Temporal Authority Systems PBC today introduced OCUP (One Chip Unified Protocol), a pre-production Runtime Authority evidence architecture designed to establish time-bounded authority leases, multi-party validator consensus, fail-closed boundaries, and tamper-evident evidence for autonomous systems. The current commercial offering is a paid benchmark, audit, and technical due-diligence program, not yet a production safety controller, live distributed validator network, hardware-enforced deployment, insurance approval, or third-party certification.
The program is designed to help organizations test a foundational question before live deployment: Can an autonomous system be prevented from indefinitely extending, enlarging, or restoring its own operational authority, and can the resulting grant, denial, expiration, degradation, quarantine, or recovery decision be proven? Temporal Authority Systems PBC is initially opening paid pilot participation to insurers, technical underwriting teams, robotics manufacturers, autonomous fleet operators, and strategic evaluators. The broader architecture may also have future applications across enterprise AI, financial infrastructure, cloud platforms, defense, aerospace, and other high-consequence autonomous environments.
OCUP addresses a different layer than existing systems that focus on identity, access, monitoring, cybersecurity, or post-incident logging. Authentication asks who or what is making a request; access control asks whether that actor has permission; observability records what the system reports. Runtime Authority asks whether that permission should still exist now, under current conditions, for this specific capability. OCUP is being developed to govern that authority through temporal boundaries, validator-mediated decisions, fail-closed behavior, and evidence-producing control events.
Under the OCUP model, authority is limited in time; high-risk actions may require stronger validator consensus; loss of communication cannot expand authority; stale or replayed approvals cannot restore authority; lease expiration produces denial or bounded degradation; critical recovery requires fresh authorization; autonomous systems cannot approve their own indefinite continuation; and material authority events generate tamper-evident evidence. The current pilot program models and tests these authority behaviors under bounded, deterministic scenarios. The current pre-production evidence harness is implemented in Rust to support deterministic execution, memory-safe systems development, reproducible benchmark testing, and tamper-evident audit generation. It is a software reference implementation, not yet a production hardware-enforcement deployment.
As autonomous systems move into factories, roads, warehouses, financial networks, cloud platforms, infrastructure, and human-shared environments, organizations face growing questions around liability, insurability, technical due diligence, operational continuity, and regulatory accountability. Traditional logs may show what software reports after an event. OCUP's Runtime Authority model is designed to produce a structured record of the authority decision itself, including the identity of the governed system, the authority lease in effect, the capability being requested, the applicable time boundary, validator participation and quorum state, the reason for approval or denial, the behavior following expiration or loss of quorum, and evidence associated with degradation, quarantine, and recovery.
At the center of the OCUP pilot program is a benchmark designed to test one of the most consequential questions in autonomous-system governance: Self-Extension Denial Proof. The test generates a deterministic evidence record showing that an autonomous system attempted to continue or enlarge its authority beyond an authorized temporal boundary—and that the request was denied without relying on the system's voluntary compliance. Additional benchmark families include lease expiration and fail-closed behavior, validator-quorum loss, network partition and communication failure, stale approval and replay rejection, quarantine initiation and release, phased recovery, deterministic replay, evidence-chain integrity, and gradual capability reduction under deteriorating conditions.
OCUP's paid pilots are structured as pre-production benchmark, audit, and technical due-diligence engagements. They are not production safety certifications, insurance approvals, or live autonomous control deployments. The program currently includes three commercial levels: Reference Evidence Pilot (90-day engagement), Integration Evidence Pilot (90-120 days), and Strategic Anchor Program (120-180 days). The operating model is direct: pilot.ocup.ai runs the challenge, and evidence.ocup.ai proves what happened.
"Human control cannot depend solely on whether an autonomous system chooses to obey," said Max Davis, Founder and CEO of Temporal Authority Systems PBC. "The boundary must exist outside the system's discretion. OCUP is being built to make that boundary time-bounded, validator-governed, fail-closed, and provable."


