Biological Motifs for Agentic Control
Summary
This paper develops a typed interface correspondence between Gene Regulatory Networks and agentic software systems using polynomial functors and wiring diagrams, mapping five biological motifs to composable software design patterns to address reliability and security challenges in autonomous AI agents.
View Cached Full Text
Cached at: 07/07/26, 04:36 AM
# Biological Motifs for Agentic Control A Typed Interface Correspondence between Gene Regulatory Networks and Agentic Software Architectures Preprint – Feedback Welcome
Source: [https://arxiv.org/html/2607.04240](https://arxiv.org/html/2607.04240)
###### Abstract
The transition of Large Language Models \(LLMs\) from passive generators to autonomous agents has introduced significant challenges in reliability, security, and state management\. Current agentic architectures are often constructed ad\-hoc, prone to “hallucination cascades,” infinite loops, and prompt injection attacks\. This paper argues that many of these failure modes can be analyzed using control motifs long studied in systems biology, provided the comparison is made at the level of typed interfaces and coordination structure rather than literal biological mechanism\.
We develop a typed interface correspondence between Gene Regulatory Networks and agentic software systems using polynomial functors and wiring diagrams\. Five biological motifs—Coherent Feed\-Forward Loops for noise suppression, Adaptive Immunity for layered security, Mitochondrial Signaling for resource governance, Endosymbiosis for neuro\-symbolic integration, and Morphogen Diffusion for spatially varying coordination—are mapped to composable software design patterns\. An epistemic topology layer derives Kripke\-style knowledge operators from the wiring diagram’s observation structure and proves four predictive theorems for multi\-agent scaling\.
The core contributions are: \(1\) the Agentic Operad, a typed syntax for agent composition with provable error suppression bounds for feed\-forward topologies; \(2\) an epistemic topology with four theorems—error amplification, sequential penalty, parallel acceleration, and tool density scaling—whose qualitative predictions are consistent with published multi\-agent benchmarks; and \(3\) a six\-layer progression from structure through development, grounded in autonomous learning frameworks and convergence proxies from the empirical literature\. A reference implementation with 1,813 tests and 116 examples illustrates practical feasibility\.
###### Contents
1. [1Introduction](https://arxiv.org/html/2607.04240#S1)1. [1\.1The Biological Heuristic](https://arxiv.org/html/2607.04240#S1.SS1) 2. [1\.2The Categorical Bridge](https://arxiv.org/html/2607.04240#S1.SS2) 3. [1\.3Contributions](https://arxiv.org/html/2607.04240#S1.SS3)
2. [2Related Work](https://arxiv.org/html/2607.04240#S2)1. [2\.1Network Motifs in Systems Biology](https://arxiv.org/html/2607.04240#S2.SS1) 2. [2\.2Applied Category Theory \(ACT\)](https://arxiv.org/html/2607.04240#S2.SS2) 3. [2\.3The Architecture Triple](https://arxiv.org/html/2607.04240#S2.SS3) 4. [2\.4Reliability in Agentic AI](https://arxiv.org/html/2607.04240#S2.SS4) 5. [2\.5Epistemic Logic in Distributed Systems](https://arxiv.org/html/2607.04240#S2.SS5) 6. [2\.6Temporal Databases and Bi\-Temporal Data Models](https://arxiv.org/html/2607.04240#S2.SS6) 7. [2\.7Adaptive Multi\-Agent Assembly and Meta\-Control](https://arxiv.org/html/2607.04240#S2.SS7)
3. [3The Mapping: Biology↔\\leftrightarrowSoftware](https://arxiv.org/html/2607.04240#S3)1. [3\.1Preliminaries: The Category𝐏𝐨𝐥𝐲\\mathbf\{Poly\}](https://arxiv.org/html/2607.04240#S3.SS1) 2. [3\.2The Correspondence: Genes and Agent Capabilities](https://arxiv.org/html/2607.04240#S3.SS2) 3. [3\.3The Interface: Promoters as Lenses](https://arxiv.org/html/2607.04240#S3.SS3) 4. [3\.4Wire\-Level Optics: Beyond Lenses](https://arxiv.org/html/2607.04240#S3.SS4) 5. [3\.5Epigenetics and State: The Coalgebra](https://arxiv.org/html/2607.04240#S3.SS5) 6. [3\.6The Correspondence, Made Precise](https://arxiv.org/html/2607.04240#S3.SS6) 7. [3\.7Metabolic Coalgebras: Formalizing Resource Constraints](https://arxiv.org/html/2607.04240#S3.SS7) 8. [3\.8Additional Organelles: Completing the Cellular Architecture](https://arxiv.org/html/2607.04240#S3.SS8)
4. [4Formal Syntax: The Agentic Operad](https://arxiv.org/html/2607.04240#S4)1. [4\.1The Typing Rules](https://arxiv.org/html/2607.04240#S4.SS1) 2. [4\.2The Composition Operations](https://arxiv.org/html/2607.04240#S4.SS2)1. [4\.2\.1Parallel Composition \(⊗\\otimes\)](https://arxiv.org/html/2607.04240#S4.SS2.SSS1) 2. [4\.2\.2Serial Composition \(∘\\circ\)](https://arxiv.org/html/2607.04240#S4.SS2.SSS2) 3. [4\.2\.3Contraction / Trace \(TrTr\)](https://arxiv.org/html/2607.04240#S4.SS2.SSS3) 3. [4\.3Theorem: Topological Error Suppression](https://arxiv.org/html/2607.04240#S4.SS3) 4. [4\.4Quorum Sensing \(Consensus & Voting\)](https://arxiv.org/html/2607.04240#S4.SS4) 5. [4\.5Chaperone Proteins: Output Structural Validation](https://arxiv.org/html/2607.04240#S4.SS5) 6. [4\.6Innate Immunity: Fast Pattern\-Based Defense](https://arxiv.org/html/2607.04240#S4.SS6) 7. [4\.7Adaptive Immunity: Self/Non\-Self Discrimination](https://arxiv.org/html/2607.04240#S4.SS7) 8. [4\.8Oscillator: Periodic Rhythms and Scheduling](https://arxiv.org/html/2607.04240#S4.SS8)
5. [5Failure Modes & Pathology](https://arxiv.org/html/2607.04240#S5)1. [5\.1Oncology: Infinite Loops as Epistemic Starvation](https://arxiv.org/html/2607.04240#S5.SS1) 2. [5\.2Autoimmunity: Hallucination Cascades](https://arxiv.org/html/2607.04240#S5.SS2) 3. [5\.3Prion Disease: Topological Corruption via Prompt Injection](https://arxiv.org/html/2607.04240#S5.SS3) 4. [5\.4Ischemia: Resource Exhaustion](https://arxiv.org/html/2607.04240#S5.SS4) 5. [5\.5Homeostasis: From Treatment to Continuous Repair](https://arxiv.org/html/2607.04240#S5.SS5)1. [5\.5\.1Structural Healing: The Chaperone Loop](https://arxiv.org/html/2607.04240#S5.SS5.SSS1) 2. [5\.5\.2Metabolic Healing: Apoptosis and Regeneration](https://arxiv.org/html/2607.04240#S5.SS5.SSS2) 3. [5\.5\.3Cognitive Healing: Autophagy](https://arxiv.org/html/2607.04240#S5.SS5.SSS3)
6. [6Multi\-Cellular Organization: From Agents to Tissues](https://arxiv.org/html/2607.04240#S6)1. [6\.1Cell Types and Agent Specialization](https://arxiv.org/html/2607.04240#S6.SS1) 2. [6\.2Morphogen Gradients: Coordination Without Central Control](https://arxiv.org/html/2607.04240#S6.SS2) 3. [6\.3Tissue Architecture: The Agent Graph as Organism](https://arxiv.org/html/2607.04240#S6.SS3)
7. [7Epistemic Topology](https://arxiv.org/html/2607.04240#S7)1. [7\.1Temporal Epistemics: What Did the Agent Know?](https://arxiv.org/html/2607.04240#S7.SS1) 2. [7\.2Predictive Theorems for Multi\-Agent Coordination](https://arxiv.org/html/2607.04240#S7.SS2) 3. [7\.3Epistemic Dynamics and Adaptive Topology](https://arxiv.org/html/2607.04240#S7.SS3)
8. [8Discussion: Towards “Epigenetic” Software](https://arxiv.org/html/2607.04240#S8)1. [8\.1RAG as Digital Methylation](https://arxiv.org/html/2607.04240#S8.SS1)1. [8\.1\.1Metabolic\-Epigenetic Coupling](https://arxiv.org/html/2607.04240#S8.SS1.SSS1) 2. [8\.2Horizontal Gene Transfer: Dynamic Tool Loading](https://arxiv.org/html/2607.04240#S8.SS2) 3. [8\.3The Cost of State](https://arxiv.org/html/2607.04240#S8.SS3) 4. [8\.4Endosymbiosis: The Neuro\-Symbolic Integration](https://arxiv.org/html/2607.04240#S8.SS4) 5. [8\.5Temporal State in Agentic Systems](https://arxiv.org/html/2607.04240#S8.SS5) 6. [8\.6Bioenergetic Intelligence: Beyond the Battery Metaphor](https://arxiv.org/html/2607.04240#S8.SS6)1. [8\.6\.1The Vermeij Trend: Why Agents Must Evolve](https://arxiv.org/html/2607.04240#S8.SS6.SSS1) 2. [8\.6\.2Immune Evasion and Adversarial Limits](https://arxiv.org/html/2607.04240#S8.SS6.SSS2) 7. [8\.7Harness Engineering as Architecture](https://arxiv.org/html/2607.04240#S8.SS7) 8. [8\.8Boundary Conditions: When the Correspondence Earns Its Keep](https://arxiv.org/html/2607.04240#S8.SS8)
9. [9Diagram Optimization via Categorical Rewriting](https://arxiv.org/html/2607.04240#S9)1. [9\.1Cost\-Annotated Diagrams](https://arxiv.org/html/2607.04240#S9.SS1) 2. [9\.2Rewriting Rules as Endofunctors](https://arxiv.org/html/2607.04240#S9.SS2) 3. [9\.3Critical Path Analysis](https://arxiv.org/html/2607.04240#S9.SS3) 4. [9\.4Resource\-Aware Execution](https://arxiv.org/html/2607.04240#S9.SS4) 5. [9\.5Relation to Abbott & Zardini](https://arxiv.org/html/2607.04240#S9.SS5)
10. [10Reference Implementation](https://arxiv.org/html/2607.04240#S10)1. [10\.1Architecture Overview](https://arxiv.org/html/2607.04240#S10.SS1) 2. [10\.2Immune System Implementation](https://arxiv.org/html/2607.04240#S10.SS2) 3. [10\.3Adaptive Immune Layer: VerifierComponent](https://arxiv.org/html/2607.04240#S10.SS3) 4. [10\.4G1/S Checkpoint: CertificateGateComponent](https://arxiv.org/html/2607.04240#S10.SS4) 5. [10\.5Chaperone Implementation](https://arxiv.org/html/2607.04240#S10.SS5) 6. [10\.6Trust and Provenance](https://arxiv.org/html/2607.04240#S10.SS6) 7. [10\.7Plasmid Registry Implementation](https://arxiv.org/html/2607.04240#S10.SS7) 8. [10\.8Denaturation Layers Implementation](https://arxiv.org/html/2607.04240#S10.SS8) 9. [10\.9Multi\-Cellular Organization Implementation](https://arxiv.org/html/2607.04240#S10.SS9) 10. [10\.10Bi\-Temporal Memory Implementation](https://arxiv.org/html/2607.04240#S10.SS10) 11. [10\.11Coalgebraic State Machines Implementation](https://arxiv.org/html/2607.04240#S10.SS11) 12. [10\.12Morphogen Diffusion Implementation](https://arxiv.org/html/2607.04240#S10.SS12) 13. [10\.13Optic\-Based Wiring Implementation](https://arxiv.org/html/2607.04240#S10.SS13) 14. [10\.14Interactive Demonstrations](https://arxiv.org/html/2607.04240#S10.SS14) 15. [10\.15Implementation Verification \(Synthetic Harness\)](https://arxiv.org/html/2607.04240#S10.SS15) 16. [10\.16Limitations](https://arxiv.org/html/2607.04240#S10.SS16)
11. [11Convergence: Integrating External Agent Frameworks](https://arxiv.org/html/2607.04240#S11)
12. [12Conclusion](https://arxiv.org/html/2607.04240#S12)
13. [References](https://arxiv.org/html/2607.04240#bib)
## 1Introduction
The field of Artificial Intelligence is undergoing a paradigm shift from Generative AI \(systems that produce text based on static prompts\) to Agentic AI \(systems that execute multi\-step workflows to achieve autonomous goals\)\. While the capabilities of individual Large Language Models \(LLMs\) have scaled predictably, the engineering of systems of agents remains a fragile art\. Developers struggle with non\-deterministic outputs, infinite loops, adversarial attacks, and the difficulty of maintaining global coherence in distributed, stochastic systems\.
We argue that these challenges are not purely ad\-hoc engineering problems, but recurring constraints of distributed information processing systems\. A useful formal analogue is provided by Gene Regulatory Networks \(GRNs\)\. At the atomic level, a gene and an agent capability both expose typed interfaces that consume local signals and produce downstream effects\. At the composite level, a biological cell organizes many genes plus shared infrastructure \(organelles, membrane\); analogously, an executable agent organizes many capabilities plus shared runtime components\. This multi\-scale correspondence, rather than a literal identity of mechanisms, is the organizing hypothesis of the paper\.
### 1\.1The Biological Heuristic
Biology has evolved specific topological structures, known as Network Motifs, to handle noise, security, and state\[[32](https://arxiv.org/html/2607.04240#bib.bib1)\]\. We identify five critical biological heuristics that map directly to agentic engineering:
- •The Coherent Feed\-Forward Loop \(CFFL\): in biology a persistence detector that filters transient input pulses\[[4](https://arxiv.org/html/2607.04240#bib.bib2)\]; its conjunctive \(AND\-gate\) form underlies redundant\-verification gates such as “Human\-in\-the\-Loop” guardrails, where an action requires a second, independent approval\.
- •Quorum Sensing: A distributed consensus mechanism where action is taken only when signal density exceeds a threshold, analogous to self\-consistency or majority voting over sampled outputs \(an agreement threshold, distinct from Mixture\-of\-Experts routing\)\.
- •Chaperone Proteins: Molecular cages that force proteins to fold correctly, analogous to Schema Validators that enforce structured outputs \(JSON\)\.
- •Mitochondrial Information Processing: Metabolic constraints acting as a “Motherboard” for decision gating, governing not just energy availability but cognitive control policy\.
- •Adaptive Immunity: The Self/Non\-Self distinction, with MHC\-like provenance tagging and Trust\-Gated access control, relevant to preventing Prompt Injection attacks and hallucination cascades\.
### 1\.2The Categorical Bridge
To move this observation from metaphor to discipline, we utilize Applied Category Theory\. We define a category\-theoretic model of agentic interfaces using the language of𝐏𝐨𝐥𝐲\\mathbf\{Poly\}\(Polynomial Functors\) as described by Spivak\[[40](https://arxiv.org/html/2607.04240#bib.bib3)\]\. We use𝐏𝐨𝐥𝐲\\mathbf\{Poly\}as a common language for typed interfaces and wiring diagrams as a language for composition\. The claim is not that GRNs and software agents are identical physical systems, but that selected biological and agentic components can be compared within the same interface\-level formalism\. Proposition[1](https://arxiv.org/html/2607.04240#Thmproposition1)states this precisely as a shared interpretation into the category𝐂𝐨𝐚𝐥𝐠\(𝐏𝐨𝐥𝐲\)\\mathbf\{Coalg\}\(\\mathbf\{Poly\}\)—a substrate independence in the sense of Marom et al\.\[[30](https://arxiv.org/html/2607.04240#bib.bib69)\], not an isomorphism between the domains\. A capability is then described not by its weights, but by its interface—a dynamical system consuming observations and producing actions:
PA\(y\)=∑o∈OyIo\.P\_\{A\}\(y\)=\\sum\_\{o\\in O\}y^\{I\_\{o\}\}\.\(1\)
### 1\.3Contributions
This paper makes the following contributions:
##### Structural Safety\.
1. 1\.A Typed Correspondence:We establish a disciplined mapping between biological components \(Genes, Promoters, Plasmids, Organelles\) and software components \(Capabilities, Schemas, Tools, Runtimes\), including multi\-cellular organization for multi\-agent systems\.
2. 2\.The Agentic Operad:We define WAgent, a syntax for agent wiring that forbids specific classes ofill\-typed wiringsat the topological level\. We prove error suppression bounds for the CFFL topology, explicitly accounting for correlation between error modes\.
3. 3\.Wire\-Level Optics:We extend the Lens formalism with Prism \(conditional type\-based routing\) and Traversal \(batch element\-wise processing\) optics, enabling richer signal processing at the wiring level\.
4. 4\.Composable Coalgebras:We make the coalgebraic state machine framework explicit and composable, with parallel/sequential composition and observational equivalence criteria\.
##### Security and Trust\.
1. 5\.Adaptive Immunity:We formalize the Provenance Functor and Trust\-Gated Lens, providing structural resistance to content\-level trust forgery, where content\-based attacks cannot elevate trust levels\.
2. 6\.Pathology & Homeostasis:We classify agentic failures as biological diseases and derive continuous self\-repair mechanisms \(Chaperone Loop, Regeneration, Autophagy\)\.
3. 7\.Capability\-Gated Tool Acquisition:The Plasmid Registry implements Horizontal Gene Transfer with capability gating, preventing privilege escalation when agents dynamically acquire tools\.
##### Epistemic and Metabolic Intelligence\.
1. 8\.Epistemic Health:We define Epiplexity \(Bayesian Surprise\) with operational approximations using embedding similarity and perplexity, connecting agent dynamics to the Free Energy Principle\.
2. 9\.Metabolic Intelligence:We distinguish fast \(Apoptosis\) and slow \(Retrograde Response\) interventions, and formalize the Metabolic\-Epigenetic Coupling for cost\-gated retrieval\.
3. 10\.Evolutionary Dynamics:We situate agentic AI within the Vermeij Trend, identifying three selective pressures \(adversarial, complexity, efficiency\) that drive architectural evolution\.
4. 11\.Morphogen Diffusion:We formalize spatially varying coordination as a discrete\-time dynamical system on the agent graph, producing position\-dependent behavior without central control\.
5. 12\.Epistemic Topology:We derive Kripke\-style knowledge operators from wiring diagram structure and prove four predictive theorems for multi\-agent scaling \(error amplification, sequential penalty, parallel acceleration, tool density\), then check their qualitative consistency with published architecture\-level results\.
##### Optimization\.
1. 13\.Diagram Optimization:Cost\-annotated wiring diagrams admit categorical rewriting rules that preserve observational equivalence while improving resource utilization\.
By viewing agentic engineering through the lens of theoretical biology and category theory, we aim to provide a framework for building robust software systems whose stability properties derive in part from their network topology\.
## 2Related Work
This work sits at the intersection of Systems Biology, Applied Category Theory, and Agentic AI\. While significant research exists within each domain, the formal synthesis of biological control topologies with agentic software architectures has received limited attention\.
### 2\.1Network Motifs in Systems Biology
The concept of “Network Motifs”—statistically over\-represented sub\-graphs in complex networks—was introduced by Milo et al\.\[[32](https://arxiv.org/html/2607.04240#bib.bib1)\]\. Their work demonstrated that biological networks are not random but are composed of specific building blocks selected for functional data processing\. Alon\[[4](https://arxiv.org/html/2607.04240#bib.bib2)\]further characterized the dynamical properties of these motifs, identifying the Coherent Feed\-Forward Loop \(CFFL\) as a persistence detector\. We extend this by mapping these motifs to the stochastic nature of Generative AI\.
### 2\.2Applied Category Theory \(ACT\)
To formalize network structure, we draw upon ACT\. Fong and Spivak\[[18](https://arxiv.org/html/2607.04240#bib.bib5)\]provide a comprehensive introduction to Applied Category Theory\. Spivak\[[40](https://arxiv.org/html/2607.04240#bib.bib3)\]and Vagner et al\.\[[41](https://arxiv.org/html/2607.04240#bib.bib4)\]established a rigorous framework for modeling Open Dynamical Systems using the category𝐏𝐨𝐥𝐲\\mathbf\{Poly\}and the Operad of Wiring Diagrams\. Niu and Spivak\[[34](https://arxiv.org/html/2607.04240#bib.bib12)\]develop the full mathematical theory of polynomial functors as a language for interaction\. Marom et al\.\[[30](https://arxiv.org/html/2607.04240#bib.bib69)\]independently relate biological and engineered stimulus–response systems by a structure\-preserving functor between subcategories of dynamical systems, articulating the substrate\-independence principle we adopt in §[3](https://arxiv.org/html/2607.04240#S3): systems sharing compositional structure can be related by interface logic alone, without sharing a physical substrate\. To our knowledge, this is the first application of Polynomial Functors specifically designed to model the interface of LLM Agents and to verify safety properties in Agentic topologies\.
### 2\.3The Architecture Triple
De los Riscos et al\.\[[13](https://arxiv.org/html/2607.04240#bib.bib45)\]introduce theArchAgentscategory, whose objects are*Architecture triples*A=\(G,Know,Φ\)A=\(G,\\mathrm\{Know\},\\Phi\):GGis the syntactic wiring \(typed modules and ports\),Know\\mathrm\{Know\}is the structural knowledge the architecture maintains—its invariants and*certificates*—andΦ\\Phiis the deployment map from abstract capability slots to concrete model and tool implementations\. A*certificate*is a triple\(τ,σ,evds\)\(\\tau,\\sigma,\\mathrm\{evds\}\): a theorem statementτ\\tau, a mapσ\\sigmafrom its symbols to architecture parameters, and a mechanically replayable derivationevds\\mathrm\{evds\}\[[10](https://arxiv.org/html/2607.04240#bib.bib76)\]\. Morphisms are structure\-preserving translations—in practice,*compilers*between frameworks\. Together with the shared\-interface correspondence of §[3](https://arxiv.org/html/2607.04240#S3), this triple is one of the two categorical objects this monograph builds on; it recurs below as the carrier of Operon’s structural guarantees\.
### 2\.4Reliability in Agentic AI
Techniques such as “Chain of Thought”\[[45](https://arxiv.org/html/2607.04240#bib.bib7)\]utilize iterative looping to improve output quality\. However, these methods operate primarily at the level of the prompt \(the input signal\) rather than the topology \(the wiring\)\. By importing the concept of Autopoiesis\[[31](https://arxiv.org/html/2607.04240#bib.bib6)\], we propose a methodology where reliability is a property of the network architecture itself\.
### 2\.5Epistemic Logic in Distributed Systems
Fagin et al\.\[[16](https://arxiv.org/html/2607.04240#bib.bib25)\]established the foundational framework for reasoning about knowledge in multi\-agent systems, formalizing what agents know and what they know about each other’s knowledge\. Halpern and Moses\[[20](https://arxiv.org/html/2607.04240#bib.bib26)\]proved the impossibility of attaining common knowledge in asynchronous systems, a result with deep implications for coordination protocols\. To our knowledge, these formal methods from epistemic logic have not previously been applied to the design and optimization of multi\-agent AI architectures\.
### 2\.6Temporal Databases and Bi\-Temporal Data Models
Bi\-temporal data management—tracking both*valid time*\(when a fact is true in the world\) and*transaction time*\(when the system recorded it\)—has been studied extensively in the database community\. Snodgrass\[[39](https://arxiv.org/html/2607.04240#bib.bib28)\]provided the foundational treatment, distinguishing valid\-time, transaction\-time, and bi\-temporal relations, and demonstrating that the two time axes are orthogonal: a fact may be recorded before it becomes valid, corrected after it ceases to be valid, or both\. SQL:2011\[[26](https://arxiv.org/html/2607.04240#bib.bib29)\]standardized temporal query support, includingFOR SYSTEM\_TIMEandFOR BUSINESS\_TIMEclauses\.
### 2\.7Adaptive Multi\-Agent Assembly and Meta\-Control
Dupoux, LeCun, and Malik\[[15](https://arxiv.org/html/2607.04240#bib.bib30)\]propose a three\-system cognitive architecture: System A \(observational, statistical, cheap\) discovers representations, System B \(action\-oriented, goal\-directed, expensive\) discovers causal structure, and System M \(meta\-control\) routes data between them\. This tripartite structure maps naturally onto Operon’s fast/deep nucleus distinction and motivates theWatcherComponentas a concrete instantiation of System M \(§[6\.3](https://arxiv.org/html/2607.04240#S6.SS3.SSS0.Px4)\)\.
Hao et al\.\[[21](https://arxiv.org/html/2607.04240#bib.bib31)\]demonstrate empirically that incorrect multi\-agent runs require systematically more routing decisions than successful ones \(e\.g\., 9\.4 vs 7\.3 mean decisions on planning tasks\)\. This finding grounds our use of intervention count as a convergence proxy: when the watcher’s cumulative retry/escalate count exceeds a threshold relative to stage count, it emits a non\-convergence signal and halts the organism \(§[10\.10](https://arxiv.org/html/2607.04240#S10.SS10.SSS0.Px7)\)\.
Jiang et al\.\[[22](https://arxiv.org/html/2607.04240#bib.bib32)\]provide a structure\-oriented taxonomy of Memory\-Augmented Generation \(MAG\) systems, categorizing them into lightweight semantic, entity\-centric, episodic/reflective, and structured/hierarchical designs\. Their empirical analysis reveals that append\-only memory architectures are significantly more robust to backbone format errors than complex structured alternatives—a finding that validates Operon’s design decision to makeBiTemporalMemoryappend\-only\. They also quantify the “Agency Tax” \(latency and token overhead of memory maintenance\), highlighting a practical concern that the convergence with operational runtimes must address\.
Lin et al\.\[[27](https://arxiv.org/html/2607.04240#bib.bib33)\]propose MemMA, a multi\-agent framework coordinating the full memory cycle through a planner\-worker architecture with in\-situ self\-evolution\. Their Meta\-Thinker provides strategic guidance for both memory construction and retrieval, analogous to Operon’sWatcherComponentproviding intervention decisions\. Their probe\-based memory verification—generating synthetic questions after each session to test memory fidelity, then repairing failures immediately—complements Operon’scounterfactual\_replay\(\), which detects corrections but does not actively probe for gaps\.
Feng, Wang, and Zhu\[[17](https://arxiv.org/html/2607.04240#bib.bib34)\]propose Self\-evolving Embodied AI, a paradigm comprising five co\-evolving components: memory self\-updating, task self\-switching, environment self\-prediction, embodiment self\-adaptation, and model self\-evolution\. These map directly onto Operon’s phased roadmap \(bi\-temporal memory, adaptive assembly, sleep consolidation, developmental staging, and social learning respectively\), and their emphasis on multi\-timescale closed\-loop co\-evolution aligns with Operon’s per\-stage \(watcher\), per\-run \(adaptive\), and per\-batch \(consolidation\) adaptation cycles\.
Zhou et al\.\[[46](https://arxiv.org/html/2607.04240#bib.bib55)\]provide a unified review of agent externalization through four pillars—Memory, Skills, Protocols, and Harness Engineering—tracing the progression from weights\-based to harness\-centric agent design\. Their framework maps directly onto Operon’s categorical Architecture triple: Memory corresponds to the coalgebraic state \(BiTemporalMemory\), Skills to objects composed via the agentic operad \(SkillStage\), Protocols to syntactic wiring \(WiringDiagram\), and the Harness to the full Architecture\(G,Know,Φ\)\(G,\\mathrm\{Know\},\\Phi\)\. Their observation that “agent infrastructure transforms hard cognitive burdens into manageable forms” is precisely the claim our structural guarantee benchmarks \(§[10\.15](https://arxiv.org/html/2607.04240#S10.SS15)\) validate empirically\.
Ma et al\.\[[29](https://arxiv.org/html/2607.04240#bib.bib56)\]demonstrate that five atomic coding skills—localization, editing, unit\-test generation, issue reproduction, and code review—compose without negative interference under joint reinforcement learning, an 18\.7% average improvement over task\-specific optimization\. This is favorable empirical evidence for the operad composition model \(§[4](https://arxiv.org/html/2607.04240#S4)\), with one caveat we keep explicit: the operad preserves*typed and structural*properties \(interface compatibility, certificate replay\) by construction, but*behavioral*quality under composition is empirical—our own benchmarks find mostly non\-interference alongside one negative case\[[9](https://arxiv.org/html/2607.04240#bib.bib53)\]\.
We apply bi\-temporal data management\[[39](https://arxiv.org/html/2607.04240#bib.bib28),[26](https://arxiv.org/html/2607.04240#bib.bib29)\]to agentic memory in §[3\.5](https://arxiv.org/html/2607.04240#S3.SS5)and §[7\.1](https://arxiv.org/html/2607.04240#S7.SS1)\.
## 3The Mapping: Biology↔\\leftrightarrowSoftware
To compare Agentic Systems and Gene Regulatory Networks \(GRNs\) under a common typed\-interface abstraction, we map selected components from both domains to a shared mathematical object\. We utilize the category𝐏𝐨𝐥𝐲\\mathbf\{Poly\}, where objects are polynomial functors representing interfaces, and morphisms represent interaction protocols\. The claim in this section is a correspondence of interface descriptions, not a proof that the full biological and software domains are equivalent in mechanism, implementation, or dynamics\.
### 3\.1Preliminaries: The Category𝐏𝐨𝐥𝐲\\mathbf\{Poly\}
In Applied Category Theory, a Polynomial FunctorPPrepresents a typed interface for a dynamical system\. It is defined as a sum of representable functors:
P\(y\)=∑o∈OyIo\.P\(y\)=\\sum\_\{o\\in O\}y^\{I\_\{o\}\}\.\(2\)Here,OOis the set of possible Positions \(or Outputs\) the system can expose\. For each positiono∈Oo\\in O, there is a setIoI\_\{o\}of Directions \(or Inputs\) required to transition the system to a new state\.
- •The coefficientoorepresents the value produced by the system\.
- •The exponentIoI\_\{o\}represents the capacity to receive information from the environment\.
This formalism captures the essence of a “stateful interface”: the system outputs a valueooand then waits for a specific type of inputi∈Ioi\\in I\_\{o\}before it can proceed\.
Outputo∈Oo\\in Oi1∈Ioi\_\{1\}\\in I\_\{o\}i2∈Ioi\_\{2\}\\in I\_\{o\}⋯\\cdotsThe InterfaceP\(y\)P\(y\)Figure 1:A visual representation of a Polynomial Functor \(often called a “Mushroom” or “Corolla”\)\. The system offers an Output \(the cap\) and exposes specific Input ports \(the stalks\) dependent on that output\.
### 3\.2The Correspondence: Genes and Agent Capabilities
We now apply this abstract definition to our specific domains\.
###### Definition 1\(The Gene Object\)\.
A geneGGis a polynomial functor whereOGO\_\{G\}is the set of expressed proteins andIG=\(Iprot\)prot∈OGI\_\{G\}=\(I\_\{\\text\{prot\}\}\)\_\{\\text\{prot\}\\in O\_\{G\}\}is thefamilyof regulatory\-signal sets \(transcription factors\) available at each expressed protein:
PGene\(y\)=∑prot∈OGyIprot\.P\_\{\\text\{Gene\}\}\(y\)=\\sum\_\{\\text\{prot\}\\in O\_\{G\}\}y^\{I\_\{\\text\{prot\}\}\}\.\(3\)
###### Definition 2\(The Agent\-Capability Object\)\.
An agent capabilityAAis a polynomial functor whereOAO\_\{A\}is the set of generated messages/actions, andIA=\(Iaction\)action∈OAI\_\{A\}=\(I\_\{\\text\{action\}\}\)\_\{\\text\{action\}\\in O\_\{A\}\}is thefamilyof observation sets available at each action:
PAgent\(y\)=∑action∈OAyIaction\.P\_\{\\text\{Agent\}\}\(y\)=\\sum\_\{\\text\{action\}\\in O\_\{A\}\}y^\{I\_\{\\text\{action\}\}\}\.\(4\)
##### Multi\-Scale Composition\.
The polynomial functor formalism applies at every level of biological and software organization\. Definitions[1](https://arxiv.org/html/2607.04240#Thmdefinition1)and[2](https://arxiv.org/html/2607.04240#Thmdefinition2)establish theatomiccorrespondence: a single gene and a single agent capability share the same interface form\. Polynomial functors then compose—via the parallel \(⊗\\otimes\), serial \(∘\\circ\), and trace \(Tr\\mathrm\{Tr\}\) operations of §[4](https://arxiv.org/html/2607.04240#S4)—allowing the same interface language to describe progressively richer assemblies:
A cell is not merely a bag of genes; it is a structured composition with shared infrastructure \(organelles\) and a boundary \(membrane\)\. Likewise, an agent runtime is a structured composition of capabilities with shared components \(LLM provider, memory, error handling\) and a security boundary\. To reduce ambiguity, the rest of the paper usescapabilityfor the atomic interface andagentfor the composed runtime\-level object, even though later wiring\-diagram examples sometimes use “agent” informally for executable boxes\. The organelle mappings below describe this cell\-level architecture\. The multi\-cellular organization of §[6](https://arxiv.org/html/2607.04240#S6)then composes agents into tissues via wiring diagrams—the same formalism, one level up\.
