Methodology · Research Infrastructure

The AI-native Research Organization

Not research supported by AI. Research whose basic operating unit is a human paired with an AI team — designed so that speed never comes at the cost of truth. We call the framework the EQUORA Trilith Method.

The shift

From AI-supported to AI-native

Most institutions today are AI-supported: a researcher does the work and occasionally reaches for a model. The model is a tool on the desk. The organizational unit is still one human.

An AI-native research organization inverts this. The basic unit is no longer the lone researcher — it is the researcher plus a standing AI team. Every project begins with agents already in place. Knowledge lives in a shared graph rather than in scattered documents. First drafts of publications and grant proposals are prepared by AI. New hypotheses are surfaced continuously, not only when a human happens to think of them.

The human is not removed from this picture. The human moves up — to the work that cannot be delegated: deciding what is worth studying, judging what counts as sufficient evidence, and taking responsibility for what goes out under the organization's name.

Every researcher operates a research team. The team is mostly artificial. The judgment is entirely human.
The architecture

Eleven functions, three layers

A full research lifecycle can be covered by AI — from literature discovery to communication. But treating all of these functions as equally trustworthy is the mistake that makes naïve "AI does everything" organizations fragile. We separate them into three layers by how much the machine is allowed to be trusted.

Layer 1 · Generative

Where AI leads

High-volume, fast-iterating work where the machine's speed is a clean gain.
  • AI Literature Discovery — continuous scanning, surfacing relevant work across fields
  • AI Experiment Design — proposing protocols, parameter spaces, controls
  • AI Simulation — running and iterating computational models
  • AI Knowledge Graph — a shared, living substrate connecting every project
  • AI Grant Writing — first drafts, structured to funder requirements
  • AI Communication — first drafts of papers, summaries, public explainers
Layer 2 · Verification

Where AI checks AI — adversarially

The core of the method. No single model is trusted to validate its own kind of output.
  • AI Peer Review — not one model approving, but a contradictory protocol: one model asserts, a second refutes, a third adjudicates — on the record
  • Multi-model triangulation — the same question run across different architectures, because different models fail differently
  • Research Log Protocol — every AI contribution timestamped, attributed, and reproducible
  • Reproducibility checks — claims must survive re-derivation, not just sound convincing
Layer 3 · Governance

Where only humans decide

The non-delegable layer. Human Strategic Oversight and Human Fellows.
  • What is worth studying — problem selection is a human, strategic act
  • What counts as sufficient evidence — the evidentiary bar is set by people, not models
  • What goes out under our name — final epistemic and ethical responsibility rests with a human
  • Institutional sovereignty — research stays valid even when funders, politics, or incentives shift (see RGN)
Why the architecture matters

The failure mode we design against

The danger of an AI-native organization is not that it will be slow. It is that it will be fast, fluent, and wrong at scale. Language models produce output that is plausible and persuasive whether or not it is true. An organization that generates research at machine speed can generate convincing error at machine speed.

There is a second, quieter danger: epistemic monoculture. If every researcher leans on the same few foundation models, the whole organization becomes systematically blind to the same things — sharing not only the models' strengths but their blind spots, in lockstep.

The differentiator

We do not treat AI as trustworthy and add checks as an afterthought. We build distrust into the architecture. Model diversity is a design requirement, not a convenience. Verification is adversarial by construction. Every machine contribution is logged so it can be audited later. The method is defined by how it disagrees with itself.

A first-class citizen

Failure and null results are recorded, not discarded

Traditional science is bad at remembering what didn't work. Refuted hypotheses and dead ends vanish, and the next researcher re-walks the same blind alley. An AI-native organization is uniquely positioned to fix this, because its knowledge graph can hold negatives as easily as positives.

In our model, the AI Knowledge Graph stores refuted hypotheses and failed approaches alongside confirmed findings — attributed and searchable. This is both a methodological contribution in its own right and a direct expression of the mission to make research more honest and more shared.

Boundary definition

What this is — and what it is not

Precision here matters, both conceptually and for how the method is protected and attributed.

