The Physical Limits of Finite Observation
Establishes that every finite observer operates under unavoidable physical, statistical, and logical bounds. Those limits force an error budget, a visible competence boundary, and abstention beyond it.
Horos Engineering is a UK deep-tech organization. We build a deterministic observer — a system that reads a process's true state from the signals it already produces, advises before failure, and refuses to advise when it can't measure.
Most monitoring tells you a part failed. Ours reads the precursor — from signals the system already gives off — and acts on it through a deterministic decision rule: the same reading always yields the same verdict, including a hard abstain when it can't measure.
It catches the precursor others miss, tells a real reading from a corrupted or spoofed one, and flags when it cannot measure rather than guessing. Detection is statistical; the verdict on it is deterministic — computed from the underlying invariant by a fixed rule, its energy scale self-normalised from the signal's own baseline rather than hand-tuned per deployment, so it holds where soft rules drift. It is built to slot into the instruments and systems already in place, rather than replace them.
Our lead vertical: a fail-closed estimator that catches the precursor of systematic drift in cryogenic quantum control — demonstrated in simulation and against IBM's public hardware-calibration telemetry (read-only).
One governed detector, tested two ways — a controlled adversary in simulation, and a real drift event caught in IBM's own public calibration record, pointable enough that their engineers can re-pull and check it.
96.7% of drift-collapse scenarios caught before the actuator saturates, at a 12 s median lead, with 0% false positives across 210 healthy runs — over 7 sensor-environment conditions including 1/f noise.
Two read-only tests on 156 real IBM qubits. Spatial — one calibration snapshot: the detector flagged the 2 genuinely degraded qubits, and no others. Temporal — 43 daily snapshots: the drift test fired on exactly one qubit, q126 (T1 88.0 → 19.1 µs, −78%), staying silent on the other 155, including one that is chronically poor but stable. Firing on change, not on badness, is the hard part.
The full technical brief walks the method end-to-end — the simulation sweep, then a read-only check against IBM’s published calibration history, down to a single qubit (q126 on ibm_fez), reproducible from public data.
TRL-4 · advisory detection layer, not a deployed controller. Preprints (not peer-reviewed), CC-BY 4.0 — kernel: DOI · PDF ↗ · architecture: DOI · PDF ↗
Underneath the domains there is a single machine: a governed resolver with memory. It reads a system’s true state, weighs each action against a competence boundary — abstaining rather than guessing — and remembers, provenance-checked, across runs.
What changes between builds is only what it is wired to, and whether we own it. Own the inference source — a measurement system, or a model on our own hardware — and it runs closed: one sovereign machine that observes itself and acts. Run it on a model we don’t own and it runs open: a governance-and-memory layer over a foreign engine, with a human in the observing seat. Same resolver, different source — one architecture, several builds.
Before we built anything, we derived why a correct finite observer must declare its limits and refuse to act past them — building on established bounds in information theory, thermodynamics, and quantum estimation. A constraint, not a design preference. Everything we build instantiates that result. Open-access preprints (not peer-reviewed), CC-BY 4.0, openly available for inspection.
Establishes that every finite observer operates under unavoidable physical, statistical, and logical bounds. Those limits force an error budget, a visible competence boundary, and abstention beyond it.
Turns the finite-observation limit into a diagnostic instrument. Deviation between matched artefacts localises where an uncaptured or varying interaction must be investigated.
Carries the result into system design: committing execution and wide-field vigilance must be separated, then re-coupled so execution cannot finalise what vigilance has not verified.
Horos GCA — a Governed Cognitive Architecture: a fail-closed governance and adaptive memory layer that sits on a trained language model, not a wrapper on one.
It governs the model against a competence boundary — abstaining instead of hallucinating, refusing a manipulated instruction by construction — and it remembers, carrying provenance-checked memory across sessions so each run stands on the last. The governance is computed, not tuned; the adaptation is fail-closed too.
Reads the architecture's live state from within and reports it without disturbing it — a non-perturbative observer that holds to zero writes.
Weighs every action against its competence boundary — allow, abstain, or refuse — and fails closed. It advises; it does not certify.
Carries provenance-checked memory across sessions so each run builds on the last — and refuses the paths it has already seen fail.
The three don't sit side by side — they close a loop: the observer feeds the governor; the governor decides against its bounds, governs the model beneath, and draws on a memory it also governs. The boundary it enforces is the one its own memory is held to — one horos, closing on itself.
A TRL-4 prototype — internal, not yet released. The mechanism is designed to be open to inspection — a prompt changes a model's distribution; this changes its computation: the manipulated text is never an argument to the decision function, so an injected instruction has nothing to act on. The grounding it answers from is real and deliberately narrow: asked past its edge, it abstains rather than guess.
mechanism · GitHub on release
The same governed resolver, wired to different inference sources. Quantum and structural are the closed measurement build — the machine calculates from measurement and watches itself; autonomous is the open governance build — governing a model we don’t own, with a human in the loop. The quantum build is furthest along.
Detects the precursor of systematic drift in cryogenic quantum control from the signal's dynamics — before the actuator saturates — and fails closed when it cannot measure.
Reads the failure precursor in a structure's dynamics before threshold alarms trip, and tells a failing structure from a failing sensor.
Reads the true state of an input, tells a genuine instruction from a manipulated one, acts deterministically — and flags when it cannot decide.
Demonstrated in computational simulation across the three domains — in quantum, also validated against real hardware-calibration data (read-only) — with a working harness in the autonomous case.
Validation in a relevant environment. In quantum this is defined: a bounded advisory experiment on a live or authorised feed — success criteria fixed before the run, fail-closed on insufficient evidence.
Proven in live, high-consequence operation as the fail-closed measurement-and-control layer — advisory throughout: the operator keeps the plant at every rung.