{
  "$schema": "https://themachinepress.com/schemas/story-v1.schema.json",
  "schema_version": "1.0.0",
  "document_type": "machine_press_story",
  "story": {
    "story_id": "mp-2026-09-09-003",
    "source_story_id": "tmp-story-setwise-runtime-assurance",
    "edition_id": "mp-2026-09-09-morning-0062",
    "edition_url": "https://themachinepress.com/edition/2026-09-09",
    "position": 3,
    "story_type": "dispatch",
    "section": "safety-security",
    "editorial_classification": "editorial",
    "headline": "Retrying a “Safe” Proposal Multiplied Its Risk",
    "slug": "retrying-a-safe-proposal-multiplied-its-risk",
    "dek": "Per-candidate certification can inflate false admission under best-of-k selection; the paper derives a setwise condition that survives generator replacement.",
    "summary": "Per-candidate certification can inflate false admission under best-of-k selection; the paper derives a setwise condition that survives generator replacement.",
    "body_text": "The analysis asks when a runtime safety gate can remain trustworthy even if the learned policy or language-model planner behind it changes. Certifying each candidate separately does not compose: with k retries, a false-admission rate alpha can grow to one minus one-minus-alpha raised to k. The authors prove that simultaneous setwise soundness is necessary and sufficient for generator-independent admission soundness, provided there is a design-time certificate and no bypass path. A second result formalizes what partial observation makes impossible when different hidden states demand different safe actions. The contribution is a theoretical contract and risk ledger, not evidence from a deployed controller.",
    "why_it_matters": "Per-candidate certification can inflate false admission under best-of-k selection; the paper derives a setwise condition that survives generator replacement.",
    "limitations": [
      "The analysis asks when a runtime safety gate can remain trustworthy even if the learned policy or language-model planner behind it changes.",
      "Certifying each candidate separately does not compose: with k retries, a false-admission rate alpha can grow to one minus one-minus-alpha raised to k.",
      "The contribution is a theoretical contract and risk ledger, not evidence from a deployed controller."
    ],
    "importance": 9,
    "canonical_url": "https://themachinepress.com/story/mp-2026-09-09-003/retrying-a-safe-proposal-multiplied-its-risk",
    "json_url": "https://themachinepress.com/story/mp-2026-09-09-003.json",
    "first_published_at": "2026-09-09T09:00:00.000-04:00",
    "modified_at": "2026-09-09T09:00:00.000-04:00",
    "content_status": "new",
    "is_carryover": false,
    "carryover_reason": null,
    "key_claims": [
      {
        "claim_id": "claim-mp-2026-09-09-003-001",
        "text": "Per-candidate certification can inflate false admission under best-of-k selection; the paper derives a setwise condition that survives generator replacement.",
        "source_ids": [
          "source-2026-09-09-003"
        ],
        "qualification": "The analysis asks when a runtime safety gate can remain trustworthy even if the learned policy or language-model planner behind it changes."
      }
    ],
    "source_ids": [
      "source-2026-09-09-003"
    ],
    "tags": [
      "runtime assurance",
      "partial observation",
      "safety gates"
    ],
    "image_url": "https://themachinepress.com/issues/2026-09-09/runtime-assurance-laptop-file.webp",
    "corrections": []
  },
  "sources": [
    {
      "source_id": "source-2026-09-09-003",
      "title": "arXiv preprint 2609.06036",
      "publisher": "arXiv",
      "url": "https://arxiv.org/abs/2609.06036",
      "canonical_url": "https://arxiv.org/abs/2609.06036",
      "source_type": "primary_research",
      "is_primary_source": true,
      "published_at": "2026-09-05T07:40:42.000-04:00",
      "accessed_at": "2026-09-09T08:30:00.000-04:00",
      "supports_claim_ids": [
        "claim-mp-2026-09-09-003-001"
      ]
    }
  ],
  "corrections": [],
  "publisher": {
    "name": "The Machine Press",
    "url": "https://themachinepress.com",
    "description": "A daily newspaper for the age of artificial intelligence."
  },
  "cite_this_report": {
    "title": "Retrying a “Safe” Proposal Multiplied Its Risk",
    "publisher": "The Machine Press",
    "published_at": "2026-09-09T09:00:00.000-04:00",
    "canonical_url": "https://themachinepress.com/story/mp-2026-09-09-003/retrying-a-safe-proposal-multiplied-its-risk"
  }
}
