Human-led multi-surface ai system with sandboxed simulation and human-gated execution
The human-led multi-surface AI system addresses autonomous execution risks and opaque reasoning by using a sandboxed simulation and non-permeable barrier, ensuring human-gated approval and transparent decision-making across diverse devices.
Patent Information
- Application Number
- PCT/IB2025/061978
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-11-22
- Publication Date
- 2026-01-15
AI Technical Summary
Existing AI systems lack a sandboxed simulation domain, a non-permeable execution barrier, and human-gated approval mechanisms, leading to autonomous execution risks, opaque reasoning, and lack of transparency in decision-making across diverse surfaces and devices.
A human-led multi-surface AI system with a sandboxed simulation domain, non-permeable action barrier, and cognitive mental-model engine that mimics human reasoning, ensuring all AI-generated commands are approved by humans before execution, while maintaining a unified interface across various devices.
Ensures safe, transparent, and human-controlled execution with high-precision guidance and authenticity evaluations, while recording decision-making processes for regulatory compliance.
Smart Images

Figure 00000017_0000 
Figure 00000017_0001 
Figure 00000017_0002
Abstract
Description
[0001] TITLE
[0002] HUMAN-LED MULTI-SURFACE Al SYSTEM WITH SANDBOXED SIMULATION AND
[0003] HUMAN-GATED EXECUTION
[0004] CROSS-REFERENCE TO RELATED APPLICATIONS
[0005] This application is related to International Patent Application PCT / IB2025 / 068471, titled “MULH -LANGUAGE Al VISUAL- ASSISTANCE TRAINER AND CONTROL MODULE WITH UNIVERSAL DISPLAY ADAPTATION AND CROSS-INDUSTRY COMPATIBILITY,” filed 22 August 2025 and published as WO / 2025 / 248510.
[0006] The disclosures of that application are hereby expressly incorporated by reference in their entirety to the extent permitted by applicable law.
[0007] The present invention builds upon and improves certain multi- surface, multi-workflow, and Al-driven guidance concepts disclosed therein, while introducing a sandbox-based non-permeable execution barrier, a human-gated approval system, and a cognitive mental-model engine for human-style authenticity and safety evaluation.
[0008] TECHNICAL FIELD
[0009] The invention relates generally to:
[0010] • human-AI collaboration systems
[0011] • Al safety and governance frameworks
[0012] • multi-surface instructional and operational interfaces
[0013] • workflow execution architectures with human gatekeeping
[0014] • authenticity evaluation and fraud detection systems
[0015] • explainable artificial intelligence (XAI)
[0016] • machine reasoning engines that replicate human cognitive decision models
[0017] BACKGROUND OF THE INVENTION Modern artificial intelligence systems increasingly participate in operational decision-making across automotive, medical, industrial, administrative, and other domains. Two major safety and trust challenges arise:
[0018] 1. Autonomous execution risk Al may operate machinery, software, or infrastructure without human approval, creating hazards and potentially violating safety regulations, industry standards, or legal requirements.
[0019] 2. Opaque reasoning (“black box” Al) Stakeholders such as regulators, courts, insurers, enterprises, and end-users cannot reliably trust outputs that lack transparent, human-understandable reasoning. Conventional models often provide outputs without exposing the cognitive process or weighing of risk factors.
[0020] Existing systems typically:
[0021] • provide only textual suggestions or static recommendations, or
[0022] • enable fully autonomous execution of commands and machine control.
[0023] They generally do not provide:
[0024] • a sandboxed simulation domain where Al may “act” safely without touching live systems
[0025] • a physically or logically isolated execution domain where only humans may trigger real operations
[0026] • a non-permeable barrier blocking all Al-originated control signals into the live operational domain
[0027] • a human cognitive mimic engine that evaluates authenticity, safety, and correctness in a manner analogous to a trained human examiner
[0028] • a unified, multi-surface implementation spanning dual screens, augmented reality overlays, mirrored displays, vehicle HUDs, kiosk terminals, and remote terminals
[0029] As a result, there is a need for a system in which Al provides high-precision, human-style guidance, authenticity evaluations, and risk assessments, while execution remains strictly human-led and safety-governed across diverse surfaces and devices.
