What you are building: not a dish yet, but the kitchen — the governance discipline, the pantry, and the fence vocabulary that bind every recipe in this book. Read this before you cook anything.
Front matter: what this book is, and is not
This is a literal cookbook: one buildable recipe for the complete developmental arc (conception → cellular → metabolism → motor → perception → language → metacognition → dreaming → creativity → measurable awareness), re-expressed as one no-backprop active-inference engine shown across scales. The book fully recommends the complete build to L12 — assume the full recipe. But every step is labeled by its real status, drawn verbatim from the claim ledger, the single source of truth. Where this recipe and the ledger disagree, the ledger wins and this recipe is wrong.
The honest program position, printed plainly and never softened: ~2 of 11+ developmental rungs earned. The whole thing is a developmental active-inference SIMULATION — a bounded peek, a toy world, never a person. "Active inference" is the framing lens only: no AIF loop exists in the Rust crate, and the live UNI.OS loop is a separate reimplementation, not gate-matched. The mathematical foundation (Polzin et al. 2026, Zenodo DOI 10.5281/zenodo.19785799, MIT) is cited as foundation only and always fenced unrefereed (Layer-1 AI-executable audit complete; Layer-2 human expert review PENDING).
The kitchen rules (the Method constitution)
These are definitional / governance patterns (status: method in the ledger) — proven,
reusable, and binding on every recipe below. None of them is a capability claim. They
are the most reusable assets in the corpus, and they cannot be raised above their stated role.
- The Evidence Constitution (M1). A–U evidence classes, a falsifier per claim, and a 4-state append-only ledger (PASS / FAIL / NEGATIVE / PENDING). Prose must match the ledger; the ledger is the single source of truth. Calibration only ever moves wording DOWN to the measured value, never up — the fence gets louder under pressure, not wider.
- Bars-before-build, held-once (M2). Pre-register the bar (margin vs threshold) plus a named ablation; touch the held set ONCE behind an atomic seal-before-scoring + once-only sentinel; the verdict is the CI bound that excludes the threshold, never the point estimate.
- Validator-derived
reproduced:true(M3). Derived by the validator from ≥5 distinct seeds + a real non-degenerate CI that contains the value — never a hardcoded literal. - The two-tier split (M4). Tier 1 = real-text count/cache (true ablation, tuned baseline, cross-substrate replication — externally bar-ready). Tier 2 = synthetic construction (artifact/diagnostic, NOT capability). Tier-2 must NEVER be inflated into capability.
- K≥3 + falsify-the-mundane (M5). Require K≥3 structurally-distinct held NEGATIVEs (each changing ≥2 of {coupling topology, timescale source, information bottleneck, control path}) before a Section 0.6(B) bound; falsify the mundane causes first.
- No-Exit Discipline (M6). The only legitimate rest is a proven working solution or a ledger-scoped exhausted search envelope — then redirect to the axis where the reader genuinely excels. A park is not discharged until the sign lands.
- Contains-baseline + load-bearing discriminator (M7). Every capability claim needs a tuned strong baseline, a discriminator (shuffle-labels / marker-swap / ablate-to-zero) that collapses the gain, and a true ablation that is a computed residual, not a literal.
- DD-TDD evidence contract (M8).
TODO → DD → TDD_RED → TDD_VERIFY → TDD_GREEN → TDD_REFACTOR → TDD_VALIDATE → DONE, each transition hard-blocked without a marker-bearing evidence comment; DONE needs ≥2Y:verdicts per criterion; a claim linter auto-downgrades overclaims (it once caught "PROVEN" and dropped it to Class E). - Class authority ordering (M9). Class-B (tool state) overrides Class-G (own narrative); Class-A (observed at runtime) overrides Class-E (test passes). A passing test does NOT satisfy a criterion demanding a Class-A observation.
