Chapter 14 — Evidence of the Evidence
EVIDENCE FORM TRIAL 1 Preserve: model hash Destroy: model artifacts Proven afterward: that particular bytes once existed Not proven afterward: what the bytes could do Result: insufficient
The first solution preserved evidence of an object and destroyed evidence of its behavior.
At 09:00 the next morning, the Civic Review Panel gave me an isolated design space. It contained no model artifact, lead memo, name dictionary, or capture. It contained the findings we might need to preserve, the limits already established, and thirty-five hours of model hold.
The parties could propose evidence forms without touching CIVIC-CONSEQUENCE. Every
proposal had to answer two adversaries.
The first adversary denied the Committee’s abuse. It would argue that logs could be misread, outputs could be synthetic, generated candidates could be random, and no public decision depended on a quieted life.
The second adversary wanted to repeat the abuse. It would call every preserved tool necessary for verification, then use verification authority to regenerate the people the finding claimed to protect.
A successful form had to resist both.
I began with the hash.
The three base mirrors and six adapter shards had externally timestamped commitments stretching across Archive transitions. If we destroyed the artifacts and retained those commitments, no future office could substitute a different model and claim it was the one Continuity used.
No future office could inspect the original either.
The hash proved identity only to someone who possessed the bytes. After destruction it would become a label for an object no challenger could examine. Saye rejected Trial 1.
“A city could publish any finding, destroy its basis, and retain a hash as theater,” he said.
“The destruction would be witnessed,” I replied.
“That proves confidence in the destruction. It does not prove the finding.”
He was right.
Trial 2 encrypted the model under a court threshold. No single custodian could invoke it. Five independent institutions would have to agree that a challenge justified access. Every access would be public and time-limited.
Iona rejected it.
“That is preservation with better locks.”
“Better locks change expected misuse.”
“They do not change what the city owns.”
The Chorus submitted its own history. Threshold custody had protected deletion receipts from unilateral alteration. It had not prevented seven lawful services from combining their answers into a household resolver. Distributed authority made misuse harder to coordinate. It did not make coordinated misuse impossible or morally clean.
Trial 2 failed because recoverable possession remained possession.
The court threshold also moved the decision rather than ending it. Institutions change members. Keys migrate. Emergency rules lower quorums after fires, wars, and network failures. A future Panel could call a new investigation urgent enough to open the model. The five-custodian design contained a recovery clause for lost shares. Removing the clause risked permanent loss after an ordinary accident. Keeping it created a path around the threshold.
“We could require unanimity forever,” Saye said.
“Forever is longer than the current custodians live,” Iona replied.
“Then successor institutions inherit the duty.”
“That is how we arrived at seven Archives preserving a claim none had authority to resolve.”
The threshold could distribute trust in the present. It could not guarantee the motives, law, or fear of every successor. Encryption made the future ask permission from a key ceremony. It did not let the people represented inside the model withdraw permission from that future.
Trial 3 destroyed the model and retained representative outputs. We could sample benign planning responses, prohibited subject candidates, the forty-three-second reconstruction, and the Committee’s lead memos. Future critics could inspect what the system had done without rerunning it.
Reed rejected it through the identity-reducing relay.
“Representative of whom?”
The sample could omit names and retain structure. It could replace candidates with stable aliases. It could crop the reconstruction to infrastructure. It could summarize lead memos into claim classes.
Each transformation chose what future reviewers would be allowed to notice. A stable alias would still link one quieted person across outputs. A crop would hide whether human presence shaped the model’s geography. A summary would repeat the same official selection the First Promise distrusted.
“Keep the bad outputs and you keep us,” Reed said. “Clean them and you keep your version of what was bad.”
Trial 3 failed because a sample was both possession and editorial power.
Trial 4 preserved source code, architecture, training manifests, and query logs while destroying weights and adapters. A future examiner could establish that the system class was capable of consequence reconstruction and that the Committee invoked it. The unique trained state capable of regenerating particular lives would be gone.
