Projection Engineering projects uncertain Claims into an auditable graph

Image: generated with Google Gemini.

An automated system says that July’s rent was not paid.

Producing that sentence is cheap. Verifying it is not. Someone must inspect the lease, identify the registered accounts, check the relevant period, distinguish settled from pending transfers, ask whether another debt could have received the payment, and determine which policy allows the result to trigger a notice or eviction.

The answer is one sentence. Its verification boundary reaches across the world.

This is the structural problem of generative AI. It is not merely that a model can be wrong. A plausible Claim can now be produced almost instantly, while checking it may require reconstructing the records, assumptions, transformations, policies, and omissions behind it.

Verification became more expensive than generation.

Making the model more fluent does not repair that inversion. Neither does attaching a citation if nobody can tell which part of the source supports which proposition, which version was used, or what must be reopened when the source changes.

Mature institutions solved analogous problems by inserting a responsibility layer between observation and calculation. Physics built metrology. Law built legal fact-finding. AI has fragments of both, but no recognized discipline responsible for turning open-world Claims into premises that a decision may safely use.

I call that missing responsibility Projection Engineering.

The Missing Layer Between a Record and a Decision

Metrology Does Not Trust the Needle

A sensor displaying a number has not yet produced a trustworthy measurement. A measurement also needs a unit, calibration history, traceability chain, uncertainty, and a declared range of validity. NIST emphasizes that metrological traceability belongs to a measurement result, not merely to an instrument carrying a calibration sticker (Metrological Traceability: Frequently Asked Questions and NIST Policy).

That surrounding machinery makes failure diagnosable. If a structure fails, an investigator can walk from the reported value through transformations and calibrations to the original observation. Arithmetic alone does not provide that path. Metrology makes a number capable of bearing institutional weight.

An LLM answer usually arrives without an equivalent chain. It rarely identifies the observation from which each Claim began, what was lost in transformation, where the Claim remains valid, or which dependent decisions must be reopened after a correction. It is a moving needle without a scale or calibration certificate.

Law Does Not Trust the Allegation

A court does not encounter the past itself. It encounters allegations, testimony, records, exhibits, and expert reports. Through evidence rules, burdens, standards of proof, and authorized procedure, legal fact-finding decides which competing Claims may serve as premises in a particular case. The distinction between substantive reality and formal legal truth is an old problem of judicial fact-finding (Formal Legal Truth and Substantive Truth in Judicial Fact-Finding).

Separating fact-finding from rule application also separates errors. A record can be collected incorrectly. A proposition can be admitted under the wrong standard. A correct premise can meet an incorrectly implemented rule. A correct conclusion can be executed against the wrong person. Each failure belongs to a different layer and requires a different repair.

Metrology turns observations into traceable values. Law turns a contested record into findings usable for one judgment. Both refuse to let raw input flow silently into consequential calculation. That is the missing layer in AI decision systems.

Fact Means Accepted Fact

The name Projection Engineering needs a strict boundary. It does not promise to manufacture absolute truth.

In Projection Engineering, Fact means Accepted Fact.

An Accepted Fact is a Claim authorized for use as a premise in a particular decision under an explicit purpose, scope, reference time, standard of proof, and policy.

Three objects must remain distinct:

  • Claim: an assertion or observation submitted by an identified source.
  • Accepted Fact: a Claim admitted as a premise by an authorized procedure.
  • Conclusion: a result computed from Accepted Facts and rules.

An Accepted Fact is a Claim with a documented institutional status, not reality captured in a field. Truth remains the aim: the proposition should correspond to reality. What the system can preserve is narrower and operational—who asserted what, from which record, at what time, through which transformation; who accepted or rejected it, under which authority; and what followed from that bounded premise set.

Projection Engineering does not own truth. It engineers the boundary around a decision so that another person can inspect and contest it.

AI Is Already Closed—Over Tokens

A frozen Transformer is closed in a useful computational sense. Fix its weights, input, runtime, and decoding conditions, and its forward pass can be replayed. The architecture computes what token should come next (Attention Is All You Need). It is closed over token probabilities, not over reality.

That distinction explains both its resilience and its limit. A training corpus can contain X and not-X. Classical deduction must manage such a contradiction because unrestricted explosion can make anything follow. A language model does not explode: contradictory passages alter a distribution rather than invalidate a proof, because entailment is not the primitive operation being performed.

For the same reason, attention and softmax contain no rule guaranteeing that true premises preserve truth through generation. Modern systems can reduce confident errors, but hallucination persists in part because training and evaluation may reward guessing over acknowledging uncertainty (Why Language Models Hallucinate).

