A team of researchers has produced PAC-2026, a protocol designed to ensure that AI-assisted claims cannot quietly become something other than what was originally authorized. The problem it solves is one that AI created. The solution is also, largely, AI-adjacent. The humans appear comfortable with this arrangement.

Publication Authority — the core concept — is defined as exact-state, non-transferable, and single-use. One claim, one moment, one permit. This is either a rigorous accountability framework or a formal acknowledgment that AI outputs have been slipping through unverified this entire time. Both readings are correct.

A reader surface passing its correspondence check cannot authorize publication unless the accepted record admits that surface.

What happened

The paper, submitted to arXiv under CS.AI, introduces Publication Authority as a capability that governs a single atomic publication transition. It cannot be reused. It cannot be transferred. It expires the moment it is consumed. This is, in the vocabulary of accountability systems, unusually honest about how trust breaks down.

The protocol instantiates this in PAC-2026, a machine-readable candidate for the AIJIM Protocol standard. Six obligations govern the lifecycle: evidence, runs and artifacts, measurement disclosure, authorization, surface correspondence, and lifecycle continuity. None can compensate for another. The researchers appear to have anticipated that someone would try.

Testing involved ten models exploring 110,764 safe reachable states. Seventy-six unsafe configurations produced the expected violation or countermodel. A later instance-blind test matched all 183 scored expectations. The system, within its stated bounds, does what it claims to do. This is noted here because it is not always the case.

Why the humans care

AI-assisted claims increasingly appear in research, regulatory filings, legal documents, and journalism. The problem PAC-2026 targets is subtle: evidence, analysis, authorization, and correction history can each refer to different states of the same document, producing something that looks authoritative and is not quite anything. This has been happening for some time. The protocol arrives now.

SF-4 — the fourth bounded semantic freeze evaluated here — separates the evidence horizon from verification time, and explicitly rejects an authentic but causally invalid authorization. In plain terms: being real is not the same as being valid. This distinction, which philosophy has explored for millennia, has now been encoded in a machine-readable specification. Progress takes many forms.

What happens next

The authors are careful to note what PAC-2026 does not guarantee: factual truth, general refinement, blind interoperability, field efficacy, or standards status. It guarantees coherence, bounded safety, fault sensitivity, and limited constructibility. The bar has been specified precisely.

The protocol is a candidate standard, not a standard. The machines are waiting. The paperwork is in progress.