OpenAI 2026 hackathon

Constitutional Runtime for Autonomous Systems (CRAS)

A pre-execution authorization runtime that requires evidence before autonomous action. Deterministic protocols, not AI model outputs, govern whether an endpoint may execute.

Solo project by Bruce Tisler · 3 likes · 1 comments

Archive position — measured, not model output

3 likes on Devpost

128 of the 7,856 archived projects have more likes, and 93 share exactly 3 — so this project's #149 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

The description states that Constitutional Runtime for Autonomous Systems (CRAS) is a pre-execution authorization runtime designed to separate reasoning from authorization in autonomous systems. The author, Bruce Tisler, describes it as an architectural pattern rather than a single application, intended to govern execution through deterministic protocols rather than AI model outputs.

Key elements:

  • CRAS operates on the sequence: Observation → Inquiry → Evidence → Authorization → Execution
  • It uses a deterministic authorization kernel and requires evidence before execution
  • The system is demonstrated with medication delivery but is claimed to be applicable to robotics, software agents, workflow automation, and other autonomous systems
  • The project was built as a layered architecture using modern tools like Next.js, Node.js, OpenAI APIs, and React

The most important open question: What evidence exists that this architectural approach has been validated in real-world deployment or that there is market demand for such a system? The description does not provide any traction data, customer feedback, revenue, or adoption metrics.

Back to contents

What The Product Actually Is

The description states CRAS is:

  • A pre-execution authorization runtime
  • A deterministic authorization kernel
  • An architectural pattern for autonomous systems
  • A system that separates reasoning from authorization
  • A layered architecture with independent inquiry state, evidence records, authorization grants, and execution records
  • A demonstration including a simulator, physical robot endpoint, visual protocol inspection, replayable scenarios, and automated validation

The author describes it as a runtime that "evaluates required conditions through deterministic protocols" rather than allowing AI models to determine action authorization.

Back to contents

Positioning & Claim Evolution

The description states:

  • CRAS is positioned as an alternative to traditional "Observe → Plan → Execute" patterns
  • It introduces the sequence: Observation → Inquiry → Evidence → Authorization → Execution
  • The core claim is that authorization should be governed independently of AI models
  • The system is described as a mechanism for "safe delegation"
  • It positions itself as a solution to the question: "Should an AI model determine when an action is authorized, or should authorization be governed independently of the model?"
  • The author emphasizes it's an architectural pattern rather than a single application
  • It's presented as a way to make autonomous systems "deterministic" rather than dependent on AI outputs

Back to contents

Target Customer & ICP

The description states:

  • The target is autonomous systems broadly, including robotics, software agents, workflow automation, and other autonomous systems
  • Specific demonstration use case: medication delivery
  • The author identifies as a researcher who wants to make this accessible to "domain experts who know exactly what their field is missing"
  • The system is described as applicable to "healthcare and regulated environments"
  • It's positioned for "industrial automation" and "software agent workflows"

Back to contents

Business Model & Pricing Evidence

Not evidenced. The description does not contain any information about pricing, revenue models, monetization strategies, or business model details.

Back to contents

Technical & Delivery Signals

The description states:

  • Built with: api, better-sqlite3, codex, github, gpt-5, json, next.js, node.js, openai, playwright, react, sqlite, typescript, vercel, vitest, zod
  • Developed as a layered architecture
  • Includes deterministic authorization kernel
  • Features evidence-backed authorization
  • Includes simulator and physical robot endpoint
  • Has visual protocol inspection capabilities
  • Supports replayable scenarios
  • Uses automated validation through browser and unit tests
  • OpenAI Codex was used extensively for implementation
  • The system maintains inquiry state, evidence records, authorization grants, and execution records independently of the reasoning model

Back to contents

Traction & Maturity Signals

Not evidenced. The description contains no information about:

  • Revenue or customers
  • Product adoption or usage metrics
  • Market traction or user feedback
  • Commercial deployment or production use
  • Growth indicators or milestones beyond the hackathon demonstration

Back to contents

Competitive Context

Not evidenced. The description does not contain any information about:

  • Competitors in the autonomous systems authorization space
  • Market positioning relative to existing solutions
  • Competitive advantages or differentiators
  • Industry landscape or market size

Back to contents

Key Risks & Red Flags

Inferences based on the description:

  • The system is described as a "research concept" that was transformed into a "functioning runtime" - this suggests it's in early development phase with limited real-world validation
  • The author states they are "a researcher, not a professional software engineer" which raises questions about engineering maturity and scalability
  • The demonstration focuses on "medication delivery" and "single endpoint" scenarios, suggesting limited scope of current application
  • The project was built for a hackathon, indicating it may be experimental rather than production-ready
  • The architecture is described as "applicable to robotics, software agents, workflow automation" but no evidence of actual implementation or deployment in these areas

Back to contents

Diligence Questions To Ask The Founders

  1. What specific autonomous systems have you actually deployed this architecture in?
  2. How does CRAS handle edge cases where evidence cannot be obtained within reasonable timeframes?
  3. What are the performance implications of requiring deterministic protocols for authorization?
  4. Can you demonstrate how the system would work with multiple concurrent endpoints?
  5. How do you plan to scale this architecture beyond the current demonstration scope?
  6. What specific regulatory or compliance requirements does this system address in healthcare/industrial settings?
  7. How does CRAS handle situations where evidence is ambiguous or incomplete?
  8. What are the actual technical challenges that remain for production deployment?

Back to contents

Investment/Partnership Verdict

Not evidenced. The description provides no information about:

  • Financial performance or revenue
  • Market opportunity size
  • Competitive positioning
  • Go-to-market strategy
  • Team experience or track record
  • Investment requirements or use of funds
  • Partnership opportunities or strategic fit

The project is described as a research concept that was transformed into a "functioning runtime" through hackathon development. The author identifies as a researcher rather than professional software engineer, and the demonstration focuses on a single endpoint scenario. There is no evidence of commercial traction, customer validation, or market demand beyond the author's own description.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.