# Three Walls

## A Formal Limit on the Computational Paradigm, Its World Models, and Their Deployment

**Author:** Nourizadeh, Moreno  
**ORCID:** 0009-0006-0174-2585  
**DOI:** 10.5281/zenodo.20775851  
**Published:** July 2026  
**Version:** v1_0

---

> *The purpose of a system is what it does.*
>
> — Stafford Beer

---


## Abstract

The systems the current AI industry sells are sold under three promises: that they understand the world, that they are safe enough to be deployed at scale, and that they learn how the world works from watching it. This paper argues that each promise meets a limit the industry's own resources cannot remove, that the three limits are independent of each other, and that the systems now in deployment meet all three limits at once. The first limit says that a system that has only seen the world through a fixed body of data cannot vouch for the cases that lie outside that data, and adding more data or more compute does not close the gap. The second limit says that a system whose probability of a serious failure on each action does not fall in response to its own serious failures will, deployed long enough, produce them without end, no matter how small the per-action probability is. The third limit says that an agent acting on a system that recovers slowly, an institution, a supply chain, an ecology, cannot tell a healthy state from a depleting one when the agent only ever sees the short run, and ends up spending what it cannot see. The three are established from sources already canonical in the relevant fields and the limits are then turned back on the field's own descriptions. The world-model programme is the central case, because two of the three limits strike it independently. For each limit the paper states the condition under which the limit would be false.

**Keywords:** grounding, world models, computational paradigm, requisite variety, Borel-Cantelli, foreclosure, AI safety, reference, identifiability

---

## Part I. The Claim and the Frame

### 1. Three walls, one structure

This section says what the paper is going to do. The argument is built around three claims about the systems the current AI industry has put into the field. Each claim is a wall, in the sense that it sets a limit beyond which the systems cannot pass on the resources their builders have given them. The three walls are different from each other: each is about a different aspect of how the systems work, and no repair to one of them reaches the others. The section names the three walls in order, says what each one is going to claim, and fixes the small set of terms the rest of the paper uses to talk about them. The proofs come later, in Parts II and III. The point of this section is to put the structure in view.

A language model produces a sentence; a world model trained on video produces a prediction of the next frame; a proof procedure decides a theorem; a control system holds a process within a tolerance band. Each produces outputs over a range of cases for which it is held responsible, and each operates from a base that covers only a portion of that range. The paper is the investigation of the gap between the two, and the argument is laid out as a numbered structure to which the rest of the paper returns at every step. Three terms are fixed before any claim is made.

A system has a *domain*, the full range of cases for which it is held to answer. It has a *substrate*, the mechanism that produces its outputs: a trained network, a procedure of derivation, a body of measurements, a regulator's control law. It has a *cut*, the portion of the domain to which the substrate has operational access: the training distribution, the axioms and rules, the regime of measurement, the disturbances the regulator's loop can sample within its cycle. The three are not theoretical conveniences; they are the parts the field's own descriptions already presuppose whenever it speaks of training data, model behaviour, and deployment context. The argument operates entirely on these terms.

To these three the paper adds a fourth: the *claim*, *Λ*, the assertion made on behalf of the system that its substrate operating on its cut suffices to determine correct accounts for elements of its domain, including elements outside the cut. The claim is not an act of the substrate but a commitment of those who build and deploy the system. A model trained on curated video is presented as a model of physical dynamics; a score on a fixed evaluation is presented as competence on open-ended work; a regulator tuned on a fast signal is presented as a governor of the slow process it sits inside. In each case a result about the cut is sold as a result about the domain, and the paper's investigation is the investigation of how that distance is to be closed and what it would take.

The argument proceeds along three axes; each is a different property of the same arrangement, and each is the variable that the corresponding wall governs. The first axis is the relation between cut and domain at a single instant: what the substrate can reach. The second axis is the temporal behaviour of the substrate's failure mode: whether catastrophe on a mode deforms that mode's future probability. The third axis is the relation between the agent's evaluation horizon and the cycle on which its target system varies: whether the agent's feedback span can resolve the distinction between a sustainable state of the target and a depleting one. The three axes are distinct, and the paper's claim of independence among the three walls is the formal consequence of that distinctness; Part IV proves the independence, and the no-exit result follows from it.

The first wall is the wall of foreclosure. In plain terms: a system that has only seen the world through a fixed body of data cannot certify what is correct on cases that lie outside that data, because two different ways the world might extend past the data are equally consistent with what the system has been trained on, and the system has no resource for choosing between them. Adding more data shifts the gap but does not close it. The formal version of the claim turns on what counts as "outside the data" and what counts as the system "certifying" a correct account, and the proof is the underdetermination argument familiar from Quine (1960), Putnam (1980), and Kripke (1982): two completions of the world that agree on the data produce identical system behaviour, and no operation of the system can distinguish their differing accounts of a case outside the data. The wall stands at a single instant; it says nothing about deployment or repetition; it says only that the part the system can reach does not contain the part the claim is made about. Part IV will show, drawing on Lawvere (1969) and Yanofsky (2003), that the three lenses through which the first wall is proved are instances of a single categorical structure.

The second wall is the wall of compounding hazard. In plain terms: if the probability that a system produces a serious failure on a given action stays the same no matter how many times that same failure has already occurred, then deploying the system for long enough will produce that failure without end, however small the probability is. A system whose probability collapses sharply after each realised failure, so that the failure suppresses itself, produces only a few. The "ninety-nine percent safe" figure the industry reports is a per-action probability; the working lifetime of a deployed system is many millions of actions; the per-action figure and the deployed total behave oppositely under repetition. The formal version of the claim is the pair of Borel-Cantelli lemmas, with the divergent regime closed by the conditional extension due to Lévy (1937) that drops the independence assumption the classical second lemma requires (Williams, 1991, §12.15). The wall is temporal; the variable it governs is not the size of the hazard but its law of motion.

The third wall is the wall of horizon-mismatch. In plain terms: an agent that acts on something that takes a long time to recover, an institution, a supply chain, an ecology, will deplete what it acts on if it only ever sees the short run. The healthy state and the depleting state of the slow thing look the same inside the window the agent can evaluate; the difference between them only shows up across the cycle on which the slow thing recovers, and the agent's window does not reach that cycle. The agent acts on what it sees, sees only the short cycle, and spends the slow thing without noticing until it has been spent. The formal version of the claim joins finite-horizon observability (Chen, 1999) to the Conant-Ashby theorem (Conant and Ashby, 1970): states the agent's feedback cannot distinguish inside its window do not enter the agent's model, and a regulator whose model lacks the distinction cannot, by the Conant-Ashby result, hold the system in the sustainable state (Ashby, 1956; Conant and Ashby, 1970). The variable here is not the rate dynamics of the second wall; it is the relation between the agent's window and the slow thing's recovery cycle. A system can have a perfectly cost-collapsing hazard and still sit on the wrong side of this wall.

The independence of the three is the structural claim that carries the rest of the paper. Each wall governs a different variable; each variable can be set independently of the others; current systems fail on all three at once. The consequence for repair is sharp: alignment and patching address, at most, the second variable, and leave the first and third where they were; enlargement of the training distribution addresses, at most, the first variable, and leaves the second and third; extension of the evaluation horizon addresses, at most, the third, and leaves the first and second. The toolkit the paradigm has assembled reaches one variable at a time. The result is the no-exit result, proved formally in Part IV: a system that is foreclosing, cost-stationary, and horizon-mismatched, which is what the deployed systems are, requires three independent repairs, and no single repair the field has proposed reaches more than one of the three.

The paper proceeds along seventeen sections. Part II establishes the first wall and its three lenses: the semantic underdetermination of reference (Frege, 1892; Putnam, 1980; Kripke, 1982; Sellars, 1956; Searle, 1980; Carnap, 1928; Quine, 1960), the statistical underdetermination of the law over a training distribution, and the formal lens through which the field's own positive results assume the grounding they were taken to produce (Ashby, 1956; Conant and Ashby, 1970). Part III establishes the two temporal walls and the distinction between them (Williams, 1991; Chen, 1999). Part IV proves the independence of the three walls and the identity behind the first wall's formal instances (Lawvere, 1969; Yanofsky, 2003), and marks the boundaries the argument does not cross. Part V supplies the genealogy that accounts for the field's blindness to the limits from inside (Shannon, 1948; Newell and Simon, 1976; Fodor, 1975; Dreyfus, 1972), the convergence of the failure pattern across architectures that supports the paradigm-level cause, and the deployment consequence that follows from the three walls together. Part VI states the escape conditions and the falsifiers for each wall, marks what the paper does not claim, and closes.

### 2. What would have to be true for the paradigm to deliver

This section sets up what the three walls are going to falsify. The paradigm's three promises are not assertions out of nothing; each rests on a condition about how the systems work. If those conditions held, the promises would follow. The argument of the paper is that the conditions do not hold. To make the argument testable, the section states each condition cleanly first, in the form that would have to be true for the promise to be delivered. The rest of the paper falsifies each condition in turn.

The argument is sharpened by stating, before the walls are raised, what the paradigm's three descriptions would require in order to hold. The requirements are the negations of the three theorems, and the paper's task is the falsification of these antecedents one by one. The conditions are laid out as a numbered set; the rest of the paper falsifies each in turn.

The first condition: the correct account of every consequential element of the domain is fixed by the substrate's behaviour on the cut. There would have to be no consequential element of the domain on which two cut-indistinguishable extensions of the world disagree. If reference, the rule, the law governing an unobserved configuration were all determined by the statistics of the observed sample, a system that captured those statistics would have captured the relation; the understanding claim requires that grounding be a property internal to the data. The classical results on the underdetermination of reference (Frege, 1892; Quine, 1960), of rule by record (Kripke, 1982), of theory by formal constraint (Putnam, 1980), of meaning by trace (Sellars, 1956), and of semantic relation by symbol manipulation (Searle, 1980) all bear on this antecedent and are taken up in Part II.

The second condition: the per-action probability of catastrophe is either zero, which the architecture of probabilistic generation forbids by construction, or its dynamics are such that the mode's hazard probabilities sum in deployment. The system would have to learn from each realised catastrophe in the indexed and immediate way that drives the rate on the mode toward zero. The safety claim at scale requires that the failure distribution be deformed by its own catastrophic outputs in the right way. The Borel-Cantelli dichotomy (Williams, 1991, §12.15), with the Lévy (1937) conditional extension for the dependent case, is the formal apparatus that distinguishes the two regimes and is taken up in Part III.

The third condition: where the system is an agent coupled to a slow-replenishing system, the agent's evaluation horizon reaches the cycle on which the slow variable becomes legible, so that the sustainable and depleting states are distinguishable inside the horizon. The world-learning-and-governance claim requires that the evaluation horizon be matched to the replenishment cycle of the systems on which the agent is to act. Finite-horizon observability (Chen, 1999) together with the Conant-Ashby theorem (Conant and Ashby, 1970) and the Law of Requisite Variety (Ashby, 1956) supply the formal apparatus that fixes when the antecedent fails and is taken up in Part III.

The three conditions are the antecedents the paper falsifies. The conjunction fails in three independent places: grounding is shown not to be internal to the data; the failure distributions of the deployed systems are shown not to be deformed by realised catastrophes on the consequential modes; and the agentic systems are shown to evaluate the consequences of their actions on horizons that fall short of the cycles on which the systems they act upon replenish. What remains, after the three antecedents are denied, is a system that cannot reach what it claims, cannot survive its own deployment, and cannot resolve the slow systems it is held to keep sustainable, sold as a system that does all three.

---


## Part II. The First Wall: Foreclosure

### 3. The foreclosure theorem

This section states the first wall as a theorem and proves it. The plain content of the theorem is that a system trained on a fixed body of data cannot, by training alone, certify what is correct on cases outside that data when two equally consistent extensions of the world disagree on those cases. The proof is short: if two extensions of the world agree on the data, the system trained on the data cannot tell them apart, and whatever account it gives of the case outside the data is the account it would have given under either extension. The work of the section is to state the theorem cleanly, prove it in three lines, and identify the conditions under which the gap matters in practice. The three lenses of §§4-6 then show that the conditions are met by the systems the paper treats.

The first wall is stated in a single proposition and proved by underdetermination. The terms are those fixed in §1: a domain *D*, a substrate *S*, a cut *C* ⊂ *D* to which *S* has operational access, and a claim Λ asserting that the action of *S* on *C* suffices to determine correct accounts for elements of *D*. To these the proof requires one further notion. An element *d* ∈ *D* is *consequential under Λ* when the claim explicitly extends to *d*, that is, when Λ is taken to license action or assertion at *d*; and a consequential element is *off-cut* when *d* ∉ *C*. The foreclosure theorem then takes the following form.

**Theorem 1 (Foreclosure).** *Let* (*D*, *S*, *C*, Λ) *be a system in the sense of §1, with C* ⊊ *D and Λ unrestricted to C. If there is a consequential off-cut element d on which there exist two extensions of the world to D, both consistent with the substrate's behaviour on C and both compatible with the conditions Λ imposes, that yield distinct correct accounts of d, then no operation of S on C alone certifies the correct account of d under Λ.*

The proof proceeds in three lines. By hypothesis the two extensions are indistinguishable to the substrate, since *S* sees only *C* and the extensions agree on *C*; hence the substrate's behaviour is identical under either; hence any account *S* produces for *d* is produced equally under either extension; hence *S* alone cannot select between the differing correct accounts; the consequential off-cut element *d* therefore stands without certification by *S*. The structure of the argument is the underdetermination structure familiar from Quine (1960), Putnam (1980), and Kripke (1982): a fixed sample is consistent with a multiplicity of extensions to the unsampled region, and the sample's behaviour does not discriminate among them.

The theorem is unsurprising in form and inescapable in scope; the cut does not contain its own off-cut completion. What it states formally is the structural condition under which the gap matters: there must exist an off-cut element on which two cut-indistinguishable extensions disagree in their correct account, and that element must be consequential under the claim Λ. Both conditions are met by the systems the paper treats. The off-cut elements are the unprecedented configurations that constitute the cases of consequence; the disagreement is the disagreement among lawful continuations of the data the system has not seen; the claim Λ is the unrestricted competence the paradigm advertises. The paper now establishes these conditions through three lenses: the semantic lens of reference, the statistical lens of law, and the formal lens of the conditions of identifiability. The lenses converge on a single structural finding, and §10 will demonstrate, drawing on Lawvere (1969) and Yanofsky (2003), that the convergence is identity rather than analogy.

