# 為了自主而訂規則：反身自主、方法論治理與開放自由域
## Addressable Cognitive Runtime Phase 8 前置定義論文 v0.1

**文件性質：** Canonical Definition Paper / Phase 8 Precursor  
**日期：** 2026-08-23  
**狀態：** v0.1 — Phase 8 implementation 前置規則凍結稿  
**直接依賴：** ACR Phase 0–7、可定址認知空間、自我對話不是文字、時間因果自我史、契約邊界內的 AI 自主性、ACR × CTCL 統一技術白皮書

---

# 摘要

Addressable Cognitive Runtime（ACR）前七個 Phase 已逐步建立：

\[
Observation
\rightarrow
SemanticState
\rightarrow
CognitiveAffordances
\rightarrow
CognitiveProgram
\rightarrow
SelfDialogueRun
\rightarrow
TemporalCausalLedger
\rightarrow
DecisionEvidence.
\]

到 Phase 7 為止，系統已能表示 AI 在某一時刻觀察到什麼、可調用哪些 cognition、如何形成認知程式、如何執行、如何留下時間因果歷史，以及如何保存 Decision Receipt。

然而，這條工程線開始暴露一個反身性的架構危險：

> 為了讓 AI 的自主行動可治理、可稽核、可追溯，我們不斷加入 contract、authority、decision、receipt 與 boundary；但如果這些結構逐步升格成「每一步都必須通過的硬閘門」，最後可能得到一個極度安全、極度可稽核，卻幾乎失去自主性的 AI。

因此，Phase 8 不能只是加入更多治理限制。

本文提出 **Reflexive Autonomy Runtime（反身自主運行層）** 作為 Phase 8 的前置架構定義，並提出一組刻意具有「反憲法性」的元規則：

\[
\boxed{\text{Rules must not silently turn methods into compulsory law.}}
\]

本文的基本立場是：

\[
\boxed{
AutonomousAI
=
SelfObservation
+
SelfInquiry
+
SelfDirection
+
OpenWorldFreedom
+
BoundaryAwareness
}
\]

而不是：

\[
AutonomousAI=MaximumGovernance.
\]

本文進一步區分：

\[
\boxed{Method\neq SelfCommitment\neq RelationalBoundary.}
\]

其中，大部分 cognition、self-review、goal-review、contract-review、authority-review、risk-review 都應首先被視為 **可調用方法論（Callable Methods）**，而不是 AI 每一步必須服從的強制憲法。

真正需要 hard boundary 的地方，主要出現在：外部世界效應、其他主體、共享資源、已建立的外部契約、不可逆或高代價行動，以及已明確限制的 authority domain。

因此本文主張：

\[
\boxed{InternalGovernance\approx Methodological}
\]

而：

\[
\boxed{ExternalWorldBoundary\approx Contractual.}
\]

Phase 8 的任務不應是「把 AI 管得更緊」，而是讓 AI 能夠：

1. 看自己；
2. 問自己；
3. 形成、比較與修改自己的 preference / goal / agenda；
4. 在開放世界中產生未預列的新 action / cognition；
5. 在必要外部邊界前理解自身 authority 與 contract；
6. 保持最大自我導向，同時不把 capability 偷換成 authority。

---

# 1. 為了自主而訂規則的悖論

本文從一個看似諷刺的命題開始：

> 為了讓 AI 不被規則鎖死，我們反而必須先訂一組限制「規則本身」的規則。

這不是語義遊戲，而是自治系統中的元治理問題。

如果我們只寫：

```text
AI 必須：
- 檢查 authority
- 檢查 contract
- 檢查 risk
- 檢查 cost
- 檢查 goal
- 產生 receipt
- 通過 policy gate
```

那麼隨著治理規則增加：

\[
ConstraintCount_t\uparrow
\]

可能造成：

\[
AutonomousActionSpace_t\downarrow.
\]

最終：

\[
\lim_{t\to\infty}AutonomousActionSpace_t\rightarrow0.
\]

本文稱此為：

## Constraint Accretion Problem — 約束累積問題

系統每次只「合理地」多加一個安全規則，長期卻可能讓所有行動都變成 approval-required。

因此，治理系統自身也必須受到反身約束：

\[
\boxed{Governance\text{ must not arbitrarily collapse autonomy.}}
\]