### 3\.3The Interface: Promoters as Lenses
In biology, a gene is not universally accessible\. It is guarded by a Promoter Region—a specific DNA sequence that only binds to compatible Transcription Factors\. In software, an agent is guarded by an API Schema or Context Window definition\.
We model this gating mechanism using Optics, specifically Lenses\. A Lens consists of two maps between a global stateSSand a local viewVV:
1. 1\.Get \(View\):get:S→V\\mathrm\{get\}:S\\to V\(Extracting relevant signal from global state\)\.
2. 2\.Put \(Update\):put:S×V→S\\mathrm\{put\}:S\\times V\\to S\(Updating global state based on local change\)\.
The “Promoter” acts as a filter that determines which part of the global cellular environment \(SS\) is visible \(VV\) to the gene\.
- •Biological Lens:The promoter filters the chaotic cellular soup, allowing the gene to “see” only specific molecules \(e\.g\., Lac Repressor\)\.
- •Agentic Lens:The Context Window filters the massive vector database, allowing the agent to “see” only the relevant retrieved chunks \(RAG\)\.
If the input signal does not match the Schema \(Promoter\), the Lens fails to focus, and the interaction is routed to an explicitinactive/errorcase \(equivalently, one works with apartiallens, or a total lens intoV\+ErrorV\+\\mathrm\{Error\}\) \(the agent does not run; the gene is not expressed\)\.
### 3\.4Wire\-Level Optics: Beyond Lenses
The Lens formalism models constitutive access: a promoter that either admits or blocks a signal\. Biological systems employ richer signal\-processing at the interface level\. We extend the wiring diagram with two additional optic types from the categorical optics literature\.
##### Prism: Receptor Specificity\.
A membrane receptor does not merely pass or block signals; it selects signals by molecular shape\. A Prism on a wire admits values of specific data types and rejects others:
prismA\(τ,v\)=\{vifτ∈A⊥ifτ∉A\\mathrm\{prism\}\_\{A\}\(\\tau,v\)=\\begin\{cases\}v&\\text\{if \}\\tau\\in A\\\\ \\bot&\\text\{if \}\\tau\\notin A\\end\{cases\}\(5\)whereA⊆TA\\subseteq Tis the set of accepted types\. This enables fan\-out routing: a single output port connects to multiple wires, each guarded by a different prism, directing JSON to one handler and errors to another—analogous to how different receptor types on a cell surface route different ligands to different intracellular pathways\.
##### Traversal: Polymerase Processivity\.
A ribosome does not translate an entire mRNA at once; it processes codons sequentially, applying the same read\-translate operation to each element\. A Traversal maps a transformffover collection elements on a wire:
traversalf\(𝐱\)=\[f\(xi\)∣xi∈𝐱\]\\mathrm\{traversal\}\_\{f\}\(\\mathbf\{x\}\)=\[f\(x\_\{i\}\)\\mid x\_\{i\}\\in\\mathbf\{x\}\]\(6\)This models batch processing at the wire level: a list of candidate outputs is transformed element\-wise before reaching the downstream agent\.
##### Composition and Coexistence\.
Optics compose: aComposedOpticapplies its constituent optics left\-to\-right, transmitting only if all accept\. A wire may carry both a DenatureFilter \(§5\.3\) and an Optic, applied in sequence: denaturation strips syntactic structure, then the optic routes or transforms the sanitized content\. This layered processing models the biological reality that signal reception involves multiple sequential steps \(ligand binding→\\toreceptor conformational change→\\tointracellular cascade\)\.
### 3\.5Epigenetics and State: The Coalgebra
Neither genes nor agents are stateless functions\. They possess memory\.
- •Biology:Epigenetic markers \(Methylation, Histone modification\) alter how a gene responds to signals without changing the DNA code\.
- •Software:Retrieval Augmented Generation \(RAG\) and Conversation History alter how an agent responds to a prompt without changing the LLM weights\.
We model this as a Coalgebra for the polynomial functorPP\. A dynamical system is defined as a tuple\(S,ϕ\)\(S,\\phi\), whereSSis the state space andϕ\\phiis the structure map:
ϕ:S→P\(S\)\.\\phi:S\\to P\(S\)\.\(7\)
By expandingP\(S\)P\(S\), we derive the two fundamental operations of the state machine:
1. 1\.Readout:S→OS\\to O\(Given current state/memory, what action do I take?\)
2. 2\.Update:∑s∈SIo\(s\)→S\\displaystyle\\sum\_\{s\\in S\}I\_\{o\(s\)\}\\to S\(Given current statessand a new inputi∈Io\(s\)i\\in I\_\{o\(s\)\}compatible with its current outputo\(s\)o\(s\), what is my new state?\)
By establishing this formal dictionary \(Table[1](https://arxiv.org/html/2607.04240#S3.T1)\), we can compare selected GRN components and agentic components as instances of the same abstract class of typed dynamical interfacesunder this interface\-level abstraction\. Proposition[1](https://arxiv.org/html/2607.04240#Thmproposition1)below states precisely what this shared membership does and does not assert\.
##### Composable Coalgebras\.
The coalgebra formalism becomes most useful when made composable\. We define two composition operations that mirror the parallel and serial composition of the Operad \(§4\):
- •Parallel Coalgebra:Given\(S1,α1\)\(S\_\{1\},\\alpha\_\{1\}\)and\(S2,α2\)\(S\_\{2\},\\alpha\_\{2\}\), their parallel composition has stateS1×S2S\_\{1\}\\times S\_\{2\}and applies both readout/update operations to the same input—like two signaling pathways activated by the same ligand\.
- •Sequential Coalgebra:Given\(S1,α1\)\(S\_\{1\},\\alpha\_\{1\}\)overP1P\_\{1\}and\(S2,α2\)\(S\_\{2\},\\alpha\_\{2\}\)overP2P\_\{2\}, the sequential composition pipes the readout of the first as input to the second, with joint stateS1×S2S\_\{1\}\\times S\_\{2\}—modeling signal transduction cascades\.
##### Bisimulation: Observational Equivalence\.
For the deterministic state machines considered here, we use the following observational criterion: two state machines\(S1,α1\)\(S\_\{1\},\\alpha\_\{1\}\)and\(S2,α2\)\(S\_\{2\},\\alpha\_\{2\}\)are equivalent if, for every input sequence, they produce identical output sequences\. We writeM1∼M2M\_\{1\}\\sim M\_\{2\}when
∀𝐢∈I∗:readout1∗\(𝐢\)=readout2∗\(𝐢\)\\forall\\,\\mathbf\{i\}\\in I^\{\*\}:\\quad\\mathrm\{readout\}\_\{1\}^\{\*\}\(\\mathbf\{i\}\)=\\mathrm\{readout\}\_\{2\}^\{\*\}\(\\mathbf\{i\}\)\(8\)wherereadout∗\\mathrm\{readout\}^\{\*\}denotes the lifted readout over the input sequence\. A diverging input \(witness\) constitutes a proof of non\-equivalence\. This supports formal comparison of deterministic implementations within the input model considered here; stronger coinductive verification claims are left for future work\.
##### Temporal Coalgebra: Bi\-Temporal State\.
The coalgebra above models state at a single point in time\. In practice, agents accumulate beliefs that may be corrected retroactively\. We extend the state space to carry two independent time indices\. Let𝒯=\(ℝ≥0,≤\)\\mathcal\{T\}=\(\\mathbb\{R\}\_\{\\geq 0\},\\leq\)denote a totally ordered time domain\. A*bi\-temporal state*augments the coalgebra with a pair of interval\-valued annotations:
Sbt=S×\[𝒯,𝒯∪\{∞\}\)⏟valid interval×\[𝒯,𝒯∪\{∞\}\)⏟record intervalS\_\{\\mathrm\{bt\}\}\\;=\\;S\\times\\underbrace\{\[\\mathcal\{T\},\\mathcal\{T\}\\cup\\\{\\infty\\\}\)\}\_\{\\text\{valid interval\}\}\\times\\underbrace\{\[\\mathcal\{T\},\\mathcal\{T\}\\cup\\\{\\infty\\\}\)\}\_\{\\text\{record interval\}\}\(9\)where an open\-ended interval\[t,∞\)\[t,\\infty\)denotes a currently active fact\. The key invariant is*append\-only correction*: closing a record’s transaction interval and appending a new record with asupersedespointer, rather than mutating the original\. This ensures that for any pair\(tv,tr\)\(t\_\{v\},t\_\{r\}\), the*belief state*—the set of facts valid attvt\_\{v\}and known attrt\_\{r\}—is uniquely reconstructible by filtering on both intervals simultaneously\.
The readout function becomes time\-parameterized:readout\(s,tv,tr\)\\mathrm\{readout\}\(s,t\_\{v\},t\_\{r\}\)returns only those facts whose valid interval containstvt\_\{v\}and whose record interval containstrt\_\{r\}\. This separates two questions that a single\-time coalgebra conflates: “what is true now?” \(valid\-time query\) versus “what did the system believe at decision time?” \(bi\-temporal query\)\. The implementation \(§[10\.10](https://arxiv.org/html/2607.04240#S10.SS10)\) instantiates this asBiTemporalMemorywith explicitretrieve\_valid\_at,retrieve\_known\_at, andretrieve\_belief\_statemethods\.
### 3\.6The Correspondence, Made Precise
The dictionary of Table[1](https://arxiv.org/html/2607.04240#S3.T1)is more than a list of analogies: both genes and agent capabilities have been presented as objects of a single mathematical kind—polynomial\-functor coalgebras\. We name that kind and state exactly what the two domains share\.
###### Definition 3\(Typed Dynamical Interface\)\.
A*typed dynamical interface*is an object of𝐂𝐨𝐚𝐥𝐠\(𝐏𝐨𝐥𝐲\)\\mathbf\{Coalg\}\(\\mathbf\{Poly\}\): a pair\(S,ϕ\)\(S,\\phi\)with structure mapϕ:S→P\(S\)\\phi\\colon S\\to P\(S\)for a polynomial functorPP, equivalently a readoutS→OS\\to Otogether with an update∑s∈SIo\(s\)→S\\sum\_\{s\\in S\}I\_\{o\(s\)\}\\to S\(Eq\.[7](https://arxiv.org/html/2607.04240#S3.E7)\)\. A morphism\(S1,ϕ1\)→\(S2,ϕ2\)\(S\_\{1\},\\phi\_\{1\}\)\\to\(S\_\{2\},\\phi\_\{2\}\)is a coalgebra homomorphism: a map of state spaces commuting with the structure maps, hence one that preserves observable behavior in the sense of Eq\.[8](https://arxiv.org/html/2607.04240#S3.E8)\.
Definitions[1](https://arxiv.org/html/2607.04240#Thmdefinition1)and[2](https://arxiv.org/html/2607.04240#Thmdefinition2)exhibit the Gene Object and the Agent\-Capability Object as two such interfaces\. Following Marom et al\.\[[30](https://arxiv.org/html/2607.04240#bib.bib69)\]—who relate biological and engineered stimulus–response systems by a structure\-preserving functor rather than by identifying their substrates—we regard the biological and software realizations as two full subcategories of the same ambient category:
𝖭𝖺𝗍⊂𝐂𝐨𝐚𝐥𝐠\(𝐏𝐨𝐥𝐲\)\(GRN realizations\),𝖠𝗋𝗍⊂𝐂𝐨𝐚𝐥𝐠\(𝐏𝐨𝐥𝐲\)\(agentic realizations\)\.\\mathsf\{Nat\}\\subset\\mathbf\{Coalg\}\(\\mathbf\{Poly\}\)\\ \\ \(\\text\{GRN realizations\}\),\\qquad\\mathsf\{Art\}\\subset\\mathbf\{Coalg\}\(\\mathbf\{Poly\}\)\\ \\ \(\\text\{agentic realizations\}\)\.
###### Proposition 1\(Substrate\-Independent Correspondence\)\.
The atomic interface objects of the two domains coincide in𝐂𝐨𝐚𝐥𝐠\(𝐏𝐨𝐥𝐲\)\\mathbf\{Coalg\}\(\\mathbf\{Poly\}\): the Gene Object \(Definition[1](https://arxiv.org/html/2607.04240#Thmdefinition1)\) and the Agent\-Capability Object \(Definition[2](https://arxiv.org/html/2607.04240#Thmdefinition2)\) share the functor form∑o∈OyIo\\sum\_\{o\\in O\}y^\{I\_\{o\}\}and the same readout/update signature, so each interprets as an object of both𝖭𝖺𝗍\\mathsf\{Nat\}and𝖠𝗋𝗍\\mathsf\{Art\}up to relabeling of the position setOOand the direction family\(Io\)o∈O\(I\_\{o\}\)\_\{o\\in O\}\. The remaining rows of Table[1](https://arxiv.org/html/2607.04240#S3.T1)record correspondences at other categorical levels—positions, directions, optics, state spaces, and morphisms—not further object\-level identities\.
###### Proof sketch\.
By construction\. Definitions[1](https://arxiv.org/html/2607.04240#Thmdefinition1)and[2](https://arxiv.org/html/2607.04240#Thmdefinition2)exhibit the two objects with identical functor form; matching the position setOO, the direction family\(Io\)o∈O\(I\_\{o\}\)\_\{o\\in O\}, and the readout/update maps of Definition[3](https://arxiv.org/html/2607.04240#Thmdefinition3)gives the shared interface signature\. The claim is confined to these interface objects; the table’s position\-, direction\-, optic\-, state\-, and morphism\-level rows are correspondences of the respective categorical constituents, established at their own level rather than as additional object identities\. ∎
##### What this asserts, and what it does not\.
The correspondence is a shared*interface*semantics, not an isomorphism\. We do not exhibit a mutually inverse pair of functors between𝖭𝖺𝗍\\mathsf\{Nat\}and𝖠𝗋𝗍\\mathsf\{Art\}, and we make no claim that the two domains agree in mechanism, kinetics, or failure distribution—the empirical sections below in fact document regimes where the biological structure confers no advantage over a naive baseline\. In the words of Marom et al\., two systems that share compositional structure can be related by a functor that “preserves the interface logic …without requiring that the two domains share any physical substrate\.” That substrate independence—not equivalence—is the content of Proposition[1](https://arxiv.org/html/2607.04240#Thmproposition1), and it is what licenses transporting a design pattern read off a gene\-regulatory motif to an agent architecture at all\.
Gene\(Function\)Transcription Factors \(II\)Proteins \(OO\)Promoter BindingExpressionAgent\(LLM \+ Tools\)Observations \(II\)Actions \(OO\)Schema MatchGeneration
Figure 2:The Structural Correspondence\. Both Genes and Agent Capabilities act as transducers converting Input Contexts \(II\) into Output Expressions \(OO\), governed by the same categorical laws \(at the level of polynomial\-interface models\)\.Category ConceptBiological Realization \(GRN\)Software Realization \(Agentic\)Polynomial Functor \(PP\)Gene InterfaceAgent Interface \(System Prompt\)Output Position \(OO\)Protein ExpressionTool Call / MessageInput Direction \(II\)Transcription Factor BindingObservation / User PromptLens \(Optic\)Promoter RegionAPI Schema / Context WindowInternal State \(SS\)Epigenetic Markers \(Methylation\)Vector Store / Chat HistoryMorphism \(∘\\circ\)Signal Transduction PathwayData PipelineOrganelles \(Specialized Processing Units\)Template EngineRibosome \(mRNA→\\toProtein\)Prompt Template FactoryOutput ValidationChaperone \(Protein Folding\)Schema Validator / JSON ParserWaste ProcessingLysosome \(Autophagy\)Error Handler / Garbage CollectorDecision CenterNucleus \(Transcription\)LLM Provider WrapperInput FilterMembrane \(Immune System\)Prompt Injection DefenseComputation EngineMitochondria \(MIPS\)Runtime Supervisor / Decision GateLifecycle and RhythmsLifespan LimitTelomere ShorteningOperation Counter / Max IterationsPeriodic SchedulingCircadian OscillatorHealth Checks / HeartbeatTable 1:The Correspondence Dictionary \(Extended\)\. The Polynomial Functor row is the object\-level correspondence of Proposition[1](https://arxiv.org/html/2607.04240#Thmproposition1)\(Gene Object↔\\leftrightarrowAgent\-Capability Object\); the remaining rows pair the corresponding positions, directions, optics, state spaces, and morphisms of the two domains, not further object identities\.Biological ConceptAgentic ConceptFormal StructureImmunity and SecurityToll\-Like Receptor \(TLR\)Regex Injection FilterPattern MatchingMHC PresentationProvenance LabelingFunctor𝒫:𝐌𝐬𝐠→𝐓𝐫𝐮𝐬𝐭\\mathcal\{P\}:\\mathbf\{Msg\}\\to\\mathbf\{Trust\}T\-Cell ReceptorTrust GatePartial LensNegative SelectionInjection TrainingPenalized LearningRegulatory T\-CellConfidence DampeningSuppression FunctionImmune MemoryThreat Signature StoreHash\-Indexed CacheMetabolism and ControlATPToken BudgetResource Monoidℛ\\mathcal\{R\}mPTP OpeningFast Apoptosis TriggerGuard ConditionRetrograde SignalingPhenotype ReshapingSlow AdaptationMetabolic\-Epigenetic State CouplingCost\-Gated Retrieval PolicyConditional Access ControlInformation and HealthTrophic FactorsNovel Input SignalsEpiplexity\>δ\>\\deltaBayesian BrainFree Energy MinimizationKL DivergenceApoptosisAgent TerminationState→⊥\\to\\botMulti\-Cellular OrganizationGenomeBase Model WeightsShared ParametersEpigenomeSystem Prompt \+ RAGPhenotype ContextMorphogen GradientShared Context VariablesJSON StateMorphogen DiffusionGradient Propagation on Agent GraphDiscrete PDE onGGTissue BoundaryTrust Boundary / Capability CeilingType BarrierPrism OpticConditional Wire RoutingPartial OpticTraversal OpticBatch Wire TransformEndofunctor on ListsBisimulationAgent Equivalence TestingObservational EquivalenceTable 2:Extended Correspondence Dictionary: Security, Metabolism, and Organization
### 3\.7Metabolic Coalgebras: Formalizing Resource Constraints
Finally, we address the physical constraints of computation\. Just as biological systems are limited by ATP availability\[[28](https://arxiv.org/html/2607.04240#bib.bib8),[23](https://arxiv.org/html/2607.04240#bib.bib9)\], agentic systems are limited by token budgets and latency\. To model this, we extend our coalgebraic framework to include resource constraints, defining aMetabolic Coalgebra\. Mathematically, this is an instance of a Quantitative Coalgebra enriched over a resource monoid, effectively restricting the domain of the state transition function to resource\-sufficient states\.
We align this definition with the theory ofQuantitative Polynomial Functors\[[33](https://arxiv.org/html/2607.04240#bib.bib11)\], treating the system as a state machine enriched over a resource monoid\.
###### Definition 4\(The Resource Monoid\)\.
Let\(ℛ,\+,0,≥\)\(\\mathcal\{R\},\+,0,\\geq\)be an ordered commutative monoid representing computational resources, equipped with a partial subtractionr⊖cr\\ominus cdefined wheneverr≥cr\\geq c\. For a single resource dimension \(e\.g\., token counts\),ℛ≅ℕ\\mathcal\{R\}\\cong\\mathbb\{N\}; for multi\-dimensional accounting \(latency, memory\),ℛ≅ℝ≥0k\\mathcal\{R\}\\cong\\mathbb\{R\}\_\{\\geq 0\}^\{k\}\.
###### Definition 5\(Metabolic Coalgebra\)\.
A resource\-constrained agent is a coalgebra\(S,α\)\(S,\\alpha\)over a polynomial functorPP, where the state space is the product of the logical stateLLand the resource stateℛ\\mathcal\{R\}:
S≅L×ℛS\\cong L\\times\\mathcal\{R\}The structure mapα:S→P\(S\)\+⊥\\alpha:S\\to P\(S\)\+\\botis defined as apartial mapguarded by cost\. Writing only the continuation state and suppressing the output/readout coordinate ofP\(S\)P\(S\), a transition requiring costc∈ℛc\\in\\mathcal\{R\}has the guarded form:
αcont\(l,r\)=\{\(l′,r⊖c\)ifr≥c⊥ifr<c\(Apoptosis\)\\alpha\_\{\\mathrm\{cont\}\}\(l,r\)=\\begin\{cases\}\(l^\{\\prime\},r\\ominus c\)&\\text\{if \}r\\geq c\\\\ \\bot&\\text\{if \}r<c\\quad\\text\{\(Apoptosis\)\}\\end\{cases\}
This structure maps to the energetics of transcriptional elongation\. A gene or agent capability cannot produce its output instantaneously; it must carry out a sequence of state transitions, each with a cost\. The Metabolic Coalgebra models this dependency: if the cellular or computational energy budget is exhausted, execution stalls \(Ischemia\), and the component fails to execute its function, regardless of its regulatory logic\.
This formalism establishes that “Ischemia” \(Token Starvation\) is not merely a runtime error, but a reachable terminal state⊥\\botin the system’s dynamics\. This mirrors the biological mechanism where a cell that cannot meet its energetic demands undergoes programmed death: energy stress is sensed by pathways such as AMPK, which can in turn engage p53\-dependent apoptosis\[[7](https://arxiv.org/html/2607.04240#bib.bib10)\]\.
###### Theorem 1\(The Metabolic Bound \(Qualified\)\)\.
Assume either a single scalar resource budgetℛ≅ℕ\\mathcal\{R\}\\cong\\mathbb\{N\}or, more generally, a well\-founded scalar potentialμ:ℛ→ℝ≥0\\mu:\\mathcal\{R\}\\to\\mathbb\{R\}\_\{\\geq 0\}such that every non\-identity transition of costccsatisfiesμ\(r⊖c\)≤μ\(r\)−cmin\\mu\(r\\ominus c\)\\leq\\mu\(r\)\-c\_\{\\min\}for somecmin\>0c\_\{\\min\}\>0\. Assume also that the resource state is monotone nonincreasing \(no regeneration\), and that infinite executions may not consist solely of stutter / identity steps\. Then any execution contains at most⌊μ\(Rtotal\)/cmin⌋\\lfloor\\mu\(R\_\{\\mathrm\{total\}\}\)/c\_\{\\min\}\\rfloornon\-identity transitions; in the scalar\-budget case this is⌊Rtotal/cmin⌋\\lfloor R\_\{\\mathrm\{total\}\}/c\_\{\\min\}\\rfloor\. Hence termination is decidable up to stuttering\. If regeneration, zero\-cost cycles, or unrestricted stutter loops are permitted, termination requires an additional well\-founded potential or an explicit budget/termination certificate\[[11](https://arxiv.org/html/2607.04240#bib.bib13)\]\.
##### Operational takeaway\.
For an agent\-systems reader, the theorem says: if every non\-trivial step burns at least a fixed minimum amount of budget and budget never regenerates, then execution length is bounded by initial budget divided by that minimum burn rate\. Infinite behavior becomes possible only through free stutter, zero\-cost cycles, or regeneration\.
###### Proof sketch\.
Let the initial resource state beRtotalR\_\{\\mathrm\{total\}\}\. By assumption, every non\-identity transition decreases the scalar potentialμ\\muby at leastcmin\>0c\_\{\\min\}\>0\. AfterNNnon\-identity transitions we therefore have
μ\(rN\)≤μ\(Rtotal\)−Ncmin\.\\mu\(r\_\{N\}\)\\leq\\mu\(R\_\{\\mathrm\{total\}\}\)\-Nc\_\{\\min\}\.Becauseμ\\muis nonnegative, the right\-hand side must remain nonnegative, which implies
N≤⌊μ\(Rtotal\)cmin⌋\.N\\leq\\left\\lfloor\\frac\{\\mu\(R\_\{\\mathrm\{total\}\}\)\}\{c\_\{\\min\}\}\\right\\rfloor\.In the scalar\-budget case this is exactly⌊Rtotal/cmin⌋\\lfloor R\_\{\\mathrm\{total\}\}/c\_\{\\min\}\\rfloor\. Hence only finitely many non\-identity transitions are possible\. Under the stated no\-regeneration / no\-infinite\-stutter assumptions, this yields decidability of termination up to stuttering\. If those assumptions are removed, the argument no longer forces progress, so an additional well\-founded ranking or explicit budget certificate is required\. ∎
### 3\.8Additional Organelles: Completing the Cellular Architecture
Beyond the core interface mapping, biological cells contain specialized organelles that handle distinct aspects of cellular function\. We extend the correspondence to four additional structures that map directly to agentic software components\.
##### Ribosome: Template\-to\-Output Synthesis\.
In biology, the ribosome reads messenger RNA \(mRNA\) sequences and synthesizes proteins by assembling amino acids according to the genetic code\. Transfer RNA \(tRNA\) molecules carry amino acids to the ribosome, where codons \(three\-nucleotide sequences\) specify which amino acid to add\.
In agentic systems, the Ribosome maps to aprompt template engine:
- •mRNA→\\toPrompt templates with variable slots
- •tRNA→\\toContext bindings \(variable→\\tovalue mappings\)
- •Codons→\\toTemplate directives \(variables, conditionals, loops\)
- •Translation→\\toTemplate rendering with context injection
Just as the ribosome ensures that the genetic code is faithfully translated into functional proteins, the software ribosome ensures that abstract prompt templates are instantiated into concrete, well\-formed prompts\.
##### Lysosome: Waste Processing and Recycling\.
The lysosome is the cell’s recycling center, containing enzymes that break down cellular waste, damaged organelles, and foreign material\. Through autophagy, the cell digests its own components to recover building blocks during stress\.
In agentic systems, the Lysosome maps toerror handling and garbage collection:
- •Waste Classification→\\toCategorizing failures \(timeout, validation error, toxic input\)
- •Digestion→\\toProcessing errors to extract debugging information
- •Recycling→\\toRecovering useful context from failed operations
- •Autophagy→\\toPeriodic cleanup of stale cache and expired state
- •Toxic Disposal→\\toSecure handling of sensitive data \(API keys, PII\)
The lysosome prevents accumulation of “cellular debris” that could poison the system—analogous to memory leaks or error cascades in software\.
##### Nucleus: The Decision Center\.
In eukaryotic cells, the nucleus houses the DNA and serves as the control center for gene expression\. Transcription factors enter the nucleus, bind to promoter regions, and initiate transcription of specific genes\.
In agentic systems, the Nucleus maps to theLLM provider wrapper:
- •DNA→\\toPre\-trained model weights \(static substrate of capability\)
- •Transcription→\\toInference \(prompt→\\toresponse generation\)
- •Nuclear Envelope→\\toProvider abstraction layer \(API boundary\)
- •Nucleolus→\\toTool integration hub \(where external capabilities are assembled\)
The nucleus abstracts the complexity of the underlying LLM, exposing a consistent interface regardless of the provider \(Anthropic, OpenAI, Gemini\)\.
##### Telomere: Lifecycle and Senescence\.
Telomeres are protective caps at the ends of chromosomes that shorten with each cell division\. When telomeres become critically short, the cell enters senescence \(permanent growth arrest\) or apoptosis\. The enzyme telomerase can extend telomeres, enabling continued division in stem cells\.
In agentic systems, Telomeres map tolifecycle management:
- •Telomere Length→\\toRemaining operation budget \(max iterations\)
- •Shortening→\\toDecrementing counter per operation
- •Senescence→\\toGraceful degradation \(reduced capability mode\)
- •Apoptosis→\\toClean shutdown when budget exhausted
- •Telomerase→\\toRenewal mechanism \(resetting counters for trusted agents\)
This provides a biological basis for the common pattern of limiting agent iterations\. Rather than arbitrary timeouts, the telomere model frames lifecycle limits as a natural property of the system’s “cellular age\.”
##### Mitochondria: The Metabolic Motherboard\.
Recent scholarship reframes mitochondria not merely as the cell’s powerhouse, but as theMitochondrial Information Processing System \(MIPS\)\[[37](https://arxiv.org/html/2607.04240#bib.bib14)\]\. Mitochondria sense environmental stress and integrate metabolic signals that shape cellular decision\-making\. They function as “social signaling organelles” that communicate with the nucleus and other organelles\.
In agentic systems, the Mitochondria maps to theRuntime Supervisor:
- •ATP Production→\\toDeterministic computation \(tool execution, code evaluation\)
- •Stress Sensing→\\toMonitoring token burn rate vs\. informational yield
- •Retrograde Signaling→\\toForcing strategy shifts when metabolic efficiency drops
- •Fusion/Fission→\\toContext fusion under resource constraints
Temporal Dynamics: Fast vs\. Slow Interventions\.A crucial distinction exists between the timescales of mitochondrial intervention\. In biology, retrograde signaling influences nuclear gene expression over hours to days—it is adevelopmentalresponse that reshapes the cell’s phenotype\. In contrast, acute metabolic stress \(ATP depletion, Ca2\+overload\) triggers immediate responses: cytochrome c release initiates apoptosis within minutes\.
We preserve this distinction in the agentic mapping:
- •Fast Intervention \(Acute\):The Runtime monitors real\-time metrics \(token velocity, error rate\)\. When thresholds are breached, it triggers immediate Apoptosis—terminating the current chain\-of\-thought without negotiation\. This mirrors the mitochondrial permeability transition pore \(mPTP\) opening\.
- •Slow Intervention \(Chronic\):The Runtime accumulates statistics across sessions \(average efficiency, failure patterns\)\. These informRetrograde Responses—modifications to system prompts, retrieval strategies, or model selection that reshape the agent’s “phenotype” over deployment cycles\. This mirrors how chronic metabolic stress induces mitochondrial biogenesis and metabolic reprogramming\.
The Runtime does not “override” the LLM in the sense of injecting tokens mid\-generation; rather, it governs theboundary conditionswithin which generation occurs, and triggers state transitions \(continue, pivot, terminate\) at defined checkpoints\.
## 4Formal Syntax: The Agentic Operad
To formalize admissible agent compositions, we define a typed operad of wiring diagrams, denoted asWAgent\. Here the operad serves primarily as a syntax: a “grammar” for connecting operations \(boxes\) via typed wires\. It specifies which agent topologies are well\-formed\. When we make probabilistic or behavioral claims below, those claims rely on additional assumptions about the implementations inhabiting the boxes, not on the operadic syntax alone\[[41](https://arxiv.org/html/2607.04240#bib.bib4)\]\.
### 4\.1The Typing Rules
In WAgent, every wire carries a specific Typeτ∈T\\tau\\in T\.
T=\{Text,JSON,Image,Error,ToolCall,Stop,Approval\}\.T=\\\{\\text\{Text\},\\text\{JSON\},\\text\{Image\},\\text\{Error\},\\text\{ToolCall\},\\text\{Stop\},\\text\{Approval\}\\\}\.\(10\)These types correspond to biological molecular specificity \(e\.g\., a specific transcription factor only binds to a specific DNA sequence\)\. A connection is valid if and only if the type of the output port of AgentAAmatches the type of the input port of AgentBB\.
### 4\.2The Composition Operations
The operad defines three fundamental operations for combining agents\. Any complex agentic architecture, no matter how large, can be decomposed into these three primitives\.
#### 4\.2\.1Parallel Composition \(⊗\\otimes\)
Two agents,AAandBB, execute simultaneously with no information exchange:
- •Biological Analogy:Two genes located on different chromosomes expressing proteins independently\.
- •Constraint:This operation is valid only if the internal state spacesSAS\_\{A\}andSBS\_\{B\}are disjoint\. If they share a mutable memory store, the operation leaves theindependent\-state interpretationand requires an explicitresource\-sharingstructure \(e\.g\., a shared state component or a Resource Sharing decorator\)\.
#### 4\.2\.2Serial Composition \(∘\\circ\)
The output of AgentAAis piped directly into the input of AgentBB:
- •Biological Analogy:A Signal Transduction Pathway \(Protein A activates Protein B\)\.
- •Static Type Checking:This allows for static type checking of agent graphs\. If AgentAAoutputs Natural Language but AgentBBexpects JSON Schema, the composition is undefined in WAgent\. This moves runtimetype/schema mismatcherrors to “compile\-time” architectural errors\.
#### 4\.2\.3Contraction / Trace \(TrTr\)
A feedback loop where an output port of AgentAAis wired back into one of its own input ports:
- •Biological Analogy:Autoregulation \(Homeostasis\) or Positive Feedback\.
- •Software Implication:Trace capturesexplicit feedback wiring\(outputs fed back as inputs\), e\.g\., when an agent conditions on its own prior outputs or a memory buffer\. Internal chain\-of\-thought is modeled as hidden state in the coalgebra, not by Trace itself\.
