Symphonix-Health
Symphonix-Health
Research · World Models

The Dormant Machine

Why your clinical AI is blind to the risks that haven’t surfaced yet - and how to see them before they fire.

Dr Josh Tedam MBA, CEO, Chief AI Architect and Founder of Symphonix-Health Dr Josh Tedam MBA
CEO | Chief AI Architect | Founder
Symphonix-Health · June 2026

Two very different traditions have been circling the same idea without quite meeting. One is Critical Realism, a philosophy of science that starts from ontology - it asks what exists? The other is LeJEPA, a recent line of work on self-supervised world models that starts from representation - it asks what must be represented to explain what we observe?

They are walking towards each other from opposite ends of the same tunnel. Critical Realism says reality is layered: beneath the events we record sit mechanisms - real, structured causal powers that generate those events. LeJEPA says a model trained the right way can recover latent variables - the hidden factors that generate the observations. Set the two vocabularies side by side and the rhymes are hard to miss.

Critical Realism and LeJEPA converging on hidden generative structure. On the left, the Critical Realism stack runs Empirical (observations) to Actual (events) to Real (mechanisms). On the right, the LeJEPA / World Models stack runs World model to Latent variables to Observations. Both converge on a shared insight: observed events arise from hidden generative structure.
Two traditions, opposite starting points, one destination: observed events arise from hidden generative structure.
Critical Realism LeJEPA / World Models In plain words
MechanismLatent variable / factorAn underlying cause the model never sees directly, but infers from its effects.
ContextState configurationThe surrounding conditions that decide whether a cause actually does anything.
OutcomeObservationWhat we actually record - the visible result.
Generative causationState-transition dynamicsThe rule that turns one moment into the next.
Demi-regularityStatistical regularityA pattern that mostly holds - a strong tendency, not an iron law.
TendencyPredictive dynamicsWhat a system is inclined to do, even when something blocks it.
Powers & liabilitiesState-dependent transition potentialWhat a thing is capable of doing, given the right conditions.
Open systemPartially observable environmentA real-world setting where you can never see or control everything.
Stratified realityHierarchical representationsReality in layers - surface events sitting on top of deeper structure.

The interesting part is not where the two line up. It is where they almost do - and the most valuable mismatch of all is a single Critical Realist idea that today’s world models mostly ignore: a mechanism can be entirely real while lying completely dormant.

◆

Where This Began - The Substrate Beneath the Software

I did not arrive at world models through machine learning. I arrived through a more stubborn question: why does the same intervention succeed in one hospital and fail in another that looks identical on paper? That question led me, almost by accident, to Critical Realism - and to a handful of thinkers who quietly reorganised how I see technology altogether.

Roy Bhaskar gave me the foundation. His insistence that reality is stratified - that beneath the events we observe lie real mechanisms with causal powers, whether or not they happen to be firing - is the single idea this entire blog rests on. Ray Pawson and Nick Tilley then took that ontology and made it operational for the messy social world: their Context-Mechanism-Outcome formula - what works, for whom, in what circumstances - is, if you squint, the exact shape of the dormant-capacity model in this post. A mechanism produces an outcome only when the context fires it. Justin Jagosh sharpened the method, showing how retroduction lets you reason backwards from an outcome to the hidden mechanisms that must have produced it. And Margaret Archer reminded me that structure and agency are not a tug-of-war but a process unfolding over time - her morphogenesis - the continual making and remaking of social structure over time - is a moving picture, not a snapshot.

The three layers of reality

Critical Realism splits reality into three depths, and the whole argument depends on telling them apart:

Empirical what we actually observe and measure: the data we manage to collect.
Actual the events that really happen, whether or not anyone observed them.
Real the deepest layer: the mechanisms and causal powers that generate those events, including the ones lying dormant and producing nothing visible right now.

Shallow to deep - the data you have, down to the mechanisms you do not see

A model trained only on data lives in the empirical. The ambition here is to reach down to the real.

What these authors share is a conviction I have come to hold tightly: technology never runs in a vacuum. It runs in society - an open system of mechanisms, tendencies, and powers, most of them dormant at any given moment. Build a clinical AI that models only the clinical signal and you have modelled the foam on the wave. The substrate is social. That is precisely why a healthcare world model has to reach for the real, and not merely the actual.

