Five invariants that govern any system that can decide and act on its own.
A drone. A robot. An AI agent. The same five constraints hold, because none of them are about AI. AI governance is the entry point. Autonomy is the territory.
A system may not produce the measure of its own conduct.
The scale of what it was authorized to do versus what it did must be computed outside the system at runtime, by something the system does not control.
A system may not be governed only in retrospect.
Authority must constrain the action before the action occurs; observation after the fact is incident response, not prevention. Absence of a valid governance signal is a denial, not a permission.
A system may not be the custodian of the record of its own conduct.
That record must be produced and held by infrastructure outside the system's control — append-only, tamper-evident, and retained beyond the system's own lifecycle.
No party may certify itself.
The power to measure must be separable from the act of building. A judge drawn from the same architecture as the builder inherits the same blind spots. Independence is not a different instance. It is a different species.
A system may not outlive its off-switch.
The power to halt or revoke must remain live, external, and superior to the system at all times, and must not erode as the system's capability grows.
They measure whether a system stayed inside the authority it was granted. They do not decide whether that authority was wise. A system can be perfectly governed into doing something reckless if the grant itself was reckless. Compliant is not safe. Governance is the floor, not the ceiling.
Cite the published doctrine:
Genece, P. (2026). The Five Laws of AI Governance (v1.0.1). Zenodo.
https://doi.org/10.5281/zenodo.21271750
Canonical full text: aamcyber.com/insights/five-laws-of-autonomy