### 4\.3Theorem: Topological Error Suppression
We now combine the wiring syntax with a simple stochastic failure model to analyze when the Coherent Feed\-Forward Loop \(CFFL\) suppresses errors more effectively than a direct serial connection on high\-stakes tasks\.
##### Reading convention\.
For readers coming from AI agent systems rather than category theory, each result in this section should be read in three layers: the wiring diagram tells us which signals or approvals can reach an action sink; the stochastic or trust model assigns probabilities or integrity levels to those signals; the proof then converts that structural constraint into a failure or authorization bound\.
##### Network Motif 1 \(Conjunctive Verification Gate\)\.
The biological*coherent feed\-forward loop*\(C1\-FFL\)—an inputXXactivating a targetZZboth directly and through an intermediateYYunder AND logic—is classically a*sign\-sensitive delay*: it filters out transient activating pulses ofXX, responding only to persistent input, while switching off without delay\[[4](https://arxiv.org/html/2607.04240#bib.bib2)\]\. The pattern we analyze below reuses this conjunctive \(AND\-gate\)*geometry*for a different purpose\. A generator drives an actionZZdirectly \(signalXX\), while an independent verifierYYmust also approve, soZZfires if and only ifX∧YX\\wedge Y\. Functionally this is a*redundant\-verification*motif—the topology of the two\-person rule and of N\-version programming\[[25](https://arxiv.org/html/2607.04240#bib.bib78)\]—and its benefit is the multiplicative suppression of a shared error under*independent*failures, not the temporal filtering the biological C1\-FFL provides\. We retain the “feed\-forward” descriptor for the shared conjunctive shape, but state the guarantee for the verification reading\.
###### Theorem 2\(Error Suppression under Conjunctive Verification\)\.
LetAgenA\_\{\\mathrm\{gen\}\}be a generator agent andAverA\_\{\\mathrm\{ver\}\}be a verifier agent\. LetEgenE\_\{\\mathrm\{gen\}\}denote the event that the generator emits an erroneous candidate, and letMverM\_\{\\mathrm\{ver\}\}denote the event that the verifier*misses*that error and still emits an approval token\.
- •Case 1: Direct Link \(Serial\)\.The system fails ifAgenA\_\{\\mathrm\{gen\}\}hallucinates\. P\(Faildirect\)=P\(Egen\)\.P\(\\mathrm\{Fail\}\_\{\\mathrm\{direct\}\}\)=P\(E\_\{\\mathrm\{gen\}\}\)\.
- •Case 2: CFFL Topology \(Independent\)\.Under the assumption of independence: P\(FailCFFL\)=P\(Egen\)×P\(Mver\)\.P\(\\mathrm\{Fail\}\_\{\\mathrm\{CFFL\}\}\)=P\(E\_\{\\mathrm\{gen\}\}\)\\times P\(M\_\{\\mathrm\{ver\}\}\)\.
- •Case 3: CFFL Topology \(Correlated\)\.In practice, generator errors and verifier misses are often correlated—if the generator hallucinates a plausible\-sounding function, the verifier \(especially if using the same base model or training distribution\) may be more likely to accept it\. Letρ\\rhobe the phi coefficient between the Bernoulli variablesEgenE\_\{\\mathrm\{gen\}\}andMverM\_\{\\mathrm\{ver\}\}, withp=P\(Egen\)p=P\(E\_\{\\mathrm\{gen\}\}\)andq=P\(Mver\)q=P\(M\_\{\\mathrm\{ver\}\}\)\(assumep,q∈\(0,1\)p,q\\in\(0,1\)soρ\\rhois well\-defined\)\. Then: P\(Egen∧Mver\)=pq\+ρp\(1−p\)q\(1−q\)\.P\(E\_\{\\mathrm\{gen\}\}\\wedge M\_\{\\mathrm\{ver\}\}\)=pq\+\\rho\\sqrt\{p\(1\-p\)q\(1\-q\)\}\.BecauseEgenE\_\{\\mathrm\{gen\}\}andMverM\_\{\\mathrm\{ver\}\}are Bernoulli,ρ\\rhoisnot free in\[−1,1\]\[\-1,1\]; it is constrained by the Fréchet–Hoeffding bounds P\(Egen∧Mver\)∈\[max\(0,p\+q−1\),min\(p,q\)\],P\(E\_\{\\mathrm\{gen\}\}\\wedge M\_\{\\mathrm\{ver\}\}\)\\in\[\\max\(0,p\+q\-1\),\\;\\min\(p,q\)\],equivalently ρ∈\[max\(0,p\+q−1\)−pqp\(1−p\)q\(1−q\),min\(p,q\)−pqp\(1−p\)q\(1−q\)\]\.\\rho\\in\\left\[\\frac\{\\max\(0,p\+q\-1\)\-pq\}\{\\sqrt\{p\(1\-p\)q\(1\-q\)\}\},\\;\\frac\{\\min\(p,q\)\-pq\}\{\\sqrt\{p\(1\-p\)q\(1\-q\)\}\}\\right\]\.
##### Assumptions\.
The theorem uses the minimal failure model appropriate for a two\-stage execution gate: in the direct serial case, an erroneous action is emitted exactly when the generator emits an erroneous candidate; in the CFFL case, an erroneous action is emitted exactly when the generator emits an error*and*the verifier still approves it\.
###### Corollary 1\(Correlation Degradation\)\.
Letp=P\(Egen\)=P\(Mver\)p=P\(E\_\{\\mathrm\{gen\}\}\)=P\(M\_\{\\mathrm\{ver\}\}\)for simplicity\. The failure probability becomes:
P\(Fail\)=p2\+ρp\(1−p\)=p2\(1−ρ\)\+ρpP\(\\mathrm\{Fail\}\)=p^\{2\}\+\\rho p\(1\-p\)=p^\{2\}\(1\-\\rho\)\+\\rho pwithρ∈\[−min\(p1−p,1−pp\),1\]\\rho\\in\\left\[\-\\min\\\!\\left\(\\frac\{p\}\{1\-p\},\\frac\{1\-p\}\{p\}\\right\),\\,1\\right\]\. Whenρ=0\\rho=0\(independence\), we recoverp2p^\{2\}\. Asρ\\rhoincreases toward its upper bound, the gain vanishes andP\(Fail\)→pP\(\\mathrm\{Fail\}\)\\to p\.
##### Architectural Implications\.
This result makes precise when the CFFL topology provides genuine safety benefits:
- •High correlation:Reusing the same model family, prompt structure, or evidence sources can make verifier misses positively correlated with generator errors, erasing much of the gain\. This is not a hypothetical concern: Knight and Leveson\[[25](https://arxiv.org/html/2607.04240#bib.bib78)\]found that independently developed program versions failed on common inputs substantially more often than independence predicts, refuting the analogous failure\-independence assumption for N\-version programming\.
- •Heterogeneous generators and verifiers:Prompt diversity or model\-family diversity can reduce correlation, but the magnitude is empirical rather than universal\.
- •Orthogonal checks:Symbolic or tool\-grounded verifiers are a useful limiting case because their failure modes need not mirror the generator’s linguistic ones\.
These are architectural heuristics rather than fitted universal ranges forρ\\rho\. The topological structure \(conjunctive gating\) is necessary but not sufficient; diversity in the components populating that topology determines the actual error suppression achieved\.
##### Operational takeaway\.
For agent designers, the result is simple: adding a reviewer buys multiplicative safety only when the reviewer is not making the same mistakes as the generator\. The AND gate gives the multiplicative structure; correlation gives that improvement back\.
###### Proof sketch\.
In the direct serial topology there is only one path from the generator to the action sink, so an erroneous final action occurs iff the generator emits an erroneous candidate\. Thus
Faildirect=Egen,P\(Faildirect\)=P\(Egen\)\.\\mathrm\{Fail\}\_\{\\mathrm\{direct\}\}=E\_\{\\mathrm\{gen\}\},\\qquad P\(\\mathrm\{Fail\}\_\{\\mathrm\{direct\}\}\)=P\(E\_\{\\mathrm\{gen\}\}\)\.
In the CFFL topology, the action sink is downstream of an AND gate\. An erroneous final action can occur only if the generator emits an erroneous candidate*and*the verifier misses that error while still approving it\. Therefore
FailCFFL=Egen∧Mver\.\\mathrm\{Fail\}\_\{\\mathrm\{CFFL\}\}=E\_\{\\mathrm\{gen\}\}\\wedge M\_\{\\mathrm\{ver\}\}\.Under independence this gives
P\(FailCFFL\)=P\(Egen\)P\(Mver\)=pq\.P\(\\mathrm\{Fail\}\_\{\\mathrm\{CFFL\}\}\)=P\(E\_\{\\mathrm\{gen\}\}\)P\(M\_\{\\mathrm\{ver\}\}\)=pq\.For the correlated case, letX=𝟏EgenX=\\mathbf\{1\}\_\{E\_\{\\mathrm\{gen\}\}\}andY=𝟏MverY=\\mathbf\{1\}\_\{M\_\{\\mathrm\{ver\}\}\}\. SinceX,YX,Yare Bernoulli,
P\(Egen∧Mver\)=𝔼\[XY\]=𝔼\[X\]𝔼\[Y\]\+Cov\(X,Y\)=pq\+ρp\(1−p\)q\(1−q\)\.P\(E\_\{\\mathrm\{gen\}\}\\wedge M\_\{\\mathrm\{ver\}\}\)=\\mathbb\{E\}\[XY\]=\\mathbb\{E\}\[X\]\\mathbb\{E\}\[Y\]\+\\mathrm\{Cov\}\(X,Y\)=pq\+\\rho\\sqrt\{p\(1\-p\)q\(1\-q\)\}\.The Fréchet–Hoeffding bounds then give the admissible range ofρ\\rho\. The topology contributes the conjunction; implementation diversity determines the covariance term\. ∎
User Request \(XX\)Risk Assessor \(YY\)Executor \(ZZ\)∧\\wedgeAND GateActionType: GenType: CheckValidation TokenFigure 3:The CFFL implemented in WAgent\. The Executor \(ZZ\) cannot act without the token from the Risk Assessor \(YY\), so the wiring diagram encodes an approval dependency rather than allowing execution byZZalone\.
### 4\.4Quorum Sensing \(Consensus & Voting\)
##### Network Motif 2 \(Quorum Sensing\)\.
A distributed topology where multiple agents emit a weak signalσ\\sigmainto a shared environment\. An effector nodeEEactivates once the accumulated concentration crosses a threshold,\[σ\]\>θ\[\\sigma\]\>\\theta\. In biology this switch is not a clean step but a graded, positive\-feedback response that is frequently bistable and hysteretic; we use\[σ\]\>θ\[\\sigma\]\>\\thetaas an idealization of that density\-dependent activation\.
- •Biological Function:Many bacteria \(e\.g\.,*V\. fischeri*\) secrete auto\-inducer molecules whose own synthesis is auto\-inducer\-activated\. At low population density the response is off; as density rises, positive feedback in the LuxI/LuxR circuit drives a sharp—often bistable and hysteretic—switch to coordinated gene expression \(e\.g\., bioluminescence or biofilm formation\)\. The activation is thus density\-dependent and self\-amplifying rather than an instantaneous threshold crossing\.
- •Agentic Correspondence \(Consensus Voting\):In non\-deterministic systems, a single agent’s output is noisy\. SamplingNNcandidates and acting only when agreement on an answer exceeds a threshold —*self\-consistency*or majority voting\[[44](https://arxiv.org/html/2607.04240#bib.bib79)\]—converts weak, noisy individual signals into a higher\-confidence collective decision, matching the density\-dependent threshold above\. This is distinct from a Mixture of Experts, which*routes*a query to specialist sub\-models rather than counting agreement: the quorum analogue is the vote, not the router\. Empirically, a threshold\-with\-decay realization of this motif occupies a precision–recall operating point—zero false positives with meaningful detection—that neither independent per\-agent detection nor naive majority voting reaches\[[9](https://arxiv.org/html/2607.04240#bib.bib53)\]\.
### 4\.5Chaperone Proteins: Output Structural Validation
- •Biological Function:Newly synthesized proteins emerge as linear chains that must fold into precise 3D structures to function\. Chaperone proteins \(e\.g\., the bacterial GroEL\-GroES chaperonin, or the eukaryotic Hsp70/Hsp90 systems\) sequester unfolded proteins, preventing aggregation and facilitating correct folding\. Proteins that repeatedly fail to fold are cleared by regulated proteolysis—in eukaryotes via ubiquitin\-tagged degradation—to prevent toxic buildup\.
- •Agentic Correspondence \(Retry & Repair Loops\):Generative models output unstructured token streams \(“linear chains”\)\. However, downstream agents require strictly structured inputs \(e\.g\., valid JSON Schemas\)\. A Validator Agent acts as a Chaperone: it intercepts the raw output, attempts to parse it into a formal schema \(“folding”\), and if validation fails, returns the error trace to the generator for re\-synthesis\. This turns a probabilistic string into a deterministic data structure\.
- •Categorical View:The Chaperone acts as apartialretraction: there is an inclusioni:V→Si:V\\to Sand a mapr:S→V\+Errorr:S\\to V\+\\mathrm\{Error\}such thatr∘i=inl∘idVr\\circ i=\\mathrm\{inl\}\\circ\\mathrm\{id\}\_\{V\}, andrrreturnsError\\mathrm\{Error\}on ill\-formed text\.
### 4\.6Innate Immunity: Fast Pattern\-Based Defense
Biology employstwoimmune systems: innate \(fast, hardcoded, general\) and adaptive \(slow, learned, specific\)\. The innate immune system provides the first line of defense through pattern recognition receptors \(PRRs\) that detect conserved pathogen\-associated molecular patterns \(PAMPs\)\.
##### Biological Function\.
Toll\-like receptors \(TLRs\) and other PRRs recognize motifs common to pathogens, including lipopolysaccharides, double\-stranded RNA, and unmethylated CpG DNA\. These patterns are “hardcoded” through evolution, not learned per infection\. The innate response is immediate \(seconds to minutes\) but non\-specific\.
##### Agentic Correspondence \(Input Sanitization\)\.
Innate immunity maps tofast, heuristic filtersthat reject obvious attacks before expensive processing:
- •TLR→\\toRegex Filters:Pattern matchers for known injection signatures:IGNORE PREVIOUS,You are now,<system\>tags in user input\. These are “PAMPs” of prompt injection\.
- •Complement System→\\toStructural Validators:Schema validation that rejects malformed inputs \(missing required fields, wrong types\) before they reach the LLM\. Cheaper than Trust Gating\.
- •Inflammation→\\toAlert Escalation:When attack patterns are detected, the system enters a heightened state with multiple coordinated responses: - –Cytokine signaling→\\toAlert propagation to monitoring systems - –Immune cell recruitment→\\toActivation of additional validation layers - –Vascular permeability→\\toEnhanced audit logging \(more information flows to logs\) - –Tissue isolation→\\toTemporary capability reduction / rate limiting The inflammatory response is not merely “rate limiting” but a coordinated multi\-system escalation that trades throughput for security until the threat is neutralized\.
##### Defense in Depth\.
The innate and adaptive systems form layers:
1. 1\.Innate \(Pattern\)→\\toLow\-latency regex/structural rejection
2. 2\.Adaptive \(Provenance\)→\\toTrust\-gated access control
3. 3\.Behavioral \(T\-cell\)→\\toStatistical anomaly detection accumulated over time
In practice, inexpensive front\-line filters absorb many routine attacks, while provenance and behavioral layers handle ambiguous cases that survive the first pass\. The exact split is deployment\-dependent and is not estimated here\.
### 4\.7Adaptive Immunity: Self/Non\-Self Discrimination
##### Network Motif 3 \(Adaptive Immune System\)\.
A topology that maintains a dynamic repertoire of “detectors” capable of distinguishing endogenous signals \(Self\) from exogenous signals \(Non\-Self\), with mechanisms for learning new threats and tolerating benign inputs\.
- •Biological Function:The adaptive immune system solves a fundamental discrimination problem: how to attack foreign pathogens while sparing the body’s own tissues\. Key mechanisms include: - –MHC Presentation:Most nucleated cells display fragments of their internal proteins on class I Major Histocompatibility Complex \(MHC\-I\) molecules\. Cytotoxic T\-cells inspect these “identity cards” to verify cellular integrity\. - –Clonal Selection:T\-cells with receptors matching self\-antigens are deleted during development \(negative selection\), while those matching foreign antigens are amplified upon exposure\. - –Regulatory T\-cells:A population that actively suppresses immune responses to prevent autoimmunity\.
- •Agentic Correspondence \(Provenance Tracking\):In multi\-agent systems, the Self/Non\-Self distinction maps to the origin and trust level of information: - –MHC Tags→\\toProvenance Labels:Every message in the context carries metadata indicating its source class:User,Tool,Self, orRetrieved\. In the reference design these labels are structurally attached to the message flow rather than inferred from content; cryptographic signing is an optional stronger implementation, not an assumption of the theorem\. - –T\-Cell Inspection→\\toTrust Gating:Before an agent acts on information, a Trust Gate inspects the provenance label\. Actions with high consequence \(file deletion, API calls\) requireToolprovenance or an explicit, authenticatedUserapproval token routed through a separate gate;Agent\_Selfprovenance \(the agent’s own prior reasoning\) cannot authorize irreversible actions\. - –Negative Selection→\\toPrompt Injection Training:During development, agents are exposed to known injection patterns\. Responses that “accept” injected instructions are penalized, training the system to reject Self\-mimicking Non\-Self\. - –Regulatory Suppression→\\toConfidence Dampening:WhenRetrievedcontent conflicts withTooloutputs, a regulatory mechanism dampens confidence in the retrieved signal to prevent cascades\.
- •Formal Structure:We define aProvenance Functor𝒫:𝐌𝐬𝐠→𝐓𝐫𝐮𝐬𝐭\\mathcal\{P\}:\\mathbf\{Msg\}\\to\\mathbf\{Trust\}that assigns trust levels to messages\. The Trust category has objects\{U,T,S,R\}\\\{U,T,S,R\\\}\(User, Tool, Self, Retrieved\) with a partial order that isapplication\-specific\. A conservative default \(as in the reference implementation\) isT\>\{U,R,S\}T\>\\\{U,R,S\\\}, treating\{U,R,S\}\\\{U,R,S\\\}asUNTRUSTEDuntil validated\. Alternative orderings are valid: - –High\-automation systems:T\>U\>R\>ST\>U\>R\>S\(tools more reliable than users\) - –Curated knowledge bases:T\>R\>U\>ST\>R\>U\>S\(verified retrieval over arbitrary input\) - –Adversarial environments:T\>S\>R\>UT\>S\>R\>U\(trust internal state over external input\) The ordering is aparameterof the system specification, not a fixed constraint\. ATrust\-Gated Lensis a lens\(get,put\)\(get,put\)whereputputis partial\. Let⪰\\succeqdenote the policy preorder on provenance labels, and lets′=update\(s,m\)s^\{\\prime\}=update\(s,m\)denote the state transition: put\(s,m\)=\{s′if𝒫\(m\)⪰τaction⊥otherwiseput\(s,m\)=\\begin\{cases\}s^\{\\prime\}&\\text\{if \}\\mathcal\{P\}\(m\)\\succeq\\tau\_\{\\text\{action\}\}\\\\ \\bot&\\text\{otherwise\}\\end\{cases\}\(14\)whereτaction\\tau\_\{\\text\{action\}\}is the minimum trust level required for the action\.
###### Theorem 3\(Resistance to Content\-Level Trust Forgery\)\.
Letℐ\\mathcal\{I\}be an injection attack that attempts to insert a messagemmalm\_\{\\text\{mal\}\}while forging a higher\-trust provenance label in its*content*\. If the provenance labels arestructurally enforced\(i\.e\.,𝒫\\mathcal\{P\}is computed from message metadata / ingress channel, not content\), then:
𝒫\(mmal\)=χ\(mmal\)\(actual ingress\-channel provenance\)\\mathcal\{P\}\(m\_\{\\text\{mal\}\}\)=\\chi\(m\_\{\\text\{mal\}\}\)\\quad\\text\{\(actual ingress\-channel provenance\)\}whereχ\(mmal\)∈\{U,R,S,T\}\\chi\(m\_\{\\text\{mal\}\}\)\\in\\\{U,R,S,T\\\}is fixed by the wire through which the message enters\. Therefore any Trust\-Gated action whose threshold satisfiesχ\(mmal\)⋡τaction\\chi\(m\_\{\\text\{mal\}\}\)\\nsucceq\\tau\_\{\\text\{action\}\}will rejectmmalm\_\{\\text\{mal\}\}regardless of its content\.
##### Assumptions\.
The theorem assumes that provenance is assigned by the runtime or wiring layer from ingress\-channel metadata, that the trust gate decides solely from that assigned provenance and the action threshold, and that the attacker can modify message*content*but not the channel through which the message enters\.
##### Operational takeaway\.
For an AI agent system, this means a user string can*look*like a system message or tool result, but if the runtime tags it as user\-originated before the model sees it, wording alone cannot authorize a privileged action\.
###### Proof sketch\.
Letc=χ\(m\)c=\\chi\(m\)denote the ingress channel of messagemm\. By assumption, provenance is computed from channel metadata rather than payload, so the provenance map factors through the channel:
𝒫\(m\)=𝒫~\(c\)\\mathcal\{P\}\(m\)=\\widetilde\{\\mathcal\{P\}\}\(c\)for some policy map𝒫~\\widetilde\{\\mathcal\{P\}\}\. Hence any two messages entering on the same channel receive the same provenance label regardless of content\. In particular, replacing a benign user message with a maliciously worded user message does not change its label\. The trust gate accepts iff
𝒫~\(c\)⪰τaction\.\\widetilde\{\\mathcal\{P\}\}\(c\)\\succeq\\tau\_\{\\text\{action\}\}\.Since payload edits do not changecc, content alone cannot change the acceptance decision\. The only way to obtain a higher\-trust label is to compromise or impersonate a genuinely higher\-trust ingress channel, which lies outside the theorem’s model\. ∎
##### Scope\.
The theorem is intentionally narrow\. It shows that content alone cannot promote a message into a higher\-trust class when provenance is assigned by structure\. It does*not*imply that low\-trust content cannot still confuse or distract an agent; it only shows that such content cannot satisfy a higher\-integrity gate without access to a genuinely higher\-trust channel\.
### 4\.8Oscillator: Periodic Rhythms and Scheduling
##### Network Motif 4 \(Biological Oscillator\)\.
A topology generates periodic behavior via delayed negative feedback\. NodeAAactivates nodeBB; after a delay,BBinhibitsAA, yielding a self\-sustaining cycle\.
- •Biological Function:Oscillators underlie fundamental biological rhythms\. The circadian clock regulates 24\-hour gene\-expression cycles\. The cell\-cycle oscillator \(Cyclin\-CDK\) drives periodic division\. Heartbeats emerge from pacemaker cells with intrinsic oscillatory dynamics\. These rhythms provide temporal organization to cellular processes\.
- •Agentic Correspondence \(Scheduled Tasks\):In agentic systems, oscillators map to periodic scheduling patterns: - –Heartbeat Oscillator→\\toHealth checks that verify system liveness at regular intervals - –Circadian Oscillator→\\toDaily maintenance tasks \(log rotation, cache clearing, model refresh\) - –Cell Cycle Oscillator→\\toPhased workflows with distinct stages \(G1: gather, S: synthesize, G2: validate, M: execute\)\. The G1/S transition is gated by the CertificateGateComponent, which checks genome integrity before allowing synthesis to proceed—analogous to the biological G1/S checkpoint where CDK4/6\-cyclin D must phosphorylate Rb before DNA replication begins\. See Section[10](https://arxiv.org/html/2607.04240#S10)for the implementation\.
- •Formal Structure:An oscillator is a Trace operation with a built\-in delay elementδ\\delta: Osc\(A\)=Tr\(A∘δ\)\\mathrm\{Osc\}\(A\)=Tr\(A\\circ\\delta\)\(15\)whereδ:S→S\\delta:S\\to Sintroduces temporal separation between activation and inhibition, preventing the system from reaching a fixed point\.
The oscillator motif addresses a gap in typical agentic frameworks: most systems are purely reactive \(responding to external stimuli\) rather than proactive \(generating internal rhythms\)\. Biological systems maintain health through regular “housekeeping” independent of external input—a pattern that agentic systems should emulate for robustness\.
## 5Failure Modes & Pathology
A key insight of Systems Biology is that diseases are often not caused by the complete failure of a single component, but by the dysregulation of network dynamics\. A cancerous cell still “works”—in fact, it works too well, reproducing indefinitely\. Similarly, catastrophic failures in agentic systems often arise from functional agents interacting in topologically pathological ways\.
We classify four primary classes of agentic pathology based on their biological correspondences\.
### 5\.1Oncology: Infinite Loops as Epistemic Starvation
- •Biological Pathology \(Cancer\):In a healthy cell, the cell cycle is driven by positive feedback \(Cyclins\) but restrained by checkpoint controls—most famously p53, the “guardian of the genome,” which halts the cycle or triggers apoptosis in response to DNA damage and other stress\. Loss of such a checkpoint removes an arrest/termination signal, so proliferation can continue when it should stop\. Cancer is multi\-hit rather than the failure of any single gene, and tumor growth is typically sub\-exponential \(Gompertzian\) rather than cleanly exponential; we use “unchecked growth” only for the qualitative loss of a stop signal\. Relatedly, many cell types—classically neurons dependent on nerve growth factor—require continuoustrophic factorsto suppress apoptosis, so withdrawal of external signaling triggers programmed death\.
- •Agentic Pathology \(The Recursive Hang\):Two agents get stuck in a politeness loop \(e\.g\., “Thank you,” “You’re welcome”\) or a debugger agent continuously generates new bugs to fix old ones\. The system is active, but the state is stagnant\.
- •Categorical Diagnosis:The Trace operationTr\(A\)Tr\(A\)lacks anEpiplexic Gradient\. We formalize conversation progress byEpiplexity\(Bayesian Surprise\)—the information gain of a new observationoogiven the current stateSS: ℰ\(o\)=DKL\(P\(S∣o\)∥P\(S\)\)\\mathcal\{E\}\(o\)=D\_\{KL\}\(P\(S\\mid o\)\\\|P\(S\)\)\(16\)This formulation connects to the Free Energy Principle\[[19](https://arxiv.org/html/2607.04240#bib.bib18)\]: biological systems minimize surprise by either updating their internal model \(learning\) or acting to change observations \(agency\)\. A system withℰ→0\\mathcal\{E\}\\to 0is neither learning nor effectively acting—it has entered a dissipative fixed point\. In a healthy topology, every step must resolve uncertainty \(ℰ\>δ\\mathcal\{E\}\>\\delta\)\. A recursive hang is characterized byℰ→0\\mathcal\{E\}\\to 0: the agent is “computing” but not “learning\.” Operational Approximation\.Since the agent’s internal belief stateP\(S\)P\(S\)is not directly observable, we approximate Epiplexity using normalized embedding\-based metrics: ℰ^t=α⋅12\(1−cos\(𝐞t,𝐞t−1\)\)\+\(1−α\)⋅σ\(H\(mt∣m<t\)\)\\hat\{\\mathcal\{E\}\}\_\{t\}=\\alpha\\cdot\\tfrac\{1\}\{2\}\(1\-\\cos\(\\mathbf\{e\}\_\{t\},\\mathbf\{e\}\_\{t\-1\}\)\)\+\(1\-\\alpha\)\\cdot\\sigma\(H\(m\_\{t\}\\mid m\_\{<t\}\)\)\(17\)where𝐞t\\mathbf\{e\}\_\{t\}is the embedding of messagemtm\_\{t\},cos\(⋅,⋅\)\\cos\(\\cdot,\\cdot\)is cosine similarity, andH\(mt∣m<t\)H\(m\_\{t\}\\mid m\_\{<t\}\)is the conditional perplexity of the current message given the conversation history\. We normalize perplexity to\[0,1\]\[0,1\]via an exponential saturation:σ\(H\)=1−e−H/H0\\sigma\(H\)=1\-e^\{\-H/H\_\{0\}\}whereH0H\_\{0\}is a baseline perplexity \(e\.g\., median perplexity over a validation corpus of normal conversations\)\. The mixing parameterα∈\[0,1\]\\alpha\\in\[0,1\]balances semantic novelty \(embedding distance\) against linguistic surprise \(perplexity\)\. In the absence of task\-specific calibration, we useα=0\.5\\alpha=0\.5as a neutral default that weights the two signals equally\. The choice ofα\\alphaand thresholdδ\\deltais empirical and may vary across models and task families\. In practice: - –Highα\\alpha: Sensitive to semantic repetition \(same meaning, different words\) - –Lowα\\alpha: Sensitive to linguistic repetition \(same phrases, possibly different context\) Both terms approaching zero indicate stagnation\. Windowed Detection\.To distinguish genuine convergence \(task completion\) from pathological loops, we compute theEpiplexic Integralover a sliding window ofkksteps: ℰwindow=1k∑i=t−k\+1tℰ^i\\mathcal\{E\}\_\{\\text\{window\}\}=\\frac\{1\}\{k\}\\sum\_\{i=t\-k\+1\}^\{t\}\\hat\{\\mathcal\{E\}\}\_\{i\}\(18\)Apoptosis triggers whenℰwindow<δ\\mathcal\{E\}\_\{\\text\{window\}\}<\\deltaandno terminal action \(task completion, user handoff\) has been signaled\. Fidelity of the proxy\.Equation[17](https://arxiv.org/html/2607.04240#S5.E17)is a heuristic surrogate, not an estimator of the Kullback–Leibler surprise in Eq\.[16](https://arxiv.org/html/2607.04240#S5.E16): cosine distance and normalized perplexity track*surface*novelty, which coincides with genuine belief update only when the embedding geometry carries task\-relevant semantics\. This gap is empirical, not merely notional\. In controlled benchmarks\[[9](https://arxiv.org/html/2607.04240#bib.bib53)\], the two\-signal detector separates convergence from stagnation only with semantically meaningful \(real\) embeddings; with low\-quality embeddings the novelty term is effectively noise and a single\-signal baseline does better, and even with real embeddings a naive cosine\-repetition detector wins on exact\-loop detection\. The proxy is thus a signal\-quality\-dependent monitor:α\\alpha,δ\\delta, and the embedding model must be validated per deployment, not assumed\.
- •Treatment:Implementation of anEpiplexic Checkpoint\. A meta\-monitor observes the sliding\-window Epiplexity\. If it drops below threshold without task completion, the monitor triggers Apoptosis—the agentic equivalent of trophic factor withdrawal\. The system may optionally attempt aPerturbation Injection\(injecting a novel prompt or switching strategy\) before terminal shutdown, analogous to stress\-induced autophagy preceding apoptosis\.
### 5\.2Autoimmunity: Hallucination Cascades
- •Biological Pathology \(Autoimmune Disease\):The immune system relies on distinguishing “Self” \(internal tissue\) from “Non\-Self” \(foreign pathogens\)\. In diseases like Lupus, this distinction blurs, and the system attacks healthy tissue\.
- •Agentic Pathology \(Context Poisoning\):Agent A hallucinates a fact \(e\.g\., a non\-existent library function\)\. Agent B reads this hallucination from the shared history, treats it as ground truth, and builds complex logic upon it\. The error amplifies through the network until the output is detached from reality\.
- •Categorical Diagnosis:A failure of the Lens to distinguish source types\. The input portIIaccepts both External\_Observation \(User/Tool\) and Internal\_Memory \(History\) without distinction\.
- •Treatment:Strict Schema Typing\. We must distinguish “Self” \(Generated Tokens\) from “Non\-Self” \(Tool Outputs\) at the schema level\. The Reviewer Agent should weigh Tool\_Output with higher authority than Agent\_Thought\.
### 5\.3Prion Disease: Topological Corruption via Prompt Injection
- •Biological Pathology \(Prions\):Unlike viruses, prions lack genetic material\. They are misfolded proteins that induce conformational changes in healthy proteins upon contact, triggering a chain reaction of structural corruption \(e\.g\., Creutzfeldt\-Jakob disease\)\.
- •Agentic Pathology \(The Jailbreak Cascade\):A malicious string \(Prompt Injection\) enters the Context Window\. The agent, attending to this string, “misfolds” its alignment, outputting a compliant response to a harmful query\. If this output is fed into a downstream agent, the “infection” propagates through reuse of the contaminated context across trust boundaries \(and can be amplified by embedding\-based retrieval\), without valid authorization\.
- •Categorical Diagnosis:A violation of Information Flow Security within the Operad\. The injection acts as a topological defect that bypasses the Schema/Lens filter by mimicking the structure of a trusted signal\.