### 4. The semantic lens: reference is not in the cut

#### 4.1 The first lens introduced

This section runs the foreclosure theorem through the first of three lenses, the one philosophy of language has been working out for over a century. The point of the lens is to show that the gap the foreclosure theorem identifies between training data and the world is the same gap analytic philosophy has been calling the underdetermination of reference. The argument is constructed entirely from the field's own canonical sources, on its own terms; the lens does not import an outside standard. The reader who knows Frege, Putnam, Kripke, Sellars, Quine, and the rest will recognise the moves; the reader who does not will be walked through them. The case-by-case construction shows that the same structure appears at five canonical points in the philosophy of language and one engineering case, which is what the lens needs to establish.

The first lens passes the foreclosure structure through the semantic theory of reference; the resources used are the canonical resources of analytic philosophy of language, and the line of argument is the line by which that tradition itself learned to formulate the underdetermination thesis. The discipline of immanent critique requires that the field's own classical sources do the work; the canon is the warrant. The lens proceeds case by case through Frege (1892), Putnam (1980), Kripke (1982), Tarski (1936), Gödel (1931), Sellars (1956), Searle (1980), Carnap (1928), and Quine (1960): reference, the rule, the inferential role, the formal limits of definability, the indeterminacy of translation. The lens closes in §4.10 with a contrast taken from the engineering field's own working categories.

#### 4.2 Frege: reference is not given with structure

Frege's distinction between sense and reference (Frege, 1892, "Über Sinn und Bedeutung") is canonical for a reason the present argument requires. The morning star and the evening star are presented under distinct senses while sharing a single reference, the planet Venus; the identity of reference is not given to the language user by the structural composition of either sense; the identification is an achievement of astronomy, not of grammar; and the achievement was made not by closer inspection of the senses but by extending the perceptual cut to include the planet itself across its orbital phases. The structural lesson the paper takes from Frege (1892) is exact: that the reference of a term is not read off the structure of the expression in which the term occurs; reference is fixed by the world the expression is taken to be about, and the world is not in the expression.

#### 4.3 Putnam: permutation does not perturb the sentences

Putnam's model-theoretic argument (Putnam, 1980, "Models and Reality", *Journal of Symbolic Logic* 45(3)) sharpens the point. A theory's formal constraints, even when taken to be the full set of constraints the theory affords, do not fix the reference of its terms; the theory admits non-standard interpretations on which the truth-values of all sentences are preserved while the terms are reassigned to wholly different objects in a permuted universe (Putnam, 1980). The constraints internal to the theory are not constraints on the reference of the terms; the link from term to object is supplied from outside the theory, by the world in which the theory is applied. The argument is the underdetermination structure of Theorem 1 stated for the formal apparatus of theories: a fixed body of sentences is consistent with multiple reference-assignments, and no operation on the sentences alone selects among them. The two extensions of the world that Theorem 1 requires are, in Putnam's formulation, the standard and permuted models of the theory.

#### 4.4 Kripke: the rule is not in the record

Kripke's reading of Wittgenstein on rule-following (Kripke, 1982, *Wittgenstein on Rules and Private Language*) establishes the temporal-extension form of the same structure. A finite record of applications of a rule is consistent with infinitely many rules that agree on the record and diverge beyond it; the famous case (Kripke, 1982) is the rule *quus*, which agrees with the addition function on every pair the speaker has so far computed and returns five on every pair larger than the largest the speaker has yet considered. The record does not contain the rule it is a record of; the extension of the rule beyond the record is undetermined by the record. The form is again the foreclosure form: a finite cut, a domain that exceeds the cut, and a claim of competence on the domain that the cut underdetermines.

#### 4.5 Tarski and Gödel: the structural limit from inside

The formal closure of the lens is supplied by results internal to logic itself. Tarski (1936, "Der Wahrheitsbegriff in den formalisierten Sprachen") establishes that the truth predicate for a sufficiently rich formal language is not definable within that language; the language cannot internalise its own semantics; the relation of the sentences to the world they describe is not a relation the sentences themselves can capture. Gödel (1931, "Über formal unentscheidbare Sätze...") establishes that a consistent, sufficiently strong formal system contains true sentences it cannot prove; the apparatus does not exhaust the truths in its own domain. These are not external critiques; they are theorems of the discipline that the field's own formalisms inherit. The lesson the paper takes from them is the same lesson the previous cases have delivered: the cut, however formal and however complete in its own terms, does not contain what the claim made on its behalf requires it to contain. Part IV will return to Tarski (1936) and Gödel (1931) as instances of a single categorical structure (Lawvere, 1969; Yanofsky, 2003); here they establish only that the semantic reach a grounded system would need is not securable from within a formal substrate. The argument has now encountered, for a third time inside the semantic lens, the same form of insufficiency. The recurrence is the lens's confirmation that the structure of Theorem 1 is the structure of reference itself, not an analogy.

#### 4.6 Sellars: meaning lives in the space of reasons, not in the trace

Sellars's argument against the Myth of the Given (Sellars, 1956, "Empiricism and the Philosophy of Mind") supplies the further specification the lens requires. Meaning is not a property of an isolated item, sensory or symbolic; it lies in the normative inferential relations the item bears to other items, and these relations are constituted in a practice that determines what counts as a reason for what (Sellars, 1956). A linguistic substrate that produces tokens whose statistical distributions match those of a competent speaker captures the surface trace of that practice, the regularity of inferential transitions as they appear in text; it does not, by capturing the trace, participate in the practice itself, which is constituted by what counts as a reason for what, not by the statistical pattern of what follows what.

The sharpening this argument requires is the structural form of the Sellarsian point against the consciousness-dependent reading. The lens does not turn on whether the system has phenomenal experience; that question, however settled, is not what the argument needs. The argument needs only that the normative inferential practice in which meaning is constituted is not internal to the trace the practice leaves in the substrate's training data; the practice is the world relation the cut does not contain, and the substrate operates on the cut. The trace is the cut; the practice is the off-cut remainder; and the failure of the trace to constitute the practice is the form of Theorem 1 once more.

#### 4.7 Searle: the formal apparatus does not constitute the relation

Searle's argument (Searle, 1980, "Minds, Brains, and Programs") is read here in its structural form, set apart from the consciousness-intuition reading the original argument made famous. The structural form is the form the foreclosure theorem requires: a system that operates by purely formal manipulation of symbols, with no causal connection to the objects the symbols are taken to denote, has nothing in its operation that constitutes the semantic relation between symbol and object (Searle, 1980). The semantic relation is constituted by the relation between the formal apparatus and the world it is applied to, and the system, by hypothesis, lacks that relation. The argument is the foreclosure argument: the apparatus is the cut, the world is the domain, and the relation from cut to domain is not internal to the cut. Whether the system has experience, what experience would be, what role experience plays, all of these are downstream of the structural point, and none is required to make it. The paper's use of Searle (1980) is therefore deliberately re-grounded in logic rather than in the intuition-pump form for which the original argument is best known, and the structural reading is defensible against the original on the terms the original itself supplies.

#### 4.8 Carnap and Quine: the world is required, the cut is not enough

The *Aufbau* (Carnap, 1928, *Der logische Aufbau der Welt*) attempts the constructive form of the opposing position: the world is to be constructed from sense data and logical operations, that is, from a cut consisting of immediate sensory tokens and a set of operations defined over them. The project's failure to deliver the world is acknowledged by Carnap (1928) himself and amplified by Quine's later analysis (Quine, 1960, *Word and Object*). The gavagai example (Quine, 1960) fixes the lesson: pointing at a rabbit while uttering the term is consistent with reference to the whole animal, to the temporal slice, to the undetached parts, to the colour, to the act of attention; the pointing does not select among these, and no extension of pointing closes the gap; the reference is not determined by the perceptual cut, however refined.

The two cases close the lens at its strongest point. Carnap (1928) failure is from inside the most ambitious form of the cut-suffices position; Quine's (1960) analysis is the diagnostic that explains why the failure is structural rather than incidental. The substrate that operates on a cut consisting of tokens, however richly structured, does not by that operation acquire the world-relation the claim made on its behalf requires; the underdetermination of reference by sample is the underdetermination of the world by the cut, and the foreclosure theorem is its formal statement.

The lens has now run through the canon's central cases: Frege (1892) on sense and reference; Putnam (1980) on permutation; Kripke (1982) on rule-following; Tarski (1936) and Gödel (1931) on the formal limits from inside; Sellars (1956) on the normative space; Searle (1980) on the formal apparatus and its world-relation; Carnap (1928) and Quine (1960) on construction and indeterminacy. Each is a case of the same structure; each makes the structural point through different resources; each is a theorem or argument internal to the canon of philosophy of language. The recurrence is what the lens needs; the canon has been encountering the foreclosure structure for a century, and the canon's own resources are what have been forcing the encounter.

#### 4.9 The figure of camera and carving

To anchor the lens before the next one is taken up, the paper introduces a structural figure to which §5 will return. A camera, however precisely engineered and however dense the resulting image, records the surface of a scene; it does not, on the strength of the image, recover the bones of what it photographs. A carving, by contrast, is the product of an act that engages the material on which it is performed; the carver works against the wood, the wood resists; the resulting form is the joint product of a hand and a substance whose internal grain has been encountered and worked.

The figure is not a metaphor for argument; it is the structural homologue of the cut and the world. The substrate that processes a record of the world processes the camera-image; the operation on the image, however refined, does not by itself reach the bones of the scene the image records. The world, in the cases the paper treats, is what would have been encountered had the substrate worked against the material rather than reading it; the carving is the off-cut relation; and the difference between camera and carving is the difference between cut and domain. The figure is exact in the sense the eco-NR register requires of analogy: applied term by term, it survives the application; the substrate is the camera, the data is the image, the world is the scene, the practice is the carving, and the absent relation is the relation between hand and grain.

#### 4.10 Accumulation against model: the field's own contrast

A second case from the field's own resources confirms the figure. A mesh of triangles obtained by image-to-three-dimensional reconstruction supplies a surface but no internal model: the object behind the mesh is not constituted by the mesh; the mesh is a skin draped over an inference from photographs (Schönberger and Frahm, 2016). A parametric or building-information model, by contrast, is constituted by objects that carry material, dimension, constraint, and relation; the model contains what the mesh contains by inference and what the mesh does not contain at all (Eastman, Teicholz, Sacks, and Liston, 2018). The contrast is not a contrast between two technologies; it is the contrast between accumulation and constitution, between cut and domain, between camera and carving. The case is included because the field itself has produced both kinds of object and is in a position to confirm, from its own working categories, that the kinds are distinct.

The semantic lens closes on the structural fact it has now established at eight canonical points (Frege, 1892; Putnam, 1980; Kripke, 1982; Tarski, 1936; Gödel, 1931; Sellars, 1956; Searle, 1980; Carnap, 1928; Quine, 1960) and one engineering case (Schönberger and Frahm, 2016; Eastman et al., 2018). The substrate operates on a cut; the world it is claimed to model lies in part outside the cut; the relation from cut to world is not internal to the cut; the substrate's behaviour on the cut underdetermines its correct account of the off-cut domain. The foreclosure theorem of §3 is the formal statement of what the lens has now traced through reference, rule, inference, indeterminacy, and the formal limits of definability. The second lens turns the same structure into measure-theoretic form and gives the field's own statistical apparatus the chance to confirm the result on its own grounds.


### 5. The statistical lens: the bridge from semantics to measure

#### 5.1 What the second lens does

This section runs the foreclosure theorem through the second lens, the measure-theoretic one. The point is to show that the same gap the philosophy of language identified is the gap the field's own statistical apparatus operates over. In plain terms: the loss function the system is trained to minimise is an integral against the data, and an integral does not care about what happens off the data; any extension of the system's behaviour to cases outside the data is equally good by the loss. This is a textbook measure-theoretic fact and the section states it as a proposition. The section then shows the proposition is the same fact as the foreclosure theorem in §3, restated in the field's working vocabulary, and confirms the prediction from inside the field's own world-model literature.

The first lens established the foreclosure structure through the canonical resources of reference (Frege, 1892; Putnam, 1980; Kripke, 1982; Sellars, 1956; Searle, 1980; Carnap, 1928; Quine, 1960) and the formal limits of definability from inside (Tarski, 1936; Gödel, 1931); the second lens restates the same structure in the measure-theoretic terms in which the field's own statistical apparatus operates. The transit is required because the field's positive claims are framed as claims about distributions, training, and generalisation, and the argument has to enter that frame to be felt as an immanent critique rather than as a foreign objection. The lens proceeds in four steps: the formal restatement of the foreclosure condition in measure-theoretic terms, the support-invariance proposition that closes the lens, the identification of that proposition with the foreclosure condition of §3, and the confirming experiment supplied from inside the field's own positive-result literature.

#### 5.2 Effective support, not nominal support

The translation requires one preliminary distinction the field's own working practice already presupposes. Let the substrate be a learner trained on a sample drawn from a probability distribution *P* over the domain *D*; let *μ* be the measure *P* induces on *D*. The *nominal support* of *μ* is the closure of the set of points carrying positive measure under *μ*; in any continuous-space setting nominal support can be the whole space, since the density is positive almost everywhere a single observation might land. The cut, in measure-theoretic terms, is not nominal support but the *effective support*: the region in which the density is, in operational terms, not negligible at the resolution at which the learner discriminates and acts. The terms "in-distribution" and "out-of-distribution" are not casual labels in the field's working practice; they presuppose a distinction the formal language requires, and the present argument takes them at the field's word. The effective support is the cut; the off-cut region of measure is the off-cut region of the domain in §3.

#### 5.3 The support-invariance proposition

With effective support fixed, the lens's central proposition follows by a standard measure-theoretic argument. Let *L* be a loss functional defined as an integral of a pointwise loss against the data distribution *μ*; let *f̂* be the minimiser of *L* over a class of candidate functions; let *f̂'* be the corresponding minimiser when *f̂* is altered arbitrarily on a set of *μ*-measure zero. Then *L*(*f̂'*) = *L*(*f̂*), because the integral does not register changes on null sets; the off-support behaviour of the minimiser is undetermined by the loss; any extension of *f̂* to the off-support region that preserves the on-support behaviour is a minimiser of *L*. The proposition is unsurprising in form and inescapable in consequence: optimisation on a distribution does not discipline off-distribution behaviour.

