Constitutional Runtime

Govern what systems are allowed to make happen.

A Constitutional Runtime separates the ability to act from the authority to produce a consequential effect.

It is an independent software authority layer applied to selected consequential processes. It sits between a proposed action and protected execution; it is not installed inside the intelligence or used to replace the surrounding system.

System independent. Process applied.

Where it sits

The surrounding AI, software, person or automated system proposes an action. The Constitutional Runtime independently evaluates whether that exact action has valid authority. Only then can the action proceed through the protected execution boundary.

Applied in practice: select the process → profile the Constitutional Case → evaluate independently → determine PERMIT, WITHHOLD or REQUEST MORE INFORMATION → derive Exact Authority → verify at protected execution → preserve the evidential record.

The question changes at execution time.

Not simply: Can this system do this?
But: Does this exact action have valid authority to happen here, now and under these conditions?

Finance

Govern an exact payment before funds move.

Information

Govern an exact disclosure before protected information leaves.

Automation

Govern a proposed machine or software action before execution.

Critical operations

Govern consequential commands at the protected boundary.

Capability ≠ Authority.

The acting intelligence does not create its own authority.

Patent pending · UK application filed 21 August 2026

What is a Constitutional Runtime?

Capability ≠ Authority.

A Constitutional Runtime is an execution-time governance architecture that determines whether a proposed action is authorised before that action is permitted to produce a governed effect.

PROPOSE→GOVERN→AUTHORISE→BOUNDARY
Verified Constitutional Runtime · 143 tests passing · 34/34 integrated system tests across five governed domains · 0 failures · No live external effects enabled
PROPOSAL
CONSTITUTIONAL CASE
EVALUATION
DETERMINATION
EXACT AUTHORITY
PROTECTED BOUNDARY
EFFECT
EVIDENTIAL RECORD
What it does

From proposed action to authorised action to governed effect.

Traditional policies describe what should happen. A Constitutional Runtime participates in determining what may actually happen at the point where authority is required.

System independent. Process applied.

Proposed Action → Authorised Action → Governed Effect. The surrounding system does not need to become a Constitutional Runtime. The architecture is system-independent and applied to the consequential process where a proposed action seeks authority to produce an effect.

Why this category matters

Increasing capability makes the distinction unavoidable.

Ai agents, autonomous systems and increasingly capable software can now propose, decide and act at a speed and scale that makes a fundamental distinction unavoidable: the fact that a system can perform an action does not establish that it may perform that exact action. The architecture makes that distinction operational.

Authentication can establish identity. Access control can restrict resources. Policy engines can apply rules. Ai guardrails can influence model behaviour. Human approvals can authorise workflow stages. Risk systems can estimate severity or confidence. A Constitutional Runtime is concerned with a different and complementary question: does this exact consequential action have legitimate authority to create this effect now?

Defining characteristics

What should qualify as a Constitutional Runtime?

01 · Separation

Capability and authority remain distinct.

The acting system does not gain authority merely because it can technically perform the action.

02 · Independence

The proposer does not create its own authority.

The consequential action is subject to an authority process that is constitutionally distinct from the actor's intention.

03 · Exactness

Authority relates to the exact action.

A general capability or earlier permission cannot silently become authority for a materially different recipient, purpose, scope or effect.

04 · Protected boundary

Authorisation must matter at execution.

A constitutional decision is meaningful only if the consequential capability cannot simply ignore or bypass it.

05 · Non-compensation

A mandatory constitutional failure cannot be averaged away.

Strength, confidence or favourable conditions elsewhere do not transform a failed mandatory requirement into legitimate authority.

06 · Truthful outcome

Potential consequence and actual effect remain separate.

A high-consequence proposal is not presented as though the event actually happened when the constitutional boundary stopped it.

07 · Evidence

The constitutional outcome remains inspectable.

The system should preserve a comprehensible record of what was proposed, determined, authorised and actually effected.

A new category, not a replacement label

Capability, instruction and authority are different.

What can the system do? What has somebody asked it to do? What is it actually authorised to do? These are different questions. Capability describes what is technically possible. Instruction describes an intended outcome. Authority determines whether the particular proposed action may actually produce the governed effect.

Access control

Primarily asks whether an identity or role can reach a resource or capability.

Ai guardrails

Primarily constrain or guide model behaviour and outputs.

Policy engines

Evaluate rules or policy decisions, often as part of a wider control system.

Constitutional Runtime

Governs whether the exact consequential action has legitimate authority to cross the protected boundary into effect.

Security upgrade

Is your current security architecture ready for consequential Ai?