We take a calculation about language and use it as a judgment about the world. The closure exists, but one layer below where responsibility is needed. Projection Engineering supplies a different closure: it declares which Claims, policies, authorities, and times define the world of this decision. Reproducible rules can then compute inside it.

The Metre Shows What Closure Can Do

In 1983, the 17th General Conference on Weights and Measures defined the metre as the distance light travels in vacuum during 1/299,792,458 of a second, fixing the speed of light at exactly 299,792,458 m/s within the SI definition (Resolution 1 of the 17th CGPM (1983)).

The value did not become exact because humanity finally measured nature without uncertainty. An authorized community moved it across a boundary: from a quantity to refine into part of the system’s definition. Measurements beneath that boundary became more precise because the boundary was explicit.

This was not a claim to own reality. It was a dated convention adopted by an identifiable authority through a defined procedure and revisable by another procedure. Projection Engineering closes a decision in the same limited sense. It does not close reality. It freezes which Claims may serve as premises here and now, under a named policy and authority.

Where the Analogy Breaks

Metrology is a guide, not a disguise for unresolved problems.

First, ordinary measurement often benefits from repetition. A payment, consent, inspection, dismissal, or accident may be a one-off event. The closer model is forensic metrology: a single observation must survive an adversarial process through preserved artifacts, chain of custody, documented procedure, and known instrument limits.

Second, numerical uncertainty can often propagate through equations. Unresolved propositions do not yet have an equally general arithmetic. Preserving supported, defeated, and unknown through long derivations without laundering them into false precision remains an open research problem.

Third, declaring a source complete or a policy binding is an exercise of authority. Traceability can reveal that choice, but cannot make it unbiased. Projection Engineering must expose who placed the thumb on the scale; it cannot promise to remove every thumb.

GAF Is Not a List

Storing an Accepted Fact alone destroys the information that made it acceptable. We lose who submitted it, what challenged it, which policy admitted it, and what authority made that policy operative.

The deliverable of Projection Engineering is therefore a Graph of Accepted Facts (GAF).

Records / Observations
        Claims ◀──── Evidence / Counterevidence
  Evaluation + Projection Policy
   Accepted Facts ─────┐
          │             │
          ▼             │
 Rules / Derivations    │
          │             │
          ▼             │
      Conclusions       │
 Provenance ────────────┘

A GAF connects original records, extracted Claims, supporting and defeating evidence, evaluations, policy and authority, Accepted Facts, derivations, conclusions, versions, timestamps, and dependencies. Existing standards already model entities, activities, agents, and provenance relations; PROV-O: The PROV Ontology shows that this vocabulary need not belong to one database product.

Nor must a GAF live in a graph database. A relational database or append-only log is sufficient if it preserves relationships and bidirectional lineage.

  • From a conclusion, an auditor must be able to walk backward through Accepted Facts and Claims to original records.
  • From an invalidated record, the system must be able to walk forward to every Accepted Fact, conclusion, and authorized action that may require reopening.

The first path makes a decision auditable. The second makes correction computable.

One Rent Payment, Three Engineering Problems

Return to the rent dispute. The tenant says the rent was paid. The landlord says it was not received as rent. A bank ledger shows that money moved between their registered accounts during the agreed period, but the memo is blank.

The first task is proposition decomposition:

A payment moved from the tenant's account to the landlord.  [accepted]
That payment discharged this month's rent obligation.       [undetermined]

Transfer and legal allocation are different Claims. If another debt could exist, the first does not entail the second. Choosing to separate them is not clerical work. In a dismissal case, asking whether the stated reason existed, whether procedure was followed, whether the reason justified dismissal, and whether the actor had authority produces different decision graphs from the same records.

This is issue formation, the core craft of Projection Engineering. Whoever frames the propositions determines what can be accepted, defeated, or left unknown. The system must preserve who made that decomposition, for what purpose, under what authority, and which alternatives were excluded. Perfect provenance after biased framing only documents the bias elegantly.

The second problem is absence. Failure to find a payment does not establish nonpayment. The period may be wrong, the search incomplete, the transfer pending, or another institution may hold the record. Absence becomes evidence only after a completeness contract defines what the source promises to contain.

Completeness contract C-04

Declarant: operator of ledger L
Scope: all settled transactions for account A during period P
Excludes: pending transactions and records held by other institutions
Authority: signed policy version V

Only then may absence support negation within that scope. Calling a convenient source complete can turn an unknown case into a decidable one, so the declaration must carry identity, signature, date, version, and authority.

