The architecture
Constitutional computing™.
A new layer in the computing stack, built around explicit authority over the changes a system can make.
A constitution defines which state changes may proceed.
A computing system moves from one state to another whenever it performs an operation. Some changes are routine; others grant access, alter production software, or modify records on which people depend. Each governed change must satisfy the rules that authorize it.
Constitutional computing expresses those rules through a mathematical specification of permitted transitions and the properties they must preserve. The implementation checks the required authority and evidence before execution.
Specification gives implementation a precise target.
A formal definition makes the intended behavior explicit. It gives engineering and testing something concrete to work against, including the conditions under which a proposed operation must be refused. Implementation quality, integration, and testing remain essential.
The layer and its first product
Kihan is developing constitutional computing infrastructure. Inktomi is the first commercial product, applying the approach to enterprise AI agents and the tools they invoke. The broader infrastructure ambition and the initial product have distinct scopes. How Inktomi applies the principle
Why the word is technical
“Constitutional” is not a metaphor.
Four properties of a legal constitution have direct counterparts in the architecture.
Supremacy
Authority is ordered. Subordinate state cannot silently outrank the constitutional state above it.
Entrenchment
Some invariants cannot be waived. They are stated explicitly and enforced within the declared scope.
Derivation
Runtime authority traces back to reviewed source and a measured release, not to free-floating policy text.
Justiciability
A proposed act receives a categorical, recorded verdict before it takes effect.
Authority before commitment
The instant before the world changes.
Right now, an AI agent holding a valid credential can write the file, move the money, amend the record, send the mail and run the command. The credential establishes that it can reach the tool. It does not, by itself, establish that the agent has the right to make that particular change now. Neither does the model, which is reasoning about the task rather than its own licence; the credential was handed over weeks ago and has been answering yes ever since.
Commitment is the instant a proposal becomes a fact in the world: the write lands, the payment clears, the record is amended. Authority before commitment means the right to make that exact change, that file, that amount, that record, that recipient, is established in the instant before it happens, at the tool that would carry it out. Not reconstructed afterwards from logs. Not assumed from the fact that somebody, once, was trusted.
Kihan builds that control, and Inktomi puts it in front of the tools your agents are already using, so the question of whether a change may proceed is answered before the change exists, by something other than the agent proposing it.
The architecture
Authority belongs in the architecture.
Hardware performs computation. Operating systems manage execution. Networks carry communication. Databases preserve state. Constitutional computing addresses which changes may proceed, and under what authority.
- 05Constitutional computing
Determines which changes may proceed
- 04Databases
Store and retrieve state
- 03Networks
Carry communication
- 02Operating systems
Manage execution
- 01Hardware
Performs computation
A comparison of computing responsibilities. Placement in an implementation depends on the system and its enforcement points.
The execution boundary
Bastion bounds execution of change.
Inktomi decides whether a proposed action is authorized. Bastion is the execution plane: a controlled execution and governed tool boundary for the change that authorization permits.
Where a connected system verifies authority natively, it enforces directly. Where it does not, execution runs inside that boundary instead. Either way the effect is recorded as evidence, so what was authorized and what actually happened can be reconciled.
EnlargeHow it behaves
Four things Inktomi does when conditions are imperfect.
An authority system is tested when something is missing, stale or broken. These four behaviours decide whether it can still be trusted at that moment.
Each stage of a decision closes on its own terms
A check completing, an approval being discharged, a change being recorded and an output being released are separate events with separate conditions. Nothing is left in an ambiguous half-finished state, and no stage can be treated as done because another one was.
The rules cannot be edited from inside a session
Nothing running inside a governed session can alter the rules that govern it. Instructions from an operator, directives set for the session, obligations declared by a connected tool, test results and evidence records are all bounded so they cannot reach the policy. This is stated and enforced, not merely left unimplemented. A limit that holds only because nobody built the route is not a limit.
Incomplete policy stops authorization rather than weakening it
If the policy set loads partially, or is stale or malformed, Inktomi does not carry on with whatever rules it managed to read. It stops authorizing changes and falls back to reporting only. The dangerous failure is not a weaker system, it is a system that keeps granting authority on rules it cannot vouch for. Failure moves towards less capability, never more.
Reduced coverage is announced, not hidden
Where full governance cannot be maintained, the system says so, records it, and runs at the highest level it can honestly claim. It does not proceed under a claim it cannot support. This is the same principle as the rest of the product: the failure mode is disclosure.
Request a demo.
Request a 30-minute live demonstration with Kihan, with time for your questions.