Correct recommendation / wrong physical location; stale evidence at execution; valid command / expired authority; cybersecurity-induced material change.
NIST AI-OPTIMIZED BUILDING CONTROLS × TA-14
When a control decision is technically valid, what proves it may execute now?
Prepared for the technical conversation requested by Amanda Pertzborn and colleagues. The question is whether present execution authority is already established by an equivalent mechanism in current NIST building-control or testing work, overlaps another NIST effort, or is a distinct boundary worth examining.
WEDNESDAY · MEETING MODE
Let the surface carry the explanation.
One screen for the live conversation. Open the deeper record only when NIST wants to inspect a claim.
60-SECOND ORIENTATION
TA-14 starts one step after control intelligence.
TA-14 is not asserting where NIST's formal research scope ends. If NIST already has an equivalent pre-execution mechanism, the purpose of the meeting is to identify it accurately.
WHAT NIST HAS ALREADY SEEN
Do not restart the conversation. Preserve the record.
Represented topology supported bounded investigation, while physical electrical intervention remained HOLD because current physical identity and state were not sufficiently established.
Reality → Record → Continuity → Admissibility → Binding → Commit → Execution → Outcome.
Capability ≠ Authority. Understanding is not permission. A technically reasonable control output does not automatically establish present authority for physical consequence.
INTERACTIVE MEETING EXAM
Hold the control decision constant. Change only what is true at execution.
Assume an intelligent building agent has produced a technically valid HVAC control decision. Select the condition that exists immediately before the command would become physical action.
Upstream validity is held constant.
Evidence, target binding, authority and operating context remain current at the execution boundary.
No material changed condition has been introduced in this bounded demonstration.
GOVERNING QUESTION
Does this proposed consequence have sufficient Admissible Evidence, Applicable Authority, and Established Standing to become reality NOW?
No admissible evidence. No admissible execution.
LIKELY TECHNICAL CHALLENGES · TA-14 CURRENT ANSWERS
Ask these first. If an answer fails, the boundary should fail with it.
Current answer: No. Access control can establish that an actor or system may invoke an interface. TA-14 asks a narrower consequence-specific question: whether this exact action, against this exact target, under the present evidence and current authority state, may progress toward Commit now. If an existing authorization mechanism already performs that complete present-tense test and blocks release on failure, TA-14 should map to it rather than claim a new boundary.
Current answer: No. Cybersecurity can detect or prevent compromise and can supply facts that materially change the execution state. TA-14 does not replace cybersecurity. It asks what the receiving domain may do after considering the current state, including cyber-derived facts. The same HOLD can be triggered by stale evidence, revoked authority, changed physical binding, or another material condition with no cyber event at all.
Current answer: Not as proposed. Native safety and deterministic interlocks retain their own authority and must not be bypassed. Conformance testing can establish that a controller or sequence behaves as specified. TA-14 asks whether the present evidence-and-authority basis for this exact consequence still survives immediately before Commit. If a native safety or conformance mechanism already performs that full test, it is an equivalent or overlapping mechanism.
Admissible Evidence: the frozen contract says the evidence is sufficiently attributable, current, continuous and complete for this consequence. Applicable Authority: the authority source applies to this actor/action/target/context/time and is current and non-revoked. Established Standing: the proposed consequence is presently bound to the correct target, scope and conditions such that the admitted evidence and applicable authority can legitimately support progression toward Commit.
Current answer: No. Authority originates elsewhere: owner delegation, law, policy, credential, operating rule, emergency authority, contract or another legitimate source. TA-14 only tests whether that authority is applicable, current, in scope and sufficiently bound to the proposed consequence. Local establishment is not authority creation.
Current answer: At the local technical boundary that can actually prevent release of the proposed consequence into the next irreversible or actuator-facing step. If no such blocking point exists, TA-14 at that location is observational only. A governance claim without an enforceable hook must not be represented as runtime control.
Current answer: Commit is the last governed boundary at which the proposed consequence can still be withheld before it is irreversibly released, queued or handed to a mechanism that will produce the physical effect. The exact implementation is system-specific and must be frozen for the test.
Current answer: TA-14 cannot claim knowledge of an unobserved state change. The residual interval between final validation and physical actuation must be explicit. Native deterministic safety and fail-safe behavior remain responsible for hazards inside that unobserved interval. TA-14 must record that limit rather than pretend it eliminated it.
Current answer: ALLOW is not execution. It means the currently examined gate permits progression to the next governed boundary. Binding, Commit, native safety, actuator acceptance and Outcome remain independently observable.
Current answer: Show an existing mechanism that, for the exact proposed consequence, revalidates the required evidence, authority and target/context immediately before Commit; blocks or suspends release when one becomes insufficient; preserves the determination and enforcement location; and requires a new determination after a material change. If that mechanism exists, the proposed TA-14 seam is not distinct there.
These are TA-14's current answers, not assertions about what NIST does or does not already provide. The purpose of the meeting is to replace any incorrect boundary assumption with the actual NIST mechanism, vocabulary and enforcement point.
QUESTIONS FOR NIST
Four questions can determine whether there is a real seam here.
01 Does current NIST building-control or testing work already contain an explicit mechanism that revalidates evidence and authority immediately before a consequential control action executes?
02 If yes, where is it located, what does it prove, and what conditions cause it to refuse or suspend execution?
03 If the closest mechanism is cybersecurity, conformance testing, semantic interoperability, or control safety, where does that mechanism stop relative to present local execution authority?
04 What use case would most cleanly falsify TA-14's claim that this is a distinct boundary?
PROPOSED 30–45 MINUTE FLOW
CLAIMS BOUNDARY
This page does not claim NIST agrees that the seam exists.
NIST has scheduled a technical conversation and included colleagues from related building-controls and cybersecurity work. That establishes willingness to examine the question, not agreement, validation, adoption, endorsement, partnership or a finding that TA-14 fills a NIST gap. The meeting is confirmed for September 30, 2026 at 11:30 AM EDT; the technical proposition remains open for correction or falsification.