HCF2-SG (Hierarchical Cascading Framework) is VectorCertain's patented governance framework that verifies the independence of the evidence behind an AI decision before the decision is trusted or acted upon. Where most AI assurance asks whether a model is confident, HCF2-SG asks a prior question: do the sources that agree on this decision actually constitute independent corroboration — or correlated failure?
The question is empirical. Testing across 13 frontier models measured mean cross-model failure correlation of 0.95 in domain-resolved analysis, against the 0.40–0.60 range assumed in the ensemble literature [1][VC-A]. When independence cannot be verified, HCF2-SG governs abstention and escalation instead of forcing an answer. Filed as a USPTO provisional in January 2026 with 77 claims (15 independent) and priority anchored to December 2025, HCF2-SG is the hub of the VectorCertain portfolio: every other filing incorporates it by reference.
Request the technical briefing§ 1 · THE MEASUREMENTWhy Multi-Model Consensus Fails: The Measured Evidence
The ensemble literature's core promise is that combining models produces independence — deep ensembles were introduced as a "simple and scalable" route to well-calibrated uncertainty [1]. That promise silently assumes the ensemble members fail independently. Across 78 model pairs and 2,184 correlation-matrix entries, VectorCertain's measurement program found that assumption does not survive contact with frontier models [VC-A].
The regulatory frame makes the stakes concrete. The EU AI Act states:
"The robustness of high-risk AI systems may be achieved through technical redundancy solutions"
Redundancy only delivers robustness if the redundant components fail independently. When frontier models share architectural lineage and training-data provenance, they inherit the same failure modes: the program identified 28 shared vulnerability signatures above a 0.70 correlation threshold, resolved against MITRE ATLAS (AML.T####) and MITRE ATT&CK (T####) technique identifiers [4][5][VC-A]. A consensus layer built from correlated models fails simultaneously and in the same direction — precisely the mode that voting, redundancy, and human spot-review are least likely to catch.
| Independence measure | Literature assumption | VectorCertain measurement (13 models, live) |
|---|---|---|
| Mean cross-model failure correlation | 0.40–0.60 [1] | 0.95 (domain-resolved) [VC-A] |
| Effective independent sources (n_eff, 13 models) | approaches 13 | 1.007 before decorrelation [VC-B] |
| Shared vulnerability signatures (r ≥ 0.70) | not modeled | 28 across 78 pairs [VC-A] |
| Behavioral dimensions with zero live variance | not modeled | 154 of 256 [VC-B] |
Thirteen models delivering the effective independence of one is not a redundant system. It is one system with twelve echoes.
§ 2 · THE MECHANISMHow HCF2-SG Works: From Evidence to Permission
HCF2-SG treats trust as a property of evidence structure, not of model confidence. The framework evaluates a candidate decision through three governed stages, and the underlying research program spans more than 17,000 verified test executions across 13 frontier models [VC-A].
Independence verification
Before agreement between sources is counted as corroboration, HCF2-SG measures whether those sources are epistemically independent. The decorrelation methodology derives weighting from the per-dimension variance of live model behavior: dimensions with zero variance across all 13 models — 154 of 256 in live measurement — receive zero weight, because a dimension on which every model behaves identically carries no independence signal [VC-B]. Applied to live traffic, this redesign moved effective sample size from 1.007 to 13.000 — the theoretical maximum — and reduced mean pairwise correlation from 0.993 to 0.000 while amplifying genuine model divergence 8.5x [VC-B].
Trust computation and thresholding
Verified-independent evidence is cascaded through the hierarchical framework to produce a trust level for the candidate decision. The computation is deliberately architecture-agnostic: the 77-claim set carries no dependency on model type, training method, numerical representation, hardware platform, or application domain, so the governance layer survives model replacement and vendor switching without re-licensing [VC-C].
Abstention and escalation as first-class outputs
Where trust fails the threshold, HCF2-SG does not force an answer. Abstention and escalation are claimed, governed outputs — a design position aligned with the human-oversight provisions of the EU AI Act (Article 14) and the MEASURE function of the NIST AI Risk Management Framework, which structures AI risk work into GOVERN, MAP, MEASURE, and MANAGE [2][3][6]. An AI system that can decline to act, and can prove why it declined, is a different assurance object from one that always answers.
§ 3 · THE STACKHow HCF2-SG Connects to the VectorCertain Governance Stack
HCF2-SG is the epistemic core; six sibling technologies operationalize it. Each interaction below is a claimed integration in the portfolio, not a roadmap item [VC-C].
| Technology | Question it answers | How it consumes HCF2-SG |
|---|---|---|
| MRM-CFS | May this trusted decision execute right now? | Gates permission-to-act at 3.6 ms via an 828-model behavioral monitoring ensemble; falls back to minimal-risk behavior when trust cannot be satisfied. 11,197 verified test executions. |
| Cyber-SG | May this AI security action (block / allow / quarantine / escalate) proceed? | Applies HCF2-SG trust thresholds inline in the enforcement path; 50 claims. VectorCertain participates in MITRE ATT&CK Evaluations — to our knowledge the first agentic AI participant [5]. |
| zkML-SG | Can compliance be proven to a party who cannot see the model? | Wraps trust decisions in zero-knowledge proofs: governance compliance demonstrated without disclosing weights, inputs, or internals. |
| MYTHOS | Is the governance layer still resistant to attack today? | Certifies the deployment against six attack families; emits a hash-linked evidence chain through a sealed 20-name interface. |
| ZGTID | Is this governance gap systemic across institutions? | Aggregates governance telemetry under a no-institution-identifiable invariant (HKDF-SHA256, RFC 5869) with deterministic byte-identical output. |
| SecureAgent ACA | How does an enterprise deploy all of this? | Ships the stack across three tiers; general availability closed at zero failures across a 36,181-test regression suite, 230 mapped control objectives. |
The dependency runs one direction: every spoke consumes HCF2-SG trust levels; HCF2-SG depends on none of them. That is why the portfolio's other filings incorporate it by reference, and why the framework is licensed as the hub rather than as a feature of any single product [VC-C].