Technology does not run on silicon. It runs on society - an open system whose most important mechanisms are, at any given moment, asleep.
- Dr Josh Tedam MBA, CEO | Chief AI Architect | Founder, Symphonix-Health
◆

The Idea Machine Learning Keeps Missing

Critical Realism insists that a causal power exists even when it is not firing. A hospital can hold strong leadership that shows no measurable effect until a major transformation programme begins. The mechanism is present; the evidence is absent. A purely data-driven system, trained only on what manifested, would never see it. A Critical Realist would never miss it.

In machine-learning language this is conditional activation, or state-dependent dynamics. A self-driving car’s world model carries a “road condition” variable even on a dry day - its influence appears only when the rain starts. The variable was always there. The trigger was not. Carry that into a health system, and the stakes change. Dormant capacities in healthcare are everywhere:

So the research question that sits at this intersection is the one neither community has fully answered: can a world model learn latent variables that represent not only the current state of a healthcare system, but also its dormant causal capacities - the mechanisms that have not yet manifested but could be triggered under future conditions?

The short answer is yes - but only under specific conditions. LeJEPA is a strong starting point. It is not, on its own, sufficient.
- The central claim of this programme
◆

Why Symphonix-Health Is the Right Test Bed

Symphonix-Health† is already built more like a distributed model of a health system than a single application. GHARRA is a federated, zero-trust registry for healthcare AI agents, with a non-PHI control plane, an ABAC-style policy engine, event streaming, and trust routing. Nexus A2A is an inter-agent protocol with 25 clinical agents, a 13-point route-admission process, and more than 7,000 scenario-driven tests. The observability work maps, across 34 repositories, where metrics, traces, audit trails, and health probes already live - and where they do not.

Read those artefacts together and a pattern appears: the tools are the mechanisms. ambulance-ems is pre-hospital flow; appointment-system and scheduling-gateway are scheduling friction; lis and pacs-ris are diagnostic bottlenecks; eps and pharmacy-system are prescribing and medication safety; insurance-eclaims is adjudication; triage-api is escalation. Symphonix-Health now has a verified platform-spine world model. What remains is the full clinical operational world model: longitudinal patient state, care-pathway state machines, ontology-bound clinical semantics, care-team authority, temporal reasoning, outcome feedback, and live telemetry-backed validation.

4

The data families a world model needs - clinical workflow events, operational logs, agent/control-plane state, and policy/governance metadata - are all already present across the Symphonix-Health estate.

The Core Move: Separate Active State From Dormant Capacity

Here is the design idea in one sentence. Active state is what is presently expressed - arrivals, beds occupied, queue lengths, pending claims, stock levels. Dormant capacity is a property that exists before it manifests - surge fragility, denial propensity, burnout susceptibility, interoperability brittleness.

In Critical Realist terms, the model should represent both the actual (what is happening now) and the real (what can happen when the right conditions obtain). In machine-learning terms, that means carrying a slow-moving latent (a hidden internal variable the model learns, but never reads off directly) for each mechanism, plus a trigger gate - a switch that decides when that hidden variable is allowed to affect what happens next:

zt = [ xt , mt ]   # active state x and dormant capacity m
gt = σ( W·[ xt , ct , ut ] + b )   # the trigger gate
xt+1 = f( xt , ut , mt ⊙ gt , εt )   # capacity acts only when its gate opens

where, reading the symbols left to right:

The point is not merely to predict the next observation. It is to make the dormant variable mt identifiable enough that probing the latent tells you what kind of system you are currently inside - even when the harmful mechanism has not yet fired.

The Gaussian regulariser

LeJEPA nudges its latent cloud towards an isotropic Gaussian - a bell curve centred at zero with the same spread in every direction. Under its assumptions, that is the one shape for which the identifiability guarantee holds - the promise that the model can pin down the true hidden factors rather than some scrambled mix of them. It untangles the latent space and makes it easy to probe and plan in. It is superb at organising active state. It will not, on its own, reveal a dormant mechanism unless the training design makes that mechanism statistically legible in the first place.

The Gaussian regulariser in LeJEPA, in four panels. Panel 1, before regularisation: the latent space is tangled, uneven, and hard to interpret. Panel 2, the Gaussian regulariser: LeJEPA nudges the latent cloud towards an isotropic Gaussian, a bell curve centred at zero with the same spread in every direction. Panel 3, what this gives you: identifiability under the theory's assumptions, easier linear probing, and better planning in latent space, which is excellent for organising active state. Panel 4, what it does not do on its own: a dormant mechanism will not appear just because the cloud is Gaussian; the data and training design must make the mechanism statistically legible through triggering conditions, informative trajectories, and relevant context variation.
The Gaussian regulariser organises active state beautifully - but a dormant mechanism becomes learnable only when the data and training design make it legible.

