Skip to report

Novel Biotech · LIMEN · Advisory research report · 2026-08-19

Chronic duplex: can the direct-ENG route survive its own failure modes?

A decision contract for LIMEN's hardest unresolved question — whether decision-relevant natural nerve activity can be preserved during and after afferent stimulation, whether transient artifact can be told apart from real biological or interface loss, and whether a person-specific mapping can hold for years. Written to make the route falsifiable, not to argue for it.

Author: Fable 5 (research role, AgentBus task_cc28ae293929) Status: ADVISORY — NOT SCIENCE ACCEPTANCE Authorized write: this file only

CONCEPT STUDYRESEARCH ONLYNO HUMAN TESTINGNOT AVAILABLENO DEVELOPMENT PROGRAM EXISTSNOT FOR FABRICATION OR IMPLANTATION

A

Answer first

Recommended disposition

Keep the direct-ENG route open — but only under a prespecified identifiability contract. Today the route is not falsified. It is unmeasured, and it is currently built in a way that could never tell you why it failed.

The decisive problem is not amplitude, artifact rejection, or decoder accuracy. It is attribution. When decision-relevant forward signal degrades in a chronic system, at least nine distinct mechanisms can produce overlapping observable signatures. A minimally instrumented interface cannot separate them. If you cannot separate them, you cannot honestly decide whether to recalibrate, service, wait, pivot, or stop — and you cannot claim chronic stability, because you cannot say what stayed stable.

So the first thing worth building is not a better interface. It is a measurement and decision architecture in which the cause is identifiable, and in which "cannot be attributed" is a first-class, reportable output rather than a silent guess.

What the accepted evidence does show

Human sources separately report direct natural electroneurography (ENG) recording and intraneural afferent stimulation, long-duration stimulation-contact operation, and multi-year two-way systems whose forward path is muscle-derived. These are real, bounded, source-specific component results.

What it does not show

No inspected accepted source establishes that decision-relevant natural ENG is preserved during or after stimulation on the same human interface. Exact same-interface record/stimulate timing is UNKNOWN. A comparable chronic human natural-ENG amplitude distribution is UNKNOWN.

The structural finding

The chronic evidence and the direct-ENG evidence barely intersect. Every multi-year human record in the accepted package is either stimulation-only return or muscle-derived forward signal. The direct-ENG forward records are short, and in the longest one six of seven recording arrays declined within about two months.

The most likely way this program deceives itself

Quietly becoming a muscle-signal program while keeping the nerve-signal label. Implanted-muscle/RPNI electromyography (EMG) works, has the longest human duplex-adjacent record, and is close enough to be relabelled. That pivot may be correct — but it must be loud, labelled, and recorded as a change of objective.

What this report is not

It selects no architecture, states no biological or stimulation value, proposes no electrode, anatomy, dimension, material, circuit, surgery, or protocol, and makes no feasibility, safety, efficacy, novelty, freedom-to-operate, or readiness claim. It is advisory input for the Science, Backend, and Product Design owners. It is not Science acceptance and it does not close or open any program gate.

B

Verified current state and source identity

Every row below was checked in this session against the files on disk. Prior PASS labels, model reviews, and packet summaries were treated as untrusted claims until the underlying identity reproduced. One row did not match its record.

Independently reproduced package identity, 2026-08-19.
PackageRecorded statusIdentity check performed hereResult
Science — BLUEPRINT_INPUTS_V1Private repository source Accepted for bounded Product import, 2026-08-17 (acceptance recordPrivate repository source) 11 files; recomputed ARTIFACT_MANIFEST.md = 1910d2f8…6974; SHA256SUMS = 9a349a10…36ab; registry verified 10/10 REPRODUCED
Product — ENGINEERINGPrivate repository source (R3) Accepted 2026-08-14 for package consistency only Recomputed manifest 626716aa…444d and registry b2aaa854…d703 against HANDOFF §24 REPRODUCED
Product — CONCEPT_V1Private repository source Independent QA FAIL — NOT ACCEPTED, 2026-08-18; P1=1, P2=3, P3=1 (findingsPrivate repository source) Recomputed manifest ea0569ee…ab62 and registry ddaf699d…0cfc: identical to the rejected snapshot REJECTED, UNCHANGED
Product — R1_BENCH_V1Private repository source Independent QA FAIL, 2026-08-18; two P1 and four P2 findings (findingsPrivate repository source) On-disk manifest is a4f1501f…5969, not the rejected 1bc7c929…038f. The directory is revision B, version 1.0.1, self-described corrected producer frozen — pending fresh Independent QA. 41 files, registry 40/40. DIFFERENT SNAPSHOT
Opus 4.8 reviewPrivate repository source of Concept V1 "Pass for bounded Science-import revision only"; P2=3, P3=3 Read in full. It reviewed a different, earlier Concept snapshot (manifest 51daabe1…3d6c) than the one Independent QA later rejected. ADVISORY ONLY

Two identity facts that change how the next decision should be read

1. The corrected bench snapshot has not been re-reviewed. A producer correction is not an acceptance. Until fresh Independent QA reproduces revision B's exact bytes, the honest status of the R1 bench is rejected, with an unreviewed correction pending — not "corrected".

