Safety

Governance

Governance decides how a consequential capability is assessed, who may use it, who can stop work, and how disagreements are resolved. Potomac’s governance is still being developed. This page sets out the proposed structure and marks what has and has not been adopted.


Capability assessment

Capability assessment

The practical significance of a result depends on more than a qubit count. Review should consider reliability, runtime, hardware assumptions, required expertise, repeatability, and whether a result materially changes what others could accomplish.

A logical circuit improvement is different from an experiment on a device. Both are different from a production-scale key recovery. Each can be scientifically useful without establishing the next. Reports should identify which claim is being made and what remains untested.

Additional review should be triggered when a finding materially lowers barriers to misuse, exposes an unexpected class of systems, or invalidates an assumption used in earlier safety decisions. Such reviews must be based on the actual capability and its context. A fixed calendar or a single headline metric is insufficient.

Controlled experiments should preserve enough evidence to investigate alternative explanations, including classical shortcuts, access to known answers, or errors in an evaluator. Consequential claims should be open to independent technical replication under suitable conditions.


Research access

Access for AI systems and hardware

Research agents and external compute providers are part of the safety boundary. A model should not receive unrestricted authority to select third-party targets, handle recovered secrets, or initiate asset transfers. Tool access, job scope, and approval requirements need to reflect the consequences of the action.

The same principle applies to collaborators. Agreements for hardware access, compiler integration, or joint evaluation should identify the permitted workload and the handling of sensitive outputs. Portability across providers should not become a way to evade restrictions or repeat an experiment that has been stopped for review.

The detailed access controls remain part of the operating framework to be established. Public copy distinguishes implemented safeguards from planned controls.


Oversight and accountability

Decision responsibility

For consequential cases, the proposed decision record identifies who approves the scope, who can stop work, how disagreements are escalated, and who can authorize resumption. Recording those responsibilities together makes a decision contestable and prevents an unresolved objection from disappearing between teams.

A future accountability record should distinguish research results, controls adopted, outstanding risks, and planned improvements. Significant policy changes should be dated and explained. Where a claim is corrected, the correction should remain discoverable alongside the original publication.

Scope approval
Who approves what the work may do, on which systems, with which data.
Stop authority
Who can halt affected work, and on what grounds.
Escalation
How an objection travels upward and is recorded when it is not resolved.
Resumption
Who can authorize a stopped activity to continue, and what evidence they need.

Independent review

Independent review

Review of consequential research should include the technical ability to challenge a claim and the independence to question whether an action should proceed. Relevant perspectives include cryptography, quantum computing, security operations, claims governance, and public-interest concerns.

The company will publish the remit and appointment process of any formal review body when it exists. Until then, this framework is not evidence of an established advisory board or external approval. Reviewers need access to enough evidence to disagree meaningfully, with appropriate handling of confidential material.


Incidents and concerns

Incidents and concerns

Unexpected capabilities, unauthorized jobs, exposed secrets, leaked research artifacts, and incorrect results each require a response. Before sensitive operations begin, the program needs named responsibility for stopping affected work, preserving evidence, limiting further exposure, and deciding when work can resume.

The process should provide a way for employees and outside researchers to raise concerns without retaliation. It should also identify when affected parties or appropriate coordinators need to be informed.

For now, research enquiries go to the technical contact. Do not send private keys, seed phrases, or confidential recovery evidence through an ordinary website contact link. A secure intake mechanism and handling policy will be established before any such materials are solicited.


Policy status

Policy status

This framework is original editorial and policy work informed by published guidance. It is not a legal determination, a certification, or an adopted policy of the organizations referenced.

Adopted
Research on synthetic keys and authorized experiments; dated, sourced public evidence; reports that separate measured, simulated, and estimated results.
Proposed
Coordinated-disclosure process, publication categories, capability-review triggers, access controls for agents and providers, decision records, incident handling.
Not yet defined
Recovery authority, claims rules, custody, fees and disposition, the review body and its appointment, secure intake.

Further reading

These references inform the framework. They do not represent endorsement of Potomac or adoption of its proposed recovery program.