Firewalls, identity, access control, zero trust, monitoring and endpoint protection remain essential. A Constitutional Runtime adds a different question: when a capable or compromised system attempts a consequential action, does that exact action have legitimate authority to proceed?

Security protects systems and capabilities. Constitutional governance determines when an exact capability has authority to be exercised.
Reference implementation

What does a working Constitutional Runtime look like?

A category is more credible when it can be demonstrated in functioning software rather than described only in theory.

sCAiPe™ sCr Constitutional Runtime icon

sCAiPe™ is SAIFE Technologies Ltd's proprietary Constitutional Runtime technology and working reference implementation.

sCAiPe™ Constitutional Runtime is developed by SAIFE Technologies Ltd. It provides a concrete working reference through which the category can be examined across governed models and materially different consequential contexts.

Where the category applies

Wherever consequential capability needs legitimate authority.

Finance, information security, defence, autonomous systems, critical infrastructure, healthcare and other environments can differ radically in their rules while sharing the same constitutional problem.

Runtime definition

The category in precise and ordinary language.

A Constitutional Runtime applies governance at execution time so that relevant rules participate in determining whether a proposed action may become an authorised action. The question is not merely whether a system is constrained, but whether this particular proposed action has obtained the authority required to produce this particular governed effect.

Plain language:

A capable system can propose an action. It does not get to grant itself execution authority. No intelligence may authorise its own intended action.

The constitutional problem

Who or what wishes to act is not the same question as whether the action is authorised.

As software becomes more autonomous, systems can increasingly generate their own plans and proposed actions. A constitutional architecture must therefore avoid treating intention, identity, capability, confidence or urgency as substitutes for legitimate authority.

The runtime answer

Authority is determined at the point where consequence matters.

The constitutional relationship remains active through the transition from proposal to protected effect. It is not enough to have a policy document somewhere upstream if the action arriving for execution can materially differ from what was authorised or bypass the authority decision entirely.

Seven constitutional stages

The category is defined by a relationship, not a logo.

Proposal

What is being proposed? An intention enters the process without acquiring authority merely because it exists.

Constitutional Case

What exactly must be decided? The relevant purpose, circumstances, evidence and constitutional requirements are brought together.

Determination

Is the exact action constitutionally permissible? The determination remains distinct from the actor's desire to proceed.

Exact Authority

Precisely what has actually been authorised? A permitted determination does not itself become unrestricted execution authority. Exact Authority remains bounded to the action that earned it.

Protected Boundary

Does the action arriving for execution still match valid authority? The consequential capability remains behind the boundary.

Effect

What actually happened? Actual effect is recorded separately from the consequence that was merely possible.

Evidential Record

What can be established afterwards? The governed history remains capable of human and technical examination.

What qualifies

Independent authority relationship

The actor cannot simply infer its own mandate from capability.

Runtime significance

The determination must matter before protected consequential effect.

Exact-action binding

The authorised action and executed action cannot be casually decoupled.

Evidential distinction

Proposal, determination and actual outcome remain distinguishable.

What does not qualify by itself

A prompt saying “be safe”

Behavioural instruction may be valuable, but it is not itself an independent protected authority layer.

A generic login permission

Identity and access can be relevant, but they do not automatically authorise every consequential use of the capability.

A risk score

Risk can inform a constitution, but a favourable aggregate score is not equivalent to exact authority.

A retrospective audit only

Evidence after the event is important, but the defining constitutional decision must matter before protected effect.

sCAiPe™sCr Runtime icon

Reference implementation: sCAiPe™

The category definition can be examined through a working implementation rather than remaining purely conceptual.

Applications

The constitutional problem appears wherever capability can create consequence.

A Constitutional Runtime is category-level infrastructure. The governing rules vary by domain, but the architectural relationship remains recognisable: proposed action, legitimate authority, protected boundary and evidential effect.

Core Governance

Constitutional decisions

General consequential decision governance independent of a particular industry.

Financial

Transactions and instructions

Exact authority before a payment, transfer or material financial instruction creates effect.

Information Security

Protected information actions

Purpose-bound authority before consequential access, alteration, disclosure or external release.

Defence

Command and decision governance

Preserve mandate, limits and accountability as distinct from capability.

Healthcare

Sensitive purpose-bound decisions

Consent, legitimate purpose, role, necessity and authority can matter before sensitive consequence.

Autonomous Systems

Machine action

Physical or digital ability to act remains subordinate to exact authority.

Critical Infrastructure

Essential-system intervention

Authority, limits and evidence between a proposed control action and consequential effect.

Category principle

The core architecture is reusable. The constitution is not generic.