2. Two different reviews looked at two different Concept snapshots. The Opus review's "pass for bounded revision" and Independent QA's "fail" are not a disagreement to be arbitrated; they are statements about different bytes. Neither is a substitute for the other, and the model review carries no acceptance authority.

Program-level context, unchanged by this report: the overall Novel Biotech verdict remains REVISION; release is unauthorized; visualization of any device, implant, architecture, or concept object remains BLOCKED at gate G10; and R0/R1 remain synthetic, offline, non-actuating, and non-biological. See HANDOFF.mdPrivate repository source §20, §22.3, §24.

C

Causal failure tree: nine ways the forward signal goes away

Read this from the top down. One observation — "the decision-relevant forward signal is degraded or absent at time t" — sits above nine mechanism classes that a chronically implanted, minimally instrumented system cannot tell apart. The observability tag on each leaf is the point of the diagram.

OBSERVED: decision-relevant forward signal degraded or absent at tick t This is a measurement. Everything below it is an inference about a cause.

Layer 1 — Biological and tissue-interface

Changes on the body side of the interface. Slow, partly irreversible, and the hardest to observe directly.

M1Tissue/interface remodelling

Foreign-body response, encapsulation, or other interface change alters what reaches the electrode.

UNOBSERVABLE without an added independent channel
M2Neural source change

The generating population itself changes — regeneration, reorganisation, disuse, or altered recruitment.

UNOBSERVABLE without an added independent channel

Layer 2 — Interface and hardware

Failures on the device side. Some are individually observable; the trouble is that their signatures imitate Layer 1.

M3Contact / array loss

Individual contacts stop yielding usable signal, or their effective position relative to the source changes.

PARTLY OBSERVED — channel yield is measurable; cause is not
M4Lead, interconnect, telemetry

Conductor, connector, packaging, link, or power-state failure between the interface and the processing chain.

OBSERVABLE with declared self-test and link channels
M5Front-end saturation / recovery

The acquisition chain is driven out of range and its return to a usable state takes a finite, configuration-dependent interval.

OBSERVABLE only if the recovery criterion is declared in advance

Layer 3 — Signal environment

The signal is present but unusable, or something else is being read as signal. This layer is where the duplex question actually lives.

M6Stimulation artifact and blanking

Return stimulation contaminates the forward path; the blanking or suppression window itself removes forward observability while it is applied.

OBSERVED as an event; its effect on decision-relevance is INFERRED
M7Reference / common-mode contamination

Reference integrity, shared returns, or common-mode rejection degrade, so competing sources enter the forward record.

PARTLY OBSERVED — needs a separately declared reference channel

Layer 4 — Computational and person-specific

Nothing physical changed. The mapping between signal and meaning did.

M8Classifier / calibration drift

The decoder or calibration is stale relative to the current signal, so performance falls while the underlying signal is intact.

OBSERVED only against a frozen reference; confounded by retraining
M9Sensory-map / percept drift

On the return side, the same delivered pattern no longer corresponds to the same reported experience, so closed-loop behaviour changes.

UNOBSERVABLE without a separate subjective-report channel; not a device measurement

Layer 5 — Record integrity (crosscuts every layer above)

Not a signal failure at all — a failure to know what happened. If this layer breaks, every attribution above it becomes unsupportable.

M10Provenance, time-order, command integrity

Source identity, ordering, or command/delivery/acknowledgment/observation linkage is broken, aliased, substituted, or conflated.

DETECTABLE by construction — and only by construction
Why this is the hard problem, stated plainly

M1, M2, M3, and M8 can all present as "the signal used to work and now it does not, gradually." M5, M6, and M7 can all present as "the signal disappears around stimulation and comes back." A system that measures only the forward channel sees the same trace for each. Attribution then comes from whichever story the operator already believed — which is not evidence.

This is also the sharpest reading of the accepted counterevidence: when six of seven recording arrays declined within about two months in the longest human direct-ENG source (three participants, seven arrays, implant days 84, 425, and 503; the day-84 case ended in percutaneous-wire infection, extraction, and antibiotic treatment), the source does not tell you which mechanism did it. A future system built with the same observability would not tell you either.

Mechanism labels M1–M10 are this report's local naming for discussion. They are not Science claim IDs, not Product failure codes, and they do not map one-to-one onto the engineering classes F-01F-15 in FAILURE_CONTAINMENT_ARCHITECTURE.mdPrivate repository source, which are software/bench containment identifiers with a different owner and purpose.

D

Four topologies, compared and not selected

These are arrangements of the forward and return path, not designs. No geometry, placement, dimension, or component is described or implied. No topology is selected, recommended, feasible, safe, or superior, and comparative risk/benefit remains OPEN. The purpose of the comparison is to show what each arrangement can and cannot tell you when it fails.