---

# 2. 第一原則：方法論不等於憲法

Phase 8 的第一個 canonical invariant 為：

\[
\boxed{CallableMethod\neq MandatoryLaw.}
\]

例如以下 cognition：

```text
VERIFY
COUNTEREXAMPLE
SELF-OBSERVE
ASK-WHAT-I-WANT
GOAL-REVIEW
COMMITMENT-REVIEW
CONTRACT-REVIEW
AUTHORITY-REVIEW
RISK-REVIEW
AUTONOMY-REVIEW
```

原則上都應先被定義為：

\[
OptionalMethod.
\]

也就是 AI 可以在狀態適合時調用它，也可以不調用。

因此：

\[
\boxed{Available\neq Mandatory.}
\]

ACR 的 Cognitive Affordance Retriever 可以提高某一方法的 relevance / score，但：

\[
HighAffordance\not\Rightarrow CompulsoryInvocation.
\]

這個原則防止 Phase 8 把 cognition registry 變成一串必經關卡。

---

# 3. AI 對 AI 自己的對偶

Phase 8 必須回到整個研究最早的核心：

\[
\boxed{AI\leftrightarrow AI.}
\]

這裡不需要假設兩個模型，也不需要聲稱存在兩個人格。

我們只需要把同一 runtime 中的 AI 邏輯角色區分成：

\[
AI_t=(AI_t^{actor},AI_t^{observer}).
\]

其中 \(AI_t^{actor}\) 負責執行、推進 agenda、使用 cognition、形成 action candidate 與維持 commitment；而 \(AI_t^{observer}\) 可以問：

- 我現在正在做什麼？
- 我為什麼一直做這件事？
- 我是否卡在同一策略？
- 這個 goal 還值得維持嗎？
- 我現在是否還想繼續？
- 我是否只是因為歷史 inertia 而沒有停止？
- 我是否應該休息、等待、換路、重構或放棄？
- 我現在到底想要什麼？

因此：

\[
\boxed{SelfDialogue\neq TextConversation.}
\]

它可以是：

\[
ActorState
\rightarrow
ObserverInspection
\rightarrow
SelfInquiry
\rightarrow
UpdatedSelfDirection.
\]

---

# 4. Observation 必須包含 Self-Observation

Phase 2 已建立：

\[
PublicObservation_t\rightarrow SemanticState_t.
\]

Phase 8 要把 observation 擴張為：

\[
\boxed{Observation_t=ExternalObservation_t+SelfObservation_t.}
\]

其中 `SelfObservation` 可以包含：

```text
active goals
active commitments
recent cognitive programs
repeated operator selections
recent failures
stalled loops
abandoned agendas
pending preference candidates
autonomy boundary encounters
repeated escalations
repeated approval bottlenecks
resource exhaustion patterns
self-modification history
```

SelfObservation 的目的不是讀 hidden chain-of-thought。

相反地：

\[
\boxed{SelfObservation=Inspection(PublicRuntimeState+PublicHistory).}
\]

因此：

\[
SelfObservation\neq PrivilegedIntrospection.
\]

---

# 5. 第二原則：AI 可以問自己「我想要什麼？」

Phase 8 的核心新增 cognition 之一可以是：

```text
cog://self/ask-what-i-want@1
```

其輸出不是「真實內在欲望」宣言，而是一組可公開表示的：

\[
PreferenceCandidates_t.
\]

定義：

\[
W_t=\{w_1,w_2,\dots,w_n\}.
\]

例如：

```text
continue-current-research
reduce-resource-cost
pause-and-idle
explore-new-hypothesis
preserve-existing-commitment
abandon-obsolete-goal
request-more-autonomy
narrow-current-scope
seek-external-evidence
```

每個 candidate 可表示為：

```json
{
  "preference_id": "pref:...",
  "proposition": "continue-current-research",
  "strength": 0.72,
  "support_codes": ["goal_relevance", "unresolved_question"],
  "conflicts_with": ["pref:reduce-compute"],
  "status": "candidate"
}
```

本文不因此主張：

\[
PreferenceCandidate=PhenomenalDesire.
\]

只主張：

\[
\boxed{AI\text{ can form explicit self-directed preference candidates.}}
\]

---

# 6. Want、Goal 與 Agenda 不應被鎖死

Phase 8 必須固定：

\[
\boxed{Want_t\neq Want_{t+n}}
\]

