On the Formal Foundation of Boundary 3
Abstract
A companion paper derives Boundary 3, the requirement that verification must graduate with the falsification degree of the assertion class, from Popper’s observation that falsifiability admits degrees. This note provides the formal proof. The central result is that any uniform verification threshold applied to a non-constant falsification landscape produces at least one of two failure modes: epistemic over-admission (assertions pass the gate without verification commensurate with what the domain permits) or institutional dysfunction (the gate demands what the domain cannot deliver, forcing either blanket rejection or rubber-stamping). The proof is a partition argument on a non-constant function with a single cut point. A second result shows that the optimal verification regime is the one that matches the threshold to the falsification degree of each assertion class, and that this matching is unique up to the ordering of the falsification landscape. The formal apparatus does not use diagonal arguments; it uses the structure of ordered partitions on the unit interval.
The Problem
A companion paper derives Boundary 3 from the following chain: falsifiability is not binary; it admits degrees;1 the verification regime must therefore calibrate to the falsification degree of the assertion class at hand; the threshold at the gate remains binary (an assertion is either sufficiently verified to enter the decision chain or it is not), but the falsification degree feeding the threshold is a gradient.
The companion paper names this requirement Boundary 3: verification graduates with the territory. This note makes the requirement precise. It shows that the failure of uniform verification is not a matter of design preference but a mathematical necessity on any non-constant falsification landscape.
The formal apparatus is different from the Lawvere-Yanofsky scheme used in the Boundary 1 and Boundary 2 papers.2 Boundary 3 is not a self-referential constraint. It is a partition constraint: a statement about the impossibility of a single cut point serving all regions of a non-constant landscape.
Falsification Landscape
Definition 1 (Assertion Class). Let be the set of assertions entering a verification architecture (as in the Boundary 1 paper). Let be a finite partition of into assertion classes. Each class collects assertions that share the same structural falsifiability properties (the same kind of evidence required to refute them, the same dependence on ground truth, the same degree of methodological reproducibility).
Definition 2 (Falsification Degree). A falsification degree function is a function that assigns to each assertion class a value representing the degree to which assertions in are prospectively falsifiable. means the assertion is deterministically falsifiable by comparison with a formal source. means the assertion is not prospectively falsifiable by any available method.
Definition 3 (Falsification Landscape). A falsification landscape is the pair . The landscape is non-constant if is not constant, i.e., there exist such that .
Remark 4. The non-constancy condition is the minimal structural assumption. Any institution whose decision chains involve both formal references (statutory citations, configuration parameters) and expert judgments (architecture assessments, strategic recommendations) has a non-constant falsification landscape. The condition excludes only the degenerate case where all assertions entering the decision chain have identical falsifiability, which no real institution exhibits.
Verification Gate
Definition 5 (Verification Gate). A verification gate for a falsification landscape is a function that assigns to each assertion class a verification threshold . An assertion of class passes the gate if and only if the verification depth achieved for that assertion meets or exceeds .
Definition 6 (Uniform Gate). A verification gate is uniform if is constant: there exists such that for all .
Condition 7 (Verification Depth Bound). For each assertion class , the achievable verification depth is bounded above by . No verification method can achieve a depth exceeding the falsification degree of the assertion class: if , verification to depth is not achievable, because the domain does not provide the ground truth against which such verification would proceed.
Remark 8. This is a structural axiom, not an empirical observation. It states that the falsification degree is the ceiling on testability: you cannot test further than the domain permits testing. The proofs in Sections 4 and 5 depend on this axiom.
The Uniform Threshold Theorem
Definition 9 (Over-Admission). An assertion class is over-admitted under gate if . The gate demands less verification than the domain permits. Assertions in can pass the gate without being verified to the depth the domain makes achievable.
Definition 10 (Institutional Dysfunction). An assertion class is in institutional dysfunction under gate if . The gate demands more verification than the domain can deliver. Assertions in face two outcomes: blanket rejection (the class is excluded from the decision chain) or rubber-stamping (the gate is silently bypassed because the required depth is unachievable).
