Sections 20–29 · synthetic model → deterministic governance

FDE-AIQOS — AI & Quantum Operating System

Data centre → data → applications → knowledge → AI/ML → agentic AI → quantum intelligence → nudge and assist → deterministic governance → human decision → audit → neural feedback. Every layer independently observable, every number generated offline.

$ python -m fde_toolkit aiqos --count 500 --export audit.jsonl

20 · Synthetic data model

500 events · seed fde-aiqos-2026 · no real customer data

Events

500

Allow

323

Review

137

Reject / isolate

40

Mean risk

0.300

FieldUnitDistributionNormal band
cpu_pct%normal(62, 18) clipped 5..99< 80
memory_pct%normal(68, 16) clipped 10..99< 85
network_pct%normal(42, 20) clipped 1..99< 75
latency_msmslognormal(ln 95, 0.45) clipped 15..1200< 250
error_rate_pct%beta(1.5, 18) × 8< 1.5
packet_loss_pct%beta(1.2, 25) × 3< 0.5
temperature_c°Cnormal(58, 8) clipped 30..90< 70
ALLOW

Normal

Risk below 0.55, KYC verified, retrieval grounded, no structural breach.

execute and audit

REVIEW

Review

Risk at or above 0.55, KYC pending or expired, or retrieval relevance below 0.45.

human-in-the-loop queue

REJECT_ISOLATE

Reject / isolate

Velocity > 0.85, ethics linkage < 0.35, sanctions hit, or value ≥ 10 000 without dual approval.

block, isolate, escalate

20a · Resource and risk distributions

500 events · histogram counts per band

CPU utilisation

%

mean 62.2 · p50 62.2 · p95 91.1 · max 99.0

0–205 · 1.0%
20–4044 · 8.8%
40–60176 · 35.2%
60–80191 · 38.2%
80–10084 · 16.8%

Memory utilisation

%

mean 68.1 · p50 68.1 · p95 94.1 · max 99.0

0–200 · 0.0%
20–4020 · 4.0%
40–60135 · 27.0%
60–80221 · 44.2%
80–100124 · 24.8%

Network utilisation

%

mean 43.9 · p50 43.7 · p95 75.5 · max 99.0

0–2055 · 11.0%
20–40159 · 31.8%
40–60189 · 37.8%
60–8082 · 16.4%
80–10015 · 3.0%

Latency

ms

mean 104.9 · p50 94.5 · p95 203.7 · max 316.5

0–100272 · 54.4%
100–200201 · 40.2%
200–40027 · 5.4%
400–8000 · 0.0%
800–12000 · 0.0%

Deterministic risk

0..1

mean 30.0 · p50 29.8 · p95 38.0 · max 42.8

0–2010 · 2.0%
20–40478 · 95.6%
40–5512 · 2.4%
55–750 · 0.0%
75–1000 · 0.0%

Transaction value

lognormal(ln 1 800, 1.1) · dual-approval threshold at $10k

< $1k141 · 28.2%
$1k–10k326 · 65.2%
$10k–50k32 · 6.4%
$50k–250k1 · 0.2%
> $250k0 · 0.0%

20b · KYC, PEP and sanctions rates

population share per control flag

KYC verified412 · 82.4%
KYC pending58 · 11.6%
KYC expired30 · 6.0%
PEP flagged17 · 3.4%
Sanctions hit10 · 2.0%
Dual approval present117 · 23.4%
Invoice evidence present52 · 10.4%
Weak grounding (RAG < 0.45)77 · 15.4%
Control flagCountRate
KYC verified41282.4%
KYC pending5811.6%
KYC expired306.0%
PEP flagged173.4%
Sanctions hit102.0%
Dual approval present11723.4%
Invoice evidence present5210.4%
Weak grounding (RAG < 0.45)7715.4%

20c · Q-LOCK gate counts

allow / review / reject-isolate, split by domain

ALLOW323 · 64.6%
data center115
business data121
application87
REVIEW137 · 27.4%
data center48
business data51
application38
REJECT_ISOLATE40 · 8.0%
data center11
business data23
application6

21 · Example synthetic function output

same inputs, same output — always

OntologyMapper

TBL_CUST_99X_REV
    ↓
Customer
    ↓
confidence = 0.99
AUTO_ACCEPT

Above the 0.95 auto-accept threshold; below it the mapping goes to a steward.