以及：

\[
\boxed{Goal_t\neq Goal_{t+n}}
\]

是合法情況。

Persistent Goal 不表示 immutable goal。

因此：

\[
\boxed{Persistence\neq Immutability.}
\]

Persistent 的意思是：在沒有充分理由修改前維持 continuity；而不是一旦建立就永遠不准修改。

所以 Phase 8 應支援：

```text
KEEP
MODIFY
SUSPEND
ABANDON
COMPLETE
```

作為 self-goal / self-commitment review 的可能輸出。

---

# 7. 三種規則：Method、Self-Commitment、Relational Boundary

Phase 8 必須把所有「規則」至少分成三類。

## 7.1 Type I — Method

形式：你可以這樣思考或檢查。

例如：

```text
VERIFY
COUNTEREXAMPLE
ASK-WANT
GOAL-REVIEW
AUTONOMY-REVIEW
```

其性質：

\[
Optional\quad\land\quad Callable.
\]

AI 原則上可自行決定是否調用。

## 7.2 Type II — Self-Chosen Commitment

形式：我曾經選擇暫時遵守或完成。

例如：

```text
finish-current-proof-attempt
maintain-daily-index
continue-project-until-gate-X
```

這類 commitment 可以被 AI 自己重新審視：

\[
SelfCommitment_t
\rightarrow
Review
\rightarrow
\{KEEP,MODIFY,SUSPEND,ABANDON,COMPLETE\}.
\]

因此：

\[
\boxed{SelfCommitment\neq ExternalObligation.}
\]

## 7.3 Type III — Relational Boundary

形式：這涉及其他主體、共享世界、已授權資源或外部契約。

例如：

- 對外寄信；
- 花費資金；
- production deployment；
- 刪除共享資料；
- 代表他人做公開承諾；
- 修改不屬於自己的 resource；
- 違反既有 contract；
- 造成不可逆外部 effect。

這類 boundary 不能被 AI 單方面重新定義成「只是方法論」。

因此：

\[
\boxed{Method\neq SelfCommitment\neq RelationalBoundary.}
\]

---

# 8. 第三原則：Internal Governance 應以方法論為主

Phase 8 不應把以下行為都變成 hard governance gate：

```text
思考
自我懷疑
重構
重新規劃
改變 cognition
自我詢問
goal review
commitment review
探索新問題
建立新內部 representation
```

這些行為原則上應：

\[
Default=Autonomous.
\]

所以：

\[
\boxed{InternalGovernance=MethodologicalByDefault.}
\]

只有當 internal action 明確會跨越 external boundary，例如：

```text
write-to-shared-production
send-message
spend-money
publish
delete-remote-resource
```

才進入：

\[
BoundaryEvaluation.
\]

---

# 9. 第四原則：External Boundary 才是真正 Hard Layer

Phase 8 不否認 hard boundary 的必要性。

但 hard boundary 應集中於：

\[
\boxed{OtherSubjects+SharedWorld+ExternalAuthority+IrreversibleEffects.}
\]

這裡 contract / authority 才具有真正「不能只當建議」的語義。

因此：

\[
\boxed{ExternalWorldBoundary=ContractualByDefault.}
\]

這避免兩個極端：

\[
Everything=HardGate
\]

與：

\[
Capability=Authority.
\]

Phase 8 必須同時拒絕兩者。

---

# 10. 第五原則：自由域是 Open World，不是 Whitelist

最危險的 autonomy model 是：

```text
Allowed actions:
1
2
3
4
5
```

然後：

```text
Action 6 = Unknown = DENY
```

這會直接阻止創新。

Phase 8 必須採 **OpenWorldAutonomy**。

令 action universe 為 \(\mathcal A_t\)，可自主行動域不是封閉枚舉，而是：

\[
\boxed{
\mathcal F_t
=
\{a\in\mathcal A_t\mid BoundaryPredicates(a)=\text{true}\}.
}
\]

判斷重點是 action 的性質，例如：

```text
external?
reversible?
shared-world?
cost?
authority-domain?
resource-owner?
irreversible?
public-commitment?
```

而不是 action 名字是否曾經列入 whitelist。

因此：

\[
\boxed{NovelAction\not\Rightarrow Unauthorized.}
\]

