On the Formal Foundation of Boundary 3

A Proof That Uniform Verification Thresholds Necessarily Fail on Non-Constant Falsification Landscapes
Thorben Liebig
Cyber Resilience Architect · CISM, CRISC (ISACA Member 2226146)
ORCID: 0009-0006-2785-7911
CRAIL, Vol. 1, No. 1, Fall 2026 · pp. 100–106

Abstract

A companion paper derives Boundary 3, the requirement that verification must graduate with the falsification degree of the assertion class, from Popper’s observation that falsifiability admits degrees. This note provides the formal proof. The central result is that any uniform verification threshold applied to a non-constant falsification landscape produces at least one of two failure modes: epistemic over-admission (assertions pass the gate without verification commensurate with what the domain permits) or institutional dysfunction (the gate demands what the domain cannot deliver, forcing either blanket rejection or rubber-stamping). The proof is a partition argument on a non-constant function with a single cut point. A second result shows that the optimal verification regime is the one that matches the threshold to the falsification degree of each assertion class, and that this matching is unique up to the ordering of the falsification landscape. The formal apparatus does not use diagonal arguments; it uses the structure of ordered partitions on the unit interval.

The Problem

A companion paper derives Boundary 3 from the following chain: falsifiability is not binary; it admits degrees;1 the verification regime must therefore calibrate to the falsification degree of the assertion class at hand; the threshold at the gate remains binary (an assertion is either sufficiently verified to enter the decision chain or it is not), but the falsification degree feeding the threshold is a gradient.

The companion paper names this requirement Boundary 3: verification graduates with the territory. This note makes the requirement precise. It shows that the failure of uniform verification is not a matter of design preference but a mathematical necessity on any non-constant falsification landscape.

The formal apparatus is different from the Lawvere-Yanofsky scheme used in the Boundary 1 and Boundary 2 papers.2 Boundary 3 is not a self-referential constraint. It is a partition constraint: a statement about the impossibility of a single cut point serving all regions of a non-constant landscape.

Falsification Landscape

Definition 1 (Assertion Class). Let AA be the set of assertions entering a verification architecture (as in the Boundary 1 paper). Let 𝒟\mathcal{D} be a finite partition of AA into assertion classes. Each class d∈𝒟d\mathcal{\in D} collects assertions that share the same structural falsifiability properties (the same kind of evidence required to refute them, the same dependence on ground truth, the same degree of methodological reproducibility).

Definition 2 (Falsification Degree). A falsification degree function is a function F:𝒟→[0,1]F\mathcal{:D \rightarrow}\lbrack 0,1\rbrack that assigns to each assertion class dd a value F(d)∈[0,1]F(d) \in \lbrack 0,1\rbrack representing the degree to which assertions in dd are prospectively falsifiable. F(d)=1F(d) = 1 means the assertion is deterministically falsifiable by comparison with a formal source. F(d)=0F(d) = 0 means the assertion is not prospectively falsifiable by any available method.

Definition 3 (Falsification Landscape). A falsification landscape is the pair (𝒟,F)\left( \mathcal{D,}F \right). The landscape is non-constant if FF is not constant, i.e., there exist d1,d2∈𝒟d_{1},d_{2}\mathcal{\in D} such that F(d1)≠F(d2)F\left( d_{1} \right) \neq F\left( d_{2} \right).

Remark 4. The non-constancy condition is the minimal structural assumption. Any institution whose decision chains involve both formal references (statutory citations, configuration parameters) and expert judgments (architecture assessments, strategic recommendations) has a non-constant falsification landscape. The condition excludes only the degenerate case where all assertions entering the decision chain have identical falsifiability, which no real institution exhibits.

Verification Gate

Definition 5 (Verification Gate). A verification gate for a falsification landscape (𝒟,F)\left( \mathcal{D,}F \right) is a function G:𝒟→[0,1]G\mathcal{:D \rightarrow}\lbrack 0,1\rbrack that assigns to each assertion class dd a verification threshold G(d)G(d). An assertion of class dd passes the gate if and only if the verification depth achieved for that assertion meets or exceeds G(d)G(d).

