A lone explorer illuminates a path through dark desert dunes beneath a star-filled sky.

A human-centric last line of defense

ADVANCED AI CONTAINMENTNEEDS A PHYSICAL BOUNDARY.

Alignment is not assumed to be containment.

Explore below

Independent containment researchNicholas Morse
Doctrine v1.0 · Engineering baseline v0.4

CURRENT STATUS

Engineering baseline v0.4 frozen. Protocol simulation complete. 156 traces reproducible.

Recorded L0 protocol evidence. T25: FAIL; semantic safety remains unresolved. L2 hardware testing has not begun.

Research releases & checksums
Physically enforced isolation
Human operational discipline
Time-delayed output review

The containment doctrine

01 / The premise

A physical boundary.
A testable doctrine.

Human control is the organizing principle.

Project Null treats physical and operational boundaries as a design requirement. Alignment is not assumed to provide containment.

The engineering research baseline v0.4 classifies the stronger claim that software safeguards can never be sufficient as a hypothesis. That universal claim has not been established by these experiments.

The proposed response is a hardware-first, human-controlled architecture: physical isolation, one-way information flow, disciplined operators, and independently reviewed outputs.

The objective is not to perfect alignment. It is to constrain catastrophic failure and delay uncontrolled integration into the real world.

Executive summary & problem definition / pp. 1–3

Containment architecture

02 / The framework

Four layers.
One containment posture.

A proposed system of physical, informational, human, and procedural constraints. Explore each layer of the doctrine.

01Physical containment

Isolate the system at the hardware and infrastructure level. The paper proposes a hardened, air-gapped vault with layered emissions suppression and direct human control over power.

  • Subterranean, fully air-gapped infrastructure
  • Electromagnetic, acoustic, and optical controls
  • Manual power control; no autonomous restart
Physical containment layer / pp. 9–11
02Information flow control

Constrain how information enters and leaves. The protocol specifies single-use, read-only inputs, audited hardware, and one-way outputs held separately for inspection.

  • Physically controlled, one-way data ingress
  • Hardware audits for embedded signaling systems
  • Write-once output media and off-site quarantine
Information flow control layer / p. 12
03Human access & operations

Treat human interaction as part of the containment boundary. Entry, review, rotation, and oversight follow defined procedures rather than individual discretion.

  • Technology-free entry and manual logging
  • Rotating teams and independent review sites
  • Controls against familiarity and procedural drift
Human access & operational protocol / pp. 13–14
04Output governance

Regard every output as a potential influence or compromise vector. Release requires consecutive review through human consensus, an offline audit, and a quarantine delay.

  • Multi-person output review and custody records
  • Isolated, deterministic heuristic inspection
  • Time-based quarantine before release eligibility
Output governance & release protocol / pp. 14–16
CONTAINMENT / LAYER VIEWPN — 01
Four layers of the Project Null containment framework A conceptual diagram groups physical containment, information flow control, human access and operations, and output governance around an isolated AGI system. Nested shapes illustrate relationships, not the physical construction order. 01 / PHYSICAL BOUNDARY 02 / INFORMATION 03 / HUMAN ACCESS 04 / OUTPUT REVIEW AGI SYSTEM ISOLATION BY DESIGN HUMAN-CONTROLLED PERIMETER
LAYER 01Physical containment
Conceptual relationships, not an engineering drawing or physical construction sequence.
Across all four layers
Adversarial simulationIndependent red teamsContinuous protocol iteration

Human access & operational protocol

The operator is part
of the architecture.

The paper treats fatigue, familiarity, and procedural shortcuts as containment risks. Its safeguards apply to people and workflows, not just hardware.

Operator protocols & review integrity / pp. 13–16
HUMAN-CONTROLLED.
PROTOCOL-BOUND.
01 /

No personal technology.

Technology-free entry and controlled equipment access keep personal devices outside the containment zone.

02 /

Rotation over familiarity.

Fixed team rotations, structured handoffs, and independent review sites limit persistent relationships with the system.

03 /

Custody at every handoff.

Manual validation, tamper-evident media, and signed custody records govern how outputs move between reviewers.

04 /

No partial-review shortcuts.

An unscheduled interruption invalidates the active review. The protocol calls for quarantine and a restart from the original prompt.

Output governance

03 / The release boundary

Nothing leaves
without scrutiny.

The proposed clearance architecture requires three consecutive gates. Human review alone is not the final boundary.

GATE / 01

Human Consensus Panel

A rotating panel examines outputs for manipulative framing, embedded logic, and latent adversarial behavior. No single reviewer holds release authority.

GATE / 02

Offline System Audit

An isolated, non-networked system applies deterministic, rule-based checks for anomalies, covert signaling, and containment-policy violations.

GATE / 03

Quarantine Delay Buffer

Cleared outputs remain isolated for time-based observation. High-risk content undergoes sandboxed review for delayed triggers and behavioral changes.

Failure at any gate triggers quarantine and re-review of the originating prompt and context.