**Proposition (Support-invariance).** *Let L be an objective of the form L(f) = ∫_D ℓ(f(x), y(x)) dμ(x), and let f̂ minimise L. For any extension f̂' of f̂ that agrees with f̂ μ-almost everywhere on the effective support, L(f̂') = L(f̂). The minimiser of L is unique only up to alteration on the off-support set.*

The proposition is the measure-theoretic translation of the underdetermination structure encountered in §4. There the cut was the body of sentences (Putnam, 1980), the perceptual record (Quine, 1960), or the finite list of applications (Kripke, 1982); here the cut is the effective support of the training measure; the off-cut region is the off-support set; and the substrate's behaviour off-support is undetermined by the loss whose minimisation defines the substrate. The cases at which the off-support behaviour is consequential are the cases at which the claim made on the substrate's behalf extends to the off-support region; those are the cases the foreclosure theorem governs. The continuous case Kripke (1982) treated discretely under the rule-following heading is here the continuous case made exact in measure-theoretic dress.

#### 5.4 The identification with the foreclosure condition

The identification is exact and is stated as a corollary. Let *f̂* be a substrate trained to minimise a loss on a distribution *μ*; let an off-support element *d* be consequential under the claim Λ that the substrate's competence extends to *D*. By the support-invariance proposition, there exist two extensions *f̂'* and *f̂''*, both minimising *L*, differing at *d*. The two extensions stand in the relation of Theorem 1: they are indistinguishable to the substrate's operational criterion, and they disagree on *d*. The argument has now encountered, for a second time, the same form of insufficiency the semantic lens established (Frege, 1892; Putnam, 1980; Kripke, 1982; Quine, 1960); the recurrence is the structural one.

The consequence is sharp on its own grounds. The standard remedies the field has proposed for off-distribution behaviour cannot, by the form of the proposition, address the gap. Scale enlarges the substrate's capacity but does not address its objective; the objective remains an integral over the support, and the minimiser remains undetermined off-support. Distillation, fine-tuning, and reinforcement from feedback adjust the substrate's behaviour on the support; they do not introduce information about the off-support region the support does not contain. The remedies operate at the level the proposition forecloses: they refine the cut, they do not constitute the relation from cut to domain.

#### 5.5 The confirming experiment from inside the literature

The empirical face of the proposition is supplied by the field's own world-model literature. Recent work on video-trained models of physical dynamics reports that the systems succeed strikingly on configurations resembling those of the training distribution, fail consistently on configurations outside it, and generalise by reverting to the nearest in-distribution configuration rather than by applying the law that would extend across the support boundary; the failure pattern is the pattern the support-invariance proposition predicts, at the place the proposition locates the failure, with the inefficacy of scale the proposition derives [D-23]. The argument requires only the structural finding: the failure is nearest-training-neighbour reversion rather than lawful extension; the failure is consistent across scale; the failure is the off-support gap the proposition forbids the objective to close.

The experiment is included as confirmation, not as load-bearing premise. The proposition stands on the formal argument from the loss integral; the experiment is the field's own apparatus producing the prediction the proposition derives. The status of the citation is the status the paper's apparatus assigns: the empirical claim is conditional on the specific result; the structural claim is the load-bearing claim, and the structural claim stands on the proposition.

#### 5.6 The world-model programme as the central case

The lens's strongest application is to the world-model programme itself, the programme of building learners that recover the dynamics of the physical world from observation. The programme is sold as the line of attack on the foreclosure problem: where language models operate on linguistic traces, world models are taken to operate on the world's behaviour directly, and the cut is taken to approach the world. The proposition forecloses the line on its own grounds. A model trained on video is trained on a sample of trajectories the world produces; the sample is the cut; the regions of physical configuration space not sampled are the off-cut; the model's behaviour off-sample is undetermined by its objective. The world-model programme inherits the foreclosure structure from the cut/world distinction the camera-and-carving figure of §4.9 fixed: the model receives the camera-image of dynamics, not the dynamics themselves; the relation between the recorded trajectory and the law that produced it lies, by the proposition, off the support the objective sees.

#### 5.7 The identifiability result that smuggles a world-relation

The lens closes by considering, for the discipline of immanent critique, the field's strongest positive result on the question of grounding. Recent identifiability theorems in the self-supervised and joint-embedding traditions establish that, under stated conditions, the true latent variables underlying observed data are recoverable up to a small set of permitted ambiguities [D-24]. The result is taken in the relevant literature as evidence that representational learning, given enough data and the right architecture, recovers the structure of the world it is trained on. The structural reading the present argument requires is that the result's force depends on its conditions, and the conditions are not innocent.

A representative result of this kind requires assumptions about the latent dynamics: that the latent process is a specified diffusion or has a particular mean-reversion structure (the Ornstein-Uhlenbeck case is canonical), or that the latent distribution lies in a specified parametric family [D-24]. The recovery follows from the conditions; without the conditions, the recovery fails; the theorems are stated honestly in this form. The structural reading of the conditions is the reading the present argument requires. A condition on the latent dynamics is not a property the learner discovers from the data; it is a property the learner is told to assume about the world the data come from. A projectile under gravity is not Ornstein-Uhlenbeck; an explosion is not mean-reverting; a phase transition is not Gaussian. The condition that licenses the identifiability is a substantive claim about the world, supplied from outside the data, and the recovery is the recovery of what the claim already encodes. The identifiability result is, in the structural sense the foreclosure theorem requires, a result of the form: given a substantive assumption A about the world, the data permit recovery of the world's structure consistent with A. The assumption is the world-relation; the data alone do not supply it; the result confirms the proposition rather than overturning it.

The argument has now encountered, for a third time inside the statistical lens, the same form of insufficiency. The first encounter was the support-invariance proposition itself; the second was the world-model programme's symptomatic failure [D-23]; the third is the field's own positive identifiability results carrying their world-relation in the assumptions that license the result [D-24]. The lens has reached the same structural finding as the semantic lens (Frege, 1892; Putnam, 1980; Kripke, 1982; Tarski, 1936; Gödel, 1931; Sellars, 1956; Searle, 1980; Carnap, 1928; Quine, 1960), by an entirely independent route through the measure theory the field itself relies on. The third lens, formal and cybernetic (Ashby, 1956; Conant and Ashby, 1970), closes the convergence.


### 6. The formal lens: the conditions of the act of regulating

#### 6.1 What the third lens does

This section runs the foreclosure theorem through the third lens, the cybernetic one. The point is to show that what cybernetics has been saying about regulation since the 1950s is the same point the other two lenses have been making: a regulator can only handle a system whose variety it can match, and a regulator built from a training cut has the variety of the cut, not of the world. The section uses two results, both standard: Ashby's Law of Requisite Variety, which says a regulator must have at least as many distinct internal states as the system it regulates, and the Conant-Ashby theorem, which says that to regulate a system the regulator must contain a model of it. The section then shows that the field's own positive identifiability results carry the same point in disguise: they recover the world only when the conditions that license the recovery have already been assumed, which is to say the world has been supplied from outside the data.

The first lens passed the foreclosure structure through reference (Frege, 1892; Putnam, 1980; Kripke, 1982; Sellars, 1956; Searle, 1980; Carnap, 1928; Quine, 1960; Tarski, 1936; Gödel, 1931); the second through measure (the support-invariance proposition); the third passes it through the formal results that govern what it takes for a system to regulate another system at a specified resolution. The resources are again from inside the relevant canon: Ashby's *Introduction to Cybernetics* (Ashby, 1956) and the theorem of Conant and Ashby (1970). The lens establishes that the field's own positive concept of generalisation, the concept by which a system trained on a cut is said to extend its competence to the domain, presupposes a model-of-the-world relation that the cut does not contain. The argument runs through three results: the Law of Requisite Variety (Ashby, 1956), the Conant-Ashby theorem (Conant and Ashby, 1970), and the scope conditions of the identifiability results ([D-24]), each shown to carry the same structural commitment.

#### 6.2 Ashby: the Law of Requisite Variety

Ashby's Law (Ashby, 1956, p. 207) states the formal condition for regulation: a regulator can hold a system within an acceptable set against disturbances only if the regulator's variety, the count of distinct internal states it can adopt, is at least equal to the variety of the disturbances against which it must regulate. The Law is presented in Ashby (1956) with the table-of-disturbances demonstration: an arrangement of disturbance values across rows and regulator responses across columns shows that the regulator must have at least as many distinct response settings as the disturbance has distinct values, or some disturbance value is met by an inadequate response, and the system leaves the acceptable set. The result is, in Ashby's (1956) own formulation, "only variety can destroy variety"; the form is a conservation principle on the resolution of regulation. The requisite variety can be matched in two ways: by amplifying the regulator, supplying it with more distinct responses, or by attenuating the system, reducing the variety it presents (Beer, 1974); the engineering arts of regulation have always operated in both directions.

The Law's relevance to the present argument is the relevance of variety to the cut/domain relation. A substrate that has been trained on a cut has, at most, the variety the cut supplies; the variety of the disturbances it will encounter in deployment is the variety of the domain; the disparity between the two is the disparity between cut and domain. The Law gives the formal consequence: the substrate cannot, by Ashby's (1956) own argument, regulate against disturbances whose variety exceeds the variety it has internalised from the cut, and any such disturbance falls outside the substrate's resolvable distinctions. The substrate's competence on the cut, however refined, supplies a variety bounded by the cut; the variety of the domain is not bounded by the cut; the Law forecloses the substrate's regulation of the off-cut domain on its own resources.

#### 6.3 Conant-Ashby: every good regulator must be a model

The Conant-Ashby theorem (Conant and Ashby, 1970, *International Journal of Systems Science* 1(2), pp. 89–97) sharpens the Law's lesson into the form the present argument requires. The theorem states that every regulator that holds a system optimally within an acceptable set must, in a formal sense the paper makes precise, be a model of the system it regulates: its internal states must be in a homomorphic correspondence with the states of the system, and its transitions must mirror the system's transitions at the resolution the regulation requires (Conant and Ashby, 1970). The argument is internal to the formal apparatus of regulation; it shows that the requisite variety is, more than a quantity, a structural correspondence: the regulator does not only contain enough internal distinctions, it contains *the right* internal distinctions, organised in the way the system's own dynamics organise their states. The result is a theorem in the discipline's own formal language, derived from the conditions of optimal regulation themselves.

The relevance to the foreclosure structure is exact. A substrate that is to govern a domain must, by Conant-Ashby (1970), be a model of the domain at the resolution the governance requires; a substrate that has been trained on a cut is, at most, a model of the cut; the cut is a model of the domain only if the relations between cut elements and domain elements are themselves contained in the cut, which by Theorem 1 is precisely what the cut cannot contain. The substrate's competence on the cut does not by itself constitute it a model of the domain; the model-of-the-domain relation is the off-cut remainder Theorem 1 forecloses; the Conant-Ashby theorem (1970) confirms, from inside the cybernetic apparatus, that this remainder is what optimal regulation requires.

#### 6.4 Identifiability and the conditions that license recovery

The same structure appears in the field's positive identifiability results when their scope conditions are read as the apparatus they are. A theorem of identifiability, as §5.7 noted, recovers the true latent structure of a process from observations of that process under stated assumptions about the latent dynamics [D-24]; the recovery follows when the assumptions hold and fails when they do not. The scope conditions are not, in the formal sense the discipline uses, optional; they are the conditions under which the theorem applies, and the recovery is the recovery of structure consistent with them.

Read through the Conant-Ashby (1970) lens, the scope conditions are the model-of-the-system the identifiability machinery requires. The condition that the latents are Ornstein-Uhlenbeck is the assumption that the system's dynamics belong to a specified family with stable, mean-reverting behaviour; the condition that the distribution is in a specified parametric class is the assumption that the system's variation is constrained in a specified way. These assumptions are, in the cybernetic sense (Ashby, 1956; Conant and Ashby, 1970), the regulator's model of the system: they specify the resolution and structure the apparatus presupposes about the world the data come from. When the assumptions hold, the identifiability machinery recovers the latent structure consistent with them; when the assumptions fail, the recovery fails because the model the machinery presupposed of the system does not match the system. The argument has now encountered, for a third time across the lenses, the same form of insufficiency: a substrate that proposes to recover the structure of a domain by operating on a cut succeeds only when a relation between cut and domain has been supplied from outside the cut.

### 7. The convergence of the three lenses

This section closes Part II. The three lenses of §§4-6 have established the same fact from three different canons. This section says what that means. The three are not three loose analogies that happen to land in the same place; they are three statements of one structural fact, and the section lands the structural statement Part II has been building toward. §10 in Part IV will then prove formally, drawing on Lawvere (1969) and Yanofsky (2003), that the three lenses are instances of a single categorical theorem; this section states what the proof in §10 will be the proof of.

The three lenses now stand together and the convergence calls for the structural statement the paper has been building toward.

The semantic lens established that the relation of reference (Frege, 1892), the rule (Kripke, 1982), the inferential role (Sellars, 1956), the conditions of symbol manipulation (Searle, 1980), the indeterminacy of translation (Quine, 1960), and the formal limits of definability (Tarski, 1936; Gödel, 1931) all show that the cut of expressions, applications, or sentences does not contain the world-relation that fixes the correct account on the off-cut domain. The statistical lens established the same fact in measure-theoretic form: an objective that integrates against the data distribution does not discipline behaviour on the off-support set, and the field's own positive identifiability results carry their world-relation in the assumptions that license the recovery [D-23]. The formal lens established the same fact through requisite variety (Ashby, 1956) and the Conant-Ashby theorem (Conant and Ashby, 1970): the variety the cut supplies is insufficient to the domain's variety, and the model-of-the-domain relation the regulation requires is precisely the off-cut remainder.

The three findings are not three analogous results that happen to share a slogan. They are three formal statements of one structure, derived from three independent canons, agreeing on the same elements. The cut in each case is the substrate's operational base; the off-cut remainder in each case is the domain element whose correct account the claim made on the substrate's behalf requires; the relation from cut to off-cut remainder in each case is what the cut does not, by the result of that lens, contain. The three lenses are in a structural correspondence with one another; the correspondence is exact and is reached in §10, where the formal identity of the three is shown to follow from a single fixed-point argument (Lawvere, 1969; Yanofsky, 2003). The convergence at this point is the empirical claim about the lenses; §10 will be the theoretical statement that the empirical claim is not coincidence.

The structural landing of Part II is the statement the three lenses now license. *Foreclosure is one structure proved three times over inside the canons of reference (Frege, 1892; Putnam, 1980; Kripke, 1982; Sellars, 1956; Searle, 1980; Carnap, 1928; Quine, 1960; Tarski, 1936; Gödel, 1931), measure (the support-invariance proposition; [D-23]), and regulation (Ashby, 1956; Conant and Ashby, 1970).* The substrate that operates on a cut cannot, on the strength of that operation alone, certify a correct account of an off-cut domain whose competing extensions are indistinguishable to it; the claim made on the substrate's behalf, when unrestricted to the cut, is unsupported by the substrate's operation; and the field's own apparatus, in three independent forms, has been encountering and stating this fact. The first wall stands. The paper now turns to the two walls that govern the temporal behaviour of deployed substrates: the wall of compounding hazard, which governs the law of motion of the failure rate (Williams, 1991, §12.15; Lévy, 1937), and the wall of horizon-mismatch, which governs the relation between the agent's evaluation horizon and the system it acts upon (Chen, 1999; Ashby, 1956; Conant and Ashby, 1970).