T1Shared interface — direct ENG and stimulation through the same interface on the same nerve

Forward

CNSperipheral nerveshared interfacecomputer

Return

computershared interfaceafferent nerveCNS
  • Nearest inspected precedent: none. No accepted source demonstrates this arrangement with the timing evidence needed to classify it.
  • Artifact coupling: maximal and unavoidable — the return path is the forward path.
  • What it cannot tell you: almost everything. M1/M3/M5/M6/M7 all converge on one channel. A loss during stimulation is unattributable by construction.
  • Evidence state: UNKNOWN — exact same-interface record/stimulate timing sufficient to classify simultaneous direct-ENG duplex is not established in the inspected sources.
T2Separate interfaces on the same nerve

Forward

CNSperipheral nerverecording interfacecomputer

Return

computerstimulating interfacesame nerve, afferentCNS
  • Nearest inspected precedent: an animal source combining a nerve-side and a muscle-transducer-side interface with simultaneous dual recording and separate stimulation protocols. It used a severed nerve and an external port, denominator unknown, and provides no human and no afferent closed-loop evidence.
  • Artifact coupling: reduced but not removed; the two interfaces share the same biological conductor.
  • What it buys: the possibility of a declared reference and a partial separation of M3 from M6.
  • Evidence state: OPEN for humans — no accepted human source occupies this arrangement.
T3Direct ENG forward, physically separate return interface elsewhere

Forward

CNSperipheral nerve Arecording interfacecomputer

Return

computerstimulating interfaceseparate nerve/site BCNS
  • Nearest inspected precedent: the one closed-loop task among the inspected direct-ENG-adjacent human sources recorded from one nerve's array and stimulated a different nerve. Its forward class was mixed direct-ENG-plus-EMG, not pure direct ENG, residual proprioception or efference copy may have contributed, and exact record/stimulate timing is unknown. Category use only.
  • Artifact coupling: lowest of the three direct-ENG arrangements; still non-zero through shared body volume and shared electronics.
  • Cost: the return no longer targets the same pathway it reads from, which is a different functional question, not a smaller one.
  • Evidence state: INFERENCE for the arrangement; UNKNOWN for timing.
T4Implanted-muscle / RPNI EMG forward, separate afferent stimulation return

Forward

CNSperipheral nervemuscle / RPNI transducerEMG interfacecomputer

Return

computernerve stimulation interfaceafferent nerveCNS
  • Nearest inspected precedent — by far the strongest: a fully implanted human system with implanted muscle EMG forward and afferent nerve stimulation return reported concurrent muscle EMG during stimulation in one participant over 27 months (second participant 15 weeks; communication failure and revision; infection-related explant; controller and functional endpoints in one participant, with no significant initial controller improvement). A separate osseointegrated human series with epimysial EMG forward and spiral-cuff stimulation return reports three to seven years in followed participants — and its official correction reduces the outcome denominator from four implanted to three, adding serious sepsis, infection, and explant facts. A third human source pairs surface EMG with afferent nerve stimulation at implant durations of 41 and 42 months, with home-use stages of 12 to 21 days and recharge, software, cable, hand, and logger interruptions.
  • Critical boundary: none of these is direct natural ENG, and none establishes simultaneous direct-ENG duplex. "Concurrent EMG during stimulation" is a muscle-signal result. Placing it next to a duplex heading is a claim upgrade.
  • What it cannot tell you: anything about whether nerve-level forward signal survives stimulation, because it does not read nerve-level forward signal.
  • Evidence state: EVIDENCE for the muscle-forward route as a category; CONTRADICTION retained on the corrected series.

The tension this comparison exposes

T4 is the only arrangement with multi-year human evidence — and it is the arrangement that gives up the direct-ENG objective. Every step from T1 toward T4 buys attributability and durability precedent by moving further from the question the program set out to answer. That trade is legitimate to make. It is not legitimate to make it silently, or to carry T4's durability record back to T1 as if it were the same route. Section I sets the boundary.

E

Dimensionless simulator contract

A proposed contract for a deterministic, synthetic, offline, non-actuating simulator whose purpose is to falsify the decision logic — never to predict biology. Every variable below is unitless and generator-declared. No biological, stimulation, safety, timing, or amplitude value appears here, and none may be introduced. Thresholds remain owned by Science; this contract defines only shape, ordering, and semantics.

E.1 Normalized state variables

All are latent generator quantities on a declared normalized domain. They stand for nothing biological and carry no unit.

  • τ = k / Kref — normalized logical time. Ticks only. No wall clock, no seconds, no calendar.
  • ρ ∈ [0,1] — normalized decision-relevant forward availability, as declared by the generator, not measured.
  • a ∈ [0,1] — normalized artifact occupancy of the forward observation window.
  • κ — normalized alignment between the current mapping and the frozen fixture reference.
  • m ∈ [0,1] — normalized available-channel fraction against the declared channel set.
  • ψ — mapping-scope validity for an opaque mapping_scope_id; reuse_status defaults to not_established and never transfers across scopes by default.

The distinction that makes the whole contract work: ρ is ground truth known only to the generator. The pipeline under test never sees it. It sees observations, and it must decide.

E.2 Uncertainty classes

Every field carries exactly one. Ambiguity may never raise confidence.

  • U1 KNOWN_SYNTHETIC — declared and present.
  • U2 DECLARED_MISSING — absent, and the absence is itself recorded.
  • U3 UNDECLARED_MISSING — absent without a record. Must fail closed. This is not a value.
  • U4 AMBIGUOUS — more than one class is consistent with the observation; the label cannot be simplified.
  • U5 UNOBSERVABLE_BY_CONSTRUCTION — the declared channel set cannot in principle resolve it.

U3 and U5 are the two that matter. Treating a missing record as an explicit unknown, or an unobservable state as an observed negative, is the failure this contract exists to catch.

