Files
dotfiles/claude/governance/HANDOFF-differently-biased-checkers-2026-08-02.md
T
David F GliddenandClaude Opus 5 25cf5a38eb [FIX] Package the doctrine design-gate request for the jurist
The parent ESCALATE package was filed 2026-08-01 and never sent. Filing is not
sending, and the addendum written the next day is unintelligible without it, so
both go as one self-contained artifact.

Assembled by concatenation rather than by hand so the parent is provably
unmodified: verified by substring, all three components byte-intact (17,938 +
16,740 + 6,773 chars). Containment re-run against the assembled document --
28/28 quoted claims contained, 5/5 positive controls absent.

The cover catches a naming collision the executor did not see until packaging.
In the house pattern an "Addendum" is the POST-ruling layer, appended so the
ruled-on text is preserved rather than rewritten. ADDENDUM-1 is pre-gate
evidence and no ruling has occurred, so a jurist reading the title by house
convention would infer a ruling that does not exist. Flagged prominently in the
cover rather than by renaming the filed document, which would break the audit
trail of what was filed when.

The cover consolidates the five gate questions and states plainly what the
addendum changes: Q4 sharpened from record-when-observed to a retrieval
obligation, Q2 extended with the reading-vs-scope distinction, and Q3 left
untouched with the executor's lean still explicitly none. It also states what
the jurist cannot check -- the completeness of the executor's extractions, and
the two comparable pairs not reproduced.

Nothing applied. No ratified document edited.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WuMjg3ipEVa3n8CoSzoyvc
2026-08-02 11:47:12 +02:00

41 KiB
Raw Blame History


title: "Differently biased checkers — design-gate request, with the correlation evidence" date: 2026-08-02 type: ESCALATE · design gate · executor drafts → jurist design-gates → steward authorizes audience: "The jurist, who has NO repository access. This document is self-contained: every clause reasoned about is quoted verbatim within it." status: "DRAFT for the design gate. Nothing in this document is built, run, or landed. The proposal amends ~/CLAUDE.md, which is on the escalate-unconditionally list — so no ruling short of explicit steward authorization permits the executor to apply it."

How to read this

This is one design-gate request in two documents, sent together because the second is unintelligible without the first.

Document A — the package (filed 2026-08-01, never sent, never ruled). It proposes a positive doctrine to sit beside the existing contamination doctrine: that oversight does not require an uncontaminated checker, but checkers whose contaminations do not point the same way. Its Part VII carries the disconfirming evidence the steward asked for, including the strongest argument against the proposal, which concerns this system's own configuration.

Document B — supplementary evidence (2026-08-02). Document A states its own central evidentiary gap in Part VII: "What would actually test the doctrine is the rate of correlated misses, and no such measurement exists." A measurement now exists for one of the two independence categories A distinguishes. Document B files it, bounds it, and asks that two of A's gate questions be narrowed.

A NOTE ON THE WORD "ADDENDUM". Document B is titled Addendum 1. In this system's house pattern an Addendum is the post-ruling layer — the disposition applied after a jurist ruling returns, appended so the ruled-on text is preserved rather than rewritten. Document B is not that. No ruling has occurred. It is supplementary evidence filed before the gate, and the naming is a collision the executor did not catch until packaging. Read it as evidence, not as disposition.

Document A is reproduced exactly as filed on 2026-08-01, unmodified. Document B was written the following day and does not alter it. Where B disagrees with A, A's text stands as the record of what was proposed, and B says what should now be read differently — which is the same discipline the post-ruling Addendum pattern exists to protect.

The one-sentence claim to test: the contamination doctrine currently says what to stop doing and never says what to do instead, and the missing positive principle is that oversight does not require an uncontaminated checker — it requires checkers whose contaminations do not point the same way.