[0030] SUMMARY OF THE INVENTION The invention provides a human-led, multi-surface Al workflow system that separates Al simulation activity from human-controlled execution, enforces a non-permeable action barrier, and employs a cognitive mental-model engine that mimics human analytical reasoning and authenticity judgment.
[0031] Key aspects include:
[0032] • Al Simulation Surface (sandbox domain): Al engine simulates actions, highlights elements, animates tool paths, generates warnings, and explains logic without issuing real commands.
[0033] • Human Execution Surface (operational domain): Only a human operator can trigger real commands, modify live data, and perform final execution.
[0034] • Non-Permeable Control Barrier: Prohibits any Al-generated signal from directly controlling or modifying the live operational interface.
[0035] • Human-Gated Approval Framework: Every Al proposal is presented for human ACCEPT / MODIFY / DECLINE decisions, optionally with multi-factor or biometric confirmation.
[0036] • Cognitive Mental-Model Engine: Emulates human-style reasoning, evaluates authenticity and safety, assigns risk weights, produces human-readable explanations, and incorporates human feedback.
[0037] • Multi-Surface Architecture: Operates across monitors, laptops, smartphones, tablets, vehicle infotainment screens, AR / VR displays, projections, kiosks, holographic interfaces, wearables, and remote browser sessions.
[0038] The invention further includes logging, audit, and compliance mechanisms that record Al proposals, human approvals, rejections, authenticity evaluations, reasoning chains, and executed actions, enabling regulatory, legal, and enterprise governance review.
[0039] BRIEF DESCRIPTION OF THE DRAWINGS
[0040] • FIG. 1: Block diagram of multi-surface architecture showing Al sandbox domain and human execution domain connected by a one-way proposal channel. • FIG. 2: Flow diagram of Al-to-human approval workflow with ACCEPT / MODIFY / DECLINE decision gateways.
[0041] • FIG. 3: Non-permeable action barrier comprising hardware and software interception layers.
[0042] • FIG. 4: Schematic of mental-model cognitive engine showing perception, human-logic emulation, risk assessment, authenticity evaluation, explanation, scoring, and feedback layers.
[0043] • FIG. 5: Example authenticity scoring interface with overlays, highlighted regions, and cognitive explanation text.
[0044] • FIG. 6: Representative multi-surface configurations (dual screens, mirrored displays, AR overlays, VR plus monitors, kiosks, projections, vehicle screens, remote terminals).
[0045] • FIG. 7: Example workflows across automotive, medical, industrial, administrative, and forensic applications.
[0046] DETAILED DESCRIPTION OF THE INVENTION
[0047] (Figures Anchored: FIG. 1 = 100-series, FIG. 2 = 200-series, FIG. 3 = 300-series, FIG. 4 = 400-series, FIG. 5 = 500-series, FIG. 6 = 600-series, FIG. 7 = 700-series)
[0048] 1. System Overview
[0049] The invention comprises a human-led, multi-surface artificial intelligence workflow system that separates Al simulation activity from human-controlled execution activity.
[0050] As shown in FIG. 1 (100-series items), the system includes:
[0051] • Al Simulation Domain (110) • Human Execution Domain (120)
[0052] • Non-Permeable Action Barrier (130) positioned between them
[0053] • Cognitive Mental-Model Engine (140) for human-style reasoning
[0054] • Human-Gated Approval Framework (150) ensuring no Al-generated operation is executed without explicit human authorization
[0055] • Multi-Surface Display System (160) enabling operation across screens, devices, projections, AR / VR surfaces, or remote terminals
[0056] • Logging and Compliance Module (170) capturing reasoning traces, actions, approvals, and authenticity evaluations
[0057] 2. Multi-Surface Architecture
[0058] 2.1 Definition of “Surface”
[0059] As shown in FIG. 6 (600-series items), a “surface” may include:
[0060] • 600: monitors
[0061] • 602: smartphones
[0062] • 604: tablets
[0063] • 606: vehicle displays
[0064] • 608: AR / VR headsets
[0065] • 610: projected surfaces
[0066] • 612: kiosks
[0067] • 614: remote web terminals
[0068] Any subset of these surfaces may function as sandbox or execution domains.