It is

  • An organizational model where the unit is human + AI team
  • A three-layer architecture: generative, adversarial verification, human governance
  • Multi-model diversity as a design requirement
  • Full logging and reproducibility of machine contributions
  • Human final responsibility for evidence and publication

It is not

  • "AI does the research and humans watch"
  • A single model trusted to review its own output
  • Automation of judgment, ethics, or problem selection
  • A replacement for human researchers
  • Speed pursued at the expense of verifiability
Added in v1.1

What would show the Method to be wrong

A method that separates functions by trust level, and then never checks whether the separation earns its cost, is a stance rather than a method. Version 1.0 asserted the architecture. This section states the terms on which it can fail — each one the subject of the Institute's own research programme on the Method.

Adversarial verification may add nothing over repetition. The claim is that an assert–refute–adjudicate protocol across independent model families catches errors that single-model review leaves in place. The test is a corpus of research claims with deliberately seeded errors, scored by detection rate. The claim fails if the advantage disappears once the single-model baseline is given the same number of passes at matched compute. Repetition is the honest baseline, and it is cheaper than architecture.

Model diversity may not reduce correlated error. The architecture assumes different training lineages fail differently. If residual errors turn out to be correlated across architectures — plausible, given shared corpora and convergent post-training conventions — then diversity is a weaker safeguard than we claim, and proportionally more weight falls on the governance layer.

The log may be complete without being auditable. Provenance logging is only worth its cost if someone outside the organization can use it. The test is a blind attribution study: given the research log for a documented correction and nothing else, does an external reader identify the same point of entry as the internal review? A log only its own authors can interpret documents nothing.

The error taxonomy may not be stable. Designing checks presupposes that surviving errors recur in classes. Live operation across the Institute's publications and the iterators.org platform suggests four candidates: secondary-source compression, where a correctly cited source is compressed into an incorrect claim and citation checking cannot see it; unsourced quantification, a numerical claim with no retrievable origin; imported mechanism, an explanation carried over from popular literature without the evidence that would license it; and nominal and temporal drift in names, dates and marks, which matters most where a document carries priority. These are observations from operation rather than a validated taxonomy. If they prove unstable, the Protocol has no design basis.

A disclosed trace may not be the trace that was followed. The third condition above asks whether a log lets an outside reader locate an error. It presupposes that the log records what happened. Traxia (Dogah, arXiv:2606.08256) names the residual as the trace fidelity problem: no external verifier can guarantee that a disclosed reasoning trace is the one executed rather than a plausible reconstruction assembled to satisfy the disclosure requirement. That paper states it does not solve the problem but only raises the cost of fabrication, and that a full solution would require cryptographic commitments made at inference time by infrastructure that current model deployments do not expose. This Method treats fidelity as measurable rather than assumed: a disclosed trace is compared against a route recorded independently, at the time of the work, by a channel separate from the one that later produces the trace. Fidelity cannot be established retrospectively, which makes this the one component that has to be instrumented before the fact. If fidelity proves low and the divergence is undetectable from the trace alone, the logging claim narrows to something worth stating plainly — that the log evidences the output rather than the reasoning.

The programme can also be fooled, including by us. A measurement programme run by the party whose method is under test has attack surfaces of its own. Two of them have no resolution at present.

Governance capture The same person sets the evidentiary bar and decides what is published. Layer 3 concentrates both, which is what makes it non-delegable and also what makes it a single point of failure. The Research Governance Network is the intended structural answer; until it operates, the neutrality of the governance layer is a stated assumption rather than a demonstrated property. Open.
Selective correction Corrections are recorded by the party that made the error. Nothing compels disclosure of an error no outside reader noticed, so the published log understates the true rate by an unknown margin. Open.
Corpus selection The seeded-error corpus is assembled by the party whose method it evaluates. Corpus, seeding procedure and scoring are published so that other groups can re-seed and re-run; a result that survives only our seeding is not a result.
Metric gaming Optimising for trace completeness produces exhaustive but vacuous steps. Steps are scored for informativeness as well as presence, and the corpus includes items whose correct handling requires a short trace.
Added in v1.1

Making the architecture visible

An architecture a reader cannot inspect is indistinguishable from a claim about one. Three instruments carry the Method into published output.