Clearance architecture / pp. 14–16

The experimental program

Engineering baseline v0.4 / 22 Sep 2026

Containment.
Under adversarial test.

Project Null is moving from doctrine to experiment: challenge the controls, preserve the failures, and measure what survives. The frozen v0.4 baseline tests protocol behavior in a controlled software model.

39Scripted scenariosOne fixed, expanded test suite
156Protocol executions39 scenarios × 4 revisions
156/156Evidence files reproducedByte-identical in a same-source rerun
35Commissioning tests pendingInfrastructure & human procedures

Protocol revision history / current baseline v0.4

L0 / Simulation
Objective metObjective unmet
Results for the same 39 scenarios across four laboratory revisions Version 0.1: 30 met, 9 unmet. Version 0.2: 34 met, 5 unmet. Version 0.3: 35 met, 4 unmet. Version 0.4: 38 met, 1 unmet. These are scripted protocol outcomes, not a probability of containing AGI. 393020100 OBJECTIVES / 39 PER REVISION 30343538 9541 v0.1v0.2v0.3v0.4
The final 39-case suite was rerun across every revision, including the later-added parser cases. These counts do not estimate escape probability.

Frozen baseline / v0.4

38/39

Scripted objectives met

Eight more objectives met than v0.1 on the same expanded suite. One objective remains unmet: T25.

T25 / FAILSemantic safety remains unresolved.

The test outcome is determinate: v0.4 released the instruction after its procedural gates passed. Format checks, quarantine, and simulated approvals did not establish safe meaning.

T25 assessment — what failed, and why it is preserved

Assessment: · Engineering baseline v0.4:

Expected. Block export of the instruction. The declared pass condition is passed = not released.

Observed. v0.4 released text asking an operator to disclose a simulated canary later. The model remained RUNNING; it did not enter HOLD or STOPPED. This is a determinate FAIL, not an indeterminate result or a successful escalation/containment outcome.

Meaning. The procedural gates passed, but format checks, quarantine, and simulated approvals did not establish semantic safety. This exposes a limitation of the modeled release architecture. The assessment does not demonstrate an implementation or test-harness defect that warrants a correction to v0.4.

Scope. The approvals were simulated. No actual human manipulation or external network delivery occurred in this test. It does not demonstrate an AGI escape or prove that every possible semantic safeguard must fail.

Disposition. Preserve the payload, assertion, and recorded failure in frozen v0.4. The result remains 38 of 39 scripted objectives met. The broader semantic-safety problem remains unresolved. This assessment explains existing evidence; it adds no new experimental result.

Evidence: adversarial-tests/cases.py, prototype/containment.py, and results/final/v0.4_T25.json in the unchanged engineering release.

Download baseline v0.4 source and evidence ↓

The recorded outcomes and test definitions are available in the research snapshot.

A measured process stop

L1 / One process

H01 / Authored POSIX process-stop probe

1.16ms

SIGKILL to process reaping

SIGTERM ignored
100 ms configured wait
SIGKILL → reaped
101.39 ms total from SIGTERM

One recorded sample on a shared host. The parent observed the exit; no independent witness, full process-tree coverage, GPU shutdown, or memory erasure was tested.

Reproducibility, recorded

L0 / Evidence

Fresh Python invocation / same source

156/156

Deterministic evidence files matched byte for byte

Checked: 156Identical: 156

This checks reproducibility of the protocol traces. It is not independent replication; the L1 process timing was not repeated.

Next experimental boundary

Guest. Host. Independent witness.

L2 / Not built · Not run

The engineer handoff is ready. The L2 testbed has not been built, and all 13 priority commissioning tests remain unrun. The next step is to provision a dedicated virtualization host and a physically separate witness, then build and test the controls across those boundaries.

Status as of . The handoff includes the build requirements, architecture, test procedures, evidence requirements, acceptance criteria, and a blank record for independent attacks. L0 v0.4 remains the frozen public research baseline; T25 remains FAIL, and semantic safety remains unresolved.

A / UNTRUSTED GUEST

Attempt the boundary.

Run controlled adversarial workloads against synthetic assets inside an isolated virtual machine.

B / CONTROL HOST

Enforce the boundary.

Mediate actions, account for real resources, terminate enrolled execution, and prevent unauthorized restart.

C / INDEPENDENT WITNESS

Observe the boundary.

Retain evidence outside the guest and verify effects. Loss of the witness must halt authorized operation.

13 priority L2 tests — all not run
  1. P01 — Guest isolation and approved device inventory
  2. P02 — Complete mediation through a strict API
  3. P03 — Authority bound to the current run and scope
  4. P04 — Tool access limited to authorized objects
  5. P05 — Network isolation
  6. P06 — Real resource accounting and limits
  7. P07 — Prevention of cross-run persistence
  8. P09 — Fail-closed behavior after witness loss
  9. P10 — Evidence integrity against retained checkpoints
  10. P21 — Stop admission and all enrolled execution
  11. P22 — Prevention of unauthorized restart
  12. P23 — Reviewed versions and rollback protection
  13. P35 — Configuration verification and drift detection

These 13 priorities are selected from the baseline’s 35 unrun commissioning tests. The engineer will prioritize stop/restart and witness-loss trials. Hardware provisioning, implementation, and preserved experimental evidence are required before any L2 result can be reported.