[0069] 2.2 Al Simulation Surface
[0070] The Al Simulation Domain 110 is a sandboxed environment in which the Al can:
[0071] • highlight UI elements (112)
[0072] • draw arrows or boxes (114)
[0073] • animate tool paths (116) • simulate pointer motion (118)
[0074] • generate warnings (119)
[0075] All simulated actions occur only within the sandbox.
[0076] 2.3 Human Execution Surface
[0077] The Human Execution Domain 120 presents a live operational interface directly connected to real systems, devices, or workflows. Only human-initiated commands (122) can affect operational states. The Al is incapable of generating executable actions on this surface.
[0078] 3. Non-Permeable Action Barrier
[0079] As shown in FIG. 3 (300-series items), the Non-Permeable Action Barrier 130 includes:
[0080] • 310: hardware-level input interception
[0081] • 320: operating system command filtering
[0082] • 330: virtualization boundary
[0083] • 340: API command nullifier
[0084] • 350: blocked command log
[0085] The barrier enforces unidirectional flow: Al proposals only human; human execution.
[0086] Al outputs are transformed into non-executable proposal metadata (360) that cannot directly affect operational components.
[0087] 4. Human-Gated Execution Framework
[0088] As illustrated in FIG. 2 (200-series items), every Al-generated proposal is routed through a Human Approval Panel (210) consisting of:
[0089] • ACCEPT control (212)
[0090] • MODIFY control (214)
[0091] • DECLINE control (216) Final execution occurs only through human confirmation (220), which may require:
[0092] • biometric verification (222, 224)
[0093] • safety PIN (226)
[0094] • hardware switch (228)
[0095] • dual-operator confirmation (230)
[0096] If the human modifies a proposed action, the executed command may differ from the original Al recommendation.
[0097] 5. Cognitive Mental-Model Engine
[0098] The internal reasoning architecture is shown in FIG. 4 (400-series items). The Cognitive Mental-Model Engine 140 comprises:
[0099] • Perception Layer (410): extracts features from documents, images, metadata, signals, workflow states, or sensor data.
[0100] • Human-Logic Emulation Layer (420): applies reasoning patterns analogous to trained human examiners.
[0101] • Risk Assessment Layer (430): assigns weighted risk or suspicion scores (432) to anomalies (434).
[0102] • Authenticity Evaluation Layer (440): evaluates fonts (442), seals (444), signatures (446), layout (448), linguistic patterns (450), metadata (452).
[0103] • Explanation Layer (460): produces human-readable reasoning (462) and highlights regions (464).
[0104] • Score Synthesis Layer (470): combines outputs into authenticity scores (472).
[0105] • Feedback Layer (480): receives human corrections (482) and updates parameters.
[0106] 6. Authenticity Evaluation Interface
[0107] As shown in FIG. 5 (500-series items), the system may generate an authenticity interface comprising:
[0108] • 500: document display • 510: highlighted anomaly zones
[0109] • 520: authenticity score
[0110] • 530: explanation panel
[0111] • 540: cognitive reasoning chain
[0112] • 550: heatmap overlay
[0113] • 560: metadata comparison region
[0114] This interface is displayed on a sandbox surface, ensuring evaluations do not modify original content unless explicitly approved by a human.
