Abstract
Autonomous artificial intelligence systems can call tools and create external consequences, yet model-level safeguards do not by themselves establish institutional authority, evidential support, state safety or enforceable single-use execution. This paper presents the Quantum-Safe Ledger Architecture (QSLA), a non-compensatory runtime-assurance architecture that separates an agent’s proposal from permission to act.
Architectural Contribution. QSLA composes a machine-readable bounded-use contract, HALL claim-evidence classification, discrete-time stochastic safety barriers, a theta ordered-intervention mechanism, single-use capability semantics and an independent evidence path. Its defining rule is conjunctive: strength in another dimension cannot rescue a material action when authority, evidence or safety fails. The claimed novelty is this transaction-level composition and enforcement order, not invention of the underlying barrier, conformal, cryptographic or distributed-systems primitives.
Implementation Contribution. The research prototype defines six JSON Schema artefacts and implements admission predicates, HALL classification, treasury barriers, ordered intervention, reservation, idempotent commit, fencing identifiers and a hash-linked event chain. Version 2.1 adds a prospective independent-deployment protocol, authentic-corpus data dictionary, blinded HALL review instrument, Stochastic Control Barrier Function (SCBF) calibration plan, comparator matrix, adversarial test suite, statistical analysis plan, independence attestation and archival manifest.
Evaluation Contribution.
Ten automated tests passed. In 50,000 fixed-seed synthetic treasury cases, full QSLA semantics produced zero disagreements with the declared conjunctive oracle by construction. The compensatory aggregate baseline admitted 24,640 oracle-unsafe cases; policy-only admitted 23,164; removing HALL admitted 21,617; and removing the barrier admitted 1,250. A 5,000-case in-process benchmark measured median decision latency of 42.383 microseconds, p95 of 65.121 microseconds and p99 of 141.315 microseconds in the declared environment. These are internal conformance and local-overhead results. No authentic deployment, human-review agreement result, independently calibrated SCBF result or unaffiliated replication is claimed in this edition.