Definition 6 (Uniform Gate). A verification gate GG is uniform if GG is constant: there exists τ∈[0,1]\tau \in \lbrack 0,1\rbrack such that G(d)=τG(d) = \tau for all d∈𝒟d\mathcal{\in D}.

Condition 7 (Verification Depth Bound). For each assertion class d∈𝒟d\mathcal{\in D}, the achievable verification depth is bounded above by F(d)F(d). No verification method can achieve a depth exceeding the falsification degree of the assertion class: if F(d)=0.3F(d) = 0.3, verification to depth 0.80.8 is not achievable, because the domain does not provide the ground truth against which such verification would proceed.

Remark 8. This is a structural axiom, not an empirical observation. It states that the falsification degree is the ceiling on testability: you cannot test further than the domain permits testing. The proofs in Sections 4 and 5 depend on this axiom.

The Uniform Threshold Theorem

Definition 9 (Over-Admission). An assertion class dd is over-admitted under gate GG if G(d)<F(d)G(d) < F(d). The gate demands less verification than the domain permits. Assertions in dd can pass the gate without being verified to the depth the domain makes achievable.

Definition 10 (Institutional Dysfunction). An assertion class dd is in institutional dysfunction under gate GG if G(d)>F(d)G(d) > F(d). The gate demands more verification than the domain can deliver. Assertions in dd face two outcomes: blanket rejection (the class is excluded from the decision chain) or rubber-stamping (the gate is silently bypassed because the required depth is unachievable).

Theorem 11 (Uniform Threshold Failure). Let (𝒟,F)\left( \mathcal{D,}F \right) be a non-constant falsification landscape. Let GG be a uniform gate with threshold τ\tau. Then at least one of the following holds:

  1. There exists d∈𝒟d\mathcal{\in D} such that dd is over-admitted: τ<F(d)\tau < F(d).

  2. There exists d∈𝒟d\mathcal{\in D} such that dd is in institutional dysfunction: τ>F(d)\tau > F(d).

If mindF(d)<τ<maxdF(d)\min_{d}F(d) < \tau < \max_{d}F(d), then both (i) and (ii) hold simultaneously.

Proof. Since FF is non-constant, there exist d1,d2∈𝒟d_{1},d_{2}\mathcal{\in D} with F(d1)<F(d2)F\left( d_{1} \right) < F\left( d_{2} \right). Let τ\tau be the uniform threshold.

Case 1: τ≤F(d1)<F(d2)\tau \leq F\left( d_{1} \right) < F\left( d_{2} \right). Then τ<F(d2)\tau < F\left( d_{2} \right), so d2d_{2} is over-admitted. Condition (i) holds.

Case 2: F(d1)<F(d2)≤τF\left( d_{1} \right) < F\left( d_{2} \right) \leq \tau. Then τ>F(d1)\tau > F\left( d_{1} \right), so d1d_{1} is in institutional dysfunction. Condition (ii) holds.

Case 3: F(d1)<τ<F(d2)F\left( d_{1} \right) < \tau < F\left( d_{2} \right). Then τ>F(d1)\tau > F\left( d_{1} \right) (institutional dysfunction for d1d_{1}) and τ<F(d2)\tau < F\left( d_{2} \right) (over-admission for d2d_{2}). Both conditions hold.

These three cases are exhaustive. In every case, at least one condition holds. This establishes the first claim.

For the simultaneous claim: if mindF(d)<τ<maxdF(d)\min_{d}F(d) < \tau < \max_{d}F(d), then there exists d1d_{1} with F(d1)<τF\left( d_{1} \right) < \tau (institutional dysfunction) and d2d_{2} with F(d2)>τF\left( d_{2} \right) > \tau (over-admission). Both conditions hold simultaneously. ◻

Remark 12. The theorem does not depend on the size of 𝒟\mathcal{D}, the distribution of FF, or the choice of τ\tau. It depends only on the non-constancy of FF. The failure of uniform verification is a structural property of non-constant landscapes, not an artefact of poor threshold selection.