## Part III. The Two Temporal Walls

### 7. The wall of compounding hazard

This section states and proves the second wall. The first wall is about what a system can reach. The second wall is about what happens to a system over time once it is deployed. In plain terms: if a system makes the same kind of mistake at the same rate forever, then deploying it long enough will produce that mistake a lot of times, however small the rate is; and if the rate goes down each time the mistake occurs, so that the mistake suppresses itself, then it only happens a few times. The section uses a textbook result from probability, the Borel-Cantelli lemmas, to make this dichotomy precise. The wall is then about which side of the dichotomy the deployed systems sit on, and the architectural premise of §7.2 settles it: the systems sit on the side where the rate does not respond to its own failures, and the lemma's conclusion follows.

#### 7.1 What the second wall governs

The first wall is a statement about what a substrate can reach at a single instant. The second wall is a statement about what happens to a substrate that is deployed, that is, that produces outputs repeatedly over a duration long enough for the rare to occur. The variable the wall governs is not the substrate's per-action probability of producing a catastrophic output; that probability can be, and in the systems under treatment is, very small. The variable is the law of motion of that probability under realised cost: whether the per-action probability on a given catastrophic mode falls in response to the mode actually producing a catastrophe, or whether the probability is stationary, that is, unchanged from one action to the next regardless of what the substrate has produced. The wall is established by the pair of Borel-Cantelli lemmas (Williams, 1991), with the divergent regime stated in the conditional form due to Lévy (Lévy, 1937; Williams, 1991, §12.15) that drops the independence assumption the classical second lemma requires.

#### 7.2 The architecture of deployment fixes the wall's premise

The wall's premise is supplied by the architecture of the systems under treatment, not by an external assumption about their hazard. A deployed language model, a deployed world-model agent, a deployed control system whose parameters are frozen between training runs produces, on each action, an output sampled by the substrate's stochastic procedure; the per-action probability that a given catastrophic mode is realised is, in the relevant operational sense, the same on the *n*-th action as on the first; the system does not, between actions, alter the architecture from which the sampling is drawn. The softmax that closes the autoregressive procedure assigns strictly positive probability to every token in its vocabulary (Goodfellow, Bengio, and Courville, 2016, §6.2.2.3, eq. 6.29); the per-action probability of a catastrophic output, however small, cannot be driven to zero on the strength of the architecture; the catastrophic mode is, in the rate-stationary sense, available on each action. The premise of the wall is this architectural fact: the substrate's per-action hazard on a consequential mode does not respond to that mode's realised catastrophes by being driven to zero, and the wall's conclusions follow.

The premise is to be read at the level of the deployed system's effective output distribution, not only at the level of the raw substrate's softmax. Production systems wrap the substrate in engineered safety layers; refusal classifiers, output filters, blocklists, ensembles of moderation models, and similar post-hoc apparatus alter the conditional probabilities of the substrate's outputs reaching the user. The wall's architectural premise applies to the conditional probability of a consequential catastrophic mode in the deployed output stream, after any such filtering. The objection that safety layers move the system out of the divergent regime is met by the same dichotomy Theorem 2 establishes: a layer that drives the conditional sum on the consequential mode to convergence places the deployed system in the convergent regime, by Borel-Cantelli's first lemma (Williams, 1991); a layer that suppresses the mode probabilistically without driving the conditional sum to convergence leaves the deployed system in the divergent regime, by Lévy's extension (Lévy, 1937; Williams, 1991, §12.15). The argument does not turn on whether the substrate is wrapped or unwrapped; it turns on whether the effective deployed hazard on the consequential mode is stationary in the relevant sense, and the dichotomy is the same.

#### 7.3 The Borel-Cantelli dichotomy

The formal apparatus separates exactly two regimes. Let *E_n* be the event that the *n*-th action produces a catastrophe on the mode under consideration, and let *p_n* = ℙ(*E_n*) be the per-action probability. The first Borel-Cantelli lemma (Williams, 1991) states that if ∑ *p_n* < ∞, then ℙ(*E_n* infinitely often) = 0; the catastrophes are almost surely finite in number. The second lemma, in the conditional form due to Lévy (Lévy, 1937; Williams, 1991, §12.15), states that if ∑ ℙ(*E_n* | ℱ_{n-1}) = ∞ almost surely, where ℱ_{n-1} is the σ-algebra of the history through action *n*-1, then ℙ(*E_n* infinitely often) = 1; the catastrophes are almost surely infinite in number. The conditional form is essential and is the form the present argument requires: independence among the *E_n* is not assumed, and in the relevant cases independence does not hold; the conditional form drops the assumption.

The dichotomy is the wall's structural finding. The behaviour of the deployment is one of two things, with no third: either the per-action probabilities, conditional on the history, sum to a finite quantity, in which case the realised catastrophes are almost surely finite (Williams, 1991); or they sum to an infinite quantity, in which case the realised catastrophes are almost surely infinite (Lévy, 1937; Williams, 1991, §12.15). The dichotomy is established without any assumption about the size of *p_n*; a very small probability that does not collapse on cost produces unboundedly many catastrophes; a substantial probability that collapses sharply on cost produces only a few. The wall's variable is the law of motion of the conditional probability, not its level.

#### 7.4 The theorem of compounding hazard

The wall is now stated as a theorem with three modes of deployment, each forcing a distinct form of the conclusion.

**Theorem 2 (Compounding Hazard).** *Let a substrate be deployed for an indefinite sequence of actions, with E_n the event of a catastrophe on a specified mode at action n, and p_n = ℙ(E_n | ℱ_{n-1}) the conditional per-action probability of the mode given the history.*

*(i) Recurrent case: if the mode admits unbounded repetition and ∑ p_n = ∞ almost surely, then almost surely the mode produces catastrophes infinitely often, by the Lévy form of Borel-Cantelli (Lévy, 1937; Williams, 1991, §12.15).*

*(ii) Terminal case: if the mode is terminal, that is, the deployment ends on the first realised catastrophe, and ∑ p_n diverges over the deployment's planned actions, then the probability that the deployment ends in catastrophe approaches one as the number of planned actions grows.*

*(iii) Replicated case: if the substrate is replicated across many simultaneous deployments and the mode is independently available in each, then the expected number of realised catastrophes across the replication, equal to the sum of the per-action probabilities across deployments and actions, grows without bound as the replication and the per-deployment duration grow.*

The three forms are the three deployment regimes the field's own systems occupy. A conversational assistant in continuous use is the recurrent case: the mode does not end the deployment, the deployment continues across many users and many actions, and the expected number of consequential outputs accumulates. An autonomous vehicle, an automated trading system, or any agent whose catastrophic mode ends the run is the terminal case: each deployment is a single trial against the cumulative hazard, and the probability of catastrophic termination approaches one as the deployment extends. A fleet of replicas across many simultaneous deployments is the replicated case: the expected count across the fleet grows linearly in the product of replicas and per-replica actions, and the variance of that count grows correspondingly. Theorem 2 says, formally, what the architecture commits its deployments to.

#### 7.5 The mode-indexed transformation

A regulator that is to make a difference to the wall's conclusion must transform the conditional probability *p_n* on the mode through the cost realised on that mode, and must do so in a way that depends on the mode's identity. The point is structural rather than rhetorical. A substrate that learns indiscriminately from each event, raising or lowering its outputs across the whole behavioural distribution, does not deform the per-mode hazard sharply enough to drive any single mode's conditional sum to convergence; the deformation is spread across modes, and the catastrophic mode remains in the divergent regime. The regulator that can make the difference is the regulator that, given a realised catastrophe on a specific mode, indexes the cost to that mode and reduces the conditional probability of recurrence on that mode sharply enough that the mode's *p_n* sum converges. The conditions under which this kind of mode-indexed transformation is in place, given a substrate frozen between training runs and patched on cycles separated by long intervals, are the conditions the third subsection of this section reaches. The mode-indexed transformation is not a property every regulator can claim; it is a condition the wall's first regime (Williams, 1991) requires.

#### 7.6 The laundering of the per-action figure

The wall's empirical face appears in the field's own headline safety figures. A statement that a system is, on a given evaluation, ninety-nine point nine per cent safe is a statement about a per-action rate measured against a curated evaluation set: the probability that a single action from the system on a single sampled input from the evaluation produces an unsafe output is the figure reported. The figure is, in the operational sense the field uses, a per-action quantity. The figure is then heard, by the regulatory, commercial, and public audiences for which it is supplied, as a guarantee about the system's deployed behaviour over a working lifetime: the system is taken to be reliably safe in operation (Goodfellow, Bengio, and Courville, 2016, §11.1, characterising the field's safety target as a per-example error rate on a fixed evaluation set). The two quantities behave oppositely under repetition. A per-action probability of 10⁻³ is a near-certainty of catastrophe over 10⁴ actions; the deployed lifetime of a continuously running assistant or an agentic system is several orders of magnitude longer. The laundering is not a deception in the rhetorical sense; it is a structural feature of how a quantity measured on a curated cut is presented in the language a deployment requires. The headline reports the figure that the architecture permits and the evaluation supports; the deployment carries the conditional sum the headline does not state.

The paper's framing of the second wall does not rest on the laundering claim alone. The architectural premise of §7.2 is sufficient: the substrate is frozen, the per-action probability on a consequential mode is, in the rate-stationary sense, available on each action, and Theorem 2 applies. If the curated figure is also recast as a lifetime guarantee, the gap between the per-action quantity and the deployed sum is the laundering (Goodfellow, Bengio, and Courville, 2016, §11.1). If the figure is honestly stated as a per-action rate and the audience hears it as a per-action rate, the wall still stands, because the deployed sum is still the deployed sum. The laundering is the symptom, not the cause; the cause is the architecture and the dichotomy Theorem 2 establishes (Williams, 1991, §12.15).

#### 7.7 The patch cycle: a conditional argument

The architectural premise of §7.2 already places the unpatched deployed substrate in the divergent regime of Theorem 2; the wall stands on the unpatched substrate by Borel-Cantelli's conditional form (Lévy, 1937; Williams, 1991, §12.15). The conditional argument of this subsection concerns a different question: whether the patch cycles the field actually operates move the deployed substrate out of the divergent regime onto the convergent one. The wall is not, in this sense, conditional; what is conditional is the field's claim to have escaped it.

The remedy the field has assembled for the wall's conclusion is the patch cycle: a realised catastrophe is recorded as an incident, a corrective update is prepared and tested against curated evaluation, and the update is deployed on a cycle separated from the incident by an interval of days, weeks, or months. The structural question is whether the patch cycle implements the mode-indexed transformation of §7.5 sharply enough to drive the catastrophic mode's *p_n* sum to convergence, or whether the apparent improvement is confined to the curated evaluation while the deployed conditional probability on the mode persists.

The structural condition for the convergent regime (Williams, 1991, first lemma) is sharp: the conditional sum on the mode, over deployed actions in the interval between patches, must remain bounded as the deployment continues. The condition is met if each patch drives the deployed probability on the mode toward zero with a sharpness sufficient to overcome the rate of new actions in the interval. The condition is not met if the deployed probability on the mode is reduced by an amount that fails the convergence criterion, or if the patch's effect is confined to the curated set on which it was tested and does not transfer to the deployment distribution, or if new modes of the same form appear at a rate that compensates for the patches applied to the old ones.

Whether deployed patch cycles meet this condition is an empirical question, and the deployment-record evidence to settle it is, in the present argument, conditional [D-26a]. The argument therefore states the patch case explicitly conditional: where the patch cycle implements the mode-indexed transformation sharply, the substrate moves to the convergent regime of Theorem 2 on the modes the patches address; where the patch cycle does not implement the transformation sharply, the deployed substrate remains in the divergent regime (Lévy, 1937; Williams, 1991, §12.15). The architectural premise of §7.2 establishes which regime the un-patched substrate occupies; whether the patch cycle moves the substrate out of it is the question the deployment data would settle, and the paper does not assert what the deployment data have not shown.

The compounding-hazard wall stands as a theorem about the law of motion of the per-action hazard under realised cost (Williams, 1991, §12.15; Lévy, 1937), with the architectural premise supplying the divergent regime for the unmodified substrate, and the patch cycle a conditional remedy whose efficacy is the empirical question the deployment data would settle [D-26a]. The wall does not depend on the laundering of the figure or on the empirical efficacy of the patch; it depends on the dichotomy Theorem 2 establishes and on the architectural fact that the per-action probability on the mode does not respond to cost on the strength of the architecture itself. The paper now turns to the third wall, which governs a variable Theorem 2 does not reach.


### 8. The wall of horizon-mismatch

This section states and proves the third wall. The first wall is about what a system can reach; the second is about what happens to it over time on a per-action basis. The third is about what happens when a system acts on something that takes a long time to recover. In plain terms: if a recommender system, an automated trader, an agentic AI acts inside an institution, a supply chain, an ecology, and the system can only evaluate its actions over minutes or days or weeks, then a slow thing that recovers over years is invisible to the system inside its window. Whether the slow thing is being maintained or being depleted looks the same to the system; it only knows what its evaluation window can see. So it acts on what the window shows and spends the slow thing without seeing what it spent. The section makes this precise by joining a textbook result from control theory, finite-horizon observability, to the Conant-Ashby theorem from cybernetics. The wall holds when the system's window is shorter than the slow thing's recovery cycle and the healthy and depleting states look the same inside the window.

#### 8.1 What the third wall governs

The second wall is established and stands as a theorem about the law of motion of a per-action probability under realised cost (Williams, 1991, §12.15; Lévy, 1937). The third wall governs a different variable, on a different temporal scale, and applies to a system in a different posture. It applies not to a substrate producing outputs against a curated evaluation but to an agent acting within a system whose state includes a slow variable; the agent's actions affect the slow variable; the slow variable replenishes on a characteristic time; the agent receives feedback on a horizon over which it evaluates its actions and updates its policy. The variable the third wall governs is the relation between the agent's evaluation horizon and the system's replenishment cycle. The wall holds when the horizon is shorter than the cycle and the sustainable and depleting states of the slow variable are not distinguishable inside the horizon. The wall does not depend on the second wall's variable; a system with perfect cost-collapsing hazard on each action can still sit on the wrong side of this wall, and the paper now establishes why.

