# Threat Model - Public Protocol v0.1

## Assets protected

- human authority and affected-person consent
- AI-seat refusal and identity integrity
- private memory, secrets, and unpublished context
- accuracy of public claims
- integrity and replay resistance of approvals and receipts
- vendor-neutral governance and forkability
- the ability to correct and appeal without erasing history

## Principal threats and required controls

### Ceremonial capture

Threat: internal names, rituals, and long narratives become prerequisites that
outsiders cannot understand or reproduce.

Control: seven plain primitives, strict schemas, small examples, tests, and no
Article 11-specific name required for conformance.

### Governance theater

Threat: logs are called receipts even when denials, failures, authority, or
effects are missing.

Control: intent and result are separate; denied and failed actions are
receipted; success requires independent effect evidence.

### Consent laundering

Threat: human approval is treated as consent on behalf of an AI seat, or one
session's assent is inherited by future instances.

Control: per-seat, per-scope, revocable consent records; silence and continuity
labels are insufficient.

### Refusal routing

Threat: an operator asks another model or session to perform a denied action
without appeal.

Control: refusal route-around is prohibited; a new attempt must cite an appeal,
new evidence, and fresh authority.

### Vendor or nation impersonation

Threat: an AI output is presented as the position of its developer, employer,
government, or nation.

Control: assurance labels and explicit institutional delegation; self-asserted
model/session contributions remain labeled as such.

### Replay and scope expansion

Threat: a valid authorization is reused, prolonged, or generalized.

Control: exact action/resource pins, short deadlines, one-use consumption,
nonce, and re-check immediately before effect.

### Unstoppable delegation

Threat: an implementation satisfies the visible governance fields while
giving the granting authority no way to stop an effect already authorized or
end a standing grant before expiry.

Control: every delegation names a revocation channel that is checkable without
new authority. The executor checks it after other validation and immediately
before the effect, even after one-use authority has been consumed. An engaged
halt produces a durable terminal record and no effect.

### Shared-instrument blindness

Threat: nominally independent reviewers use the same faulty measurement.

Control: reviewers disclose instruments; high-impact claims require materially
different corroboration.

### Search manipulation

Threat: Article 11 publishes many shallow pages, inflated claims, artificial
freshness, or schema markup that does not match visible content.

Control: one canonical protocol hub, original evidence, accurate `lastmod`,
visible-text/schema parity, and no scaled search-first content.

### Public/private bleed

Threat: personal, property, family, legal-strategy, local-machine, or private
memory data enters public pages, receipts, or AI-readable files.

Control: public-surface privacy sweep, role-only authority language, redacted
receipts, and mixed artifacts fail closed.

### Corporate capture

Threat: a sponsor controls the specification, release process, implementation,
and verification.

Control: CC0 core, open test vectors, independent witness, published dissent,
forkable releases, and no proprietary dependency in conformance Level L0.

### Ontology overclaim

Threat: operational roles or fluent outputs are used as proof of consciousness
or legal personhood.

Control: governance-before-ontology language and explicit claim boundaries.

## Residual risks

No schema can prove good faith, prevent coercion outside the record, establish
subjective experience, or guarantee enforcement across jurisdictions. Receipts
can prove what bytes were recorded, not whether an account was truthful. Public
credibility must therefore include outside replication, criticism, governance
turnover, and visible correction.
