← Blog
May 19, 20267 minpractice

Why I write a preprint about galaxies while running an AI automation practice

On the side of the consulting work I run a research programme called Neural Cosmology. Here is why those two are the same job, not two.


Clients sometimes ask. The contract is for an AI automation rollout, or an audit trail, or a regulatory-immunity build, and a few weeks in someone notices the GitHub bio: independent researcher, Pointer Architecture preprint, three books in progress. The follow-up is always polite, and always the same. "I'm just curious — what does the galactic-rotation thing have to do with the AI work?"

The honest answer is that they are the same job at different scales of consequence.

I write under two brands. The business and consulting work happens here, at mikefluff.com, as the Business Doctor. The research and the books happen at neuralcosmology.com, as Mikhail Savchenko, who is also me — one person writing through two doors. The branding is a courtesy to the reader; most people who land on the consulting page don't want a thirty-page argument about whether memory-density is a scalar field, and most people who land on the preprint don't want pricing for an AI privacy review. Splitting the doors keeps both rooms tidier.

But the toolkit is shared.

The Pointer Architecture preprint is, on the surface, about galactic rotation curves. It takes the SPARC dataset (171 galaxies, calibrated, public), fits three competing models against it (NFW baseline, free pointer, constrained pointer), and reports which model wins on AIC and where. The result is a partial win, with caveats, with a reproducibility pipeline you can run on your laptop, and with three falsifiers written into the manuscript that I have promised in advance would force me to retract the conclusion.

That last sentence is the bit that transfers. The falsifiers, written first, in public, before the result is available.

In client work the same move happens at a smaller scale and a higher tempo. A vendor security review for an LLM product begins, properly, with a list of events that would prove the privacy story is a lie. "If user-supplied PII ever appears in the embedding index for a different tenant, our claim is wrong." "If the audit log can be edited by anyone with write access to the production DB, our claim is wrong." "If a model fine-tuned on tenant A data can be requested by tenant B, our claim is wrong." Each one is a falsifier. Each one is a tripwire. Write them down before the build, and the build is forced to be honest. Write them down after, and they're decoration.

Most AI products I get called in to look at have not written them down. They have a privacy mood, not a privacy claim. The architecture diagram looks right. The vendor questionnaire says yes in the right boxes. There is a copy of someone else's DPIA in a Google Doc. What is missing is the sentence that ends with "if X ever happens, we are non-compliant." When X happens — and X always eventually happens, because X is the event the org has implicitly committed to not noticing — the team finds out at the same time as the regulator.

Regulatory Immunity, as I sell it, is basically the engineering version of the preprint discipline. We write down the falsifiers first, in the language the regulator will use, with the engineers in the room. We design the audit trail so that any of those events would be visible to a hostile auditor without anyone's cooperation. And we treat the system as a published claim: anyone can re-run the privacy story end-to-end and watch it either survive or crack. That standard is older than any compliance regime. It comes from the same place as the reproducibility pipeline in the preprint.

It runs the other way too. The client work is what keeps the preprint honest about what's tractable. A falsifier in a manuscript that nobody can actually action is decorative — it's a confession dressed up as rigor. A reproducibility pipeline whose data lineage is opaque does not survive a hostile audit. Adversarial replication is the standard for a published model and it is the standard for an audit log. The two crafts are calibrating to the same instrument and pretending they are not.

So when someone asks why a working AI engineer is publishing on galactic rotation, the short answer is: it is the same discipline working at maximum range. The preprint is the version where the adversary is the field. The audit trail is the version where the adversary is the regulator, and the version of yourself who will lie to you in eighteen months, when convenient. Both need the falsifier written down in ink before the work starts. Both improve from being held to that.

For the consulting side, you are already in the right room. The relevant doorway is Regulatory Immunity — AI privacy and compliance architecture as an engineering layer, not a slide deck. The research side, where the same discipline runs without a deadline or a budget, is at neuralcosmology.com: the Pointer Architecture preprint, the essays, and the three books — The Celestial Code (non-fiction), Bugs Academy (sci-fi novel), and Era of Architects (literary sequel in progress).

If you ever wondered whether the person writing the preprint and the person writing the regulatory-immunity contract are the same person, they are. They are also the same job. The brands are just two doors into one room.

Mike Fluff← Blog