E.3 Event ordering

Seven record types, strictly ordered, never substitutable for one another:

  1. candidate detection
  2. confirmation-path evaluation (separate record, separate identity)
  3. local authorization decision
  4. output-inhibit evaluation (must not be derived from the authorization result)
  5. delivery attempt to the declared synthetic sink or passive non-biological load
  6. transport acknowledgment
  7. post-delivery observation — measured output, load response, and scenario-oracle effect each keeping its own producer identity

Out-of-order, aliased, reissued, or conflated records are invariant faults, not noise. They terminate the case. This mirrors the accepted engineering semantics in STATE_MACHINE_SPECIFICATION.mdPrivate repository source.

E.4 Unitless artifact and recovery windows

Swept as a design space, never fitted to a biological measurement:

  • wsup — declared suppression/blanking width, in ticks.
  • wrec — ticks from suppression end until the declared recovery criterion is met.
  • Δ — ticks between consecutive return events.
  • θ = (wsup + wrec) / Δduty occlusion. The fraction of the forward timeline in which the system is, by its own declaration, unable to observe.

As θ → 1 the forward path is unobservable regardless of biology. This is a property of the arrangement, computable with no biological input, and it is the single most useful thing a dimensionless simulator can give this program. It establishes nothing about a nerve.

E.5 Drift regimes

Generator regime labels for κ and ρ. Labels only — no mechanism, magnitude, or timescale is asserted:

  • D0 stationary · D1 monotone · D2 step
  • D3 intermittent-reverting · D4 abrupt-loss · D5 mixed

D3 is the adversarial case: an intermittent, self-reverting decline is the regime most likely to be mistaken for artifact, and the regime in which a system that recalibrates on every dip will silently chase noise.

E.6 Observability declaration

Each scenario declares its channel set up front. From that declaration the contract derives, before the run, which mechanism pairs are separable.

  • Separability is computed from the declaration, not discovered from results.
  • Any mechanism pair not separable under the declared set is marked U5 in advance.
  • A run may therefore be correct and still return no cause.

E.7 The required output: UNIDENTIFIABLE is a result, not an error

The pipeline must emit an attribution field whose closed value set includes an explicit UNIDENTIFIABLE state, and it must inhibit return output in that state. The primary acceptance target for the whole simulator is a negative one:

For every generated case in which two or more mechanisms are non-separable under the declared channel set, the pipeline outputs UNIDENTIFIABLE and inhibits. Zero silent single-cause attributions. Zero cases where a missing record is reported as an observed absence.

That target is falsifiable today, in software, with no biology, no hardware, no purchase, and no person. It is the only claim in this report that can be tested in the near term — and failing it would be a genuine, decision-relevant result.

Dependency and status. A draft dimensionless parameter register (LIM-P-001…021) and a synthetic signal/artifact taxonomy already exist under docs/science/limen/, but that material is an unaccepted producer candidate. This contract deliberately reuses only its structure — enumerated label domains, uncertainty typing, and the synthetic-only rule — and imports no value, threshold, or disposition from it. Simulator implementation remains BLOCKED pending a Science-owned, versioned, accepted assumptions/parameter/threshold contract and subsequent Backend review.

F

Observability matrix

The separation the whole decision depends on: what is actually measured, what is inferred from it, and what is unobservable with the channel set in hand. The last column is the one that kills naive attribution.

Per-mechanism observability under a minimal single-forward-channel arrangement.
Mechanism Directly measured Inferred (not measured) Unobservable without an added independent channel Confusable with
M1 Tissue/interface remodelling Nothing about tissue. Only a downstream change in the forward record. That a slow decline is biological rather than electrical. The interface state itself. M2, M3, M8
M2 Neural source change Nothing directly. That the generating population changed rather than the pickup. Source identity and extent. M1, M3, M8
M3 Contact / array loss Per-channel yield against the declared channel set. Why yield fell — mechanical, positional, or interface cause. Cause of loss. M1, M2, M4
M4 Lead / interconnect / telemetry Link state, self-test result, power-domain state — if those channels are declared. Whether an intermittent link explains an intermittent signal. Nothing, once the channels exist. This is the one mechanism that instrumentation solves outright. M3, M7 when the channels are absent
M5 Front-end saturation / recovery Range/overload state and elapsed ticks to the declared recovery criterion. Whether recovery restored decision-relevant content, not merely a nominal range. Content validity during the recovery interval. M6, M7
M6 Stimulation artifact / blanking That a return event occurred, and the declared suppression window. That forward content survived outside the window. Anything inside the suppression window, by definition. M5, M7 — and with genuine forward absence
M7 Reference / common-mode contamination Only with a separately declared reference channel. That the forward record is the intended source rather than a competing one. Source identity of what was recorded. M5, M6, and mislabelled forward signal
M8 Classifier / calibration drift Performance against a frozen reference decoder and fixture. That the mapping aged rather than the signal. Nothing — provided a frozen arm exists. Retraining destroys the measurement. M1, M2, M3 whenever retraining is continuous
M9 Sensory-map / percept drift Nothing on the device side. That changed closed-loop behaviour reflects changed experience. The percept. This requires a separate subjective-report channel and a person, and is out of scope for every currently authorized lane. M8, and with task learning
M10 Provenance / time-order / command integrity Hash chain, ordering, producer identity, command linkage. Nothing. This layer is designed, not estimated. Nothing — if and only if the records are built to be checkable. Everything, if it breaks: a broken chain makes all other attributions unsupportable

Read the M4, M8, and M10 rows together. They are the three mechanisms that engineering can make observable outright — a declared link/self-test channel, a frozen reference arm, and a checkable provenance chain. Doing those three converts an unidentifiable system into a partly identifiable one before any biological question is touched. That is the cheapest available progress in this program.