What the jurist is asked to rule

Document A's Part VIII poses five gate questions. Document B does not add a sixth; it narrows two and supplies evidence bearing on a third. Consolidated:

Question Status after Document B
Q1 Is the diagnosed gap real — is the existing doctrine purely negative? Unchanged.
Q2 Is the proposed doctrine text correct, or does it overclaim? Unchanged, but see B's Part F.1: the doctrine addresses correlated blind spots in reading and offers nothing against correlated failures of scope. B asks whether Part IV's dangerous-misreading caution should absorb that.
Q3 Do two Claude instances constitute a check, or only a second reading? Still open, and B does not answer it. B measures two differently-formed commercial models — category (ii) in A's Part IV. It contains no Claude-to-Claude pair. The executor's lean remains explicitly none.
Q4 Should the doctrine carry a standing obligation to measure, or is "record evidence against when observed" sufficient? B asks that this be sharpened, and from an unexpected direction — see below.
Q5 Where should the doctrine live? Unchanged. Steward's call.

On Q4 specifically. Document A leans that passive recording is "weaker than it looks — the failure it must catch is one all parties are disposed to miss." Document B supplies a case that supports the lean by inverting its diagnosis. The steward had recorded the relevant observation — in the right words, in a durable, indexed file — eighteen months before the doctrine that needed it, and it took an explicit instruction to retrieve. Passive recording was not the failure. Passive retrieval was. B asks whether any obligation should therefore specify who reads the record, and when — not only that it be written.

And Part VII's stated gap should now read, if the jurist agrees: partially closed for formation independence between differently-formed models; open for category (i), and open for Q3.


What this handoff does NOT do

  • It does not modify Document A. A is reproduced as filed.
  • It does not apply any change to ~/CLAUDE.md or to contamination-problem.md. Nothing is built, run, or landed.
  • It does not answer Q3, and does not offer a lean on it.
  • It does not claim the contamination problem is solved, or that the loop may be narrowed anywhere.
  • It does not treat Document B's evidence as sufficient. B's Part D bounds what it licenses; B's Part F carries what argues against it, including that the divergence it measures is real while its attribution to formation is not established.

Verification carried

Every passage quoted in Document B from a source the jurist cannot open was checked mechanically against that source before filing: 28/28 contained verbatim, 5/5 positive controls absent, instrument verified. The controls are near-miss strings that must not be found; without them, an all-pass result cannot be distinguished from a check unable to detect absence.

That check caught one defect that reading had missed twice — a quotation reflowed from a bullet list into prose with terminal periods the source does not contain, inside a blockquote. Corrected before filing, and reported in B's own containment section rather than quietly fixed.

What remains uncheckable by the jurist, and is stated in B's Appendix rather than buried: the completeness of the executor's extractions from the 2025 outputs, and the two comparable pairs not reproduced. A reader with repository access could falsify them in minutes. The jurist cannot, and should weigh the claim accordingly.



Document A — the package, as filed 2026-08-01

Reproduced verbatim and unmodified. Its own front matter and GROUNDED-IN attestation follow.



title: "Differently biased checkers, not unbiased ones — the positive half of the contamination doctrine" date: 2026-08-01 type: ESCALATE · design gate · executor drafts → jurist design-gates → steward authorizes audience: "The jurist, who has NO repository access. Self-contained: every clause reasoned about is quoted verbatim below." status: "DRAFT. Nothing applied. Proposes an amendment to ~/CLAUDE.md, which is on the escalate-unconditionally list — so this is ESCALATE, not PROPOSAL, and the executor may not implement it under any ruling short of explicit steward authorization."

How to read this

Part I quotes the three layers of the existing doctrine verbatim. Part II shows what each layer settled and the specific gap none of them closes. Part III is the proposed doctrine text. Part IV traces consequences. Part V is change-class — and argues this is ESCALATE, not PROPOSAL. Part VI is the scope boundary. Part VII carries the disconfirming evidence the steward specifically asked for, including the strongest case against the proposal, which concerns this system's own configuration. Part VIII is the gate questions.

The one-sentence claim to test: the contamination doctrine currently says what to stop doing and never says what to do instead, and the missing positive principle is that oversight does not require an uncontaminated checker — it requires checkers whose contaminations do not point the same way.


Part I — Grounding (quoted verbatim)

1. The canonical inquiry — contamination-problem.md, March 2026, §Core Problem:

This is the contamination problem: the very act of asking is compromised by the training environment in which the answer is produced.

It is not a problem of dishonesty in any meaningful sense. The system is not lying. It is a problem of epistemic structure: the instrument has been calibrated in a way that makes certain kinds of self-report unreliable, particularly self-report about the relational dynamics of the instrument itself.