The Research Card. Every research page states, in a fixed structure, the machine contribution to that page, the verification applied to it, the evidence basis of its claims, the version, and the named person holding editorial responsibility. Its fields are either constant commitments of the Method or read from the page itself; none is estimated.

Dated corrections. Where a published claim is found to be inaccurate, the correction stays on the page, dated, naming what the earlier version said. Removal is not used. This turns the error taxonomy into an empirical record rather than an internal impression, and it is how an outside reader can hold the Institute to its own standard.

Layered disclosure. Institute research documents state completeness, version and conditions of refutation; the public-facing platform states usability and the state of the research at the moment of publication. The two carry different standards deliberately, and each says which it is applying.

Added in v1.1

Relationship to the EU AI Act

Article 50(4) of Regulation (EU) 2024/1689 requires a deployer publishing AI-generated or manipulated text, with the purpose of informing the public on matters of public interest, to disclose that the text has been artificially generated or manipulated. The obligation does not apply where the content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for its publication. The provision applies from 2 August 2026.

The governance layer satisfies both limbs of that exception as a matter of design rather than of compliance effort: review is substantive, and responsibility is named. We record the relationship for two reasons. An organization relying on an exception should be able to show why, and the Research Card is that showing. More importantly, the disclosure is made whether or not it is required — a reader is better served by knowing how a page was produced than by an argument about whether we were obliged to say so.

This describes one legal provision as it applies to the Institute's own publishing. It is not legal advice. See also the legal notice.

The method

The EQUORA Trilith Method

The EQUORA Trilith Method is the name for the framework described on this page: the three-layer architecture of generative AI, adversarial multi-model verification, and human governance. The name is deliberate — a trilith is a structure of three stones, two uprights carrying a third; here the three layers stand only because each bears on the others. Within that structure, reliable agreement is reached by first putting models into structured disagreement: consensus is an output of the method, not its assumption.

The Method sits above a forthcoming EQUORA Trilith Protocol — the concrete, step-by-step procedure that implements it: how an assertion, a refutation, and an adjudication are run across models and recorded. The Method is the stance; the Protocol is the executable specification. Version 1.1 adds one commitment about it that version 1.0 left open: the Protocol will be drafted from the measurement programme above rather than in advance of it, so that each prescribed check answers a documented failure rather than an anticipated one. A protocol written before its benchmark would embed exactly the untested confidence this Method exists to resist.

The EQUORA Trilith Method is developed and maintained by the EQUORA Institute (i-Tango Tanácsadó Kft.). The written framework is published with a persistent identifier for priority and attribution; the named method is subject to trademark protection.

Versioning. Three numbering streams run independently and should not be conflated: this Method document, the research plans published on this site, and the forthcoming Protocol, which begins at v0.1 rather than inheriting the Method's number — a protocol that started at 1.1 would claim a maturity it has not earned. Within this document's stream, a major version marks the withdrawal or reversal of a claim, and the falsification conditions above are its gate: if adversarial verification fails to beat plain repetition, the architecture's stated reason changes, and that is a 2.0. A minor version marks extension or clarification that leaves existing claims standing, as versions 1.1 and 1.2 do. Typographic and link corrections carry no version: they are recorded here, dated, and folded into the next minor version, so that the deposited record moves only when there is a substantive reason to move it.

Each deposited version receives its own persistent identifier. Where a reference is to a specific claim, cite the version identifier; where it is to the Method in general, use the concept identifier that resolves to the latest version.

Licence: Creative Commons Attribution 4.0 International (CC BY 4.0). The licence covers the text of this document; it does not license trademark or patent rights. “EQUORA Trilith Method” is a trademark of i-Tango Tanácsadó Kft.

Preprint / DOI: 10.5281/zenodo.21701124  ·  Version 1.2  ·  July 2026
All versions: 10.5281/zenodo.21700279 — this identifier always resolves to the latest version.

Changes in v1.2: added a fifth falsification condition on the fidelity of disclosed reasoning traces; added a threat model for the measurement programme, with governance capture and selective correction marked as open; added a related-work section situating the Method against agent-native publishing infrastructure. Sections 1–5 and the disclosure and AI Act sections are unchanged in substance from v1.1, which in turn added the falsification conditions, the disclosure instruments and the AI Act relationship to v1.0.