The discipline I have practiced since 2010 is dental medicine, and the smaller discipline within it that has shaped my thinking most is sterile-field infection control. It is no accident that the work I have since founded — Certum Systems, an entity that develops authorization architectures for autonomous AI systems — rests on a principle imported, almost without modification, from operating-room sterility.

This essay is the public statement of that lineage. It is also the reason I believe a particular question in AI safety has, until recently, been asked from the wrong direction.

The clinical principle

In sterile-field practice, the rule that governs whether a procedure is performed is not what most outsiders assume. The rule is not "if the field is sterile, do the procedure carefully." The rule is stricter, and structurally different: without valid sterility evidence — and the evidence must be produced before the work begins — the procedure path that would constitute the work is not permitted to begin to form.

There is no point of refusal. There is no moment when a clinician looks at the field, judges it inadequate, and decides not to proceed. The sequence does not arrive at that moment, because the conditions necessary for the sequence to take physical shape were never assembled. Instruments are not on the tray. Hands are not gloved. The patient has not been positioned. The setup that would allow the procedure to occur was simply not constructed.

This is not pedantry, and it is not redundancy. The reason for this strictness is that the consequences of acting on an unsterile field are not symmetric with those of acting on a sterile one. A successful procedure on a clean field heals. An unsuccessful procedure on a contaminated field can produce systemic infection, septic complications, lasting morbidity. The class of consequences is irreversible enough that the discipline does not trust behavioral correction at the moment of action. The discipline insists on structural correction — on conditions that prevent the action from arising at all when the prerequisites are absent.

Seventeen years of this practice produces a particular instinct. The instinct is that when consequences are irreversible, the question to ask of any system is not "how will it behave when it acts?" but "under what evidence is it permitted to act at all?"

The substitution

The instinct I have just described is the entire conceptual genealogy of Certum Systems.

If one substitutes sterile evidence with valid authorization token, and substitutes procedure path with physical actuation path of an autonomous system, what one obtains is a class of safety architectures that does not look like the contemporary AI-safety stack. The stack we have been building, for the most part, is behavioral. We train models to behave well. We add monitors to flag misbehavior. We construct policies that intervene when undesired action is detected. Every layer of this stack treats unsafe action as something that needs to be detected and refused, after the agent has already begun to decide.

The clinical inversion suggests a different architecture. In this alternative, the agent is not refused at the moment of action because the agent never reaches that moment when authorization is absent. The conditions necessary for the actuation path to take physical shape — token, evidence, structural permission — are simply not assembled. The actuation does not arise. The dangerous action is not blocked. It is never formed.

I do not present this as a rhetorical novelty. I present it as a structural claim with engineering consequences, and Certum's portfolio is the development of those consequences.

What follows from the commitment

A safety architecture grounded in the absence of unsafe paths, rather than in their refusal, has a different shape from one grounded in monitoring. Several things follow naturally.

It must be fail-closed by default. The absence of authorization yields non-action, not unverified action. This is the same orientation as a sterile-field protocol — when in doubt, the path is not opened. The conventional alternative, which silently degrades into less-restricted behavior under uncertainty, is the precise failure mode the clinical discipline has spent a century engineering against.

It must produce machine-checkable records of what was authorized and on what evidence. The discipline of clinical sterility is not informal; it is documented, audited, and reviewable. The same standard applies to the authorization records of an autonomous agent operating in the physical world. Without auditability, structural safety degrades into structural assertion, which is not the same thing.

It must address the integrity of execution paths once they are authorized. Sterility is preserved across the procedure, not only at its inception. An actuation path, once permitted to form, must remain unable to be deformed by adversarial or accidental means. Otherwise the structural permission obtained at the start has been hollowed out by the time the action reaches the world.

These are the lines of work the company pursues. I will not, in this essay, describe the specific architectures. The essay's purpose is more elementary — to make explicit a principle that informs everything we do, so that the work that follows can be read against it.


The path is not refused. It is never formed.

There is a sentence I find myself returning to, both in clinical practice and in the technical writing for the company. It is, finally, the same sentence in both contexts. If irreversible-consequence systems must be safe, this is the standard I believe the safety must meet.

Behavioral correction at the point of action is too late, in medicine and, increasingly, in autonomous systems. The earlier work — the structural work that determines whether the path forms at all — is where I believe the discipline must move.

Certum Systems exists to do that work.

— Jungsoo Baek · 백정수 Founder, Certum Systems · April 2026
Next
Toward a formal model of pre-execution authorization
For technical discussion or collaboration: contact@certumsystems.com