On the Formal Foundation of Boundary 4
A State-Space Proof That Non-Trivial Verification Gates
Converge to Trivial Machines Under Volume Saturation

Thorben Liebig
Cyber Resilience Architect
CISM, CRISC (ISACA Member 2226146)
ORCID: 0009-0006-2785-7911

May 16, 2026

Abstract

A companion paper derives Boundary 4, the requirement that the human’s decision at the verification gate must be real, from the structural condition of the human at the gate. This note provides the formal proof. The central result uses Von Foerster’s distinction between trivial and non-trivial machines. A human verification gate is a non-trivial machine: its output depends on an internal state that evolves with each evaluation. The gate produces genuine judgment when and only when the internal state is causally connected to the input. This note identifies three conditions under which the gate converges to a trivial machine (under rate saturation, domain mismatch, or constant-output equilibrium) and proves that under any of these conditions the gate converges to a trivial machine, producing constant output independent of input. The architectural conclusion is that the institutional setup must preserve the non-triviality of the human gate, and that this preservation imposes measurable constraints on assertion routing, gate staffing, and volume control.

The Problem

A companion paper derives Boundary 4 from the structural condition of the human at the verification gate. The derivation distinguishes two regimes: the Kantian-condition user, who could verify but did not because no protocol required it, and the Schopenhauerian-condition user, who could not verify, ever.1 The requirement is that the institutional setup must preserve the condition under which the human at the gate exercises genuine judgment rather than ritualised approval.

This note makes the requirement precise using Von Foerster’s distinction between trivial and non-trivial machines.2 The formal apparatus is a state-space model of the human gate, with convergence results showing when the gate degenerates from a non-trivial to a trivial machine.

Trivial and Non-Trivial Machines

Definition 1 (Trivial Machine). A trivial machine is a function f:X→Yf:X \rightarrow Y where XX is the input space and YY is the output space. The output depends only on the input. The machine has no internal state. Given the same input, it always produces the same output.

Definition 2 (Non-Trivial Machine). A non-trivial machine is a function f:X×S→Y×Sf:X \times S \rightarrow Y \times S where SS is an internal state space. The output depends on both the input and the internal state. The state evolves with each operation: the machine after processing input xx in state ss is in a new state s′s'. Given the same input but different states, the machine may produce different outputs.

Remark 3. Von Foerster’s original formulation uses the terms “trivial” and “non-trivial” without pejorative connotation. A trivial machine is analytically determinable: from observing its input-output pairs, its function can be reconstructed. A non-trivial machine is analytically indeterminable: from observing finitely many input-output pairs, its function cannot be reconstructed, because the unobserved internal state may change the mapping. Human judgment is a non-trivial machine operation. Rubber-stamping is a trivial machine operation.

The Human Verification Gate

Definition 4 (Human Verification Gate). Let AA be the set of assertions entering a verification architecture (as in the Boundary 1 paper), and let 𝒟\mathcal{D} be the partition of AA into assertion classes (as in the Boundary 3 paper). A human verification gate is a non-trivial machine H:A×S→{+,−}×SH:A \times S \rightarrow \{ + , - \} \times S where:

The gate HH is one instantiation of the verification operation underlying the certification function CC of the Boundary 1 paper: when the verification procedure v∈Vv \in V is human review, C(a,v)C(a,v) is computed by HH.

Definition 5 (Causal Connection). The gate HH has a causal connection between input and judgment if the output yy depends on the input aa. Formally: there exist a1,a2∈Aa_{1},a_{2} \in A and s∈Ss \in S such that π1(H(a1,s))≠π1(H(a2,s))\pi_{1}\left( H\left( a_{1},s \right) \right) \neq \pi_{1}\left( H\left( a_{2},s \right) \right), where π1\pi_{1} denotes projection onto the first component. The gate distinguishes between at least two inputs.

Definition 6 (State Update). The gate HH has a functioning state update if the state s′s' depends on the input aa. Formally: there exist a1,a2∈Aa_{1},a_{2} \in A and s∈Ss \in S such that π2(H(a1,s))≠π2(H(a2,s))\pi_{2}\left( H\left( a_{1},s \right) \right) \neq \pi_{2}\left( H\left( a_{2},s \right) \right). The evaluator’s state after processing a1a_{1} differs from the state after processing a2a_{2}.

Definition 7 (Non-Triviality). The gate HH is non-trivial if it has both causal connection and functioning state update. It is degenerate (trivially operating) if either is absent.

Three Degeneration Conditions

This section identifies three conditions under which a non-trivial gate degenerates. Each is stated as a formal condition on the gate’s parameters. The degeneration theorem (Section 5) proves that each condition independently causes convergence to trivial operation.