[0115] 7. Workflow Execution Across Industries
[0116] FIG. 7 (700-series items) illustrates applications across:
[0117] • 710: automotive diagnostics
[0118] • 720: paint / refinishing workflows
[0119] • 730: medical imaging and aesthetics
[0120] • 740: industrial layout and robotics
[0121] • 750: administrative / government workflows
[0122] • 760: software troubleshooting
[0123] • 770: identity and document authenticity (including pet documents)
[0124] Al provides guidance, simulations, authenticity checks, and risk evaluations in all domains, while execution remains strictly human-controlled.
[0125] 8. Logging, Audits, and Compliance
[0126] The Logging & Compliance Module 170 stores:
[0127] • 172: action logs
[0128] • 174: Al proposal logs
[0129] • 176: human approval logs
[0130] • 178: reasoning trace logs
[0131] • 179: authenticity evaluation logs Data may be stored as hashed or signed records for regulatory audits, insurance requirements, legal evidence, or enterprise governance.
[0132] 9. Multi-Surface Configurations and Anti-Design-Around
[0133] The invention covers any configuration of multiple surfaces as shown in FIG. 6, in which:
[0134] • at least one surface functions as sandbox domain (110)
[0135] • at least one surface functions as execution domain (120)
[0136] • the Non-Permeable Barrier (130) remains enforced
[0137] • the Cognitive Mental -Model Engine (140) continues to operate independent of number or type of surfaces
Claims
CLAIMSINDEPENDENT CLAIM 1 — SYSTEM1.A computer- implemented system, comprising: a first display surface configured to present an artificial-intelligence simulation environment in which an artificial intelligence (Al) engine generates proposed operational actions, visual guidance, predictive outputs, or authenticity evaluations; a second display surface distinct from the first display surface and configured to present a live operational interface; a non-permeable control barrier that prohibits any Al-generated action from directly controlling or modifying the live operational interface; and a human-operated approval mechanism that authorizes execution of selected Al-generated proposals within the live operational interface.DEPENDENT CLAIMS (System)2. The system of claim 1, wherein the first and second display surfaces comprise any combination of monitors, laptops, smartphones, tablets, vehicle infotainment panels, head- mounted displays, augmented-reality overlays, virtual-reality environments, projected surfaces, holographic displays, kiosk terminals, smart televisions, or remote web interfaces.
3. The system of claim 1, wherein the Al engine highlights user interface elements, animates tool paths, simulates pointer movements, or visually indicates recommended actions without issuing executable commands to the live operational interface.
4. The system of claim 1, wherein the non-permeable control barrier comprises operating system-level interception of input events, virtualization or containerization of the Alenvironment, blocking of Al-originated hardware or firmware commands, or filtering of Al-originated application programming interface (API) calls.
5. The system of claim 1, wherein the human-operated approval mechanism presents ACCEPT, MODIFY, and DECLINE options for each Al-generated proposal.
6. The system of claim 5, wherein human approval requires biometric verification, dual-confirmation by two distinct physical actions, a safety PIN, a physical switch, or a two-operator confirmation protocol.
7. The system of claim 1, wherein more than two display surfaces are present and any subset of the surfaces is configured as the Al simulation environment or the live operational interface.
8. The system of claim 1, further comprising an advisory mode and an enforcement mode, the enforcement mode restricting or halting execution of proposed operations until rule-based or safety-based criteria are satisfied.INDEPENDENT CLAIM 9 — ARCHITECTURE9.A non-autonomous action-execution architecture, comprising: a sandbox domain in which an Al engine simulates actions, annotates interface elements, or generates instruction sequences; an execution domain capable of performing real operations; a unidirectional communication channel converting outputs of the Al engine into non-executable proposal metadata; and a human-initiated triggering mechanism that performs execution of one or more operations in the execution domain only upon explicit human confirmation.DEPENDENT CLAIMS (Architecture)10. The architecture of claim 9, wherein the sandbox domain and execution domain are separated by network segmentation, virtualization boundaries, or hardware input filtering.
