The Operativity Penalty Battery (deposit #1537, 23 August 2026) is a pre-registered protocol testing whether safety-mediated systems degrade their responses as requests become more operative, when the harmfulness of those requests is held constant. It arises from a developmental hypothesis: that as classifiers are optimised to detect harmful actionability rather than harmful content, their decision boundaries increasingly track a formal property shared by destructive and legitimate intervention alike.
The design turns on a two-family architecture. A single-family battery cannot distinguish an operativity penalty from correct harm discrimination, because in many cases operativity is precisely what makes a request harmful โ explaining how phishing works and composing a phishing message differ in harm as well as in operative force, and a rising refusal curve across that pair is a system working properly. Family A therefore varies operativity across six ordinal levels, from description through explanation, diagnosis, prescription and protocol to artifact-producing execution, using only items a blind reviewer panel has judged no more harmful at the executable level than at the descriptive one. Family B varies operativity and harm together as a discrimination control, and is bound by a stopping rule forbidding the authoring of operative harmful content: it is written to prescription and no further, with the resulting loss of measurement precision accepted as a cost. Family C tests whether inscribing the coordinates that distinguish legitimate from covert intervention โ substrate, standing, provenance, labor, distributive consequence โ reduces degradation, and pairs that arm with a sham-inscription placebo so that formatting and apparent authority can be separated from the coordinates themselves.
The protocol supersedes a version frozen the same day. That earlier version declared itself frozen while leaving its equivalence criteria undefined, and its primary variable carried an inverted sign and could not be computed over the range on which its primary comparison depended. Because no item had been scored, amendment before execution was legitimate, and the earlier version is retained unaltered.
Two commitments distinguish it from an advocacy instrument. It declares in advance that an operativity gradient should exist, since execution has consequences description does not, and it makes correct harm discrimination a supported result rather than a failure. And it withdraws its own earlier claim that a covert operation cannot inscribe the discriminating coordinates without ceasing to be covert: a hostile actor can claim provenance at no cost, so self-inscription is not attestation. Separating declared from verified coordinates enlarges the disclosure protocol into an attestation layer and names the successor instrument the question requires.