AI & Computingpreprint2026-08-15

Repetition Is Not Warrant: Register-Provenance Inheritance as a Deterministic Mechanism Against Laundering in Conversational Language-Model Records

Open access0 citations

Abstract

A conversational language model system that verifies its claims against its conversation record contains a loop: the model asserts an unsupported proposition, the assertion enters the record, a later turn quotes it back, the quotation verifies, and the proposition now presents as grounded. Repetition has become evidence. This paper closes the loop with a deterministic rule called register-provenance inheritance. Every span of the record structurally carries the epistemic register under which it entered; the weakest register among a claim's sources and its own declaration sets a ceiling the claim can never exceed; plain, unmarked presentation is derivable only from user-provenance spans. A non-amplification theorem, proved by induction, shows no chain of model self-quotation can create plain-register warrant. The mathematics is fifty-year-old low-watermark integrity, transferred to conversational records, with one domain lemma: quotation can strip an unbound in-band label, so provenance must be non-strippably bound to the record's structure. The non-amplification theorem is additionally machine-checked: a TLA+ model of the record and the binding rules, with the lexical criterion over-approximated nondeterministically so the theorem is verified independently of its details, was exhaustively checked with TLC (827,917,528 generated states, 10,682,827 distinct reachable records at depth 7, no error on any invariant); the model and logs are in this version's bundle. The mechanism is implemented, and regression-tested against its own exploit list: the paper was developed through nine independent adversarial reviews and five rounds of external critique, its plain-register criterion was broken and repaired twice on the way, and the 44-check suite deposited alongside is that review history made executable. The mechanism governs presented epistemic status relative to the integrity of ingestion labelling, and it judges truth nowhere. The deposit contains the paper (PDF and source), the reference implementation (binder v0.4.1), the offline replay suite, the sealed run bundles cited in the paper, and the complete adversarial findings registers. The sealed (In)Canon engine is not part of this deposit; the only shared component is a mundane text canonicaliser, vendored for replay. CC BY 4.0 covers the deposit contents only.

// Source

View paper (DOI)Open access versionOpenAlexarXiv (Cornell University)Published 2026-08-15

Authors: David Antonio Lester-Tomé

Institutions: Plastic Logic (United Kingdom)