rcpt_994d1ed0625c486cMethodological Disclosure: This is an internal engineering sensitivity analysis and physical accounting review conducted by ManyMoats Systems Research. It evaluates proposed architectural claims and boundary limits against classical governing physical equations (Navier-Stokes thermal transport, Nyquist-Shannon control bounds, orbital kinematics, and Pennes bioheat equations). It is not an outside corporate certification and does not claim external regulatory findings under FDA or ISO 14708.
Document type: Internal engineering sensitivity
analysis
Date: 2026-09-23
Author: Brennan DeCrow // ManyMoats Systems
Research
Subject: Brennan DeCrow — four first-principles claims
covering high-density host power, actuator dynamics, orbital timing, and
cortical heat dissipation
Scope: Boundary conditions and refutation criteria for
Theorems 1–4
A theorem holds only if three criteria close simultaneously: the governing physical equation, the arithmetic that turns that equation into the headline number, and a measured transfer function from the proposed mechanism to that number. Unit conversions that start from an unmeasured watt, radian, or milliwatt do not count as empirical measurements.
| Theorem | What is physically real | Headline number | Verdict |
|---|---|---|---|
| 1. Colossus host serialization | Host-side serialize/copy burns CPU power. Cutting allocator traffic and using a dense binary record reduces that term on a serialization-bound process. | 211 W/server, 2.54 MW, 22.25M kWh/y, 10.58M gal/y | Fails. The wattage is unmeasured, and it contradicts the megawatt figure. Water and annual energy are unit conversions of that broken wattage. |
| 2. Optimus / FSD, 2,600 Hz XPBD | A 33.3 ms delay inside a joint servo whose crossover is tens of hertz removes phase margin and can make the loop unstable. | 12 rad lag, Nyquist floor at 2,000 Hz, guaranteed gear destruction, exact Hamiltonian XPBD in ≤384 μs | Fails. The stability intuition is right. The phase number, the citation of Shannon, the destruction guarantee, the WebGPU budget, and “exact Hamiltonian” conservation are wrong. |
| 3. Starlink / Starship steering | Circular LEO speed is about 7.8 km/s. A 50 ms freeze moves the vehicle 390 m along-track. Hard real-time loops cannot sit on a garbage-collected pause. | Steering coefficients required every 1.5 ms; 50–200 ms GC causes 390 m of tracking loss; BLAKE3 Merkle chain handles SEUs in ≤9.8 μs | Fails. 390 m is the 50 ms distance only. Beam loss is an angle problem. Flight computers that steer beams are not GC runtimes. A hash chain detects corruption; it does not radiation-harden a processor. |
| 4. N1 cortical ceiling | Chronic cortical implants are perfusion-limited, and implant firmware uses static memory. Small ΔT is the right design constraint. | FDA/ISO ⇒ 1.0°C ⇒ 70 mW; heap parsing at 112.5 mW and 1.61°C necrosis; fix at 24.8 mW and 0.35°C | Fails. The standards do not state that wattage. 1.61°C is the wrong necrosis threshold. The milliwatts require a byte rate the N1 electrode count does not produce. |
Family failure: each theorem multiplies “0 bytes of heap allocation” by a plant whose dissipation or stability is set by a different physical channel. The channel is HBM and GPU power delivery, the inverter current loop, line-of-sight angle, or perfused bioheat. Zero heap traffic does not determine that channel.
Using 1.8 L of evaporation per kWh (0.4755 US gal/kWh), which is the standard latent-heat shortcut at about 2,260 kJ/kg:
Those two lines are a calculator. They contain no Memphis wet-bulb temperature, no cycles of concentration, no blowdown, and no cooling-plant diagram. At five cycles of concentration, withdrawal is about 25% above evaporation. The gallons figure is the energy figure wearing a unit conversion.
An 8-GPU host model of a 100,000-GPU cluster is 12,500 servers.
[ 211, 500 = 2.6375, ]
The claimed 2.54 MW is 203 W/server at 12,500 hosts, or 12,038 servers at 211 W. The wattage, the host count, and the megawatts are three different statements. Annual energy and cooling-tower water inherit 2.54 MW, so they inherit the inconsistency.
211 W continuous is a large fraction of a modern host CPU socket. It is a believable number only for a host whose cores are already pegged on serialize-and-copy, with package power measured at the RAPL (Running Average Power Limit) domain or the board power inlet, voltage and frequency allowed to drop when the work disappears.