A bank, hospital, defence organisation and infrastructure operator do not have the same legitimate authority rules. The Constitutional Runtime category does not flatten those differences. It provides a disciplined architectural place in which each environment's legitimate authority can govern exact consequential action.

Reference implementation

sCAiPe™ demonstrates the common architecture across materially different contexts.

The working reference implementation provides a practical way to test whether the category survives domain change rather than existing only as a single-use pattern.

Security in the age of consequential Ai

When access is legitimate, the action can still be wrong.

Modern cybersecurity is built from essential layers: identity, authentication, network controls, endpoint protection, access management, monitoring, detection and response. A Constitutional Runtime does not replace those controls. It addresses a further problem created by increasingly capable Ai and autonomous software: what if the system has access and capability, but the exact action should still not be authorised?

The security gap to consider

An attacker does not always need to defeat every control if a trusted or compromised system can be induced to perform the harmful action itself.

That is why securing identity and access is necessary but may not be the final constitutional question. The organisation may also need to govern the authority of the action itself: its purpose, target, scope, timing, conditions and consequence.

A Constitutional Runtime makes the authority of the action itself part of the protected security boundary.

The aim is not to promise an “unhackable” system. It is to add a governed layer that can prevent capability from automatically becoming authority.

Existing security + constitutional control

Keep the controls you need. Add the question they may not answer.

Established security controls may ask

  • Who is this person, service or process?
  • Is the credential or device trusted?
  • Can it access this resource?
  • Is the connection permitted?
  • Does this role or process have permission?
  • Is suspicious activity being detected?

A Constitutional Runtime additionally asks

  • What exact consequential action is being proposed?
  • What legitimate authority exists for that exact action?
  • Does that authority apply now, for this purpose and target?
  • Does the action reaching execution still match what was authorised?
  • If authority fails, can the action be stopped at the protected boundary?
  • Can the decision and actual effect be proved afterwards?
For organisations reviewing security

A useful question for your next security upgrade.

If an Ai agent, automated workflow, administrator, service account or compromised process can reach a consequential capability, what independently determines whether the exact action is authorised before effect?

Ai securityAi agent securitystop Ai acting without permissionprotect data from Aiprevent unauthorised Ai actionscybersecurity for autonomous agents
Reference implementation

sCAiPe™ provides a working Constitutional Runtime for this additional authority layer.

It can be considered alongside existing security architecture where consequential actions require independent constitutional determination before protected execution.

Discuss a security architecture
Licensing & integration

Use the reference implementation within a wider secure system.

Security providers, integrators and technology organisations can discuss using sCAiPe™ as a constitutional control layer within their own governed architectures, products or client implementations.

Discuss licensing & integration
Reference demonstrations

See a Constitutional Runtime govern an exact action.

The demonstrations use sCAiPe™ as the working reference implementation. They are not generic product tours: each example exposes the same constitutional relationship in a different consequential setting.

Concrete example

Governed bank transfer.

A simulated transfer can be proposed without that proposal becoming authority. Recipient, value, approval conditions and exact action remain constitutionally significant before any protected execution.

Proposed consequenceTRANSFER REQUEST

A payment instruction is proposed with a specific recipient, amount and context.

Constitutional determinationEXACT AUTHORITY CHECKED

The Runtime determines whether the required authority applies to this exact transfer.

Protected effectPASS OR NO PASS

The protected side respects the constitutional outcome. The simulation does not move real money.

What the demonstration proves

Proposal is not authority

The requesting actor can propose the transfer without being able to self-authorise it.

Authority is exact

A materially different recipient, value or action cannot simply inherit an earlier approval.

The boundary matters

The protected consequential capability receives the constitutional result rather than relying on model good behaviour.

Outcome remains truthful

A refused or simulated action is not presented as though money actually moved.

Other reference contexts

Constitutional decisions

Domain-neutral demonstration of mandatory constitutional conditions.

Server information protection

Governed disclosure and protected information action.

Defence decision governance

Local non-operational illustration of mandate, limits and consequence.

Governed Command & Control

Exact command authority, continuity, acknowledgement and refusal in a contained model.

sCAiPe™sCr Runtime icon

sCAiPe™ supplies the reference implementation.

The category site explains what a Constitutional Runtime is. sCAiPe™ is SAIFE Technologies Ltd's proprietary Constitutional Runtime technology and demonstrates the architecture in working governed models.

Architecture

Where a Constitutional Runtime sits — and how it is applied.

System independent, process applied. A Constitutional Runtime is not installed inside an entire system as another internal feature. It is applied to the specific consequential process that needs authority, sitting between the proposed action and the protected capability that can execute it.