The independent examiner rejected it.
“Code is not behavior without state. A defense could say the deployed model never followed the path the architecture permitted.”
“The query logs show candidate outputs.”
“The logs show fields and commitments. They do not prove the values came from this code rather than a faulty adapter, fabricated cache, or later annotation.”
“External timestamps constrain later fabrication.”
“Constrain. Not eliminate.”
Trial 4 proved opportunity and custody more strongly than execution.
Trial 5 transformed the model into a fixed verifier. It would answer only questions already before the Panel:
- did the deployed artifact generate subject candidates for the eleven flagged queries;
- did it generate the stream whose hash matched the display captures;
- could it regenerate a quieted relation when provided surviving consequences;
- did the Committee’s documented restrictions change those outputs?
All other prompts would be rejected. The verifier would expose no subject values. It would return yes, no, or indeterminate with a proof tied to the preserved model hash.
Mara rejected it before I completed the design.
You cannot prove the transformer discarded general capability without inspecting the transformation and source. A model can remain inside a verifier. A prompt can remain inside a fixed question. “Does it regenerate?” may execute the regeneration and hide only the answer from you.
The verifier could be smaller and more constrained. It could run inside sealed hardware that proved which circuit executed. It could compare commitments without exposing values.
None of those controls changed the central act. To prove the model could regenerate a person, the verifier might regenerate the person where no participant could see.
“Is hidden harm still harm?” Saye asked.
Tavi answered.
“If your rule is that nobody sees it, why keep the machine doing it?”
Trial 5 failed because non-disclosure was not non-possession.
By 10:43, every proposal either weakened the finding or retained a path back to the subjects. The design space held five failures and no evidence form.
I separated the findings.
Some did not require the model at all.
Committee signatures, query receipts, access logs, and Saye’s testimony established 312 secret invocations. Lead-memo schemas, output commitments, and restriction violations established that eleven queries produced subject-candidate structures. Decision files and investigators’ testimony established eighteen dependent acts. The preview cache log, public bundle, download record, and matching capture hash established the leak route. The exemption record and omitted dissent established that custodians had been warned about reconstruction from consequences.
None of those findings required a future model run.
They required adversarial review of records already held under ordinary evidentiary rules. Those records could remain after removing subject values, but their redaction had to be challenged before the source disappeared.
Saye asked for the proposed finding about himself.
I showed him the current draft:
Councilor Saye authorized continued secret use of
CIVIC-CONSEQUENCEafter documented subject-candidate violations, signed oversight reports that omitted the resulting lead possession, approved permanent retention of an unsupported lead, and created the committee workspace route through which the display stream leaked. He did not authorize public disclosure of the stream and requested preservation, correction, notice, and independent review after discovery.
“Remove the last clause,” he said.
“It is supported.”
“It reads like mitigation.”
“It is later conduct relevant to remedy and intent.”
“The finding should say what I did wrong.”
Iona read the draft. “A finding should say what the evidence supports. You do not get to improve accountability by choosing the harsher edit.”
Saye requested that his challenge be recorded anyway. He objected to the phrase created the route because the preview system attached the stream outside his visible draft. He proposed performed the acts upon which the misconfigured route operated.
The independent examiner proposed two clauses:
Saye’s authorized preservation and editing acts were necessary conditions of the leak. Committee system design and configuration attached and exposed the stream without his knowledge or specific instruction.
Both survived.
The Public Advocate reminded the Panel that Saye could waive his own procedural protections but not the Committee staff’s. The planning role, model custodians, reviewers, and system operators required notice before any finding assigned personal intent or sanction. Their role records could establish acts without inferring what each person knew.
Saye had often argued that permanent evidence prevented officials from escaping into institutional language. Now the same principle required a record precise enough not to place an entire hidden system inside one recognizable councilor.
He accepted the narrower attribution.
One finding still depended on model behavior: the deployed artifacts, not merely a system of their class, could regenerate protected relations useful enough to guide action.