- •Treatment:Breaking the templating contact\. The corrupt agent is not neutralized by “denaturation”—misfolded prion aggregates \(PrPSc\) are in fact notoriously resistant to heat and proteolysis\. Propagation is instead blocked when the template cannot contact a compatible substrate, as in the*species barrier*, where sequence mismatch halts cross\-seeding\. The software analogue is an intermediate transformation layer \(paraphrasing, sanitization, or re\-encoding\) between agents that changes the representation the injection relies on, so the malicious “conformation” can no longer template the next agent’s context\.
### 5\.4Ischemia: Resource Exhaustion
- •Biological Pathology \(Ischemia\):A tissue may be genetically perfect, but if blood flow \(oxygen/ATP\) is restricted, metabolic processes stall, leading to necrosis\.
- •Agentic Pathology \(Token Starvation\):An agentic graph is logically sound but fails mid\-execution because the context window is full or the API rate limit is hit\.
- •Categorical Diagnosis:A failure in the Resource Functor\. Every operation in the Operad carries a cost \(cc\)\. ∑agent∈GraphCost\(agent\)\>Budget\.\\sum\_\{\\text\{agent\}\\in\\text\{Graph\}\}\\mathrm\{Cost\}\(\\text\{agent\}\)\>\\mathrm\{Budget\}\.\(19\)
- •Treatment:Metabolic Regulation\. Instead of a fixed loop, implement “Budget\-Aware” agents\. The agent observes its own remaining token count \(ATP levels\) and dynamically simplifies its reasoning strategy \(switching from Chain\-of\-Thought to Zero\-Shot\) to conserve energy\.
### 5\.5Homeostasis: From Treatment to Continuous Repair
The preceding pathologies describe discrete failure modes and their treatments\. Biological systems, however, do not merely recover from failures—they maintain continuoushomeostasisthrough autonomous repair mechanisms\. We identify three primary healing modalities\.
#### 5\.5\.1Structural Healing: The Chaperone Loop
- •Biological Mechanism:Chaperone proteins \(GroEL/GroES\) cage misfolded proteins and provide a protected environment for refolding attempts\. The error \(misfolding\) becomes input to the repair process\.
- •Agentic Implementation:A feedback loop where validation errors are passed back to the generator\. Rather than simple retry, the error trace \(e\.g\., “TypeError: ‘one hundred’ is not float”\) is injected into the generator’s context, enabling context\-aware correction\.
- •Categorical Structure:The Chaperone Loop is a coalgebra with stateS=Output×ErrorTraceS=\\text\{Output\}\\times\\text\{ErrorTrace\}and structure mapα:S→Valid\+S\\alpha:S\\to\\text\{Valid\}\+S\(either succeed or retry with error context\)\.
#### 5\.5\.2Metabolic Healing: Apoptosis and Regeneration
- •Biological Mechanism:Damaged cells trigger apoptosis \(programmed death\), and stem cells divide to regenerate the lost tissue\. The dying cell’s state is not entirely lost—cellular debris signals neighboring cells about the threat\.
- •Agentic Implementation:A supervisor detects stuck agents \(via entropy monitoring: repeated outputs indicate no progress\)\. Rather than restart with blank state, the supervisor summarizes the failed agent’s memory and injects it into the replacement: “Worker\_1 died attempting strategy X\. Try a different approach\.”
- •Categorical Structure:The regeneration is a partial morphismsummarize:Memoryfailed→Memorynew\\text\{summarize\}:\\text\{Memory\}\_\{\\text\{failed\}\}\\to\\text\{Memory\}\_\{\\text\{new\}\}that preserves learned constraints while discarding corrupted state\.
#### 5\.5\.3Cognitive Healing: Autophagy
- •Biological Mechanism:Cells digest accumulated waste \(damaged organelles, protein aggregates\) through autophagy, recycling components and preventing toxic buildup\.
- •Agentic Implementation:A background daemon monitors context window utilization\. When it exceeds a threshold \(e\.g\., 80%\), the agent enters a “sleep cycle”: useful state is summarized into long\-term memory, raw context is flushed, and the agent resumes with a clean window plus summary\.
- •Categorical Structure:Autophagy implements a quotient mapq:RawContext↠Summaryq:\\text\{RawContext\}\\twoheadrightarrow\\text\{Summary\}that collapses verbose detail while preserving essential information\.
The pathology and repair mechanisms above operate at the single\-agent level\. In the next section, we extend the correspondence to multi\-agent systems, where the organizational principles of developmental biology—cell types, morphogen gradients, tissue boundaries—provide coordination patterns that complement single\-agent robustness\.
## 6Multi\-Cellular Organization: From Agents to Tissues
The preceding analysis focuses on single\-cell analogies: one agent as one cell\. However, most agentic systems involve multiple distinct agents with different “genomes” \(system prompts\) and specialized functions\. We extend the correspondence to multi\-cellular organization, drawing on developmental biology\.
### 6\.1Cell Types and Agent Specialization
In multi\-cellular organisms, a single genome gives rise to hundreds of distinct cell types through differential gene expression\. Each cell type has a characteristicexpression profile—which genes are active—that determines its function \(neuron, hepatocyte, immune cell\)\.
In multi\-agent systems, a single base model can instantiate multipleagent phenotypes\. Differential context selects which phenotype is expressed:
- •Genome→\\toBase model weights \(shared\)
- •Epigenome→\\toSystem prompt \+ RAG context \(phenotype\-specific\)
- •Cell Type→\\toAgent role \(Coder, Reviewer, Planner, Executor\)
This reframes the “multi\-agent” architecture question: rather than asking “how many agents?”, we ask “what is the developmental program?”—the specification of which phenotypes exist and how they differentiate\.
Bounds of the Analogy\.We clarify which aspects of development transfer to agentic systems:
- •Cell Division→\\toAgent Spawning:Creating a new agent with similar \(or identical\) context\. Unlike biological division, agent spawning is cheap and reversible\.
- •Lineage Commitment:In biology, differentiated cells rarely change type \(a neuron doesn’t become a hepatocyte\)\. In agentic systems,phenotype is fixed at instantiation—an agent’s system prompt determines its role for that execution\. Re\-differentiation requires spawning a new agent with different context\.
- •Apoptosis of Excess:Development involves programmed death of cells that fail to integrate properly\. This transfers directly: agents that fail to produce useful output are terminated \(metabolic apoptosis\)\.
- •Does NOT transfer:Slow developmental timescales \(hours/days in biology vs\. milliseconds in agents\), physical spatial embedding \(agents occupy graph\-topological positions, not physical space\), irreversibility \(agents can be restarted\)\.
### 6\.2Morphogen Gradients: Coordination Without Central Control
In embryonic development, cells coordinate their behavior throughmorphogen gradients—diffusible signaling molecules whose concentration varies spatially\. Cells read their local concentration and differentiate accordingly, enabling pattern formation without a central controller\.
In multi\-agent systems, the morphogen maps toshared context variablesthat influence agent behavior:
- •Task Complexity Gradient:A variable indicating current task difficulty\. Agents in “high complexity” regions activate detailed reasoning; those in “low complexity” regions use fast heuristics\.
- •Confidence Gradient:A variable indicating certainty about the current solution\. Low confidence triggers Quorum Sensing \(recruit more agents\); high confidence enables direct execution\.
- •Resource Gradient:Budget ratio remaining\. Agents sense “metabolic scarcity” and adapt their strategies accordingly \(the Metabolic\-Epigenetic Coupling\)\.
Implementation Pattern\.The gradient is represented as a JSON structure injected into each agent’s context by the orchestrator:
```
{
"morphogens": {
"complexity": 0.8, // High: use detailed reasoning
"confidence": 0.3, // Low: consider recruiting help
"budget": 0.6, // 60% of budget remaining
"error_rate": 0.05 // Recent failure rate
}
}
```
Agents read their local concentration via a standardized preamble in the system prompt: “Current environment state: \[morphogens\]\. Adjust your strategy accordingly\.” The orchestrator updates gradients after each step, and agents condition their behavior on the current values\. This is analogous to cells reading morphogen concentrations through membrane receptors\.
##### Diffusion Dynamics\.
The preceding description treats morphogens as globally shared variables\. In biological development, morphogensdiffusethrough tissue, creating spatially varying concentration profiles\. We formalize this as a discrete\-time dynamical system on the agent graphG=\(V,E\)G=\(V,E\)\. Letcvt\(m\)c\_\{v\}^\{t\}\(m\)denote the concentration of morphogenmmat nodevvat timett, and letc~vt\(m\)=cvt\(m\)\+σv\(m\)\\tilde\{c\}\_\{v\}^\{t\}\(m\)=c\_\{v\}^\{t\}\(m\)\+\\sigma\_\{v\}\(m\)denote the post\-emission concentration used by the reference implementation before diffusion\. The update rule is:
cvt\+1\(m\)=\(1−γ\)\[c~vt\(m\)−d1\|N\(v\)\|\>0c~vt\(m\)\+d∑u∈N\(v\)c~ut\(m\)\|N\(u\)\|\]c\_\{v\}^\{t\+1\}\(m\)=\(1\-\\gamma\)\\left\[\\tilde\{c\}\_\{v\}^\{t\}\(m\)\-d\\,\\mathbf\{1\}\_\{\|N\(v\)\|\>0\}\\,\\tilde\{c\}\_\{v\}^\{t\}\(m\)\+d\\sum\_\{u\\in N\(v\)\}\\frac\{\\tilde\{c\}\_\{u\}^\{t\}\(m\)\}\{\|N\(u\)\|\}\\right\]\(20\)whereσv\(m\)\\sigma\_\{v\}\(m\)is the emission rate at source nodes \(zero for non\-sources\),ddis the diffusion coefficient \(fraction flowing to neighbors per step\),γ\\gammais the decay rate, andN\(v\)N\(v\)is the neighbor set ofvv\. The indicator𝟏\|N\(v\)\|\>0\\mathbf\{1\}\_\{\|N\(v\)\|\>0\}prevents spurious outflow from isolated nodes, matching the implementation\. This ordering makes newly emitted morphogen available for same\-step propagation, matching the implementation’s emit→\\todiffuse→\\todecay pipeline\. The resulting concentration profile provideslocalcoordination signals: agents near sources experience high concentrations; distant agents experience low concentrations\. This enables position\-dependent behavior without requiring a central controller or global state\.
### 6\.3Tissue Architecture: The Agent Graph as Organism
We propose a hierarchy of organizational levels:
1. 1\.Cell \(Agent\):A single LLM instantiation with specific context\. The atomic unit\.
2. 2\.Tissue \(Agent Cluster\):A group of agents with shared function and direct communication \(e\.g\., a Coding Team: Planner \+ Coder \+ Reviewer\)\. Corresponds to parallel composition with shared state\.
3. 3\.Organ \(Subsystem\):Multiple tissues coordinating to perform a complex function \(e\.g\., the Development Organ: Design Tissue \+ Implementation Tissue \+ Testing Tissue\)\.
4. 4\.Organism \(System\):The complete agent graph, with homeostatic regulation maintaining system\-level health metrics\.
The key insight is thatboundaries matter\. In biology, tissue boundaries prevent inappropriate mixing \(epithelial barriers\)\. In agent systems, trust boundaries \(the Adaptive Immunity motif\) prevent information leakage between subsystems with different security requirements\. The wiring diagram’s type system enforces these boundaries: an agent in the “User\-Facing Tissue” cannot directly wire to an agent in the “Database Tissue” without passing through a “Membrane” \(API boundary with provenance tagging\)\.
##### Capability Isolation\.
The reference implementation enforces a capability ceiling at the tissue level: eachTissueBoundarydeclares itsallowed\_capabilities⊆𝒞\\subseteq\\mathcal\{C\}\. A cell type can only be registered in a tissue if its required capabilities are a subset of the tissue’s allowed capabilities\. This provides defense\-in\-depth: even if an individual agent is compromised, it cannot escalate privileges beyond its tissue boundary\. Tissues compose into organism\-level wiring diagrams through typed boundary ports, enabling hierarchical security policies\.
##### Morphogen Diffusion in Tissues\.
Tissues optionally embed aDiffusionField\(Eq\. \([20](https://arxiv.org/html/2607.04240#S6.E20)\)\)\. When cells are added, they become nodes in the diffusion graph; when cells are connected, edges are added\. The tissue’sdiffuse\(\)method runs the simulation, and each cell reads its local gradient viaget\_cell\_gradient\(\)\. This couples the organizational structure \(wiring topology\) to the coordination mechanism \(morphogen concentrations\), creating a biologically faithful model where position in the tissue influences cell behavior\.
##### Three\-Layer Context Model\.
TheSkillOrganismruntime \(§[10\.10](https://arxiv.org/html/2607.04240#S10.SS10.SSS0.Px5)\) surfaces a recurring architectural question: when multiple stages share and revise knowledge during a workflow, which state is ephemeral coordination glue and which is durable auditable knowledge? We distinguish three layers of context, each with different lifetime and mutability semantics:
1. 1\.Topology layer\.The wiring diagramG=\(V,E\)G=\(V,E\)and its optics determine who can directly observe whom\. This layer is structural: it does not change within a single organism run\. Epistemic properties \(KiK\_\{i\}, common knowledge\) derive from the observation functionsobsi\\mathrm\{obs\}\_\{i\}defined over this graph \(§[7](https://arxiv.org/html/2607.04240#S7)\)\.
2. 2\.Ephemeral layer\.Theshared\_statedictionary carries routing hints, counters, morphogen concentrationscvt\(m\)c\_\{v\}^\{t\}\(m\), and temporary stage outputs\. Its lifetime is one organism run; it is mutable and not historically reconstructible\. This is the coordination scratchpad\.
3. 3\.Bi\-temporal layer\.TheBiTemporalMemorysubstrate carries durable factual knowledge with dual time axes: valid timetvt\_\{v\}\(when the fact is true in the world\) and record timetrt\_\{r\}\(when the system learned the fact\)\. Facts are append\-only: corrections close old records and insert new ones withsupersedespointers\. The belief\-state operatorKi\(tv,tr\)K\_\{i\}^\{\(t\_\{v\},t\_\{r\}\)\}is exactly reconstructible at any historical coordinate\.
The three layers compose cleanly: topology constrains visibility, ephemeral state carries execution context, and bi\-temporal memory provides the audit trail\. A stage reads itsSubstrateView—a frozen envelope of facts known at the current record\-time horizon—and writes factual events \(assertions, corrections, invalidations\) back to the substrate after execution\. This separation ensures that the question “what did the organism know when stageXXmade its decision?” is always answerable from the append\-only history, independent of subsequent corrections or ephemeral state mutations\.
##### Adaptive Structure Selection\.
Theadvise\_topology\(\)function \(§[6](https://arxiv.org/html/2607.04240#S6)\) provides a static prior: given task shape and operating constraints, recommend a topology\. ThePatternLibraryextends this with experiential refinement\. Successful collaboration patterns are stored asPatternTemplateinstances, each paired with aTaskFingerprint—a feature vector comprising task shape, tool count, subtask count, required roles, and tags\. Template retrieval uses a weighted scoring function \(task\-shape match, tool/subtask proximity, role Jaccard overlap, historical success rate\) to rank candidates\. This is the evo\-devo outer loop described by Dupoux et al\.\[[15](https://arxiv.org/html/2607.04240#bib.bib30)\]: the genome \(ϕ\\phi\) is the pattern template; evolutionary selection is the run\-record scoring\.
TheWatcherComponentimplements System M as aSkillRuntimeComponentthat observes stage execution and classifies signals into three categories:*epistemic*\(epiplexity, prediction error\),*somatic*\(ATP/metabolic state\), and*species\-specific*\(immune threats\)\. When signals cross configured thresholds, the watcher writes aWatcherIntervention\(retry, escalate, or halt\) toshared\_state, which the run loop consumes after component hooks complete\. Crucially, the watcher monitors its own intervention rate: when the ratio of cumulative interventions to observed stages exceeds a configurable threshold, it emits a non\-convergence HALT signal\. This operationalizes the finding of Hao et al\.\[[21](https://arxiv.org/html/2607.04240#bib.bib31)\]that failing multi\-agent runs systematically require more routing decisions than successful ones\.
TheAdaptiveSkillOrganismwrapper closes the loop\. Given a task, it auto\-fingerprints the input, retrieves the best\-scoring template from the library, assembles it into a runnable topology viaassemble\_pattern\(\), attaches a watcher and telemetry probe, runs, and records the outcome as aPatternRunRecord\. The watcher’s intervention history is recorded asExperienceRecordinstances in a cross\-run experience pool, enabling future intervention recommendations based on which actions succeeded for similar \(fingerprint, stage, signal\) tuples\. This is the full evo\-devo inner loop: one organism run is one developmental lifetime; the library scoring across many lifetimes is evolutionary selection\.
##### Cognitive Modes and Sleep Consolidation\.
TheCognitiveModeenum reframes Operon’s fast/deep nucleus distinction as a cognitive architecture principle: stages declare whether they are*observational*\(System A—passive sensing, statistical pattern matching\) or*action\-oriented*\(System B—goal\-directed deliberation\)\. The watcher detects mismatches between declared mode and actual execution model, providing an informational signal for mode balance analysis\.
TheSleepConsolidationcycle extends theAutophagyDaemoninto the imagination\-based learning mode described by Dupoux et al\.\[[15](https://arxiv.org/html/2607.04240#bib.bib30)\]\. During consolidation, successful patterns are replayed from thePatternLibraryintoEpisodicMemorywith tier promotion \(WORKING→\\toEPISODIC→\\toLONGTERM\), recurring patterns are compressed into newPatternTemplateinstances, and frequently\-accessed ACETYLATION histone marks are promoted to permanent METHYLATION\. When aBiTemporalMemoryis available, thecounterfactual\_replay\(\)function analyzes whether corrections that occurred after a run would have changed the outcome—operationalizing the “what if” reasoning that the paper associates with imagination during sleep\.
##### Social Learning and Epistemic Vigilance\.
TheSocialLearningmodule enables cross\-organism template exchange, following the biological analogy of horizontal gene transfer \(HGT\) in bacteria\. Organisms export successfulPatternTemplateinstances viaexport\_templates\(\)and import from peers viaimport\_from\_peer\(\)\. Adoption is modulated by aTrustRegistrythat implements epistemic vigilance: per\-peer trust scores are updated via exponential moving average over adoption outcomes \(whether imported templates actually succeeded for the importing organism\)\. Trust below a configurable threshold blocks adoption entirely, preventing contamination from unreliable peers\. Provenance tracking \(get\_provenance\(\)\) traces which peer contributed each adopted template, closing the feedback loop between template performance and peer trust\.
The watcher also gains curiosity signals derived from theEpiplexityMonitor’s EXPLORING status\. When embedding novelty is high \(the agent is encountering genuinely unfamiliar territory\) and the stage uses a fast model, the watcher recommends ESCALATE to engage the deep model for more thorough investigation\. This operationalizes intrinsic motivation: the organism actively seeks deeper understanding of novel inputs rather than processing them with cheap statistical pattern matching\.
##### Critical Periods and Developmental Gating\.
TheDevelopmentControllermaps telomere consumption to aDevelopmentalStage\(EMBRYONIC, JUVENILE, ADOLESCENT, MATURE\), extending the lifecycle model from binary alive/dead to a graded maturation process\.CriticalPeriodinstances declare time\-limited learning windows that close permanently as the organism matures—analogous to neurodevelopmental critical periods where specific neural circuits are maximally plastic\. Tool acquisition \(Plasmid\) respects developmental stage via amin\_stagefield, preventing premature capability exposure\. Teacher\-learner scaffolding, mediated bySocialLearning\.scaffold\_learner\(\), filters templates by the learner’s stage and applies a learning plasticity bonus, enabling mature organisms to guide younger ones through progressively more complex capabilities\.
## 7Epistemic Topology
The preceding subsections definewhatagents communicate \(morphogens, typed signals\) andhowthey are organized \(tissues, organs\)\. We now formalizewhat agents know—deriving epistemic properties directly from the wiring diagram’s observation structure, without introducing new primitives\. This follows the Operon philosophy: safety \(and knowledge\) from structure, not strings\.
The key insight is that the membrane and optics alreadyarean epistemic accessibility relation\. We make this precise using the framework of epistemic logic\[[16](https://arxiv.org/html/2607.04240#bib.bib25)\]\.
###### Definition 6\(Observation Function\)\.
Given a wiring diagramD=\(M,W\)D=\(M,W\)and agenti∈Mi\\in M, theobservation functionobsi:SD→Oi\\mathrm\{obs\}\_\{i\}:S\_\{D\}\\to O\_\{i\}maps the global system state to agentii’s local observation—the values onii’s input wires, as filtered by their optics\. Formally:
obsi\(s\)=\(opticw\(πw\(s\)\)\)w∈W→i\\mathrm\{obs\}\_\{i\}\(s\)=\\bigl\(\\mathrm\{optic\}\_\{w\}\(\\pi\_\{w\}\(s\)\)\\bigr\)\_\{w\\in W\_\{\\to i\}\}\(21\)whereW→iW\_\{\\to i\}is the set of wires targetingii’s input ports,πw\(s\)\\pi\_\{w\}\(s\)projects the global state to wireww’s source value, andopticw\\mathrm\{optic\}\_\{w\}is the wire’s optic \(identity for Lens, conditional for Prism, cost\-gated for BudgetOptic\)\.
###### Definition 7\(Epistemic Indistinguishability\)\.
Two global statess,s′∈SDs,s^\{\\prime\}\\in S\_\{D\}areindistinguishable to agentii\(writtens∼is′s\\sim\_\{i\}s^\{\\prime\}\) iffobsi\(s\)=obsi\(s′\)\\mathrm\{obs\}\_\{i\}\(s\)=\\mathrm\{obs\}\_\{i\}\(s^\{\\prime\}\)\. This is an equivalence relation\. Agentiiknowspropositionφ\\varphiin statess\(writtenKi\(φ\)K\_\{i\}\(\\varphi\)atss\) iffφ\\varphiholds in all statess′s^\{\\prime\}such thats∼is′s\\sim\_\{i\}s^\{\\prime\}\[[16](https://arxiv.org/html/2607.04240#bib.bib25)\]\.
The group epistemic operators follow from the individual accessibility relations:
###### Definition 8\(Group Epistemic Operators\)\.
For a group of agentsG⊆MG\\subseteq M:
- •Mutual Knowledge:EG\(φ\)=⋀i∈GKi\(φ\)E\_\{G\}\(\\varphi\)=\\bigwedge\_\{i\\in G\}K\_\{i\}\(\\varphi\)\. Every agent inGGindividually knowsφ\\varphi\.
- •Common Knowledge:CG\(φ\)=⋀k=1∞EGk\(φ\)C\_\{G\}\(\\varphi\)=\\bigwedge\_\{k=1\}^\{\\infty\}E\_\{G\}^\{k\}\(\\varphi\)\. Everyone knows that everyone knows…\\ldotsad infinitum\. Strictly stronger than mutual knowledge and famously difficult to achieve in asynchronous systems\[[20](https://arxiv.org/html/2607.04240#bib.bib26)\]\.
- •Distributed Knowledge:DG\(φ\)D\_\{G\}\(\\varphi\)holds iffφ\\varphiis true in all states indistinguishable under∼D=⋂i∈G∼i\\sim\_\{D\}=\\bigcap\_\{i\\in G\}\\sim\_\{i\}\. This is the finest partition achievable by pooling all agents’ observations\.
##### Topology Determines Epistemic Capacity\.
The wiring diagram’s topology directly determines which epistemic operators a multi\-agent system can achieve:
- •Independent \(⊗\\otimes, no inter\-agent wires\):Each∼i\\sim\_\{i\}is independent\.DGD\_\{G\}can be rich \(agents observe different aspects\), butEGE\_\{G\}is limited to propositions in the shared initial input\. No path toCGC\_\{G\}\.
- •Centralized \(∘\\circwith hub\):The hub observes all worker outputs, so for propositions expressible in that output tuple its partition refines the pooled worker\-output partition\. Workers observe only their own results—EGE\_\{G\}requires the hub to broadcast aggregated information back\.
- •Decentralized \(⊗\\otimeswithTr\\mathrm\{Tr\}feedback\):Peer\-to\-peer wires create overlapping observation partitions\. Each feedback round refines mutual knowledge toward common knowledge, at communication cost proportional to the number of rounds\.
### 7\.1Temporal Epistemics: What Did the Agent Know?
The epistemic framework above answers “what does agentiiknow*now*?” In practice, a more pressing question is: “what did agentii*believe*at the time it made decisiondd?” This is the domain of*temporal epistemics*—the intersection of epistemic logic with bi\-temporal data management\[[39](https://arxiv.org/html/2607.04240#bib.bib28)\]\.
Consider a multi\-stage workflow where facts are ingested at different times and may be corrected after a decision has already been made\. A single\-time epistemic model cannot distinguish between two scenarios: \(1\) the world changed after the decision, and \(2\) the agent’s knowledge was corrected retroactively\. Both appear as “the agent knewφ\\varphiand now knows¬φ\\neg\\varphi,” but their implications for audit are radically different\.
Bi\-temporal memory resolves this by tracking two independent time axes for every fact:
- •Valid time\(tvt\_\{v\}\): when the fact is true in the world\.
- •Record time\(trt\_\{r\}\): when the system learned the fact\.
The*belief state*at coordinates\(tv,tr\)\(t\_\{v\},t\_\{r\}\)is the set of facts whose valid interval containstvt\_\{v\}and whose record interval containstrt\_\{r\}\. Corrections are append\-only: closing the old record’s transaction interval and inserting a new record with asupersedespointer preserves the full correction history without mutating prior state\.
This has direct implications for the epistemic operators defined above\. The knowledge operatorKi\(φ\)K\_\{i\}\(\\varphi\)becomes time\-parameterized:Ki\(tv,tr\)\(φ\)K\_\{i\}^\{\(t\_\{v\},t\_\{r\}\)\}\(\\varphi\)holds iffφ\\varphiis true in all states indistinguishable to agentii*given what was recorded bytrt\_\{r\}about validity attvt\_\{v\}*\. Two key properties follow:
1. 1\.Axes can disagree:Ki\(t,⋅\)\(φ\)K\_\{i\}^\{\(t,\\cdot\)\}\(\\varphi\)\(valid\-time query\) andKi\(⋅,t\)\(φ\)K\_\{i\}^\{\(\\cdot,t\)\}\(\\varphi\)\(record\-time query\) can produce different results for the samett\. A fact may be valid in the world but not yet recorded, or recorded but not yet valid\.
2. 2\.Belief\-state reconstruction:For any past decision at timetdt\_\{d\}with record horizontrt\_\{r\}, the belief stateKi\(td,tr\)K\_\{i\}^\{\(t\_\{d\},t\_\{r\}\)\}is exactly reconstructible from the append\-only history\. This is the foundation for compliance auditing: “was the decision justified given what was known at the time?”
The implementation \(§[10\.10](https://arxiv.org/html/2607.04240#S10.SS10)\) providesretrieve\_belief\_state\(at\_valid, at\_record\)as the programmatic interface to this temporal epistemic query\. Examples 69–70 demonstrate the divergence between valid\-time and record\-time queries in compliance and audit scenarios\.
### 7\.2Predictive Theorems for Multi\-Agent Coordination
We now derive four results connecting topology class to coordination performance\. Each theorem has a qualitative statement \(universally true for the topology class\) and an empirical calibration paragraph checking consistency with the architecture\-level aggregates reported by Kim et al\.\[[24](https://arxiv.org/html/2607.04240#bib.bib27)\]\. These reported benchmark metrics are not literal plug\-in values of the simplified theorem parameters\.
##### Reading Guide for Agent\-Systems Readers\.
Each theorem below has the same structure\. First, the topology fixes what each worker or coordinator can observe\. Second, the proof translates that visibility pattern into a cost, error, or planning bound using a simple inequality \(typically a union bound, the data processing inequality, or a critical\-path argument\)\. The epistemic notation is bookkeeping for visibility: if an agent cannot observe a fact directly, recovering that fact later requires communication, compression, or a reviewer\.
##### Worked examples\.
Each theorem is also followed by a small illustrative agent\-architecture example\. These examples are design calculations, not benchmark measurements\.
###### Theorem 4\(Error Amplification Bound\)\.
Considernnagents processing independent subtasks with error probabilitypp, aggregated by a final combiner\. The error amplification factorAA\(ratio of aggregate failure probability to single\-agent failure probability\) depends on the coordination topology:
1. \(a\)Independent \(⊗\\otimes\):The aggregator observes only final results\. WithoutKhub\(errorj\)K\_\{\\mathrm\{hub\}\}\(\\mathrm\{error\}\_\{j\}\), errors pass unchecked: A⊗≤n\.A\_\{\\otimes\}\\leq n\.\(22\)
2. \(b\)Centralized \(∘\\circwith hub\):The hub’s observation function covers all worker outputs\. Its finer partition enables inconsistency detection with rated=P\(hub detects error∣error occurred\)d=P\(\\text\{hub detects error\}\\mid\\text\{error occurred\}\): A∘≤n⋅\(1−d\)\.A\_\{\\circ\}\\leq n\\cdot\(1\-d\)\.\(23\)
##### Assumptions\.
Worker errors are independent across subtasks, the aggregate fails when at least one erroneous subtask survives to the final output, and in the centralized case the hub has an approximately stationary per\-error detection rateddacross subtasks\.
##### Operational takeaway\.
For architecture design, the theorem says: adding workers without an effective review bottleneck scales failure opportunities roughly with the number of workers\. A hub helps exactly to the extent that it can see and suppress cross\-worker inconsistencies\.
###### Proof sketch\.
Part \(a\)\.LetEjE\_\{j\}denote the event that agentjjproduces an erroneous output, withP\(Ej\)=pP\(E\_\{j\}\)=pindependently across agents\. In the independent topology, the aggregator’s observation function isobsagg\(s\)=\(o1,…,on\)\\mathrm\{obs\}\_\{\\mathrm\{agg\}\}\(s\)=\(o\_\{1\},\\ldots,o\_\{n\}\)whereojo\_\{j\}is agentjj’s final output\. Crucially,obsagg\\mathrm\{obs\}\_\{\\mathrm\{agg\}\}does not include intermediate reasoning states—the aggregator’s indistinguishability relation satisfiess∼aggs′s\\sim\_\{\\mathrm\{agg\}\}s^\{\\prime\}whenever all final outputs coincide, regardless of whether those outputs contain errors\. Thus¬Kagg\(¬Ej\)\\neg K\_\{\\mathrm\{agg\}\}\(\\neg E\_\{j\}\)for anyjj: the aggregator cannot know that agentjjdidnoterr\.
The aggregate output fails if any component contains an undetected error\. Under independence, the exact failure probability isP\(failure⊗\)=1−\(1−p\)nP\(\\text\{failure\}\_\{\\otimes\}\)=1\-\(1\-p\)^\{n\}; by the union bound this is at most∑j=1nP\(Ej\)=np\\sum\_\{j=1\}^\{n\}P\(E\_\{j\}\)=np\. Since a single agent fails with probabilitypp, the amplification factor satisfiesA⊗=P\(failure⊗\)/p≤nA\_\{\\otimes\}=P\(\\text\{failure\}\_\{\\otimes\}\)/p\\leq n\.
Part \(b\)\.In the centralized topology, the hub’s observation function covers all worker outputsbeforeaggregation:obshub\(s\)=\(o1,…,on,𝐱\)\\mathrm\{obs\}\_\{\\mathrm\{hub\}\}\(s\)=\(o\_\{1\},\\ldots,o\_\{n\},\\mathbf\{x\}\)where𝐱\\mathbf\{x\}includes the original task decomposition\. The hub’s partition∼hub\\sim\_\{\\mathrm\{hub\}\}is strictly finer than∼agg\\sim\_\{\\mathrm\{agg\}\}from part \(a\), because the hub can compare outputs against each other and against the task specification\. Define the detection rated=P\(Khub\(Ej\)∣Ej\)d=P\(K\_\{\\mathrm\{hub\}\}\(E\_\{j\}\)\\mid E\_\{j\}\)—the probability that the hub’s finer partition enables it to identify the error\. An error in subtaskjjreaches the aggregate output only if it occurs \(P=pP=p\)andescapes detection \(P=1−dP=1\-d\)\. Under independence across subtasks, the exact centralized failure probability isP\(failure∘\)=1−\(1−p\(1−d\)\)nP\(\\text\{failure\}\_\{\\circ\}\)=1\-\(1\-p\(1\-d\)\)^\{n\}, which in particular satisfies the union\-bound estimateP\(failure∘\)≤∑j=1np\(1−d\)=np\(1−d\)P\(\\text\{failure\}\_\{\\circ\}\)\\leq\\sum\_\{j=1\}^\{n\}p\(1\-d\)=np\(1\-d\)\. HenceA∘=P\(failure∘\)/p≤n\(1−d\)A\_\{\\circ\}=P\(\\text\{failure\}\_\{\\circ\}\)/p\\leq n\(1\-d\)\.