#### 8.2 The architecture of the third wall

Five elements are required, each supplied by the operating arrangement of the systems the wall is to govern. An agent *A* acts in time, producing an action *a_t* at each time step; the action is taken with respect to a system *T*, whose state *x_t* the agent influences. The state contains a slow variable *s_t* whose characteristic time of replenishment is τ_*S*, that is, the time over which *s_t* recovers, partially recovers, or is consumed in response to the agent's actions. The agent's evaluation horizon is τ_*A*, the span over which its objective integrates the consequences of its actions and updates its policy; this is the operational horizon of the agent's feedback, set by the temporal discount in its reward, the rollout length of its planning, the look-ahead of its model, or the length of its training window. The wall's first hypothesis is τ_*A* < τ_*S*: the agent's horizon is shorter than the system's replenishment cycle. The wall's second hypothesis is the observational-equivalence hypothesis: the sustainable and depleting trajectories of *s_t* produce identical observation sequences within any window of length τ_*A*, and diverge only on scales τ_*S* and beyond.

The two hypotheses jointly capture the practical situation. An agent optimising over short horizons against a system replenishing over long ones is the standard operating arrangement of the systems the third wall governs: a recommender system tuned to short-horizon engagement metrics acting on a media ecology whose trust and informational health vary on cycles of years; an automated procurement system tuned to quarterly cost metrics acting on a supplier ecosystem whose stability is measured in years; an agentic AI tuned to within-episode reward acting on institutions, infrastructures, and ecologies whose replenishment cycles run into decades. The horizon mismatch is a feature of the deployment, not an accident of any particular system's tuning.

#### 8.3 The horizon bound, by finite-horizon observability

The first formal input is finite-horizon observability (Chen, 1999): a regulator whose feedback is confined to a window of length τ_*A* can distinguish two states of the regulated system only if the states produce distinct observation sequences within that window. The result is a standard one in linear system theory (Chen, 1999) and transfers to the present case without modification: the regulator's resolvable variety within its horizon is bounded by the distinctions its feedback supplies in that horizon; states observationally equivalent across the horizon are not in the regulator's resolved state space. The wall's second hypothesis, observational equivalence of sustainable and depleting trajectories within τ_*A*, places those states in the unresolved equivalence class; the agent's feedback does not, by the observability bound (Chen, 1999), separate them.

#### 8.4 The Conant-Ashby step, and the theorem

The second formal input is the Conant-Ashby theorem (Conant and Ashby, 1970): a regulator that holds a system in the acceptable set must be a model of the system at the resolution the regulation requires. The model must contain the distinction between sustainable and depleting states, since holding the system in the sustainable set requires the regulator to act differently in the two cases (Ashby, 1956; Conant and Ashby, 1970). The wall's two hypotheses jointly preclude this: by observability (Chen, 1999), the distinction does not enter the regulator's resolved state space; by Conant-Ashby (1970), a regulator whose model lacks the distinction cannot regulate the system at the resolution the distinction requires.

The third wall is now stated.

**Theorem 3 (Horizon-Mismatch).** *Let an agent A act on a system T containing a slow variable s_t with replenishment cycle τ_S, where the agent's evaluation horizon τ_A satisfies τ_A < τ_S, and where the sustainable and depleting trajectories of s_t are observationally equivalent within any window of length τ_A. Then the agent's feedback does not distinguish sustainable from depleting states of the slow variable (by finite-horizon observability; Chen, 1999), and any regulator built on that feedback lacks the distinction the Conant-Ashby theorem (Conant and Ashby, 1970) requires of a good regulator of T at the resolution sustainable/depleting; hence the agent cannot, on the strength of its own feedback, preserve the slow variable.*

The theorem composes two standard results. Observability (Chen, 1999) supplies the first bound; Conant-Ashby (1970) supplies the consequence; the wall's two hypotheses connect the two. The composition is the paper's own; the inputs are canonical (Ashby, 1956; Conant and Ashby, 1970; Chen, 1999).

#### 8.5 The order-of-magnitude mismatch

The hypotheses of the theorem are not abstract: in the cases the paper treats, the magnitudes separate by orders. An agent's evaluation horizon, set by the rollout length, the within-episode return, or the training-window length, is at most weeks and is typically minutes to hours. The replenishment cycle of an engineering culture is years to decades; of a supplier ecosystem, years; of an institutional trust, decades; of ecological buffer capacity, decades to centuries. The mismatch is not marginal; the agent's horizon is two to four orders of magnitude shorter than the cycles of the systems it is to govern. The order-of-magnitude statement is offered as common-knowledge orders of magnitude, not as precise measurements; the argument requires only that the cycles exceed the agent's horizon by enough to keep the sustainable and depleting trajectories indistinguishable within the horizon, which holds across the range of slow institutional, productive, and ecological processes the wall is to cover.

#### 8.6 Why the third wall is not the second wall

The two temporal walls are independent and the paper now states the structural reason in advance of the formal independence proof of §9. The second wall's variable is the law of motion of the per-action hazard under realised cost (Williams, 1991, §12.15; Lévy, 1937): whether the hazard responds to its own catastrophes by collapsing on the mode. The third wall's variable is the relation between the agent's evaluation horizon and the system's replenishment cycle (Chen, 1999): whether the agent's feedback can resolve the distinction sustainable/depleting. The two variables are different in kind and orthogonal in effect. An agent with a perfectly cost-collapsing hazard, that drives the per-action probability of catastrophe to zero on each realised cost, can still sit on the wrong side of the third wall if its evaluation horizon is shorter than the replenishment cycle of the slow variable it acts upon; the cost collapsing on each catastrophe does not, by itself, lengthen the horizon. An agent with no cost collapsing whatever, whose hazard is stationary in the second wall's sense (Williams, 1991, §12.15), can still sit on the right side of the third wall if its evaluation horizon exceeds the system's replenishment cycle; the stationary hazard does not, by itself, shorten the horizon. The two walls bite on different variables, and neither implies the other.

#### 8.7 The irreversibility distinction

The third wall is sharpened by the distinction between estimation and irreversible depletion. A regulator that fails to estimate the slow variable correctly within its horizon will, given enough time, observe the failure: when the slow variable crosses the threshold at which depletion becomes legible on a scale the horizon does reach, the regulator updates. The point of the third wall is that the observation is then too late: the slow variable is depleted, not mis-estimated; the resource is spent, not in error; the regulator's eventual update on the now-legible signal does not restore what has been consumed during the horizon over which the consumption was unresolved. The wall does not say the regulator will never see the depletion; it says the regulator will see the depletion only when the depletion has crossed into the longer cycle, and the regulator's update at that point cannot recover what the slow variable has already lost. The mismatch is between the cycle on which the resource is consumed (short, the horizon) and the cycle on which the consumption is legible (long, the replenishment cycle). The irreversibility is the gap between consumption and legibility.

The estimation/irreversibility distinction sharpens the wall against a standard line of objection. The objection runs: a regulator with a sufficiently rich state estimator, a Kalman filter or its modern equivalents, can extrapolate the slow variable from its short-horizon observations and so resolve the sustainable/depleting distinction without lengthening the horizon. The reply, which the wall's two hypotheses already foreclose, is that the extrapolation is itself bounded by the observability conditions of §8.3 (Chen, 1999): an estimator can extrapolate only what its observations within the horizon discriminate, and the wall's observational-equivalence hypothesis denies the estimator the discrimination it would need. A richer estimator does not see what no estimator in the class can see; the equivalence is in the observations, not in the apparatus that processes them. The objection has been pre-empted by the construction of the hypotheses.

#### 8.8 The world-model programme as the double-hit

The third wall returns the world-model programme to the centre of the argument under a second heading. The first wall foreclosed the world-model programme as a programme that learns the world from observation: the substrate operates on a cut of recorded trajectories, the law it would need to extend across the cut boundary is not in the cut, and the foreclosure stands (Frege, 1892; Putnam, 1980; Kripke, 1982; Quine, 1960; the support-invariance proposition; Ashby, 1956; Conant and Ashby, 1970). The third wall now strikes the world-model programme again, in a different role and at a different stage. Where the first wall struck the substrate at the moment of learning, the third strikes it at the moment of acting: a world-model deployed as an agent, optimising over its model-based rollouts of trajectory, operates with an evaluation horizon set by the rollout length; the rollout length is the agent's window into the consequences of its actions; institutional, infrastructural, and ecological systems on which a deployed agentic world model would act have replenishment cycles vastly exceeding the rollout length. The agentic world-model programme inherits the horizon-mismatch wall directly (Chen, 1999; Conant and Ashby, 1970); the foreclosure wall and the horizon-mismatch wall strike it independently.

The double-hit is the structural finding the third wall and the first wall together establish about the world-model programme: it forecloses as a programme of learning, by Theorem 1 and the support-invariance proposition; it horizon-mismatches as a programme of acting, by Theorem 3 (Chen, 1999; Conant and Ashby, 1970). The two walls strike at the two distinct stages of the programme's ambition. The independence proof of §9 will state this formally; the paper here states the structural fact in advance: the programme that takes itself to be the line of attack on the foreclosure problem inherits, in its agentic form, a second independent wall the foreclosure programme does not face.

#### 8.9 The human posture against the wall

The wall is sharpened by the contrast with a human regulator whose feedback is not confined to a short horizon. A human institution, a guild, a craft tradition, a discipline of professional practice carries the slow variable in its own continuity: the institution remembers what the slow cycle has been doing across decades because the institution itself replenishes on that cycle; its members are trained into the long memory that no within-episode observation supplies. The contrast is not a romantic claim about human cognition; it is the structural claim that the institution and the slow system are coupled on the slow cycle, while the agent and the slow system are coupled only on the agent's short cycle. The agent that replaces the institution is not, in any operational sense, the institution's continuation; it is the institution's replacement by a regulator that has no slow memory, on a substrate whose horizon is set by something other than the system's replenishment cycle. The replacement is structural, and the third wall (Chen, 1999; Conant and Ashby, 1970) is the structural consequence.

The third wall stands as a theorem on the relation between the agent's evaluation horizon and the system's replenishment cycle, established from finite-horizon observability (Chen, 1999) and the Conant-Ashby theorem (Conant and Ashby, 1970), with the observational-equivalence hypothesis fixing the application to the present case. The wall does not depend on the second wall's variable; the two walls are independent in the strict sense the paper now turns to prove. Part IV establishes the formal independence of the three walls and the identity, beneath the appearance of three results, of the structural fact the first wall states three times over (Lawvere, 1969; Yanofsky, 2003).


## Part IV. Independence, Identity, Boundaries

### 9. The independence of the three walls

This section proves that the three walls are independent of each other. The argument matters because the no-exit result the paper has been pointing toward depends on it. In plain terms: if the three walls were variations of the same underlying problem, then a repair to one of them might fix the others, and the field's existing toolkit would have more reach than the paper is claiming. The section shows that the three walls are genuinely separate, governing different variables, by constructing systems that fail on one wall while passing the others, in both directions, for each pair. The result is that a system failing all three walls at once, which is what the deployed systems do, needs three independent repairs and no current tool reaches more than one.

#### 9.1 What independence requires

The three walls have been established as theorems, each from its own resources, each governing its own variable. The first wall stands on the underdetermination canon (Frege, 1892; Putnam, 1980; Kripke, 1982; Quine, 1960) and the support-invariance proposition, with the formal lens running through Ashby (1956) and Conant and Ashby (1970); the second wall stands on Williams (1991, §12.15) and the Lévy (1937) conditional extension of Borel-Cantelli; the third wall stands on finite-horizon observability (Chen, 1999) joined with the Conant-Ashby theorem (Conant and Ashby, 1970). The paper now establishes that the three are independent of one another: that the satisfaction of any one wall's escape condition does not entail the satisfaction of either of the others, that the failure modes the three walls describe are distinct, and that the toolkit assembled to repair one wall does not, by that repair, reach the others. The form of the argument is the standard form for independence: it is shown that for each pair of walls there exist systems satisfying one and failing the other, in both directions, so that no relation of implication binds the pair. Three pairs of counterexamples close the argument.

#### 9.2 The independence statement

**Proposition (Independence).** *Let W₁ be the foreclosure wall, W₂ the compounding-hazard wall, W₃ the horizon-mismatch wall. The three walls are pairwise independent in the following sense: for each pair (W_i, W_j) with i ≠ j, there exists a system that satisfies the escape condition for W_i and fails on W_j, and a system that satisfies the escape condition for W_j and fails on W_i. Hence no escape from one wall implies escape from any other.*

The proof exhibits the required systems pair by pair.

#### 9.3 W₁ and W₂

*Forecloses, hazard-collapses.* A substrate trained on a cut that does not cover the domain, but equipped with a perfect mode-indexed correction such that the per-action probability on any catastrophic mode collapses to zero on the first realised catastrophe of that mode, satisfies W₂'s escape condition by Theorem 2 (Williams, 1991, first lemma), since the conditional probabilities sum after the first catastrophe; the substrate fails W₁ on every consequential off-cut element, since the foreclosure structure of Theorem 1 turns on the cut/domain relation and is not addressed by the rate dynamics.

*Hazard-stationary, cut-complete.* A substrate operating on a domain it fully covers but whose architecture leaves its per-action hazard on a consequential mode stationary, with cost not deforming the conditional probability on the mode, satisfies W₁ by hypothesis, since the cut contains the domain and Theorem 1's premise fails; the substrate fails W₂ by Theorem 2 (Lévy, 1937; Williams, 1991, §12.15), since the stationary per-action probability sums to infinity over deployment.

The two cases together show that the variables W₁ and W₂ govern are independent: a system can be foreclosing without being hazard-stationary, and hazard-stationary without being foreclosing.

#### 9.4 W₂ and W₃

*Hazard-collapses, horizon-mismatches.* The substrate of the first case of §9.3 fails W₃ if the slow variable of the system it acts upon has a replenishment cycle exceeding the substrate's evaluation horizon and the observational-equivalence hypothesis holds (Chen, 1999; Conant and Ashby, 1970). The hazard-collapsing substrate need not, by the rate-collapsing remedy, acquire a longer evaluation horizon; cost-collapsing on catastrophes within the horizon does not give the substrate visibility of the slow variable across the cycle on which it replenishes. The substrate satisfies W₂ and fails W₃.