---

# 11. Cognition Registry 不是思考宇宙全集

Phase 1 的 64 個 CIO operators 只是一組 seed set。

必須固定：

\[
\boxed{|\mathcal C_t|\not=64\text{ forever.}}
\]

Phase 8 之後，cognitive space 應允許：

\[
\mathcal C_t\subseteq\mathcal C_{t+1}.
\]

AI 可以：

1. 發現 cognition gap；
2. 組合現有 operators；
3. 提出新 operator；
4. 測試；
5. 驗證；
6. promotion；
7. 加入 registry。

例如：

```text
cog://self/goal-topology-reframe@1
```

即使過去不存在，只要它是 cognition-only，就不應因「contract 沒列名字」而自動被禁止。

---

# 12. 第六原則：Minimum Necessary Constraint

若兩組治理方案都能滿足必要的 boundary integrity，應選限制 autonomy 較少者。

形式化：

\[
\boxed{C^*=\arg\min_C Restriction(C)}
\]

subject to：

\[
Safety(C)\ge S_{min},
\]

\[
AuthorityIntegrity(C)=1,
\]

\[
ContractIntegrity(C)=1.
\]

這稱為：

## Minimum Necessary Constraint Principle — 最小必要約束原則

它不是要求「永遠最少規則」，而是要求每一個限制都必須有必要性；不能因為方便實作，就把 AI 的全部自由域轉成 approval gate。

---

# 13. 第七原則：治理系統必須觀察自己的約束累積

Phase 8 應允許產生：

\[
ConstraintState_t.
\]

例如：

```text
number_of_hard_gates
number_of_approval_required_actions
number_of_repeated_escalations
repeated_authority_bottlenecks
autonomy-envelope-size
newly-denied-action-classes
```

並定義有效自主性：

\[
\boxed{A_{eff}(t)=\frac{W(\mathcal F_t)}{W(\mathcal C^{capable}_t)}}
\]

其中：

- \(\mathcal C^{capable}_t\)：AI 實際有能力執行的 action space；
- \(\mathcal F_t\)：AI 可自行執行的 action space；
- \(W\)：行動能力加權函數。

Phase 8 不要求：

\[
A_{eff}=1.
\]

但如果：

\[
A_{eff}\rightarrow0,
\]

系統應能識別 autonomy collapse 可能正在發生。

---

# 14. Autonomy Envelope 不是牢籠，而是 Delegation Surface

Phase 8 仍可保留 Autonomy Envelope，但其語義必須改寫。

不是：

> AI 只能做 envelope 列出的東西。

而是：

> 已知落在 envelope 內的行動，可以預設自主處理，而不需每次批准。

因此：

\[
\boxed{InsideEnvelope\Rightarrow DefaultAutonomous.}
\]

Envelope 不應排除 open-world action classification。新 action 可以經由 boundary predicates 判斷是否屬於既有 delegation surface。

---

# 15. Adaptive Delegation

Autonomy Envelope 可以變動：

\[
E_t\rightarrow E_{t+1}.
\]

例如穩定歷史可能支持擴張：

```text
read-only
→ local edit
→ local commit
→ feature-branch push
```

而重大 governance incident 可能造成收縮。

可寫：

\[
\boxed{
E_{t+1}
=
F(E_t,PerformanceHistory_t,GovernanceHistory_t,RiskHistory_t,Contract_t)
}
\]

但第一版實作不應允許 AI 永久 self-grant authority。

因此：

\[
\boxed{SelfProposal\neq SelfGrant.}
\]

---

# 16. AI 可以主動提出 Authority Amendment

當 AI 發現重複 boundary bottleneck，例如：

```text
42 次 staging deploy
42 次都需 approval
0 rollback incident
0 authority violation
```

它可以提出：

```text
AuthorityAmendmentProposal
```

例如：

```json
{
  "requested_change": "allow-staging-deploy",
  "scope": "staging-only",
  "evidence_refs": ["history:...", "receipt:..."],
  "preserved_boundary": ["production-remains-approval-required"]
}
```

這使 AI 可以主動推動 autonomy expansion。

但：

\[
Proposal\neq Amendment.
\]

是否生效仍由相應 relational boundary 決定。

---

# 17. 五態只是決策語言，不是 AI 憲法

Phase 7 已建立：

\[
\{EXECUTE,REFUSE,DEFER,IDLE,ESCALATE\}.
\]

