SAFE-AI Unified: A Mathematical Framework for User-Applied Operations on Frozen-Weight LLMs
Abstract
Monograph I of the SAFE-AI program — Zenodo Version 4. A unified mathematical framework, in four Parts, for what a disciplined user can and cannot do to a frozen-weight large language model by applying structured operations — brackets, anchors, traversal protocols, and engagement modalities — at inference time, without touching the model’s parameters. Part I (Foundations) develops the inference-time risk identity: the deployed model’s risk decomposes into a contextual Bayes floor and an exploitation gap, on a σ-algebra that moves with the applied context rather than the classical fixed σ(X) frame. The asymmetric-information channel — the user’s information field strictly contains the model’s — is the framework’s load-bearing structure. Autonomous, no-bracket inference is compared against the model’s stationary law (Zekri et al.), with the directional content of the drift stated as a testable structural hypothesis rather than a derived result. Part II (Geometry) gives the Fisher-geometric account of steering: a spectral ceiling on pullback sensitivity, stated as a direct corollary of standard interlacing results, separates the shape of the spectrum (proved) from its semantics (a named assumption). Part III (Session dynamics) supplies the evolving-information identity that decomposes squared-loss risk over the acquired-information σ-algebra, and the session-level objects the companion volumes inherit. Part IV (Governance) is governance-receiving rather than governance-defining: it receives a community-authorized target, task surface, action policy and data-lifecycle constraints, and states its population-scale result as a named conjecture with explicit operational falsifiers. What is new in Version 4. A point revision following an external technical read, with no displayed mathematics changed: the directional clause of Proposition 4.3 is re-tagged as a definitional consequence of Definition 4.2(ii) and the Epistemic Status register notes that the Zekri rate constant is not informative at deployed scale; Definition 4.2(i) is annotated with the separation requirement it imposes on the task family; the Part I §3.8 squared-loss bridge now routes through Identity 7.4-Ω; Theorem 3.6-EC is re-tagged as a direct corollary of standard results, with its dependence on the declared reference metric noted; the §4.8 analogy is restated as structural; and the Part IV §5.1 notes on weights and necessity are reconciled. Status. Every claim carries an epistemic status under the series taxonomy (imported theorem; direct corollary; new theorem under structural assumptions; modeling identification; empirical hypothesis or conjecture; normative specification). Working paper; not peer-reviewed by a journal; version history in the Revision Note. This monograph has not been developed with, reviewed by, or endorsed by any Indigenous People, Nation, community, or governance body. It offers a proposed technical apparatus — an interface for receiving governance, not a validated Indigenous-governance mechanism — and defers to applicable community authority and protocol. The next scholarly step, before any stronger claim, is substantive review under terms controlled by the relevant governance participants. Related records. Monograph II, SAFE-AI Decision Diagnostics — all versions 10.5281/zenodo.20938141 (Zenodo Version 4). Monograph III, SAFE-AI Inclusive Sovereignty — all versions 10.5281/zenodo.21776915 (Zenodo Version 2, document Version 3.1). All versions of this volume: 10.5281/zenodo.20649477. Cite as. Berardi, V. L. (2026). SAFE-AI Unified: A Mathematical Framework for User-Applied Operations on Frozen-Weight LLMs (Version 4; document revision 5.5.1). TheSOLE.Institute. https://doi.org/[version DOI] — all versions: https://doi.org/10.5281/zenodo.20649477