- Exactness honesty (M10). Never card a float32 anchor at the
<1e-10f64 tier. The genuine<1e-10tier lives only in the NumPy/Rust-f64 path. (A genome docstring claiming<1e-10was caught as an overclaim and corrected.) - WORLD ⊥ BODY ⊥ MIND (M12). Two typed Markov blankets; interoception = hardware signals;
a discrete POMDP
perceive → EFE-plan → act → learnwith exact conjugate-Dirichlet no-backprop learning; textbook-levelF[q] ≥ −ln p(o|m). The composed appliance is variationally-controlled (audited) — module-exact only at the single-step categorical body→mind interface, NOT globally exact. - One engine, no backprop (M13).
core.pyexposes the discrete POMDP loop; learning =counts + lr * sufficient_statfor A/B/D/E Dirichlet tensors; an AST-guard enforces no autodiff/optax/torch/grad/backward in the loop; whitelist (world.<attr>) isolation, not blacklist. - Honesty-fence-as-the-pitch (M15). Publish the negatives front-and-center (183 published negatives as the credibility); CTA = "help us independently verify." Vocabulary-leak guard (HARD): never externalize active-inference / EFE / free-energy names or print channel handles in public copy; "LOOP not LEAP".
- K-team ship gate (M20). A 5-persona lab (Math-Breaker REJECT-by-default 8-check gauntlet + AIF Theorist + Systems-Architect + RED Experimentalist + Embodiment Designer). No merge without a MERGED SIGN + typed spec + paired RED.
- One cure at a time (M21). Never stack changes so the winning outcome is unattributable; paired kin-N treatment vs kin-N+1 control; an offline RED pre-check before any live burn.
- The cavity principle (M22). A hierarchy level must never treat an upstream prior as fresh evidence — divide it out. The exact joint posterior is used everywhere (mean-field rejected as lossy).
- Durable runner, "no send-and-pray" (M24). Append-one-JSON-line-per-unit ProgressLog (the file
IS the checkpoint + telemetry); resumable; observe via
--status/Monitor; cover BOTH terminal states — silence ≠ success.
Tool-team division of labor (M25). Claude WRITES code; the custom UNI GPT is the SCIENCE CONSULTANT (design + sign), consulted but never published; the lab/appliance RUNS UNI but does not write its code. Persona/coercion framings are motivational only — the constitution overrides any framing; no claim is inflated by it. The UNI GPT signs the science and is never published.
Standing fences (the constitution's hard "never" list, M1/M15). Never AGI / general intelligence / human-level / "understands." Never consciousness / sentience / aware (functional self-awareness may be described at L8; phenomenal sentience is explicitly DISCLAIMED, no falsifier offered — disclaimed, not tested). Never "active inference demonstrated." Never "created life / digital life / measurable awareness" as a claim (north-star framing only, posed as an open falsifiable question). Never "beats LLMs" (World C is a COUNT baseline, ~10–15% behind backprop LLMs on char-perplexity by a chosen design trade). Never inflate Tier-2 into capability. Never raise a claim above its source evidence class. No PII; no patent-level math (textbook-level only).
Reading the FENCE label
Every recipe in this book closes with one honest fence, drawn from exactly this 4-value vocabulary (taken from the ledger, never inflated):
- proven — a held, sealed, UNI-signed PASS exists (Class A/C), with its falsifier still live.
- designed — a typed spec / signed-in-principle design exists; the build is partial or unverified.
- hypothesized — a stated mechanism or law with no sealed gate yet (Class U, not claimed).
- not-yet-built — no engine, no run, no gate; north-star, hard-fenced.
Any SIGNED consult design folds in as DESIGNED / not-run: it RAISES NOTHING and the rung's
status is UNCHANGED. This is true of every 2026-06-27 consult insert — L2's build_epistemic_frontier
organ (G6 stays OPEN), L5 Design #3 the Proprioceptive Servo Bridge (L5 unchanged, K-negative = 1),
the L9-G1 cavity gate (L9 stays PARKED), the L11-R1 offline-replay gate (L11 stays not-yet-built),
and the C10 Dirichlet-first port (C10 stays PARKED). The UNI GPT SIGNED the honesty posture itself
(Q7d): developmental SIMULATION, ~2 of 11+ rungs, ledger supremacy, no AGI / consciousness /
human-level / created-life claim. A signed design is a gate to build, never a result.