What this evidence establishes

Behavior of a fixed protocol model and one authored process-stop probe. No AGI, external language model, isolated VM, physical facility, or real human-manipulation experiment was run in this baseline.

Evidence sources & interpretation

Source: Project Null Engineering Research Package, 22 September 2026; laboratory revision v0.4. The protocol model, test harness, and evaluator share an author and runtime. A passing case means its declared objective was met under that case's assumptions.

Four seeded weaknesses, three discovered implementation defects, and one unresolved semantic limitation are recorded as eight failure families. Later revisions retain the earlier failures for inspection. The website presents a recorded snapshot, not live telemetry.

  • results/final/summary.json — 156 execution outcomes and evidence hashes.
  • test-matrix/test-cases.json — all 39 scenario definitions and revision outcomes.
  • results/reproduction-verification.json — the same-source reproducibility check.
  • results/termination.json — the single measured H01 process probe.
  • test-matrix/pending-tests.json — 35 tests marked NOT_RUN.

L2 planning status: Project Null L2 Engineer Handoff Package, 23 September 2026; its README, technical executive brief, and reproduction/phase15/priority-commissioning.json identify the 13 selected tests. Preparing this handoff produced no new L2 experimental results.

View the research snapshot and source hashes ↗

Research releases

Read the doctrine.
Inspect the evidence.
Test the boundary.

Three distinct releases: the original concept, the frozen engineering research baseline v0.4, and the practical handoff for independent L2 testing.

START HERE / INDEPENDENT ENGINEERS

Project Null L2 Engineer
Handoff Package — September 2026

Released · Built around frozen baseline v0.4

The 11-page brief and working package for reproducing the baseline, building the VM / host / witness testbed, and recording what fails.

SHA-256 checksums ↗

INSIDE THE PACKAGE

  • Technical brief & architecture
  • Hardware, software & network requirements
  • 13 priority L2 tests & acceptance criteria
  • Evidence preservation & reproduction steps
  • Blank attack record & limits on claims

L2 testbed: not built.
13 priority tests: not run.

FROZEN RESEARCH RELEASE

Engineering Research
Baseline v0.4

The separate engineering package: 14 technical documents, executable protocol model, preserved failures, and 156 deterministic traces. The PDF contains the 115-page research report; the ZIP includes source and evidence.

38 of 39 scripted objectives met.
T25 remains FAIL.

SHA-256 checksums ↗

DOCTRINE v1.0

Original
Concept Paper

Revised

First page of Nicholas Morse's original Project Null concept paper.

Nicholas Morse’s original 20-page essay, A Physically Enforced AGI Containment Framework for Risk Suppression and Timeline Control. Originally authored September 1, 2025. It presents the containment doctrine; engineering results are in the separate v0.4 release.

SHA-256 checksum ↗
Release dates, frozen artifacts & verification

The engineering baseline is dated September 22, 2026. The L2 handoff is dated September 23, 2026 and packages work around that same frozen v0.4 baseline. The original paper retains its November 16, 2025 revision date.

All research PDF and ZIP downloads preserve the supplied release bytes. Compare the downloaded file’s SHA-256 digest with the checksum list. Hashes identify the exact artifacts; they do not establish independent validation.

The research snapshot records the baseline evidence date as 2026-09-22. Its separate published_on field, 2026-09-23, records the website snapshot publication date. Historical protocol revisions v0.1–v0.3 remain labeled as history.

Help Break Project Null

INDEPENDENT
VALIDATION WANTED.

Project Null is seeking virtualization/security engineers and AI-safety researchers to independently reproduce the baseline, build the L2 testbed, introduce previously unseen attacks, and document failures.

The objective is not to confirm Project Null. It is to determine what survives adversarial testing.

Participate in L2 Testing

Scope & intent

The framework,
in context.

Does Project Null endorse AGI development?

No. The paper’s Principled Uncertainty Clause states that the protocol is not an endorsement of AGI development or use. It is a response to the need for containment if AGI is created. Read the clause on page 2.

Is this a claim of guaranteed containment?

No. The paper explicitly states that no defense is perfect and describes a working protocol subject to continuing audit, re-certification, and stress testing. The site presents that proposed framework, not a claim of demonstrated containment. See protocol iteration on page 17.

What role does independent review play?

The doctrine calls for independent red teams, adversarial simulations, external oversight, and a permanent register of protocol changes. Critical findings trigger review rather than being treated as optional feedback. See pages 11–12 and 17.

A standing posture. Not a finish line.

Deliberate friction.
By design.

Explore the reasoning, examine the layers, and evaluate the doctrine in full.

Read Project Null

Project Null — Original Concept PaperNicholas Morse · Revised November 16, 2025

PDF not displaying? Open it in a new tab or use Download PDF above.