Spherity AI Safety Series — Paper 1 of 3
Resource Bounded Program Equilibria under Cryptographic Commitments and Revocable Authority
AI Safety: Safeguarding Multi-Agent Interactions through Deterministic State Controllers
Browse this paper
In brief
What does this research establish?
The paper defines a finite resource-bounded program game and a protected deterministic controller that separates incentives from current authority, evidence and external effects. Under explicit assumptions, it gives an exact unilateral-deviation criterion and verifies that epoch, version, action, delegation, replay and aggregate-budget guards are jointly necessary for the modeled execution path.
Key takeaways
- A strategically stable agent program still needs an external protected controller because equilibrium does not establish current authority or safe effects.
- Reservations must count against aggregate budgets before effects commit; per-action checks alone allow parallel overspend.
- Authority epochs, controller versions, logical operation identifiers and exact payload binding prevent stale approval, replay and action substitution.
- The evaluation covers specified finite games and mediated digital effects, not general alignment or physical-world safety.
Download Paper 1
Download the full paperThe formal model, exact deviation criterion, deterministic controller, exhaustive test space and omission counterexamples.
Start with the executive brief
Download the executive briefRead the leadership case and how all three technical papers form one AI Safety control chain.
Abstract
This paper studies finite resource-bounded program games mediated by a protected deterministic execution controller. It separates four questions that are often conflated: whether a program has an incentive to deviate, whether its authority is current, whether its evidence is acceptable, and whether a proposed external effect remains within shared resource limits. The paper derives an exact unilateral-deviation criterion that includes implementation costs and revocation, then verifies controller properties for current authority, aggregate budget, exact action, delegation scope and replay resistance.
Keywords: resource-bounded program equilibrium; protected execution; deterministic controller; AI agents; shared budgets; revocable authority; exact-action binding
Core result: incentives and execution are different safety claims
Program equilibrium asks whether an agent benefits by switching to another available program under the modeled payoffs and costs. Protected execution asks whether a particular external effect is currently authorized, evidenced and affordable. A safe architecture must answer both questions independently.
The paper’s exact criterion makes implementation cost and revocation visible in the deviation calculation. That improves analytical clarity, but it remains conditional on the specified finite game and available deviations. The controller then provides a separate stateful boundary that agents cannot bypass.
Protected execution architecture
The agent proposes an action. A narrow policy kernel and optional proof mechanism produce evidence for that exact proposal. A protected verifier/controller checks authority, delegation scope, version, operation identity and aggregate resources before reservation and commit. The covered resource executes only the committed payload and returns an outcome record.
This separation makes the trust boundary explicit. A persuasive agent message, a valid signature or a successful proof is not itself permission to create an external effect. Permission exists only when the protected state transition accepts the exact action under the current state.
Use case: two organizations jointly book constrained compute
Consider two engineering organizations whose agents jointly reserve a limited compute pool. Each request may be individually below a threshold while simultaneous requests exceed the shared budget. The controller therefore reserves capacity before commit and counts pending reservations against the same aggregate limit. If a request fails, is canceled or its authority changes, the state machine governs release rather than trusting the requesting agent to clean up.
The same pattern applies to test facilities, shared procurement limits, emissions budgets, API quotas and other resources where cross-company concurrency can create an aggregate violation.
Five controller guards and why each matters
The evaluated controller uses five independent protections:
- Aggregate reservation counts committed and pending use before admitting another action.
- Current authority epoch invalidates approvals from an earlier mandate state.
- Controller version prevents evidence created for an obsolete policy or implementation from being replayed.
- Unused logical operation ID makes retries idempotent and blocks duplicate effects.
- Exact payload binding prevents a proof or approval for one action from authorizing a substituted action.
The paper removes each control in turn and gives a concrete counterexample. This is important engineering evidence: it shows not only that the full design passes its modeled invariants, but also why a superficially simpler design fails.
Evaluation evidence and limits
The analysis checks 38,880 parameter combinations. Controller abstractions contain 1,427 and 1,819 reachable states in the reported configurations, and five omission variants yield explicit violations. These results support the stated finite model and controller logic.
They do not establish general AI alignment, policy correctness, physical safety, robustness to every implementation defect or safe behavior outside the controller’s mediated effects. Deployment requires independent implementation review, adversarial testing, operational monitoring and careful definition of which resources truly have no bypass.
Selected references
- Halpern and Pass, Algorithmic Rationality: Game Theory with Costly Computation.
- NIST, Zero Trust Architecture, SP 800-207.
- W3C, Verifiable Credentials Data Model v2.0.
How to cite Paper 1
Stöcker, Carsten (2026). Resource Bounded Program Equilibria under Cryptographic Commitments and Revocable Authority: AI Safety—Safeguarding Multi-Agent Interactions through Deterministic State Controllers. Spherity GmbH. https://spherity.github.io/spherity-research/resource-bounded-program-equilibria-ai-safety.html. Licensed CC BY 4.0.
This research page and the linked Paper 1 PDF is licensed by its named author under the Creative Commons Attribution 4.0 International License (CC BY 4.0). Reuse must credit every named author, link to this canonical version and the license, and indicate whether changes were made.
How to cite this work
Dr. Carsten Stöcker (2026-09-28). “Resource Bounded Program Equilibria under Cryptographic Commitments and Revocable Authority: AI Safety: Safeguarding Multi-Agent Interactions through Deterministic State Controllers.” Spherity GmbH. https://spherity.github.io/spherity-research/resource-bounded-program-equilibria-ai-safety.html. Licensed CC BY 4.0.
Direct answers
Questions this research answers
What is a resource-bounded program equilibrium?
It is a modeled interaction in which programs choose actions under explicit computational and implementation costs, and no participant benefits from an allowed unilateral program deviation under the stated game, commitment and authority assumptions.
Why is a protected controller needed if the programs are in equilibrium?
Equilibrium describes incentives inside the specified game; it does not prove that authority is current, evidence is valid, aggregate resources remain available or the executed payload matches the approved action. The protected controller enforces those external conditions.
Which guards are essential in the shared-resource example?
The model requires aggregate reservation, current authority epoch, controller version, unused logical operation identifier and exact action-payload checks. Omission testing produces a specific violation when each guard is removed.