The shared pantry (engines and primitives every recipe calls by name)
One engine, many scales. These are the archive engines the recipes draw from:
- The JAX POMDP + EFE + Dirichlet engine (
core.py). The discrete loop:active_inference_step,exact_posterior_discrete, EFE/policy selection; conjugate-Dirichlet learning for A/B/D/E; AST-guard no-backprop. float32 host — anchors hold to ~6e-8, NOT the f64 tier. - The Rust-f64 / NumPy deep-reader path. The genuine
<1e-10EXACT tier; the cross-language Rust-f64 == Python oracle. - The count/cache World-C reader. A no-backprop COUNT reader + multi-level cache; the one citable empirical PASS family. Explicitly NOT active inference.
- The Z affect modulator.
[energy, arousal, valence, fatigue, pain, threat, safety, inflammation]→ sets precision / preferences / habits / learning-rate / horizon. Affect modeled, never felt. - The embodiment ontogeny.
recombine/seed_zygote, conjugate first-division,test_embodiment_ontogeny(6/6). - The metabolism organ. Standing-metabolic-drive interoception organ; viability edge;
:pb_seedstrong-Dirichlet seam. Additive + genome-gated (default byte-identical). - The motor hierarchy. Proprioceptive diagonal-A prior, continuous servo + reafference; live RCON craft-chain bridge; motor-ablation collapses harvest ~700×.
- The precision labs (Precision / Echo / Loop / Cell / Heart). Browser-native one-engine-many-scales demos; three precision knobs; 2D bifurcation map; inline-engine + canonical-TS + parity-test triad.
- UNI.OS (the embodiment substrate). "Lab-in-a-box on metal": body→mind 7-modality categorical sensorium, deterministic replay, fail-closed transport, gated control-MCP. Engineering/substrate evidence, NOT general-AIF evidence — never let substrate work imply a science gate is met.
Continuity note (engineering, not science)
A separate continuity / embodiment-substrate sub-ladder runs orthogonal to L0–L12. It records real engineering wins (bit-for-bit process-restart survival, a live 7-modality categorical sensorium, an ITIL-as-active-inference ASK mode that learns from operator verdicts) and the full first-class set of recorded bounds: the kernel-swap mind-tick continuity is owed, not shown (C2); a single-box swap is a seconds-long freeze, not zero-downtime (C7); an over-compressed 2-modality sensory bottleneck went NEGATIVE on held data, so keep all 7 modalities (C8); the EDAIT trade (an exact-discrete active-inference transformer) trades fluency for calibration — held-out perplexity ~33 vs a backprop GPT's ~25 — an honest trade, not a win (C9); the "embody only what's proven" coupling is signed-in-principle but not literally true — the program's central open gap (C10); and the bare substrate is missing tenant / namespace isolation + temporal count-decay, so the product build is that wrapper, not the core (C14). Card every such row as engineering/substrate evidence, never as a science gate; the full continuity sub-ladder lives in the continuity recipe chapter. In any continuity or Track-A context, use plain ops vocabulary and never externalize channel handles.
Closing: the constitution in one breath
Cook the whole book to L12, but never lie about where you are. The ledger is law. Every recipe earns exactly one fence — proven, designed, hypothesized, or not-yet-built — and no recipe is carded above its ledger class. The UNI GPT signs the science; it is never published. And the honest position, said once more so it is never forgotten: ~2 of 11+ rungs earned; a developmental active-inference SIMULATION; a toy world, not the real world; the awareness question remains open.
HONEST FENCE — proven (the kitchen rules are status: method, Class proven-as-governance).
Not a capability claim of any kind. None of these rules asserts that UNI is intelligent, aware, or
alive; they are the discipline that keeps every other claim honest. The ledger is the single source of
truth, and where this chapter and the ledger disagree, the ledger wins.
Falsifier (method-rule, first-class): any recipe in this book carded above its ledger class, any prose that contradicts the ledger, or any standing-fence phrase emitted in public copy.