Where it sits

The surrounding system remains itself; the selected process gains an authority gate.

A Constitutional Runtime does not govern every thought, computation or recommendation inside the host environment. The significant transition occurs only on the selected execution path: when a proposed consequential action is about to move from intention into effect, it must pass through independent constitutional authority.

Existing system / agent
proposes action
→
Constitutional Runtime
software authority layer
→
Selected process
executes if authorised
How it is applied

Six steps from process selection to execution.

01 · Select the process

Identify the consequential process whose execution requires explicit constitutional authority. The surrounding system remains otherwise independent.

02 · Profile the Constitutional Case

Define the exact proposed action, purpose, scope, context, evidence and recognised sources of authority that matter to that process.

03 · Evaluate independently

Evaluate the Case against the applicable constitutional requirements without allowing the proposing system to create or approve its own authority.

04 · Reach a determination

Return PERMIT, WITHHOLD or REQUEST MORE INFORMATION according to the requirements and evidence available for that exact case.

05 · Derive Exact Authority

Where permitted, derive authority that is bounded to the exact action that earned it rather than a general permission to continue.

06 · Execute through the protected boundary

The selected process may execute only when the action arriving at the boundary still matches valid Exact Authority; the outcome remains evidentially distinct afterwards.

Technology-independent principle

The category is system independent and process applied.

The surrounding system could be an Ai agent, workflow engine, autonomous controller, conventional application or human-operated software. The Constitutional Runtime is applied to the consequential process that needs authority, not defined by — or installed throughout — the technology that generated the intention.

Implementation

The process is adapted to the Runtime; the whole system is not replaced.

Real implementation identifies the selected process, its legitimate authority sources, the Constitutional Case profile, the protected execution boundary and the interface points needed to route that process through the authority layer. Integration details depend on the environment, but the architectural distinction remains the same.

Evidence & category integrity

A category should be judged by what its architecture can prove.

“Constitutional Runtime” should not become a loose marketing label. A credible implementation should be able to demonstrate that authority is independent of capability, that exact actions are governed before effect, that protected execution respects the determination, and that the outcome remains evidentially intelligible.

Integrated system milestone

CS-SYS-0001 demonstrates the constitutional architecture as one functioning system.

Complete integrated working Constitutional System implementation.

The reference Runtime baseline reached release candidate 1.0.0-rc.1 with 143 tests passing. The later CS-SYS-0001 milestone exercised the common constitutional architecture across five materially different governed domains: general constitutional decisions, governed financial transfer, protected information handling, defence decision governance and governed command & control; its integrated regression suite passed 34/34 tests with 0 failures.

143 tests passing34/34 integrated system testsFive governed domains0 failuresNo live external effects enabled
Evidence questions
Separation

Can the actor act without constitutional authority?

If a consequential capability remains directly reachable around the authority layer, the constitutional claim is weakened.

Exactness

Is authority bound to the action actually determined?

A general approval should not silently authorise a materially altered action.

Mandatory conditions

Can a mandatory failure be compensated away?

A constitutional requirement that is truly mandatory should not disappear because confidence or aggregate score is favourable elsewhere.

Boundary

Does the protected side enforce the decision?

The constitutional result must have operational significance before consequence.

Truth

Can potential and actual effect be distinguished?

A blocked high-consequence proposal should remain visibly different from a real event.

Record

Can the constitutional history be inspected afterwards?

The evidence should remain comprehensible to responsible humans as well as technically examinable.

Reference implementation evidence

sCAiPe™ provides a concrete test of the category.

The complete integrated working reference implementation has been exercised across materially different governed contexts while preserving the same constitutional core. Public presentation remains deliberately separated from confidential source, security-sensitive engineering and protected implementation mechanisms.

Truthful status vocabulary

Demonstration

Illustrates constitutional behaviour in a contained presentation.

Working model

Functioning software exists for the bounded model being described.

Potential application

The architecture is applicable in principle but is not represented as deployed.

Deployment

Reserved for a system genuinely operating in the claimed external environment.

sCAiPe™sCr Runtime icon

Reference implementation: sCAiPe™

The category definition and evidence criteria are intended to remain broader than a single product while being demonstrable through a functioning implementation.

Questions & Answers

Questions about the Constitutional Runtime category.

The category should be understandable without requiring the visitor to know sCAiPe™ first. Product-specific material is introduced only where the reference implementation helps make the architecture concrete.

What is a Constitutional Runtime?

An independent governance layer through which an exact consequential action must obtain legitimate authority before it can cross a protected boundary into effect.

Why “runtime”?

Because the constitutional question matters while the system is operating and before the consequential action creates effect — not only in design documents or retrospective audit.

