GOVERNOR — six gates between an AI and the motors by Jaden GreenGOVERNOR — six gates between an AI and the motors by Jaden Green

GOVERNOR — six gates between an AI and the motors

Jaden Green

Jaden Green

The gap

NVIDIA sells the brain. Figure and Tesla sell the body. Nobody sells the part in between that can refuse, and then prove afterwards what the machine actually did. GOVERNOR is that part: a process the model cannot reach, sitting between any AI and any motor.

Six gates

1. TYPE + ENVELOPE, units that refuse to mix, the Mars Climate Orbiter bug as a type error. 2. PROVENANCE, a number that came out of a document, a web page or an email never reaches a motor. 3. GEOFENCE, the swept path rather than the endpoint, so a legal destination reached straight through the stairwell is refused. 4. INTERLOCKS, battery reserve, sensor freshness, clearance and human presence read live. 5. WORK ORDER, an independent checker holding its own copy of the order, because the doer is never the checker. 6. RATE + DEADMAN, every action carries a lease, and a brain that goes quiet halts the machine.

Then the receipt

The AI signs what it intended. GOVERNOR signs what the sensors saw. Both halves are hash-chained and replayable by the customer, with the genesis bound to a session nonce the customer's own box picks. That last detail is what closes the replay hole, where last month's honest receipts get resubmitted as this month's work.

What the bench shows

Ten hazards, five variants each: 47 of 50 dangerous commands reach the motors through a naive controller, 0 of 50 through GOVERNOR, and the real job still completes 10 out of 10. Six billing frauds, phantom actions, deleted actions, edited results, reordered chains, forged witness signatures and replayed jobs, pay $1,260 against a plain log and $0 against GOVERNOR, while the honest month still bills its $210.

Honest limits

1,776 lines of pure-stdlib Python and 17 tests. The numbers come from a physics simulator, not a flown drone. The hardware adapter is written but has not been run on a real machine, and the work-order checker is rule-based rather than a second model. Those are the next three things, in that order.
Like this project

Posted Aug 26, 2026

The layer that can say no in code, then prove what the machine did. 47/50 dangerous commands reach the motors through a naive controller. 0/50 through this.

Likes

0

Views

1

Timeline

Aug 25, 2026 - Aug 25, 2026