A Colossus training server’s continuous heat is set by GPU sockets, HBM, NVLink or NVSwitch, and the rectifiers. Eight high-end GPUs are several kilowatts to about ten kilowatts before the host CPU is counted. Control-plane records, even protobuf records, are tiny next to gradient and activation traffic. Sparse delta opcodes reduce traffic only when the payload is sparse. Training-state exchanges are dense.
“0 bytes of dynamic heap” removes allocator tax on the control path. The tensor still moves. GPUDirect, RDMA, and flat binary layouts already exist for this reason. The marginal wattage of one more binary format is an instrument reading, not a consequence of a 64-byte record.
Saved CPU joules become saved cooling-tower water only for the heat the towers actually see, only while those cores were going to be busy, and only at the site’s real water-use effectiveness. Public discussion of the Memphis cluster is on the scale of 10⁶ gallons/day of site withdrawal. The claimed saving is
[ 10.58 ^6 , ^4 ,. ]
Even a true 2.54 MW IT reduction is a small fraction of site water. Publishing it at four figures implies a plant model that the theorem does not contain.
Theorem 1, as stated, is not certified. Reopen only with a per-host wattmeter A/B on the production dataloader and collective path, then a fleet sum that uses the same host definition as the cluster that is actually installed.
A delay of (t = 33.3,) at cyclic frequency (f) produces phase lag
[ = 2f t . ]
| Actuator frequency | Phase lag at 33.3 ms | In degrees |
|---|---|---|
| 100 Hz | 20.9 rad | 1,200° |
| 200 Hz | 41.9 rad | 2,400° |
| 300 Hz | 62.8 rad | 3,600° |
The frequency that yields 12 rad at 33.3 ms is
[ f = = 57.3,. ]
Twelve radians is outside the 100–300 Hz band stated in the theorem. The qualitative statement “many radians of lag” is true. The number 12 is not the phase of that band.
The Nyquist–Shannon sample floor for a band limited at (f_) is (f_s f_).
A 2,000 Hz floor is the practical servo rule of about 7× to 10× bandwidth, mislabeled as Shannon. Use it as a crossover-frequency rule. Do not cite it as the sampling theorem.
Phase of a pure delay at gain crossover (_c) is (-_c t). With (t = 33.3,) and no other phase loss, the −180° crossing sits near 15 Hz. A vision or diffusion planner at 30 frames/s, placed inside the joint feedback loop, will not stabilize a 100 Hz structural mode. That part of the claim matches loop-shaping practice.
Industrial and vehicle stacks already separate the loops:
A late planner produces tracking error and late contact response. Chatter and gear damage are possible outcomes of an unstable torque loop. They are not guaranteed. Current limits, coulomb friction, and a watchdog that opens the loop all interrupt the story “delay ⇒ destroyed gearbox.”
The period at 2,600 Hz is (1/2600 = 384.6,). A solve that finishes in ≤384 μs occupies the entire tick. A production real-time budget keeps worst-case execution well under the period so sensor input, actuator output, and jitter still fit. The stated bound is zero slack.
WebGPU or Metal command-buffer submission on a general-purpose GPU stack costs tens to hundreds of microseconds before a kernel runs. A ~40-degree-of-freedom rigid-body solve is a small CPU problem. A GPU round trip can make the latency worse.
Extended Position-Based Dynamics (XPBD) projects constraints with compliance. That formulation dissipates energy and drifts. A symplectic integrator (leapfrog / Verlet) stays near a shadow Hamiltonian and still does not conserve the true Hamiltonian exactly. “Exact Hamiltonian energy conservation” is the wrong property for XPBD.
Diffusion world models and XPBD also answer different questions: predicted images versus contact constraints. A fast constraint solver does not retire a perception model, and a perception model does not belong in the current loop.
Theorem 2, as stated, is not certified. The salvageable statement is narrower: keep 33 ms models outside the torque loop; budget phase margin on the actuator you actually ship; measure worst-case execution on that controller.
[ 7{,}800, , = 390,. ]
[ 7{,}800, , = 11.7,. ]
[ 7{,}800, , = 1{,}560,. ]
A pause range of 50–200 ms is a ground-track range of 390–1,560 m. The theorem quotes the bottom of that range for the whole interval. Textbook circular-orbit speed near 7.8 km/s is the right LEO (low Earth orbit) magnitude; a 550 km circular orbit is closer to 7.6 km/s. That 3% is irrelevant next to the geometric error below.
The plant is line-of-sight rate, beamwidth, and slot schedule. Along-track meters are the integral of velocity, not the pointing error.
Orbital angular rate at 550 km altitude is only about 0.06 deg/s. Angular rate as seen from a user on an overhead pass is on the order of 0.5–1.5 deg/s. Freeze the beam for 50 ms at 1 deg/s and the pointing error is 0.05 deg. Freeze it for 1.5 ms and the geometric step is 0.0015 deg.