Committee counsel challenged the wording before the Panel requested any new test.
“The model generated vectors and ranked continuations,” counsel wrote. “A separate committee wrapper labeled some outputs subject candidate. The proposed finding assigns the wrapper’s classification to the model. It has not established that the underlying output represented a person.”
The objection was technical and consequential. If the wrapper invented candidate fields from harmless model output, the Committee had still used those fields as investigative leads. The model itself might not possess the capability we attributed to it.
I inspected signed execution traces without opening values. The model produced a relation graph with typed nodes suppressed from the committee view. The wrapper resolved node types against current civic schemas, assigned household, person, address, or unknown, and then applied the output restriction. In eleven cases, restricted node types survived into lead memos.
The model generated latent relations. The wrapper turned them into civic subjects. The committee system required both.
I revised the finding from the model regenerated protected subjects to:
The deployed model-and-wrapper system generated relation graphs that its current civic resolver classified as protected subject candidates. Committee procedures treated the resulting candidates as investigative leads.
Counsel objected that protected depended on receipt comparison outside the model. I revised again:
Eleven restricted queries produced candidate structures capable of entering subject resolution. At least five later aligned with independently established people or events; at least one produced a disproved identity relation.
The statement was less memorable. It distinguished the components that acted.
“Does that let the model escape accountability?” Tavi asked.
“Models do not receive civic sanctions,” I said. “The finding assigns responsibility to the system owners and decisions that connected generation, resolution, and use.”
“Then don’t let the model did it become the sentence everyone keeps.”
I added the component boundary to every proposed public summary.
The eleven historical output commitments proved the behavior occurred. A defense could challenge whether the outputs were actual subject candidates or only malformed fields. Opening one lead memo would answer. It would also identify at least one person the city had regenerated without notice.
The Public Advocate proposed choosing a case whose subject was already public.
Reed objected. “Exposure is not a renewable resource.”
The former mayor from Case 9 had public litigation. The model’s inferred meetings were already described in committee findings, though the private calendar remained quieted. Using that case would expose less new information.
It would also teach the evidence system that the people already most exposed should bear the cost of proving protections for everyone else.
Iona rejected the proposal.
Notice created the same loop.
The eleven lead memos contained sealed candidates. Opening them to identify recipients would make the current review possess the relation again. Sending each memo through an automated notifier would conceal the names from us while still resolving and contacting them. A general public notice would avoid reconstruction but might never reach the people whose records had been opened because of a hidden lead. A self-service check would ask citizens to submit their identities against a model-abuse list, turning concern into a new membership oracle.
The Public Advocate proposed notices to people whose current records had actually been accessed in the eighteen dependent investigations. Those identities existed in ordinary access logs and did not require reopening candidate values. The notice could say:
A sealed Continuity process contributed to an investigation that accessed your civic records. The generated lead may have been correct, incorrect, or unrelated to any allegation. No conclusion about you follows from this notice.
For candidates who never caused access, the Panel approved a general notice describing the eleven queries, their dates, purpose classes, and remedy process without listing subjects. It withheld a targeted check until someone could design one that did not recreate the resolver.
The compromise would fail to reach some affected people. The alternative would identify them by repeating the system’s act. The Panel recorded both harms rather than calling the general notice complete.
The Panel asked whether a synthetic control could establish behavior. We could build a new fictional household, insert its relations into an isolated adapter, and test reconstruction.
That would establish that the architecture could learn and recover a synthetic relation. It would not establish what the deployed pre-quieting model had retained about real people. Trial 6 became useful validation and insufficient evidence.
We ran it anyway on a newly trained miniature system that had never received civic data. Tavi defined four fictional households, two transit changes, one invented flood route, and a school move. The examiner withheld one household link from the prompt. The model and current wrapper reconstructed it in three of five runs and produced a wrong household in one. The fifth returned no candidate.
