The Semantic Enforcement Appliance
The Semantic Enforcement Appliance is the same enforcement moved out of the software control plane into a dedicated hardware datapath at the decode boundary. A gating element, biased by hardware default to a blocking state, prevents commitment of any non-accepted token, and emission is enabled only on a hardware-root-of-trust attestation that the loaded policy is unmodified. No software at any privilege level can remove or bypass it.
No verified token, no action, the constraint physically held.
The six stages
Parallel divergence lanes in dedicated silicon, arbitrated into a single verdict, asserting a hardware interrupt no software can mask. The OR-path: a deterministic Mode B rules/grammar gate fires the same interrupt into the identical stages 2–6.
No OS, hypervisor, or firmware mediating it.
One-time-programmable memory, validated by a hardware root of trust.
Pulls the output back inside the boundary.
Generates the compliance token binding the full constraint lineage to the final output.
No token, no action.
The precision paragraph
"Deterministic" describes the enforcement path: stages 2–6 run in fixed, non-bypassable order and always produce the same action for the same verdict. Stage 1 is the probabilistic input, and its reliability in semantic mode remains the design claim the validation experiment tests.
The honest boundary
Enforcement guarantees form, not meaning: output conforms to the attested policy; conformance does not by itself guarantee semantic safety, accuracy, or appropriateness. This layer governs what a system is permitted to do, not the advice an AI gives a human.
Trust relocated onto the silicon and its attestation chain, concentrated into the one place an independent party can inspect. Not abolished. The eight rules →