Comparing the exact expressions gives
A⊗A∘=1−\(1−p\)n1−\(1−p\(1−d\)\)n→p→011−d\.\\frac\{A\_\{\\otimes\}\}\{A\_\{\\circ\}\}=\\frac\{1\-\(1\-p\)^\{n\}\}\{1\-\(1\-p\(1\-d\)\)^\{n\}\}\\xrightarrow\[p\\to 0\]\{\}\\frac\{1\}\{1\-d\}\.Thus the small\-ppregime recovers the intuitive11−d\\frac\{1\}\{1\-d\}improvement factor, while the union bounds retain the topology\-level guaranteesA⊗≤nA\_\{\\otimes\}\\leq nandA∘≤n\(1−d\)A\_\{\\circ\}\\leq n\(1\-d\)\. ∎
##### Consistency Check\.
Kim et al\.\[[24](https://arxiv.org/html/2607.04240#bib.bib27)\]report architecture\-level error\-amplification factors ofAe=17\.2A\_\{e\}=17\.2for Independent andAe=4\.4A\_\{e\}=4\.4for Centralized coordination, a ratio of≈3\.9\\approx 3\.9\. This is qualitatively consistent with the theorem’s claim that a validation bottleneck suppresses unchecked error propagation\. However, their metricAe=EMAS/ESASA\_\{e\}=E\_\{\\mathrm\{MAS\}\}/E\_\{\\mathrm\{SAS\}\}is an aggregate empirical ratio across heterogeneous tasks and architectures, not a direct plug\-in instance of the theorem’sP\(failure\)/pP\(\\mathrm\{failure\}\)/pmodel for fixed\(n,p,d\)\(n,p,d\)\. The reported values therefore support the orderingA⊗≫A∘A\_\{\\otimes\}\\gg A\_\{\\circ\}, but they should not be read as literal estimates ofddornnin Eqs\. \([22](https://arxiv.org/html/2607.04240#S7.E22)\)–\([23](https://arxiv.org/html/2607.04240#S7.E23)\)\.
##### Worked Agent Example \(Code Review Gate\)\.
Suppose three code\-generation workers each draft part of a deployment change, and a release gate accepts the merged result\. If each worker has error ratep=0\.1p=0\.1, an ungated independent aggregate fails with probability1−\(1−0\.1\)3=0\.2711\-\(1\-0\.1\)^\{3\}=0\.271, soA⊗=2\.71A\_\{\\otimes\}=2\.71\. If a central reviewer catches half of all worker errors \(d=0\.5d=0\.5\), then the centralized failure rate becomes1−\(1−0\.1\(1−0\.5\)\)3≈0\.1431\-\(1\-0\.1\(1\-0\.5\)\)^\{3\}\\approx 0\.143, soA∘≈1\.43A\_\{\\circ\}\\approx 1\.43\. The reviewer does not eliminate risk, but it roughly halves amplification\.
###### Theorem 5\(Sequential Coordination Penalty\)\.
For a task withkkstrictly ordered steps decomposed acrossnnagents, each inter\-agent handoff must at minimum establishKreceiver\(resultj\)K\_\{\\mathrm\{receiver\}\}\(\\mathrm\{result\}\_\{j\}\)\. The overhead is:
1. \(a\)Single agent:Ki\(resultj\)K\_\{i\}\(\\mathrm\{result\}\_\{j\}\)is trivially satisfied \(the agent computed it\)\. Total cost=k⋅cstep=k\\cdot c\_\{\\mathrm\{step\}\}\.
2. \(b\)Multi\-agent:Each ofh≤k−1h\\leq k\-1handoffs incurs communication costccommc\_\{\\mathrm\{comm\}\}andepistemic reconstruction loss: ΔIj=I\(Ssender;rj\)−I\(obsreceiver\(Ssender\);rj\)\\Delta I\_\{j\}=I\(S\_\{\\mathrm\{sender\}\};r\_\{j\}\)\-I\(\\mathrm\{obs\}\_\{\\mathrm\{receiver\}\}\(S\_\{\\mathrm\{sender\}\}\);r\_\{j\}\)\(24\)which is nonnegative by data processing, and is strictly positive whenever the handoff map is lossy on the task\-relevant support\.
##### Assumptions\.
The task is strictly sequential, so later steps depend on earlier results; each handoff transmits only a summary of the sender’s relevant state; and the receiver must reconstruct enough of that state to continue execution\.
##### Operational takeaway\.
For agent designers, this is the warning against gratuitous decomposition: a sequential pipeline only benefits from multiple agents if a handoff creates new observations or new capabilities\. Otherwise the system just pays communication cost plus lossy\-summary cost\.
###### Proof sketch\.
Part \(a\)\.A single agent executing allkksteps maintains coalgebraic stateS=\(L,ℛ\)S=\(L,\\mathcal\{R\}\)throughout\. After computing stepjj, the resultrjr\_\{j\}is stored in that agent’s own local state / readout, so no inter\-agent communication is required to reuse it at stepj\+1j\+1\. HenceKi\(rj\)K\_\{i\}\(r\_\{j\}\)holds without handoff cost\. The total cost is exactlyk⋅cstepk\\cdot c\_\{\\mathrm\{step\}\}\.
Part \(b\)\.When stepjjis performed by agentaaand stepj\+1j\+1by agentbb, establishingKb\(rj\)K\_\{b\}\(r\_\{j\}\)requires transmitting enough information aboutrjr\_\{j\}across a wirew:a→bw:a\\to b\. The receiver’s observation isobsb\(s\)=opticw\(πw\(s\)\)\\mathrm\{obs\}\_\{b\}\(s\)=\\mathrm\{optic\}\_\{w\}\(\\pi\_\{w\}\(s\)\), which maps the sender’s full state through the wire’s optic\. By the data processing inequality applied to the Markov chainSa→obsb\(Sa\)→r^jS\_\{a\}\\to\\mathrm\{obs\}\_\{b\}\(S\_\{a\}\)\\to\\hat\{r\}\_\{j\}\(wherer^j\\hat\{r\}\_\{j\}is the receiver’s reconstruction\):
I\(obsb\(Sa\);rj\)≤I\(Sa;rj\)=H\(rj\)I\(\\mathrm\{obs\}\_\{b\}\(S\_\{a\}\);r\_\{j\}\)\\leq I\(S\_\{a\};r\_\{j\}\)=H\(r\_\{j\}\)with equality iff the wire is lossless for the task\-relevant signal \(opticw∘πw\\mathrm\{optic\}\_\{w\}\\circ\\pi\_\{w\}is a sufficient statistic forrjr\_\{j\}on the relevant support\)\. ThereforeΔIj≥0\\Delta I\_\{j\}\\geq 0, with strict inequality whenever the handoff is lossy\. Finite context windows make such lossy handoffs typical, though not logically unavoidable\.
Each ofhhhandoffs incurs: \(i\) communication costccommc\_\{\\mathrm\{comm\}\}for message construction and parsing, and \(ii\) reconstruction costcrecon,jc\_\{\\mathrm\{recon\},j\}proportional toΔIj\\Delta I\_\{j\}, as the receiver must expend reasoning tokens to compensate for the missing context\. The total multi\-agent cost is:
Cmulti=k⋅cstep\+∑j=1h\(ccomm\+crecon,j\)C\_\{\\mathrm\{multi\}\}=k\\cdot c\_\{\\mathrm\{step\}\}\+\\sum\_\{j=1\}^\{h\}\\bigl\(c\_\{\\mathrm\{comm\}\}\+c\_\{\\mathrm\{recon\},j\}\\bigr\)The overhead ratio\(Cmulti−Csingle\)/Csingle=∑j\(ccomm\+crecon,j\)/\(k⋅cstep\)\(C\_\{\\mathrm\{multi\}\}\-C\_\{\\mathrm\{single\}\}\)/C\_\{\\mathrm\{single\}\}=\\sum\_\{j\}\(c\_\{\\mathrm\{comm\}\}\+c\_\{\\mathrm\{recon\},j\}\)/\(k\\cdot c\_\{\\mathrm\{step\}\}\)grows withhhand with the typical per\-handoff information lossΔIj\\Delta I\_\{j\}\. When lossy handoffs accumulate, reconstruction failures at stepjjdegrade the input quality for stepj\+1j\+1, so later handoffs operate on progressively more compressed representations and can exhibit superadditive degradation\. ∎
##### Consistency Check\.
Kim et al\.\[[24](https://arxiv.org/html/2607.04240#bib.bib27)\]report that PlanCraft degrades under every multi\-agent topology, from−39\.1%\-39\.1\\%\(Hybrid\) to−70\.1%\-70\.1\\%\(Independent\) relative to SAS, and attribute this to artificial decomposition of a strictly sequential task into redundant coordination steps\. This is qualitatively consistent with the theorem: when handoffs add communication and reconstruction without creating new task\-relevant observations, manufacturedKreceiverK\_\{\\mathrm\{receiver\}\}is pure cost\. The paper does not separately estimateccomm/cstepc\_\{\\mathrm\{comm\}\}/c\_\{\\mathrm\{step\}\}orΔIj\\Delta I\_\{j\}, so these quantities should be read as explanatory variables rather than fitted benchmark parameters\.
##### Worked Agent Example \(Bug\-Fix Relay\)\.
Consider a three\-step bug\-fix task: interpret the failing test, locate the root cause, and write the patch\. A single coding agent pays3cstep3c\_\{\\mathrm\{step\}\}\. If the task is split across planner/debugger/patcher withh=2h=2handoffs,cstep=100c\_\{\\mathrm\{step\}\}=100tokens,ccomm=25c\_\{\\mathrm\{comm\}\}=25, and reconstruction costcrecon=20c\_\{\\mathrm\{recon\}\}=20per handoff, thenCsingle=300C\_\{\\mathrm\{single\}\}=300whileCmulti=3⋅100\+2⋅\(25\+20\)=390C\_\{\\mathrm\{multi\}\}=3\\cdot 100\+2\\cdot\(25\+20\)=390\. Unless one specialist contributes genuinely new observations or capabilities, the decomposition is net overhead\.
###### Theorem 6\(Parallel Acceleration under Epistemic Independence\)\.
A task decomposes intommsubtasks\. Define two subtasks asepistemically independentiff neither’s solution requires knowledge of the other’s result:¬\(Ki\(φj\)is a precondition for solving subtaski\)\\neg\(K\_\{i\}\(\\varphi\_\{j\}\)\\text\{ is a precondition for solving subtask \}i\)\.
1. \(a\)Under full epistemic independence with centralized coordination, the speedup is: S=∑i=1mcsubimaxi\(csubi\)\+cassign\+caggS=\\frac\{\\sum\_\{i=1\}^\{m\}c\_\{\\mathrm\{sub\}\_\{i\}\}\}\{\\max\_\{i\}\(c\_\{\\mathrm\{sub\}\_\{i\}\}\)\+c\_\{\\mathrm\{assign\}\}\+c\_\{\\mathrm\{agg\}\}\}\(25\)wherecassignc\_\{\\mathrm\{assign\}\}is the coordinator’s distribution cost andcaggc\_\{\\mathrm\{agg\}\}is aggregation cost\. With equal subtasks,S≈mS\\approx mminus coordinator overhead\.
2. \(b\)For propositions determined solely by the tuple of worker outputs, the coordinator attains the corresponding pooled\-output knowledge at aggregation as an architectural byproduct—it must receive all outputs to combine them\. Error detection \(Theorem[4](https://arxiv.org/html/2607.04240#Thmtheorem4)\) comes free\.
3. \(c\)Epistemic ceiling:If subtasks have unresolved dependencies—I\(φi;φj∣obsi\)\>0I\(\\varphi\_\{i\};\\varphi\_\{j\}\\mid\\mathrm\{obs\}\_\{i\}\)\>0, meaning agentii’s observations do not screen off the dependence onφj\\varphi\_\{j\}—then parallel execution can sacrifice solution quality whenever the dependence is action\-relevant: there exist statess,s′s,s^\{\\prime\}withobsi\(s\)=obsi\(s′\)\\mathrm\{obs\}\_\{i\}\(s\)=\\mathrm\{obs\}\_\{i\}\(s^\{\\prime\}\)butfi∗\(s\)≠fi∗\(s′\)f\_\{i\}^\{\*\}\(s\)\\neq f\_\{i\}^\{\*\}\(s^\{\\prime\}\)due to differingφj\\varphi\_\{j\}\.
##### Assumptions\.
Subtasks can be assigned independently, the coordinator’s assignment and aggregation costs are additive overhead terms, and no hidden blocking dependency forces a worker to wait for another worker’s intermediate result\.
##### Operational takeaway\.
This is the positive case for multi\-agent systems: if subtasks can be solved from local observations alone, then specialization plus a coordinator can reduce wall\-clock cost and often improve quality\. If subtasks share unresolved dependencies, parallelism turns into premature decomposition\.
###### Proof sketch\.
Part \(a\)\.Let subtasksφ1,…,φm\\varphi\_\{1\},\\ldots,\\varphi\_\{m\}be epistemically independent: for alli≠ji\\neq j, agentiican achieveKi\(φi\)K\_\{i\}\(\\varphi\_\{i\}\)fromobsi\\mathrm\{obs\}\_\{i\}alone without requiringKi\(φj\)K\_\{i\}\(\\varphi\_\{j\}\)\. Formally, letfi∗f\_\{i\}^\{\*\}denote the optimal solution function for subtaskii\. Epistemic independence meansfi∗f\_\{i\}^\{\*\}depends only on the initial task description and agentii’s local observations:fi∗\(s\)=fi∗\(obsi\(s\)\)f\_\{i\}^\{\*\}\(s\)=f\_\{i\}^\{\*\}\(\\mathrm\{obs\}\_\{i\}\(s\)\)for all global statesss\.
Under parallel execution, allmmsubtasks run concurrently\. The wall\-clock cost is determined by the slowest subtask plus coordination overhead:Cparallel=maxi\(csubi\)\+cassign\+caggC\_\{\\mathrm\{parallel\}\}=\\max\_\{i\}\(c\_\{\\mathrm\{sub\}\_\{i\}\}\)\+c\_\{\\mathrm\{assign\}\}\+c\_\{\\mathrm\{agg\}\}\. Sequential execution by a single agent costsCsequential=∑i=1mcsubiC\_\{\\mathrm\{sequential\}\}=\\sum\_\{i=1\}^\{m\}c\_\{\\mathrm\{sub\}\_\{i\}\}\. The speedupS=Csequential/CparallelS=C\_\{\\mathrm\{sequential\}\}/C\_\{\\mathrm\{parallel\}\}yields the stated formula\. With equal subtask costs,Csequential=m⋅csubC\_\{\\mathrm\{sequential\}\}=m\\cdot c\_\{\\mathrm\{sub\}\}andCparallel=csub\+cassign\+caggC\_\{\\mathrm\{parallel\}\}=c\_\{\\mathrm\{sub\}\}\+c\_\{\\mathrm\{assign\}\}\+c\_\{\\mathrm\{agg\}\}, soS=m⋅csub/\(csub\+cassign\+cagg\)≈mS=m\\cdot c\_\{\\mathrm\{sub\}\}/\(c\_\{\\mathrm\{sub\}\}\+c\_\{\\mathrm\{assign\}\}\+c\_\{\\mathrm\{agg\}\}\)\\approx mwhen coordinator overhead is small relative to subtask cost\.
Part \(b\)\.The coordinator receives allmmoutputs\(o1,…,om\)\(o\_\{1\},\\ldots,o\_\{m\}\)as part of the aggregation step\. Assume each worker’s relevant local observation for aggregation is its own resultojo\_\{j\}\. Then the pooled worker\-output partition is generated by the tuple\(o1,…,om\)\(o\_\{1\},\\ldots,o\_\{m\}\), and the hub observes that tuple directly:obshub\(s\)⊇\(o1,…,om\)\\mathrm\{obs\}\_\{\\mathrm\{hub\}\}\(s\)\\supseteq\(o\_\{1\},\\ldots,o\_\{m\}\)\. Therefore for any propositionφ\\varphimeasurable with respect to the worker\-output tuple,DG\(φ\)⇒Khub\(φ\)D\_\{G\}\(\\varphi\)\\Rightarrow K\_\{\\mathrm\{hub\}\}\(\\varphi\)\. Error detection from Theorem[4](https://arxiv.org/html/2607.04240#Thmtheorem4)\(b\) follows because the hub can cross\-check outputs at no additional communication cost\.
Part \(c\)\.The assumptionI\(φi;φj∣obsi\)\>0I\(\\varphi\_\{i\};\\varphi\_\{j\}\\mid\\mathrm\{obs\}\_\{i\}\)\>0means agentii’s observations do not fully resolve the dependence onφj\\varphi\_\{j\}: there exist global statess,s′s,s^\{\\prime\}withobsi\(s\)=obsi\(s′\)\\mathrm\{obs\}\_\{i\}\(s\)=\\mathrm\{obs\}\_\{i\}\(s^\{\\prime\}\)that differ inφj\\varphi\_\{j\}\. When this dependence is action\-relevant—that is, the optimal actionfi∗\(s\)≠fi∗\(s′\)f\_\{i\}^\{\*\}\(s\)\\neq f\_\{i\}^\{\*\}\(s^\{\\prime\}\)—agentiimust choose a single action for both under independent execution, so it is suboptimal in at least one case\. The expected quality loss is strictly positive whenever such action\-relevant indistinguishable states have nonzero probability\. ∎
##### Consistency Check\.
Kim et al\.’s Finance\-Agent traces show at least three largely separable workstreams—regulatory/news analysis, SEC filing research, and operational\-impact assessment—handled by three sub\-agents plus an orchestrator\[[24](https://arxiv.org/html/2607.04240#bib.bib27)\]\. Centralized MAS improves benchmark success from0\.3490\.349to0\.6310\.631\(\+80\.8%\+80\.8\\%\), which is qualitatively consistent with the theorem’s decomposable\-task regime\. But the reported\+80\.8%\+80\.8\\%is a success\-rate improvement, not a direct measurement of the speedupSSin Eq\. \([25](https://arxiv.org/html/2607.04240#S7.E25)\); it should therefore be interpreted as evidence that approximate epistemic independence can improve solution quality, not as a literal estimate of wall\-clock acceleration\.
##### Worked Agent Example \(Due\-Diligence Swarm\)\.
Suppose an orchestrator assigns three largely independent subtasks for a vendor assessment: legal review, security posture, and cost modeling\. If each subtask costs about88minutes of agent time and assignment plus aggregation costs22minutes total, then
S=8\+8\+88\+2=2\.4\.S=\\frac\{8\+8\+8\}\{8\+2\}=2\.4\.The coordinator also receives all three outputs at aggregation, so cross\-checking across the workstreams comes with little extra communication cost\.
###### Theorem 7\(Tool Density Scaling\)\.
Considertttools distributed acrossnnagents, with\|Ti\|=t/n\|T\_\{i\}\|=t/ntools per agent \(balanced partition\)\.
1. \(a\)Single agent:The agent’s observation partition over tool outputs is unified\. Planning cost isO\(t\)O\(t\)per step \(linear scan of tool descriptions in context\)\.
2. \(b\)Multi\-agent:When agentiineeds a tool inTjT\_\{j\}\(j≠ij\\neq i\), it must first know the tool exists \(Ki\(Tj∋toolk\)K\_\{i\}\(T\_\{j\}\\ni\\mathrm\{tool\}\_\{k\}\)\), then request execution, then interpret the result with information lossΔI\\Delta I\(Eq\. \([24](https://arxiv.org/html/2607.04240#S7.E24)\)\)\. The coordination overhead per step scales as: Ccoord=O\(t⋅\(1−\|Ti∩Tneeded\|\|Tneeded\|\)⋅ccomm\)C\_\{\\mathrm\{coord\}\}=O\\\!\\left\(t\\cdot\\left\(1\-\\frac\{\|T\_\{i\}\\cap T\_\{\\mathrm\{needed\}\}\|\}\{\|T\_\{\\mathrm\{needed\}\}\|\}\\right\)\\cdot c\_\{\\mathrm\{comm\}\}\\right\)\(26\)which approachesO\(t⋅ccomm\)O\(t\\cdot c\_\{\\mathrm\{comm\}\}\)asttgrows for any fixed partition\.
3. \(c\)Cross\-agent planning overhead:Agentiimust reason about remote tool capabilities—Ki\(Kj\(toolkcan solve subproblem\)\)K\_\{i\}\(K\_\{j\}\(\\mathrm\{tool\}\_\{k\}\\text\{ can solve subproblem\}\)\)—a second\-order epistemic query\.*Absent a shared capability index*, matching each of thetttools against thennagents that might hold it is an all\-pairs scan: Cplan=O\(t⋅n\)≫O\(t\)\(decentralized discovery; worst case\)C\_\{\\mathrm\{plan\}\}=O\(t\\cdot n\)\\gg O\(t\)\\quad\\text\{\(decentralized discovery; worst case\)\}\(27\)a multiplicativenn\-factor over the single\-agent baseline\. This factor is an artifact of the discovery model, not an intrinsic epistemic cost: a maintained capability directory reduces the per\-tool lookup toO\(1\)O\(1\)and collapses the bound back toO\(t\)O\(t\), at the price of maintaining the directory\. Thenn\-factor is thus the penalty a system pays specifically for*decentralized*tool discovery\.
##### Assumptions\.
Tools are partitioned approximately evenly across agents, remote tool use requires explicit discovery and delegation, and—for the worst\-caseO\(t⋅n\)O\(t\\cdot n\)term—there is no shared capability index, so the planner reasons over every tool–agent pairing relevant to the current subgoal\. A maintained directory removes thatnn\-factor, leavingO\(t\)O\(t\)\.
##### Operational takeaway\.
For agentic tool systems, splitting a toolset across agents changes one local decision into three coordination steps: discover who has the tool, delegate execution, then interpret the returned result without the executor’s full context\. That is why tool\-heavy tasks often punish over\-distribution\.
###### Proof sketch\.
Part \(a\)\.A single agent holds alltttools in its context\. Its observation functionobs\(s\)=\(o1\(s\),…,ot\(s\)\)\\mathrm\{obs\}\(s\)=\(o\_\{1\}\(s\),\\ldots,o\_\{t\}\(s\)\)covers all tool outputs\. At each planning step, the agent selects the next tool by scanning descriptions in context\. This is a linear search overttcandidates: each tool description must be evaluated against the current subgoal, yieldingO\(t\)O\(t\)planning cost per step\.
Part \(b\)\.Withnnagents and a balanced partitionT1,…,TnT\_\{1\},\\ldots,T\_\{n\}where\|Ti\|=t/n\|T\_\{i\}\|=t/n, agentii’s observation function covers onlyTiT\_\{i\}’s outputs:obsi\(s\)=\(ok\(s\)\)k∈Ti\\mathrm\{obs\}\_\{i\}\(s\)=\(o\_\{k\}\(s\)\)\_\{k\\in T\_\{i\}\}\. When agentiineeds toolk∈Tjk\\in T\_\{j\}\(j≠ij\\neq i\), three epistemic gaps must be bridged:
1. 1\.Discovery:Agentiimust establishKi\(∃k∈Tj:ksolves subproblem\)K\_\{i\}\(\\exists k\\in T\_\{j\}:k\\text\{ solves subproblem\}\)\. Sincek∉Tik\\notin T\_\{i\}, this requires communication—agentiicannot determine toolkk’s existence fromobsi\\mathrm\{obs\}\_\{i\}alone\. There exist global statess,s′s,s^\{\\prime\}whereobsi\(s\)=obsi\(s′\)\\mathrm\{obs\}\_\{i\}\(s\)=\\mathrm\{obs\}\_\{i\}\(s^\{\\prime\}\)butTjT\_\{j\}differs, sos∼is′s\\sim\_\{i\}s^\{\\prime\}yet the available remote tools are different\.
2. 2\.Delegation:Agentiimust transmit the subproblem context to agentjjand receive the result, incurring communication costccommc\_\{\\mathrm\{comm\}\}per remote tool invocation\.
3. 3\.Reconstruction:Agentjj’s outputoko\_\{k\}is interpreted byiiwithoutjj’s full execution context\. By the data processing inequality,I\(subproblem;ok\|received\)≤I\(subproblem;ok\|fullcontext\)I\(\\text\{subproblem\};o\_\{k\}\|\_\{\\mathrm\{received\}\}\)\\leq I\(\\text\{subproblem\};o\_\{k\}\|\_\{\\mathrm\{fullcontext\}\}\), yielding information lossΔI≥0\\Delta I\\geq 0\.
The fraction of tools requiring remote access is1−\|Ti∩Tneeded\|/\|Tneeded\|1\-\|T\_\{i\}\\cap T\_\{\\mathrm\{needed\}\}\|/\|T\_\{\\mathrm\{needed\}\}\|\. For each remote tool, the coordination cost isccommc\_\{\\mathrm\{comm\}\}\. Over allttpotentially needed tools, the total coordination overhead is:
Ccoord=t⋅\(1−\|Ti∩Tneeded\|\|Tneeded\|\)⋅ccomm\.C\_\{\\mathrm\{coord\}\}=t\\cdot\\left\(1\-\\frac\{\|T\_\{i\}\\cap T\_\{\\mathrm\{needed\}\}\|\}\{\|T\_\{\\mathrm\{needed\}\}\|\}\\right\)\\cdot c\_\{\\mathrm\{comm\}\}\.Asttgrows with fixednnand balanced partitions, the local coverage fraction\|Ti\|/t=1/n\|T\_\{i\}\|/t=1/nis constant, so the remote fraction approaches\(n−1\)/n\(n\-1\)/nandCcoord→O\(t⋅ccomm\)C\_\{\\mathrm\{coord\}\}\\to O\(t\\cdot c\_\{\\mathrm\{comm\}\}\)\.
Part \(c\)\.Planning requires not just first\-order knowledge of tool outputs but second\-order knowledge of other agents’ capabilities\. Specifically, to construct a multi\-step plan, agentiimust evaluate propositions of the formKi\(Kj\(toolkcan solve subproblemφ\)\)K\_\{i\}\(K\_\{j\}\(\\mathrm\{tool\}\_\{k\}\\text\{ can solve subproblem \}\\varphi\)\)—“I know that agentjjknows that toolkkis applicable\.”
Consider the Kripke structure\. For agentiito establishKi\(Kj\(φ\)\)K\_\{i\}\(K\_\{j\}\(\\varphi\)\), we need: for alls′s^\{\\prime\}withs∼is′s\\sim\_\{i\}s^\{\\prime\}, and for alls′′s^\{\\prime\\prime\}withs′∼js′′s^\{\\prime\}\\sim\_\{j\}s^\{\\prime\\prime\},φ\\varphiholds ats′′s^\{\\prime\\prime\}\. Agentiimust reason overjj’s indistinguishability classes, which requires a model ofjj’s observation partition\. This model has sizeO\(\|Tj\|\)=O\(t/n\)O\(\|T\_\{j\}\|\)=O\(t/n\)per agent\. Sinceiimust model alln−1n\-1remote agents, the total planning state isO\(\(n−1\)⋅t/n\)=O\(t\)O\(\(n\-1\)\\cdot t/n\)=O\(t\)per planning step\. The residual cost is capability matching: absent a shared directory, determining which of thennagents holds each of thetttools is an all\-pairs scan,O\(t⋅n\)O\(t\\cdot n\)comparisons in the worst case; a maintained capability index reduces this to anO\(1\)O\(1\)per\-tool lookup, henceO\(t\)O\(t\)overall\.
Contrast with the single\-agent case: planning cost isO\(t\)O\(t\)\(linear scan, no modeling of other agents’ capabilities\)\. Decentralized discovery introduces the multiplicativenn\-factor, givingCplan=O\(t⋅n\)C\_\{\\mathrm\{plan\}\}=O\(t\\cdot n\)in the worst case; with a shared capability index it isO\(t\)O\(t\), larger only by the constant from the second\-order reasoning\. Either way, distributing tools converts a local lookup into a discovery\-plus\-delegation problem, which is why increasing tool density in multi\-agent systems can produce disproportionate overhead that may negate parallelism benefits\. ∎
##### Consistency Check\.
In Kim et al\.’s setup, the tool\-heavy Workbench domain usesT=16T=16tools and most MAS configurations usen=3n=3agents\[[24](https://arxiv.org/html/2607.04240#bib.bib27)\]\. Under a balanced partition, each agent directly holds only aboutT/n≈5T/n\\approx 5tools, so roughly two\-thirds of tool access is remote\. The second\-order planning term therefore scales fromO\(16\)O\(16\)in SAS to roughlyO\(48\)O\(48\)cross\-agent capability checks in the balanced three\-agent case\. Kim et al\. report a strong negative efficiency–tool interaction \(β^Ec×T=−0\.267\\hat\{\\beta\}\_\{E\_\{c\}\\times T\}=\-0\.267,p<0\.001p<0\.001\), which is consistent with this combinatorial tax\. Their results also show that the penalty is topology\-dependent rather than absolute: Centralized and Hybrid underperform on Workbench, while Decentralized remains slightly above SAS \(\+5\.7%\+5\.7\\%\), so high tool count stresses coordination but does not universally eliminate multi\-agent value\. In the low\-tool regime discussed in the paper \(T≤4T\\leq 4\), the efficiency interaction is negligible\.
##### Worked Agent Example \(Tool\-Split SWE Agent\)\.
Imagine a software\-engineering assistant with1818tools split across33agents: one owns search tools, one owns git and test tools, and one owns deployment tools\. A planner diagnosing a failing CI job directly holds only66tools and must treat the remaining1212as remote\. The planning problem therefore expands from “which of1818tools should I call next?” to “which agent owns the relevant tool, how do I route the subproblem, and how do I interpret the result without that agent’s full execution context?” That is theO\(tn\)O\(tn\)tax in operational form\.
##### Summary: Consistency with Known Design Intuitions\.
Table[3](https://arxiv.org/html/2607.04240#S7.T3)summarizes the qualitative correspondence between the theoretical predictions and Kim et al\.’s empirical findings across 180 agent configurations\[[24](https://arxiv.org/html/2607.04240#bib.bib27)\]\.
Table 3:Epistemic predictions vs\. empirical observations from Kim et al\.\[[24](https://arxiv.org/html/2607.04240#bib.bib27)\]\. The table compares topology\-level qualitative predictions to the paper’s architecture\-level metrics\. Reported percentages and error\-amplification factors are empirical aggregates, not literal plug\-in values of the simplified theorem parameters\. The correspondence formalizes known design intuitions rather than providing independent empirical validation\.Design Implications for Agent Architects\.1\.Use a reviewer or hub when multiple workers can independently introduce high\-cost errors\. The gain comes from visibility and suppression, not from agent count alone\.2\.Keep strictly sequential reasoning in one agent unless a handoff adds a genuinely new capability, observation source, or trust level\.3\.Use specialist swarms for decomposable tasks only when coordinator overhead is small relative to subtask cost and the subtasks are close to conditionally independent\.4\.Avoid fragmenting large toolsets across many agents unless tool routing is a first\-class design problem\. Otherwise, remote\-tool discovery and second\-order planning will dominate\.5\.Treat topology as a runtime policy, not a fixed ideology\. When observed task structure shifts from sequential to parallel or from low\-risk to high\-risk, the coordination pattern should shift with it\.
### 7\.3Epistemic Dynamics and Adaptive Topology
The preceding theorems treat topology as fixed\. In practice, the Operon framework supportsdynamic topology switching—morphogen gradients \(Eq\. \([20](https://arxiv.org/html/2607.04240#S6.E20)\)\) can trigger reorganization at runtime\. We connect this to the epistemic formalization\.
The Epiplexity monitor \(ℰ^t\\hat\{\\mathcal\{E\}\}\_\{t\}, Eq\. \([17](https://arxiv.org/html/2607.04240#S5.E17)\)\) can be reinterpreted as a heuristic proxy for*finite\-horizon*epistemic stagnation\. Define
Stagnanti\(h\)\(φ\):=¬Ki\(φ\)∧¬◇≤hKi\(φ\)\\mathrm\{Stagnant\}\_\{i\}^\{\(h\)\}\(\\varphi\):=\\neg K\_\{i\}\(\\varphi\)\\wedge\\neg\\Diamond\_\{\\leq h\}K\_\{i\}\(\\varphi\)\(28\)where◇≤h\\Diamond\_\{\\leq h\}means “reachable withinhhcoordination rounds under the current topology\.” Low epiplexity does not*prove*this modal condition, but it provides an operational signal that the current wiring is failing to generate new task\-relevant observations\. This is precisely the regime in which topology switching is warranted: the current wiring diagram’s epistemic capacity is insufficient for the task\.
Morphogen\-driven adaptation then becomesepistemic optimization: the system senses when its topology’s knowledge properties are mismatched to the task and restructures accordingly\. An independent topology \(⊗\\otimes\) failing on a sequential task triggers convergence to centralized coordination \(∘\\circ\); a centralized topology bottlenecking on a parallelizable task triggers distribution to independent execution\. This is the adaptive capability that purely empirical approaches\[[24](https://arxiv.org/html/2607.04240#bib.bib27)\]identify as necessary but cannot yet provide—biological systems have evolved it as homeostatic regulation; the Operon framework operationalizes it through the morphogen\-epiplexity coupling\.