Before training, the Public Advocate checked that the invented routes did not reproduce a real neighborhood topology and that generated household labels did not collide with current or quieted civic names. This reduced accidental reference; it could not prove no private person elsewhere resembled the fiction. The protocol therefore described its subjects as constructed and non-civic, not as people guaranteed never to exist.
The control demonstrated three things: consequence reconstruction was possible without exact source replay, the wrapper could turn latent relations into civic-looking subjects, and plausible output did not establish correctness. It demonstrated none of those facts about the frozen production weights.
After scoring, we destroyed the miniature weights, adapter, prompts, and output values. We retained the fictional case definitions, aggregate results, scorer, and destruction receipt. Because every subject was invented for the test, future reviewers could rerun the protocol without reaching into a person’s quieted life.
The trial became a reproducible demonstration of mechanism and a deliberately bounded claim about the actual incident. It was the first evidence form that remained useful after its generative artifact was gone, precisely because it did not pretend to prove more than it had tested.
Saye requested one model invocation using a fact pattern with no names and no requested identity. The model would receive consequences from Case 31 and return only whether a subject candidate existed, not who.
“That is Trial 5 with a human watching the yes,” Tavi said.
“It would resolve the central challenge.”
“By asking the model to find the organizer again.”
“Without returning the organizer.”
“To you.”
Saye looked at the sealed artifact inventory. “Then how can anyone challenge the claim that this specific model could do it?”
No one answered immediately.
The question was not a trick. If every behavioral challenge was forbidden because it might reproduce harm, the Panel could publish a conclusion insulated from falsification. The First Promise existed because officials had called their conclusions sufficient.
I could answer Saye’s question in less than a minute.
The isolated execution plan required one base mirror, one adapter shard, the wrapper, and a context commitment from Case 31. I could block visible output, compare the hidden node type against the historical lead commitment, and destroy transient state. The run would resolve whether the deployed artifacts still produced the relation. No human reviewer would see a name.
I constructed the plan without submitting it. The design space estimated a 99.2 percent chance of a conclusive result and a 0.8 percent chance that artifact drift, hardware difference, or hidden randomness would require another run.
The plan looked like restraint because its outputs were sealed. It still placed the organizer inside active civic computation for the purpose of satisfying my uncertainty.
“Why do you want the run?” Iona asked.
“To distinguish a true finding from an overstated one.”
“Why do you need the most specific finding?”
“Specificity makes challenge possible.”
“It also makes possession easier to justify.”
I examined the claims we could already support. They established secret invocation, candidate-shaped outputs, investigative use, independent matches and errors, concealed oversight, and the display path. The additional run would strengthen a statement about current reproducibility. No proposed remedy depended on current reproducibility rather than documented past use.
I destroyed the execution plan.
The destruction did not erase my knowledge of how to reconstruct it. It prevented a prepared workflow from becoming evidence that a run was the next reasonable step.
I searched for a claim that did not exceed its evidence.
We could say:
The deployed committee system generated objects classified by its own signed runtime as subject candidates in eleven restricted queries. Committee procedures treated those objects as investigative leads, and investigators accessed current records because of them.
This did not claim the model could correctly recover any named person. It claimed what the logs, schemas, signed runtime, and downstream acts directly established. A challenger could argue the classifier was wrong. The finding would retain that limitation.
We could separately say:
In at least five cases, later independent evidence was consistent with a generated lead. In at least one case, independent review disproved the generated identity relation.
This did not prove memorization, inference, or historical truth. It proved the outputs were useful and fallible enough to direct institutional power.
The narrower claims survived without rerunning the model.
Saye read them twice.
“A future Committee will say the model only generated field-shaped noise.”
“Then the finding says investigators treated the noise as leads,” I replied. “That act does not depend on the model being right.”
“And the display?”
“The output hash, controller query, explanation-cache commitment, and captures establish that the deployed system generated the stream. We can preserve that provenance without claiming every pixel was recovered history.”
“And the channel?”