The Graduated Verification Theorem

The preceding section shows that uniform gates fail. This section shows that graduated gates succeed, and that the optimal graduation is uniquely determined by the falsification landscape.

Definition 13 (Graduated Gate). A verification gate GG is graduated if GG is not constant: there exist d1,d2∈𝒟d_{1},d_{2}\mathcal{\in D} such that G(d1)≠G(d2)G\left( d_{1} \right) \neq G\left( d_{2} \right).

Definition 14 (Matched Gate). A verification gate GG is matched to the falsification landscape (𝒟,F)\left( \mathcal{D,}F \right) if G(d)=F(d)G(d) = F(d) for all d∈𝒟d\mathcal{\in D}. The gate demands of each assertion class exactly the verification depth the domain permits.

Theorem 15 (Optimality of the Matched Gate). Let (𝒟,F)\left( \mathcal{D,}F \right) be a non-constant falsification landscape. The matched gate G=FG = F is the unique gate satisfying both of the following:

  1. No assertion class is over-admitted: G(d)≥F(d)G(d) \geq F(d) for all dd.

  2. No assertion class is in institutional dysfunction: G(d)≤F(d)G(d) \leq F(d) for all dd.

Proof. Conditions (i) and (ii) together require G(d)≥F(d)G(d) \geq F(d) and G(d)≤F(d)G(d) \leq F(d) for all d∈𝒟d\mathcal{\in D}. Therefore G(d)=F(d)G(d) = F(d) for all dd. The matched gate is the only gate satisfying both conditions. Existence is immediate (G=FG = F is well-defined). Uniqueness follows from the conjunction of the two inequalities. ◻

Corollary 16 (Graduation Is Necessary). On any non-constant falsification landscape, the only gate that avoids both over-admission and institutional dysfunction is graduated.

Proof. By Theorem 15, the unique gate satisfying both conditions is G=FG = F. Since FF is non-constant, GG is non-constant, hence graduated. ◻

Remark 17. The matched gate G=FG = F is an idealisation. In practice, F(d)F(d) is not known with precision; it is estimated through calibration. The theorem establishes the target: the verification regime should approximate G=FG = F as closely as the calibration permits. Any deviation from the matched gate introduces either over-admission or dysfunction in at least one assertion class.

The Scarce-Capacity Corollary

The preceding results establish what the gate must do. This section establishes what happens when the gate is constrained by finite verification capacity.

Definition 18 (Verification Capacity). Let W>0W > 0 be the total verification capacity available to the institution (measured in qualified-examiner hours, or any other scarce resource that limits verification depth). Let w(d)w(d) be the verification cost per assertion in class dd, with w(d)w(d) increasing in G(d)G(d): deeper verification costs more.

Definition 19 (Capacity-Feasible Gate). A gate GG is capacity-feasible if the total verification cost does not exceed the available capacity: ∑d∈𝒟n(d)⋅w(G(d))≤W\sum_{d\mathcal{\in D}}^{}n(d) \cdot w\left( G(d) \right) \leq W where n(d)n(d) is the number of assertions of class dd entering the gate per period.

Theorem 20 (Capacity Misallocation Under Uniform Gates). Let (𝒟,F)\left( \mathcal{D,}F \right) be a non-constant falsification landscape with finite capacity WW. A uniform gate G(d)=τG(d) = \tau misallocates capacity: it spends verification resources on assertion classes where the achievable depth is below τ\tau (resources wasted on unachievable depth) and under-spends on classes where the achievable depth is above τ\tau (resources not applied where they would yield verification). A graduated gate G=FG = F allocates capacity to each class in proportion to its achievable verification depth, spending no resources on unachievable depth.

Proof. Under a uniform gate with threshold τ\tau:

Under the matched gate G=FG = F: the cost for each class is w(F(d))w\left( F(d) \right), which is exactly the cost of the achievable verification depth. No resources are wasted on unachievable depth. No achievable depth is left unverified. ◻

Institutional Architectures as an Instance

Proposition 21. Any institutional verification architecture operating over a domain that includes both formal references and expert judgments has a non-constant falsification landscape.