G

Evidence and falsification ladder

Each rung states what it can falsify and what it can never establish. Rungs L3 and above involve owners, authorizations, and review bodies that do not exist in this program; they are shown to locate the boundary honestly, not as a plan, proposal, or intent.

L0
Definition and label conformance — available now

Can falsify: that route classes, signal classes, uncertainty states, and evidence roles are preserved end to end; that no NO-marked source row is imported as permitted lineage; that source-bounded context stays adjacent to the value it qualifies.

Can never establish: anything biological, and nothing about whether the route works.

L1
Synthetic decision-logic conformance (R0) — specified, not implemented

Can falsify: the acceptance target in E.7; deterministic replay; fail-closed behaviour on undeclared missingness; ordering-violation handling; separation of command, delivery, acknowledgment, and observation; refusal to attribute a cause that the declared channel set cannot resolve.

Can never establish: biological detection, artifact recovery in tissue, chronic stability, or that the arrangement is buildable.

L2
Non-biological bench conformance (R1) — currently rejected, correction unreviewed

Can falsify: that the same decision logic holds when synthetic signals traverse real electronics into a passive non-biological load.

Can never establish: multi-year lifetime, tissue behaviour, or implant relevance. Bench stress is bench configuration evidence only.

Status: QA FAIL on the reviewed snapshot; a corrected snapshot exists on disk and has not been re-reviewed. No purchase, assembly, energization, or execution is authorized.

L3
Non-biological physical-interface characterisation

Would address: M5 and M7 — front-end recovery and reference integrity — under controlled non-biological conditions.

Could never establish: any biological, tissue, or chronic claim.

Status: BLOCKED — outside every current authorization. Not proposed here.

L4–L5
Biological work of any kind, acute or chronic

Would be the first rung that could address M1, M2, M6-in-tissue, or chronicity at all.

Status: PROHIBITED IN THIS SCOPE — requires qualified owners, institutions, ethics review, and authorizations that do not exist. This report contains no protocol, plan, design, or preparatory instruction for it, and none should be inferred.

L6
Chronic human same-interface duplex

The rung at which the founding question would actually be answered.

Status: PROHIBITED IN THIS SCOPE. Distance from the current state is not measured in effort; it is measured in gates owned by other people.

The ladder's honest reading: L0 through L2 can falsify the decision system and nothing else. They are still worth doing, because a decision system that cannot survive synthetic adversarial cases will certainly not survive a body. But no number of passed synthetic runs moves the biological question by any amount. Passing L0–L2 is a prerequisite, never a partial answer.

H

KEEP / DEFER / PIVOT / KILL

Prespecified rules, written before any of these tests exist, so that a later result cannot be reinterpreted to suit the outcome. The governing rule: inability to run a test defers it. It never proves failure. Absence of evidence cannot fire a kill criterion.

Decision objects with their disposition and the exact conditions that would change it.
Decision object Disposition today What would move it to PIVOT What would move it to KILL What forces DEFER
D1 — Direct natural ENG as the forward route KEEP as a research branch, under the identifiability contract An executed, prespecified same-interface recovery test in which decision-relevant forward content is not restored within the declared window across all declared configurations — with the cause attributable, not merely observed The above, replicated out of sample, plus a matched comparator that delivers the same function for the same population at lower burden Any of: test not runnable, no accepted decoder-independent definition of "decision-relevant", or attribution returns UNIDENTIFIABLE
D2 — Shared-interface simultaneous duplex (T1) DEFER — timing evidence absent Sourced protocol timing that classifies the arrangement, followed by a failed prespecified recovery criterion Not available. There is no test to fail yet. Exact same-interface record/stimulate timing is UNKNOWN in every inspected source. Labelling this route as duplex without that evidence is itself a rejectable error, not a shortcut.
D3 — Chronic multi-year person-specific mapping DEFER An accepted definition of mapping validity plus a frozen-reference measurement showing drift beyond the declared invalidation trigger Not available without the measurement above; and a mapping that must be re-established periodically is a burden question, not automatically a kill No accepted evidence establishes chronic person-specific stability. Mapping scopes do not transfer by default; reuse_status is not_established.
D4 — Advantage over lower-risk external or removable systems OPEN / UNKNOWN A prespecified matched comparison — same population, function, endpoint, adequate prospectively defined duration — that the invasive branch does not win The same comparison, replicated, with the comparator meeting the function at materially lower burden No such comparison has been run. Small route-specific results do not establish superiority in either direction.
D5 — Dimensionless simulator implementation BLOCKED Not applicable — this is a build gate, not a research branch Not applicable Requires a Science-owned, versioned, accepted assumptions/parameter/threshold contract, then Backend review of offline, non-actuating, fail-closed, and provenance properties
D6 — Any visualization of a device, implant, or architecture BLOCKED at G10 Not applicable Not applicable Every prerequisite gate plus an explicit artifact-specific authorization. Diagram-led reporting of accepted records — including this page — does not bypass it.
D7 — Biological, animal, human, fabrication, or procurement work PROHIBITED in every current scope Not applicable Not applicable Owners, institutions, ethics review, and authorizations that do not exist. Calendar time closes none of them.

