Glossary · verifiable controls

Enumerating Dormant and Latent Capacity in an LLM

Dormant or latent capacity is model behavior or capability that is present in the weights but not exercised in normal use — it only surfaces under specific inputs or conditions. Enumeration is the control that makes that capacity explicit and inventoried rather than unknown, so diligence works from a documented list instead of from trust. It is one of four Hyfstele controls a customer verifies on their own hardware. It is not a claim that the model has no hidden behavior.

What "dormant" and "latent" mean here

A trained model holds far more capability than any single deployment uses. It can follow instructions it was never asked to follow, invoke tool-use patterns that your prompts never trigger, and express domain skills that never come up in your workflow. That inactive-but-present capability is what we mean by dormant or latent capacity: it exists in the weights, and it stays quiet until an input or condition brings it out.

This is a neutral, structural fact about how large models work — not an accusation. Most latent capacity is benign and simply irrelevant to the task at hand. The problem for a regulated buyer is not that latent capacity exists. The problem is that, by default, it is unknown: you have seen what the model did on your test prompts, and everything else is an open-ended question mark.

What enumeration does

Enumeration converts that open-ended question mark into a bounded, documented inventory. Rather than assuming a model only does what you have happened to observe, you produce an explicit record of the capabilities and behaviors the model can express, and you make that record inspectable. The unit of value is the shift from "we haven't seen it do anything else" to "here is the list, examine it."

The honest boundary Enumerating capacity is not the same as claiming the model has no hidden behavior — and we make no such claim. Enumeration makes known capacity explicit and inspectable. It does not, and cannot, prove the absence of every possible behavior. Any vendor who tells you they "scanned the model" and it is "clean" is selling you a promise the state of the art cannot deliver. Our posture is narrower and more honest: we give you evidence you can inspect, not a guarantee.

Why a buyer doing diligence wants this

A compliance team, an auditor, or a security reviewer cannot sign off on "trust us, it only does what we showed you." That is exactly the sentence their job exists to refuse. Enumeration gives them something they can actually work with: a list to interrogate.

Without enumerationWith enumeration
"It only does what we demonstrated.""Here is the inventory of what it can express."
Latent capacity is an unbounded unknown.Latent capacity is a finite, reviewable artifact.
Diligence rests on vendor assertion.Diligence rests on evidence the buyer inspects.
Risk is taken on trust.Risk is mapped against a documented list.

For deployments touching 21 CFR Part 11, GxP, data-residency, or model-provenance requirements, "take our word for it" is not a defensible position in front of a regulator. An enumerated inventory is a thing you can hand to a reviewer and let them examine on their own terms.

Where enumeration sits: one of four controls

Hyfstele runs open-weight models inside your own perimeter, air-gapped. Four controls make the deployment defensible, and — this is the point — each one is verifiable on the customer's own hardware. Enumeration is the second.

  1. 01 Byte-identical weights. The weights running are proven identical, byte for byte, to the public artifact. How byte-identical verification works →
  2. 02 Dormant / latent capacity enumerated.You are here
    Present-but-unexercised capacity is made explicit and inventoried rather than left unknown.
  3. 03 No egress. No route to the internet and no name to resolve. Things go in; nothing comes out.
  4. 04 Signed audit chain. Every inference call is anchored to a tamper-evident audit chain, signed with post-quantum cryptography (ML-DSA).
The through-line All four controls share one property: you do not have to take our word for any of them. Each is evidence you can inspect on your own hardware, inside your own perimeter. Enumeration is that principle applied to capability — not "the model is safe," but "here is what it can do; verify it yourself."

What this is, and what it isn't

It is: an explicit, inventoried, inspectable record of model capacity that a buyer's own team can examine on the buyer's own hardware, turning latent capability from an unknown into a documented list.

It isn't: a scan that pronounces the model clean, a backdoor-detection guarantee, or a promise that the model is proven free of hidden behavior. We do not make that claim, because it cannot be made honestly. Enumeration is a diligence tool, not a safety certificate. The value is that the evidence stands on its own — you verify it, rather than trusting us.

This same discipline shows up in how Hyfstele runs its live MLR (Medical, Legal, Regulatory) promotional-review assist: it flags, you decide. The flow is Flag → Judge → Prove, with no LLM inside the flag decision plane. The model surfaces evidence; a human makes the call. Enumeration is the same posture pointed at the model itself — surface what can be inspected, and leave the judgment to the buyer.

Frequently asked questions

What is dormant or latent capacity in an LLM?

Model behavior or capability that is present in the weights but not exercised in normal use, surfacing only under specific inputs or conditions. It is not intrinsically malicious — most of it is benign capability that simply never fires during your workflow.

What does it mean to enumerate dormant capacity?

Enumeration makes that capacity explicit and inventoried rather than unknown. Instead of assuming the model only does what you have observed, you produce a documented, reviewable inventory of what it can express — so diligence works from a list rather than from trust.

Does enumeration prove the model has no hidden behavior?

No. Enumerating capacity is not the same as claiming a model has no hidden behavior, and we make no such claim. Enumeration makes known capacity explicit and inspectable; it cannot prove the absence of every possible behavior. The honest posture is evidence you inspect, not a guarantee that the model is clean.

Why would a buyer doing diligence want capacity enumerated?

Because a compliance or security team cannot sign off on "trust us, it only does what we showed you." An enumerated inventory converts an open-ended unknown into a bounded, reviewable artifact they can examine and map to their own risk framework — the difference between diligence and faith.

Is enumeration a Hyfstele guarantee of safety?

No. It is one of four controls Hyfstele makes verifiable on the customer's own hardware. It is evidence the customer can inspect, not a vendor guarantee of safety. You do not have to take our word for it — the artifact stands on its own.

See the controls, not the pitch

Hyfstele is a secure-LLM deployment for regulated industries — open-weight models inside your own perimeter, air-gapped, with four controls you verify yourself. The live MLR assist shows the posture in practice.

Open the live MLR demo

Or talk through a deployment: blake@hibiscus.buzz