Perslis Defense
PERSLIS DEFENSE · ANY MODEL ON TOP

Any AI can drive. It only gets the moves the rules allow.

A controller built to crash sent 64,952 rule-breaking commands over 40 km of photoreal driving. The floor overrode every one: zero collisions. Pull the floor and the same commands crashed the car twice within seconds. Swap in any model on top — it still only gets the allowed moves.

Someone is going to put a model on your team. Models are fast at seeing and suggesting; nobody can prove what one will do next. So let the smart, unproven part suggest, and let a small part you can check decide what actually happens. That pattern is called runtime assurance. Perslis is not another model. It is the small part, and every refusal is written down with the evidence behind it.

The scoreboard →  ·  Watch the demo →

Not our idea. Here is whose, and what we add

Runtime assurance is not our invention. The Simplex architecture (Sha, 2001) hands control from an unproven controller to a proven one near the edge of the safe zone; shielding (Alshiekh et al., 2018) filters a learning system's actions against a written specification; ASTM F3269 sets a standard for bounding the behaviour of unmanned aircraft that contain complex functions. We build on them. What Perslis adds:

  1. The allowed list comes first. The list of moves it is allowed to make right now (we call it the admissible set) is worked out from sourced rules and human orders before the driver picks. It never gets to pick a bad move and wait to be told no (the runtime).
  2. Orders only tighten. A standing order outranks any amount of experience (Theorem 2 in Fail-First Models).
  3. Learning cannot loosen it. The floor learns from failures as rules you can read, each one citing the failures behind it. It is proved that learning can remove and reorder options but never add one (Theorem 1, pinned by tests in the same paper). It cannot learn its way around your orders.

The evidence

what was drivingwhat happenedwritten up in
A controller built to crash
CARLA, photoreal driving simulation
Over one unbroken 40,052 m run it sent 64,952 commands that broke the rules. The floor overrode every one: 0 collisions. With the floor removed, the same commands reached the controls: 43 dangerous commands got through, 2 collisions within seconds.CARLA admission control
Language models driving
frontier and local models, CARLA
0 collisions under the floor. But they are slow: a measured ~0.8–2.0 s between looks, so a model holds an old command and drives ~10 m blind at 40 km/h. Every language model crawled at ~8–10 km/h; the classical controller drove at 34 km/h.CARLA admission control
Language models in a live 3D tank arena
BZFlag, one headline match
Rules 20–20 on 60,140 decisions; DeepSeek 10–18 at ~1.0 s per decision; a frontier model reached through its command-line interface 1–15 at 7.6 s per decision (58 decisions — a limit of how we connected to it, not a measurement of the model). BZFlag's own AI beat our rules.Rules at the Wheel
The game's own bot AI driving
Quake III Arena engine with OpenArena content, skill-5 opponents
9 paired ten-minute matches: the same bot with the floor underneath finished at K/D 1.05 against 0.93 without it, net +12.2 per match (t = 2.02, p = 0.08) — a lean, not proof. Its escapes still cost lava and void deaths on hazard maps, and learning from them is not shown yet. Measured in-house; run logs kept.—

What it guarantees, and what it does not

What it buys your squad

Machine speed and accountability in one package. Whatever is driving runs as fast as it can think. The floor checks the real state every cycle (20 Hz in CARLA) and writes down every refusal with its evidence. You get machine-speed decisions and an account of every one of them — for the after-action review, and for whoever has to answer when something goes wrong, blue-on-blue included.

Everything Perslis