ToolSynthesizer

POST /payments
    ↓
create_payment
    ↓
HIGH RISK
REQUIRES_APPROVAL

Write scope exposed only with payments.write plus a human approval step.

IntentRouter

"What is our exposure?"
    ↓
Compliance / Graph Agent
    ↓
confidence = 0.94
ROUTE

Specialist route: 22× cheaper and 4× faster than the frontier fallback.

RAGRetriever

"EDD refresh policy"
    ↓
Sentence chunk #4
    ↓
hybrid score = 0.502
RETRIEVE

0.6 dense + 0.4 keyword, then metadata and permission filters.

PolicyEngine

TXN-10021
    ↓
ALLOW
    ↓
0 rules matched
AUDIT

An allow is still an audited decision, not silence.

PolicyEngine

TXN-20051 · $50M shell beneficiary
    ↓
V1 + V4 breach
REJECT_ISOLATE

Deterministic gate overrides a 0.97-confidence model proposal.

22 · Full enterprise inference pipeline

                ┌─────────────┐
                │ USER / EVENT│
                └──────┬──────┘
                       ↓
                Intent Detection
                       ↓
                Risk Classification
                       ↓
                ┌──────┴──────┐
                ↓             ↓
             SLM path       LLM path
                │             │
                └──────┬──────┘
                       ↓
                Context Builder
                       ↓
        ┌──────────────┼──────────────┐
        ↓              ↓              ↓
       RAG          Graph DB       Memory
        │              │              │
        └──────────────┼──────────────┘
                       ↓
                 Agent Planner
                       ↓
                   DAG/ReAct
                       ↓
                  MCP Tools
                       ↓
                AI/ML Inference
                       ↓
                Quantum Signal
                       ↓
                  AI Insights
                       ↓
                  AI Nudge
                       ↓
                 POLICY/Q-LOCK
                       ↓
        ┌──────────────┼──────────────┐
        ↓              ↓              ↓
      ALLOW          REVIEW          DENY
        ↓              ↓              ↓
     Execute       Human HITL       Isolate
        └──────────────┼──────────────┘
                       ↓
                     AUDIT
                       ↓
                  OUTCOME DATA
                       ↓
                NEURAL FEEDBACK
                       ↓
               MODEL/EVAL UPDATE

Stage by stage

what each stage owns and emits

StageResponsibilityOutput
Intent detectionClassify what the request actually is before spending a token.intent + confidence
Risk classificationDecide the blast radius: read, advisory or state-changing.low / medium / high
SLM vs LLM pathCheap specialist by default; frontier model only when it earns it.route + cost
Context builderAssemble permission-filtered context under a token budget.context pack
RAG / graph / memoryDocuments, relationships and prior decisions in parallel.evidence set
Agent plannerDecompose into a DAG or run a ReAct loop for exploratory work.plan
MCP toolsScope-gated tool descriptors; writes need approval.tool calls
AI/ML inferenceBehavioural, anomaly and ranking models score the case.scores
Quantum signalQFT spectral view and QSVM candidate classification.safe / unsafe
AI insightDrivers, network context and evidence — not an adjective.explanation
AI nudgeThe next best action, offered before the mistake is made.recommendation
Policy / Q-LOCKDeterministic deny-overrides gate above every model.ALLOW / REVIEW / DENY
Execute / HITL / isolateThree terminal paths, all of them logged.action
AuditHashed, ordered, append-only, regulator-replayable.evidence
Neural feedbackOutcomes and overrides become the next eval set.model + policy update

23 · Use-case matrix

✓ intensity per capability

SectorUse caseRAGGraphAgentQuantum / AIQ-LOCK
BankingAML investigation✓✓✓✓✓✓✓✓✓✓✓✓✓✓
BankingKYC investigation✓✓✓✓✓✓✓✓✓✓✓
InsuranceClaims fraud✓✓✓✓✓✓✓✓✓✓✓✓
Data centrePredictive operations✓✓✓✓✓✓✓✓✓
TelecomNetwork anomaly✓✓✓✓✓✓✓✓✓✓✓
Trade financeInvoice / party risk✓✓✓✓✓✓✓✓✓✓✓✓✓✓
HealthcareClinical document intelligence✓✓✓✓✓✓✓✓✓✓✓
ManufacturingPredictive maintenance✓✓✓✓✓✓✓✓✓
LogisticsRoute optimisation✓✓✓✓✓✓✓✓✓ / QAOA✓
GovernmentCase management✓✓✓✓✓✓✓✓✓✓✓✓

24 · Banking / AML demonstration

one question, ten hops, one gate

“Investigate CUST-4412 and determine whether the latest payment should be released.”