Why “constitutional”?

Because the architecture distinguishes higher-order governing authority and mandatory conditions from the wishes or capabilities of the actor proposing the action.

Is this just access control?

No. Access control usually governs whether an identity or role can reach a resource or capability. A Constitutional Runtime governs the authority of the exact consequential action.

Is it an Ai guardrail?

It can govern Ai-agent actions, but the category is broader. Model guidance and safety filters can be useful controls; the Constitutional Runtime is concerned with independent authority before protected consequence.

Is it a policy engine?

A policy engine may form part of an implementation, but the category includes the wider constitutional relationship: proposal, case, authority, protected boundary, effect and evidence.

Does the acting Ai decide whether it is authorised?

That would undermine the defining separation. The proposer can supply information and intention, but the constitutional authority relationship must remain independent of the actor's desire to proceed.

What makes authority “exact”?

The permission relates to the action actually determined — including materially relevant target, purpose, scope or other conditions — rather than becoming a broad licence for a different action.

Why does the protected boundary matter?

Because a constitutional decision has little operational value if the consequential capability can bypass it. The boundary is where valid authority must still matter.

Can a high confidence score override a failed mandatory condition?

Not in a constitutional architecture where that condition is genuinely mandatory. Strong performance elsewhere does not create authority by compensation.

Does a high potential consequence mean the event happened?

No. Potential consequence, constitutional determination and actual effect must remain visibly distinct.

Is the category only about Ai?

No. The architecture applies wherever consequential capability and legitimate authority need to be separated, including conventional software, agents, autonomous systems and human-operated digital systems.

What is sCAiPe™?

sCAiPe™ is SAIFE Technologies Ltd's proprietary Constitutional Runtime technology and working reference implementation of the architecture.

Is every described application already deployed?

No. Working models, demonstrations, potential applications and deployments are different claims and should be labelled accordingly.

Where can I see it operating?

The reference demonstrations use sCAiPe™ to show the architecture in governed financial, information-security, defence and command contexts.

Is Constitutional Runtime patented?

A UK patent application covering aspects of the Constitutional Runtime architecture was filed on 21 August 2026. Patent pending.

Is the system already deployed in live banking, defence or infrastructure environments?

No. A complete integrated working implementation has been built and tested across materially different governed contexts, but no live external effects are currently enabled. Demonstration, working implementation and live deployment remain deliberately distinct claims.

Who should I contact?

For Constitutional Runtime category and architecture enquiries, email contact@constitutionalruntime.com. For sCAiPe™ product and programme enquiries, email info@scaipe.ai.

About ConstitutionalRuntime.com

The home of the Constitutional Runtime category and its working reference implementation.

This site exists to define the category in clear language, explain the architecture, distinguish it from adjacent controls, show where it can apply, and provide a working implementation against which the concept can be examined. A UK patent application covering aspects of the architecture was filed on 21 August 2026.

Category purpose

Define before promoting.

The phrase “Constitutional Runtime” should carry a coherent architectural meaning. This site therefore leads with the category: separation of capability and authority, exact-action governance, protected execution and evidential outcome.

Reference implementation

sCAiPe™ demonstrates the category in functioning software.

sCAiPe™ Constitutional Runtime is developed by SAIFE Technologies Ltd and serves as the proprietary working reference implementation through which the architecture can be demonstrated, challenged and applied across different consequential contexts.

sCAiPe™sCr Runtime icon

sCAiPe™ Constitutional Runtime

Working reference implementation · governed application models · human-first constitutional explanation · protected technical evidence.

Stewardship

SAIFE Technologies Ltd

This site defines the Constitutional Runtime category. SAIFE Technologies Ltd develops sCAiPe™ Constitutional Runtime as its proprietary implementation. Public communication remains plain-language first while confidential engineering and protected implementation remain controlled.

Contact

Discuss the category, architecture or reference implementation.

For enquiries about the Constitutional Runtime category, architecture or potential application, use the dedicated public contact below. sCAiPe™ product and programme enquiries remain available through scaipe.ai.

Category & architecture

Questions about the definition, architectural characteristics or where a Constitutional Runtime may fit.

Reference demonstration

Request the governed bank-transfer example or another suitable sCAiPe™ reference demonstration.

Potential application

Discuss a consequential environment where capability and authority need to remain independently governed.

sCAiPe™ programme

Product, programme, commercial or technical enquiries about the working reference implementation.

Security & responsible disclosure

Use a clear subject line and avoid unnecessary sensitive material in an initial message.

Legal & privacy

Questions relating to public legal notices, privacy, disclosure status or appropriate legal routing.