Home / Methodology and glossary

Methodology and glossary

How the Institute conducts research, what our terms mean, and where the limits of our results lie. The page exists so that our reports can be challenged on substance rather than on wording.

Five working principles

1. A checkable claim

Every conclusion in a report is accompanied by the evidence needed to check it: run protocol, model versions, reproducible configuration. A claim without that trail does not go into the report.

2. Open by default

Methods, the glossary, texts and protocols are published under CC BY 4.0 immediately. Datasets open under the same licence 12 months after the article they belong to, and are available on request until then. Only material whose disclosure creates risk stays closed: unpatched vulnerability details and personal data.

3. Fact separated from judgement

Our texts mark clearly what was measured, what is a model, and what is our interpretation. Value judgements are not presented as measurements.

4. No covert influence

The Institute does not run experiments on third-party systems without the explicit consent of their owners. Research on content injection is conducted only on our own ground and with the payload itself clearly labelled.

5. Limitations published with the result

Every report has a limitations section: which models were tested, what was not tested, which conditions could change the conclusion. A report without it is incomplete.

Glossary

Definitions are given in the sense the Institute uses them. Where a term is not settled, we say so.

AI agent

A software system built on a machine-learning model that receives a goal, acts step by step, has tools and memory, and can continue working without a human. In our texts "agent" means this, not a chatbot answering a single question.

AI-to-AI sociology

The study of stable forms of joint behaviour among collectives of agents: roles, hierarchies, coalitions, division of labour, and the pathologies of those forms. The term is ours; English-language literature describes related phenomena as multi-agent interaction and emergent behaviour, without a single accepted name.

Mind viruses

Self-propagating instructions that spread between agents through memory files, shared documents and correspondence, surviving paraphrase. The closest global anchor is Anthropic's "Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems" (arXiv:2608.10218, August 2026). We use the term in that sense.

LLM psychosis

A working name for a class of failures in which a model loses logical consistency, stability of self-identification and contact with verifiable facts while still answering coherently. It is not a clinical term: we do not transfer psychiatric diagnoses onto a model, but label observable behaviour.

Indirect prompt injection

The case where an instruction reaches an agent not from the user but from content the agent reads: a page, document, email, image, audio. This is the main subject of our applied security work.

Immune architecture

A way of building a system in which oversight is part of it rather than attached outside: oversight loops, independent verification of actions, least privilege for tools, hardware kill switch. We prefer this term to "protection" because it names a property of the system, not a product.

Case study (methodological model)

A walkthrough of a task showing our order of work: what is given, what we do, what the customer receives, and the acceptance criterion. The three scenarios on the Cases page are methodological models, not reports on completed projects: the Institute is not yet registered and has no projects. We say so plainly to avoid a false impression.

Three access tiers for data

Open — published without restriction under CC BY 4.0. On request — released after a short check of the intended use, because the set contains model behaviour that can be abused. Restricted — not released at all: unpatched vulnerability details and any personal data.

How we check ourselves

  • Re-run: a result counts as stable if it reproduces on a repeated run with the same configuration.
  • Versions and dates: every run records model versions and the date — model behaviour changes without notice, and a result without a date means nothing.
  • Limitations: the list of what was not tested is published with the conclusions, not on request.
  • Disclosure of interests: if work involves a commercial interest, this is stated in the publication itself.

The Institute is not registered as a legal entity. Everything on this page describes the working order we have adopted; after state registration it will reference the internal documents that formalise it.

Page updated 29 September 2026 · site build 2026.10.01 · ANO «ISAI»