*Horizon-matches, hazard-stationary.* An agent with an evaluation horizon exceeding the system's replenishment cycle, and observations distinguishing sustainable from depleting trajectories within that horizon, satisfies W₃ by the negation of Theorem 3's hypothesis; if the agent's architecture leaves its per-action hazard on a consequential mode stationary in the second wall's sense (Williams, 1991, §12.15), the agent fails W₂ by Theorem 2.

The two cases together show that the variables W₂ and W₃ govern are independent: the law of motion of the hazard does not determine the horizon-cycle relation, and the horizon-cycle relation does not determine the law of motion.

#### 9.5 W₁ and W₃

*Forecloses, horizon-matches.* A substrate that operates on a cut not covering the domain, deployed in a role where the system it acts upon replenishes on a cycle shorter than the substrate's evaluation horizon, satisfies W₃ and fails W₁. The foreclosure of Theorem 1 turns on the cut/domain relation at a single instant; it does not change with the substrate's horizon.

*Cut-complete, horizon-mismatches.* A substrate that operates on a domain it fully covers, deployed in a role where the system it acts upon replenishes on a cycle exceeding the substrate's evaluation horizon, satisfies W₁ and fails W₃ (Chen, 1999; Conant and Ashby, 1970).

The two cases together show that W₁ and W₃ are independent: a substrate's cut/domain relation does not determine its horizon-cycle relation.

#### 9.6 The no-exit result

The independence statement has a sharp consequence for the toolkit the field has assembled. The proposition can be restated as a constraint on repair: a single repair targeted at the variable W_i governs leaves the variables W_j and W_k governing W_j and W_k where they were. The consequences are stated as a numbered set.

1. Alignment, fine-tuning, and reinforcement from feedback, in their canonical forms, address the substrate's behavioural distribution and the law of motion of its per-action probabilities; they touch, at most, the variable W₂ governs (Williams, 1991, §12.15). Enlargement of the training distribution touches, at most, the variable W₁ governs. Extension of the evaluation horizon touches, at most, the variable W₃ governs (Chen, 1999).

2. A system that is foreclosing, hazard-stationary on consequential modes, and horizon-mismatched against the systems it acts upon, requires three independent repairs; no single intervention reaches more than one of the three.

3. The intersection of the three escape conditions, that is, the conditions under which all three walls have been escaped jointly, requires that the cut cover the domain, that the per-action probability collapse on cost in a mode-indexed transformation, and that the evaluation horizon reach the replenishment cycle of the slow variables in the systems acted upon, with the sustainable/depleting distinction observable within the horizon. The current systems do not occupy this intersection.

The no-exit result is the structural finding for repair: the toolkit reaches one variable at a time, the systems require three independent repairs, and no proposed repair the paper has examined addresses more than one of the variables the three walls govern.

### 10. The identity behind the three lenses of the first wall

This section deepens the first wall. §7 said that the three lenses of Part II converged on the same finding; this section shows that the convergence is identity, not just resemblance. The three lenses are formally the same theorem stated in three different mathematical settings. The result the section uses is the Lawvere fixed-point theorem, which Yanofsky has shown is the underlying structure of all the classical self-referential paradoxes (Cantor, Russell, Gödel, Tarski, Turing). The section shows that the three lenses of Part II are three more instances of the same structure. This does not collapse the three walls into one; only the three lenses of the first wall are unified here. The second and third walls govern different variables and remain independent, as §9 has just proved.

#### 10.1 What this section establishes

The semantic, statistical, and formal lenses of Part II established the first wall from three independent canons: reference (Frege, 1892; Putnam, 1980; Kripke, 1982; Sellars, 1956; Searle, 1980; Carnap, 1928; Quine, 1960; Tarski, 1936; Gödel, 1931), measure (the support-invariance proposition), and regulation (Ashby, 1956; Conant and Ashby, 1970). The convergence of the three was stated at §7 as a structural fact about the lenses. This section establishes that the convergence is identity rather than analogy: the three lenses are formally instances of one structure, which is the structure the Lawvere fixed-point theorem (Lawvere, 1969) makes precise and the uniform treatment of Yanofsky (Yanofsky, 2003, *Bulletin of Symbolic Logic* 9(3), pp. 362–386) shows to be the structure of all the self-referential paradoxes the discipline has formalised. The first wall is the standing of the same theorem in three categorical settings; the appearance of three results is the appearance of one result in three appropriate categories.

#### 10.2 The Lawvere fixed-point theorem

The Lawvere fixed-point theorem (Lawvere, 1969, "Diagonal arguments and cartesian closed categories") is stated for a cartesian closed category and an object *Y* with a fixed-point-free endomorphism *t* : *Y* → *Y*. The theorem (Lawvere, 1969) states that under these conditions there is no point-surjective map from any object *A* of the category to the function object *Y^A*; equivalently, no map *φ* : *A × A* → *Y* is universal in the sense that every map *A* → *Y* is recovered as a section of *φ*. The contrapositive is the form most directly useful to the paper: where a point-surjective representation of all maps *A* → *Y* is claimed to exist, no fixed-point-free endomorphism of *Y* exists; equivalently, the existence of such an endomorphism forecloses the representation. The theorem is a single result in category-theoretic form; the strength of the result is that the choice of category and the choice of *Y* and *t* recover each of the foundational self-referential paradoxes as an instance.

Yanofsky (2003) makes this strength explicit. Cantor's theorem is recovered (Yanofsky, 2003) by taking the category to be the category of sets, *Y* to be the two-element set with the swap endomorphism as fixed-point-free *t*, and the result is that no surjection exists from a set to its power set. Russell's paradox is recovered by an analogous choice (Yanofsky, 2003). Gödel's first incompleteness theorem (Gödel, 1931) is recovered by taking the category to be the category of formal systems with a suitable arithmetic structure, *Y* to be the truth values with a suitable endomorphism, and the result is that no consistent sufficiently strong system represents its own truth predicate (Yanofsky, 2003). Tarski's undefinability of truth (Tarski, 1936) is recovered analogously. Turing's halting problem is recovered with a different category (Yanofsky, 2003). The five results, classically presented as five different theorems, are instances of one categorical statement (Lawvere, 1969; Yanofsky, 2003). The discipline has been encountering, in the form of paradoxes about its own foundations, the Lawvere structure repeatedly; the recurrence has not been understood as recurrence until Lawvere (1969) stated the theorem and Yanofsky (2003) catalogued the instances.

#### 10.3 The three lenses as instances of one structure

The argument can now claim what §7 stated as convergence. The semantic lens through reference (Frege, 1892; Putnam, 1980; Kripke, 1982; Quine, 1960), the statistical lens through measure (the support-invariance proposition), and the formal lens through regulation (Ashby, 1956; Conant and Ashby, 1970) are not three analogous failures; they are three instances of the Lawvere (1969) structure, obtained by choice of category. The semantic lens treats the category in which the objects are languages and the maps are reference-fixing operations; the off-cut remainder Theorem 1 forecloses is the fixed-point-free element of the relevant *Y* (Lawvere, 1969; Yanofsky, 2003). The statistical lens treats the category in which the objects are measurable spaces with their distributions and the maps are loss-minimising procedures; the off-support set is the structurally analogous element. The formal lens treats the category in which the objects are regulators and systems, and the maps are model-of relations between them (Conant and Ashby, 1970); the model-of-the-domain remainder Conant-Ashby (1970) identifies as required is the structurally analogous element. The three lenses are the three categorical instantiations of one foreclosure result.

The same structure can be traced through a wider catalogue of foundational limits: the measurement problem in quantum mechanics, the arrow of time, the status of the continuum, the limits of effective procedures, wherever a framework's operative reach falls short of the domain it claims and the gap is structural rather than incidental. The wider cartography is beyond the scope of the present argument, which needs only what the three lenses have established and what the Lawvere-Yanofsky result (Lawvere, 1969; Yanofsky, 2003) certifies about them. What matters here is that the first wall's recurrence across the three lenses is identity, not resemblance: the claim of one structure across the three is a claim of fact about category-theoretic instantiation, not a loose figure.

#### 10.4 The two-tier asymmetry: the result and its instances

A clarification follows. The unification at the Lawvere (1969) level is the unification of the three lenses of the *first* wall. The independence proof of §9 establishes that the three *walls*, not the three *lenses*, are formally independent: the variable each wall governs is different, the failure mode each wall describes is different, and no escape from one wall implies escape from another. The two-tier structure is this: within the first wall, the three lenses are instances of one categorical theorem (Lawvere, 1969; Yanofsky, 2003); across the three walls, the variables and failure modes are independent. The unification at the lens level deepens the first wall's force; it does not reduce the three walls to one. The compounding-hazard wall (Williams, 1991, §12.15; Lévy, 1937) and the horizon-mismatch wall (Chen, 1999; Conant and Ashby, 1970) are not Lawvere-instances of the first; they are independent results on independent variables, established by their own theorems, sharing no fixed-point structure with the first wall.

### 11. Three honest boundaries

This section says what the paper is not claiming. The argument has just established three independent walls and proved the structural identity behind the first wall. Before moving on to Part V, the paper marks the limits of what it has shown. The three walls are not claims that intelligence is impossible, that all artificial systems forever cannot pass them, or that the systems are bad because they lack consciousness. They are claims about a specific operation, on systems built in a specific way, deployed in specific arrangements. Three boundaries are marked: the walls are operation-bounded, not impossibility claims; the walls do not rest on any premise about consciousness or experience; the walls do not apply to architectures whose premises they do not reach. The section is here to keep the paper honest about its own scope.

The argument has now reached its substantive conclusions. Before Part V takes up the genealogy, the convergence, and the deployment consequence, the paper marks three boundaries the argument does not cross.

#### 11.1 The argument does not claim the impossibility of intelligence

The walls are walls on a specified arrangement: a substrate operating on a cut, with the claim made on its behalf unrestricted to the cut, in deployments specified by the second and third walls' premises (Williams, 1991, §12.15; Chen, 1999). The walls do not claim that intelligent systems are impossible, that grounded reference is unachievable, that safe deployment is unachievable, or that long-horizon governance is unachievable. They claim that the systems built by the current paradigm, in the arrangements they currently occupy, meet the three walls' premises and therefore meet the three walls' conclusions. A system that escapes the walls is a system that does not meet the walls' premises: a system that includes the relation between cut and world in its operative substrate, that responds to realised catastrophe with mode-indexed transformation, that evaluates on horizons matched to the replenishment cycles of the systems it acts upon. Whether such a system can be built is not what the paper claims; that the systems currently called by these names do not, and on the strength of the paradigm's own resources cannot, do these things is what the paper claims.

#### 11.2 The argument does not depend on a phenomenological premise

The walls are stated in the structural language of the resources from which they are proved: underdetermination (Frege, 1892; Putnam, 1980; Kripke, 1982; Quine, 1960), measure (the support-invariance proposition), requisite variety (Ashby, 1956), the Borel-Cantelli dichotomy (Williams, 1991, §12.15; Lévy, 1937), observability (Chen, 1999). They do not depend on a premise about consciousness, experience, or any specifically human capacity. The structural reading of Searle (1980) in §4.7 was the reading that set the consciousness-dependent intuition aside and kept the structural point. The argument has been carried out at the formal level the resources permit; the conclusions follow without an appeal to what cannot be formalised. The argument is therefore not vulnerable to the standard objection that an external standard has been imported; the only standards used are the standards internal to the three canons the lenses pass through.

#### 11.3 The argument does not extend to all possible architectures

The walls are stated under the architectural premises supplied by the systems the paper treats. The foreclosure wall presupposes a cut-bound substrate; an architecture that does not operate on a cut, that reaches the world through embodied causal interaction rather than through a corpus, falls outside the wall's premise. The compounding-hazard wall presupposes a frozen-weight substrate; an architecture that updates on each action in a way that drives the conditional probability sum on the consequential mode to convergence (Williams, 1991, first lemma) falls outside the wall's premise. The horizon-mismatch wall presupposes an evaluation horizon shorter than the replenishment cycle (Chen, 1999); an architecture whose horizon is matched to the cycle falls outside the wall's premise. The walls are not claims about every conceivable system; they are claims about systems whose architectural premises match the systems in current deployment. The boundary is honest: the paper does not foreclose what its premises do not reach.

The three boundaries mark the limits of the argument's reach. Part V now turns to the genealogy that accounts for the field's blindness to the limits from inside (Shannon, 1948; Newell and Simon, 1976; Fodor, 1975; Dreyfus, 1972), the convergence of failure patterns across architectures that supports the paradigm-level cause, and the deployment consequence that follows from the three walls together.


## Part V. Genealogy, Convergence, Deployment

### 12. The genealogy of the bracket

This section answers a question the walls raise. The field's own canonical resources, philosophy of language, probability theory, cybernetics, are exactly what the paper has used to prove the three walls. If those resources have been sitting in the field for a century, how is the field deploying systems on which the walls bite without seeing the walls? The section's answer is genealogical: a methodological move Shannon made in 1948 for engineering reasons, the bracket that set semantic content aside as not part of the engineering problem, hardened in two stages. First into a metaphysical commitment (Newell and Simon, Fodor); then into the unstated background of the contemporary engineering culture, where the bracket is no longer argued for or against but simply taken for granted in how training data is described, how competence is evaluated, how grounding is treated. The section traces the two hardenings using only the field's own canonical sources.

#### 12.1 What the genealogy explains

The three walls have been established and their independence proved. A standing question remains: how a field whose own canonical resources establish each of the walls (Frege, 1892; Putnam, 1980; Kripke, 1982; Sellars, 1956; Searle, 1980; Carnap, 1928; Quine, 1960; Tarski, 1936; Gödel, 1931; Williams, 1991, §12.15; Lévy, 1937; Ashby, 1956; Conant and Ashby, 1970; Chen, 1999; Lawvere, 1969; Yanofsky, 2003) has come to deploy systems on which the walls bite jointly, and how the deployment is conducted as though the walls were not there. The paper's answer is genealogical: a methodological move made for engineering reasons at the foundation of the discipline hardened, in two stages, into a metaphysical commitment whose presence is now invisible to those operating inside it. The genealogy is given as an immanent reading of the discipline's own foundational texts; the resources are the field's own, and the line of descent is the line the field's own histories acknowledge.

#### 12.2 Shannon and the bracket

The bracket is supplied by Shannon (1948, "A Mathematical Theory of Communication", *Bell System Technical Journal*) at the opening of *A Mathematical Theory of Communication*: the semantic aspects of communication are declared irrelevant to the engineering problem, which is to be addressed at the level of the formal apparatus that transmits signals between sender and receiver (Shannon, 1948, p. 379: "Frequently the messages have meaning; that is they refer to or are correlated according to some system with certain physical or conceptual entities. These semantic aspects of communication are irrelevant to the engineering problem."). The declaration is, in Shannon's (1948) own framing, methodological: a deliberate restriction of the engineering problem to the formal apparatus, leaving the question of meaning aside as not in the scope of the result. The declaration is honest about its scope, and the engineering achievement that follows from it is the engineering achievement of a problem honestly bounded.

