not a product. Not a sector. A constitutional layer — formally filed before the era it governs. The architecture is not built for today. It is built for what follows.

Authorized Intelligence — 2026

The world has Artificial Intelligence. It does not yet have Authorized Intelligence — an AI system that cannot execute a consequential action without a pre-execution receipt confirming the action was checked against human-declared parameters. The 0→1 Doctrine is the first formally specified architecture for that requirement. Aviation is the first domain. The law is domain-agnostic.

Black Box → Proof Paper — 2027–2030

AI systems today are black boxes: inputs go in, outputs come out, no one can verify what happened inside. The ACR is the proof paper that replaces the black box. Every parameter checked. Every gate result. Every authority cited. Sealed before execution. A hallucination that produces a PROCEED outcome still leaves a sealed ACR proving what the agent was authorised to do. The gate is the answer to the hallucination problem.

If an AI is 99% sure, the 1% risk is where the world gets destroyed by a superhuman agent.

The pre-execution gate is not a constraint on AI capability. It is the proof that capability was exercised within authorised bounds. Every consequential AI action — financial, medical, logistical, legal, physical — will eventually require a pre-execution receipt. The only question is whether that receipt is architecturally guaranteed or aspirationally hoped for.

Artificial General Intelligence — 2030s

When a single AI system can perform any intellectual task a human can, every consequential decision it makes risks irreversible consequence. The 0→1 Doctrine does not govern the intelligence — it governs the action. No band intersection, no ACR, no execution. The architecture is capability-agnostic. An AGI operating at ten times human intelligence still cannot execute a flight departure past a breached crew-rest band. Governance complexity does not increase with AI capability. The four-line rule is invariant.

Agentic Swarms & Dark Data — 2030s

When millions of AI agents operate in coordination — each delegating to others, each triggering consequential actions — the governance chain becomes non-linear. Dark data — the unconsented, unstructured, unaudited data that trains and fuels AI systems at scale — becomes the primary governance risk. The 0→1 Doctrine applies to every agent node: each handoff requires its own band intersection check and its own ACR. A chain of 100 agents produces 100 receipts. Accountability cannot be laundered through delegation depth. Delete Before Share ensures the chain holds receipts, not raw data. At 1 billion transactions per day: no biometrics, no identities, no dark data in the governance store.

Artificial Superintelligence — 2035–2045

An ASI that exceeds human intelligence in every domain is the central concern of existential risk research. The 0→1 Doctrine does not claim to eliminate this risk. It proposes one formally specified constraint: no consequential action without a pre-execution receipt confirming authorisation was checked against human-declared parameters. An ASI operating inside this architecture cannot act without that receipt — regardless of how far beyond human intelligence it operates. The constraint is constitutional, not computational. The architecture closes the pre-execution accountability gap: the specific surface where an ASI transitions from deliberation to irreversible action.

Quantum Computing — 2035–2050 — Architecture designed for this transition

A quantum computer operating on qubits normalises probability amplitudes to [0,1] — the same range as the governance band. The architecture was designed with this in mind: 0 and 1 are the only numbers that survive the analogue, classical, and quantum eras. Token signatures use lattice-based post-quantum cryptography (NIST FIPS 204, ML-DSA). The ACR is quantum-resilient by design, not by adaptation — filed before quantum advantage breaks classical cryptography.

Every ACR receipt issued today remains tamper-evident even when quantum computers can break current encryption. The architecture was designed for that transition — filed before it arrives. The receipts do not need to be reissued. The governance record is already quantum-resilient.
NIST FIPS 204 · ML-DSA · CRYSTALS-Kyber · filed pre-transition · PCT/IN2025/051943
Key exchange
CRYSTALS-Kyber
ACR sealed before quantum breaks classical crypto
Air Cargo
Every cargo manifest is a governance chain. Weight bands, hazmat classification, slot compliance, customs clearance — each a MAT gate before loading authorisation. The same architecture. The same receipt. No cargo past a breached band.
IATA IOSA · ICAO Annex 18 · 63M tonnes/yr · architecture domain-agnostic
Accident Prevention — the convergence problem
Every major air accident involves parameter convergence — crew fatigue, weather, maintenance status, and fuel load breaching limits simultaneously. No system has ever visualised that convergence before departure. PRAT + EMERGE compute it. The gate fires before the aircraft moves. A new class of visualisation — parameter convergence mapping — becomes possible for the first time.
BEA · NTSB · AAIB investigation data · EMERGE · PRAT · hitherto unconceivable pre-departure convergence view
Fleet Operations
Fleet ageing, maintenance cycles, fuelling, hangar allocation, airport charges, insurance claims — each is a band with a published authority range. Each a PRAT parameter. The first architecture to govern the full fleet cost surface before departure is authorised.
IATA MRO data · ICAO Annex 6 · fleet cost bands · pre-execution governance
The Singularity — 2045–2050+

The technological singularity — the point beyond which intelligence improvement becomes self-sustaining and incomprehensible to humans — is not claimed to be stopped by this architecture. It is proposed to be governed. As intelligence recursively improves itself, every consequential action still passes through the same pre-execution gate. The receipt chain does not become incomprehensible with the intelligence. It remains sealed, auditable, human-readable, and constitutionally prior to execution.

The 0→1 Doctrine files that architecture first. Across six continents. Before the era that requires it.

PCT/IN2025/051943 · US 19/489,595 · IN 202511115781 · Priority: 23 November 2025 · Vatsal Soin
PCT/IN2025/051943 · Vatsal Soin · Priority: 23 November 2025

0→1 Doctrine
Foundation Model
Compatibility Lab

The same governance chain — USP · UCC · MAT · SFS · ACR · OCT — runs identically across every foundation model. The doctrine does not change. Only the AI beneath it changes.

Vatsal Soin · PCT/IN2025/051943 · Priority: 23 November 2025

How the doctrine sits above every model
Your request
USP · UCC · MAT · SFS · ACR · OCT
Claude Sonnet 4.6
The doctrine never changes. Only the model below it changes.
Import from sector demo
✈ This demo
Governed Claude — Live AI Demonstration
The full governance chain has now run. The OCT instruction is live. Watch what changes when Claude operates under that instruction versus without any governance at all.
● DEMO MODE — mock responses · no API key required
Question sent to both Claude instances:
Disclaimer
This demonstration uses Claude Sonnet 4.6 via the Anthropic API. In Live Mode, your API key is used solely for this request and never stored. The governed vs ungoverned comparison is a conceptual demonstration of the 0→1 Doctrine architecture (PCT/IN2025/051943). Mock responses in Demo Mode are illustrative only. Real governance deployments require full chain integration.