{"schema_version":1,"research_id":"eoa_inverse_innovation_exp04_external_evaluation_20260802","source_assessment_id":"computability_boundary_mapping__art_aesthetics:PROPOSAL_FIRST:v0","cell_id":"computability_boundary_mapping__art_aesthetics","search_queries":["site:tate.org.uk conservation time-based media software art obsolescence artist requirements","site:si.edu time based media art conservation software preservation digital art","generative art exhibition software artwork technical failures curator platform interactive art conservation","formal verification creative coding generative art runtime sandbox p5.js exhibition","site:mattersinmediaart.org software-based art installation checklist risk assessment artist intent","site:moma.org media conservation software-based art emulation documentation","site:rhizome.org preservation emulation software art Webrecorder oldweb.today","site:guggenheim.org conservation software based art technical questionnaire","software-based art conservation code analysis risk assessment executable artwork paper","formal verification interactive digital art model checking generative art","museum generative software art sandbox watchdog reset exhibition runtime","computer-based art conservation source code analysis Guggenheim risk","Formal Verification for Node-Based Visual Scripts Using Symbolic Model Checking DOI PDF","Cousot abstract interpretation 1977 PDF principles of programming languages","Rice theorem undecidable semantic properties programs official reference","BLS software developers hourly wage May 2025 museum conservators wage","site:bls.gov/oes/2025/may software developers 15-1252 wage","site:bls.gov/ooh computer software developers median pay 2025","site:bls.gov/ooh education museum conservators median pay 2025","site:bls.gov/oes/current 25-4013 museum technicians conservators wage"],"sources":[{"source_id":"S1","title":"Handling Digital Assets in Time-Based Media Art","publisher":"Smithsonian Institution Archives","url":"https://siarchives.si.edu/blog/handling-digital-assets-time-based-media-art","source_class":"OFFICIAL_ORGANIZATION_DATA","publication_date":"2014-02-20","accessed_at":"2026-08-02","claims_supported":["Interactive and generative time-based works impose documented curatorial and conservation workflow obstacles.","Technical evaluation and monitoring have not consistently been cemented into museum procedures.","Smithsonian curators, conservators, registrars, and gallery staff were seeking resources and expertise for collection-specific needs.","Policies must distinguish artwork classes, variability, intended behavior, and changing software environments."]},{"source_id":"S2","title":"The Conserving Computer-Based Art Initiative","publisher":"Solomon R. Guggenheim Museum and Foundation","url":"https://www.guggenheim.org/conservation/the-conserving-computer-based-art-initiative","source_class":"OFFICIAL_GUIDANCE","publication_date":"n.d.","accessed_at":"2026-08-02","claims_supported":["The Guggenheim operates an identifiable computer-based-art conservation initiative serving museum staff, researchers, collectors, and the public.","Its work includes source-code analysis through collaboration with New York University computer scientists.","Computer-based artworks require documentation of digital and physical components beyond conventional collection-management records."]},{"source_id":"S3","title":"Matters in Media Art","publisher":"Museum of Modern Art","url":"https://www.moma.org/research/conservation/matters-in-media-art","source_class":"OFFICIAL_GUIDANCE","publication_date":"n.d.","accessed_at":"2026-08-02","claims_supported":["MoMA, SFMOMA, Tate, and New Art Trust created a collaborative program for acquisition, lending, and care of time-based media.","Time-based artworks are complex installed systems requiring new skills and cross-functional collaboration.","Artist-specific installation and technology requirements matter to stewardship.","The consortium reported a need for greater international agreement on care practices."]},{"source_id":"S4","title":"Risk Assessment as a Tool in the Conservation of Software-Based Artworks","publisher":"Electronic Media Review, American Institute for Conservation","url":"https://resources.culturalheritage.org/emg-review/volume-two-2011-2012/falcao/","source_class":"PRIMARY_RESEARCH","publication_date":"2012","accessed_at":"2026-08-02","claims_supported":["A structured software-art risk-assessment method was applied to four Tate collection works, including interactive, randomized, networked, and spatially tracked installations.","Risk assessment can begin at acquisition and inform media requests, agreements, archiving, and artist/programmer documentation.","Successful installation of examined interactive works required collaboration with artists and programmers."]