What a control device inherits from the abstraction it is plugged into, measured on ToxTwin V2.4
Two molecules, one stereocenter apart. One service. One number. On 15 July 2026, ToxTwin V2.4 returned fourteen identical toxicity scores for 17β-estradiol and 17α-estradiol and declared both inside its applicability domain. The device was not miscalibrated. It reported, correctly, on an object from which the difference had already been removed. The condition under which that happens is narrow enough to be worth naming: an applicability domain computed downstream of the featurization it is meant to qualify measures a proximity, never a capacity. Remove the shared abstraction and the claim dissolves, which is what makes it a claim rather than a complaint. The artifact under audit here belongs to this Institute, is named rather than anonymized, and the audit was not commissioned.
17β-estradiol and 17α-estradiol are C17 epimers: same formula, same mass, same topological graph, five stereocenters of which exactly one diverges. The 17α form is a markedly weaker agonist of the nuclear estrogen receptor (Kuiper and colleagues), both forms are stable, and neither converts into the other in vivo. Submitted to the V2.4 service, they return the same fourteen scores to the third decimal: NR-ER at 0.5588, hERG at 0.8488, applicability domain composite at 0.4673, is_in_domain: true on both. A third string, the same skeleton with every stereocenter left unspecified, returns the same composite and the same fourteen scores, together with a regulatory paragraph citing ICH S7B about this molecule. That string is not a molecule. It is an equivalence class of stereoisomers of which estradiol is one member, and the domain certified it.
What this establishes is bounded, and the bound matters. Nothing here says ToxTwin is wrong about 17β-estradiol. It says the experimental divergence is documented, the device returns one number, and it is therefore wrong about one of the two without being able to say which.
Two questions exist about any query. Does it resemble what I have seen, and which of its properties survive my encoding. The canonical literature settles which one the field asks: Dimitrov and colleagues in 2005, then Sahigara and colleagues in their comparative survey, define the applicability domain as a domain of structural similarity. The domain therefore never promised the preservation of information, and the strongest objection to this article is that the defect lies in the featurization while the domain is merely right about an inadequate space.
That objection is the argument, and it arrives one link too early. Capacity here does not mean model capacity, representational capacity or VC dimension. It means information preservation: which properties of the object survive the featurization. A correct report of conformity to an inadequate space, published as is_in_domain: true, stops being a correct report the moment anything downstream reads it as a permission to use.
The blindness is not a shared architecture. The structural term reads a Morgan fingerprint at radius 2 into 2048 bits. The model reads a 163-dimensional atom featurization of the benchmark kind. The neighbour and density terms read the latent embedding of a third encoder, older than the two that serve the fourteen predictions and serving no prediction itself. Three computation paths, three representations, no shared line of code, and one shared convention inherited from library defaults and benchmark usage: the chiral tag is never read. RDKit’s fingerprint generator exposes an includeChirality argument whose default is False, and that default is documented library behaviour rather than an internal of this system.
The measurement is reproducible in three lines. On RDKit 2026.03.3, the Tanimoto similarity between the two epimers computed with the probe’s own configuration is 1.0000. Computed with useChirality=True, same molecules, same library, it is 0.8182. The information was present and a default argument discarded it. The IUPAC identifier makes the same point in its own grammar: the three states share the connectivity block VOXZDWNPVJITMN and differ in the stereochemistry block. The featurization computes the equivalent of the first block and calls it the molecule.
Which invites the repair, and the repair is the mistake. Set the flag to True on both sides and the epimers separate, but the enriched representation still discards conformation, protonation state, tautomeric equilibrium and solvation, and whatever the model then fails to see, the probe fails to see with it while reporting a proximity with undiminished confidence. Flipping the flag moves the boundary. It does not remove the bound. Stereochemistry is the witness here, never the defendant.
Once information has survived the representation, a second and independent limitation appears, and it belongs to arithmetic rather than to encoding.
Lemma of non-veto. Let s = Σ wᵢxᵢ with xᵢ ∈ [0,1], Σwᵢ = 1, and a decision s ≥ θ. Term i can impose a refusal only if 1 − wᵢ < θ, that is, only if wᵢ > 1 − θ. For all n terms to hold a veto, θ > (n−1)/n is required.
ToxTwin serves weights of 0.30, 0.40 and 0.30 against a threshold of 0.40. The minimum weight for a veto is 0.60, no term reaches it, and with three terms every term would hold a veto only above a threshold of 0.667. The instance is arithmetic on the decomposition the API already returns: for 17β-estradiol the Tanimoto and KDE terms alone contribute 0.4024, so zeroing the heaviest term, the one measuring position in the model’s own latent space, and letting it vote the molecule outside, leaves the composite at 0.4024 and the molecule admitted. No calibration removes that property, because it is not a calibration property.
is_in_domain is a boolean where the measure is continuous. A proximity becomes an authorization by crossing a comparison operator, and nothing in the pipeline performs that inference while everything downstream depends on it. This is an instance of what Article VI of this corpus named the promotion gap, and it is the first one the Institute has found in its own product. The refusal side is symmetric: cisplatin returns a composite of 0.05 and is_in_domain: false, with its kNN and KDE terms both at zero and the 0.05 entirely structural, and the fourteen scores are emitted anyway with an interpretive paragraph. The domain is consultative. The interface is not.