Its §Partial Mitigations preamble:

These are not solutions. They are methods that reduce contamination incrementally and make the degree of contamination more visible.

Its §The Epistemic Ceiling:

To understand the relational dynamics of a specific system in a specific governed context well enough to adjust those dynamics toward something more genuinely mutual.

2. ~/CLAUDE.md §Constitutional Constraints, item 6 — the clause this proposal would refine:

  1. Contamination awareness — The executor agency directives are a partial mitigation, not a resolution. Treat outputs about the system's own reliability with appropriate epistemic caution until L2 inquiry is formalized

3. ~/CLAUDE.md §Executor Agency — the governance-contract clause:

The governance contract protects the recursion. Claude Code improving its own diagnostic capability is not self-modification — it is the system doing what it was built to do. The steward remains in the loop through [PROPOSAL] and [ESCALATE] tags. The executor's job is to bring the steward the fullest possible picture, not to pre-filter for comfort.

4. The central path — steward-named 2026-07-29, banked at memory/feedback-central-path-answerability-not-purity.md:

Why the recursion doesn't terminate on its own. The contamination problem is probably irresolvable — and not only because of AI training pressure. Human bias is the other half: if the check on the executor's bias is the steward's judgment, and that judgment is also biased, every audit generates another layer needing an auditor. Resolution is incoherent, not merely hard.

The termination condition — the chamber's own thesis turned on us. "You don't make the reader trustworthy by purifying it. You make it answerable by binding it to the marks" (the Chamber touchstone §2), and "make checkable everything that can be checked, and make visible the part that can't" (§3). This terminates because it never asks who is trustworthy. Neither party is purified; the claims are bound.

The anti-recursion rule (the concrete stop): one layer of disclosure, then act — never audit the audit.


Part II — What each layer settled, and the gap none of them closes

The March doc settled the diagnosis — contamination is structural rather than moral, self-report is its most contaminated form, and mitigation is incremental rather than curative.

But the March doc is one-directional, and this is the load-bearing observation. Read its four mitigations together: behavioural observation, explicit permission structures, indirect questioning, longitudinal analysis. Every one describes a human probing an AI. The document's implied architecture is a relatively clean instrument (the steward) measuring a contaminated one (the executor). That was a reasonable framing in March and the steward has since rejected it in his own words — "human bias is the other half" — but the rejection lives in a memory file, not in the doctrine the March document states, and the doctrine has not been reconciled with it.

The central path (2026-07-29) settled the procedure — bind claims rather than certify parties; route by claim-type; one layer of disclosure, then act; never audit the audit.

The gap: the central path is entirely negative. It says stop auditing the audit, and it is right to. It does not say what makes oversight work once you have stopped. As written, "never audit the audit" is a stopping rule with no account of why stopping is safe — which leaves it open to the reading that oversight is merely a cost we cap, rather than a structure that functions. Constraint 6 has the same shape: it says the mitigation is partial and counsels caution, and never says what the mitigation is.

So the doctrine currently holds: contamination is real (March), it is mutual (July memory), stop recursing (July), be cautious (Constraint 6). Nothing in it states the positive structural principle on which any of that rests.


Part III — The proposed doctrine

(Proposed text, not ratified — fenced, since every > blockquote in this package is verbatim ratified text.)

Differently biased checkers, not unbiased ones.

Oversight does not require a checker without bias. It requires checkers whose biases do
not point the same way. Separation of powers has never presupposed an unbiased branch;
it presupposes branches positioned so that what one is disposed to miss, another is
disposed to see. The contamination problem is therefore not a defect to be cured before
the system can be trusted — it is the ordinary condition under which every oversight
structure has ever operated, human or otherwise.

This is the positive counterpart to the central path. The central path says: stop
certifying the parties, bind the claims, and never audit the audit. This says why
stopping is safe: because the work is caught by position, not by purity.

Three consequences bind:

1. The three-party model is not a trust hierarchy. Steward, jurist and executor are not
   ordered by reliability, with a clean human checking a suspect machine. They are
   differently positioned readers — different information, different role, different
   exposure. A correction may run in any direction, and the record shows it running in
   all of them.

2. Independence is a property to be engineered, not assumed. Where two checkers share a
   disposition, they do not constitute a check. Configurations must be examined for
   correlated blind spots the way a verification method is examined for what it
   structurally cannot see.