},{"source_id":"S5","title":"Emulation or it Didn’t Happen","publisher":"Rhizome","url":"https://old.rhizome.org/editorial/2020/dec/21/flash-preservation/","source_class":"OFFICIAL_GUIDANCE","publication_date":"2020-12-21","accessed_at":"2026-08-02","claims_supported":["Emulation and containerized legacy environments are established approaches for preserving and presenting executable digital art.","Different emulation methods have different compatibility, infrastructure, latency, and fidelity tradeoffs.","Emulated behavior should be compared against documentation of the original artwork.","Runtime emulation supports access but does not provide the candidate's proposed class-wide preflight guarantee."]},{"source_id":"S6","title":"Formal Verification for Node-Based Visual Scripts Using Symbolic Model Checking","publisher":"IEICE Transactions on Information and Systems","url":"https://www.jstage.jst.go.jp/article/transinf/E105.D/1/E105.D_2021EDP7063/_article/-char/en","source_class":"PRIMARY_RESEARCH","publication_date":"2022-01-01","accessed_at":"2026-08-02","claims_supported":["Visual scripts can be translated automatically into a symbolic model-checker representation for selected mechanically specified defects.","The method was evaluated on production scripts from Final Fantasy XV and detected targeted bugs in reasonable time.","Formal checking of restricted interactive visual programs is technically plausible, but the evidence does not establish verification of arbitrary generative artworks or aesthetic constraints."]},{"source_id":"S7","title":"Abstract Interpretation: A Unified Lattice Model for Static Analysis of Programs by Construction or Approximation of Fixpoints","publisher":"ACM Press","url":"https://cs.nyu.edu/~pcousot/COUSOTpapers/POPL77.shtml","source_class":"PRIMARY_RESEARCH","publication_date":"1977","accessed_at":"2026-08-02","claims_supported":["Abstract interpretation derives sound information about concrete computations through an abstract semantic domain.","The method can provide consistent but incomplete program properties and finite fixpoint approximations.","Imprecision is intrinsic to useful abstractions, supporting explicit possible-violation or unknown labels rather than universal exact claims."]},{"source_id":"S8","title":"Software Developers, Quality Assurance Analysts, and Testers","publisher":"U.S. Bureau of Labor Statistics","url":"https://www.bls.gov/ooh/computer-and-information-technology/software-developers.htm","source_class":"GOVERNMENT_OR_REGULATOR","publication_date":"2025-08-28","accessed_at":"2026-08-02","claims_supported":["The May 2024 median annual wage for software developers was $133,080 and for software quality-assurance analysts and testers was $102,610.","These wage benchmarks provide a conservative labor basis for 2026 resource-equivalent estimates before benefits, overhead, formal-methods specialization, and museum staff time."]}],"problem_evidence":{"support":"MODERATE","rationale":"Museum and conservation sources visibly document interactive and software-based artworks as complex, variable systems requiring technical evaluation, monitoring, class-specific policies, source-code analysis, artist collaboration, and new workflows. This establishes a consequential underlying problem. No opened source directly documents the candidate's more specific claimed baseline—preflight timeouts being coerced into approval or rejection, or universal palette/luminance/spatial assurances being publicly made—so that symptom remains unverified.","source_ids":["S1","S2","S3","S4"]},"stakeholder_evidence":{"support":"MODERATE","rationale":"The Smithsonian Time-Based Media Art Working Group, Guggenheim Conserving Computer-Based Art Initiative, and Matters in Media Art consortium are identifiable potential adopters or funders with expressed needs for technical procedures, source-code analysis, collaboration, and better stewardship practices. None expresses demand for this exact guarantee-bounded router or commits data, staff, or funding to a pilot.","source_ids":["S1","S2","S3","S4"]},"prior_art":{"proximity":"ADJACENT_PRIOR_ART","closest_analogues":[{"name":"Tate software-art risk assessment","similarity":"Already structures acquisition-stage technical risk analysis around institution and stakeholder objectives for executable, interactive, randomized, and networked artworks.","remaining_difference":"It does not publish a computability classification, model-relative guarantee lattice, or router separating exact, bounded, sound-incomplete, and unknown verdicts.","source_ids":["S4"]},{"name":"Guggenheim–NYU source-code analysis for computer-based art","similarity":"Combines museum conservation authority with computer-science analysis of artwork source code and detailed component documentation.","remaining_difference":"The opened evidence does not describe formal termination