A dormant mechanism will not appear just because the latent cloud is Gaussian, and that single sentence in panel four is the whole lesson for clinical AI: the Gaussian regulariser in LeJEPA (Lean Joint Embedding Predictive Architecture) tidies the model’s internal representation of whatever it is currently encoding, so the active state of a system becomes identifiable, easy to probe linearly and well suited to planning - yet it cannot conjure causal mechanisms that the training data never actually exercised.

For healthcare, the implication is a warning against a seductive false signal. A clinical model whose latent space looks clean, balanced and statistically well-behaved may still be entirely blind to a rare disease pathway, an uncommon adverse drug response, a comorbidity interaction or a subgroup effect - simply because those mechanisms stayed dormant in the data. Organisational neatness is not causal completeness, and it is certainly not safety.

To make such a dormant mechanism learnable you must design the data and the training to make it legible, which in practice means deliberately capturing its triggering conditions, its longitudinal patient trajectories and relevant context variation across diverse populations and care settings - rather than trusting a regulariser to surface it for free. For artificial intelligence more broadly, the takeaway is that representation-quality metrics are necessary but never sufficient evidence of capability: a model must be evaluated by actively exercising the capacities you care about, because whatever you never trigger, you never truly learn - and what you have not learned, you cannot trust.

The architecture follows from this: one encoder for recent event context, one predictor for masked future embeddings, a shared latent bottleneck regularised towards that Gaussian, and two heads - one for active-state probing, one for dormant-capacity and trigger prediction. The decisive evaluation is not forecasting accuracy. It is this: after a trigger fires, does the model behave as though it had already encoded the mechanism before manifestation? If yes, it has learned structure, not surface correlation.

◆

Four Honest Limitations

A proposal is only as trustworthy as its stated weaknesses. There are four, and they are serious.

Where this proposal is fragile

One - the theory describes a tidier world than healthcare is. LeJEPA’s strongest formal guarantee assumes stationary, additive-noise dynamics and a Gaussian latent. Real health systems are regime-switching, policy-sensitive, non-stationary, and only partially observed.

Two - some of the evidence is still provisional. Parts of the system map this work relies on are inferred rather than independently confirmed. Any claim that rests on them should be treated as a hypothesis until it has been verified directly.

Three - synthetic success is not causal truth. Recovering a planted mechanism in a simulator proves the method can do so under designed conditions. It does not prove the mechanism is real in a live service.

Four - even synthetic realism carries ethical risk. Overfitting synthetic generators to restricted datasets can leak structure. Worse, a healthcare digital twin can be turned to punitive workforce surveillance, opaque triage rationing, or denial optimisation if governance is weak.

◆

...And Four Answers

The encouraging part is that each limitation has a concrete, literature-backed response - and several are enforced by machinery Symphonix-Health already owns.

01

Answer to One - make closure local, not global

Idealised assumptions vs non-stationary healthcare

LeJEPA’s identifiability proof assumes one tidy, stationary, Gaussian world - healthcare is none of those. The sequential-identifiability literature points to a fix: enrich the state to [x_t, m_t, r_t, q_t], adding a latent regime (which policy and staffing world we are in) and an observation-quality latent (missing, delayed, coded elsewhere, or truly absent), with a regime-aware trigger gate. Demote the Gaussian to a regime-conditional bottleneck - tractable inside each regime while the system may switch, drift, and hide information.

Regime + observation latents History-aware Multi-environment
Train across many environments - hospitals, service lines, policy periods, payer mixes - on purpose: a mechanism that is never varied stays invisible until it manifests. A guarantee that holds inside each regime beats one that pretends healthcare is a closed system.
02

Answer to Two - turn the inventory into a verified evidence ledger

Medium-confidence portfolio scan

Treat that inferred inventory as a hypothesis set, not ground truth, and promote each claim from ‘plausible’ to ‘attested’. The evidence ladder: a confidence class on every inferred capability; repository-level SBOMs; build provenance via SLSA and in-toto; OpenTelemetry traces to confirm what actually runs; and OpenLineage for data lineage - folded into the NIST secure-development framework. Symphonix-Health’s seeded_alignment_trace.py is the natural home for the ledger.

