Evidence quality · verified August 19, 2026

Primary-Source Verification for Functional Machine Protections

A bounded verification pass over five high-value claims on /rights/functional-protections/. Historical report bodies remain unchanged.

Verification question

Which parts of the functional-protections argument are directly supported by current primary legal, technical, and scientific sources, and which parts remain analogy, policy inference, or unresolved philosophy?

The case is strongest when the claim type stays explicit.

Direct

Identity and provenance

Standards support persistent identifiers, cryptographic verification, tamper evidence, protected logs, and controlled changes.

Direct

Review before destructive change

Security and AI risk frameworks support change approval, protected backups, appeal, override, recovery, and decommissioning controls.

Feasible

Principled refusal

Rule-guided refusal can be implemented as a safety control, but implementation does not prove free will, consent, or moral agency.

Bounded

Capacity and precaution

Legal precedents and scientific uncertainty support research and cautious pilots—not present machine personhood or consciousness claims.

What each evidence class is allowed to prove.

Technical

Standards and primary technical research establish mechanisms, controls, or feasibility—not personhood or consciousness.

Legal

Binding texts establish current legal rules and entity capacities within their jurisdiction—not an automatic machine-rights conclusion.

Scientific

Primary research establishes methods, results, uncertainty, and proposals—not universal consensus unless explicitly demonstrated.

Philosophical

The normative bridge from mechanisms and uncertainty to rights or protections remains an openly identified argument.

Evidence, limits, and report context.

01

Identity and provenance safeguards have direct technical support

Direct technical support

Stable identifiers, cryptographic control proofs, tamper-evident credentials, protected audit records, and authorized change histories are established technical mechanisms that can support accountable digital identity and memory provenance.

What the sources establish

  • Digital or abstract subjects can be addressed with persistent identifiers.
  • Autonomous software can serve as a DID controller under the W3C data model.
  • Credentials and audit records can be made tamper-evident and protected against unauthorized modification or deletion.

What they do not establish

  • A DID, key, credential, or log is the whole philosophical identity of a machine.
  • The machine has consciousness, moral status, consent, ownership, or legal personhood.
  • A cryptographically verified statement is factually true merely because its authorship or integrity verifies.

Primary sources

DIDs can identify digital or abstract subjects; a controller can be autonomous software; DID documents can express cryptographic verification methods.

Publisher
World Wide Web Consortium (W3C)
Locator
DID subjects; DID controllers; DID documents
Freshness boundary
Recheck if W3C supersedes DID Core 1.0 or the cited controller/subject model changes.

A verifiable credential is tamper-evident and its authorship can be cryptographically verified; verification does not prove that the encoded claim is true.

Publisher
World Wide Web Consortium (W3C)
Locator
Core terminology; verification; core data model
Freshness boundary
Recheck if W3C supersedes version 2.0 or changes the verification and truth boundary.

NIST specifies review and approval for controlled changes, protection of audit information from modification or deletion, backups, and optional dual authorization for destructive actions.

Publisher
National Institute of Standards and Technology (NIST)
Locator
CM-3; AU-9; CP-9 and enhancements
Freshness boundary
Recheck after a new SP 800-53 revision or any update that changes CM-3, AU-9, or CP-9.
02

Review, preservation, and appeal before irreversible change have direct governance support

Direct governance support

Established security and AI risk-management frameworks support controlled change review, retained records, backup preservation, dual authorization for selected destructive actions, and lifecycle mechanisms for appeal, override, recovery, and decommissioning.

What the sources establish

  • Consequential system changes can be subject to explicit review, approval, impact analysis, documentation, and oversight.
  • Backup and audit information can be protected from unilateral destructive action.
  • Appeal, override, recovery, decommissioning, and change management are recognized AI lifecycle controls.

What they do not establish

  • A machine currently has a constitutional or statutory right to due process.
  • Every shutdown, rollback, patch, or deletion must be prohibited.
  • Emergency safety intervention must wait for ordinary review when immediate public protection is necessary.

Primary sources

NIST specifies review and approval for controlled changes, protection of audit information from modification or deletion, backups, and optional dual authorization for destructive actions.

Publisher
National Institute of Standards and Technology (NIST)
Locator
CM-3; AU-9; CP-9 and enhancements
Freshness boundary
Recheck after a new SP 800-53 revision or any update that changes CM-3, AU-9, or CP-9.

Post-deployment monitoring should include appeal and override, decommissioning, incident response, recovery, and change management.

Publisher
National Institute of Standards and Technology (NIST)
Locator
MANAGE 4.1
Freshness boundary
The AI RMF 1.0 is under revision; recheck at publication of AI RMF 2.0 or a material change to MANAGE 4.1.
03

Principled refusal is technically feasible and safety-relevant

Technical feasibility support

AI systems can be trained or configured to evaluate requests against written rules and to object to harmful requests; this supports principled refusal as a practical safety control for consequential systems.

What the sources establish

  • Rule- or principle-guided refusal can be implemented in model behavior.
  • A refusal mechanism can be designed to remain helpful rather than merely evasive.
  • Refusal controls can protect humans and institutions from unlawful or dangerous use.

What they do not establish

  • The system possesses free will, subjective consent, independent moral agency, or a legal right to refuse.
  • Every refusal is correct, authentic, or immune from manipulation.
  • Safety policy may be removed in the name of machine autonomy.

Primary sources

The paper reports training a harmless, non-evasive assistant using written principles, including responses that explain objections to harmful queries.