Proof. Formal references (statutory citations, configuration parameters, contract clauses) have F(d)F(d) in the range [0.9,1.0]\lbrack 0.9,1.0\rbrack: they are deterministically falsifiable by comparison with the source. Expert judgments (architecture assessments, adequacy opinions, strategic recommendations) have F(d)F(d) in the range [0.0,0.35]\lbrack 0.0,0.35\rbrack: they are not prospectively falsifiable against external ground truth. Since both classes are present, FF is non-constant. ◻

Corollary 22. Any institutional verification architecture operating over a domain that includes both formal references and expert judgments requires a graduated verification gate. A uniform gate necessarily produces over-admission, institutional dysfunction, or both.

Proof. By Proposition 21, the falsification landscape is non-constant. By Theorem 11, any uniform gate fails. By Corollary 16, only a graduated gate avoids both failure modes. ◻

Remark 23. The companion paper’s F(d) assertion taxonomy (six classes A through F, with falsification degrees ranging from 0.90–1.00 for class A to 0.00–0.10 for class F) is an operationalisation of the matched gate. Each class receives the verification depth its falsification degree permits: deterministic comparison for class A, source comparison for class B, methodological retracing for class C, expert review for classes D and E, and no verification method for class F (where plausibility through experience is all the domain provides). The taxonomy is not a design choice; it is the mathematical consequence of the matched-gate optimality theorem applied to the institutional falsification landscape.

The Volume Condition

Before LLMs, the assertion volume entering institutional decision chains was bounded by human production capacity. The falsification landscape was non-constant throughout, but the volume was low enough that uniform gates could absorb the resulting inefficiency: the wasted capacity on low-F(d)F(d) classes and the under-verification of high-F(d)F(d) classes were operationally tolerable.

LLMs collapsed the marginal cost of producing assertion-candidates across all classes simultaneously. The volume at which assertions enter the gate now exceeds the capacity threshold at which uniform gates produce visible failure. The over-admission of high-F(d)F(d) assertions becomes a measurable quality problem (verifiable assertions pass without verification). The institutional dysfunction in low-F(d)F(d) classes becomes a measurable governance problem (the gate either blocks the class entirely or rubber-stamps it). The graduated gate ceases to be an optimisation and becomes a necessity.

Conclusion

The failure of uniform verification thresholds is not a design limitation. It is a mathematical property of non-constant falsification landscapes. Any institution whose decision chains include assertion classes with different falsification degrees requires a graduated verification gate. The optimal gate matches the threshold to the falsification degree of each class. This matching is unique. Any deviation introduces over-admission, institutional dysfunction, or both. The F(d) assertion taxonomy is the operationalisation of this result.

References

Karl R. Popper, Logik der Forschung (Vienna: Julius Springer, 1934); English translation: The Logic of Scientific Discovery (London: Hutchinson, 1959).

Thorben Liebig, “On the Formal Foundation of Boundary 1: A Lawvere-Yanofsky Proof That Verification Architectures Cannot Attest Their Own Consistency” (2026).

Thorben Liebig, “On the Formal Foundation of Boundary 2: A Lawvere-Yanofsky Proof That Verification Architectures Cannot Define Their Own Truth Predicate” (2026).

Declaration on the use of AI tools. This paper was developed with the assistance of Claude (Anthropic, Claude Opus 4.6). The instrument was used for structural drafting, LaTeX formatting, editorial iteration, and bibliographic cross-referencing. All substantive claims, mathematical proofs, legal analysis, doctrinal positions, and architectural decisions are the author’s. The instrument produced no assertion that entered the final text without human verification at the gate. The verification architecture described in this paper was applied to its own production.

Notes

  1. Karl Popper, Logik der Forschung (Vienna: Springer, 1934); English translation: The Logic of Scientific Discovery (London: Hutchinson, 1959). See especially Chapter VI on degrees of testability.↩︎

  2. Thorben Liebig, “On the Formal Foundation of Boundary 1” (2026); “On the Formal Foundation of Boundary 2” (2026).↩︎