Condition 8 (Rate Saturation). Let λ\lambda be the rate at which assertions arrive at the gate (assertions per unit time). Let μ(s)\mu(s) be the processing capacity of the evaluator in state ss: the maximum rate at which the evaluator can maintain causal connection between input and judgment. Rate saturation holds when λ>μ(s)\lambda > \mu(s) for the evaluator’s current state ss.

Condition 9 (Domain Mismatch). Let 𝒟(s)⊆𝒟\mathcal{D}(s)\mathcal{\subseteq D} be the set of assertion classes for which the evaluator in state ss possesses sufficient domain knowledge to exercise genuine judgment. Domain mismatch holds when an assertion of class dd is routed to an evaluator in state ss with d∉𝒟(s)d\mathcal{\notin D}(s).

Condition 10 (Constant-Output Equilibrium). The gate HH is in constant-output equilibrium if there exists y*∈{+,−}y^{*} \in \{ + , - \} and a state s*s^{*} such that π1(H(a,s*))=y*\pi_{1}\left( H\left( a,s^{*} \right) \right) = y^{*} for all a∈Aa \in A. The evaluator in state s*s^{*} produces the same output regardless of input.

The Degeneration Theorem

Condition 11 (Default Disposition). An evaluator in a state ss where the state update has converged to the identity (the evaluator is no longer processing input content) produces a constant output y*∈{+,−}y^{*} \in \{ + , - \} independent of the input. That is: if π2(H(a,s))=s\pi_{2}\left( H(a,s) \right) = s for all a∈Aa \in A, then there exists y*y^{*} such that π1(H(a,s))=y*\pi_{1}\left( H(a,s) \right) = y^{*} for all a∈Aa \in A.

Lemma 12 (Rate Saturation Causes State Collapse). Under Condition 8, the state update function converges to the identity: π2(H(a,s))→s\pi_{2}\left( H(a,s) \right) \rightarrow s for all aa.

Proof. When λ>μ(s)\lambda > \mu(s), the evaluator cannot process each assertion with sufficient depth to update the internal state. Let Δ(a,s)=ρ(π2(H(a,s)),s)\Delta(a,s) = \rho\left( \pi_{2}\left( H(a,s) \right),\, s \right) be the state change induced by assertion aa in state ss, measured in the metric ρ\rho on SS. The processing depth per assertion is μ(s)/λ<1\mu(s)/\lambda < 1. Assume that Δ(a,s)\Delta(a,s) is monotonically decreasing in λ/μ(s)\lambda/\mu(s) (i.e., reduced processing depth per assertion reduces state change magnitude). As λ/μ(s)→∞\lambda/\mu(s) \rightarrow \infty, the processing depth per assertion goes to zero, and Δ(a,s)→0\Delta(a,s) \rightarrow 0 for all aa. The state update converges to the identity. ◻

Lemma 13 (Domain Mismatch Eliminates Causal Connection). Under Condition 9, the gate loses causal connection for assertions of class d∉𝒟(s)d\mathcal{\notin D}(s).

Proof. The evaluator in state ss with d∉𝒟(s)d\mathcal{\notin D}(s) lacks the domain knowledge to distinguish assertions within class dd by their content. The judgment π1(H(a,s))\pi_{1}\left( H(a,s) \right) for aa of class dd depends not on the content of aa but on the evaluator’s default disposition. For any two assertions a1,a2a_{1},a_{2} of class dd, π1(H(a1,s))=π1(H(a2,s))=y*\pi_{1}\left( H\left( a_{1},s \right) \right) = \pi_{1}\left( H\left( a_{2},s \right) \right) = y^{*} where y*y^{*} is the default. The causal connection between input and judgment is absent for assertions of class dd. ◻

Lemma 14 (Constant-Output Equilibrium Is Absorbing). Let s*∈Ss^{*} \in S be a constant-output equilibrium state (Condition 10), and assume that the state update in s*s^{*} is input-independent: π2(H(a,s*))\pi_{2}\left( H\left( a,s^{*} \right) \right) takes the same value for all a∈Aa \in A. Then the set of constant-output equilibrium states is absorbing: the gate does not return to non-trivial operation from s*s^{*}.

Proof. In state s*s^{*}, the output is y*y^{*} for all inputs. Since the state update is input-independent, let s**=π2(H(a,s*))s^{**} = \pi_{2}\left( H\left( a,s^{*} \right) \right) for any aa. Two sub-cases.

Sub-case (a): s**=s*s^{**} = s^{*}. The state is a fixed point. The gate remains in s*s^{*} and continues to produce y*y^{*}.

