What does a routed decision leave behind?

Training optimizes a loss. Deployment, today, optimizes nothing — the model runs and the answer is delivered. The receipt is the missing artifact: a decomposed, signed, replayable trace of which primitives ran, how many joules each cost, and what verifiability the output carries.


A bill is not a receipt.

Today's AI invoice has a line item: tokens processed. That's a bill. It tells you what the vendor charged. It doesn't tell you what the work cost, which mechanisms ran, or whether the answer can be checked. The buyer is paying for an output they cannot decompose, against a price they cannot verify, with no way to compare vendors except on outcomes.

A receipt is different. It carries the trace of the decision: every primitive that ran, the thermodynamic floor of each, the impedance mismatch on the deployment hardware, the verifiability class the output qualifies for, and a signature from the runtime that produced it. The receipt is auditable. The receipt is comparable. The receipt is the thing the cost function was made to produce.

Without a receipt, every AI claim is unfalsifiable. "Our model is more efficient." Against what? Measured how? With what verifier? The receipt makes the claims falsifiable, which makes them useful. An unfalsifiable claim is marketing. A claim with a receipt is engineering.


The deployment-time objective nobody optimizes.

The field has spent a decade optimizing one thing: the training-time loss. Deployment optimizes nothing — the function runs, returns, repeats. There is no objective.

minimize E(x)   subject to   V(x) ≥ Vrequired

The deployment-time objective · minimize energy, subject to verifiability

The objective is simple: among all candidate mechanisms that can satisfy the verifiability requirement, pick the lowest-cost. The receipt is the optimization target made measurable. Without it there's no E and no V to optimize. With it, the cost function becomes a routing problem with a closed-form answer for every input.

The same E that the thesis equation describes after a decision runs is what the cost function estimates before it runs. The receipt closes the loop: estimate, run, measure, compare estimate to receipt, update the estimator. The receipt is how the system learns to route better over time.


A worked receipt.

One decision, decomposed. The task is closed-form — an ISBN-13 check-digit validation. The router picks a deterministic mechanism. The receipt below is what comes back.

decision id #00072 timestamp 2026-05-13T19:42:18.337Z task validate ISBN-13 check digit: 978-0-13-468599-1 coordinate ⟨ Z₁, persistent, L₀, {parse, checksum, eq}, tokens, full, facts ⟩ router cost-fn/v0.4 · routed to deterministic-runtime

primitive θ(p) μ(p,H) cost isbn_parse 0.4 nJ 3.2× 1.3 nJ digit_extract 0.6 nJ 2.8× 1.7 nJ weighted_sum 0.3 nJ 2.5× 0.8 nJ mod_10 0.1 nJ 2.1× 0.2 nJ eq_check 0.1 nJ 2.0× 0.2 nJ

output true total energy 4.2 nJ baseline (LLM) ~2.5 J ratio 5.9 × 10⁸× lower-cost verifiability V₁ · full · decision-time signature deterministic-runtime/v0.4 · sha256:8a3f…c712 replayable yes · primitives are deterministic, hardware is fixed

Five primitives. Total energy: 4.2 nanojoules. The LLM-baseline equivalent for the same task: ~2.5 J. The receipt makes the gap measurable, the mechanism comparable, the cost auditable, and the output checkable in O(1) by re-running the deterministic primitives. This is the unit of information the cost function was designed to produce.


Six things that can't exist without it.

Verifiable claims

"Our model is 100× lower-cost" stops being marketing.

With receipts, the buyer can compare two vendors decomposition-to-decomposition. Without receipts, every efficiency claim is asserted, not measured.

Energy-denominated pricing

Price the work in the unit the work costs.

Joules per decision + a markup denominated in the same unit. The buyer verifies the price against the receipt. Tokens-and-seats stop being the proxy.

Audit trails

Decisions reconstructable, in court if needed.

A signed receipt with the primitive trace can be replayed against the same input on the same hardware version. Defensible. Regulators-ready.

Capacity planning

Joules per workload, not tokens per quarter.

Receipt streams produce real distributions of cost per task class. Capacity decisions become "X mJ p99 at Y QPS" instead of guesswork.

Debugging cost spikes

"Why did the bill jump 4× last Tuesday?"

Without receipts: nobody knows. With them: the answer is in the decomposition — a routing regression, a cache invalidation, a model upgrade with worse μ.

The system learns to route

Compare estimate to receipt. Update the estimator.

The cost function's confidence output is meaningless without ground truth to calibrate against. Receipts are the ground truth.


The receipt has to be checkable too.

A receipt you cannot audit is just a different kind of marketing. The format has to be designed for verifiability of the receipt itself, not just verifiability of the output.

Three properties make the receipt auditable. Decomposition: every primitive is in the published 258-primitive basis, with a known Landauer floor θ(p). Replayability: deterministic primitives on fixed hardware produce identical traces every time. Signature: the runtime that produced the receipt is identified and versioned. The buyer can re-run the decomposition, check the floor against published silicon specs, and verify the signature against the vendor's public key.

There's an honesty boundary worth naming. θ(p) is exact. It comes from physics; you can derive it. μ(p, H) is estimated — vendor specs are rarely complete, and per-instruction energy is sometimes opaque. So the receipt is an exact lower bound times a calibrated estimate. That's still a million times better than a scalar bill, and the gap between θ and the observed cost is itself an indictment of the mismatch.

A receipt you cannot audit is marketing. A receipt you can re-run is engineering.


The unit. The artifact. The substrate.

The cost function names the choice. The receipt is what the choice leaves behind. Composition is what receipts add up to. Verifiability is the axis the receipt's V column reports.