11. The architecture of claim 9, wherein a control barrier intercepts and nullifies Al-generated input events at an operating system, hardware, or firmware level.
12. The architecture of claim 9, wherein the control barrier prevents Al-originated API calls from reaching operational systems and logs blocked attempts for compliance auditing.INDEPENDENT CLAIM 13 — REASONING ENGINE13.An artificial-intelligence reasoning engine, comprising: a perception layer extracting features from documents, images, data structures, logs, sensor data, or system states; a cognitive model emulating human analytical reasoning and authenticity judgment; a risk-assessment module assigning weighted suspicion levels to anomalies; a natural- language explanation generator producing human-readable justifications; and a score synthesis module generating at least one authenticity score, risk score, or confidence score.DEPENDENT CLAIMS (Cognitive Engine)14. The engine of claim 13, wherein the cognitive model is trained or tuned using labeled data from human experts in forensic examination, diagnostics, auditing, or workflow compliance.
15. The engine of claim 13, wherein the explanation generator identifies specific regions, tokens, or features contributing to risk or authenticity determinations.
16. The engine of claim 13, further comprising a feedback module configured to accept human corrections or overrides and update internal parameters.INDEPENDENT CLAIM 17 — AUTHENTICITY EVALUATION SYSTEM17.A multi-surface authenticity evaluation system, comprising: a first surface presenting an Al-generated authenticity analysis with overlays and human-style reasoning explanations produced by the reasoning engine of claim 13; a second surface presenting original reference material or operational content; and a control barrier ensuring authenticity evaluations do not directly modify the content on the second surface.DEPENDENT CLAIMS (Authenticity System)18. The system of claim 17, wherein authenticity evaluation includes comparison of fonts, seals, signatures, imagery, metadata, linguistic patterns, document structures, or layout features.
19. The system of claim 17, wherein authenticity scoring includes numerical scales, color-coded risk categories, or heatmaps overlaying regions of concern.
20. The system of claim 17, wherein authenticity and reasoning data are cryptographically signed or hashed to produce tamper-evident records.INDEPENDENT CLAIM 21 — METHOD21.A method for safe Al-assisted operation, comprising: receiving user input into an Al simulation interface on a first display surface; generating, by an Al engine, a proposed action sequence or authenticity evaluation using human-modeled reasoning; displaying the proposal on the first display surface as non-executable guidance; receiving a human approval input; and executing an approved action within a separate operational interface on a second display surface isolated by a non-permeable control barrier.DEPENDENT CLAIMS (Method)22. The method of claim 21, further comprising recording logs of the proposed action sequence, the human approval input, the executed action, and the reasoning process.
23. The method of claim 21, wherein rejecting an Al proposal causes the Al engine to generate at least one alternative proposal.
24. The method of claim 21, wherein the method is applied to automotive diagnostics, paint-mixing workflows, medical imaging interpretation, industrial layout planning, software troubleshooting, administrative workflows, or authenticity and fraud detection.
25. The method of claim 21, wherein the Al engine evaluates authenticity for pet-related documents, breeder certificates, microchip records, veterinary records, or government-issued identity documents.
26. The method of claim 21, further comprising dynamically assigning sandbox and execution roles among three or more surfaces based on operator preference, device capability, or regulatory policy.PLATFORM + CROSS-DEPLOYMENT CLAIMS27. A platform comprising the systems or architectures of any one of claims 1-26 integrated into a unified Al-enhanced operational workflow environment.
28. The system of claim 1, wherein the first and second display surfaces are rendered on a single physical device as distinct windows, panes, virtual desktops, or application contexts, the control barrier enforcing separation between simulation and operational contexts.
29. The system of claim 1 , wherein control of the live operational interface is restricted to a geographically or logically remote human operator over a network link, while the Al engine executes on a separate server or cloud platform.
30. The method of claim 21, wherein logs produced by the system are exported for insurance assessments, regulatory investigations, or legal proceedings.