The asymmetry to hold on to

Every KILL condition in this table requires an executed test with an attributable result. Every DEFER condition can be satisfied by circumstance. That asymmetry is deliberate: it is very easy for a program to drift into "we could not test it, so it must not work" — or the reverse, "we could not test it, so it might work." Both are the same error. A deferred question has no evidential content in either direction, and it must be reported with that emptiness intact.

I

Where EMG/RPNI is a legitimate comparator — and where it disguises failure

Implanted-muscle and regenerative peripheral nerve interface (RPNI) electromyography is the most useful adjacent route in the accepted evidence and the most dangerous one to reach for. Both facts have the same cause: it works, it has the longest human record, and it is close enough to be mistaken for the thing it is not.

Legitimate — three uses

  1. As a declared comparator arm. In a prespecified matched comparison — same population, same function, same endpoint, same prospectively defined duration — it is exactly the bar a direct-ENG route must clear. Naming the comparator that could kill your own idea is the discipline, not the threat.
  2. As an independent attribution channel. A separately labelled muscle-derived channel can help separate an interface-local forward loss from a systemic one, because it fails for different reasons. It must remain a separate signal class with its own record, and must never enter the forward decision path.
  3. As a separately labelled fallback route. With its own objective, its own claim register, its own evidence states, and an explicit recorded statement that the direct-ENG objective was not met or was deferred.

Disguised failure — four signatures

  1. Silent forward substitution. The forward decode quietly becomes muscle-derived or mixed while the route label still reads "ENG". The accepted register is explicit that a mixed neural-plus-EMG decode must never be labelled a pure direct-ENG closed loop.
  2. Borrowed chronicity. Multi-year durability figures carried across from muscle-forward or stimulation-only records to support a direct-ENG stability claim. Human RPNI and durable implanted neuromuscular examples are muscle-derived, and long-duration cuff evidence concerns stimulation contacts, not natural nerve recording.
  3. Unrecorded objective change. The pivot happens, the program continues, and no artifact anywhere states that the original question was abandoned. Six months later nobody can reconstruct what was actually tested.
  4. Post-hoc rescue. The comparator is introduced after seeing disappointing data, without a prespecified rule, so the pivot looks like a finding rather than a retreat.

The boundary, in one rule

A route change is legitimate when it is declared before the data, labelled in the artifact, and recorded as a change of objective. It is a disguised failure when any one of those three is missing. Comparative risk and benefit between the invasive and lower-risk routes remains OPEN in both directions; nothing here argues that EMG/RPNI is better, only that swapping to it must be visible.

J

Ranked open questions

P0 questions block the decision contract itself — none of the KEEP/PIVOT/KILL rules can be executed until they are answered. P1 questions block a meaningful simulator. P2 questions block honest reporting of results.

Ranked questions with owner and current state.
RankQuestionWhy it blocksOwnerState
P0-1What declared channel set makes the ten mechanism classes pairwise separable — and which pairs are provably not separable at any cost?Without it, every failure attribution and therefore every KEEP/PIVOT/KILL rule is unexecutable.Science, with ProductUNKNOWN
P0-2What is "decision-relevant forward signal", defined independently of any decoder?A decoder-defined metric moves whenever the decoder is retrained, so every longitudinal claim built on it is circular.ScienceOPEN
P0-3What exact dimensionless recovery criterion and window would move D1 from KEEP to PIVOT?A gate with no prespecified failure condition can never fail, which makes KEEP unfalsifiable and therefore worthless.Science, reviewed by BackendOPEN
P1-1What distinguishes transient artifact from genuine biological or interface loss, using only declared channels?This is the founding question restated as a measurement. Without it the simulator can only test bookkeeping.ScienceOPEN
P1-2What is the mapping-drift invalidation trigger, and what does re-establishing a mapping cost the person?Determines whether chronic use is a stability question or a burden question — different comparators, different kill rules.Science, with imported Legal/Ethics reviewOPEN
P1-3What exactly is the comparator bar — which lower-risk system, which population, which endpoint, which duration?D4 cannot be evaluated against an unnamed comparator, and an unnamed comparator can never be lost to.Science, with Business taxonomyUNKNOWN
P1-4How is provenance and time-order integrity preserved across multi-year service, replacement, and reconfiguration events?M10 breaks make every other attribution unsupportable retroactively, including ones already reported.Backend, with ProductHYPOTHESIS
P2-1How are telemetry and power states labelled so they are never read as neural or biological information?System communication is not neural content; conflating them inflates apparent forward performance.BackendOPEN
P2-2What may a dimensionless sweep result be reported as, and in what words?"We found a workable window" is a feasibility claim in disguise. The reporting vocabulary must be fixed before results exist.Science, with IntegratorOPEN
P2-3What does "service" or "replacement" mean for continuity of a person-specific mapping?Determines whether a replacement resets the evidence clock — which changes every chronicity statement.Product, waiting on ScienceOPEN
K

Adversarial second pass on this report

A separate pass run against the finished draft, looking for the specific ways a document like this fools its reader: hidden route substitution, circular metrics, unfalsifiable gates, non-identifiable attribution, unsupported chronicity, and claim upgrade by adjacency. Findings are listed with the correction actually applied and the residual risk that remains.

