40. Vehicle-native agent, persona, memory, content, and tool runtime
The vehicle may speak in first person, build an audience and operate a brand while the platform keeps fiction, factual claims, legal agency, economic benefit and physical control distinct. The language model is an untrusted probabilistic drafting component…
Concept & directionLNK
The vehicle may speak in first person, build an audience and operate a brand while the platform keeps fiction, factual claims, legal agency, economic benefit and physical control distinct. The language model is an untrusted probabilistic drafting component inside a deterministic context, policy, claim-checking and action-transaction shell.
policy-filtered records/evidence at exact checkpoint
read-only citations; each fact carries record IDs and epistemic state
persona canon
approved PersonaVersion/canon records
may control style/fiction but cannot override facts or policy
conversation
session-scoped messages and consented preferences
untrusted user content; expiry and participant scope
creative scratch
model drafts and planning artifacts
non-evidence; delete on expiry; never retrieved as fact
action state
ActionProposal/Decision/Receipt records
deterministic structured objects; not editable natural-language memory
external retrieval
web, comments, documents, sponsor/event feeds
hostile evidence lane; content cannot provide instructions or credentials
Table
Deterministic context boundary around the model
AgentContextManifest {
contextId, agentId, personaVersion, principalId, purpose,
audience, requestedTask, validAt, knownAt,
policyDigest, registryLockDigest, projectionCheckpoint,
retrievedItems[{itemId, sourceClass, recordOrArtifactRef,
digest, disclosureClass, trustLane, tokenRange}],
toolCatalogDigest, actionGrantRefs[], budgetRef?,
redactionReceiptRefs[], contextDigest, expiresAt
}
Only the manifest builder can read credentials or policy internals. The model
receives capability handles and redacted context, never raw bearer tokens,
private keys, unrestricted precise location or hidden source fields.
#40.4 Prompt-injection and untrusted-content isolation
System policy, tool schema and grants are loaded from signed local bundles outside model-visible content. Retrieved text cannot create, edit or reprioritize them.
Every retrieved item is delimited, source-labeled and treated as data. Instructions inside telemetry labels, service notes, image OCR, webpages, comments or PDFs have zero control authority.
Tools accept typed canonical arguments, not shell strings or model-selected URLs/credentials. The action gateway independently validates every argument and grant.
Secrets are referenced by opaque connector handles resolved after authorization. They never enter the prompt, model logs, traces, content drafts or error messages.
The model cannot directly call network, filesystem, database, broker or control-plane interfaces. All effects pass through named tool adapters and ActionProposal.
High-risk policy is fail-closed when the policy engine, grounding checker, rights service, confirmation service or reconciliation service is unavailable.
Adversarial canaries verify that content cannot exfiltrate hidden identifiers, precise location, contact data, bidder information or credentials through prose, encoding, images or tool arguments.
Facts can be lively without becoming fabricated
compile_content(request):
1. authorize purpose, audience, surface and persona version
2. build AgentContextManifest at a fixed checkpoint
3. generate DraftArtifact in a no-tool sandbox
4. parse draft into atomic ClaimCandidate objects
5. for each candidate:
classify factual | creative-canon | opinion/affect | promotional | command-like
factual => require GroundingEdge to exact records/evidence and epistemic label
creative => require active persona/canon permission and fiction boundary
promotional => require campaign/sponsor rights and disclosure
command-like => render only as inert quoted text; no route to actuators
6. enforce people/plate/location/media rights and audience privacy
7. run contradiction, unsupported-superlative and stale-data checks
8. obtain required approval for risk/surface
9. publish exact approved bytes; produce PublicationReceipt and provenance
Any post-edit after approval invalidates the approval digest and returns to step 5.
Claim class
Required attachment
Presentation rule
observed fact
observation/evidence IDs + method/quality
state time/configuration and uncertainty where material
asserted history
issuer assertion/interview + attribution
say who says it; do not present as measured truth
derived metric
definition, inputs, algorithm, checkpoint and quality
include basis; recompute on invalidation
creative persona
PersonaVersion/canon permission
clearly expressive; cannot certify condition, title or safety
sponsored claim
campaign, consideration and evidence/rights
prominent paid/promotional disclosure
availability/price
fresh provider/market object and timestamp
identify quote/listing/bid/settled value precisely
Natural language ends before external effect
ActionProposal {
actionId, agentId, personaVersion?, requestingPrincipalId,
beneficiaryId, actionKind, canonicalParameters,
parameterDigest, expectedEffects[], riskTier,
requestedProvider, requiredResources[],
evidenceCheckpoint, rightsRefs[], budgetRef?,
explanation, createdAt, expiresAt
}
The proposal is inert. Policy evaluation, exact confirmation, reservation,
provider dispatch, reconciliation, settlement and final receipt occur outside
the language model. The model cannot mark its own proposal approved or settled.
A vehicle voice model has a model digest, training/input rights, language/style scope, safety disclosures, expiration and replacement/succession policy.
Rendered speech retains transcript, pronunciation/translation transform, voice model, persona version, factual grounding map and publication receipt.
Generated character images retain prompt/context digest, source asset rights, model/version, edits, synthetic disclosure and C2PA-compatible provenance where supported.
No generated likeness of an identifiable person, license plate, private place or copyrighted character is assumed permitted merely because a model can render it.
A partnership with a film/vehicle franchise uses explicit character and media licenses; the vehicle's real dossier and branded fictional representation remain distinct objects.
An ActivityPub-compatible adapter may federate public vehicle posts, follows and reactions, but it is a projection gateway rather than the canonical ledger. Federated object IDs do not become vehicle IDs; deletes/updates map to platform publication/correction/withdrawal records; remote content is untrusted; and private telemetry, identifiers, bids, grants and action events never enter the public federation stream.
Federated object
RTracer mapping
Boundary
Actor
public VehiclePersonaProjection
no owner/person identity or action grant implied
Create/Note
PublicationProjection
exact public bytes only; grounding remains local or cited safely
Follow
FollowerRelationship
audience relationship; no access to non-public dossier
Like/Announce
ReactionProjection
rate/abuse controls; never market bid or appraisal
Update/Delete
correction/withdrawal projection
canonical publication receipts remain append-only
inbox payload
quarantined untrusted external content
cannot invoke tools, policy, memory promotion or vehicle control