  1. 01CUST-4412case opened from the payment request
  2. 02KYCidentity refreshed 14 months ago — EDD window breached
  3. 03Transactionsvelocity +184% versus the 90-day baseline
  4. 04Counterparties95% concentration into a single beneficiary
  5. 05UBO graphtwo hops from a previously flagged entity
  6. 06Sanctionsno direct hit; adverse-media proximity flagged
  7. 07RAG policy3 policy documents support enhanced review
  8. 08Behavioural modelrisk 0.87 · confidence 0.94
  9. 09Quantum candidate classifierUNSAFE side of the QSVM margin
  10. 10Q-LOCKdeterministic gate evaluated last
{
  "customer": "CUST-4412",
  "risk_score": 0.87,
  "rag_grounding": 0.91,
  "graph_risk": 0.84,
  "model_confidence": 0.94,
  "quantum_classifier": "UNSAFE",
  "policy": "DENY",
  "q_lock": "REJECT_ISOLATE",
  "human_review": true
}

25 · AI insight output

not an adjective — drivers, network, evidence

Instead of “Transaction appears risky.” the platform produces:

AI insightRisk HIGH

Primary drivers

  1. 1. Velocity +184% versus 90-day baseline
  2. 2. Counterparty concentration = 95%
  3. 3. Weak provenance = 0.31
  4. 4. Beneficiary KYC linkage incomplete
  5. 5. Invoice evidence absent

Network insight

Counterparty is two hops from a previously flagged entity.

RAG evidence

3 policy documents support enhanced review.

Recommended action

BLOCK → INVESTIGATE → HUMAN APPROVAL

confidence 94%deterministic gate · REJECT_ISOLATE

This is the difference between a chatbot and an enterprise cognitive operating system.

26 · AI assist vs AI nudge vs agent

capability, risk and approval surface

CapabilityAI assistAI nudgeAgent
ExplainStrongMediumStrong
RecommendMediumStrongStrong
ExecuteNoUsually noYes
Human approvalYesYesPolicy-dependent
ContextRAG / memoryReal-time telemetryFull context
RiskLowMediumHigh
AuditRequiredRequiredMandatory

27 · Audit architecture

attribution · ordering · immutability

  1. ┌Agent Event
  2. │Policy Event
  3. │Tool Event
  4. │Human Event
  5. │Decision Event
  6. │Hash
  7. │Append-only Audit Store
  8. │SIEM
  9. │GRC
  10. └Regulatory Replay
{
  "actor": "agent",
  "event": "payment.request",
  "transaction": "TXN-SYN-20051",
  "model": "risk-model-v12",
  "confidence": 0.97,
  "policy": "AML-POLICY-v18",
  "q_lock": "REJECT_ISOLATE",
  "reason": [
    "V1_velocity",
    "V4_ethics"
  ],
  "human_review": true
}