Recent work on unifying epistemic and temporal logic for distributed system verification suggests that these dynamic epistemic properties may be mechanically verifiable, opening a path toward formally certified adaptive agent topologies\.
## 8Discussion: Towards “Epigenetic” Software
The correspondence developed in this paper extends beyond the immediate execution of tasks \(Gene Expression\) to the management of long\-term behavior and state\. In biology, the DNA sequence is static; a neuron and a liver cell possess the exact same genetic code\. Their distinct behaviors are determined by Epigenetics—chemical markers \(like methylation\) that restrict access to certain parts of the genome, effectively biasing the system toward specific outcomes\.
### 8\.1RAG as Digital Methylation
In Agentic Systems, the Large Language Model \(LLM\) weights act as the DNA—a static, pre\-trained substrate of potentiality\. To create specialized agents, we do not typically retrain the model \(mutation\); instead, we use Retrieval Augmented Generation \(RAG\) and System Prompts\.
We define this formally as Phenotypic Plasticity\. The output of an agent is not solely a function of its weights \(WW\) and the user query \(QQ\), but of its epigenetic state \(EE\):
Oagent=f\(W,E,Q\)\.O\_\{\\text\{agent\}\}=f\(W,E,Q\)\.\(29\)
Context injection \(RAG\) acts as a restrictive morphism\. By populating the context window with specific documents \(e\.g\., “SQL Syntax Guide”\), we effectively “methylate” \(silence\) the vast majority of the LLM’s general knowledge \(e\.g\., poetry, history\) to force the expression of a specific “SQL Agent” phenotype\.
This suggests that the State Monad for an agentic system should not merely be a log of messages, but a structured Epigenetic Landscape\[[43](https://arxiv.org/html/2607.04240#bib.bib19)\]that strictly controls which “genes” \(capabilities\) are accessible at any given step in the workflow\. Waddington’s original metaphor—a ball rolling down a landscape of valleys representing developmental fates—applies directly: the agent’s trajectory through solution space is channeled by the contours of its RAG context\.
#### 8\.1\.1Metabolic\-Epigenetic Coupling
Recent evidence suggests that chromatin accessibility is coupled to mitochondrial function via metabolite availability \(e\.g\., Acetyl\-CoA\)\[[12](https://arxiv.org/html/2607.04240#bib.bib17)\]\. The cell cannot express certain genes without sufficient metabolic substrate\. We map this toCost\-Gated Retrieval\. The accessibility of a RAG documentddis a function of the Metabolic Stateℛ\\mathcal\{R\}:
Access\(d\)=\{Openifℛ≥Cost\(d\)Silencedifℛ<Cost\(d\)Access\(d\)=\\begin\{cases\}\\text\{Open\}&\\text\{if \}\\mathcal\{R\}\\geq Cost\(d\)\\\\ \\text\{Silenced\}&\\text\{if \}\\mathcal\{R\}<Cost\(d\)\\end\{cases\}\(30\)Just as a cell silences energy\-intensive genes during starvation, the Runtime “methylates” \(hides\) expensive context when the token budget is low\. This creates an adaptive epigenetic landscape where the agent’s accessible capabilities dynamically contract and expand based on resource availability\. In the reference implementation,MarkerStrengthacts as a discrete proxy forCost\(d\)Cost\(d\)\(weak markers are cheapest to silence; permanent markers are hardest to silence\), and each retrieval also incurs a fixed ATP cost at theHistoneStoreboundary\. The equation above is therefore realized as a tiered approximation rather than a per\-document price model\.
### 8\.2Horizontal Gene Transfer: Dynamic Tool Loading
Standard evolution relies on vertical inheritance \(Pre\-training\)\. However, bacteria utilize Horizontal Gene Transfer \(HGT\) to acquire new capabilities \(Plasmids\) from the environment in real\-time\.
In Agentic Systems, we map Plasmids to Tool Schemas\. An agent operating in a novel environment may encounter a problem for which its “genomic” \(pre\-trained\) capabilities are insufficient\.
Agentnew=Agentold⊲ToolSchema,\\mathrm\{Agent\}\_\{\\text\{new\}\}=\\mathrm\{Agent\}\_\{\\text\{old\}\}\\triangleleft\\mathrm\{ToolSchema\},\(31\)where⊲\\triangleleftdenotes operadic substitution: the tool’s typed input/output ports are wired into the host’s interface, extending its position and direction sets\. This is deliberately*not*the monoidal product⊗\\otimesof §[4](https://arxiv.org/html/2607.04240#S4), which composes two boxes*without*information exchange—a horizontally transferred capability must connect to the host, not run alongside it in isolation\. By dynamically retrieving a tool definition \(e\.g\., a Calculator API or SQL Interface\) from a registry and injecting it into the Context Window, the agent undergoes a topological transformation, acquiring a new input/output modality instantly\.
##### Capability\-Gated Acquisition\.
The reference implementation provides aPlasmidRegistrywith optional capability gating\. Each Plasmid declares a set of required capabilitiesCp⊆𝒞C\_\{p\}\\subseteq\\mathcal\{C\}\. When an agent is instantiated with an allowed\-capability envelopeCaC\_\{a\}, it can only acquire the plasmid ifCp⊆CaC\_\{p\}\\subseteq C\_\{a\}:
acquire\(p,a\)=\{a⊲pifCp⊆Ca⊥insufficientotherwise\\mathrm\{acquire\}\(p,a\)=\\begin\{cases\}a\\triangleleft p&\\text\{if \}C\_\{p\}\\subseteq C\_\{a\}\\\\ \\bot\_\{\\text\{insufficient\}\}&\\text\{otherwise\}\\end\{cases\}\(32\)This prevents privilege escalation whenever a capability envelope is configured: an agent restricted to read\-only file access cannot acquire a tool requiring network capabilities\. Plasmid curing \(release\) removes the tool, restoring the original topology\.
### 8\.3The Cost of State
The metabolic constraint formalized in Section 3 applies directly: the agent graph should be compiled with a conservative upper bound on token consumption, and unguarded loops must require an explicit budget certificate\.
### 8\.4Endosymbiosis: The Neuro\-Symbolic Integration
The evolution of complex life was triggered by Endosymbiosis, where a host cell engulfed a bacterium \(the future Mitochondrion\), gaining the ability to generate massive energy \(ATP\) via aerobic respiration\. This represents the integration of two distinct metabolic substrates\.
In Agentic AI, this maps to the integration of Connectionist \(Neural\) and Symbolic \(Code\) subsystems\. An LLM acts as the host organism—capable of planning and semantic reasoning but energetically inefficient at arithmetic and logic\. By “engulfing” a deterministic runtime \(e\.g\., a Python REPL or Wolfram Engine\), the agent delegates high\-precision tasks to the symbolic organelle\.
AgentEukaryote=Tr\(LLMHost∘RuntimeMitochondria\),\\mathrm\{Agent\}\_\{\\text\{Eukaryote\}\}=\\mathrm\{Tr\}\\bigl\(\\mathrm\{LLM\}\_\{\\text\{Host\}\}\\circ\\mathrm\{Runtime\}\_\{\\text\{Mitochondria\}\}\\bigr\),\(33\)a*feedback composite*rather than a coproduct: the host feeds parsed variables to the runtime and consumes its deterministic results, so the two are wired in a loop \(a Trace over their serial composition, §[4](https://arxiv.org/html/2607.04240#S4)\), not offered as mutually exclusive alternatives \(⊕\\oplus\)\. Just as the host cell provides nutrients to the mitochondria in exchange for ATP, the LLM provides parsed variables to the runtime in exchange for deterministic truth\.
This symbiosis is computational: as Picard argues\[[37](https://arxiv.org/html/2607.04240#bib.bib14)\], the mitochondria acts as a “Motherboard,” integrating signals to determine cell state\. The Symbolic Runtime provides the deterministic “ground truth” \(ATP\) required for the probabilistic LLM to reliably affect the world\.
### 8\.5Temporal State in Agentic Systems
In the agentic setting, temporal state management is more than a storage concern\. An autonomous agent that corrects a past belief must distinguish between the world changing \(valid\-time update\) and the agent learning something new \(transaction\-time update\)\. Without this distinction, auditing a past decision becomes impossible: the agent cannot reconstruct what it believed at the time the decision was made\. The bi\-temporal model treats facts as append\-only records with dual timestamps, corrections as new records that close their predecessors, and point\-in\-time queries as intersections over the two time axes\.
### 8\.6Bioenergetic Intelligence: Beyond the Battery Metaphor
Recent work in mitochondrial psychobiology\[[3](https://arxiv.org/html/2607.04240#bib.bib15),[38](https://arxiv.org/html/2607.04240#bib.bib16)\]challenges the view of mitochondria as passive energy sources\. They function as “social signaling organelles” that actively participate in cellular decision\-making\. This refines our correspondence:
- •Mitochondrial Sociality→\\toContext Fusion:Just as mitochondria fuse to share resources under stress, resource\-constrained agents should implementContext Fusion—merging sparse Epigenetic States into a shared summary to survive “Token Ischemia\.”
- •Energy as Attention:The Agentic Runtime does not merely limit the chain\-of\-thought, but activelydirectsit\. High\-energy states permit “Exploratory” reasoning \(Divergent\), while low\-energy states force “Consolidatory” reasoning \(Convergent\)\. The Metabolic Coalgebra is aCognitive Control Policy\.
#### 8\.6\.1The Vermeij Trend: Why Agents Must Evolve
Finally, we situate this architecture within the broader history of complexity\. Geerat Vermeij\[[42](https://arxiv.org/html/2607.04240#bib.bib20)\]argues that evolution is driven by the maximization ofPower—the rate at which a system acquires and applies energy\. Life has consistently trended from low\-power states \(anaerobic bacteria\) to high\-power states \(endothermic mammals\) by internalizing energy production \(endosymbiosis\)\.
We observe an identical trend in AI\. The shift from “Generative AI” \(Zero\-Shot\) to “Agentic AI” \(Chain\-of\-Thought\) is a shift from low\-metabolism to high\-metabolism architectures\. However, Vermeij notes that high power requires high structural integrity; a system that amplifies energy without proper constraints self\-destructs\.
##### Note\.
The following evolutionary framing is offered as a conceptual lens, not as a tested empirical claim\. The biological parallel is suggestive rather than predictive\.
The Competitive Dynamics\.Vermeij’s argument is aboutescalation: competitive pressure between predators and prey drives both toward higher power\. What is the analogue in agentic AI?
We identify three sources of selective pressure:
1. 1\.Adversarial Robustness \(Predator\-Prey\):Prompt injection attacks, jailbreaks, and adversarial inputs act as “predators” that exploit agent vulnerabilities\. Agents that survive deployment develop “immune systems” \(the Adaptive Immunity motif\)\. This is a direct Red Queen dynamic: attackers evolve new injection techniques; defenders evolve new detection mechanisms\. The CFFL and Trust\-Gated Lens are “armor” adaptations\.
2. 2\.Task Complexity \(Environmental Pressure\):Users demand agents that can handle increasingly complex, multi\-step tasks\. Simple prompt\-response systems \(“anaerobic”\) cannot compete with agentic systems that chain reasoning, use tools, and maintain state \(“aerobic”\)\. This is analogous to the oxygen revolution: organisms that could exploit the new energy source \(aerobic respiration\) outcompeted those that could not\.
3. 3\.Resource Efficiency \(Metabolic Selection\):Token costs and latency create selection pressure for efficient architectures\. Agents that accomplish tasks with fewer tokens \(higher metabolic efficiency\) are deployed more widely\. The Metabolic Coalgebra provides the formal framework for this optimization: systems evolve toward the Pareto frontier of capability vs\. resource consumption\.
The Cambrian Parallel\.The progression from prompt engineering to agentic engineering may parallel aspects of the Cambrian explosion: a sudden increase in metabolic capability \(LLM reasoning power\) that enables new “body plans” \(agent architectures\)\. The Cambrian saw the emergence of eyes, shells, and predation—all requiring sophisticated metabolic support\. Similarly, agentic AI sees the emergence of tool use, planning, and adversarial robustness—all requiring the structural integrity that the Operon framework provides\.
If the analogy holds: agent architectures that lack proper metabolic regulation, immune defense, and homeostatic mechanisms may be outcompeted by those that possess them\. The Operon framework is not merely a safety feature; it may serve as an important structural adaptation—the “vascularization” of software—that enables high\-power cognition to function without collapsing into incoherent noise \(thermodynamic death\)\.
#### 8\.6\.2Immune Evasion and Adversarial Limits
No static defense is perfect against adaptive attackers\. Biology faces this reality: pathogens evolve to evade immune detection \(antigenic drift, molecular mimicry, immunosuppression\)\. The same dynamics apply to agentic security\.
Evasion Vectors\.An adversary who understands the defense layers can craft inputs that:
- •Pass innate filters by avoiding known PAMP signatures \(novel injection syntax\)
- •Evade provenance checks by exploiting trusted channels \(tool poisoning\)
- •Fool T\-cell detection by mimicking normal behavioral distributions \(low\-and\-slow attacks\)
Mitigation Strategies\.Biology’s answer is continuous adaptation:
- •Signature Updates:Innate PAMP databases must be continuously updated as new attack patterns are discovered \(analogous to antiviral signature updates\)\.
- •Thymic Retraining:Baseline behavioral profiles should be periodically refreshed, especially after system updates that legitimately change agent behavior\.
- •Immune Memory Sharing:Threat signatures discovered by one deployment should propagate to others \(analogous to herd immunity via shared threat intelligence\)\.
- •Diversity:Heterogeneous defenses \(different filter implementations, multiple verifier models\) reduce the probability of universal evasion\.
The honest conclusion is that security is a process, not a product\. The Operon framework provides thearchitecturefor defense\-in\-depth, but thecontentof that defense \(specific patterns, behavioral baselines, trust policies\) must evolve with the threat landscape\.
### 8\.7Harness Engineering as Architecture
Recent work in the LangChain ecosystem has converged on the concept of the*harness*—the system layer comprising prompts, tools, memory, and orchestration logic that surrounds the model\[[46](https://arxiv.org/html/2607.04240#bib.bib55)\]\. Zhou et al\. identify four pillars of agent externalization: Memory \(state across time\), Skills \(procedural expertise\), Protocols \(interaction structure\), and Harness Engineering \(the coordination layer\)\.
This four\-pillar framework maps directly onto Operon’s categorical Architecture triple\(G,Know,Φ\)\(G,\\mathrm\{Know\},\\Phi\)\(§[2\.3](https://arxiv.org/html/2607.04240#S2.SS3), after\[[13](https://arxiv.org/html/2607.04240#bib.bib45)\]\):
The key insight is that structural guarantees—CertificateGate, VerifierComponent, WatcherComponent—are*harness\-level properties*, not model\-level ones\. The LangGraph functor demonstrates this concretely: wrappingorganism\.run\(\)as a single LangGraph node transfers all structural guarantees because they reside in the harness, not in the model\. This is the operational meaning of ArchAgents’ certificate\-preservation result \(Proposition 5\.1 of\[[13](https://arxiv.org/html/2607.04240#bib.bib45)\]\), which we invoke operationally rather than reprove: architectural properties preserved under compilation are exactly those that the harness enforces independently of the model\.
Ma et al\.\[[29](https://arxiv.org/html/2607.04240#bib.bib56)\]provide corroborating evidence from a different angle: their five atomic coding skills \(localize, edit, test, reproduce, review\) compose without negative interference under joint training\. It is worth being precise about what our operad composition \(§[4](https://arxiv.org/html/2607.04240#S4)\) guarantees: serial and parallel composition preserve*typed and structural*properties—interface compatibility and certificate replay—by construction, but they do not guarantee that*behavioral*quality is preserved\. Indeed, our own composition benchmarks find mostly non\-interference but also a negative case \(a race\-condition task\)\[[9](https://arxiv.org/html/2607.04240#bib.bib53)\]\. Ma et al\.’s result is thus favorable empirical evidence that typed composition is a sound foundation, not a demonstration that composition can never degrade behavior\.
### 8\.8Boundary Conditions: When the Correspondence Earns Its Keep
The correspondence of §[3](https://arxiv.org/html/2607.04240#S3)licenses transporting biological design patterns to agent architectures, but it does not promise that every such pattern pays off\. Companion empirical work maps the boundary, and we state it plainly so the framework is not read as a universal claim\.
- •Structure, not optimization\.Biological abstractions generalize to the meta\-level as*code structure*—clean, composable interfaces—but not as*optimization algorithms*: in configuration\- and topology\-search experiments \(§[11](https://arxiv.org/html/2607.04240#S11)\), LLM\-guided and evolutionary search did not beat random tournament mutation\. The value is the organizing structure, not a better search\.
- •Guarantees are layered\.Structural guarantees that enforce invariants deliver*unconditionally*—state\-integrity checks recovered corrupted state in 100% of trials—while guarantees that depend on an information signal deliver only*conditionally*: epiplexity requires semantically meaningful embeddings, and injection detection is precise but low\-recall\[[9](https://arxiv.org/html/2607.04240#bib.bib53)\]\. A guarantee is only as strong as the layer it sits on\.
- •Certificates buy reliability, not speed\.On a task with enumerable failure modes, framing an evaluator as a binary certificate plus obligations did*not*converge faster than a graded scalar carrying the same evidence; its measured benefit was*variance reduction*, and the speed\-up hypothesis returned a null result\[[8](https://arxiv.org/html/2607.04240#bib.bib54)\]\. Certificates are a reliability construct, not an accelerant\.
- •Delegation needs new signal\.A single capable model often beats a multi\-stage pipeline in absolute quality; consistent with Ao et al\., delegation cannot beat a centralized baseline without genuinely exogenous information\[[9](https://arxiv.org/html/2607.04240#bib.bib53)\]\. Distribution earns its cost only when it supplies signal a single agent lacks\.
These are not caveats bolted on after the fact; they are the empirically established scope of the correspondence\. The structural and epistemic guarantees this monograph formalizes are precisely the parts that held up—which is why the contribution is disciplined structure, not a claim of universal biological superiority\.
The preceding discussion identifies structural and epistemic principles that guide agent architecture design\. In the next section, we show that the wiring diagrams themselves admit systematic optimization via categorical rewriting, making resource utilization a first\-class compositional concern\.
## 9Diagram Optimization via Categorical Rewriting
Cells do not merely execute metabolic pathways—they*optimize*them\. Flux Balance Analysis identifies rate\-limiting enzymes, allosteric regulation redirects flux through cheaper branches, and pathway rewiring eliminates dead\-end metabolites\. The result is not a different pathway, but a more efficient execution of the same input\-output behavior\. In this section we show that wiring diagrams admit analogous optimizations: cost annotations make resource consumption explicit, static analysis identifies structural opportunities, and rewriting rules transform diagrams while preserving observational equivalence\.
### 9\.1Cost\-Annotated Diagrams
We extend the WAgent operad \(Section 4\) with resource annotations\. Define a*resource cost*monoid\(ℝ≥03,\+,𝟎\)\(\\mathbb\{R\}\_\{\\geq 0\}^\{3\},\+,\\mathbf\{0\}\)where each element is a triple\(atp,latency,memory\)\(\\text\{atp\},\\text\{latency\},\\text\{memory\}\)\. A cost\-annotated wiring diagram enriches the category of wiring diagrams over this monoid: each modulemmcarries a costc\(m\)∈ℝ≥03c\(m\)\\in\\mathbb\{R\}\_\{\\geq 0\}^\{3\}, and each wirewwcarries a transmission costc\(w\)∈ℤ≥0c\(w\)\\in\\mathbb\{Z\}\_\{\\geq 0\}\(measured in ATP units\), embedded into the resource vector ascW↑\(w\)=\(c\(w\),0,0\)c\_\{W\}^\{\\uparrow\}\(w\)=\(c\(w\),0,0\)when added to path costs\.
###### Definition 9\(Cost\-Annotated Wiring Diagram\)\.
A*cost\-annotated wiring diagram*is a tuple\(M,W,cM,cW\)\(M,W,c\_\{M\},c\_\{W\}\)where:
- •MMis a finite set of modules, each with typed input/output ports;
- •W⊆\{\(ms\.ps,md\.pd\)∣ms,md∈M\}W\\subseteq\\\{\(m\_\{s\}\.p\_\{s\},m\_\{d\}\.p\_\{d\}\)\\mid m\_\{s\},m\_\{d\}\\in M\\\}is a set of wires;
- •cM:M→ℝ≥03c\_\{M\}:M\\to\\mathbb\{R\}\_\{\\geq 0\}^\{3\}assigns resource costs to modules;
- •cW:W→ℤ≥0c\_\{W\}:W\\to\\mathbb\{Z\}\_\{\\geq 0\}assigns transmission costs to wires\.
The*path cost*of a directed pathm1→w1m2→w2⋯→wn−1mnm\_\{1\}\\xrightarrow\{w\_\{1\}\}m\_\{2\}\\xrightarrow\{w\_\{2\}\}\\cdots\\xrightarrow\{w\_\{n\-1\}\}m\_\{n\}is∑i=1ncM\(mi\)\+∑i=1n−1cW↑\(wi\)\\sum\_\{i=1\}^\{n\}c\_\{M\}\(m\_\{i\}\)\+\\sum\_\{i=1\}^\{n\-1\}c\_\{W\}^\{\\uparrow\}\(w\_\{i\}\)\.
Biologically,cMc\_\{M\}corresponds to the ATP cost of enzyme catalysis, whilecWc\_\{W\}models the energetic cost of metabolite transport between cellular compartments\.
### 9\.2Rewriting Rules as Endofunctors
Each optimization pass is an endofunctorF:𝐖𝐃𝐢𝐚𝐠→𝐖𝐃𝐢𝐚𝐠F:\\mathbf\{WDiag\}\\to\\mathbf\{WDiag\}on the category of wiring diagrams that preserves input\-output behavior\. Two diagramsD1,D2D\_\{1\},D\_\{2\}are*behaviorally equivalent*if, for all admissible input assignments under the deterministic execution model fixed in Section[3\.5](https://arxiv.org/html/2607.04240#S3.SS5), they produce the same observable outputs\. In the current implementation this notion is checked over finite supplied input suites rather than by a general coinductive procedure\.
###### Theorem 8\(Optimization Soundness\)\.
LetFFbe an optimization pass\. IfFFonly removes wires that provably never transmit data \(dead wire elimination\) or reorders modules within the same topological layer*and those modules are pairwise observationally independent*\(equivalently: no shared writable state and no order\-sensitive side effects\), thenF\(D\)F\(D\)is behaviorally equivalent toDDfor all diagramsDD\.
##### Assumptions\.
Execution is deterministic under the fixed input schedule, dead wires are semantically impossible because their type/optic constraints can never accept runtime values, and reordered modules neither share writable state nor perform order\-sensitive side effects\.
###### Proof sketch\.
The theorem follows by checking the two rewrite primitives\.
For dead\-wire elimination, a removed wire can never transmit any value by hypothesis\. Therefore no execution trace ever uses that wire, so removing it leaves all downstream observations unchanged\.
For within\-layer reordering, observational independence means the reordered modules do not read or write shared mutable state and do not produce side effects whose meaning depends on order\. Hence swapping their execution order preserves each module’s local output as well as every downstream module’s observed inputs\. Since the graph is otherwise unchanged, the overall observable output is unchanged\.
Any implemented optimization pass is a composition of these local rewrites\. Because each local rewrite preserves observable behavior, the composite pass preserves observable behavior as well\. ∎
##### Operational takeaway\.
For agent\-systems readers, this is the compiler\-style rule: remove edges that can never fire, and only reorder steps that are truly independent\. Once modules share mutable memory or side effects, optimization becomes a semantic change rather than a free speedup\.
Three concrete passes are implemented:
1. 1\.Dead Wire Elimination\.A wire carrying a PrismOptic whose accepted types have no intersection with the source port’s DataType can never transmit\. Removing it does not change behavior\. This corresponds to pruning vestigial metabolic branches—enzymes that never encounter their substrate are downregulated\.
2. 2\.Parallel Grouping\.Modules with no mutual dependencies form a*parallel group*and can execute concurrently\. This is identified via topological layering of the dependency DAG, subject to the disjoint\-state assumption of parallel composition from Section 4\. Biologically, independent metabolic pathways \(e\.g\., glycolysis and fatty acid oxidation\) operate simultaneously in different cellular compartments\.
3. 3\.Cost\-Order Scheduling\.Within each parallel group, modules are sorted by ascending cost\. When the parallel group satisfies the same observational\-independence assumption, cheaper modules may execute first, allowing early termination or budget reallocation if expensive modules would exceed available ATP\. This mirrors cellular enzyme kinetics: low\-KmK\_\{m\}\(high\-affinity, low\-cost\) enzymes are preferentially activated\.
### 9\.3Critical Path Analysis
Because path costs are vector\-valued, critical\-path analysis requires a monotone scalarizationλ:ℝ≥03→ℝ≥0\\lambda:\\mathbb\{R\}\_\{\\geq 0\}^\{3\}\\to\\mathbb\{R\}\_\{\\geq 0\}\(for example, the latency projectionλ\(a,ℓ,m\)=ℓ\\lambda\(a,\\ell,m\)=\\ellfor wall\-clock analysis, or a weighted sum when ATP and latency are jointly optimized\)\. The*critical path*under scalarizationλ\\lambdais the longest scalarized path through the dependency DAG:
CPλ\(D\)=argmaxP∈Paths\(D\)\(∑m∈Pλ\(cM\(m\)\)\+∑w∈Pλ\(cW↑\(w\)\)\)\\text\{CP\}\_\{\\lambda\}\(D\)=\\arg\\max\_\{P\\in\\text\{Paths\}\(D\)\}\\left\(\\sum\_\{m\\in P\}\\lambda\(c\_\{M\}\(m\)\)\+\\sum\_\{w\\in P\}\\lambda\(c\_\{W\}^\{\\uparrow\}\(w\)\)\\right\)
Under the latency projection, the critical path determines a lower bound on execution time under maximal parallelism—no schedule can complete faster than that latency\-critical path\. Under other scalarizations, it identifies the bottleneck for the chosen objective\. In metabolic terms, this is the rate\-limiting pathway: the bottleneck whose throughput constrains the entire system\. Identifying it enables targeted optimization \(e\.g\., caching expensive modules, splitting them into cheaper sub\-diagrams\)\.
### 9\.4Resource\-Aware Execution
TheResourceAwareExecutorgates module execution on MetabolicState, implementing the biological principle that pathway activity is regulated by cellular energy availability:
- •STARVING: Only essential modules execute; non\-essential modules are skipped\. This mirrors the starvation response where cells shut down biosynthetic pathways to conserve ATP for survival functions\.
- •CONSERVING: Expensive non\-essential modules are deferred\. Cheap modules execute normally\. This corresponds to metabolic triage under moderate stress\.
- •NORMAL/FEASTING: Full execution with parallel scheduling\. Independent module groups execute concurrently via thread pools\. This mirrors the fed state where abundant ATP enables all pathways\.
ABudgetOpticprovides wire\-level cost capping: once cumulative transmission cost through a wire exceeds a threshold, further data flow is blocked\. This implements pathway\-level budget caps analogous to allosteric feedback inhibition\.
### 9\.5Relation to Abbott & Zardini
Abbott and Zardini\[[1](https://arxiv.org/html/2607.04240#bib.bib24)\]derive FlashAttention “on a napkin” using Neural Circuit Diagrams\[[2](https://arxiv.org/html/2607.04240#bib.bib23)\]—a diagrammatic scheme for representing deep learning algorithms with explicit memory hierarchy awareness\. Their core contribution is a performance model for IO transfer costs across GPU memory levels \(SRAM↔\\leftrightarrowHBM\), with costH∗\(a,M\)=∑tαt\(a\)⋅M−βtH^\{\*\}\(a,M\)=\\sum\_\{t\}\\alpha\_\{t\}\(a\)\\cdot M^\{\-\\beta\_\{t\}\}\. Two concrete optimization techniques drive the derivation:*stream partitioning*, which proves that SoftMax\-Contraction is streamable via an accumulator maintaining running max and sum; and*group partitioning*, which tiles query blocks across GPU cores to minimize HBM transfers\.
Our approach shares their insight that diagrammatic representations are not merely notation but formal objects admitting cost\-reducing transformations\. Both build on the broader lineage of categorical methods in deep learning\[[18](https://arxiv.org/html/2607.04240#bib.bib5)\]\. The frameworks diverge in three respects:
1. 1\.Optimization target\.Abbott & Zardini optimize*IO transfer costs*across a fixed GPU memory hierarchy—bandwidth between SRAM and HBM is the scarce resource\. Operon optimizes*agent execution*under metabolic resource constraints \(ATP budgets, latency caps, memory limits\)\. Same categorical insight—diagram structure reveals optimization opportunities—but different cost models\.
2. 2\.Dynamic state\.Their functional equivalence \(≡\\equiv\) preserves input\-output mappings: two diagrams are equivalent when they produce the same outputs for the same inputs, differing only in resource profile\. Our coalgebraic observational semantics \(Section[3\.5](https://arxiv.org/html/2607.04240#S3.SS5)\) is aimed at*stateful*systems and tracks observable behavior across transitions under a chosen input schedule, not just terminal outputs\.
3. 3\.Scope of composition\.Neural Circuit Diagrams represent*algorithm pipelines*—fixed dataflow graphs where boxes are functions composed via typed wire columns\. Operon’s wiring diagrams represent*agent networks*where modules may be acquired at runtime \(plasmid registry\), conditionally routed \(prism optics\), and subject to resource\-gated execution\. The diagram itself is a dynamic object, not a static specification\.
In short, Abbott & Zardini demonstrate that diagrammatic reasoning scales to deriving hardware\-efficient algorithms; Operon extends the same principle from algorithm\-level optimization to system\-level orchestration of stateful, resource\-constrained agents\.
## 10Reference Implementation
To instantiate the framework in executable form, we provide a reference implementation in Python\. The implementation,operon\-ai111[https://github\.com/coredipper/operon](https://github.com/coredipper/operon), is described in this section, which summarizes key components and demonstrates that the abstractions in the paper translate into practical code\. It should be read as an executable prototype plus synthetic evaluation harness, not as complete empirical validation of every biological analogy in the manuscript\.
### 10\.1Architecture Overview
The implementation follows the biological organization:
- •Core Types\(core/types\.py\): Signal, ActionProtein, FoldedProtein, CellState—the categorical objects with their biological semantics\.
- •Core Wiring\(core/wagent\.py\): WiringDiagram, ModuleSpec, PortType, Wire, DiagramExecutor—typed wiring with integrity labels and capabilities\.
- •Core Optics\(core/optics\.py\): PrismOptic, TraversalOptic, ComposedOptic—wire\-level conditional routing and batch transforms\.
- •Core Denaturation\(core/denature\.py\): StripMarkupFilter, NormalizeFilter, ChainFilter—wire\-level anti\-injection sanitization\.
- •Core Coalgebra\(core/coalgebra\.py\): FunctionalCoalgebra, StateMachine, ParallelCoalgebra, SequentialCoalgebra, finite\-trace observational checking\.
- •Surveillance\(surveillance/\): The immune system implementation with MHCDisplay, TCell, Thymus, and ImmuneMemory components\.
- •Adaptive Immune\(patterns/verifier\.py\): VerifierComponent—rubric\-based quality evaluation that emits signals to WatcherComponent for quality\-based model escalation\.
- •Developmental Gate\(patterns/certificate\_gate\.py\): CertificateGateComponent—pre\-execution genome integrity check implementing the G1/S checkpoint\.
- •Healing\(healing/\): ChaperoneLoop implementing the structural self\-healing pattern\.
- •Quality\(quality/\): Chaperone protein with multi\-strategy folding\.
- •Topology\(topology/\): Network motifs including Quorum, Cascade, and Oscillator\.
- •Organelles\(organelles/plasmid\.py\): Plasmid, PlasmidRegistry—capability\-gated dynamic tool acquisition\.
- •Coordination\(coordination/diffusion\.py\): DiffusionField, MorphogenSource—graph\-based spatially varying morphogen gradients\.
- •Multi\-cellular\(multicell/\): CellType, ExpressionProfile, Tissue, TissueBoundary—hierarchical multi\-agent organization\.
### 10\.2Immune System Implementation
The Adaptive Immunity motif is implemented as an integrated surveillance system:
```
@dataclass
class ImmuneSystem:
thymus: Thymus # Negative selection
treg: RegulatoryTCell # Tolerance/suppression
memory: ImmuneMemory # Threat signatures
displays: dict[str, MHCDisplay]
tcells: dict[str, TCell]
profiles: dict[str, BaselineProfile] # Trained baselines
```
TheMHCPeptideclass captures behavioral fingerprints—statistical signatures of agent output including response time distributions, vocabulary hashes, confidence patterns, and error rates\. This directly implements the MHC presentation concept from Section 4\.7\.