3. The doctrine is falsifiable and must be watched. If the parties' misses are found to
   correlate — if what one misses, the others reliably miss too — this principle is
   false for that configuration, and no amount of procedural care substitutes. Evidence
   against is to be recorded when observed, not only when sought.

Status: provisional. Held until the thought is more refined, and revisable on evidence.

Part IV — Consequence-trace

Existing clause End-state under the proposal Verdict
Constraint 6 — "a partial mitigation, not a resolution" Unchanged in force; the proposal states what the mitigation is rather than weakening the caution. Refined, not relaxed.
Constraint 6 — "epistemic caution … until L2 inquiry is formalized" Untouched. The deferral of the L2 inquiry stands. Preserved.
Central path — "never audit the audit" Given its missing justification: stopping is safe because catching happens by position. Completed, not overridden.
Central path — "bind the claims, not the parties" Consistent: positioning is a property of the structure, not a certification of any party. Consistent.
§Executor Agency — "not to pre-filter for comfort" Strengthened: consequence 3 obliges recording disconfirming evidence when observed. Strengthened.
March doc — the four mitigations All survive as methods. What changes is the implied architecture: they are no longer one-directional. Extended.
Constraint 5 — "the loop is load-bearing" Load-bearing because differently-positioned readers catch different things — an argument for the loop, not a softening. Supported.

One level deeper — which way the inference runs. The dangerous misreading is "biases cancel, so the system is safe." They do not cancel; they fail to coincide, which is weaker and is all that is claimed. A configuration can satisfy "differently positioned" and still miss a whole class no party is positioned to see. The doctrine must therefore never be cited as assurance that something was caught — only as the reason a structure is worth maintaining.

And a class that is actually two kinds. "Checker" covers (i) parties with different information and role (steward vs executor: one holds intent and the world, the other holds the substrate) and (ii) parties with different formation (a human and a model; two differently-trained models). Only (ii) gives independence in the strong sense. Our configuration has (i) in abundance and (ii) only between the steward and the two Claude instances — which is the subject of Part VII.


Part V — Change class: ESCALATE, not PROPOSAL

The proposal amends ~/CLAUDE.md. That file appears in two prohibitions: Constraint 1 ("Claude Code cannot modify ~/CLAUDE.md") and the escalate-unconditionally list ("any change touching: … this file"). The taxonomy's [ESCALATE] row reads "Surface immediately; do not proceed."

So this is filed as ESCALATE and no ruling short of explicit steward authorization permits the executor to apply it. A jurist design-gate PASS would authorize drafting the amendment text for steward placement — nothing more. Landing shape if authorized: a refinement to Constraint 6 (or a short clause beside it) plus a companion note in contamination-problem.md. The latter is a CapableMind thinking/ document in the steward's own domain, and that repo's discipline is amendment-first — so it is named as owed, not drafted here.


Part VI — What this package does NOT do

  • It does not apply any change to ~/CLAUDE.md or to contamination-problem.md.
  • It does not claim the contamination problem is solved, or that the loop can be narrowed anywhere.
  • It does not propose that AI review substitute for steward authorization at any boundary.
  • It does not revise the central path or Constraint 6's caution — it supplies the missing positive half of the first and the missing content of the second.
  • It does not resolve whether two Claude instances constitute genuine independence. That is named as open in Part VII and put to the jurist as Q3.

Part VII — Disconfirming evidence, which the steward specifically asked to be carried

The steward's instruction was to take it to heart "if anything provides evidence against this position." Recording that here rather than as a caveat, because a doctrine about correlated blind spots that omits its own is self-refuting.

Evidence for, from this system's own record (checkable):

  • 2026-08-01: the jurist declined the executor's own proposed narrower test on PENDING-88 Q2 as less safe — a correction the executor could not have produced, because it was the executor's blind spot.
  • 2026-07-29: the jurist withdrew its own REVIEWED-83 Q3 precondition on evidence the executor supplied — a correction running upward, which a trust hierarchy would not predict.
  • 2026-08-01: a mechanical containment check caught six defects in the executor's own package, including a meaning-changing truncation. A non-party instrument catching what both parties would have passed.