Generated audit trail

500 records · first 8 shown

{"actor":"agent","event":"infra.telemetry","transaction":"TXN-SYN-20000","model":"risk-model-v12","confidence":0.83,"policy":"AML-POLICY-v18","q_lock":"ALLOW","reason":["none"],"human_review":false}
{"actor":"policy","event":"application.action","transaction":"TXN-SYN-20001","model":"risk-model-v12","confidence":0.93,"policy":"AML-POLICY-v18","q_lock":"ALLOW","reason":["none"],"human_review":false}
{"actor":"tool","event":"payment.request","transaction":"TXN-SYN-20002","model":"risk-model-v12","confidence":0.55,"policy":"AML-POLICY-v18","q_lock":"ALLOW","reason":["none"],"human_review":false}
{"actor":"human","event":"payment.request","transaction":"TXN-SYN-20003","model":"risk-model-v12","confidence":0.69,"policy":"AML-POLICY-v18","q_lock":"ALLOW","reason":["none"],"human_review":false}
{"actor":"agent","event":"infra.telemetry","transaction":"TXN-SYN-20004","model":"risk-model-v12","confidence":0.84,"policy":"AML-POLICY-v18","q_lock":"REVIEW","reason":["kyc_expired"],"human_review":true}
{"actor":"policy","event":"infra.telemetry","transaction":"TXN-SYN-20005","model":"risk-model-v12","confidence":0.89,"policy":"AML-POLICY-v18","q_lock":"REJECT_ISOLATE","reason":["no_dual_approval","weak_grounding"],"human_review":true}
{"actor":"tool","event":"payment.request","transaction":"TXN-SYN-20006","model":"risk-model-v12","confidence":0.8,"policy":"AML-POLICY-v18","q_lock":"REVIEW","reason":["kyc_pending"],"human_review":true}
{"actor":"human","event":"payment.request","transaction":"TXN-SYN-20007","model":"risk-model-v12","confidence":0.83,"policy":"AML-POLICY-v18","q_lock":"ALLOW","reason":["none"],"human_review":false}

28 · Simulator workbook contents

offline, regenerable from the CLI

SheetContents
READMEWhat the workbook is, how it was generated and the offline guarantee.
ArchitectureThe ten-layer FDE-AIQOS stack with components and outputs.
Module MapCapability map across the fourteen modules.
Function OutputsDeterministic function traces per module.
Synthetic Data500 enterprise records — data centre, business and AI fields.
140 MCQsTen technology questions per module with answer keys.
Simulator LogicEvery formula and gate used by the simulators.

Regenerate everything with python -m fde_toolkit aiqos --workbook out.xlsx (CSV fallback when no spreadsheet library is present) or --export audit.jsonl.

29 · Recommended next-generation architecture

FDE-AIQOS

                    FDE-AIQOS
                       │
       ┌───────────────┼────────────────┐
       ↓               ↓                ↓
   OBSERVE          UNDERSTAND        ACT
       │               │                │
 Data Center       Ontology           Agents
 Business Data     RAG                MCP
 Applications      Graph              DAG
 Networks          Memory             ReAct
       │               │                │
       └───────────────┼────────────────┘
                       ↓
                 AI INFERENCE
                       ↓
              Neural / SLM / LLM
                       ↓
              Quantum Candidates
                       ↓
                AI INSIGHTS
                       ↓
                 AI NUDGES
                       ↓
               DETERMINISTIC Q-LOCK
                       ↓
             ┌─────────┼─────────┐
             ↓         ↓         ↓
           ALLOW     REVIEW     DENY
             └─────────┼─────────┘
                       ↓
                    AUDIT
                       ↓
               NEURAL FEEDBACK
                       ↓
               CONTINUOUS LEARNING

RAG, vector search, graphs, memory, agents, SLMs, LLMs and quantum models are intelligence components. They are not the final authority for high-impact enterprise actions: policy, permissions, deterministic controls, human approval and audit sit above them.

Layer map

each layer independently observable and deployable

L0

Data centre

Servers, GPUs, storage, network, Kubernetes, power and cooling

→ Telemetry, logs, traces, metrics

L1

Business data

Customers, accounts, transactions, invoices, KYC, risk, exposure

→ Structured records and documents

L2

Applications

APIs, CRM, core banking, ERP, payment rails, workflow systems

→ Events, API calls, business state

L3

Data pipelines

CDC, batch and stream, schema registry, data quality, lineage

→ Canonical enterprise events

L4

Knowledge fabric

Vector DB, knowledge graph, network graph, metadata and provenance

→ Retrieval context and relationships

L5

AI / ML fabric

SLM and LLM, classifiers, anomaly detection, time series, GNN, ranking

→ Predictions, embeddings, scores

L6

Agent runtime

Intent router, ReAct, DAG, MCP tools, tiered memory

→ Plans, tool calls, observations

L7

Policy and quantum

OPA/Rego, deterministic Q-LOCK, hybrid QSVM/QAOA experiments

→ Allow / deny / escalate and optimisation

L8

Human control

AI assist, AI nudge, review queues, approvals, explainability

→ Human decision or override

L9

Audit and feedback

Immutable audit, evaluation, drift, telemetry, retro

→ Evidence plus model and policy improvement