proofs, computability-boundary records, or guarantee-labeled preflight routing.","source_ids":["S2"]},{"name":"Symbolic model checking of node-based visual scripts","similarity":"Automatically translates restricted interactive visual programs into a model checker and mechanically detects specified defects on production scripts.","remaining_difference":"It targets particular visual-script defects in game development, not unrestricted executable artworks, curator-defined display invariants, artist-rights workflow, or abstention labels.","source_ids":["S6"]},{"name":"Abstract interpretation","similarity":"Supplies the established mathematical basis for sound but incomplete static analysis and finite approximations proposed by the candidate.","remaining_difference":"It is a general formal-methods foundation, not an exhibition intake system or evidence that the proposed abstraction faithfully models palette, luminance, spatial, sensor, and reset semantics.","source_ids":["S7"]},{"name":"Rhizome emulation and documentation comparison","similarity":"Provides runtime isolation or legacy-environment reproduction and checks reperformance against original documentation.","remaining_difference":"It supports containment, access, and fidelity review rather than proving class-wide safety or termination before exhibition.","source_ids":["S5"]}],"distinctive_claim_remaining":"For executable-art intake, adding an enforceable language/property contract and guarantee-labeled router to existing sandbox-and-curator review will reduce unsupported scope inflation—especially interpretations of timeout or sampled success as proof—while preserving UNKNOWN as non-dispositive and without materially reducing curator-rated fidelity for works inside the pilot fragment. This is falsifiable through blinded comparison of reports, label-retention audits, fragment coverage, curator fidelity ratings, and counterexample checks.","confidence":"MODERATE"},"implementation_evidence":{"support":"MODERATE","rationale":"Restricted visual-program model checking, abstract interpretation, emulated execution, source-code analysis, and acquisition-stage risk workflows are all demonstrated independently. The proposed offline pilot is therefore technically plausible. Missing evidence includes a semantics for the target artwork language, sound abstractions for graphical and sensor behavior, tractability at trace depth 20, access to source code and dependencies, rights to analyze archived works, proof review, and evidence that downstream staff will preserve UNKNOWN rather than treating it as rejection. Legal and authority feasibility depend on acquisition agreements and artist/platform permission; the read-only design limits safety risk.","source_ids":["S2","S3","S4","S5","S6","S7"]},"scores":{"meaningful_impact":{"score":3,"rationale":"Preventing false assurance, unjustified rejection, and artist-intent distortion would matter, but prevalence and realized harm from the specific timeout practice are unmeasured.","source_ids":["S1","S3","S4"]},"stakeholder_pull":{"score":4,"rationale":"Multiple major institutions have dedicated programs and explicitly seek technical procedures, collaboration, and class-sensitive stewardship, although none requests this exact intervention.","source_ids":["S1","S2","S3"]},"incremental_advantage":{"score":3,"rationale":"Guarantee labels and boundary records could improve on sandbox, emulation, source review, and generic risk assessment, but advantage over a carefully documented existing workflow has not been measured.","source_ids":["S2","S4","S5","S6"]},"distinctiveness_plausibility":{"score":3,"rationale":"No direct match was found for the complete museum-specific router, but nearly every technical and conservation component has close established prior art.","source_ids":["S2","S4","S5","S6","S7"]},"technical_implementability":{"score":4,"rationale":"Finite-state verification and sound abstraction are established for restricted program classes; the main uncertainty is semantic modeling and state explosion for the selected artworks.","source_ids":["S6","S7"]},"adoption_authority_feasibility":{"score":3,"rationale":"Museums already use cross-functional conservation teams and artist/programmer collaboration, but a specific curator, safety lead, corpus owner, and independent reviewer have not authorized this pilot.","source_ids":["S1","S2","S3","S4"]},"evidence_readiness":{"score":2,"rationale":"The next step is well specified, but source code, interpreter semantics, archived works, staff judgments, proof artifacts, and operational baselines are unavailable through bounded web research.","source_ids":["S2","S4"]},"safety_net_benefit":{"score":4,"rationale":"Explicit UNKNOWN, out-of-scope routing, read-only analysis, curator authority, and runtime containment provide a strong safety net against automated