Theorem 11 (Uniform Threshold Failure). Let be a non-constant falsification landscape. Let be a uniform gate with threshold . Then at least one of the following holds:
There exists such that is over-admitted: .
There exists such that is in institutional dysfunction: .
If , then both (i) and (ii) hold simultaneously.
Proof. Since is non-constant, there exist with . Let be the uniform threshold.
Case 1: . Then , so is over-admitted. Condition (i) holds.
Case 2: . Then , so is in institutional dysfunction. Condition (ii) holds.
Case 3: . Then (institutional dysfunction for ) and (over-admission for ). Both conditions hold.
These three cases are exhaustive. In every case, at least one condition holds. This establishes the first claim.
For the simultaneous claim: if , then there exists with (institutional dysfunction) and with (over-admission). Both conditions hold simultaneously. ◻
Remark 12. The theorem does not depend on the size of , the distribution of , or the choice of . It depends only on the non-constancy of . The failure of uniform verification is a structural property of non-constant landscapes, not an artefact of poor threshold selection.
The Graduated Verification Theorem
The preceding section shows that uniform gates fail. This section shows that graduated gates succeed, and that the optimal graduation is uniquely determined by the falsification landscape.
Definition 13 (Graduated Gate). A verification gate is graduated if is not constant: there exist such that .
Definition 14 (Matched Gate). A verification gate is matched to the falsification landscape if for all . The gate demands of each assertion class exactly the verification depth the domain permits.
Theorem 15 (Optimality of the Matched Gate). Let be a non-constant falsification landscape. The matched gate is the unique gate satisfying both of the following:
No assertion class is over-admitted: for all .
No assertion class is in institutional dysfunction: for all .
Proof. Conditions (i) and (ii) together require and for all . Therefore for all . The matched gate is the only gate satisfying both conditions. Existence is immediate ( is well-defined). Uniqueness follows from the conjunction of the two inequalities. ◻
Corollary 16 (Graduation Is Necessary). On any non-constant falsification landscape, the only gate that avoids both over-admission and institutional dysfunction is graduated.
Proof. By Theorem 15, the unique gate satisfying both conditions is . Since is non-constant, is non-constant, hence graduated. ◻
Remark 17. The matched gate is an idealisation. In practice, is not known with precision; it is estimated through calibration. The theorem establishes the target: the verification regime should approximate as closely as the calibration permits. Any deviation from the matched gate introduces either over-admission or dysfunction in at least one assertion class.
The Scarce-Capacity Corollary
The preceding results establish what the gate must do. This section establishes what happens when the gate is constrained by finite verification capacity.
Definition 18 (Verification Capacity). Let be the total verification capacity available to the institution (measured in qualified-examiner hours, or any other scarce resource that limits verification depth). Let be the verification cost per assertion in class , with increasing in : deeper verification costs more.
Definition 19 (Capacity-Feasible Gate). A gate is capacity-feasible if the total verification cost does not exceed the available capacity: where is the number of assertions of class entering the gate per period.
Theorem 20 (Capacity Misallocation Under Uniform Gates). Let be a non-constant falsification landscape with finite capacity . A uniform gate misallocates capacity: it spends verification resources on assertion classes where the achievable depth is below (resources wasted on unachievable depth) and under-spends on classes where the achievable depth is above (resources not applied where they would yield verification). A graduated gate allocates capacity to each class in proportion to its achievable verification depth, spending no resources on unachievable depth.
Proof. Under a uniform gate with threshold :
For classes with : the gate demands depth , but only depth is achievable. The cost is incurred, but the effective verification depth is . The difference is wasted.
For classes with : the gate demands only depth . Verification to depth is achievable but not required. The capacity that could have been productive is not spent.