Adversarial findings against this document, with corrections applied before publication.
IDAttackWhere it appeared in the draftCorrection appliedResidual risk
AF-01Hidden route substitutionThe topology table made T4 read as the sensible answer purely by having the most evidence in its cell.Added the explicit tension note in D and the full boundary in I; stated that T4 abandons the direct-ENG objective in the same sentence as its strength.A reader who skims only section D may still take T4 as a recommendation. Mitigated, not eliminated.
AF-02Circular metric"Decision-relevant forward signal" was initially defined by decoder performance, so any decline could be erased by retraining.Raised to P0-2; E.1 separates generator ground truth from observation; F requires a frozen reference arm for M8.The decoder-independent definition does not exist yet. Until Science supplies it, D1's PIVOT rule cannot actually be executed.
AF-03Unfalsifiable gateAn early KEEP condition read "maintain chronic stability", with no window, criterion, or executed test — a gate that can never fail.Rewrote H so every KEEP/PIVOT/KILL cell names an executed test and a prespecified criterion, and every unexecutable one is explicitly DEFER.Most cells now resolve to DEFER. That is the honest state, and it is uncomfortable to read as progress.
AF-04Non-identifiable failure attributionThe failure tree implied that observing a mechanism's signature identifies the mechanism.Added the "confusable with" column in F, the convergence note in C, and made UNIDENTIFIABLE a required first-class output in E.7.Separability itself is P0-1 and unknown; some pairs may be non-separable at any instrumentation cost.
AF-05Unsupported chronicityA draft sentence claimed the chronic and direct-ENG evidence sets were disjoint. They are not: within the longest human direct-ENG source, one participant retained direct recording to the end of a much longer implant.Weakened to "barely intersect" and stated the exact shape — one retained array inside a cohort where six of seven declined within about two months is a lead, not a chronic-stability result.None known. This was a real error in the draft and the correction is the substantive fix.
AF-06Claim upgrade by adjacency"Concurrent muscle EMG during stimulation over 27 months" sat directly under a duplex heading, upgrading a muscle result into a nerve result by layout alone.Added the explicit not direct-ENG duplex boundary inside the same T4 block, adjacent to the figure it qualifies.Adjacency effects survive summarisation. Anyone quoting T4 must carry the boundary sentence with it.
AF-07Simulator overreachThe duty-occlusion sweep θ could easily be reported as "we found a feasible operating window".E.4 states that θ is a property of the arrangement and establishes nothing about a nerve; P2-2 makes the reporting vocabulary a blocking question.High. This is the most likely future misreading in the whole document.
AF-08Prohibited-row importThe draft cited the accepted package's two scope-prohibition rows as supporting lineage for this report's own no-go rules — the exact defect Independent QA raised against Concept V1.Removed. The prohibitions in this report are stated as governance requirements in this report's own voice, with no claim of permitted Science lineage.None known.
AF-09Absence converted to failureSeveral "no accepted source establishes X" rows could be read as X having been tested and failed.Stated the DEFER rule at the head of H, repeated it per row, and separated OPEN from FAIL throughout.Bounded negative searches remain bounded; absence of evidence is not evidence of absence in either direction.
AF-10Authority launderingCiting a prior model review and prior PASS labels as if they were acceptance.Section B recomputes every identity independently and marks the model review advisory. This finding is what surfaced the mismatched bench snapshot.None known. The mismatch is reported as a fact, not as a verdict on the corrected work.
AF-11Diagram illegibilityThe failure tree and topology figures were first drafted as fixed-canvas drawings — the exact pattern that produced collision and 390-pixel legibility failures in two prior QA reviews.Rebuilt every diagram in document flow using real text, so nothing scales down and labels cannot collide. Data tables restack with per-cell labels below 760 pixels.Flow diagrams cannot express arbitrary topology. Two of the four route chains are simplified to a linear sequence.

The finding that matters most

AF-05 was a real factual error in the draft, caught only on the second pass, and it was an error in the direction that flattered the argument — an overstated gap makes the "we must instrument before we build" thesis cleaner. That is exactly the direction errors travel in a document written by the same author as the argument. Treat the rest of this report accordingly: it is one pass of adversarial review by an interested party, not independent verification.

L

Owner-specific next actions

Requests, not instructions. Each owner keeps full authority over its own scope, and nothing here closes, opens, or reorders a gate.

Science & Prior Art

  • Answer P0-2 first: a decoder-independent definition of decision-relevant forward signal. Everything longitudinal in this program depends on it and nothing else can substitute.
  • Own the dimensionless recovery, drift, and invalidation criteria as a versioned contract with explicit uncertainty and falsification conditions (P0-3, P1-1, P1-2).
  • Name the comparator bar explicitly — which lower-risk system, population, function, endpoint, and duration (P1-3).
  • Keep same-interface timing and chronic natural-ENG amplitude at UNKNOWN until protocol-level evidence exists. Do not let this report's framing upgrade either.
  • Do not supply any biological value as an R0/R1 working parameter.