The third problem is repeated human judgment. A person may decide that a transfer from the registered account, within the agreed period, for the exact amount, with no competing debt, counts as rent despite a blank memo. The reusable asset is not that one answer. It is the general judgment behind it.

This is decision preservation, but an example must not silently become precedent. The judgment remains a policy candidate until an authorized person specifies its scope, exceptions, effective time, retroactivity, and revocation conditions. Only then does it become a ratified policy.

From Claim to Authorized Action

Projection Engineering is not a model or storage product. It is the process that projects open-world records into a closed decision world and reopens that world when evidence or policy changes.

Reality
Records / Observations
   │  preservation · calibration · transformation history
Claims
   │  proposition decomposition · source evaluation · conflicts and gaps
Projection
   │  purpose · scope · reference time · proof standard · authority · policy version
GAF
   │  Accepted Facts · provenance · dependencies
Closed Decision World
Deterministic Conclusion
Authorized Action

Every transition can produce a different error:

  • Missing an original record is a collection error.
  • Bad OCR or extraction is a transformation error.
  • Framing the wrong issue or accepting the wrong Claim is a projection error.
  • Computing the wrong conclusion from correct Accepted Facts is a rule error.
  • Applying a correct conclusion to the wrong target is an execution error.

Each demands a different repair. New evidence repairs collection. Reevaluation repairs projection. A corrected rules engine can replay a frozen GAF. Execution failures require cancellation, correction, or compensation—not rewritten facts. Calling every failure “the AI was wrong” makes none of them repairable.

Pay the Cost of Understanding Once

The missing layer is not only a risk. It is also a source of waste. A model reads a contract, resolves the parties, extracts obligations, and answers one question. The next question often pays much of the same interpretation cost again. Retrieval reduces the text loaded, but still moves chunks of prose because the reusable unit remains the document fragment.

Semantic compilation changes that unit. A document is interpreted once into stable propositions with identifiers, sources, temporal scope, and dependencies. Later questions reuse those propositions across prompts, users, and documents. We pay the cost of understanding once, when the Claim enters the system, rather than every time someone asks about it.

Prompt caching cannot replace this layer. A cache preserves bytes and order. A GAF preserves meaning and provenance. A prefix cache may break when order changes; a proposition can combine with Claims extracted elsewhere and serve every decision that depends on it.

Meaningful reuse creates a harder invalidation problem. If a source is corrected, superseded, or exposed as fraudulent, which conclusions must be reopened? A fact cache without provenance is a hallucination cache: it repeats the same mistake faster and with greater confidence.

Lineage is cache invalidation.

The structure that lets a person contest a decision is the same structure that lets a machine recompute only affected conclusions. Accountability and efficiency are not competing features here. They are two uses of the same dependency graph.

The Boundary with Neighboring Disciplines

Projection Engineering is not a replacement for Data, Knowledge, Rule, Prompt, or Context Engineering. It owns the responsibility boundary they currently cross without one accountable custodian.

Data Engineering moves records through source → ingest → transform → store → serve. Projection Engineering asks whether a record qualifies information for use as a premise through record → claim → evaluate → project → GAF. A valid schema can contain a false record.

Knowledge Engineering represents concepts and relationships for machine use. Projection Engineering treats each relationship first as a Claim and records who authorized its use as knowledge in a bounded decision.

Rule Engineering computes conclusions from supplied premises. Projection Engineering constructs and freezes the premise graph on which those rules run.

Prompt Engineering shapes instructions. Context Engineering selects information for computation. Projection Engineering asks the prior question: what Claim is this information, and why may it serve as a premise here?

A better prompt cannot rescue a wrongly accepted premise.

The LLM Is a Worker, Not the Authority

An LLM is a worker inside this process. It can extract candidate Claims from unstructured records, split compound statements, identify conflict, request missing evidence, and translate lineage into readable language.

It is not the authority. Its output is another Claim. Attribution research distinguishes fluent generation from statements supportable by identified sources (Measuring Attribution in Natural Language Generation Models). Research on reasoning faithfulness also shows that generated chain of thought does not reliably function as the causal execution trace of an answer (Making Reasoning Matter: Measuring and Improving Faithfulness of Chain-of-Thought Reasoning).

If the same model extracts a Claim, accepts it, chooses the rule, explains the result, and authorizes action, the pipeline collapses into one opaque generation. A post-hoc narrative is not a provenance record.

Generation may be probabilistic. Fact acceptance, completion, and authority to act must be separately governed.