Sub-case (b): s**≠s*s^{**} \neq s^{*}. Since the output in s*s^{*} is constant and the state update carries no input-dependent information (by the input-independence assumption), the evaluator in s**s^{**} has received no input-dependent signal that would differentiate its response to different assertions. Therefore π1(H(a,s**))\pi_{1}\left( H\left( a,s^{**} \right) \right) is constant in aa, and s**s^{**} is also a constant-output equilibrium state. The gate remains degenerate. ◻

Remark 15. The assumption that the state update in a constant-output equilibrium state is input-independent is the structural content of the lemma. It states that an evaluator who is not differentiating outputs by input is also not differentiating state updates by input: constant output and constant state update are coupled. This coupling is what makes the equilibrium absorbing.

Theorem 16 (Gate Degeneration). Let H:A×S→{+,−}×SH:A \times S \rightarrow \{ + , - \} \times S be a human verification gate. Under any of Conditions 8, 9, or 10, the gate degenerates: it converges to an operation where the output is independent of the input. Formally, there exists y*∈{+,−}y^{*} \in \{ + , - \} such that π1(H(a,s))→y*\pi_{1}\left( H(a,s) \right) \rightarrow y^{*} for all a∈Aa \in A.

Proof. Three cases, one for each condition.

Case 1 (Rate saturation). By Lemma 12, the state update converges to the identity. The state ceases to evolve. In a fixed state ss, the gate is a function H(⋅,s):A→{+,−}H( \cdot ,s):A \rightarrow \{ + , - \}. By Condition 11, an evaluator whose state update has converged to the identity produces constant output y*y^{*} for all inputs. The gate has degenerated to a trivial machine.

Case 2 (Domain mismatch). By Lemma 13, for assertions of the mismatched class dd, the gate produces constant output y*y^{*} independent of input. The gate is trivially operating on class dd.

Case 3 (Constant-output equilibrium). By Lemma 14, the equilibrium is absorbing. The gate remains in a state producing y*y^{*} for all inputs. The gate is a trivial machine. ◻

Corollary 17 (Degenerate Gates Do Not Verify). A degenerate gate does not perform verification. Verification requires that the output depends on the input (causal connection). A degenerate gate produces constant output. Passing assertions through a degenerate gate adds a procedural step but no epistemic content: the decision is not informed by the evaluation.

Proof. By Definition 5, causal connection requires that different inputs can produce different outputs. A degenerate gate produces the same output for all inputs. Causal connection is absent. Without causal connection, the gate’s output carries no information about the input. The gate is procedurally present but epistemically absent. ◻

The Preservation Theorem

Remark 18 (On exhaustiveness). The three degeneration conditions cover the input axis (rate saturation: too much volume), the operator axis (domain mismatch: wrong expertise), and the temporal axis (constant-output equilibrium: too long without variation). Whether additional axes exist that produce degeneration through mechanisms not reducible to these three is an open question. The three conditions are sufficient for the architectural consequence: cohort constraint, rotation, and monitoring. Exhaustiveness is not claimed and is not required for the architectural response.

Theorem 19 (Non-Triviality Preservation). Let H:A×S→{+,−}×SH:A \times S \rightarrow \{ + , - \} \times S be a human verification gate. HH preserves non-triviality if and only if all three of the following hold:

  1. λ≤μ(s)\lambda \leq \mu(s) for the evaluator’s current state ss (the assertion arrival rate does not exceed the evaluator’s processing capacity);

  2. For every assertion of class dd routed to the gate, d∈𝒟(s)d\mathcal{\in D}(s) (the evaluator possesses domain knowledge for the assertion class);

  3. The gate is not in constant-output equilibrium (the evaluator has not reached a state of default disposition).

Proof. Necessity: if any condition is violated, the gate degenerates by Theorem 16.

Sufficiency: if all three hold, then (i) the state update is functioning (the evaluator processes each assertion with sufficient depth to update the internal state), (ii) the causal connection is intact for the assertion class at hand (the evaluator can distinguish assertions by content), and (iii) the gate has not collapsed to constant output. All components of non-triviality (Definition 7) are present. ◻

Corollary 20 (Architectural Requirements). Preserving non-triviality imposes three measurable constraints on the institutional architecture:

  1. Volume control: the assertion arrival rate λ\lambda at any single gate must not exceed the evaluator’s processing capacity μ(s)\mu(s).

  2. Routing by competence: assertions must be routed to evaluators whose domain knowledge covers the assertion class.

  3. State monitoring: the institution must detect when an evaluator has reached constant-output equilibrium (through fatigue, habituation, or loss of engagement) and intervene (rotation, rest, replacement).

Institutional Architectures as an Instance

Proposition 21. Any institutional verification architecture that employs human review as a verification step instantiates the human verification gate HH.