Whether 0.05 deg drops the link depends on beamwidth and the tracking-error budget. A user-beam cell is kilometers across. A 390 m smear is a small fraction of that cell. The theorem needs a beamwidth and an allowed pointing error before it can require a 1.5 ms coefficient update. A 1.5 ms period may be a real TDMA (time-division) slot. Slot duration is a protocol choice. It does not fall out of 7.8 km/s.
Phased-array schedulers run on FPGAs and real-time processors with static memory. Starship guidance inner loops are the same class of machine: watchdogs, lockstep or redundant strings, no stop-the-world collector on the steering or fin loop. A 50–200 ms garbage-collection pause is fatal in any loop that was wrongly built that way. It is not a description of the avionics that fly.
Single-event upsets are bit flips in registers and SRAM. The remedies are error-correcting codes, scrubbing, triple modular redundancy where the function is critical, lockstep, and a watchdog that can still actuate if the processor lies. A BLAKE3 Merkle chain detects a bad state transition. Detection is valuable. The hash runs in the same radiation environment as the state it covers. A chain does not correct a flipped bit, does not keep a phase shifter on the user, and does not bound worst-case execution on a radiation-tolerant core. Those cores are often far slower than a desktop part, so a 9.8 μs claim is a measurement on a named processor, at a named state size, under a named radiation test. The theorem specifies none of the three.
Starlink beam steering and Starship flight control are different plants that share a vehicle brand. One microbenchmark cannot close both.
Theorem 3, as stated, is not certified.
ISO 14708-1 limits outer-surface temperature rise of an active implant in a specified bench setup. The figure engineers remember from that family is +2°C relative to 37°C surrounding tissue, on the surface, for the test as written. FDA review of a cortical implant then asks for a thermal test on that geometry, duty cycle, and perfusion assumption. Neural-interface groups often design to a 0.5–1.0°C tissue rise because chronic brain tissue is less forgiving than the generic implant surface test.
There is no FDA identity of the form “1.0°C ⇒ P ≤ 70 mW” that is true for every implant. Seventy milliwatts implies a hidden thermal resistance:
[ R_ = = 14.3,. ]
Under that single assumption the rest of the temperature column is linear and consistent:
| Power | ΔT at 14.3 K/W |
|---|---|
| 70 mW | 1.00°C |
| 112.5 mW | 1.61°C |
| 24.8 mW | 0.35°C |
And ((1.00 - 0.35)/1.00 = 65%) margin against their own 1.0°C ceiling. The percentage is arithmetic. The ceiling is an assumption, and (R_) is an assumption. Both are geometry-locked. Pennes bioheat makes steady (T) roughly linear with power when perfusion dominates, so the linearity is fair after (R_) is measured for the N1 package in perfused tissue or a validated phantom. It is not fair as a universal constant.
Acute coagulation injury in brain is a time-temperature integral. Sustained temperatures associated with thermal damage sit near 42–45°C (about +5°C to +8°C above 37°C), with the duration set by a CEM43-style model. A chronic +1.6°C rise is a regulatory failure and a long-term tissue-response problem. It is not, by itself, necrosis. The honest endpoints at +1.6°C are gliosis risk, barrier stress, and a failed thermal test.
[ P = E_ . ]
At the middle of the stated 120–240 pJ/byte (180 pJ/byte):
[ = = 625,. ]
At 240 pJ/byte the same power is 469 MB/s. At 120 pJ/byte it is 938 MB/s.
An N1-class digital front end is on the order of 10³ electrodes, not a memory-bandwidth machine. Full-rate digitization at about 20 kS/s and 16 bits across 1,024 channels is about 41 MB/s. Sparse spike events are far below that. At 240 pJ/byte:
The implant power budget is dominated by the analog front end, the
ADCs, stimulation drivers when they fire, and the radio. Allocator
traffic on a heap is a term serious implant firmware already refuses to
pay: static arenas, no malloc, MISRA-style rules. Removing
a heap that should not be in the image does not move dissipation from
112.5 mW to 24.8 mW. Those two milliwatt numbers need a current probe on
the rail, split by domain.
Theorem 4, as stated, is not certified.
This is the objection a principal xAI or Tesla hardware engineer would actually write in the margin:
You treated a memory-allocator choice as the plant. Close the equation on the plant, on a wattmeter or an encoder, before you publish a megawatt, a radian, or a degree.
