Demonstrated recovery capability turns the framework’s general preference for reversibility into an absolute gate for the most dangerous systems. Ordinary safety testing asks whether a system behaves as intended; this asks the harder question of whether, if it does not, control can actually be regained — and it demands the answer be shown operationally rather than assumed. Can the system be disconnected, denied compute and credentials, isolated from networks, rolled back, or replaced, under realistic conditions?
The rule it yields is blunt: critical capability should not advance beyond demonstrated recovery capability. Where a viable road back cannot be shown, capability should not keep increasing — because a system that cannot be reliably stopped, isolated, or replaced has crossed into a category where every other safeguard is contingent on a control the ecology no longer holds. It is disaster-recovery discipline applied where the disaster may be unrecoverable, and it is the physical precondition of the right to stop in loss of control.