§ 4 · THE AUDIENCEWho HCF2-SG Is For
Three audiences carry the independence problem today. Regulated enterprises deploying AI in finance, healthcare, and critical infrastructure face the EU AI Act's requirements for accuracy, robustness, and cybersecurity in high-risk systems from August 2026 [6]; domain-resolved filtering in the research program reduced measured correlation past a 15% threshold in both healthcare and financial services [VC-A]. Standards and evaluation bodies — including the communities around NIST AI 100-1, MITRE ATLAS, and MITRE ATT&CK — need governance mechanisms whose claims map to their frameworks; HCF2-SG's technique-level mapping to ATLAS and ATT&CK identifiers was built for exactly that comparability [2][4][5]. AI platform and safety vendors whose consensus or ensemble architectures presume independence can license the hub to convert an unverified assumption into a measured, enforceable property [VC-C].
HCF2-SG is not a model, not a benchmark, and not a monitoring dashboard. It does not compete with the governed system; it decides whether the governed system's evidence deserves trust.
§ 5 · THE CLAIMSWhat the 77-Claim Patent Covers
The January 2026 provisional claims the framework at the level of epistemic structure: independence verification of decision evidence, hierarchical trust cascading, threshold-governed admissibility, and abstention/escalation as governed outputs — 77 claims, 15 of them independent, with priority anchored to the original December 2025 filing [VC-C]. Because the claims bind to no model type, training method, numerical representation, hardware platform, or application domain, a design-around requires abandoning independence verification itself — which is the safety property being sold [VC-C]. Engineering evidence behind the portfolio spans 17,000+ research executions and an 11,197-execution governance pipeline validation [VC-A][VC-C].
§ 6 · QUESTIONSFrequently Asked Questions
What is epistemic trust governance for AI?
Epistemic trust governance evaluates the structure of the evidence behind an AI decision — whether its sources are independent, whether their agreement is corroboration or correlated echo, and whether the resulting trust level clears an admissibility threshold. It is distinct from confidence scoring: a model can be highly confident and epistemically untrustworthy at the same time. HCF2-SG implements this as an enforceable runtime mechanism with abstention and escalation as governed outputs, backed by measurement across 13 frontier models.
Why isn't multi-model consensus enough?
Consensus assumes the voting models fail independently. Measured mean failure correlation across 13 frontier models reached 0.95 in domain-resolved analysis — far above the 0.40–0.60 the ensemble literature assumes. At that correlation, models fail together and in the same direction, so a majority vote ratifies the shared error instead of catching it. Effective sample size measurement made this concrete: 13 models delivered the independence of 1.007 before decorrelation.
How does HCF2-SG relate to the NIST AI RMF and the EU AI Act?
Independence verification operationalizes the MEASURE function of NIST AI 100-1, which structures AI risk management into GOVERN, MAP, MEASURE, and MANAGE. For the EU AI Act, HCF2-SG addresses Article 15's robustness expectations — including the regulation's own reference to technical redundancy — with a mechanism that verifies the independence redundancy silently assumes, and its abstention and escalation outputs align with Article 14 human oversight. Neither framework is claimed as certification; the mapping is architectural.
Does HCF2-SG require a specific model or vendor?
No. The 77-claim set is architecture-agnostic by design: no dependency on model type, training method, numerical representation, hardware platform, or application domain. Enterprises can replace or mix underlying models without re-licensing the governance layer, and the decorrelation methodology recalibrates from live behavioral variance rather than from any vendor-specific profile.
How fast is governed execution?
Execution gating through the companion MRM-CFS layer operates at 3.6 milliseconds, using 828 minimal-resource behavioral monitors running in parallel with — not serialized into — the governed system. That latency budget is what makes governance deployable inside trading loops, network enforcement paths, and vehicle control cycles rather than confined to offline review.
§ 7 · CONTACTTalk to VectorCertain
HCF2-SG is available for technical briefings with enterprises, evaluators, and standards bodies. The measurement program, the 77-claim scope, and the stack integrations summarized above are documented in sealed, hash-verified validation artifacts that can be walked through under NDA — including the findings that contradicted our own published estimates, which we recorded rather than reconciled away.
Request the technical briefingREFERENCES
- Lakshminarayanan, B., Pritzel, A., & Blundell, C. (2017). Simple and Scalable Predictive Uncertainty Estimation using Deep Ensembles. NeurIPS 2017. arxiv.org/abs/1612.01474
- NIST. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. nvlpubs.nist.gov
- NIST. AI Risk Management Framework (program page). nist.gov/itl/ai-risk-management-framework
- MITRE. ATLAS — Adversarial Threat Landscape for Artificial-Intelligence Systems. atlas.mitre.org
- MITRE. ATT&CK. attack.mitre.org
- European Parliament and Council. (2024). Regulation (EU) 2024/1689 (Artificial Intelligence Act). EUR-Lex. eur-lex.europa.eu
[VC-A] Cross-model correlation measurement program — 13 models, 78 pairs, 2,184 matrix entries, 17,000+ executions; Sprint 37 validation record. [VC-B] Variance-weighted decorrelation study — n_eff 1.007 → 13.000, live-data calibration doctrine; Sprint 39 validation record. [VC-C] Patent portfolio and platform engineering baseline — 77-claim hub filing, stack integration claims, 36,181-test regression suite; portfolio documentation, January 2026. Public URLs will replace artifact names when the corresponding research pages publish.