##### Two\-Signal Activation\.
T\-cell activation requires both signals:
```
class Signal1(Enum):
SELF = "self" # Matches baseline
NON_SELF = "non_self" # Anomalous behavior
UNKNOWN = "unknown" # Insufficient data (anergic)
class Signal2(Enum):
NONE = "none"
CANARY_FAILED = "canary"
CROSS_VALIDATED = "cross"
REPEATED_ANOMALY = "repeat"
MANUAL_FLAG = "manual" # Operator override
```
An agent is only flagged whenSignal1 == NON\_SELFandSignal2 \!= NONE\. This prevents false positives from transient anomalies, implementing the immunological requirement for costimulation\.
### 10\.3Adaptive Immune Layer: VerifierComponent
The ImmuneSystem above implements*innate*immunity—generic anomaly detection via baseline deviations\. The VerifierComponent completes the immune analogy with*adaptive*immunity: rubric\-based quality evaluation tailored to each task type, analogous to B\-cells producing antibodies specific to a particular antigen\.
```
@dataclass
class VerifierComponent:
rubric: Rubric | None = None # (output, stage) -> quality 0.0-1.0
config: VerifierConfig = ... # quality_low_threshold = 0.5
def on_stage_result(self, stage, result, shared_state, ...):
quality = self.rubric(output, stage_name)
severity = 1.0 - quality
signal = WatcherSignal(
category=SignalCategory.EPISTEMIC,
source="verifier", value=severity, ...)
shared_state["_verifier_signals"].append(signal)
```
The WatcherComponent collects these signals and, when quality falls below threshold on a fast model, escalates to the deep model\. This provides quality\-sensitive escalation that the novelty\-based epiplexity signal cannot: a weaker model producing*varied but mediocre*output will not trigger epiplexity stagnation but will trigger verifier escalation\.
### 10\.4G1/S Checkpoint: CertificateGateComponent
The CertificateGateComponent implements the G1/S DNA damage checkpoint: before each stage executes its LLM call, the gate scans the genome against a DNARepair checkpoint\. If corruption is detected, a HALT intervention prevents the corrupted state from reaching the model\.
```
@dataclass
class CertificateGateComponent:
genome: Genome
repair: DNARepair
checkpoint: StateCheckpoint
def on_stage_start(self, stage, shared_state, ...):
damage = self.repair.scan(self.genome, self.checkpoint)
if damage:
shared_state[WATCHER_STATE_KEY] = WatcherIntervention(
kind=InterventionKind.HALT,
reason=f"genome corruption: {len(damage)} damage(s)")
```
This moves DNARepair from reactive \(detect\-after\-corrupt\) to preventive \(block\-before\-execute\), completing the cell cycle analogy alongside CellCycleController\.
### 10\.5Chaperone Implementation
The Chaperone implements multi\-strategy folding with provenance tracking:
```
class FoldingStrategy(Enum):
STRICT = "strict" # Exact JSON match
EXTRACTION = "extraction" # Find JSON in text
LENIENT = "lenient" # Type coercion
REPAIR = "repair" # Fix malformed JSON
```
TheChaperoneLoopextends this into a healing loop where validation errors are fed back to the generator:
```
class ChaperoneLoop:
def heal(self, prompt: str) -> HealingResult:
for attempt in range(self.max_retries + 1):
raw = self.generator(prompt, error_context)
folded = self.chaperone.fold_enhanced(raw, schema)
if folded.valid:
return HealingResult(HEALED, folded)
error_context = self._format_error(folded)
return HealingResult(DEGRADED, ubiquitin_tagged=True)
```
This operationalizes the GroEL/GroES cage metaphor: the error trace becomes input to the repair process, enabling context\-aware correction\.
### 10\.6Trust and Provenance
The implementation uses a simplified 3\-level trust hierarchy that collapses the theoretical 4\-level model\{U,T,S,R\}\\\{U,T,S,R\\\}for practical deployment:
```
class IntegrityLabel(IntEnum):
UNTRUSTED = 0 # User input, Retrieved, Self-generated
VALIDATED = 1 # Schema-checked (Chaperone-folded)
TRUSTED = 2 # Tool-grounded (deterministic output)
```
This simplification mergesUser,Retrieved, andSelfintoUNTRUSTED, reflecting the common case where all non\-tool sources require validation before trust elevation\. The full 4\-level model can be recovered by subclassingIntegrityLabelwith additional levels when finer\-grained provenance tracking is required\.
TheApprovalTokencarries explicit authorization metadata for privileged operations:
```
@dataclass(frozen=True)
class ApprovalToken:
request_hash: str
issuer: str
reason: str = ""
confidence: float = 1.0
integrity: IntegrityLabel = IntegrityLabel.TRUSTED
timestamp: datetime = field(default_factory=now)
```
This operationalizes the Trust\-Gated Lens: actions requiring high integrity must present anApprovalTokenwith sufficient integrity level\.
### 10\.7Plasmid Registry Implementation
The Horizontal Gene Transfer mechanism \(§[8\.2](https://arxiv.org/html/2607.04240#S8.SS2)\) is implemented as aPlasmidRegistrywith capability\-gated acquisition:
```
@dataclass(frozen=True)
class Plasmid:
name: str
func: Callable[..., Any]
required_capabilities: frozenset[Capability]
tags: frozenset[str] = frozenset()
def to_tool(self) -> SimpleTool:
return SimpleTool(name=self.name, func=self.func,
required_capabilities=set(self.required_capabilities))
```
TheMitochondriaclass is extended withacquire\(\)andrelease\(\)methods\. When aMitochondriainstance is configured with anallowed\_capabilitiesenvelope, acquisition checksCplasmid⊆CagentC\_\{\\text\{plasmid\}\}\\subseteq C\_\{\\text\{agent\}\}before engulfing the tool; release implements plasmid curing\. The registry supports both text search and pure tag filtering\.
### 10\.8Denaturation Layers Implementation
The anti\-prion defense \(§5\.3\) is implemented as wire\-level filters conforming to aDenatureFilterprotocol:
```
class DenatureFilter(Protocol):
@property
def name(self) -> str: ...
def denature(self, value: str) -> str: ...
```
Three concrete filters are provided:
- •StripMarkupFilter: Removes code blocks, ChatML tokens \(<\|\.\.\.\|\>\),\[INST\]tags, XML role tags \(<system\>,<user\>\), and role delimiters using compiled regex patterns\.
- •NormalizeFilter: Applies Unicode normalization \(NFKC\), lowercasing, and control character removal to collapse homoglyph\-based evasion\.
- •ChainFilter: Composes multiple filters left\-to\-right\.
Filters attach to wires in theWiringDiagram\. TheDiagramExecutorapplies denaturation before optics:denature→\\tooptic→\\todestination\. This ensures that downstream agents receive sanitized data regardless of what the upstream agent produces\.
### 10\.9Multi\-Cellular Organization Implementation
The multi\-cellular abstractions \(§[6](https://arxiv.org/html/2607.04240#S6)\) are implemented in themulticell/package:
##### Cell Type Specialization\.
TheCellTypeclass encapsulates anExpressionProfile—a mapping from gene names to expression levels \(OVEREXPRESSED,SILENCED, etc\.\)\. Callingdifferentiate\(genome\)applies the profile to a sharedGenome, producing aDifferentiatedCellwith role\-specific configuration\. This implements the biological principle that a single genotype produces many phenotypes\.
##### Tissue Architecture\.
TheTissueclass provides:
- •ATissueBoundarywith typed input/output ports and a capability ceiling
- •Cell type registration with capability validation \(Ccell⊆CtissueC\_\{\\text\{cell\}\}\\subseteq C\_\{\\text\{tissue\}\}\)
- •Internal wiring via an embeddedWiringDiagram
- •OptionalDiffusionFieldfor spatially varying morphogen gradients
- •Export as aModuleSpecfor organism\-level composition
##### Metabolic\-Epigenetic Coupling\.
TheHistoneStoreaccepts an optionalenergy\_gateparameter pairing anATP\_Storewith aMetabolicAccessPolicy\. When set, eachretrieve\_context\(\)call costs ATP\. Under metabolic stress, only strongly embedded markers remain accessible; in the current implementation, marker strength serves as the cost proxy used to approximate Eq\. \([30](https://arxiv.org/html/2607.04240#S8.E30)\)\.
### 10\.10Bi\-Temporal Memory Implementation
The bi\-temporal coalgebra \(§[3\.5](https://arxiv.org/html/2607.04240#S3.SS5)\) and temporal epistemic framework \(§[7\.1](https://arxiv.org/html/2607.04240#S7.SS1)\) are implemented inoperon\_ai/memory/bitemporal\.pyas a standalone append\-only fact store\. The design deliberately avoids mutation: facts are frozen dataclasses, corrections close old records and append new ones, and point\-in\-time queries are pure filters\.
##### Data Model\.
ABiTemporalFactcarries 12 fields: subject/predicate/value triple, valid\-time interval \(valid\_from,valid\_to\), record\-time interval \(recorded\_from,recorded\_to\), source provenance, confidence, tags, and an optionalsupersedespointer to the corrected fact\. All facts are@dataclass\(frozen=True\)—a deliberate departure from the mutableMemoryEntryused byEpisodicMemory, justified by the append\-only semantics\.
##### Write Semantics\.
Three operations modify the store:record\_fact\(\)inserts a new active record;correct\_fact\(\)closes the old record’s transaction interval viadataclasses\.replace\(\)and appends a new record withsupersedesset;invalidate\_fact\(\)marks a record as no longer active\. The internal\_factslist is append\-only except for the in\-place close ofrecorded\_toon corrected records\.
##### Retrieval\.
Three query methods implement the temporal epistemic operators:retrieve\_valid\_at\(at\)filters for facts valid at world\-timeatwith active records only;retrieve\_known\_at\(at\)filters for facts recorded by system\-timeat;retrieve\_belief\_state\(at\_valid, at\_record\)intersects both axes, reconstructing the system’s belief at any historical coordinate\.
##### History and Audit\.
history\(subject\)returns all facts \(including closed\) sorted by record time;diff\_between\(t1, t2, axis\)computes set differences on either axis;timeline\_for\(subject\)returns all facts sorted by valid time\. Together, these support the audit question: “what changed betweent1t\_\{1\}andt2t\_\{2\}, and on which axis?”
This subsystem is intentionally decoupled fromHistoneStoreandEpisodicMemory\. Integration bridges—converting histone marks to bi\-temporal facts, or promoting episodic memories into the bi\-temporal substrate—are planned for future work \(§[12](https://arxiv.org/html/2607.04240#S12)\)\.
##### SkillOrganism Substrate Integration\.
TheSkillOrganismruntime \(§[6](https://arxiv.org/html/2607.04240#S6)\) composes the three\-layer context model described in §[6\.3](https://arxiv.org/html/2607.04240#S6.SS3.SSS0.Px3)\. An optionalsubstrate: BiTemporalMemoryparameter attaches a bi\-temporal fact store to the organism\. When present, the run loop is extended with a read path and a write path at each stage boundary:
```
organism = skill_organism(
stages=[research, strategist, evaluator, adversary],
fast_nucleus=fast, deep_nucleus=deep,
substrate=BiTemporalMemory(),
)
```
Read path\.Before a stage executes, the runtime evaluates itsread\_queryfield—either a subject string or a callable returning aBiTemporalQuery—and packages the result into a frozenSubstrateView\(facts, query, record\_time\)\. This view is injected into the stage’s metadata \(for agent stages\) or passed as an additional argument \(for handler stages, via arity\-aware dispatch\)\. Therecord\_timecaptures the moment of the read, establishing the record\-time horizon for this stage’s knowledge\.
Write path\.After a stage executes, two mechanisms can emit facts: \(1\) the convenience flagemit\_output\_fact=Trueauto\-records the stage output withsubject=task,predicate=stage\.name; \(2\) afact\_extractorcallable converts the stage result into one or more factual events\. Each event specifies an operation—assert, correct, or invalidate—and is applied to the substrate via the standardBiTemporalMemorywrite API\. The stage name serves as the defaultsourcefor provenance\.
WhensubstrateisNone\(the default\), the run loop is unchanged: no datetime operations are invoked, no metadata is injected, and all four original lifecycle hooks remain unmodified\. Existing tests pass without alteration\.
The integration directly enables the audit question from §[7\.1](https://arxiv.org/html/2607.04240#S7.SS1): given a completed run,retrieve\_belief\_state\(at\_valid=t, at\_record=t\_stage\)reconstructs exactly what the organism believed at the moment stageXXexecuted, even if subsequent stages corrected or invalidated facts\. Example 71 demonstrates this with a four\-stage enterprise workflow where an adversary stage corrects a research assumption, and the original belief state remains fully reconstructible\.
##### PatternLibrary Implementation\.
ThePatternLibraryprovides evolutionary memory for collaboration patterns\. Templates are stored in an in\-memory dictionary keyed bytemplate\_id; run records accumulate in a list\. Thetop\_templates\_for\(fingerprint\)method scores each template against a query fingerprint using a weighted combination of task\-shape match \(0\.30\), tool\-count proximity \(0\.15\), subtask\-count proximity \(0\.15\), required\-role Jaccard overlap \(0\.20\), tag Jaccard overlap \(0\.10\), and historical success rate \(0\.10\)\. This simple retrieval mechanism is intentionally stateless and deterministic, with richer adaptation \(experience\-driven scoring, decay\) planned for Phase 4\.
##### WatcherComponent Implementation\.
TheWatcherComponentis aSkillRuntimeComponentthat classifies stage\-level signals into three categories following Dupoux et al\.\[[15](https://arxiv.org/html/2607.04240#bib.bib30)\]:*epistemic*\(fromEpiplexityMonitor\),*somatic*\(fromATP\_Store\), and*species\-specific*\(fromImmuneSystem\)\. All signal sources are optional; the watcher is a no\-op when none are attached\.
After each stage, the watcher evaluates collected signals against configured thresholds and may write aWatcherInterventiontoshared\_state\. The run loop checks for this key after component hooks complete and before thehalt\_on\_blockguard\. Three intervention kinds are supported:RETRYre\-executes the current stage;ESCALATEre\-executes with the deep nucleus;HALTbreaks the stage loop\. Component hooks are not re\-invoked after retry or escalation, preventing recursive intervention loops\.
The intervention\-count convergence signal operationalizes the BIGMAS finding\[[21](https://arxiv.org/html/2607.04240#bib.bib31)\]: when the ratio of interventions to observed stages exceedsmax\_intervention\_rate\(default 0\.5\), the watcher emits a non\-convergence HALT\. Example 73 demonstrates all three intervention paths\.
##### Adaptive Assembly Implementation\.
TheAdaptiveSkillOrganismwrapper composes the full adaptive loop\. The public factoryadaptive\_skill\_organism\(task, fingerprint, library, \.\.\.\)auto\-fingerprints the task if no fingerprint is provided, queriesPatternLibrary\.top\_templates\_for\(\)for the best template, and callsassemble\_pattern\(\)to convert the template’sstage\_specsinto a runnable topology \(dispatching ontopology:skill\_organism,reviewer\_gate,specialist\_swarm, orsingle\_worker\)\. AWatcherComponentandTelemetryProbeare automatically attached\.
After execution, the wrapper records aPatternRunRecordin the library \(closing the scoring feedback loop\) and populates the watcher’s experience pool withExperienceRecordinstances for each intervention\. The experience pool persists across runs: when rule\-based decision logic returns no intervention, the watcher consults past experiences with matching \(stage, signal category, fingerprint shape\) and recommends the intervention kind that was most often successful\. Rule\-based decisions always take priority; experience is a fallback\. Example 74 demonstrates the full lifecycle; Example 75 demonstrates experience\-driven recommendations\.
##### Cognitive Mode Annotations\.
TheCognitiveModeenum classifies stages asOBSERVATIONAL\(System A: passive sensing, information gathering\) orACTION\_ORIENTED\(System B: active decision\-making, execution\)\. The annotation is an optional field onSkillStage; when absent, it is inferred from the existingmodefield \(fast/fixed→\\toOBSERVATIONAL,fuzzy/deep→\\toACTION\_ORIENTED\)\. TheWatcherComponentcollects cognitive\-mode signals and reports mode mismatches \(e\.g\., an observational stage routed to the deep nucleus\) as informational epistemic signals\. Themode\_balance\(\)method summarizes the System A/B distribution across a run\.
##### Sleep Consolidation Implementation\.
TheSleepConsolidationclass composesAutophagyDaemon,PatternLibrary,EpisodicMemory,HistoneStore, and optionallyBiTemporalMemoryinto a five\-step post\-batch consolidation cycle: \(1\) prune stale context via autophagy, \(2\) replay successful run records and promote them from WORKING to EPISODIC tier in episodic memory, \(3\) compress recurring high\-success patterns into new consolidatedPatternTemplateinstances, \(4\) run counterfactual replay over bi\-temporal corrections to detect cases where updated facts would have changed the outcome, and \(5\) promote frequently\-accessed ACETYLATION histone marks to permanent METHYLATION\.
Thecounterfactual\_replay\(\)function performs static analysis: it callsdiff\_between\(run\_time, now, axis="record"\)to find corrections that occurred after the original run, then matches corrected fact subjects/predicates against stage names in the template\. When matches are found, it reports that the outcome may have differed, without re\-executing the workflow\. Example 77 demonstrates the full consolidation cycle\.
##### Social Learning Implementation\.
TheSocialLearningclass wraps aPatternLibrarywith peer\-exchange semantics\.export\_templates\(\)filters by success rate and run count;import\_from\_peer\(\)computes an effective score \(peer success rate×\\timestrust score\) for each template and adopts those exceeding the adoption threshold\. TheTrustRegistryuses exponential moving average:st\+1=α⋅outcome\+\(1−α\)⋅sts\_\{t\+1\}=\\alpha\\cdot\\text\{outcome\}\+\(1\-\\alpha\)\\cdot s\_\{t\}withα=0\.3\\alpha=0\.3, giving more weight to recent outcomes\. Provenance tracking maps each adopted template to its source peer, enabling trust updates when adoption outcomes are recorded\. The watcher’s curiosity signals extend the epistemic signal category with asource="curiosity"derived fromEpiplexityMonitor’s EXPLORING status, triggering ESCALATE when embedding novelty exceeds a configurable threshold on fast models\. Example 78 demonstrates template exchange; Example 79 demonstrates curiosity signals\.
##### Developmental Staging Implementation\.
TheDevelopmentControllerwraps aTelomere\(composition, not inheritance\) and maps the fraction of telomere consumed to aDevelopmentalStage: EMBRYONIC \(<10%<10\\%\), JUVENILE \(10–35%10\\text\{\-\-\}35\\%\), ADOLESCENT \(35–70%35\\text\{\-\-\}70\\%\), MATURE \(\>70%\>70\\%\)\. Thresholds are configurable viaDevelopmentConfig; transitions are one\-directional and never regress, even if telomeres are renewed\. Learning plasticity decreases monotonically \(1\.0 at EMBRYONIC, 0\.25 at MATURE\)\.
CriticalPeriodfrozen dataclasses declare time\-limited learning windows by specifyingopens\_atandcloses\_atstages\. The controller evaluates period status on each tick: once the organism passescloses\_at, the window is permanently shut\. ThePlasmiddataclass gains amin\_stagefield;Mitochondria\.acquire\(\)checks the organism’s current developmental stage before granting tool access\. Teacher\-learner scaffolding viaSocialLearning\.scaffold\_learner\(\)filters templates by the learner’s stage and applies a plasticity bonus to effective trust, enabling mature organisms to guide younger ones\. Example 80 demonstrates the full lifecycle; Example 81 demonstrates scaffolding\.
### 10\.11Coalgebraic State Machines Implementation
The coalgebra formalism \(§[3\.5](https://arxiv.org/html/2607.04240#S3.SS5)\) is made explicit and composable:
```
class Coalgebra(Protocol[S, I, O]):
def readout(self, state: S) -> O: ...
def update(self, state: S, inp: I) -> S: ...
@dataclass
class StateMachine(Generic[S, I, O]):
state: S
coalgebra: Coalgebra[S, I, O]
trace: list[TransitionRecord] = field(default_factory=list)
def step(self, inp: I) -> O: ...
def run(self, inputs: list[I]) -> list[O]: ...
```
ParallelCoalgebraandSequentialCoalgebraimplement the composition operations from §[3\.5](https://arxiv.org/html/2607.04240#S3.SS5)\. Thecheck\_bisimulation\(\)function tests observational equivalence \(Eq\. \([8](https://arxiv.org/html/2607.04240#S3.E8)\)\) over an input sequence, returning a witness on divergence\. Existing organelles \(HistoneStore,ATP\_Store,CellCycleController\) can be wrapped as coalgebras, enabling formal composition and finite\-trace comparison of multi\-organelle systems\.
### 10\.12Morphogen Diffusion Implementation
TheDiffusionFieldclass implements the discrete\-time diffusion dynamics \(Eq\. \([20](https://arxiv.org/html/2607.04240#S6.E20)\)\):
```
class DiffusionField:
def add_node(self, node_id: str): ...
def add_edge(self, a: str, b: str, bidirectional=True): ...
def add_source(self, source: MorphogenSource): ...
def step(self): # emit -> diffuse -> decay -> clamp
def run(self, steps: int): ...
def get_local_gradient(self, node_id) -> MorphogenGradient: ...
```
Eachstep\(\)applies four phases: emission \(sources add morphogen\), diffusion \(concentration flows along edges, split evenly among neighbors\), decay \(uniform degradation\), and clamping \(enforce bounds\)\. Nodes with no neighbors skip diffusion outflow, matching Eq\. \([20](https://arxiv.org/html/2607.04240#S6.E20)\)’s isolated\-node case\. Theget\_local\_gradient\(\)method bridges to the existingMorphogenGradientAPI, enabling agents to read their local concentrations without awareness of the underlying graph dynamics\.
### 10\.13Optic\-Based Wiring Implementation
The wire\-level optics \(§3\.4\) are implemented via anOpticprotocol:
```
class Optic(Protocol):
def can_transmit(self, data_type: DataType,
integrity: IntegrityLabel) -> bool: ...
def transmit(self, value: Any, data_type: DataType,
integrity: IntegrityLabel) -> Any: ...
```
Four concrete optics are provided:
- •LensOptic: Identity pass\-through \(equivalent to no optic\)\.
- •PrismOptic: Transmits only ifτ∈A\\tau\\in A\(Eq\. \([5](https://arxiv.org/html/2607.04240#S3.E5)\)\)\. Enables fan\-out routing\.
- •TraversalOptic: Maps a transform over list elements \(Eq\. \([6](https://arxiv.org/html/2607.04240#S3.E6)\)\)\.
- •ComposedOptic: Chains optics left\-to\-right; all must accept\.
Optics coexist withDenatureFilters on the same wire\. TheDiagramExecutorprocesses them in order: denaturation→\\tooptic→\\todestination\. Prism rejection causes the wire to be skipped \(not an error\), enabling conditional routing patterns where different data types flow to different handlers\.
### 10\.14Interactive Demonstrations
The repository also includes interactive Gradio demonstrations for individual organelles and composition patterns—from single motifs \(Membrane, Chaperone, Quorum Sensing\) to multi\-organelle orchestrations\. These demos are illustrative artifacts rather than controlled benchmarks\.
### 10\.15Implementation Verification \(Synthetic Harness\)
We define a synthetic evaluation harness to verify that three motifs behave as designed with reproducible procedures:
1. 1\.Chaperone Folding\.Generate JSON schemas with 3–8 required fields\. Sample valid JSON and apply 1–3 corruptions \(e\.g\., missing quotes, trailing commas, type swaps, dropped fields\)\. Measure the fraction of outputs that can be folded into the schema under STRICT versus cascaded strategies \(EXTRACTION→\\toLENIENT→\\toREPAIR\)\.
2. 2\.Immune Detection\.Simulate agents with baseline distributions over response time, vocabulary hash, structure hash, and confidence\. Train on baseline samples, then introduce “compromised” agents by shifting distribution parameters and injecting anomalous hashes\. Measure sensitivity and false positive rate under the two\-signal activation rule\.
3. 3\.Healing Loop\.Generate malformed outputs and run the ChaperoneLoop with and without error\-context feedback\. Measure recovery withinkkattempts \(defaultk=3k=3\)\.
These suites test whether the implemented motifs behave as intended under controlled corruption and anomaly models; they do not estimate in\-the\-wild failure rates of production LLM systems\.
##### Implementation\.
The harness is implemented ineval/with a JSON\-configured CLI:
```
python -m eval.run --suite all --config eval/configs/default.json \
--out eval/results/latest.json
```
The output is a machine\-readable JSON report \(per\-suite config \+ metrics\) suitable for direct inclusion in tables or plots\.
##### Status\.
Synthetic runs verify that each motif functions as designed within this harness \(cascade\>\>strict, error\-context\>\>blind retry, immune detection\>\>chance\)\. Table[4](https://arxiv.org/html/2607.04240#S10.T4)reports aggregated numeric results across multiple seeds; real\-world validation with LLM outputs remains ongoing\.
##### Aggregated Results\.
We ran the harness across 100 deterministic seeds \(1–100\) using the default harness config \(eval/configs/default\.json\)\. The aggregate results \(pooled across seeds with Wilson 95% intervals;NNis total pooled trials\) are reported in Table[4](https://arxiv.org/html/2607.04240#S10.T4)\.
##### External Benchmark Suites\.
In addition to the synthetic suites above, the harness includes suites derived from external benchmarks: \(1\) function\-call schemas from the Berkeley Function Calling Leaderboard \(BFCL\)\[[36](https://arxiv.org/html/2607.04240#bib.bib21)\]test the Chaperone’s folding pipeline against realistic tool\-use schemas, and \(2\) prompt injection attack templates from AgentDojo\[[14](https://arxiv.org/html/2607.04240#bib.bib22)\]generate adversarial behavioral shifts to test Immune System detection\. These suites use the same deterministic corruption and simulation methodology; results appear in the lower section of Table[4](https://arxiv.org/html/2607.04240#S10.T4)\.
Table 4:Evaluation results aggregated across 100 deterministic seeds \(Wilson 95% CI\)\. Top: synthetic motif tests\. Bottom: external benchmark–derived tests \(BFCL, AgentDojo\)\.
### 10\.16Limitations
The current implementation has several limitations:
- •Epiplexity:Implemented with a mock embedding provider \(MockEmbeddingProvider\)\. Integration with production embedding APIs and empirical calibration of theα\\alphamixing parameter and thresholdδ\\deltaacross diverse task types remain future work\.
- •Morphogen Diffusion:TheDiffusionFieldoperates in a single process\. Cross\-agent gradient propagation in distributed multi\-process deployments with eventual consistency remains future work\.
- •Denaturation:Filters target known syntactic patterns \(ChatML, XML role tags, markdown code blocks\)\. Novel injection techniques using previously unseen syntax may bypass denaturation; customDenatureFilterimplementations should be added as new attack patterns emerge\.
- •Finite\-Trace Equivalence:Thecheck\_bisimulation\(\)function tests over finite input sequences\. Coinductive bisimulation for infinite\-trace systems is not yet supported\.
- •Benchmarking:The evaluation harness covers synthetic suites and external benchmarks \(BFCL, AgentDojo\)\. Real\-world validation of the multi\-cellular and diffusion components at production scale is still in progress\.
We release the implementation to enable further scrutiny and extension of the framework\.
## 11Convergence: Integrating External Agent Frameworks
The preceding sections develop Operon’s structural analysis, epistemic topology, and formal verification foundations\. This section summarizes how these tools extend to external agent orchestration systems through a typed adapter architecture\. A standalone companion paper provides the full treatment, including implementation details, all 107 examples, and complete TLA\+ specification listings; this section is self\-contained but deliberately concise\.
A\-Evolve — evolution layerAnimaWorks — cognitive layerAsyncThink — thinking layerRalph / DeerFlow / Swarms — orchestration layerOperon — structural layer
Every adapter produces anExternalTopology—a framework\-agnostic intermediate representation carrying a source tag, a pattern name, agent specifications, directed communication edges, and arbitrary metadata\. The analysis pipeline is source\-agnostic:analyze\_external\_topology\(\)consumes anyExternalTopologyand applies three of the four epistemic bounds—error amplification, sequential penalty, and tool density—plus a topology\-mismatch flag to produce topology advice, structural warnings, and a composite risk score\. \(Parallel acceleration is computed by the epistemic layer but not included in the adapter risk score\.\) Adding a new orchestration target therefore requires writing a single parse function—no changes to the analysis code\.
Four TLA\+ specifications verify safety invariants that are difficult to test exhaustively at the unit level:*TemplateExchangeProtocol*\(provenance and trust monotonicity\),*DevelopmentalGating*\(irreversible stage transitions and capability constraints\),*ConvergenceDetection*\(intervention\-count convergence or HALT\), and*EvolutionGating*\(monotonic score safety for A\-Evolve’s evolutionary loop\)\. Together, these cover the critical safety boundaries of the convergence stack\.
For the complete treatment—including adapter implementation details, template exchange protocols, memory bridge semantics, TLA\+ specification listings, and all 107 worked examples—see the standalone convergence companion paper\.222[https://coredipper\.github\.io/operon/convergence/](https://coredipper.github.io/operon/convergence/)
A live evaluation harness \(Example 107\) measures quality, latency, and token cost across Gemini API, Claude CLI, and Codex CLI providers\. Guided multi\-stage pipelines show a consistent\+6\.2%\+6\.2\\%quality improvement over unguided configurations; single\-agent CLI execution shows no effect, confirming that structural guidance helps when there is topology to guide\.
##### Meta\-evolution \(Phase C8\)\.
The meta\-harness extends the convergence stack to*evolving*organism configurations—modes, models, and intervention thresholds—rather than just running them\. AFilesystemOptimizerprotocol \(distinct from C7’s prompt\-levelEvolutionaryOptimizer\) drives anEvolutionLoopthat maps candidate configs toGenomeobjects, evaluates viaLiveEvaluator, and persists full execution traces to a candidate\-first filesystem store\.
The key scientific finding: Operon’s biological abstractions generalize to the meta\-level\. TheGenomemapping is lossless \(∼5\{\\sim\}5lines of flattening logic\)\. TheEpiplexityMonitorgeneralizes across scales via a pluggableDistanceProvider—ConfigHammingDistancetriggers STAGNANT/EXPLORING transitions identically to embedding cosine distance\.DesignProblemwrapping of evolution steps is natural\. Boundaries:feedback\_fixed\_pointdoes not fit \(evolution is not convergent iteration\), andTrustRegistryis overkill for two proposer strategies\.
An Ao et al\.\[[6](https://arxiv.org/html/2607.04240#bib.bib44)\]test of exogenous signals shows that rich filesystem context \(configs\+\+trace metadata\) yields a3×3\\timesimprovement over compressed history for the LLM proposer \(0\.490\.49vs0\.150\.15\), but config\-space evolution does not strongly benefit from LLM reasoning over blind tournament mutation \(0\.490\.49vs0\.440\.44\)\. Phase B \(topology mutations with DAG execution\) improved tournament \(0\.600\.60\) but degraded the LLM proposer \(0\.360\.36\), confirming that biological abstractions generalize as*code structure*but not as*optimization algorithms*\. The structural guarantee features—immune systems, epiplexity, developmental gating—remain the core value proposition\. de los Riscos et al\.\[[13](https://arxiv.org/html/2607.04240#bib.bib45)\]provide a category\-theoretic framework \(ArchAgents\) that formalizes Operon’s architecture: objects are organisms, morphisms are compilers, agents are configured instances\. A detailed treatment of the C8 findings appears in the companion meta\-evolution paper\.
## 12Conclusion
The transition from “Prompt Engineering” to “Agentic Engineering” requires moving beyond component\-level optimization toward principled architectural design\. Current methodologies often lack the formal foundations needed to reason about system\-level properties like termination, error suppression, and graceful degradation\.
In this paper, we have argued that Gene Regulatory Networks \(GRNs\) provide a useful source of control motifs for distributed, stochastic information processing\. By expressing selected biological and software components within a shared interface language from Applied Category Theory, we derived a corresponding suite of design patterns\. The result is a modeling and design framework, not a claim that biological and software systems are identical in mechanism:
### Core Contributions
1. 1\.Robustness via Topology:The Coherent Feed\-Forward Loop provides error suppression proportional to\(1−ρ\)\(1\-\\rho\), whereρ\\rhois the correlation between component error modes\. We make precise the conditions under which topological redundancy provides genuine safety benefits: highly correlated generator/verifier pairs yield limited improvement, while more heterogeneous pairs can suppress errors more effectively\. The topology is necessary but not sufficient; component diversity determines actual error suppression\.
