Cross-Model Consensus Gating.
Multiple independent model families must agree before sensitive actions dispatch. 25 claims.
For any typed-action invocation classified at or above a configurable sensitivity tier, dispatch is permitted only when at least N independent model families propose the same typed-action with the same canonical input parameter values. The model families are physically isolated by separate process / container / hardware boundary, drawn from distinct vendor lineages, and each family signs its proposal under a hardware-attested per-instance key. A consensus aggregator counts only those signed votes whose canonical-serialisation byte-equivalence matches a reference vote and refuses dispatch with a typed REASON event if consensus is not reached within a bounded time window. Resists single-model prompt injection by requiring the attacker to compromise N independent model families simultaneously. Filed 4 May 2026 as GB2610421.6.