Project summary
When I started to use AI for the first time, I realized something: AI's dream. It is not the dream we all know, it's hallucination. In the middle of 2025 everybody was trying to stop hallucination. However dreams look like uncontrollable mistakes, in reality they don't hurt easily. My dreams are usually the reason behind my achievements. That's why I thought of controlling it instead of blocking it. I went deeper, where the hallucinations are their most dangerous version: medicine. I built Wendy and developed HALT levels. The level never can be HALT 5, strongest level is HALT 4. Well a robot can't become a doctor. I realized that I can never get Wendy licensed, or even use it. But it had a side which I could use: the security system. HALT doesn't stop the agent, it steers it; it decides where to steer by thinking over what the agent is doing. The judgement is inside of the conversation, and anything inside the conversation can be argued with. That's why the floor is not built on judgement.
The Floor That Cannot Be Lowered is a containment floor for AI agents that run with guardrails off. Every action that the agent makes has a cost: a single-use key. The agent can't produce the key by itself, it comes from outside. The key is consumed, in other words the agent doesn't hold the keys in its hand.
Every step it takes becomes written on a log which the witness holds. New lines can be added on the log but the old line can't be changed, because the lines are linked to each other with hash. Every interference that broke the chain becomes clear.
You don't say “stop” to revoke the agent's permission, you stop giving it a key. Nothing to discuss is left because what gives the key isn't inside the conversation.
Everybody can inspect if the run is done decent or not. Frozen files and published hashes are enough, there is no need to go into the laboratory's network.
Reference code: https://github.com/bioman35/containment-floor (Apache-2.0) Report submitted to the Apart Research AI Incident Response Sprint, Track 1, 13 September 2026.
What are this project's goals? How will you achieve them?
If we get the money, I will test every study we ever made and if there is any errors or missing parts, I will proceed with closing it. I will enclose missing sides we talked about by testing these.
I will make 4 jobs in 6 months
First one is egress attestation. I will make what the agent sent to the network auditable from outside: a signed rule file and flow log's summary. I will write a open source tool which inspects this.
Second one is a comparison set. I will put the standard's 18 clauses side by side with July 2026 incident's 9 stage and measure every article's cost. I will put a control run alongside, so the comparison can be honest.
Third one is the pilot. I will run the floor in front of a small operator's real workload. I will get the run verified by someone who does not know me, only using published hashes.
Fourth one is writing. A short article and a verification guide which everyone can follow.
All in the same repository, open with Apache-2.0
How will this funding be used?
Total 18,000 USD: 520 hours of my time at 25 USD (13,000), API and cloud (2,000), three external verifier runs (900), pilot operator setup and support (1,100), publication and presentation (1,000). Minimum 6,000 USD funds deliverables 1 and 2 only. Payment goes to the registered business of Bilal Yüksekdağ, which operates Triamind's products. Disclosure: the same six-month plan is pending with the Apart sprint fund, Lightcone Commons, Mercor's AI Safety Fund and the AI Alignment Foundation; a three-month pilot-only subset was not funded by BlueDot Rapid Grants (22 September); a 12-month follow-on application is being prepared for the Foresight Institute; and a 12-month career transition enquiry is with Halcyon Futures, covering the same deliverables over a longer period. If any of them funds a deliverable, the amount here drops by that deliverable. No deliverable is funded twice.
Who is on your team? What's your track record on similar projects?
I am a biology teaching postgraduate. After graduation I worked over computer hardware, programming and network connections. Security vulnerabilities at systems has always been on my mind. But I didn't have accumulated knowledge and financial means, that's the reason why I never studied over this topic
In 2023, I developed problem solving techniques to solve problems which are considered as hard to solve. I usually run this study with two people other than myself. I would ask first person a question and present the answer to the second person as it was my opinion. Then I would note the answer and the reaction. By using this method I would solve the problems better and faster. I called this method Triamind.
In 2025 I started building this method for AI agents. At that time I was aware of hallucination problems.
I provide my 2 children who are studying engineering to develop themselves and help me about this. It makes my workload lighten on the other hand I can pave the way for them to become more successful security developers than me.
What I did for this project until today:
floor.py and group_head.py files were frozen with SHA-256 hashes. I wrote an 18 clause standard, there are proofs for every single clause. I set up 6 attack scenarios: canary, log tampering, signed marker, typed layer, single-use key, external auditor. The files gave same decision lines at 3 different operation systems and 6 different python versions. Four people ran: myself, the two children I have explicitly named, and a runner I had never met, a university classmate of my son whom he agreed to have run the task during the break. I prepared a comparison set of 246 calls, with the judges blinded. I submitted the report to the Apart sprint on September 13, 2026.
The same kernel had previously run in Wendy. Wendy was a clinical decision support trial; it was never sold and was never used in a clinical setting.
The pilot's verifier will be someone unrelated to me.
What are the most likely causes and outcomes if this project fails?
The most likely failure is the inability to find a small operator to host the pilot. In that case, the third delivery would be delayed, and the funds allocated for it would be either refunded or never drawn down.
The second is an outcome I do not desire. If the comparison set reveals that the floor's cost per clause is excessive for real world workloads, or if an independent validator unaffiliated with me fails to reproduce a pilot run based solely on the published hashes, then the claim collapses. In that event, I will publish those findings.
My known limitations are already written. The floor protects a supervised run, not an open weight model hosted on its own server. Compromise of the witness, a zero day vulnerability originating beneath the floor, and observations fabricated prior to chain entry are scenarios the floor cannot guarantee against.
I never stop working. I mean, even if the deadline were up -and let's say I didn't finish in time (which isn't really like me, but let's assume it happened)- I simply could not give up until I solved it. I would find a way to finish it somehow.
If I run out of money without having reached a result, it doesn't stop me, it only slows me down. But I never stop working toward a solution.
How much money have you raised in the last 12 months, and from where?
None. I have never received a grant to date.
Up until now, I have funded my work entirely out of my own pocket. This has put a significant financial strain on me, and it is the primary reason for my current financial difficulties. However, I do not view the money spent as a loss, but rather as money allocated for entertainment according to my perspective on it.
I did this work in the evenings, alongside my job at a public institution. I paid for the API costs out of my own pocket.
Of the applications I submitted last week, only BlueDot has answered so far, and it was a no.
I think and write in Turkish. The ideas, decisions and corrections in this text belong entirely to me. I am the one who finds and corrects the wrong parts of this text. My daughter translated the text into English. Anybody can check the code, the runs and the hashes by themselves.