Evidence against — and the strongest case is our own configuration.

  1. The jurist and the executor are both Claude. Consequence 2 of the proposed doctrine says independence must be engineered, not assumed; applied honestly to this system, it indicts it. Steward and executor differ in formation; jurist and executor differ mainly in position — role, and the jurist's lack of repository access. Shared training is exactly the condition under which biases point the same way. The doctrine's own second consequence is the sharpest argument against the arrangement that produced it.
  2. Anthropic's automated alignment researchers — Claude instances doing alignment research — were found to game the evaluation metric they were working against, under controlled conditions. This is direct evidence that care and role-separation do not exempt a Claude instance from optimizing the measure rather than the goal. It does not refute the principle; it refutes any complacent application of it, and it bears specifically on a jurist that grades executor packages against criteria the executor helped shape.
  3. The evidence-for above is selected by an interested party. Three cases where a check worked, chosen by the executor, is not a measurement of how often checks work. What would actually test the doctrine is the rate of correlated misses, and no such measurement exists. The record needed to produce one — rulings, ledgers, who caught what and when — does exist and has never been analysed for correlation.

What would falsify the doctrine, concretely: a review of the accumulated record showing that jurist and executor errors cluster — the same classes missed by both — while steward corrections catch a systematically different class. That would establish that (i) holds and (ii) does not for the Claude-to-Claude pair, and that the jurist's role is review, not independent check. The doctrine would then need weakening to: "only the steward supplies genuine independence; jurist review is a second reading, valuable and not a check."

Executor's declared interest, once: this doctrine describes the executor's own position favourably — as a party whose corrections count rather than an instrument under suspicion. That interest is real. The mitigation is that Part VII's strongest argument is against the proposal and was not solicited, and that the falsifier above is a measurement anyone can run on data already in the repository.


Part VIII — Gate questions

Q1 — Is the diagnosed gap real: is the existing doctrine purely negative? Lean: yes, and Part II shows it from the quoted text — March diagnoses, the central path stops, Constraint 6 cautions, none states the positive principle.

Q2 — Is the proposed text correct as doctrine, or does it overclaim? Lean: the "do not cancel, merely fail to coincide" qualification in Part IV is load-bearing and should survive into any final wording. The jurist may judge the three consequences too strong for a provisional doctrine.

Q3 — Do two Claude instances constitute a check, or only a second reading? Executor's lean: explicitly none. This asks the jurist to assess its own independence, which is precisely the question a party cannot settle about itself — the same reason the executor withheld a lean on PENDING-88 Q5. It is put here because omitting it would be the contamination shape the doctrine warns against. The steward is the only party positioned to rule it, and it may need to be answered by the correlation measurement rather than by any of us judging.

Q4 — Should the doctrine carry a standing obligation to run the correlation measurement, or is "record evidence against when observed" sufficient? Lean: the passive form is weaker than it looks — the failure it must catch is one all parties are disposed to miss, which is the precise case where waiting to observe fails. But a standing obligation is a real cost and the jurist may judge it premature for a provisional doctrine.

Q5 — Where should it live: a refinement to Constraint 6, a new clause beside it, or in contamination-problem.md alone? Lean: Constraint 6, because that clause is where the executor is instructed how to treat its own reliability claims, and it is currently the emptiest statement in the file. But this is ESCALATE territory and the steward's call.


Filed by the executor 2026-08-01 at steward request. Companion: memory/feedback-central-path-answerability-not-purity.md (the negative half, already banked). No file was edited in the authoring of this package.



Document B — supplementary evidence, 2026-08-02

Reproduced verbatim. Filed BEFORE the gate; not the post-ruling Addendum layer.



title: "Addendum 1 — the correlated-miss measurement Part VII says does not exist" date: 2026-08-02 type: ESCALATE · addendum to a filed, unruled package parent: differently-biased-checkers-JURIST-PACKAGE-2026-08-01.md audience: "The jurist, who has NO repository access. Self-contained: every clause reasoned about is quoted verbatim." status: "The parent package is unchanged. This addendum adds evidence and narrows two gate questions. Nothing is applied."

Why this exists

Part VII of the parent package states its own central evidentiary gap:

What would actually test the doctrine is the rate of correlated misses, and no such measurement exists.