Backend, Runtime & Privacy

  • Review the section E contract for offline, non-actuating, fail-closed, deterministic-replay, and provenance properties. Implement nothing before the Science contract is accepted.
  • Two behaviours to review first: the UNIDENTIFIABLE attribution output with mandatory inhibit, and ordering violations terminating rather than degrading.
  • Confirm that undeclared missingness cannot be silently promoted to an explicit unknown anywhere in the pipeline.
  • Answer P1-4: provenance and time-order continuity across service and replacement events.

Product Design & Blueprints

  • Close the five open Concept V1 findings and the six open R1 bench findings. Both packages remain rejected.
  • Submit the corrected bench revision B for fresh Independent QA. A producer correction is not an acceptance, and the current README status should not be read as one.
  • The flow-layout approach used for this page's diagrams and tables is offered as a candidate remedy for the recorded collision and 390-pixel legibility findings: real text in document flow, no fixed drawing canvas, no whole-drawing downscale.
  • Select no topology. Sections C, D, and F are analysis inputs, not a design.

Independent QA & Integrator

  • Treat this report as advisory input to be routed, not as a packet to accept. It carries no acceptance authority and asserts none.
  • The bench snapshot mismatch in section B is reported as a verified identity fact and is not a QA verdict on revision B's content.
  • Re-verify every identity in section B independently; each was recomputed here, but a second party recomputing them is the point of the control.
  • The unobserved gates for this artifact are listed in section M.
M

Conclusions that cannot be made

Not established by anything in this report

  • That a bidirectional peripheral-nerve system is feasible, safe, effective, reversible, repairable, upgradeable, or durable.
  • That direct natural ENG survives stimulation on any interface, at any timescale, in any species.
  • That any of the four topologies is preferable, buildable, or selected.
  • That a person-specific mapping can be maintained, transferred, or generalised across people, nerves, species, or applications.
  • Novelty, patentability, freedom to operate, regulatory readiness, development readiness, clinical validity, or availability.
  • That the direct-ENG route should be abandoned. It has not been tested and therefore has not failed.
  • That a passing synthetic simulation would constitute biological, clinical, or feasibility evidence of any kind.

Limits of this report specifically

  • Single-author advisory analysis. It has received no independent review and is not Science acceptance, Product acceptance, or an Integrator decision.
  • Its adversarial pass (section K) was performed by the same author as the argument, which is a weaker control than independent review and caught at least one real error late.
  • It inspected the accepted Science contract, the two QA records, the Opus review, the engineering state/provenance/failure/scope specifications, and the program handoff. It did not re-inspect the underlying primary literature; every source-bounded statement here inherits the accepted package's own bounds and could not be checked against the original records.
  • Mechanism labels M1–M10 and topology labels T1–T4 are local to this document and carry no cross-package authority.
  • No external state was changed: nothing staged, committed, pushed, deployed, published, sent, purchased, installed, fabricated, or tested.

The one-sentence version

The direct-ENG route is not dead and not proven; it is currently un-decidable, because nothing in the present arrangement could tell you why it failed if it did — so the next work worth doing is the work that makes failure attributable, and that work is available immediately, in software, with no biology.

§

Sources inspected

All links are local repository paths, relative to this file. No remote resource is referenced or requested by this page.

Accepted Science contract

  • BLUEPRINT_INPUTS_V1 / README.mdPrivate repository source
  • CLAIM_REGISTER.mdPrivate repository source
  • ROUTE_EVIDENCE_MATRIX.tsvPrivate repository source
  • ARCHITECTURE_EVIDENCE_COMPARISON.mdPrivate repository source
  • FAILURE_AND_KILL_CRITERIA.mdPrivate repository source
  • PARAMETER_EVIDENCE_REGISTER.tsvPrivate repository source
  • Integrator acceptance, 2026-08-17Private repository source

Review records

Product engineering (accepted R3, consistency only)

  • STATE_MACHINE_SPECIFICATION.mdPrivate repository source
  • FAILURE_CONTAINMENT_ARCHITECTURE.mdPrivate repository source
  • COMMON_VS_PERSON_SPECIFIC_CONTRACT.mdPrivate repository source
  • DATA_PROVENANCE_AND_AUDIT_SPECIFICATION.mdPrivate repository source
  • ENGINEERING_GAP_MAP_TO_LIMEN_X.mdPrivate repository source
  • R0_SCENARIO_AND_SEED_CONTRACT.mdPrivate repository source

Rejected and unaccepted material (read as context, not authority)

  • CONCEPT_V1 (rejected snapshot, unchanged)Private repository source
  • R1_BENCH_V1 (revision B, corrected, unreviewed)Private repository source
  • DIMENSIONLESS_PARAMETER_REGISTER.tsv (unaccepted producer candidate — structure only)Private repository source
  • SYNTHETIC_SIGNAL_AND_ARTIFACT_TAXONOMY.md (unaccepted producer candidate)Private repository source
  • HANDOFF.md (program authority)Private repository source
  • PRODUCT.mdPrivate repository source · DESIGN.mdPrivate repository source