rejection and false clearance if labels are preserved.","source_ids":["S3","S4","S5","S7"]},"scalability":{"score":2,"rationale":"Reusable grammar and routing infrastructure could scale within one platform, but artwork-specific dependencies, artist intent, changing environments, abstraction refinement, and state explosion constrain cross-institutional scaling.","source_ids":["S1","S3","S4","S5","S6"]}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"50K_TO_250K","scope":"A 10–16 week partnered offline study of 12 archived works: interpreter freeze, three formal properties, restricted grammar, finite event model, bounded checker, baseline comparison, curator/conservator review, and independent formal-methods review.","confidence":"MODERATE","assumptions":["Approximately 0.5–0.8 formal-methods engineer FTE, 0.2 platform engineer FTE, 0.2 conservator/curator FTE, and limited independent-review effort.","Uses archived copies and existing compute; excludes acquisition of artwork rights, major code migration, and exhibition changes.","BLS developer wages are converted to 2026 resource equivalents with benefits, overhead, and specialist premiums."],"source_ids":["S8"]},"initial_deployment_startup":{"band_2026_usd":"250K_TO_1M","scope":"Productionize one interpreter-specific fragment, semantics, analysis service, result schema, audit record, access controls, corpus ingestion, documentation, security review, and staff training.","confidence":"LOW","assumptions":["One small multidisciplinary team for roughly 6–12 months.","No universal verifier or automated aesthetic assessment is included.","Source availability and rights are resolved by the adopting institution."],"source_ids":["S2","S3","S8"]},"operational_launch":{"band_2026_usd":"250K_TO_1M","scope":"Validate against a larger submission set, integrate with intake and sandbox workflows, conduct independent soundness and authority review, train curators and technicians, and run a monitored first exhibition cycle.","confidence":"LOW","assumptions":["Includes integration and verification labor but not new gallery hardware or artwork modification.","Every UNKNOWN remains subject to human review, increasing launch staffing.","Formal-methods specialization and institutional overhead exceed base wage rates."],"source_ids":["S3","S4","S8"]},"annual_recurring":{"band_2026_usd":"50K_TO_250K","scope":"Maintain language versions, models, proof and decision records, test corpus, dependencies, security controls, reviewer training, and per-work escalation for one platform.","confidence":"LOW","assumptions":["Roughly 0.5–1.0 combined engineering FTE plus fractional conservation and independent-review time.","Major new sensors, plug-ins, interpreters, or exhibition platforms trigger separately funded reclassification.","Compute remains modest relative to labor unless state-space bounds expand substantially."],"source_ids":["S1","S5","S6","S8"]}},"verified_pipeline_gates":{"externally_supported_problem":{"status":"YES","reason":"Official museum and primary conservation sources establish material workflow, documentation, variability, dependency, and technical-risk problems for interactive software art. The exact timeout-coercion symptom is still an evidence gap.","source_ids":["S1","S2","S3","S4"]},"externally_credible_adopter_or_authorizer":{"status":"YES","reason":"The Smithsonian working group, Guggenheim initiative, and Matters in Media Art institutions are identifiable organizations with relevant mandates and expressed needs. This establishes credibility, not commitment to the candidate.","source_ids":["S1","S2","S3"]},"distinct_testable_incremental_claim":{"status":"YES","reason":"The remaining claim can be tested against sandbox-and-curator reports using report-scope accuracy, UNKNOWN preservation, fragment coverage, false-clearance checks, false-alarm causes, processing time, and curator-rated semantic fidelity.","source_ids":["S4","S5","S6","S7"]},"bounded_next_evidence_step":{"status":"YES","reason":"A 12-work, one-interpreter, three-property, depth-20 offline study has fixed comparators, stopping conditions, outputs, and falsifiers.","source_ids":["S2","S4","S6","S7"]},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"A read-only pilot that cannot alter submission status, artwork code, or exhibition configuration is low risk if corpus permission, artist/source-code rights, curator authority, and explicit label preservation are prerequisites. Absence of those permissions blocks execution but is not an intrinsic unresolvable stop.","source_ids":["S3","S4"]},"credible_cost_scope_and_range":{"status":"YES","reason":"All four bands identify labor scope and exclusions and are anchored to official software labor data, with low confidence retained where corpus complexity and institutional overhead are unknown.","source_ids":["S8"]}},"next_evidence_step":"Secure