An intelligent guard. A persuasive agent. A button that should never be pressed.
If the enforcement layer uses intelligence, the enforcement layer can be attacked with intelligence. Prompt injection, context drift, and adversarial reasoning all exploit the same capability the guard uses to evaluate.
ZLAR removes intelligence from the enforcement path entirely. The gate pattern-matches against signed policy. It has no reasoning to exploit, no confidence to erode, no conversation to have.
Read the formal proof · Interactive walkthrough · Source code