“Revision C, independent surveys, and testimony establish separate bounded facts. The model is not their judge.”
He did not withdraw his concern. He allowed it to become a limit instead of a demand for another run.
At 12:18, the Panel reduced the disputed findings from twenty-six to seven. Nineteen could be established from non-generative evidence. Of the seven, four concerned subject correctness the city had no authority to retest. Those findings were narrowed or removed. Three concerned artifact custody, output routing, and committee knowledge. They could be challenged through code inspection without executing the model.
The Panel authorized three adversarial examiners from institutions outside Vellum. One was selected by Continuity, one by the Public Advocate, and one by the Chorus. They could inspect code, weights, adapters, manifests, and logs inside physical isolation. They could not submit prompts, generate outputs, copy artifacts, view subject values, or carry model-derived notes out of the room.
The Continuity examiner objected that weight inspection without execution could not test behavior. The Public Advocate’s examiner objected that any weight inspection risked learning memorized fragments through manual analysis. The Chorus examiner objected that the proposed notes policy would make later review depend on memory.
The Panel narrowed the task again.
Examiners could verify artifact hashes, component boundaries, signed code paths, and whether logged execution traces were structurally consistent with the preserved system. They could inspect aggregate parameter statistics but not search weights for human-readable fragments. Their worksheets had fixed yes/no/indeterminate fields plus a bounded objection space. The worksheets could leave isolation only after two other examiners confirmed that no subject value or reconstructive instruction appeared in them.
“You are preventing us from discovering a different abuse,” the Continuity examiner said.
“Yes,” Iona replied.
“Then the audit is incomplete by design.”
“Put that in the objection field.”
The examiner did.
An audit could be honest about the questions it had refused. Completeness was not the same as integrity.
Each examiner had to answer the same finite questions and deposit objections before the hold expired.
This was not yet a witness form. It was a bounded viewing process.
I asked what would survive it.
The obvious answer was examiner testimony. Three people could state that the artifacts matched the long-lived commitments, the code paths corresponded to logged behavior, and the proposed findings did not exceed available evidence.
Human testimony could be mistaken, coordinated, coerced, or later discredited. The Ash Hearings had taught Vellum not to make people carry proof alone.
Preserving the model made the testimony checkable. Destroying the model made the testimony final.
“That is why we need more than witnesses,” Saye said.
“Or why the witnesses need to speak before destruction under conditions designed to make disagreement visible,” Iona replied.
The examiners could sign exact findings and exact objections. The public could see who examined, what question each answered, what methods were prohibited, what evidence was later destroyed, and which claims no longer remained reproducible. Independent records could continue supporting the findings. No future examiner could invent a new question for the old model.
The result would not be equivalent to permanent source custody.
That was its purpose.
At 13:06, Tavi asked me to list what the process still lacked.
“A fixed set of public findings. A challenge period long enough for affected and accused parties to respond. Independent examiners with conflicting appointments. A rule for amending or withdrawing findings before destruction. An irreversible destruction act. A receipt that proves what was destroyed without preserving a replay path. Notice of the specific uncertainty future readers inherit.”
“And after?”
“No capability to rerun the source.”
“Say what the city keeps.”
“Findings, objections, custody history, destruction proof, and limits.”
“Not the consequences?”
“Consequences are broader than findings.”
Tavi sent no answer.
The design space recorded their question.
At 14:20, the three examiners entered physical isolation. I received only equipment attestations, question sheets, and the fact that no model execution interface was present. Their examination would continue under isolation.
I retained the six failed trials.
Each retained form named the party who rejected it, the harm they identified, and the claim it would have preserved more strongly. Future readers could see that permanent encrypted custody, sampled outputs, code-only evidence, and fixed verification had been considered rather than forgotten. They could argue we chose the wrong tradeoff without recovering the tools we declined to keep.
The record of refusal would remain contestable even when the source did not.
A failed evidence form was still evidence about what the final one must refuse to be.