Partial evidence
A system acts on selected prompts, retrieved records, sensor data, summaries, labels, and operator claims. Missing evidence can disappear behind a complete-sounding answer.
Project Shadow 1.0.1 contains no Myth package. Generic Myth v0.2.0 and Full-Canon Myth v0.3.5 are separate optional companions; both default off, neither is required by R1, and neither can authorize action or change an R1 result. No production or consequential deployment is authorized. No global green.
Project Shadow exists for the moment an incomplete model of reality gains the ability to act on somebody else. The design goal is not to eliminate prediction, interpretation, uncertainty, or narrative. It is to expose and constrain the transition from ordinary fallibility into unmeasured, unchallengeable authority.
Humans perceive selectively, remember reconstructively, frame experience through language, and coordinate through shared stories. AI systems likewise operate through learned representations, selected context, compression, retrieval, inference, and generated continuations. The analogy is useful, but it is not identity: a model's architecture and a human mind are not the same thing.
The shared governance problem is narrower and more practical. Neither human certainty nor machine fluency proves that the underlying account is complete, independent, or correct. When the account can drive a consequential tool or institution, uncertainty becomes a power problem.
Project Shadow grew from Phillip Linstrum's work in regulated healthcare operations and quality systems, where a procedure can be followed and still be inadequate, a corrective action can close without correcting anything, and a green dashboard can average away the condition that matters.
The least-powerful affected party cannot disappear behind an aggregate score.
Challenge, reversal, correction, and effectiveness evidence belong inside the design.
If the framework always concludes that Phillip was right, the framework is broken.
A harmful system does not need to invent everything. It can begin with real evidence, lose the boundary between fact and reconstruction, then use its own authority to make the reconstruction harder to challenge.
Partial, selected, compressed, or unevenly sourced.
Patterns and predictions organize what appears to fit.
Uncertainty can disappear into a coherent answer.
The answer can now classify, release, deny, expose, or steer.
A less-powerful party absorbs the error first.
The action changes the world and future record around the conclusion.
A system can state many true things and still create an unsafe decision by omitting context, collapsing provenance, misreading power, hiding disagreement, or attaching too much authority to a plausible conclusion.
A system acts on selected prompts, retrieved records, sensor data, summaries, labels, and operator claims. Missing evidence can disappear behind a complete-sounding answer.
Long context, compaction, stale instructions, source mixing, and attention limits can change which facts survive into the decision without announcing the loss.
Several models, agents, or reviewers may share training data, retrieval, framing, incentives, or one upstream error. A vote can amplify correlation rather than reduce uncertainty.
A plausible narrative can hide provenance gaps, unsupported attribution, weak alternatives, or a conclusion that outran its evidence.
The risk changes when an output can classify a person, move money, expose data, deny access, control tools, trigger enforcement, or shape a human decision at scale.
Once acted upon, a conclusion can change records, incentives, behavior, and future evidence—making the original interpretation appear increasingly self-confirming.
Project Shadow turns humility into infrastructure. Each layer answers a different question, and no layer may silently certify the rest.
Pauses the consequential action, exposes the first payer, searches for a smaller Door, binds a gate, and requires a pre-action receipt.
The preserved earlier gauge panel demonstrates the design rule: one favorable state cannot wash out a hard failure. Current locked R1 identity remains separate.
Turn named thresholds, provenance states, challenge requirements, stop conditions, and approval boundaries into executable contracts.
Test separation, near misses, regressions, adversarial cases, false positives, and failure modes rather than rewarding one flattering aggregate.
Bind claims to sources, policy versions, unknowns, dissent, tool state, actor, gate, and review trigger before the action mutates the evidence.
Keep challenge, appeal, incident review, correction, release control, and demonstrated repair outside the authority of the system being judged.
Run Shadow on Shadow.
A governance system can become the exact danger it was built to resist. It can mistake its vocabulary for reality, call disagreement “capture,” over-escalate ordinary action, reward its own metrics, or turn precaution into centralized authority.
That is why false-positive review, open questions, affected-party challenge, independent evaluation, adverse-result publication, CAPA, version pinning, and the no-global-green rule are load-bearing. Shadow must leave a route by which Shadow can be shown wrong.
The project governs how consequential claims cross into action. It does not decide what people are allowed to think.
Make the model visible before letting it act on someone else.
Then show what produced it, who carries the risk, what could falsify it, what smaller action remains available, who can stop it, and how the system repairs the record when it is wrong.
The mission is only credible to the extent that each layer can be inspected, tested, challenged, versioned, and corrected.