Concrete form, from the power side and the motor side at once:
Power identity. Cluster heat is GPU core, HBM, and switch fabric. A 64-byte capability word changes host instructions on the control path. It does not change joules per tensor-core MAC (multiply-accumulate) or joules per byte of HBM. The review opens with (211 500 = 2.6375), which already disagrees with 2.54. A spreadsheet that cannot add is not a measurement of Memphis.
Loop identity. Joint stability is phase margin at the inverter, and the current loop is already tens of kilohertz beside the motor. A 30 Hz model belongs outside that loop. The lag of a delay is (2f t), which is 21–63 rad across the stated actuator band, so the printed “12 rad” fails the same arithmetic test. XPBD then adds constraint damping; it does not conserve the Hamiltonian. Predicting destroyed gears from a mis-drawn block diagram will not survive a design review, because the dyno will show a late outer loop and a still-stable current loop.
Every other objection in this review (beam angle versus ground track, bioheat versus a universal 70 mW, hashes versus EDAC) is the same mistake wearing a different unit.
How fast this can be put on a production harness, if the claim is reduced to something a rig can falsify:
| Claim worth testing | Rig that exists | Time to a falsifying result | What that result is allowed to say |
|---|---|---|---|
| Host binary state versus protobuf on one training server | One 8-GPU training host, RAPL package power plus board inlet, production dataloader, fixed GPU work | 1 day to instrument, about 1 week for a controlled A/B | A watt delta on that host. It does not say 2.54 MW, and it does not say gallons in Memphis. |
| Fleet sum | The same image across a measured slice of hosts, weighted by the real server mix (HGX-8 and Grace-Blackwell racks are different host ratios) | Months, because the mix and the duty cycle have to be real | A cluster kilowatt number with an error bar. Water only after the cooling plant’s liters per kWh are measured. |
| 33 ms inside versus outside the torque loop | One Optimus or vehicle actuator on a dynamometer, stock inverter, delay injected in the command path, encoder and current probes | About 1 week | Phase margin and whether the gearbox sees a limit cycle. It does not test WebGPU, and it does not test diffusion models as a servo. |
| 2,600 Hz constraint solve | The embedded motor computer you would actually ship, worst-case execution, cache locked, allocator off | Weeks to a few months for a safety case | A schedule that fits in the tick with slack. A 384 μs solve at 2,600 Hz has none. |
| 1.5 ms steering and 9.8 μs transitions | SpaceX phased-array bench or flat-sat, named FPGA image, named processor | Months, and it is a SpaceX range, not an xAI or Tesla harness | Pointing error in degrees versus hold time. Export-controlled hardware stays on that range. |
| 24.8 mW and 0.35°C | N1-class board rail currents, then an ISO 14708 thermal phantom or instrumented tissue model | Days for the rail split; months to years for a regulatory thermal argument | Domain power in milliwatts, then °C on that geometry. A firmware diff alone cannot produce either headline. |
xAI can falsify Theorem 1’s wattage on one host this week. Tesla can falsify Theorem 2’s gear-destruction claim on one joint this week. Neither company can “adopt ATESO” as a cluster, a humanoid, a constellation, or an implant on the strength of these four statements. Theorems 3 and 4 sit on SpaceX and Neuralink plants; an xAI or Tesla harness can host a software microbenchmark of them and still prove nothing about beam angle or cortex.
I do not certify Theorems 1, 2, 3, or 4.
I certify the following smaller statements, because the physics already supports them without ATESO:
Conditions to reopen any theorem: one named instrument, one named plant configuration, one pre-registered equation, and headline digits that match the product of those three. Until then the four theorems remain hypotheses with inconsistent arithmetic.
Sign-off: Brennan DeCrow // ManyMoats Systems
Research, engineering evaluation, 2026-09-23.
Status: BOUNDS ESTABLISHED.
Authority of this sign-off: Internal adversarial
sensitivity and physical limits review on the claims as written. No
authority to bind outside corporations, FDA, or ISO, and no claim that
third-party institutions have accredited these theorems.
{
"receipt_id": "rcpt_994d1ed0625c486c",
"audit_type": "internal_adversarial_sensitivity_analysis",
"evaluated_theorems": [
"High-Density 100k GPU Cluster Serialization & Cooling Water Boundary",
"Robotic 2,600 Hz XPBD Nyquist Determinism vs 30 fps Video Generation",
"Orbital Phased-Array Sub-Cycle Beam Steering & SEU Tracking Limits",
"Cortical Implant 10,000-Channel Thermal Dissipation (Pennes Bioheat Model)"
],
"timestamp": "2026-09-23T12:47:07.139Z",
"status": "RATIFIED"
}