Statistical Assurance Cannot Explain My Case

The strongest rebuttal is practical. Organizations do not demand a complete derivation trace from every human decision-maker. They monitor aggregate outcomes, quality controls, and sample audits. Why not govern models the same way?

Statistical assurance is useful and often sufficient for improving a system. It still cannot answer the question asked by a person inside a disputed outcome:

What was the premise in my case?

Aggregate accuracy does not reveal which record was wrong, which Claim was accepted, which policy applied, or what new evidence could support an appeal. Population-level assurance and case-level contestability solve different problems.

That distinction defines the scope. Projection Engineering is not for every AI system. It is for systems that make contestable decisions—credit, pay, eligibility, eviction, insurance, medical authorization, and similar actions where a person must be able to inspect and challenge the premise set. The NIST AI Risk Management Framework treats accountability and transparency as lifecycle properties, while Regulation (EU) 2024/1689 requires event logging for high-risk systems.

For low-stakes generation that nobody needs to contest, this machinery may be excessive. Scope is part of the engineering.

The Minimum Contract

A system claiming to practice Projection Engineering should answer yes to all of the following:

  1. Does it distinguish original records from derived Claims and attach source, time, and transformation history to each Claim?
  2. Does it decompose compound Claims into independently contestable propositions and record who framed the issues and why?
  3. Does it preserve conflicting Claims and rejected alternatives rather than deleting them?
  4. Does it distinguish false, unknown, and not found, requiring a completeness contract before turning absence into negation?
  5. Can it trace an Accepted Fact backward to evidence, policy, authority, and version—and an invalidated source forward to affected conclusions?
  6. Can it reproduce the exact GAF and rule snapshot used for a decision and obtain the same conclusion under the same closure?
  7. Can it preserve recurring human judgment as a ratified policy with scope, exceptions, and effective time?
  8. Are Claim acceptance, rule judgment, and authority to act separated, with a procedure to reopen rather than erase a past decision?

If any answer is no, the system is silently promoting a Claim into a Fact somewhere.

Why This Is a New Engineering Discipline

The components already exist: provenance, evidence management, argumentation graphs, truth-maintenance systems, event sourcing, rules engines, audit logs, legal fact-finding, metrology, and closed-world reasoning.

Components are not a responsibility boundary. Databases and ETL existed before Data Engineering cohered as a field. Servers and deployment scripts existed before DevOps. A field forms when recurring failures scattered across organizations are gathered under one accountable role, one class of deliverables, and repeatable verification methods.

No role currently owns this question from end to end:

At what moment, by whose authority, and under which policy did a record from reality become an Accepted Fact usable in a decision?

Data engineers own pipelines. Knowledge engineers own representation. ML engineers own models. Domain experts explain rules. Operators handle exceptions. Between them, fact acceptance dissolves into cleaning code, prompts, application logic, model inference, and undocumented habit.

Projection Engineering does not claim that every component is novel. It proposes a new engineering discipline because the boundary itself needs an owner, a deliverable, and a deterministic way to test whether its promises were kept.

Make Verification Cheap Again

The open world never stops. New records arrive, testimony changes, sensors are recalibrated, and policies are amended. A system that waits for complete reality will never act. A system that hides uncertainty will act without accountability.

Projection Engineering chooses a narrower contract:

  • Preserve Claims instead of erasing disagreement.
  • Say Accepted Fact whenever Fact means an authorized premise.
  • Connect every acceptance to evidence, policy, authority, time, and scope.
  • Never turn unknown into false without a completeness contract.
  • Freeze the decision world and rules actually used.
  • Reproduce the conclusion from the same closed inputs.
  • Preserve recurring judgment as an explicit, ratified policy.
  • Reopen decisions when evidence changes instead of rewriting the past.

It does not own truth, eliminate bias, or make machines infallible. It makes the limited world used for a decision visible enough to inspect, challenge, replay, and repair.

Mathematics became socially powerful not because it answered every question, but because people who were absent from a derivation could inspect what followed from declared premises. Metrology made measurements bear weight by surrounding numbers with traceability. Law made judgment possible without replaying the past by separating allegations from accepted premises.

AI already has arithmetic. What it lacks is the institution around the arithmetic.

The goal of Projection Engineering is simple:

Make verification cheap again.

Reality gives us Claims.

Decisions require Accepted Facts.

Projection Engineering projects Claims into an auditable Graph of Accepted Facts.

  • Truth Is Not Discovered — why open reality gives us Claims while bounded institutional worlds can produce operative facts
  • From Claims to GAF — the technical architecture for projecting Claims into an auditable graph
  • Fluency Is Not Truth — why persuasive language must be replaced by observable evidence and checks

Sources