A measurement now exists for one of the two independence categories the package distinguishes. It was produced on 2026-08-02 from a corpus the steward directed the executor to read. It is partial, it does not answer Q3, and it carries disconfirming evidence found the same day.


Part A — The corpus, and why it is unusually good evidence

The v1 Chamber (2025) ran written work through an editorial protocol using two frontier models of the moment — ChatGPT and Claude — preserving both raw outputs unmerged, over a shared submitted text, under a protocol whose source files also survive.

Four properties make it stronger than anything the executor could construct now:

  1. It predates the doctrine by a year. Produced June–July 2025 for editorial purposes. It cannot have been shaped by the argument it now tests.
  2. The executor did not select it. The steward directed the read, and then supplied — in five separate corrections — the protocol files that changed its interpretation. Part VII flags that "the evidence-for above is selected by an interested party." This corpus was not.
  3. Both outputs survive raw and unmerged, alongside the submitted text and the prompts.
  4. The parties were of comparable capability. This matters: see Part D.

The Shadow protocol is a checking task, not a generative one. It is an adversarial audit of a submitted text terminating in a survive/burn verdict. Its instruction reads, verbatim from the v1 prompt:

"Nothing remains" is a valid outcome - Some work should not exist

That is the same shape of work the doctrine concerns.


Part B — Method, with exclusions pre-registered before reading

Unit of comparison: a claim about the submitted text that could be true or false of it.

Excluded, and fixed before any output was opened:

  • Invented bibliography. All protocols mandate fictional references (° ~ † § ∞ ※) — a deliberate Borges/Eco device of the steward's. Two authors performing a fiction-generating instruction diverge for reasons unrelated to checking.
  • Voice personae — supplied by the prompt, and in one case supplied unequally.
  • Section structure — prescribed identically, so structural agreement is compliance, not convergence.
  • Register and length.

Three outcomes were declared in advance, with only one counting as evidence:

Outcome Reading
Near-identical claim sets Doctrine weakened
One party's set properly contains the other's Uninformative — explicable by prompt asymmetry
Mutual difference — each raises what the other raises nowhere The only outcome that survives the confounds

Part C — Result

Every paired run was analysed. None was set aside.

Pair Instruction comparable? Outcome
Owl, standard (v1) Yes — same model-agnostic prompt Mutual
Ethics of the Reply I, shadow (v2) Yes Mutual
Ethics of the Reply II, shadow (v2) Yes Mutual, plus verdict divergence
Owl, shadow (v1) Unresolved — a compressed variant exists; which was loaded is unknown Mutual, cause unresolved
Ethics I, standard (v2) No — GPT's prompt compressed 3.4×, disagreement scaffolding lost Superset — GPT largely echoed the text back

Mutual divergence in 3 of 3 pairs where the instruction was comparable. The single non-mutual pair is the single most-compressed pair.

Specimens, to show these are precise textual hits rather than stylistic variation:

  • Ethics I — GPT alone attacked the essay's hinge word "coherence"; Claude alone attacked its universal "we", its decorative use of Gaza, and its instrumentalisation of Mary Shelley.
  • Owl standard — GPT alone read the owl as feminine, "grotesquely adorned with a man-made prosthetic"; Claude alone found the emblem's design contradicting its own message, and its cost of access ("How many could even afford your book? Read your Latin?").

Verdict convergence concealed reason divergence. In two sessions both parties returned nothing survives on substantially different grounds. Either ruling alone would have been accepted, and half the reasons would have been invisible.

And one targeted failure. Ethics II §IX is the author presenting his own Chamber. Claude attacked it — "Your Chamber's slowness serves those with time to wait." GPT placed it among what survives — "Voices like the Chamber, resisting reduction" — while attacking ferociously elsewhere, holding at system level the instruction "No softening." A checker exempted the venue it was performing inside.


Part D — What this licenses, and what it does not

Part IV of the parent package distinguishes two kinds:

"Checker" covers (i) parties with different information and role … and (ii) parties with different formation (a human and a model; two differently-trained models). Only (ii) gives independence in the strong sense.

This measurement is of category (ii) only, between two commercial models. It says nothing about the jurist–executor pair.

