A Formal Analysis of AI Safety Enforcement
Nearly every AI safety mechanism deployed today is an advisory constraint: a rule the system is instructed to follow, enforced by components that are separable from the computational substrate that produces decisions. Safety training, content filters, guardrails, and runtime monitors all share this property. Because the enforcement mechanism can be removed while the system keeps operating, the safety it provides is conditional on nobody removing it.
Structural constraints are different. In a structurally constrained system, reasoning that omits or fails a required constraint evaluation is computationally undefined rather than prohibited. The system does not produce a non-compliant output; it produces no output at all. This paper introduces the formal distinction between the two constraint classes and proves what each can and cannot guarantee.
The Separability Test
The paper's central diagnostic is a single operational question: can the enforcement mechanism be removed, disabled, or bypassed while the system continues to produce outputs? If yes, the constraint is advisory, whatever its marketing says. If removing the mechanism breaks the system entirely, the constraint is structural. The test applies to any AI decision system, including systems described as aligned, guardrailed, or safe by design.
What the Paper Proves
The paper is equally precise about limits: structural constraints guarantee enforcement of whatever is specified, but not that the specification is correct or complete. The specification problem remains open under both approaches.
Regulatory Implications
The paper analyzes three frameworks governing AI in high-consequence domains: Article 12 of the EU AI Act, the U.S. Department of Defense AI Ethical Principles, and the interagency SR 26-2 model risk management guidance. Each framework's requirements implicitly assume enforcement properties such as trustworthy logging or reliable constraint evaluation. The analysis identifies where those assumptions hold, where they fail under advisory enforcement, and why structural enforcement strengthens the evidentiary basis for compliance. Where supervisory guidance defers to an institution's own risk practices, as SR 26-2 does for generative and agentic AI, whether a constraint is architecturally bypassable determines what those practices are capable of assuring.
From Theory to Platform
This paper is the second installment of the research program that began with Processual Memory Architecture [link to /processual-memory-arch]. It formalizes and generalizes PMA's Proposition 6.1, proving the enforcement properties independently of any particular architecture. The formal framework, including the definitions, theorems, and the separability test, is published for open use; implementations are the subject of pending patent applications.
Luminareware's Liora ARIA™ platform is the engineering realization of structural constraint enforcement: an operational decision assurance system in which required constraint evaluations are part of the computational substrate itself, not policies layered beside it.
Diacont, W. D. (2026). Structural vs. Advisory Safety Constraints in AI Decision Systems: A Formal Analysis.
Available on: Zenodo
DOI: 10.5281/zenodo.21613380
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.