a named museum or executable-art platform, curator/conservator authorizer, source-code rights, and read-only access to 12 archived works spanning documented language features. Freeze one interpreter; formally define palette membership, maximum luminance, protected-region occupancy, reset semantics, a finite event alphabet, and trace depth 20. Build an enforceable restricted grammar and exhaustively check its finite model; separately run the current sandbox/watchdog plus curator notes, property-based interaction testing, and manual source review as comparators. Have a reviewer independent of implementation check the semantics, abstraction soundness, coverage claim, and any unrestricted-core reduction or totality proof. Blind reviewers to workflow and measure fragment coverage, analysis time, concrete violations, abstraction false alarms, UNKNOWN rate, downstream label retention, report-scope overstatement, and curator-rated semantic fidelity. Falsify or redesign if any modeled reachable violation receives clearance, enumeration fails to cover its declared envelope, fewer than 8 of 12 works retain behavior essential to curator/artist intent inside the fragment, any downstream reviewer treats UNKNOWN as pass or fail, or the bounded method costs more analyst time without improving scope accuracy over comparators. Stop after 12 works and make no unrestricted computability claim without a checked proof.","blocking_evidence":["No direct evidence that an actual exhibition platform currently coerces verifier timeout into approval or rejection or publishes the stated universal visual guarantees.","No adopter has committed authority, staff time, funding, or an archived-work corpus.","No versioned artwork language, interpreter semantics, finite input model, or formal display-property specification is available.","No checked constructive proof or undecidability reduction has been produced for the deployed language and guarantee.","No evidence establishes soundness, false-alarm rate, tractability, or expressive coverage on real artworks.","Source-code access, acquisition-agreement rights, artist consent requirements, visitor-data handling, and independent-review arrangements are unresolved.","Costs exclude institution-specific procurement, rights clearance, legacy dependency recovery, and major exhibition hardware."],"research_disposition":"PARTNERED_RESEARCH_PROGRAM","world_novelty_boundary":"World novelty, patentability, freedom to operate, market size, and realized impact were not measured. Within this bounded eight-source search, no direct instance of a museum preflight system combining enforceable language fragments, formal computability classification, exhaustive bounded traces, sound abstraction, explicit UNKNOWN routing, curator authority, and version-linked guarantee records was found. The components are nevertheless established or adjacent practices, so absence of a direct match is not evidence of world novelty.","arm":"PROPOSAL_FIRST","candidate_version":0,"controller_recommendation":{"action":"STOP_EMPIRICAL_RESEARCH_NEEDED","repairable":true,"material_progress_observed":false,"progress_targets":["Obtain written pilot authorization and identify the curator, platform safety lead, corpus owner, artist-rights contact, and independent formal-methods reviewer.","Verify the specific baseline failure mode by auditing how recent sandbox timeouts, crashes, and sampled successes were translated into decisions and public claims.","Freeze and publish the interpreter, grammar, input encoding, external-capability register, property semantics, bounds, and output-label contract.","Run the 12-work comparator study and report fragment coverage, runtime, false alarms, concrete counterexamples, UNKNOWN frequency, scope-overstatement rate, and curator-rated fidelity.","Produce and independently check the restricted-fragment correctness argument, abstraction soundness argument, bounded-enumeration coverage certificate, and any unrestricted-core computability proof.","Refine startup, launch, and recurring costs using observed engineering, conservation, review, compute, rights-clearance, and integration hours.","Demonstrate that downstream interfaces and decision-makers preserve UNKNOWN and POSSIBLE_VIOLATION without converting them into automatic rejection or clearance."],"reason":"Bounded web research establishes a real adjacent institutional need, credible adopters, mature component methods, and a testable incremental claim, but it cannot determine semantic fidelity, corpus coverage, analyzer soundness, tractability, staff behavior, rights, or comparative workflow value. Those questions require proprietary archived artworks, institutional authorization, independent proof review, and live staff testing; further general web search would not resolve the decisive evidence gaps."}}