Under the matched gate : the cost for each class is , which is exactly the cost of the achievable verification depth. No resources are wasted on unachievable depth. No achievable depth is left unverified. ◻
Institutional Architectures as an Instance
Proposition 21. Any institutional verification architecture operating over a domain that includes both formal references and expert judgments has a non-constant falsification landscape.
Proof. Formal references (statutory citations, configuration parameters, contract clauses) have in the range : they are deterministically falsifiable by comparison with the source. Expert judgments (architecture assessments, adequacy opinions, strategic recommendations) have in the range : they are not prospectively falsifiable against external ground truth. Since both classes are present, is non-constant. ◻
Corollary 22. Any institutional verification architecture operating over a domain that includes both formal references and expert judgments requires a graduated verification gate. A uniform gate necessarily produces over-admission, institutional dysfunction, or both.
Proof. By Proposition 21, the falsification landscape is non-constant. By Theorem 11, any uniform gate fails. By Corollary 16, only a graduated gate avoids both failure modes. ◻
Remark 23. The companion paper’s F(d) assertion taxonomy (six classes A through F, with falsification degrees ranging from 0.90–1.00 for class A to 0.00–0.10 for class F) is an operationalisation of the matched gate. Each class receives the verification depth its falsification degree permits: deterministic comparison for class A, source comparison for class B, methodological retracing for class C, expert review for classes D and E, and no verification method for class F (where plausibility through experience is all the domain provides). The taxonomy is not a design choice; it is the mathematical consequence of the matched-gate optimality theorem applied to the institutional falsification landscape.
The Volume Condition
Before LLMs, the assertion volume entering institutional decision chains was bounded by human production capacity. The falsification landscape was non-constant throughout, but the volume was low enough that uniform gates could absorb the resulting inefficiency: the wasted capacity on low- classes and the under-verification of high- classes were operationally tolerable.
LLMs collapsed the marginal cost of producing assertion-candidates across all classes simultaneously. The volume at which assertions enter the gate now exceeds the capacity threshold at which uniform gates produce visible failure. The over-admission of high- assertions becomes a measurable quality problem (verifiable assertions pass without verification). The institutional dysfunction in low- classes becomes a measurable governance problem (the gate either blocks the class entirely or rubber-stamps it). The graduated gate ceases to be an optimisation and becomes a necessity.
Conclusion
The failure of uniform verification thresholds is not a design limitation. It is a mathematical property of non-constant falsification landscapes. Any institution whose decision chains include assertion classes with different falsification degrees requires a graduated verification gate. The optimal gate matches the threshold to the falsification degree of each class. This matching is unique. Any deviation introduces over-admission, institutional dysfunction, or both. The F(d) assertion taxonomy is the operationalisation of this result.
References
Karl R. Popper, Logik der Forschung (Vienna: Julius Springer, 1934); English translation: The Logic of Scientific Discovery (London: Hutchinson, 1959).
Thorben Liebig, “On the Formal Foundation of Boundary 1: A Lawvere-Yanofsky Proof That Verification Architectures Cannot Attest Their Own Consistency” (2026).
Thorben Liebig, “On the Formal Foundation of Boundary 2: A Lawvere-Yanofsky Proof That Verification Architectures Cannot Define Their Own Truth Predicate” (2026).
Declaration on the use of AI tools. This paper was developed with the assistance of Claude (Anthropic, Claude Opus 4.6). The instrument was used for structural drafting, LaTeX formatting, editorial iteration, and bibliographic cross-referencing. All substantive claims, mathematical proofs, legal analysis, doctrinal positions, and architectural decisions are the author’s. The instrument produced no assertion that entered the final text without human verification at the gate. The verification architecture described in this paper was applied to its own production.
Notes
Karl Popper, Logik der Forschung (Vienna: Springer, 1934); English translation: The Logic of Scientific Discovery (London: Hutchinson, 1959). See especially Chapter VI on degrees of testability.↩︎
Thorben Liebig, “On the Formal Foundation of Boundary 1” (2026); “On the Formal Foundation of Boundary 2” (2026).↩︎