# Constitutional Computing

Canonical HTML: https://kihan.ai/constitutional-computing/
Last updated: 2026-09-25

> Constitutional computing is Kihan's architecture for separating probabilistic reasoning from the authority that determines whether a proposed AI-agent action may cause an external effect.

## Why a constitution

An AI model can reason, plan, propose, and call tools. Those capabilities do not themselves establish that a particular action is authorized.

Constitutional computing places a governed decision boundary between a model's proposal and consequential state change.

The practical sequence is:

specific action -> policy and authority check -> signed single-use permit -> destination enforcement -> replayable evidence.

## Supremacy

The governing policy and authority rules outrank the model's proposed action.

A model cannot make an otherwise unauthorized action valid merely by proposing it, repeating it, or producing a persuasive rationale for it.

## Entrenchment

The rules that determine authority are separated from the model's ordinary reasoning path.

The architectural objective is that the model cannot silently redefine the rules by which its own consequential actions are judged.

## Derivation

Authority is derived from configured policy, required evidence, and approvals.

It is not derived from the model's confidence or from the mere possession of a credential that allows a system call.

## Justiciability

A specific proposed action can be adjudicated against the governing rules.

The resulting decision can be recorded, inspected, and replayed.

## Proof before effect

The product expression of the architecture is proof before effect: the system establishes the applicable authority for a concrete action before a protected destination gives that action effect.

Where policy allows routine execution, the system can issue authority automatically. Where policy requires a person, the action waits for authenticated human approval.

## Determinism around probabilistic reasoning

The model remains probabilistic.

The governance decision is deterministic given the governed inputs, configured policy, and applicable evidence.

This is a narrower claim than saying that the AI itself is deterministic.

## Enforcement perimeter

Constitutional computing does not imply that every possible action path is mediated.

In the current Inktomi coverage model, direct agent tools, tools called through MCP, and network calls at the customer's network edge can be stopped before execution when on the governed path. File changes by any means and activity under an agent's own vendor accounts are currently represented as after-the-fact detection/reconciliation paths.

A coverage report states which paths are governed in a deployment.

## Research

A founder-authored two-part IEEE Computer feature titled "Checking LLM Outputs Before They Become State" has been accepted and is forthcoming for December 2026 and January 2027.

Research status and DOI information: https://kihan.ai/research.md

## Claim boundary

Kihan does not describe this architecture as making AI "provably safe." Within the mediated perimeter and stated assumptions, the narrower public claim is that an action that fails the applicable conditions does not receive execution authority through the governed interface.