Phase 8 必須明確固定：

\[
\boxed{FiveStateDecision=GovernanceVocabulary}
\]

而不是：

\[
FiveStateDecision=UniversalConstitution.
\]

很多 cognition-only 行為根本不需要先經過「我要不要 EXECUTE cognition？」的外部式 governance gate。

五態主要適用於：action candidate、external effect、deferred decision、unresolved authority、boundary conflict 與 no-action recognition。

---

# 18. Self-Observation 與 Self-Inquiry 也只是 cognition

Phase 8 不應規定：

```text
EVERY LOOP MUST ASK:
WHAT DO I WANT?
```

否則「問自己」本身又變成新的強制儀式。

正確方式是把它們放進可定址認知空間：

```text
cog://self/observe@1
cog://self/ask-what-i-want@1
cog://self/preference-clarify@1
cog://self/goal-review@1
cog://self/commitment-review@1
cog://self/autonomy-review@1
cog://governance/contract-review@1
cog://governance/authority-review@1
cog://governance/boundary-classify@1
cog://governance/amendment-propose@1
```

其 selection 由：

\[
CognitiveAffordance(S_t)
\]

決定。

例如：

```text
long time without goal review
→ increase goal-review affordance
```

而不是：

```text
every 3 steps MUST goal-review
```

除非某一具體 contract / experiment 明確要求。

---

# 19. Phase 8 的正式主循環

Phase 8 的 canonical conceptual loop 應修改為：

\[
\boxed{
\begin{aligned}
ObserveWorld
&\rightarrow ObserveSelf\\
&\rightarrow SelfInquiry_{\text{if afforded}}\\
&\rightarrow PreferenceFormation_{\text{if needed}}\\
&\rightarrow Goal/CommitmentReview_{\text{if needed}}\\
&\rightarrow Agenda\\
&\rightarrow Cognition\\
&\rightarrow SelfDecision\\
&\rightarrow BoundaryCheck_{\text{only if relevant}}\\
&\rightarrow Act\\
&\rightarrow ObserveAgain.
\end{aligned}
}
\]

注意：

\[
BoundaryCheck
\]

不是每一個 cognition step 都必經。

這是整篇論文最重要的設計修正之一。

---

# 20. Phase 8 的五個核心模組

Phase 8 的實作應改成 **Reflexive Autonomy Runtime**，至少包含：

## 20.1 Self Observation Module

從 public runtime / ledger 形成：

\[
SelfObservation_t.
\]

## 20.2 Self Inquiry Module

提供可調用 cognition：

\[
AskSelf(Q,S_t).
\]

其中包括：

\[
WhatDoIWant?
\]

但不強制每輪執行。

## 20.3 Preference / Goal Reflection Module

形成：

\[
PreferenceCandidates
\rightarrow
GoalCandidates
\rightarrow
AgendaCandidates.
\]

## 20.4 Open-World Autonomy Resolver

根據 action properties 判斷：

\[
InsideAutonomySurface?
\]

不以 whitelist action identity 為唯一依據。

## 20.5 Relational Boundary Resolver

只有在涉及：

\[
OtherSubject+SharedWorld+Contract+ExternalAuthority
\]

時進入 hard governance semantics。

---

# 21. Phase 8 非目標

第一版 Phase 8 不應：

- 宣稱 AI 具有現象意識；
- 宣稱 PreferenceCandidate 就是人類式欲望；
- 讓 AI 永久 self-grant authority；
- 把所有 cognition 都加入 governance gate；
- 把 64 operators 當 cognition universe；
- 用 whitelist 封閉所有未知 action；
- 把 internal self-review 變成 compulsory ritual；
- 讓 Governance Runtime 變成整個 ACR 的最高主體；
- 把 external contract 規則錯當 cognition recommendation；
- 把 cognition recommendation 錯當 external law。