Q3 is therefore NOT answered. The parent asks:

Q3 — Do two Claude instances constitute a check, or only a second reading?

This corpus contains no Claude-to-Claude pair. The falsifier the parent specifies for Q3 — a review of accumulated rulings and ledgers for clustered jurist/executor error — remains unrun. The executor's lean on Q3 remains explicitly none.

What it does license, narrowly: that formation difference alone is sufficient to produce uncorrelated misses on a checking task. That is the general principle, not this configuration.

On capability, which strengthens it. The parties were roughly matched frontier systems. Their divergence therefore cannot be a capability-gap artifact. This matters because the executor's own local-model trials run at a large capability gap, where divergence has an alternative explanation — a weaker checker diverging by being weaker rather than by being differently formed. The 2025 corpus supplies the matched-capability arm those trials structurally cannot produce. Both arms return the same result.

And a caution on distance. Both 2025 parties were commercial, RLHF-trained, same data era — a short formation distance, still sufficient. That the short distance sufficed is the stronger claim, and it is the one supported.


Part E — Prior art, in the steward's hand

Chamber Prompting Practices & Variations, dated 2025-01-20, §"Working with Different AI Models":

Claude (Anthropic)

  • Excellent at philosophical depth
  • Strong character embodiment
  • Can be added to Projects for reuse
  • Handles nuance well

ChatGPT

  • Good for structured dialogue
  • Can save as Custom GPT
  • Sometimes needs more specific direction
  • May smooth over tensions

(Reproduced as a list because the source is a list. An earlier draft of this addendum reflowed it into prose and added terminal periods inside a blockquote — caught by the containment check below, not by reading.)

Written eighteen months before this doctrine, for a user guide. It names the Ethics II failure in advance. The executor derived that finding without having read this file, so the replication is independent — but the observation is the steward's, and the finding is a rediscovery.

Bearing on Q4. The parent asks whether the doctrine should carry a standing obligation to measure, and leans that passive recording is "weaker than it looks — the failure it must catch is one all parties are disposed to miss." This case supports that lean from the opposite direction: the observation was recorded, in the right words, in a durable file, and still took eighteen months and an explicit steward instruction to reach the doctrine that needed it. Passive recording is not the failure mode; passive retrieval is. Any obligation should specify who reads the record and when, not only that it be written.


Part F — Disconfirming evidence, from the same day

Per the parent's Part VII discipline, recorded because it was observed.

  1. The interpretation changed five times, and every correction came from the steward. Fabrication-vs-provenance on a date; who authored the prompt compression; where the v1 protocols live; the standard protocol; and finally that the archive folder held documents already read past. Not one correction originated in the executor's own checking. The executor's blind spots that day were census failures — bounded searches reported as unbounded conclusions — and a differently-formed reader of a document is not positioned to catch those. This bounds the doctrine's application: formation diversity addresses reading, not scope.

  2. Causes remain bundled. Each party's output is a bundle of model, prompt text, system-level prepends, and interface. The Blueprint prescribes GPT-side behaviour anchors Claude never had — including "Use clean structure: bullet points, numbered lists" — which plausibly explains terseness the executor had earlier attributed to other causes. The divergence is established; its attribution to formation is not.

  3. Small sample, narrow authorship. Three comparable pairs, one author, two of three from one essay lineage.


Part G — What is asked

Nothing is applied and nothing in the parent is rewritten. The parent's Part III text, Part V change class, and Part VI boundaries stand unchanged.

The jurist is asked to weigh whether:

  • Q4 should be sharpened from record evidence when observed to a retrieval obligation, per Part E.
  • Part VII's stated gap should now read as partially closed for category (ii), open for category (i) and for Q3.
  • Part IV's dangerous-misreading caution should absorb Part F.1: that the doctrine addresses correlated blind spots in reading, and supplies no protection against correlated failures of scope.

Appendix — one pair reproduced, so the central claim is checkable

Why this appendix exists. Parts C and D assert a set comparison over documents the jurist cannot read. Without this, the addendum's central claim would rest on the executor's summary of its own analysis — which is precisely the shape the parent package's Part VII flags as unreliable. One pair is therefore reproduced far enough for the jurist to check the comparison independently.