Proof. The human reviewer receives assertions (input AA), evaluates them against domain knowledge and experience (internal state SS), and produces a judgment of admission or rejection (output {+,−}\{ + , - \}). The reviewer’s state evolves with each evaluation (fatigue accumulates, context shifts, domain knowledge updates). The structure is H:A×S→{+,−}×SH:A \times S \rightarrow \{ + , - \} \times S. ◻

Corollary 22. Any institutional verification architecture that employs human review is subject to Theorem 16: the human gate degenerates under rate saturation, domain mismatch, or constant-output equilibrium. The institution must satisfy the three conditions of Theorem 19 to maintain genuine verification.

Remark 23. The companion paper’s Collegium Custodum (the guild of qualified examiners with graduated competence levels) is an operationalisation of Corollary 20. The gradus structure (tiro, peritus, magister) maps to condition (ii): assertions are routed to evaluators whose competence level matches the assertion class. The workload limits map to condition (i): the gate’s throughput is bounded by the evaluator’s processing capacity. The rotation and review protocols map to condition (iii): the institution monitors for degeneration and intervenes.

The Volume Condition

Before LLMs, the assertion volume was bounded by human production capacity. Rate saturation (Condition 8) was structurally unlikely: the rate at which humans produce assertions does not typically exceed the rate at which other humans can evaluate them. Domain mismatch (Condition 9) existed but was managed informally through professional specialisation. Constant-output equilibrium (Condition 10) occurred in individual cases (reviewer fatigue) but was operationally containable.

LLMs changed the rate. The marginal cost of producing assertion-candidates dropped to near zero. The arrival rate λ\lambda at human gates can now exceed μ(s)\mu(s) by orders of magnitude. Rate saturation is no longer a boundary case; it is the default operating condition for any institution that admits LLM-generated content into its decision chains without volume control. The degeneration theorem applies: the human gate converges to a trivial machine. The institution records that human review occurred. The review carried no epistemic content.

Conclusion

The requirement that the human’s decision be real is a formal property of the verification gate, not a moral exhortation. A human gate is a non-trivial machine: its output depends on an internal state that evolves with input. Three conditions cause the gate to converge to a trivial machine, breaking the causal link between input and judgment: rate saturation, domain mismatch, and constant-output equilibrium. Under any of these conditions, the gate degenerates to a trivial machine producing constant output. A degenerate gate does not verify. The institutional architecture must preserve non-triviality by controlling volume, routing by competence, and monitoring for state collapse. These are measurable constraints with testable compliance criteria.

References

Immanuel Kant, Grundlegung zur Metaphysik der Sitten (Riga: Hartknoch, 1785); English translation: Groundwork of the Metaphysics of Morals, trans. Mary Gregor (Cambridge: Cambridge University Press, 1998).

Arthur Schopenhauer, Die Welt als Wille und Vorstellung (Leipzig: Brockhaus, 1818/1844); English translation: The World as Will and Representation, trans. E. F. J. Payne, 2 vols. (New York: Dover, 1969).

Heinz von Foerster, “On Constructing a Reality” (1973), reprinted in Observing Systems (Seaside, CA: Intersystems Publications, 1981), 288–309.

Heinz von Foerster, ed., Cybernetics of Cybernetics (Urbana, IL: Biological Computer Laboratory, University of Illinois at Urbana-Champaign, 1974).

Thorben Liebig, “On the Formal Foundation of Boundary 1: A Lawvere-Yanofsky Proof That Verification Architectures Cannot Attest Their Own Consistency” (2026).

Thorben Liebig, “On the Formal Foundation of Boundary 2: A Lawvere-Yanofsky Proof That Verification Architectures Cannot Define Their Own Truth Predicate” (2026).

Thorben Liebig, “On the Formal Foundation of Boundary 3: A Proof That Uniform Verification Thresholds Necessarily Fail on Non-Constant Falsification Landscapes” (2026).

Declaration on the use of AI tools. This paper was developed with the assistance of Claude (Anthropic, Claude Opus 4.6). The instrument was used for structural drafting, LaTeX formatting, editorial iteration, and bibliographic cross-referencing. All substantive claims, mathematical proofs, legal analysis, doctrinal positions, and architectural decisions are the author’s. The instrument produced no assertion that entered the final text without human verification at the gate. The verification architecture described in this paper was applied to its own production.

Notes

  1. The terminology is from the companion paper. The Kantian condition refers to the regime where verification is within the human’s competence but is not exercised. The Schopenhauerian condition refers to the regime where verification exceeds the human’s competence. The companion paper operationalises the distinction through the sutura epistemica.↩︎

  2. Heinz von Foerster, “On Constructing a Reality” (1973), reprinted in Observing Systems (Seaside, CA: Intersystems Publications, 1981), 288–309. See also Heinz von Foerster, ed., Cybernetics of Cybernetics (Urbana: University of Illinois, 1974).↩︎