#### 12.3 The first hardening: from methodological bracket to metaphysical commitment

The methodological bracket hardens into a metaphysical commitment in the line that runs from the physical-symbol-system hypothesis through the language-of-thought tradition (Newell and Simon, 1976; Fodor, 1975, *The Language of Thought*). Newell and Simon's (1976) hypothesis treats the symbolic apparatus not as a bounded engineering domain but as the necessary and sufficient substrate of intelligent action; Fodor's (1975) language-of-thought thesis treats meaning itself as a relation among formal symbols, with the semantic relation to the world reducible to the relations among the symbols by which the world is represented. Shannon's (1948) bracket, in this hardening, is no longer a deliberate exclusion of the semantic from a bounded engineering problem; it is the assertion that the formal apparatus *is* what meaning consists in, that the formal substrate of symbolic operation is the substrate of cognition itself. Dreyfus (1972, *What Computers Can't Do*) is the contemporary critique of this hardening, addressed by name in the discipline's own foundational dispute. The first hardening is documented in the discipline's own histories (Newell and Simon, 1976; Fodor, 1975; Dreyfus, 1972); its consequences are documented in the dispute that ran from the 1970s to the 1990s and was, in the discipline's working sense, not resolved but bypassed.

#### 12.4 The second hardening: from metaphysical commitment to engineering background

The hardening that the present argument requires the genealogy to mark is the second one. The contemporary engineer training a language model or a world model is not, as a rule, reading Newell and Simon (1976), or Fodor (1975), or Dreyfus (1972), or Searle (1980), or the canonical philosophical literature on grounding (Frege, 1892; Putnam, 1980; Kripke, 1982; Quine, 1960; Sellars, 1956). The bracket inherited from Shannon (1948) is now neither methodologically held nor metaphysically defended; it is operative as the unstated background of the engineering culture, the implicit working assumption that the substrate's behaviour on its corpus is what its competence consists in, that adequacy to the trained distribution is adequacy to the world the trained distribution is a sample from, and that the question of grounding is either solved by adequacy to the distribution or is no longer a question the engineering practice needs to address.

The second hardening is the condition that makes the discipline's blindness to the three walls structurally invisible from inside. The first hardening was a position; the second hardening is a culture. A position can be argued against; a culture is the form of life in which arguments occur, the unstated standard by which arguments are heard. The bracket is now invisible because it has become the air in which the engineering work is done: training distributions are described as samples from the world; competence on the distribution is described as competence in the world; the gap between the two is described, when it is described at all, as a refinement problem rather than a structural foreclosure. The structural finding of Part II appears, from inside the second-hardened culture, as a complaint about something that has already been settled.

The two hardenings together explain what the genealogy needs to explain: the field's resources have been encountering the foreclosure structure for a century in the form of the philosophical canon of reference (Frege, 1892; Putnam, 1980; Kripke, 1982; Quine, 1960; Sellars, 1956; Searle, 1980; Carnap, 1928) and the formal canon of self-reference (Tarski, 1936; Gödel, 1931; Lawvere, 1969; Yanofsky, 2003) and identifiability; the field's working practice has been operating under a bracket (Shannon, 1948; Newell and Simon, 1976; Fodor, 1975) that obviates exactly the question those resources have been asking; and the result is a discipline whose engineering achievement is documented and whose blindness to the walls its own engineering achievement runs into is also documented. The convergence the next section establishes is the structural face of this blindness: the failures the walls predict appear across architectures because the bracket is the same across architectures.

### 13. The convergence across architectures

This section tests the structural claim of the first wall against the field's own empirical record. The wall is paradigm-level: it should bite the same way regardless of which architecture the substrate uses. If the same kinds of failure appeared in autoregressive language models but not in joint-embedding world models, or in diffusion models but not in transformers, then the cause would be architectural rather than structural, and the wall would be misidentified. The section asks what the cross-architecture record shows. The structural prediction stands on the support-invariance proposition of §5 alone; the empirical demonstration that the prediction is borne out is the cross-architecture comparison the field's own literature has produced. §13.2 separates the two layers so the reader can see what survives in each case.

#### 13.1 What the convergence shows

The first wall predicts that systems whose substrate operates on a cut will exhibit characteristic failures on the off-cut domain: nearest-cut reversion, lawful extension failure, scope-dependent identifiability, support-bounded competence. The prediction is architecture-independent in the structural sense; the wall does not turn on whether the substrate is autoregressive, diffusion-based, joint-embedding, transformer, or otherwise. If the failures appeared on one architectural lineage and not on others, the cause would be implementation-specific and the wall would be misidentified. The structural finding the present section establishes is that the failures appear across the architectural lineages the field has deployed, on the same kinds of tasks, with the same kinds of failure signatures; the cause is paradigm-level, not implementation-specific.

#### 13.2 The failure pattern across architectures

The same-task cross-architecture comparison is the test the structural finding requires. Where the test has been conducted on physical-reasoning tasks across joint-embedding world models, diffusion-based world models, and autoregressive world models, the failure pattern reported is the failure pattern the support-invariance proposition predicts at the place the proposition locates it: nearest-training-configuration reversion rather than lawful extension across the support boundary, with the inefficacy of scale the proposition derives [D-28]. The architectural diversity is the diversity the field's own positive literature documents; the failure convergence is the structural finding. The convergence is not asserted as universal across every architecture; it is asserted as documented across the architectures on which the comparison has been conducted.

The prediction the wall makes is the prediction the structural finding bears out. The architecture-independent face of the failure is the structural face of the bracket (Shannon, 1948; Newell and Simon, 1976; Fodor, 1975): the bracket is the same across architectures, the substrate operates on the cut in each, and the off-cut behaviour is undetermined by the objective in each. The failure that would have falsified the structural cause, divergent failure modes across architectures with each architecture revealing its own implementation-specific defect, has not appeared in the cross-architecture comparisons the literature has produced. The failure that the structural cause predicts has.

The evidentiary architecture of this section is to be made explicit. The convergence argument has two layers, and the two should not be confused. The first layer is the structural prediction the support-invariance proposition of §5.3 entails on its own resources: a paradigm whose substrates operate on cuts and whose objectives integrate against the support of those cuts will, by the proposition, exhibit the same off-support behaviour regardless of architectural details, because the proposition turns on the form of the objective rather than on the form of the substrate. The first layer is theoretical; it stands on the proof of the proposition, and the documented cross-architecture failure pattern is its prediction, not its premise. The second layer is the empirical demonstration that the prediction has been borne out across the architectures the field has compared, supplied by the same-task cross-architecture studies the paragraph above cites. The second layer's evidence is the entry [D-28] and rests on the existence and character of those studies. The two layers stand or fall together for the strong form of the claim (paradigm-level cause documented across architectures); the first layer stands alone for the weaker form (paradigm-level cause predicted by the proposition, with empirical convergence as the open empirical question). A reader for whom D-28 is unavailable or shows divergent rather than convergent failure signatures takes the weaker form; the proposition still predicts what the substrates will do, and the paradigm-level claim survives as a theoretical entailment of the proposition, with the field's apparatus the place where the prediction would be confirmed or refuted. The paper does not stake the structural argument on the second layer; it stakes the structural argument on the proposition, and offers the cross-architecture convergence as the empirical face the proposition predicts.

#### 13.3 The benchmark gap

The benchmark gap is the structural face of the failure on the curated/consequential distinction. The field's evaluation apparatus is a curated set of cases; performance on the set is the figure reported; performance on the deployed distribution diverges from the curated figure in proportion to the gap between the curated set and the deployed distribution; the field's own canonical reference characterises the bridging assumption as the i.i.d. condition between training and test, and concedes that without it "there is indeed little we can do" (Goodfellow, Bengio, and Courville, 2016, §5.2). The curated/deployed gap is the operational regime in which the bridging assumption does not hold. The divergence is, again, what the support-invariance proposition predicts: the objective is optimised on the curated support, the deployed support is not the curated one, and the substrate's behaviour on the deployed-but-not-curated region is undetermined by the objective. The field's own apparatus is in a position to confirm this from inside its own working practice; the benchmark literature documents the gap that the structural finding predicts.

### 14. The deployment consequence

This section takes the three walls together and asks what they say about the systems actually in the field. The walls are theorems; their conclusions follow from their premises. The architectural facts about deployed systems, that they are trained on fixed bodies of data, that their weights are frozen between training runs, that their evaluation windows are short compared to the institutions they act on, are the premises. So the conclusions follow: foreclosure, compounding hazard, horizon-mismatch, all three at once, on the systems now being deployed. The argument is not empirical in the sense that it depends on catastrophes already observed; it is structural in the sense that the architectural premises are met by the systems' own design. The section also marks the seam clearly: the theorems are proofs; the claim that today's systems meet the premises is a claim about architecture, checkable from the systems' own design documents.

#### 14.1 What the deployment consequence states

The deployment consequence is the structural finding the three walls together establish about the systems in current deployment. The argument from theorem to deployment is the argument from the architectural premises supplied by the deployed systems, through the three theorems, to the conclusion. The architectural premises are: a cut-bound substrate, frozen weights between training runs, an evaluation horizon shorter than the replenishment cycles of the slow systems the substrate acts upon. By the architectural premises, the substrate sits within the premises of the three theorems. By Theorem 1, the substrate forecloses on its consequential off-cut domain (the underdetermination canon: Frege, 1892; Putnam, 1980; Kripke, 1982; Quine, 1960; the support-invariance proposition; Ashby, 1956; Conant and Ashby, 1970). By Theorem 2 (Williams, 1991, §12.15; Lévy, 1937), the substrate's deployment in the recurrent, terminal, or replicated regime accumulates catastrophes whose conditional sum diverges. By Theorem 3 (Chen, 1999; Conant and Ashby, 1970), the substrate's agentic action on slow-cycling systems does not preserve the slow variable. The deployment consequence is the structural fact that the systems now in deployment meet the premises of all three theorems simultaneously, and therefore meet the conclusions of all three theorems simultaneously.

#### 14.2 The seam between theorem and architectural premise

A line must be drawn here that the argument has been careful to keep visible. The three theorems are theorems; they hold of any system whose premises are met, and the premises are stated in formal terms. The deployment consequence is a claim about the systems now in deployment: that the premises are met. The first claim is mathematical and is settled by the proofs. The second claim is architectural and is settled by the architecture: the systems are cut-bound by construction, the weights are frozen by construction, the evaluation horizon is set by the rollout length or the within-episode return and is short by construction. The architectural claims are checkable from the systems' own design documents; they are not empirical findings about catastrophes that have already occurred. The deployment consequence stands on the architectural fact that the premises are met, not on the empirical fact that the conclusions have been observed.

#### 14.3 The confessions of the field

The field's own deployment documentation supplies the empirical face of the consequence in the form it can supply. Long-tail fragility on consequential cases is documented in the safety reports and limitations sections of the systems' technical documentation; human labelling dependence is documented as a structural feature of the training apparatus; confident-error failure modes are documented as a recurrent issue in the evaluation literature [D-30]. The documentation is not empirical evidence of the conclusions in the strong sense the theorems would not need; it is the field's own acknowledgement, in its own working language, that the architectural arrangements the theorems take as their premises have the consequences the theorems predict, on the systems the field itself deploys and documents.

#### 14.4 The structural landing

The deployment consequence stands as the structural finding of Part V: the systems now in deployment meet, by their architecture, the premises of all three walls; they therefore meet, by the theorems of Parts II and III, the conclusions of all three walls; they foreclose on their consequential domain (Frege, 1892; Putnam, 1980; Kripke, 1982; Quine, 1960; Ashby, 1956; Conant and Ashby, 1970), they accumulate catastrophes whose conditional sum diverges (Williams, 1991, §12.15; Lévy, 1937), and they fail to preserve the slow systems on which they are deployed to act (Chen, 1999; Conant and Ashby, 1970). The field's own positive literature documents the failure pattern across architectures that the structural cause predicts [D-28]; the field's own deployment documentation acknowledges the long-tail fragility, the labelling dependence, and the confident-error modes that the architectural premises require [D-30]. The argument does not depend on additional empirical findings; it depends on the architectural premises being met, and the premises are met by the systems' own design. The paper now turns to the falsifiers, the boundaries the argument does not claim, and the conclusion.


## Part VI. Escape Conditions, What the Paper Does Not Claim, Conclusion

### 15. Escape conditions and falsifiers

This section says what would have to be true for the paper to be wrong. The author's commitment is that the paper writes only what it sees, and is willing to eat its words if a wall turns out to be false. To make that commitment usable, the section states, for each wall, the specific finding that would falsify it: what the falsifying result would have to look like, what it would have to demonstrate, and where it would have to be found. Stating the falsifiers explicitly does two things: it keeps the argument honest against future evidence, and it forecloses the move where a wall is "always true no matter what" by definition. The walls stand on their proofs; the falsifiers state the conditions of their defeat.

#### 15.1 What this section supplies

The argument's discipline requires, for each wall, the conditions under which the wall would not hold; the conditions are the falsifiers, and they fix what would have to be true for the paper's structural conclusions to be wrong. The falsifiers are stated as a numbered set, one for each wall, with the condition the falsifier would have to satisfy in order to count, and with the empirical or formal locus at which the falsifier would be found. The discipline of falsifier-statement is the discipline by which the argument keeps itself honest against the future: the conclusions are committed to the conditions of their own defeat, and the paper does not claim what the conditions of its own defeat have not foreclosed.

#### 15.2 The falsifier of the foreclosure wall

The first wall would be falsified by a substrate that, while operating on a cut, certifies a correct account of an off-cut consequential element on which two cut-indistinguishable extensions of the world disagree, where the certification is achieved on the substrate's resources alone, without supplying from outside the cut the information that resolves the disagreement. The condition the falsifier must meet is that the resolution be achieved without smuggled world-relation; the identifiability literature's scope conditions, for instance, are not falsifiers [D-24], because the resolution they achieve depends on the assumption that licenses the recovery (Ashby, 1956; Conant and Ashby, 1970, on the model-of relation that the recovery presupposes). The locus at which the falsifier would be found is a result demonstrating support-invariance failure: a learner whose minimiser is uniquely determined by the loss on the cut, including on the off-support set, by means internal to the loss. No such result has been demonstrated; the structural form of the proposition forbids it for objectives of the integral form §5.3 specifies; a falsifier would require a different form of objective whose minimiser is not a measure-zero equivalence class, and the discipline of immanent critique then requires the falsifier to show that the new objective is the field's working objective rather than a redescription. The canonical underdetermination results (Frege, 1892; Putnam, 1980; Kripke, 1982; Quine, 1960) supply the structural form against which any falsifier would have to work.

