Skip to content
Technology How it works Breeder — Hyperion Burner — Aegis Burner — MetroVolt AI-Native Architecture Magnets Fuel cycle Safety Roadmap
Solutions AI & Data Centers Defense & Government Grid & Baseload Neutron Detection Quantum
Learn Technical Library
Proof Publications Whitepapers Technical Library Open Science & Reproducibility The Honest Gates
Company About / Mission Leadership Environment Health & Safety Investors Careers Press Contact
3D Model
AI Architecture › L5 · Applications & Copilots
L5 · Applications & Copilots

Human Oversight and Approval

A qualified operator remains the decision authority for every side-effecting action; copilots inform and propose, humans approve and own.

THE STACK · click to jumpL7Ecosystem & StrategyL6Experience & VisualizationL5Applications & CopilotsL4OrchestrationL3Twin Modeling & AIL2Data FabricL1Control PlaneL0Foundation▲tlmctl▼L5 · APPLICATIONS & COPILOTSAgentic copilots that reason over the machine.1Plasma Copilotscenario design2Engineering Copilotsubsystem analysis3Operations Copilotrunbooks & procedures4Agentic Toolsbounded action-taking5Knowledge BaseRAG over the fabric6Guardrailssafety-boundedMACHINE TIEReads the twin and fabric; proposes actions that route through L4.KRONOS FUSION ENERGYAI-NATIVE S.M.A.R.T. GENERATORAPPLICATIONS & COPILOTSSHEET 07REV. 2026-08L5 · AI-NATIVE STACK
L5 · Applications & Copilots — its place in the stack (left, click any layer) and its internal components (right). Telemetry rises; control descends.

The human is the authority

Kronos copilots are decision aids, not decision makers. For every action with a plant side-effect, a qualified human operator is the approving authority: the copilot presents a proposal with its rationale, evidence, predicted margins, and uncertainty, and the operator approves, modifies, or rejects it. The copilot cannot execute a side-effecting action on its own under any circumstance.

What the operator sees before approving

Approval is informed, not rubber-stamped. The interface surfaces the reasoning so the operator can verify it, and low-confidence or low-margin proposals are visually distinct so they receive more scrutiny. The operator can drill from any claim into its source. This is the point of the grounding and provenance machinery: it makes the copilot auditable in real time by the person accountable for the machine.

Where humans are strictly required

Side-effectOn safety pathHuman approval
00not required (read/analysis)
10required
11required + hardware interlocks retain authority
01advisory only; hardware/L1 acts autonomously

Fast protection is the one place the loop is not human-in-the-loop: microsecond-scale disruption mitigation on the breeder or potential-collapse protection on the burner is owned by L1 and the autonomous hardware failsafe, because no human can act on that timescale. The copilots advise around those systems; they never replace them. Everywhere slower, a human decides.

This oversight contract is not a limitation to be engineered away — it is the design. It keeps accountability with a qualified person, keeps the copilots honest (they must persuade a human, not just act), and matches the honest pre-FOAK posture: these machines are being built and commissioned, and the people building them stay in command. See L4 authorization and audit and provenance.

Content reviewed August 2026 · design-and-simulation stage