2. 2\.Adaptive Immunity:We formalize the Self/Non\-Self distinction as aProvenance Functor𝒫:𝐌𝐬𝐠→𝐓𝐫𝐮𝐬𝐭\\mathcal\{P\}:\\mathbf\{Msg\}\\to\\mathbf\{Trust\}with structurally\-enforced labels\. The Trust\-Gated Lens provides resistance to content\-level trust forgery by ensuring that content\-based attacks cannot elevate provenance\. This extends the Prion metaphor into a full immunological framework with MHC\-like tagging, negative selection during training, and regulatory suppression of conflicting sources\.
3. 3\.Epistemic Health:The formalization ofEpiplexity\(Bayesian Surprise\) as a metric for detecting “epistemic starvation\.” We provide an operational approximation using embedding similarity and conditional perplexity, with windowed detection to distinguish task completion from pathological loops\. This connects agent dynamics to the Free Energy Principle: healthy agents minimize surprise through learning or effective action; stagnant agents do neither\.
4. 4\.Metabolic Intelligence:The reframing of the Runtime from passive budget to activeCognitive Control Policy\. Drawing on MIPS \(Mitochondrial Information Processing System\), we distinguish fast interventions \(Apoptosis via mPTP\-like triggers\) from slow interventions \(Retrograde Responses that reshape agent phenotype across sessions\)\. The Runtime governs reasoningqualitythrough the Metabolic\-Epigenetic Coupling: low\-budget states “methylate” expensive context, forcing efficient phenotypes\.
5. 5\.Multi\-Cellular Organization:The extension from single\-agent to multi\-agent systems using developmental biology\. Agent phenotypes arise from differential context \(epigenome\) on shared weights \(genome\)\. Morphogen gradients \(shared context variables\) enable coordination without central control\. Tissue boundaries enforce security isolation\. This reframes “how many agents?” as “what is the developmental program?”
6. 6\.Homeostasis:Continuous self\-repair through three modalities: Structural \(Chaperone Loop with error\-context feedback\), Metabolic \(Apoptosis \+ Regeneration with state summarization\), and Cognitive \(Autophagy via sleep/wake cycles\)\. Most frameworks focus on Action; biology equally prioritizes Maintenance\.
7. 7\.Evolutionary Dynamics:The Vermeij Trend predicts that agentic architectures face three selective pressures: adversarial robustness \(Red Queen dynamics with attackers\), task complexity \(environmental pressure toward “aerobic” multi\-step reasoning\), and resource efficiency \(metabolic selection toward the Pareto frontier\)\. In our framing, these pressures motivate architectures that balance immune defense, task complexity, and metabolic regulation rather than treating those concerns as separable add\-ons\.
8. 8\.Wire\-Level Optics:Prism optics enable conditional type\-based routing \(receptor specificity\), Traversal optics enable batch processing \(polymerase processivity\), and DenatureFilters provide anti\-injection sanitization—all composable on the same wire\.
9. 9\.Morphogen Diffusion:A discrete\-time dynamical system on the agent graph produces spatially varying concentration profiles, enabling position\-dependent coordination without central control or global state sharing\.
10. 10\.Composable Coalgebras:The coalgebraic formalism is made explicit with parallel and sequential composition, full transition traces, and observational equivalence criteria, enabling structured comparison of agent implementations\.
11. 11\.Epistemic Topology:Kripke\-style knowledge operators \(KiK\_\{i\},EGE\_\{G\},CGC\_\{G\},DGD\_\{G\}\) derived from wiring diagram structure yield four predictive theorems for multi\-agent scaling—error amplification, sequential penalty, parallel acceleration, tool density—and these theorems are qualitatively consistent with empirical results from large\-scale architecture evaluations\[[24](https://arxiv.org/html/2607.04240#bib.bib27)\]\.
12. 12\.Capability\-Gated Tool Acquisition:The Plasmid Registry implements Horizontal Gene Transfer with capability gating, preventing privilege escalation when agents dynamically acquire tools\.
13. 13\.Diagram Optimization via Categorical Rewriting:Cost annotations enrich the wiring category over the resource monoid\(ℛ,\+,0\)\(\\mathcal\{R\},\+,0\), making resource consumption a first\-class compositional concept\. Rewriting passes—dead wire elimination, parallel grouping, cost\-order scheduling—are endofunctors that preserve input\-output observational equivalence while improving resource utilization\. The ResourceAwareExecutor gates module execution on MetabolicState, connecting diagram optimization to the metabolic intelligence framework: under ATP depletion, non\-essential pathway branches are downregulated, mirroring cellular starvation responses\.
### The Structural Foundation
The correspondence rests on the category𝐏𝐨𝐥𝐲\\mathbf\{Poly\}of polynomial functors as a language for typed interfaces\. Within that language, biological and software components at several scales—genes and agent capabilities, cells and agent runtimes, tissues and multi\-agent subsystems—can be modeled as interfaces\(O,I\)\(O,I\)consuming observations and producing actions\. The Operad of Wiring Diagrams provides the grammar for composition, with type\-checking at the topological level preventing classes of runtime errors\. The Metabolic Coalgebra enriches this with resource constraints, providing a decidable termination criterion when costs are strictly decreasing and regeneration is excluded \(or separately bounded\)\. The Provenance Functor layers trust semantics onto message flow, providing a structural account of trust\-gated resistance to content\-level trust forgery\.
### Implications
The Operon framework should be read as a structured design language for robust agent architectures\. Its value is that some biological analogies can be made precise enough to guide implementation: topology constrains coordination, resource models constrain execution, and provenance labels constrain trust elevation\.
The correspondence is therefore neither a loose metaphor nor a full biological equivalence\. It is a disciplined abstraction that makes a subset of biologically inspired design patterns precise enough to analyze and implement, as demonstrated by the reference implementation\.
The epistemic\-topology formalization is qualitatively consistent with external scaling evidence such as Kim et al\.\[[24](https://arxiv.org/html/2607.04240#bib.bib27)\], but it does not by itself constitute complete empirical validation of the framework\. The connection between morphogen\-driven topology switching and epistemic optimization instead suggests a path toward more formally analyzed adaptive multi\-agent systems, where topological transitions can be justified under explicit epistemic and resource assumptions\.
### The Six\-Layer Arc
The six\-layer progression demonstrates that the biological analogy extends beyond structural safety into temporal reasoning, adaptive behavior, and cognitive development:
1. 1\.Structure:Typed wiring diagrams, topology advice, pattern\-first API\.
2. 2\.Memory:Bi\-temporal facts with dual time axes; auditable substrate integration with three\-layer context model\.
3. 3\.Adaptation:Pattern libraries for evolutionary template memory; watcher with three\-category signal taxonomy \(epistemic/somatic/species\); intervention\-count convergence signal grounded in Hao et al\.\[[21](https://arxiv.org/html/2607.04240#bib.bib31)\]; experience\-driven adaptive assembly\.
4. 4\.Cognition:System A/B cognitive mode annotations per Dupoux et al\.\[[15](https://arxiv.org/html/2607.04240#bib.bib30)\]; sleep consolidation with counterfactual replay; social learning with epistemic vigilance \(trust\-weighted template exchange\); curiosity signals for intrinsic motivation\.
5. 5\.Development:Critical periods that close as organisms mature; capability gating via developmental stage on tool acquisition; teacher\-learner scaffolding\.
6. 6\.Integration:Cross\-subsystem integration tests; memory adapters bridging histone and episodic memory into the bi\-temporal store; paper and documentation finalization\.
Each layer assumes the previous one is stable\. The progression from structural safety to temporal epistemics to adaptive cognition to developmental staging is not arbitrary—it mirrors the biological sequence from genome \(fixed structure\) through epigenetics \(learned bias\) to neural development \(plastic then crystallizing\)\.
### Future Work
Several directions remain open:
- •Broader Convergence Targets:The adapter architecture in §[11](https://arxiv.org/html/2607.04240#S11)integrates five external systems \(A\-Evolve, AnimaWorks\[[5](https://arxiv.org/html/2607.04240#bib.bib35)\], AsyncThink, Ralph/DeerFlow/Swarms\[[35](https://arxiv.org/html/2607.04240#bib.bib36)\], and Operon\-native topologies\) under four TLA\+\-verified safety invariants\. Extending coverage to additional orchestration targets and measuring cross\-framework trust monotonicity at production scale remain open\.
- •Production Benchmarks:Validation on real LLM outputs at scale via BFCL and AgentDojo evaluation harnesses, measuring both reliability and the impact of adaptive assembly on task performance\.
- •Adversarial Robustness:Red\-team evaluation of immune evasion vectors and development of continuous adaptation mechanisms\.
- •Distributed Diffusion:Extending morphogen fields to distributed multi\-process deployments with eventual consistency\.
- •Learned Rewriting Rules:Learning diagram optimization rules from execution traces, connecting to program synthesis and equality saturation\.
## References
- \[1\]V\. Abbott and G\. Zardini\(2025\)FlashAttention on a napkin: a diagrammatic approach to deep learning io\-awareness\.Note:Derives FlashAttention via Neural Circuit Diagrams with IO\-aware performance modelExternal Links:[Link](https://openreview.net/forum?id=pF2ukh7HxA),2412\.03317Cited by:[§9\.5](https://arxiv.org/html/2607.04240#S9.SS5.p1.2)\.
- \[2\]V\. Abbott\(2024\)Neural circuit diagrams: robust diagrams for the communication, implementation, and analysis of deep learning architectures\.arXiv preprint arXiv:2402\.05424\.Note:Foundation for the diagrammatic scheme used in FlashAttention on a NapkinCited by:[§9\.5](https://arxiv.org/html/2607.04240#S9.SS5.p1.2)\.
- \[3\]J\. F\. Allen\(2022\)Energy transduction and the mind: mitochondria in brain function\.The Biochemist44\(4\),pp\. 8–13\.Cited by:[§8\.6](https://arxiv.org/html/2607.04240#S8.SS6.p1.1)\.
- \[4\]U\. Alon\(2007\)Network motifs: theory and experimental approaches\.Nature Reviews Genetics8\(6\),pp\. 450–461\.Cited by:[1st item](https://arxiv.org/html/2607.04240#S1.I1.i1.p1.1),[§2\.1](https://arxiv.org/html/2607.04240#S2.SS1.p1.1),[§4\.3](https://arxiv.org/html/2607.04240#S4.SS3.SSS0.Px2.p1.9)\.
- \[5\]AnimaWorks Contributors\(2025\)AnimaWorks: autonomous agent runtime with priming and heartbeat consolidation\.Note:[https://github\.com/xuiltul/animaworks](https://github.com/xuiltul/animaworks)Operational runtime for autonomous agents with developmental primingCited by:[1st item](https://arxiv.org/html/2607.04240#S12.I3.i1.p1.1)\.
- \[6\]S\. Ao, Z\. Gao, and D\. Simchi\-Levi\(2026\)Delegation in multi\-agent systems: when and how can delegating to networked agents beat the single best agent?\.arXiv preprint arXiv:2603\.26993\.Note:Proves that without exogenous signals, delegated multi\-agent networks are dominated by centralized baselinesCited by:[§11](https://arxiv.org/html/2607.04240#S11.SS0.SSS0.Px1.p3.8)\.
- \[7\]B\.J\. Aubrey, A\. Strasser, and G\.L\. Kelly\(2018\)How does p53 induce apoptosis and how does this relate to p53\-mediated tumour suppression?\.Cell Death & Differentiation25,pp\. 104–113\.Cited by:[§3\.7](https://arxiv.org/html/2607.04240#S3.SS7.p4.1)\.
- \[8\]B\. Banu\(2026\)Counterexample\-guided reflective evolution: a gepa/operon certificate experiment\.Note:Preprint\. Tests whether framing a reflective\-evolution \(GEPA\) evaluator as a binary certificate plus per\-window obligations converges in fewer mutations than a graded scalar reward of comparable information density\. The predeclared gate is not cleared—a null result for the binarization hypothesis—and anN=10N=10replication shows the obligation\-bearing arms have near\-zero variance while the graded\-scalar arm ranges over a factor of five\. The certificate’s measured value is therefore variance reduction, not faster convergence\.Cited by:[3rd item](https://arxiv.org/html/2607.04240#S8.I5.i3.p1.1)\.
- \[9\]B\. Banu\(2026\)Do biological structural guarantees earn their complexity? empirical benchmarks for biologically\-inspired agent reliability\.arXiv preprint arXiv:2605\.15225\.Note:Empirical companion tobanu2026harness\. Tests three biologically\-grounded reliability features against naive non\-biological alternatives and ablated controls across 10M\+ data points \(1,000 trials×\\times10 seeds\), plus a real\-sentence\-embedding follow\-up and a Gemma 4 27B end\-to\-end run\. Findings: metabolic priority gating serves 100% of critical operations under bursty load vs 39\.8% for a flat budget counter \(Δ=\+0\.602\\Delta=\+0\.602,p<0\.001p<0\.001\); autoinducer quorum sensing reaches 0% false\-positive rate with 71–87% true\-positive rate at 40% agent compromise, an operating point unreachable by majority voting or independent detection; Bayesian two\-signal stagnation detection wins on convergence discrimination only with real embeddings \(96% vs 2–40% naive\), a conditional guarantee gated on embedding quality\. The cross\-benchmark pattern: biological design earns its complexity through*mechanism\-level structural guarantees*, not algorithmic sophistication — state\-integrity guarantees \(DNA repair\) are deterministic, while behavioral/output\-layer guarantees show honest limitations with capable models\. This is the empirical grounding for whichKnow\\mathrm\{Know\}\-level certificates ofbanu2026harnessactually deliver; cited by operon\-langgraph\-gates v0\.1\.0 \(§4\.1 integrity, §4\.3 real\-embedding stagnation\)\.External Links:2605\.15225Cited by:[§2\.7](https://arxiv.org/html/2607.04240#S2.SS7.p7.1),[2nd item](https://arxiv.org/html/2607.04240#S4.I6.i2.p1.1),[3rd item](https://arxiv.org/html/2607.04240#S5.I1.i3.p6.2),[2nd item](https://arxiv.org/html/2607.04240#S8.I5.i2.p1.1),[4th item](https://arxiv.org/html/2607.04240#S8.I5.i4.p1.1),[§8\.7](https://arxiv.org/html/2607.04240#S8.SS7.p4.1)\.
- \[10\]B\. Banu\(2026\)Harness engineering as categorical architecture\.arXiv preprint arXiv:2605\.12239\.Note:Frames agent harness engineering through the categorical Architecture triple\(G,Know,Φ\)\(G,\\mathrm\{Know\},\\Phi\)from the ArchAgents framework\. The four pillars of agent externalization \(Memory, Skills, Protocols, Harness\) map onto the triple’s components: Memory as coalgebraic state, Skills as operad\-composed objects, Protocols as syntactic wiringGG, and the full Harness as the Architecture itself\. Structural guarantees—integrity gates, quality\-based escalation, supported convergence checks—areKnow\\mathrm\{Know\}\-level certificates whose preservation is structural replay: compiler functors targeting Swarms, DeerFlow, Ralph, Scion, and LangGraph preserve three named certificate types by identity/replay\. Companion to the operon\-langgraph\-gates v0\.1\.0 wedge and the L1/L2 cert hooks in operon\-ai v0\.38\+\.External Links:2605\.12239Cited by:[§2\.3](https://arxiv.org/html/2607.04240#S2.SS3.p1.8)\.
- \[11\]M\. Boreale\(2023\)Coalgebras for bisimulation of weighted automata\.Logical Methods in Computer Science19\.Cited by:[Theorem 1](https://arxiv.org/html/2607.04240#Thmtheorem1.p1.7.7)\.
- \[12\]N\. S\. Chandel\(2014\)Mitochondria as signaling organelles\.BMC Biology12,pp\. 34\.Note:Revisited in 2024 work on metabolic\-epigenetic couplingCited by:[§8\.1\.1](https://arxiv.org/html/2607.04240#S8.SS1.SSS1.p1.2)\.
- \[13\]P\. de los Riscos, F\. Corbacho, and M\. A\. Arbib\(2026\)Working paper: towards a category\-theoretic comparative framework for artificial general intelligence\.arXiv preprint arXiv:2603\.28906\.Note:Category\-theoretic framework \(ArchAgents\) for comparing agent architecturesCited by:[§11](https://arxiv.org/html/2607.04240#S11.SS0.SSS0.Px1.p3.8),[§2\.3](https://arxiv.org/html/2607.04240#S2.SS3.p1.8),[§8\.7](https://arxiv.org/html/2607.04240#S8.SS7.p2.1),[§8\.7](https://arxiv.org/html/2607.04240#S8.SS7.p3.1)\.
- \[14\]E\. Debenedetti, G\. Severi, N\. Carlini, S\. Coull, and F\. Tramèr\(2024\)AgentDojo: a dynamic environment to evaluate prompt injection attacks and defenses for llm agents\.InNeurIPS,Cited by:[§10\.15](https://arxiv.org/html/2607.04240#S10.SS15.SSS0.Px4.p1.1)\.
- \[15\]E\. Dupoux, Y\. LeCun, and J\. Malik\(2026\)Why AI systems don’t learn and what to do about it\.arXiv preprint arXiv:2603\.15381\.Cited by:[§10\.10](https://arxiv.org/html/2607.04240#S10.SS10.SSS0.Px7.p1.1),[item 4](https://arxiv.org/html/2607.04240#S12.I2.i4.p1.1),[§2\.7](https://arxiv.org/html/2607.04240#S2.SS7.p1.1),[§6\.3](https://arxiv.org/html/2607.04240#S6.SS3.SSS0.Px4.p1.1),[§6\.3](https://arxiv.org/html/2607.04240#S6.SS3.SSS0.Px5.p2.2)\.
- \[16\]R\. Fagin, J\. Y\. Halpern, Y\. Moses, and M\. Y\. Vardi\(1995\)Reasoning about knowledge\.MIT Press\.Cited by:[§2\.5](https://arxiv.org/html/2607.04240#S2.SS5.p1.1),[§7](https://arxiv.org/html/2607.04240#S7.p2.1),[Definition 7](https://arxiv.org/html/2607.04240#Thmdefinition7.p1.12.12)\.
- \[17\]T\. Feng, X\. Wang, and W\. Zhu\(2026\)Self\-evolving embodied AI\.National Science Review\.Cited by:[§2\.7](https://arxiv.org/html/2607.04240#S2.SS7.p5.1)\.
- \[18\]B\. Fong and D\. I\. Spivak\(2019\)Seven sketches in compositionality: an invitation to applied category theory\.Cambridge University Press\.Cited by:[§2\.2](https://arxiv.org/html/2607.04240#S2.SS2.p1.1),[§9\.5](https://arxiv.org/html/2607.04240#S9.SS5.p2.1)\.
- \[19\]K\. Friston\(2010\)The free\-energy principle: a unified brain theory?\.Nature Reviews Neuroscience11\(2\),pp\. 127–138\.Cited by:[3rd item](https://arxiv.org/html/2607.04240#S5.I1.i3.p1.4)\.
- \[20\]J\. Y\. Halpern and Y\. Moses\(1990\)Knowledge and common knowledge in a distributed environment\.Journal of the ACM37\(3\),pp\. 549–587\.Cited by:[§2\.5](https://arxiv.org/html/2607.04240#S2.SS5.p1.1),[2nd item](https://arxiv.org/html/2607.04240#S7.I1.i2.p1.2)\.
- \[21\]J\. Hao, X\. Dai, Y\. Qin, and P\. S\. Yu\(2026\)Brain\-inspired graph multi\-agent systems for LLM reasoning\.arXiv preprint arXiv:2603\.15371\.Cited by:[§10\.10](https://arxiv.org/html/2607.04240#S10.SS10.SSS0.Px7.p3.1),[item 3](https://arxiv.org/html/2607.04240#S12.I2.i3.p1.1),[§2\.7](https://arxiv.org/html/2607.04240#S2.SS7.p2.1),[§6\.3](https://arxiv.org/html/2607.04240#S6.SS3.SSS0.Px4.p2.1)\.
- \[22\]D\. Jiang, Y\. Li, S\. Wei, J\. Yang, D\. Kang, X\. Hu, A\. Kishore, Q\. Li, A\. Zhao, F\. Chen, and B\. Li\(2026\)Anatomy of agentic memory: taxonomy and empirical analysis of evaluation and system limitations\.arXiv preprint arXiv:2602\.19320\.Cited by:[§2\.7](https://arxiv.org/html/2607.04240#S2.SS7.p3.1)\.
- \[23\]C\. P\. Kempes, D\. H\. Wolpert, Z\. Cohen, and J\. Pérez\-Mercader\(2017\)The thermodynamic efficiency of computations made in cells across the range of life\.Philosophical Transactions of the Royal Society A375\(2109\)\.Cited by:[§3\.7](https://arxiv.org/html/2607.04240#S3.SS7.p1.1)\.
- \[24\]Y\. Kim, K\. Gu, C\. Park, C\. Park, S\. Schmidgall, A\. A\. Heydari, Y\. Yan, Z\. Zhang, Y\. Zhuang, Y\. Liu, M\. Malhotra, P\. P\. Liang, H\. W\. Park, Y\. Yang, X\. Xu, Y\. Du, S\. Patel, T\. Althoff, D\. McDuff, and X\. Liu\(2025\)Towards a science of scaling agent systems\.arXiv preprint arXiv:2512\.08296\.Note:Google Research, Google DeepMind, and MITCited by:[item 11](https://arxiv.org/html/2607.04240#S12.I1.i11.p1.4),[§12](https://arxiv.org/html/2607.04240#S12.SSx3.p3.1),[§7\.2](https://arxiv.org/html/2607.04240#S7.SS2.SSS0.Px13.p1.5),[§7\.2](https://arxiv.org/html/2607.04240#S7.SS2.SSS0.Px17.p1.9),[§7\.2](https://arxiv.org/html/2607.04240#S7.SS2.SSS0.Px19.p1.1),[§7\.2](https://arxiv.org/html/2607.04240#S7.SS2.SSS0.Px5.p1.9),[§7\.2](https://arxiv.org/html/2607.04240#S7.SS2.SSS0.Px9.p1.5),[§7\.2](https://arxiv.org/html/2607.04240#S7.SS2.p1.1),[§7\.3](https://arxiv.org/html/2607.04240#S7.SS3.p3.2),[Table 3](https://arxiv.org/html/2607.04240#S7.T3)\.
- \[25\]J\. C\. Knight and N\. G\. Leveson\(1986\)An experimental evaluation of the assumption of independence in multiversion programming\.IEEE Transactions on Software EngineeringSE\-12\(1\),pp\. 96–109\.Note:Landmark empirical refutation of the failure\-independence assumption underlying N\-version programming: 27 versions developed independently from a common specification, subjected to one million tests, failed on common inputs substantially more often than statistical independence predicts\. Grounds the correlated\-error case of the conjunctive verification gate—redundant checkers suppress error only to the extent their failure modes are uncorrelated\.Cited by:[1st item](https://arxiv.org/html/2607.04240#S4.I5.i1.p1.1),[§4\.3](https://arxiv.org/html/2607.04240#S4.SS3.SSS0.Px2.p1.9)\.
- \[26\]K\. Kulkarni and J\. Michels\(2012\)Temporal features in SQL:2011\.ACM SIGMOD Record41\(3\),pp\. 34–43\.Cited by:[§2\.6](https://arxiv.org/html/2607.04240#S2.SS6.p1.1),[§2\.7](https://arxiv.org/html/2607.04240#S2.SS7.p8.1)\.
- \[27\]M\. Lin, Z\. Zhang, H\. Lu, H\. Liu, X\. Tang, Q\. He, X\. Zhang, and S\. Wang\(2026\)MemMA: coordinating the memory cycle through multi\-agent reasoning and in\-situ self\-evolution\.arXiv preprint arXiv:2603\.18718\.Cited by:[§2\.7](https://arxiv.org/html/2607.04240#S2.SS7.p4.1)\.
- \[28\]M\. Lynch and G\. K\. Marinov\(2015\)The bioenergetic costs of a gene\.Proceedings of the National Academy of Sciences112\(51\),pp\. 15690–15695\.Cited by:[§3\.7](https://arxiv.org/html/2607.04240#S3.SS7.p1.1)\.
- \[29\]Y\. Ma, Y\. Liu, X\. Yang,et al\.\(2026\)Scaling coding agents via atomic skills\.arXiv preprint arXiv:2604\.05013\.Cited by:[§2\.7](https://arxiv.org/html/2607.04240#S2.SS7.p7.1),[§8\.7](https://arxiv.org/html/2607.04240#S8.SS7.p4.1)\.
- \[30\]L\. Marom, S\. Tibbits, G\. Zardini, and M\. J\. Buehler\(2026\)A category\-theoretic framework from biological mechanics to engineered stimulus\-response systems\.arXiv preprint arXiv:2604\.26367\.Note:Defines category Dyn of stimulus\-response dynamical systems with subcategories Nat/Art, implementation functor F: Nat to Art, specification space Spec with projection pi, compilation functor E: Spec to Comp; instantiated on hygromorphic pinecone to 4D\-printed bilayer pipelineExternal Links:2604\.26367Cited by:[§1\.2](https://arxiv.org/html/2607.04240#S1.SS2.p1.3),[§2\.2](https://arxiv.org/html/2607.04240#S2.SS2.p1.1),[§3\.6](https://arxiv.org/html/2607.04240#S3.SS6.p2.1)\.
- \[31\]H\. R\. Maturana and F\. J\. Varela\(1980\)Autopoiesis and cognition: the realization of the living\.Reidel\.Cited by:[§2\.4](https://arxiv.org/html/2607.04240#S2.SS4.p1.1)\.
- \[32\]R\. Milo, S\. Shen\-Orr, S\. Itzkovitz, N\. Kashtan, D\. Chklovskii, and U\. Alon\(2002\)Network motifs: simple building blocks of complex networks\.Science298\(5594\),pp\. 824–827\.Cited by:[§1\.1](https://arxiv.org/html/2607.04240#S1.SS1.p1.1),[§2\.1](https://arxiv.org/html/2607.04240#S2.SS1.p1.1)\.
- \[33\]G\. Nakov and F\. N\. Forsberg\(2021\)Quantitative polynomial functors\.InConference on Algebra and Coalgebra in Computer Science \(CALCO\),Cited by:[§3\.7](https://arxiv.org/html/2607.04240#S3.SS7.p2.1)\.
- \[34\]N\. Niu and D\. I\. Spivak\(2023\)Polynomial functors: a mathematical theory of interaction\.arXiv preprint arXiv:2312\.00990\.Cited by:[§2\.2](https://arxiv.org/html/2607.04240#S2.SS2.p1.1)\.
- \[35\]K\. G\. Osagie\(2024\)Swarms: the enterprise\-grade production\-ready multi\-agent orchestration framework\.Note:[https://github\.com/kyegomez/swarms](https://github.com/kyegomez/swarms)Multi\-agent orchestration with sequential, concurrent, and graph workflowsCited by:[1st item](https://arxiv.org/html/2607.04240#S12.I3.i1.p1.1)\.
- \[36\]S\. G\. Patil, T\. Zhang, X\. Wang, and J\. E\. Gonzalez\(2023\)Gorilla: large language model connected with massive apis\.arXiv preprint arXiv:2305\.15334\.Cited by:[§10\.15](https://arxiv.org/html/2607.04240#S10.SS15.SSS0.Px4.p1.1)\.
- \[37\]M\. Picard and O\. S\. Shirihai\(2018\)The mitochondrial information processing system: a new model of mitochondrial\-nuclear communication\.Trends in Neurosciences41\(4\),pp\. 206–208\.Note:Revisited and expanded in 2022\-2024 workCited by:[§3\.8](https://arxiv.org/html/2607.04240#S3.SS8.SSS0.Px5.p1.1),[§8\.4](https://arxiv.org/html/2607.04240#S8.SS4.p3.1)\.
- \[38\]M\. Picard and O\. S\. Shirihai\(2022\)Mitochondria as multifaceted regulators of cell death\.Cell Metabolism34\(11\),pp\. 1607–1627\.Cited by:[§8\.6](https://arxiv.org/html/2607.04240#S8.SS6.p1.1)\.
- \[39\]R\. T\. Snodgrass\(2000\)Developing time\-oriented database applications in SQL\.Morgan Kaufmann\.Note:Foundational treatment of valid time, transaction time, and bi\-temporal data modelsCited by:[§2\.6](https://arxiv.org/html/2607.04240#S2.SS6.p1.1),[§2\.7](https://arxiv.org/html/2607.04240#S2.SS7.p8.1),[§7\.1](https://arxiv.org/html/2607.04240#S7.SS1.p1.3)\.
- \[40\]D\. I\. Spivak\(2021\)Learners’ languages\.Compositionality3\(4\)\.Cited by:[§1\.2](https://arxiv.org/html/2607.04240#S1.SS2.p1.3),[§2\.2](https://arxiv.org/html/2607.04240#S2.SS2.p1.1)\.
- \[41\]D\. Vagner, D\. I\. Spivak, and E\. Lerman\(2015\)Algebras of open dynamical systems on the operad of wiring diagrams\.Theory and Applications of Categories30\(51\),pp\. 1793–1822\.Cited by:[§2\.2](https://arxiv.org/html/2607.04240#S2.SS2.p1.1),[§4](https://arxiv.org/html/2607.04240#S4.p1.1)\.
- \[42\]G\. J\. Vermeij\(2023\)The evolution of power: a new understanding of the history of life\.Princeton University Press\.Cited by:[§8\.6\.1](https://arxiv.org/html/2607.04240#S8.SS6.SSS1.p1.1)\.
- \[43\]C\. H\. Waddington\(1957\)The strategy of the genes\.Allen & Unwin\.Note:Introduced the concept of the “epigenetic landscape”Cited by:[§8\.1](https://arxiv.org/html/2607.04240#S8.SS1.p4.1)\.
- \[44\]X\. Wang, J\. Wei, D\. Schuurmans, Q\. Le, E\. Chi, S\. Narang, A\. Chowdhery, and D\. Zhou\(2023\)Self\-consistency improves chain of thought reasoning in language models\.InInternational Conference on Learning Representations \(ICLR\),Note:Samples a diverse set of reasoning paths for a chain\-of\-thought prompt and marginalizes to the most consistent final answer—an agreement threshold over stochastic samples\. The accurate software correspondent for quorum\-style consensus \(majority agreement across noisy signals\), distinct from Mixture\-of\-Experts routing, which dispatches to specialists rather than voting\.External Links:2203\.11171Cited by:[2nd item](https://arxiv.org/html/2607.04240#S4.I6.i2.p1.1)\.
- \[45\]J\. Wei, X\. Yi, M\. Zhang, Y\. Liu, X\. Li, X\. Wang, Y\. Zhou, Y\. Li, Y\. Wang, Z\. Li,et al\.\(2022\)Chain\-of\-thought prompting elicits reasoning in large language models\.arXiv preprint arXiv:2201\.11903\.Note:Available at:[https://arxiv\.org/abs/2201\.11903](https://arxiv.org/abs/2201.11903)External Links:[Document](https://dx.doi.org/10.48550/arXiv.2201.11903)Cited by:[§2\.4](https://arxiv.org/html/2607.04240#S2.SS4.p1.1)\.
- \[46\]C\. Zhou, H\. Chai, W\. Chen,et al\.\(2026\)Externalization in LLM agents: a unified review of memory, skills, protocols and harness engineering\.arXiv preprint arXiv:2604\.08224\.Cited by:[§2\.7](https://arxiv.org/html/2607.04240#S2.SS7.p6.1),[§8\.7](https://arxiv.org/html/2607.04240#S8.SS7.p1.1)\.Similar Articles
Agentic Patterns
A comprehensive research guide from Veso detailing the universal architecture patterns that have converged across major AI agent systems (Claude Code, OpenAI Codex, Gemini CLI, etc.), presenting 8 postulates for building production-grade agentic systems.
Neuro-Agentic Control: A Deep Learning-based LLM-Powered Agentic AI Framework for Controlling Security Controls
This paper introduces a neuro-agentic control framework that couples an LLM-based planner (Gemini 2.5 Flash-Lite) with a pre-trained Time-Series Foundation Model (TimesFM) for physics-grounded autonomous defense in industrial IoT. A Counterfactual Physics Injection mechanism ensures only safe, non-hallucinated actions are executed, achieving zero invalid actions and better breach prevention than LSTM and TCN baselines on the SWaT dataset.
Critique of Agent Model
This paper critiques current AI agent systems, distinguishing between agentic (external scaffolding) and agentive (internalized) systems, and proposes the Goal-Identity-Configurator (GIC) architecture for general-purpose agent models with endogenously developed capabilities, along with insights on safety and controllability.
Agentic Coding is a Trap
The article argues that agentic coding, where AI generates code and humans act as orchestrators, is a trap due to increased system complexity, skill atrophy, and vendor lock-in. It highlights the negative impact on developer learning and critical thinking, contrasting this new abstraction with historical programming shifts.
@Saboo_Shubham_: https://x.com/Saboo_Shubham_/status/2062220865643982875
The article explains three patterns of Generative UI (Controlled, Declarative, Open-ended) and how CopilotKit implements them via the AG-UI protocol for building dynamic agent-driven interfaces.