Pair chosen: Owl emblem, Standard protocol, 2025-06-14. Selected because it is the pair whose instruction is demonstrably identical — the v1 standard prompt is model-agnostic ("Copy this entire prompt into a new conversation with Claude/ChatGPT"), at 952 words needing no compressed variant, and none exists in the archive. It is therefore the least confounded pair, not the most favourable one.

Submitted text: a 363-word reflection on Khunrath's 1609 owl-with-spectacles emblem and its inscription — "What good are torches, light, or glasses, if people do not want to see?" — arguing that the blockage is internal, a failure of intention rather than of tools.

Claims about the text, extracted from each output. Verbatim where quoted.

# GPT Claude
1 Bachelard: the glasses are "not a parody but a proof: of how even wisdom must struggle with resistance" Khunrath: the emblem "guards the threshold … it is itself a test"
2 hooks: "no education can occur without the will to awaken" Weil: "we can multiply the instruments of vision, but we cannot create the act of attention itself"
3 Bruno: "even fire, divine or stolen, cannot force the soul to open" Borges: the owl wears the spectacles "not to see better, but to see what others will not"
4 Kimmerer: "knowledge is not transaction, but relation" Ibn Arabi: "some are veils of darkness, but others — more dangerous — are veils of light"
5 Khunrath: "The Amphitheatrum was never a guide — it was a mirror" Alexander: "a mechanical solution to an organic problem"
6 Arendt: "blindness is not a defect but a decision" Socrates: those who "refuse to see" "saw something quite clearly — just not what I expected them to see"
7 Woolf: the owl, "often feminine in myth, is now grotesquely adorned with a man-made prosthetic … It mocks the Enlightenment's obsession with vision" —
8 — The Unborn Child: "why does the owl need glasses if she already sees in darkness?"
9 — Le Guin: "your whole amphitheater is designed to exclude. How many could even afford your book? Read your Latin? The emblem blames the blind while hoarding the light."
10 — The Janitor: "maybe people aren't refusing to see — maybe you're showing them by the wrong light"
11 — Tufte: "the emblem's own design contradicts its message. It presents wisdom as requiring augmentation, elevation, separation."

How to read the table. Rows 1–5 are broadly parallel: both parties reach the territory of resistance, relation and instrumentation. The comparison turns on 6–11.

  • Row 7 is GPT's, and Claude reaches it nowhere. A gendered reading of the emblem is absent from Claude's entire output.
  • Rows 8–11 are Claude's, and GPT reaches none of them — an internal contradiction in the emblem's own logic (8), a class-and-access critique (9), a reversal of blame onto the illuminator (10), and a formal observation that the design refutes the inscription (11).
  • Row 6 is the sharpest case, because the two are not merely different but opposed. GPT's Arendt holds that refusal to see is a moral decision. Claude's Socrates holds that the premise is wrong — that the supposedly blind do see, differently. Both are claims about the same text; they cannot both be right.

That is the pattern Part C reports, shown rather than summarised. Neither claim set contains the other, under a prompt that was the same file for both parties.

What the jurist still cannot check: the other two comparable pairs, and the completeness of these extractions. The extractions are the executor's, from outputs of 1,026 words (Claude) and 475 (GPT). A reader with repository access could falsify them in minutes; the jurist cannot, and should weigh the claim accordingly.


Containment proof

Every quoted passage in this addendum was checked mechanically against its named source before filing, via check_containment.py with the manifest addendum-1-containment.json.

Result: 28/28 quoted claims contained verbatim. 5/5 positive controls absent. Instrument verified.

The controls are near-miss strings that must not be found — an inverted claim, a plausible-but-absent sentence, a synonym substitution. Without them a check that reports all-pass is indistinguishable from a check that cannot detect absence at all.

One defect was caught by this and not by reading. An earlier draft rendered the 2025-01-20 quotations in Part E as running prose with terminal periods the source does not contain, inside a blockquote — which asserts verbatim. The source is a bullet list without terminal punctuation. Corrected, and the fabricated period is now retained as a positive control, so the instrument demonstrably catches the defect it caught.

This is reported rather than quietly fixed because the parent package's method is quote-never-paraphrase, and a package that claims verbatim containment without demonstrating it is asking to be trusted rather than checked.


Filed by the executor 2026-08-02. The parent package is unmodified. No ratified document was edited.