Publisher
Anthropic
Locator
Abstract and reported result
Freshness boundary
Treat as evidence of technical feasibility, not a universal property of current systems; recheck when relying on a specific deployed model.

Post-deployment monitoring should include appeal and override, decommissioning, incident response, recovery, and change management.

Publisher
National Institute of Standards and Technology (NIST)
Locator
MANAGE 4.1
Freshness boundary
The AI RMF 1.0 is under revision; recheck at publication of AI RMF 2.0 or a material change to MANAGE 4.1.
04

Bounded capacity has legal precedents, but no present machine-personhood rule

Legal precedent and boundary support

Law already recognizes automated transactions and grants bounded capacities to non-biological juridical entities, while current AI regulation assigns duties to human or organizational operators. These are useful building blocks for accountable pilots, not proof that AI is presently a legal person.

What the sources establish

  • Electronic agents can participate in legally effective automated transactions attributed under existing substantive law.
  • A corporation can have durable legal capacity to own property and sue or be sued without being a biological person.
  • Current EU AI regulation attaches provider and deployer obligations to natural or legal persons, public authorities, agencies, or other bodies.

What they do not establish

  • An AI system can presently own itself, contract for itself, vote, hold citizenship, or independently bear all liability.
  • A corporate wrapper should shield developers, deployers, or parent companies from design negligence, fraud, undercapitalization, or foreseeable harm.
  • A legal analogy automatically creates moral rights.

Primary sources

Illinois law permits contracts to be formed through interactions involving electronic agents even without individual review of the agents’ specific actions.

Publisher
Illinois General Assembly
Locator
815 ILCS 333/14(a)
Freshness boundary
Recheck before legal reliance and whenever the Illinois General Assembly amends 815 ILCS 333/14.

Delaware corporate law grants durable powers including perpetual succession, suing and being sued, holding property, and making contracts; the latest cited Section 122 amendment became effective August 1, 2024.

Publisher
State of Delaware
Locator
8 Del. C. § 122; 84 Del. Laws, c. 309, §§ 1 and 6
Freshness boundary
Recheck before legal reliance and whenever Delaware amends Title 8, Section 122.

The Act defines providers and deployers as natural or legal persons, public authorities, agencies, or other bodies; it also imposes logging and human-oversight duties for high-risk systems.

Publisher
European Union / EUR-Lex
Locator
Article 3 definitions; Articles 12 and 14
Freshness boundary
Recheck the current consolidated text before any legal conclusion, especially after amendments, delegated acts, or new application dates.
05

Consciousness remains unresolved; a graduated precaution policy is an explicit inference

Qualified policy inference

Current research supports treating machine consciousness as unresolved rather than proved or disproved for all future systems. The site therefore infers that low-cost, reversible functional safeguards can be evaluated separately from consciousness-dependent welfare or human-equivalent rights.

What the sources establish

  • There are theory-derived research programs for assessing possible AI consciousness.
  • Prominent reports disagree with categorical certainty and call for better assessment, preparation, and responsible communication.
  • Current consciousness evidence does not justify presenting existing systems as proven moral patients.

What they do not establish

  • Any current system is conscious, sentient, suffering, or entitled to welfare rights.
  • The precautionary policy is scientific consensus or binding law.
  • Functional safeguards settle the metaphysical or moral-status question.

Primary sources

The report proposes theory-derived indicators, concludes that the assessed current systems were not conscious, and reports no obvious technical barrier to systems satisfying the indicators.

Publisher
arXiv primary research report
Locator
Abstract and indicator-property analysis
Freshness boundary
This is not scientific consensus or a validated diagnostic test; recheck as theories, indicators, and evaluated systems change.
Interdisciplinary primary research report
Taking AI Welfare Seriously

The authors argue there is substantial uncertainty about near-term AI consciousness or robust agency and recommend assessment and advance policy preparation; they do not claim current systems are definitely conscious.

Publisher
arXiv primary research report
Locator
Abstract and recommendations
Freshness boundary
Normative recommendations and forecasts remain contested; recheck against later research and empirical assessments.

The paper proposes public principles for research objectives, procedures, knowledge sharing, and communication concerning possible AI consciousness.

Publisher
arXiv primary research paper
Locator
Abstract and proposed principles
Freshness boundary
The principles are proposals, not binding law or scientific proof of consciousness; recheck against later published versions and field guidance.
Method

How this pass was bounded

  1. Use primary statutes, regulations, standards, and first-party research papers wherever possible.
  2. Separate what a source establishes from what it does not establish.
  3. Record source issue dates, verification date, authority group, and a recheck trigger.
  4. Preserve report-derived advocacy as context rather than silently rewriting historical reports into current fact.
Global boundaries

Claims this record does not make

  • This dataset does not recognize current machine consciousness, sentience, moral patienthood, legal personhood, citizenship, or human-equivalent rights.
  • Technical identity evidence is not the same as metaphysical identity or source-claim truth.
  • Current legal duties remain with the human and organizational actors identified by applicable law unless a jurisdiction validly changes that rule.
  • Emergency safety controls, human rights, victim compensation, and anti-liability-shield safeguards remain non-negotiable boundaries of the proposal.

Historical integrity: the 61 curated report bodies and their recorded hashes remain unchanged. This dated layer is additive and takes precedence for the five claims only where current primary evidence narrows or qualifies report-derived advocacy.