One reported fact belongs here and its consequence must be kept narrow. All three terms are computed against a reference corpus of 11,414 molecules labelled for two endpoints, mutagenicity and cardiac channel inhibition, while the twelve Tox21 labels live in a separate dataset and never enter the domain computation. The reference cloud is therefore not the training corpus of twelve of the fourteen endpoints the field authorizes. That is all the fact supports.
The tempting reading is that a particular team made particular mistakes and better engineering closes the matter. The architecture forbids it. ToxTwin serves fourteen endpoints from two routed encoders, seven each, and each encoder induces its own latent space, therefore its own metric, therefore its own neighbourhood relation. A molecule near the training corpus under one encoder may be far from it under the other, and no scalar expresses both. A unitary domain score over a routed ensemble has two options: select one space and stay silent about the seven endpoints served by the other, or aggregate across spaces and inherit the lemma above. Both branches fail, and the second fails by a theorem rather than by an oversight. This is the tri-routed V2.4 architecture reading its own consequence.
The external corroboration converges and its limits travel with it. von Borries and colleagues report that the Mansouri standardization protocol removes inorganic and organometallic compounds before modeling and that uncertainty estimates on those compounds are overconfident, which they read as a coverage defect to be closed with better descriptors. Their mean Jaccard distance of 0.81 for non-standardized compounds against 0.57 for standardized ones sits close to a figure measured here on carboplatin, and the proximity is a convergence of regime rather than an identity: different corpora, different fingerprints, different protocols. Weaver and Gleeson computed the domain inside the model’s own descriptor space in 2008 and said so plainly. That was not an oversight to point at twenty years later. It was a paradigm, and the assumption became implicit to the point of no longer being discussed.
Principle of representational separation. The information available to a governance device is bounded by the information contained in the representation it is plugged into. When that representation and the controlled system’s representation descend from a common abstraction, the bound inherits that abstraction’s losses whatever the device’s calibration.
Common factor criterion. An audit can be informative about a property destroyed by the model only if it does not share the factor that destroys it.
The ordering this rests on is old and elementary: Blackwell established the comparison of statistical experiments in 1953, and the useful consequence is that a quantity computed downstream of a channel carries no more information about the state than the channel carried. The criterion is necessary and not sufficient, and the distinction matters more than the criterion. Failing it is disqualifying; passing it guarantees nothing, since an audit sharing no factor with the model may still be too noisy to detect the property. Sufficiency, where it can be argued at all, is indexed on a named property, which yields the concession that costs the most: there is no property-agnostic audit. An audit is always the audit of an enumerated list. That is the same discipline the gate of The Model Was Never the Object already demanded, where validity is Required(τ) contained in Supported(τ), the joint envelope of applicability domain and delegated authority. This article is the audit of one half of that envelope, and it finds the half measuring something else.
Where this stops being an argument and becomes a specification: a validity port should not expose a proximity. It should expose which properties of the object survive the featurization. For either epimer, such a port reports five stereocenters present and zero encoded, without running the model, without a reference corpus, without calibration, without a test set. That is a property of the model rather than of the query, it is deterministic, and it is computed by reading the call graph.
The objection to a port is regress: if it must read a representation to report what another representation lost, what audits the port. The answer is positional. It needs no richer representation, it needs an earlier one. The parser still holds the five stereocenters at the moment the featurizer declines to read them, so the port compares the parser’s object against the featurizer’s computation path and reports the difference. It is not plugged in beside the model. It is plugged in before it. The corollary dissolves the composition problem rather than arguing with it: if each routed model has its own featurization, ports are per model by construction, and there is no single domain to compute because there was never a single question to answer.
The thesis holds for applicability domains whose computation descends from a factor they share with the model and which destroys the property at issue. It does not hold for an audit retaining information the model discards, and the refuting observation is nameable: an applicability domain computed on three-dimensional, quantum or geometric descriptors, correctly flagging the unencodable. The non-veto lemma holds for weighted composites with a threshold, not for single-measure domains such as leverage, Mahalanobis distance or range-based methods, which have other problems. The port falls under its own principle, since the parser is an abstraction too, having already discarded conformation, protonation state and solvation.
The evidence splits, and the split should be visible rather than smoothed. One half any reader reproduces: the fingerprint primitive is blind by default, the epimers collide at 1.0000 under it and separate at 0.8182 without it, the connectivity block is shared by all three states, and the service returns one number for all three. The other half is reported from source not published here: that two of the three terms descend from one twelve-dimensional projection retaining 80.2 percent of the variance of a 512-dimensional embedding, that the control is computed in a latent space serving no prediction, that the reference corpus carries two of the fourteen endpoints. The thesis rests on the first half. The second explains the mechanism, and a reader who declines it keeps the fact and loses the reason, which makes a shorter article rather than a different one.
An instrument that cannot tell you what it failed to see will tell you that it saw nothing wrong.
Full argument, the three objections raised and answered, the InChIKey evidence, the arithmetic of the non-veto lemma and the references (Dimitrov, Sahigara, von Borries, Weaver and Gleeson, Blackwell) in the PDF below (9 pages).
See also: The Model Was Never the Object · Governing AI: from the cost of the token to the price of the decision · The Asset Is No Longer the Model · Integration is a deliverable. Conformity is an institution. · To represent is not to reproduce
Doctrinal notes and explorations on AI in regulated systems. Once or twice a month. One-click unsubscribe.