Certum Systems
Patent-backed structural AI safety · Republic of Korea

Structural authorization
for autonomous systems.

Architectures in which unsafe execution paths are denied existence at the structural layer — not blocked at the moment of action.

Structural authorization A pre-execution control architecture in which an autonomous system cannot construct an action path unless valid evidence and permission are already present.
Read the origin essay Discuss collaboration
Patent allowed Memory-write safety · priority exam
Two papers Accepted · ICML 2026 workshops
2026 Founded · Republic of Korea
§ I Mission

Permission, before the action takes shape.

Irreversible-consequence systems must prove structural permission before they act — not after.

The conventional AI-safety stack treats unsafe behavior as something to be detected and intervened upon. Our work inverts the sequence: we treat the upstream structural conditions of execution itself as the object of safety.

Where classical safety asks an autonomous agent to behave well, we ask the prior question — under what evidence is the action permitted to take shape at all? When a system cannot form a path to a forbidden action, the action does not need to be refused. It does not arise. None of this displaces behavioral safety — training, evaluation, and oversight still shape what an agent tries to do. The structural layer bounds what it can do when they fail. Defense in depth, not rivalry.

§ II Architecture

Permission, before path formation.

A simplified view of how an authorization gate enters the action sequence — and why its position in the sequence is what matters.

01
Evidence · Token
Authorization material is presented before any decision begins.
02
Structural Gate
Validity is checked against the authorization model — not as a late policy hook.
03
Path Formation
If — and only if — valid: the actuation path is permitted to assemble.
04
Audit · Action
Action proceeds with a machine-checkable record. Otherwise: non-action.
iPhilosophical
The path is not refused. It is never formed.
iiTechnical
Authorization is a precondition for path construction.
iiiPractical
Agents default to non-action when evidence is absent.
§ III Founder

Seventeen years of clinical practice, as the ground for an AI safety architecture.

Jungsoo Baek

백정수
Founder · Principal Researcher
Clinical dentist since 2010

Jungsoo Baek has practiced clinical dentistry since 2010 and currently runs his own private clinic. Now in his seventeenth year of clinical practice — infection control its most exacting discipline — he has held to one operative principle, simple and uncompromising: no sterile evidence, no procedure path forms. The procedure is not blocked when sterility is missing — the path that would constitute the procedure is never permitted to begin.

Certum Systems, founded in 2026, is the translation of that principle into the architecture of autonomous AI systems. Replace sterile evidence with a valid authorization token, and the procedure path with a physical actuation path — and an entire class of safety architectures emerges, in which dangerous actions are denied existence at the earliest possible structural layer.

No evidence, no path. The path is not refused — it is never formed.
§ IV Research

Principle, now on record.

The same structural conviction, now on external record. A memory-write safety architecture has been allowed as a patent under Korea's priority examination, and — together with a verifiable causal-chain method — appears in two papers accepted at ICML 2026 workshops. Alongside these, the work continues across the directions below.

“A gate that cannot be made to fail is not accepted as evidence.”

01 / 05

Memory-write safety for autonomous agents

A pre-commit authorization gate for an agent's persistent memory. A write cannot take effect unless its provenance and permission are verified first — so poisoned or unverified writes never reach the store. Accepted as a paper at an ICML 2026 workshop and engineered into CMF, a live reference implementation.

264-test conformance suite · live Mem0 / Agent SDK integration · 21 invariants pre-registered
Project page — paper · poster · demo →
AI safety
agent memory
Allowed in 33 days · all 20 claims · registration in process
02 / 05

Verifiable causal-chain authorization (CCA)

Authorizing an agent action against a machine-verifiable record of the causal chain that produced it — permission that is checkable, not merely asserted. Accepted as a paper at ICML 2026 workshops and engineered into PAG, shipped as a runnable evaluation bundle.

105 no-key deterministic checks · mutation-bound · 0.1 ms median gate
Project page — paper · poster · demo →
agent safety
verifiability
PCT filed · KIPO priority examination
03 / 05

Robot Hygiene Protocol (RHP-OS)

Verified physical readiness for embodied systems: an actuation path cannot form unless hygiene-readiness evidence is verified first — by a deterministic layer independent of the model's intelligence, transplanted from the clinical regime where the principle originated. The protocol page states the argument and the structure.

Deterministic gate · fail-closed default · independent verifier
Protocol page — argument · structure →
robot hygiene
embodied AI
Patent filed · specification sealed
04 / 05

Structural integrity of execution paths

Methods to ensure that an actuation path, once authorized, cannot be deformed by adversarial or accidental means.

robot safety
embodied AI
Direction · ongoing
05 / 05

Auditability primitives for the agent industry

Machine-checkable records of authorization that make insurance, regulation, and accountability tractable at scale.

governance
standards
Direction · ongoing
§ V Writing

Notes from the practice, occasionally.

July 2026 Essay 10 min read

The Caveat Is the Theorem

If the safety result depends on the model not knowing it is being tested, the test is part of the threat model — on sandbagging, the indistinguishability caveat, and the non-formation paradigm.

Read the essay
April 2026 Essay 5 min read

The Infection-Control Origin of Structural AI Safety

Why a principle from seventeen years of sterile-field practice translates almost without modification into the architecture of autonomous-systems safety — and what that inversion makes possible.

Read the essay
§ VI Contact

Open to conversation.

Inquiries
Technical evaluation · Licensing · Research collaboration · Strategic partnership
Correspondence
Founder
Jungsoo Baek