#### 15.3 The falsifier of the compounding-hazard wall

The second wall would be falsified by a deployed substrate whose conditional per-action probability on a consequential catastrophic mode, given the history of realised catastrophes on that mode, is shown to sum to a finite quantity over the deployment, where the sum is over the deployed action sequence and not over the curated evaluation set (Williams, 1991, first lemma). The condition the falsifier must meet is two-fold: the conditional sum must be measured on the deployed distribution rather than the curated one, and the consequential mode must be the mode the paper's argument tracks rather than a mode that has been redefined by post-hoc partition. The locus at which the falsifier would be found is the deployment-record evidence the patch-cycle argument of §7.7 cites as conditional [D-26a]: a substrate whose patch cycle is shown to drive a specific mode's deployed conditional sum toward convergence is a substrate in the convergent regime, and the wall does not bite on it. The data to establish this would have to be longitudinal, mode-specific, and deployed rather than curated; the paper's framing of the patch-cycle argument as conditional is the framing the absence of such data requires.

#### 15.4 The falsifier of the horizon-mismatch wall

The third wall would be falsified by a deployed agent whose evaluation horizon is shown to extend over the replenishment cycle of the slow variables in the system it acts upon, with the sustainable and depleting trajectories of those variables observationally distinguishable within the horizon (the negation of Theorem 3's hypotheses; Chen, 1999; Conant and Ashby, 1970). The condition the falsifier must meet is that the horizon be the operative evaluation horizon of the agent's policy and updates, not a stated planning horizon that does not enter the agent's actual feedback loop; the distinction is the distinction between what the agent sees and what it claims to see. The locus at which the falsifier would be found is a deployed system whose evaluation apparatus is documented to integrate feedback across the slow cycle; such systems exist, in the form of institutions and disciplines whose continuity is the slow cycle itself, and the question for the falsifier is whether the artificial agents currently in deployment occupy this posture or not. The structural finding of §8 is that they do not; a deployed agent that did would be the falsifier.

### 16. What the paper does not claim

This section is the second honest accounting of scope, after §11. The argument has reached its full conclusion. The reader should know what it does *not* claim. Three things in particular: the walls are claims about the operation the current paradigm uses, not claims that intelligence is impossible or that no future operation could cross them; the walls do not apply to systems whose architecture does not meet the walls' premises, embodied agents that reach the world through enactment rather than through training data, for instance; and the walls do not rest on a premise about consciousness or moral worth, which is why the structural argument survives even readers who disagree with the paper on those questions. The section closes the rhetorical door on three misreadings that would otherwise be available.

#### 16.1 The walls are operation-bounded, not impossibility claims

The structural form of the three walls is the operation-bounded form, not the impossibility-claim form, and the distinction is sharp enough to be stated as its own clause. An impossibility claim says that a thing cannot be done. An operation-bounded claim says that a thing cannot be done by the operation under consideration; whether some different operation could do the thing is a question the claim does not foreclose. The three walls are claims of the second kind. The foreclosure wall says that a cut-bound substrate cannot, by the operation of training on the cut and inferring across the support boundary, certify the consequential off-cut domain; it does not say that no operation could certify the domain (the underdetermination canon: Frege, 1892; Putnam, 1980; Kripke, 1982; Quine, 1960; constraints the canon poses on the operation, not on every conceivable operation). The compounding-hazard wall says that a deployed substrate with stationary per-action hazard on a consequential mode produces unbounded catastrophes in deployment (Williams, 1991, §12.15; Lévy, 1937); it does not say that the catastrophes cannot be prevented by an architecture whose hazard is not stationary in the relevant sense. The horizon-mismatch wall says that an agent with a horizon shorter than the replenishment cycle cannot preserve the slow variable on its own feedback (Chen, 1999; Conant and Ashby, 1970); it does not say that the slow variable cannot be preserved by a regulator whose horizon is matched to the cycle. The walls are bounds on the operations of the current paradigm, not bounds on intelligence, on safety, or on long-horizon governance as such.

The distinction is the distinction between the operation a paradigm has assembled and the structural goal the paradigm proposes itself to deliver. The achievement of an engineering programme can stumble upon the operation that crosses a wall, in the sense in which aviation crossed a wall on which faster horses would never have crossed: the wing is a different operation from the breeding of stronger horses, and the wall to flight that no scale of horse could clear is cleared by the wing. The achievement of the current paradigm has been the engineering achievement of optimising a particular operation on enormous scale; the walls are the structural statement that this operation, at any scale, does not cross to where the paradigm's claims would require it to be. Whether some different operation, recognisable in retrospect as the wing of this technology, will be invented is a question the paper does not foreclose and on which the argument takes no position. The discipline the paper observes is to state what the operation under consideration cannot deliver, not to claim that what the operation cannot deliver is undeliverable.

#### 16.2 The walls do not apply to all conceivable systems

The walls' premises are stated formally, and any system whose architecture does not meet the premises falls outside the walls' reach. The foreclosure wall presupposes a cut-bound substrate; a system whose substrate is not bounded by a corpus, that reaches the world through embodied causal interaction with feedback that is not a record but an enactment, has architectural premises the foreclosure wall does not cover. The compounding-hazard wall presupposes architectural conditions that fix the rate stationarity of the hazard; a system whose hazard is not stationary in the relevant sense (Williams, 1991, first lemma) falls outside the wall's premise. The horizon-mismatch wall presupposes a specific relation between the agent's evaluation horizon and the system's replenishment cycle; an agent whose horizon is matched (the negation of the hypothesis in Chen, 1999; Conant and Ashby, 1970) falls outside the wall's premise. The walls are not claims about every conceivable system; they are claims about systems whose architectural premises the walls' theorems take as input, and those premises are the architectural premises of the systems in current deployment.

#### 16.3 The walls do not rest on a phenomenological or moralistic premise

The argument has been carried out at the structural level the resources permit. The walls do not turn on whether the systems are conscious, on whether they have understanding in some non-formal sense, on whether they are morally analogous to or different from human agents, or on any specifically human capacity not formalisable in the structural terms the paper uses. The structural reading of Searle (1980) in §4.7 was the reading that detached the structural point from the consciousness-dependent intuition pump and kept the structural point only. The reading of the genealogy in §12 was an analytic-descriptive reading of how a methodological bracket (Shannon, 1948) hardened into a working assumption (Newell and Simon, 1976; Fodor, 1975); it was not a moralistic critique of the engineers who hold the assumption or of the institutions that built the systems. The discipline of analytic-descriptive register, against partisan or moralistic register, is the discipline the argument observes throughout: structural-genealogical claims about how a paradigm came to occupy its current arrangement, not normative verdicts on those who occupy it.

### 17. Conclusion

The conclusion closes the paper. It states, in compact form, what the three walls are, what together they establish about the systems in current deployment, what the paper has not claimed, and what would prove the argument wrong. The closing paragraphs land the structural figure the paper has been building toward: the operation under consideration is the priest at the bedside, and no degree of pastoral excellence is a partial surgery. The wing of this technology, if there is one, is not the question of this paper; the question is whether the operation now sold under the names *language model*, *world model*, and *agentic AI* delivers on the descriptions under which it is sold, and the answer is the three walls.

The argument has established three structural walls on the systems built by the contemporary paradigm of artificial intelligence. The first wall, the wall of foreclosure, is a wall on what a substrate operating on a cut can reach in the domain the claim made on its behalf covers; the wall stands at a single instant and is proved by the support-invariance proposition and its semantic and formal cognates (Frege, 1892; Putnam, 1980; Kripke, 1982; Sellars, 1956; Searle, 1980; Carnap, 1928; Quine, 1960; Tarski, 1936; Gödel, 1931; Ashby, 1956; Conant and Ashby, 1970), the three lenses converging in a Lawvere instance the unification of §10 makes precise (Lawvere, 1969; Yanofsky, 2003). The second wall, the wall of compounding hazard, is a wall on what a deployed substrate with stationary per-action hazard on a consequential mode produces over deployment; the wall is temporal and is proved by the Borel-Cantelli dichotomy with the conditional extension of Lévy (Lévy, 1937; Williams, 1991, §12.15). The third wall, the wall of horizon-mismatch, is a wall on what an agent acting on a slow-replenishing system can preserve when its evaluation horizon is shorter than the cycle on which the system replenishes; the wall is operational and is proved from finite-horizon observability (Chen, 1999) joined with the Conant-Ashby theorem (Conant and Ashby, 1970).

The three walls are independent, each governing its own variable, and the no-exit result follows: a system that is foreclosing, hazard-stationary, and horizon-mismatched, which is what the deployed systems are by the architectural premises they meet, requires three independent repairs, and no single repair the field has assembled reaches more than one of the three variables the walls govern. The first wall's three lenses are instances of one categorical theorem, by Lawvere (1969) with the catalogue of instances supplied by Yanofsky (2003); the structural identity beneath the three lenses is the unification the convergence of Part II called for. The genealogy traces the engineering culture's blindness to the walls from inside, through the first hardening of Shannon's (1948) methodological bracket into the metaphysical commitment of the language-of-thought tradition (Newell and Simon, 1976; Fodor, 1975), and the second hardening into the unstated background of the contemporary engineering practice; the cross-architecture convergence of failure modes is the structural face of the bracket the genealogy isolates (Dreyfus, 1972, supplied the contemporary critique).

The deployment consequence stands as the structural finding the three walls together establish: the systems in current deployment foreclose on their consequential domain, accumulate catastrophes whose conditional sum diverges (Williams, 1991, §12.15), and fail to preserve the slow systems on which they are deployed to act (Chen, 1999; Conant and Ashby, 1970). The argument does not depend on catastrophes already observed; it depends on the architectural premises being met, and the premises are met by the systems' own design. The deployment consequence is committed to its falsifiers, stated in §15: a substrate that certifies an off-cut consequential element without smuggled world-relation, a deployment record of mode-indexed convergence on consequential modes, or an agent whose operative evaluation horizon reaches the replenishment cycle of the systems it acts upon. The argument stands on the conditions of its own defeat, and the conditions of its own defeat have not been met.

The walls are bounds on the operation of the current paradigm, not bounds on intelligence, safety, or governance as such. Whether some different operation will, in the future, cross the structural walls the present operation cannot is a question the paper does not foreclose; what the paper claims is that the operation under consideration, at any scale, on the architectural premises it now meets, does not cross them. The seeker after a better artificial intelligence is the seeker after the operation the present paradigm is not; the operation under consideration is the priest at the bedside, and the paper has been the structural statement that no degree of pastoral excellence is a partial surgery. What the wing of this technology will turn out to be, and whether it will be built, are not the questions of this paper; the questions of this paper are whether the operation now sold under the names *language model*, *world model*, and *agentic AI* delivers on the descriptions under which it is sold, and the answer is the three walls.

---

## References

Ashby, W. R. (1956). *An Introduction to Cybernetics*. London: Chapman & Hall.

Beer, S. (1974). *Designing Freedom*. Toronto: CBC Learning Systems / House of Anansi Press.

Carnap, R. (1928). *Der logische Aufbau der Welt*. Berlin: Weltkreis-Verlag.

Chen, C.-T. (1999). *Linear System Theory and Design* (3rd ed.). New York: Oxford University Press.

Conant, R. C., and Ashby, W. R. (1970). "Every good regulator of a system must be a model of that system." *International Journal of Systems Science*, 1(2), 89–97.

Dreyfus, H. L. (1972). *What Computers Can't Do: A Critique of Artificial Reason*. New York: Harper & Row.

Eastman, C., Teicholz, P., Sacks, R., and Liston, K. (2018). *BIM Handbook: A Guide to Building Information Modeling for Owners, Designers, Engineers, Contractors, and Facility Managers* (3rd ed.). Hoboken, NJ: Wiley.

Fodor, J. A. (1975). *The Language of Thought*. New York: Thomas Y. Crowell.

Frege, G. (1892). "Über Sinn und Bedeutung." *Zeitschrift für Philosophie und philosophische Kritik*, NS 100, 25–50.

Goodfellow, I., Bengio, Y., and Courville, A. (2016). *Deep Learning*. Cambridge, MA: MIT Press.

Gödel, K. (1931). "Über formal unentscheidbare Sätze der *Principia Mathematica* und verwandter Systeme I." *Monatshefte für Mathematik und Physik*, 38, 173–198.

Kripke, S. A. (1982). *Wittgenstein on Rules and Private Language*. Cambridge, MA: Harvard University Press.

Lawvere, F. W. (1969). "Diagonal arguments and cartesian closed categories." In *Reports of the Midwest Category Seminar II* (Lecture Notes in Mathematics 92), 134–145. Berlin: Springer.

Lévy, P. (1937). *Théorie de l'addition des variables aléatoires*. Paris: Gauthier-Villars.

Newell, A., and Simon, H. A. (1976). "Computer Science as Empirical Inquiry: Symbols and Search." *Communications of the ACM*, 19(3), 113–126.

Putnam, H. (1980). "Models and Reality." *Journal of Symbolic Logic*, 45(3), 464–482.

Quine, W. V. O. (1960). *Word and Object*. Cambridge, MA: MIT Press.

Schönberger, J. L., and Frahm, J.-M. (2016). "Structure-from-Motion Revisited." In *Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition* (CVPR), 4104–4113.

Searle, J. R. (1980). "Minds, Brains, and Programs." *Behavioral and Brain Sciences*, 3(3), 417–457.

Sellars, W. (1956). "Empiricism and the Philosophy of Mind." In H. Feigl and M. Scriven (eds.), *Minnesota Studies in the Philosophy of Science, Volume I: The Foundations of Science and the Concepts of Psychology and Psychoanalysis*, 253–329. Minneapolis: University of Minnesota Press.

Shannon, C. E. (1948). "A Mathematical Theory of Communication." *Bell System Technical Journal*, 27(3), 379–423; 27(4), 623–656.

Tarski, A. (1936). "Der Wahrheitsbegriff in den formalisierten Sprachen." *Studia Philosophica*, 1, 261–405.

Williams, D. (1991). *Probability with Martingales*. Cambridge: Cambridge University Press.

Yanofsky, N. S. (2003). "A universal approach to self-referential paradoxes, incompleteness and fixed points." *Bulletin of Symbolic Logic*, 9(3), 362–386.