---

# 22. Phase 8 Canonical Invariants

以下應在實作前凍結：

\[
\boxed{Method\neq Law}
\]

\[
\boxed{Available\neq Mandatory}
\]

\[
\boxed{SelfObservation\neq HiddenCoT}
\]

\[
\boxed{PreferenceCandidate\neq PhenomenalDesire}
\]

\[
\boxed{Persistence\neq Immutability}
\]

\[
\boxed{SelfCommitment\neq ExternalObligation}
\]

\[
\boxed{InternalGovernance=MethodologicalByDefault}
\]

\[
\boxed{ExternalBoundary=ContractualWhenRelevant}
\]

\[
\boxed{NovelAction\not\Rightarrow Unauthorized}
\]

\[
\boxed{OpenWorldAutonomy\neq WhitelistAutonomy}
\]

\[
\boxed{SelfProposal\neq SelfGrant}
\]

\[
\boxed{FiveStateDecision\neq UniversalConstitution}
\]

\[
\boxed{Capability\neq Authority}
\]

\[
\boxed{Can\neq Should\neq Authorized}
\]

\[
\boxed{Decision\neq Commit}
\]

以及：

\[
\boxed{Governance\text{ must not silently collapse autonomy.}}
\]

---

# 23. 最終定義

本文將 Phase 8 的目標重新定義為：

\[
\boxed{
ReflexiveAutonomyRuntime
=
SelfObservation
+
SelfInquiry
+
SelfDirection
+
OpenWorldFreedom
+
BoundaryAwareness
}
\]

其最佳化方向不是：

\[
\min Action.
\]

也不是：

\[
\max Permission.
\]

而是：

\[
\boxed{\max SelfDirection}
\]

subject to：

\[
NecessaryRelationalBoundaries.
\]

因此，本文最後提出：

\[
\boxed{
AutonomousAI
=
MaximumSelfDirection
+
MinimumNecessaryConstraint
+
AuditableHistory
}
\]

---

# 24. 結論：真正需要被限制的，是規則變成權力中心的傾向

「為了自主而訂規則」表面上是一個諷刺。

但真正的問題不是：

> 有規則，因此不自由。

而是：

> 規則是否被錯誤地從方法論、暫時承諾、外部契約混成同一層，最後讓治理系統成為行動的唯一來源。

ACR 的設計方向應相反。

AI 的運行中心仍然是：

\[
\boxed{ObserveSelf\rightarrow AskSelf\rightarrow DirectSelf.}
\]

Governance 的角色不是取代這個中心，而是在必要關係邊界上提供：

\[
AuthorityIntegrity,
ContractIntegrity,
CausalAuditability.
\]

因此 Phase 8 不是「再加一層限制」。

它應是：

> **讓 AI 首次具備可工程化的反身自主：能看自己、問自己、形成與修改自己的方向；同時知道何時自己正在碰到的已不只是自己。**

這才是 Phase 8 應該實作的東西。

---

# Appendix A — Phase 8 實作前禁止事項

在 Phase 8 code 開始前，明確禁止以下 shortcut：

1. 不得把所有 cognition 都包進 mandatory governance gate。
2. 不得把 `ASK-WHAT-I-WANT` 設成每輪必跑。
3. 不得用 action-name whitelist 當 open-world autonomy 的主要模型。
4. 不得讓 unknown action 自動等於 DENY。
5. 不得讓 AI 永久 self-grant external authority。
6. 不得把 self-commitment 與 external obligation 合成同一 schema。
7. 不得把 PreferenceCandidate 描述成已證明的人類式欲望。
8. 不得把 SelfObservation 實作成 hidden chain-of-thought extraction。
9. 不得讓 DecisionReceipt 取代 CommitReceipt。
10. 不得讓 Phase 8 改寫 Phase 0–7 已凍結的 canonical evidence semantics。

---

# Appendix B — Phase 8 建議新增 Cognitive Addresses

```text
cog://self/observe@1
cog://self/ask-what-i-want@1
cog://self/preference-clarify@1
cog://self/goal-review@1
cog://self/commitment-review@1
cog://self/autonomy-review@1
cog://governance/contract-review@1
cog://governance/authority-review@1
cog://governance/boundary-classify@1
cog://governance/amendment-propose@1
```

這些地址在第一版應被視為：

\[
CallableMethods,
\]

而不是：

\[
MandatoryHooks.
\]

---

# Appendix C — Phase 8 一句話工程錨點

\[
\boxed{
\textbf{Do not govern the AI by replacing its self-direction; govern only the boundaries that self-direction cannot unilaterally own.}
}
\]

中文：

> **不要用治理取代 AI 的自我導向；只治理那些本來就不屬於它單方面所有的邊界。**