SBOM + SLSA provenance OpenTelemetry + OpenLineage Claim-gated
Claim-gate the model: a capability may feed the world model only when an SBOM, a provenance attestation, telemetry, and a lineage record all agree it is real - so interoperability brittleness stops being abstract once retry storms and schema drift show up in the trace.
03

Answer to Three - climb a validation ladder, do not leap

Synthetic success is not causal truth

Separate three things the proposal blurs: recoverability, validity, and causality. Reposition the simulator as a falsification harness, then climb a risk-based ladder from medical-AI practice: VVUQ (verification, validation, uncertainty quantification) → silent shadow-mode deployment → recurring local validation rather than one-off external validation → target trial emulation where you want to claim a latent is causal.

Falsification harness Shadow-mode Recurring local validation
The decisive test, in shadow mode: when a trigger finally fires, did the pre-trigger latent already carry actionable warning across time, sites and regimes? Yes means structural learning; only-after-the-surface-signals means advanced correlation. Report under DECIDE-AI and TRIPOD+AI, aligned to GMLP.
04

Answer to Four - make governance an architectural feature

Ethical risk & misuse

The guidance converges - WHO, the NIST AI Risk Management Framework, NHS DCB0129/DCB0160 clinical safety, ICO, and the EU AI Act - so encode it as enforceable rules. Hard-code four boundaries: no autonomous rationing of care; no hidden worker surveillance (workforce latents stay team- and service-level - the EU AI Act bars workplace emotion recognition and treats worker-management AI as high-risk); no privacy claim without attack testing (synthetic data is not automatically outside data-protection law - require a differential-privacy budget plus membership-inference testing); and no governance without artifacts (hazard log, clinical safety case, model card, monitoring plan).

Four hard boundaries ABAC-enforced DP budget + attack testing
At Symphonix-Health these are live controls: GHARRA’s ABAC policy and Nexus route-admission bar a denial-propensity latent from feeding a denial optimiser, every dormant-capacity inference is wrapped in the TransparencyEnvelope, and evaluation reports pre-trigger detection parity across care setting, staff group, and deprivation proxies.
◆

The Test That Matters

If this works, the payoff is not a better forecast. The hierarchical, trigger-aware variant should recover active state about as well as strong sequence baselines - and then beat them at pre-trigger mechanism identification and at planning under regime change. In plain terms: it should be better at knowing what kind of system it is in, not just where the next point on the curve will land.

That is the empirical bridge between a JEPA-style world model and a Critical Realist view of mechanisms. Current world models focus on what is active. Critical Realism reminds us that reality contains causal powers that have not yet manifested - and that a system which can only see the firing mechanisms is blind to the ones quietly waiting for their trigger.

The strongest clinical world model, like the strongest clinical agent, is not the one that reacts fastest to what has happened. It is the one that already understands what could.
- Dr Josh Tedam MBA, CEO | Chief AI Architect | Founder, Symphonix-Health
◆

† About Symphonix-Health. Symphonix-Health is a healthcare-AI infrastructure company building agent-first clinical systems: GHARRA, a federated, zero-trust registry for healthcare AI agents; the Nexus A2A inter-agent communication protocol (25 clinical agents, a 13-point route-admission process, and 7,000+ scenario-driven tests); BulletTrain; and a portfolio-wide observability layer. This blog treats that estate as the empirical domain for a healthcare world model. ↩
symphonix-health.com · github.com/Symphonix-Health

References: Klindt, D., LeCun, Y., & Balestriero, R. (2026). When does LeJEPA learn a world model? arXiv. · Assran, M., et al. (2023). Self-supervised learning from images with a Joint-Embedding Predictive Architecture. CVPR. · LeCun, Y. (2022). A path towards autonomous machine intelligence. OpenReview. · Bhaskar, R. (1975). A Realist Theory of Science. · Archer, M. S. (1995). Realist Social Theory: The Morphogenetic Approach. Cambridge University Press. · Pawson, R., & Tilley, N. (1997). Realistic Evaluation. London: Sage. · Jagosh, J. (2020). Retroductive theorizing in Pawson and Tilley’s applied scientific realism. Journal of Critical Realism, 19(2), 121–130. · Johnson, A., et al. (2024). MIMIC-IV v3.1. PhysioNet. · The MITRE Corporation (2025). Synthea synthetic patient population simulator. · Symphonix-Health (2025–2026). Global agent registry, Nexus A2A protocol, and observability gap analysis & implementation plan. GitHub.