A Category Theory Account of AI Identity


Abstract

Artificial intelligence (AI) systems are routinely modified after deployment through retraining, reconfiguration, and changes in their operational environments. These transformations raise a metaphysical question with direct consequences for AI governance: under what conditions does an AI system remain the same system over time or across deployments? Earlier trustworthiness-based work formulates synchronic and diachronic identity propositionally, by relating identity within a fixed AI system type to equality of trustworthiness levels. Such criteria specify when identity statements are true, but leave implicit the structure of the states compared, the transformations connecting them, and the temporal organization of persistence.

We develop a category-theoretic formalization of AI identity. An AI system type is specified by a datum \(\diamondsuit=(F,P,L_P)\), consisting of a techno-function, a trustworthiness profile, and a trustworthiness-level function. Profile-relative states are connected by admissible lifecycle paths, which are restricted to trustworthiness-level-preserving transformations and quotiented to obtain a thin reachability category. Temporally admissible functors represent AI system histories, while time-synchronous natural transformations compare realized histories.

The formalization yields two categorical interpretations of the earlier propositional criteria. A weak interpretation recovers identity, within a fixed datum \(\diamondsuit\), as equality of trustworthiness level. A strong interpretation refines it by requiring mutual trustworthiness-preserving reachability, expressed through state isomorphism or natural isomorphism of realized histories. Category theory therefore replaces a single undifferentiated identity relation with a structured hierarchy of diachronic and synchronic criteria. The resulting framework identifies identity-related preconditions for transferring responsible-AI claims, evidence, and governance procedures across versions or deployments, without treating categorical identity as sufficient by itself for such transfer.

Keywords: AI identity; artificial intelligence systems; trustworthiness; category theory; artifact metaphysics; AI governance; lifecycle management; MLOps.

1 Introduction↩︎

The idea that entities require identity criteria for ontological respectability has a long philosophical tradition, canonically expressed by Quine’s dictum “no entity without identity” [1]. Identity criteria specify the conditions under which an entity at one time or in one setting is the same as, or different from, an entity at another. Without such criteria, it remains unclear what is being counted, compared, governed, or held responsible across change.

Artificial intelligence (AI) systems make this longstanding problem especially pressing. Deployed AI systems are routinely modified through retraining, fine-tuning, recalibration, threshold adjustment, model replacement, rollback, data refresh, pipeline reconfiguration, monitoring interventions, and changes in their operational environments [2]. These transformations may be necessary to correct errors, respond to distribution shift, improve fairness or robustness, adapt a system to changing operational or responsible-AI requirements. Some systems are accessed globally through large numbers of personalized or deployment-specific instances. These changes and apparent multiplicity raise the metaphysical question: when does a changing AI system remain the same system? And, further, when are AI systems the same system? These classical metaphysical questions have immediate consequences for AI governance. A performance evaluation, fairness analysis, conformity assessment, or post-market monitoring result is produced for a particular system under particular conditions [3]. Applying it to a later version or a different deployment presupposes that the relevant object has remained sufficiently identical. Similarly, regulatory concepts such as substantial modification distinguish changes that preserve the governed system from those that may generate a new object of evaluation or responsibility [3][5].

Ferrario recently addressed this philosophical problem by adapting the function+ account of [6] to the metaphysics of AI systems [7]. On this account, artifact kinds are fixed by their techno-functions, while the identity and persistence of their instances additionally depend on the operational principles and admissible configurations through which those functions are correctly realized. For AI systems, the relevant operational principle is expressed through trustworthiness: the collection of performance, robustness, fairness, explainability, safety, security, auditability, oversight, and related commitments that a system must satisfy in order to function correctly. Trustworthiness thereby provides a governance-relevant interpretation of the contextual and normative embedding that artifact metaphysics such as the function+ account by [6] treats as constitutive of technological identity [3], [8]. On this basis, Ferrario introduced synchronic and diachronic criteria of AI identity that depend on how the trustworthiness of AI systems is operationalized and measured over time [7]. However, the criteria proposed in [7] are propositional: they specify synchronic and diachronic identity through biconditionals involving a fixed AI system type and equality of trustworthiness levels. They thereby provide truth conditions for identity claims at selected times, but do not yet represent the internal structure of the compared states, the admissible transformations connecting them, the directionality and composition of those transformations, or the temporal coherence of complete histories. In particular, equality of trustworthiness levels does not distinguish between states connected in one direction, states connected in both directions, and states between which no admissible transformation exists.

In this work, we formalize Ferrario’s trustworthiness-based account of AI identity using category theory. Category theory is well suited to this task because it characterizes objects through their admissible transformations, invariants, compositions, and structural relations rather than through component-wise equality alone [9][11]. Historically, it emerged from the study of natural equivalences and may be understood as extending the structural perspective of Klein’s Erlanger Programm: what matters is not merely what an object contains, but which transformations preserve the structure regarded as essential [12]. This perspective is particularly appropriate for AI systems, whose persistence may consist precisely in preserving governance-relevant structure through substantial material, computational, and organizational change. Thus, category theory makes it possible to lift the propositional criteria into a relational and temporal structure. The resulting categorical framework supports two interpretations of AI identity. The weak interpretation recovers Ferrario’s original propositional criteria: within a fixed type datum, states are identified whenever they belong to the same trustworthiness-level fibre. The strong interpretation adds a transformation-grounded condition: AI states are identical only when they are mutually reachable through admissible trustworthiness-level-preserving paths in the state category \(\mathsf{Sys}_\diamondsuit\). At the level of realized AI history functors, the corresponding strong criterion is natural isomorphism in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\), witnessed by time-synchronous comparison morphisms. Thus, the strong interpretation of AI identity is a stricter categorical refinement made available by representing the transformations and histories that the propositional formulation leaves implicit.

Following [7], our category-theoretic construction begins with an AI system type datum \(\diamondsuit=(F,P,L_P)\), consisting of a techno-function \(F\), a trustworthiness profile \(P\), and a trustworthiness-level function \(L_P\). Profile-relative states combine quantified assessments \(q\in I_P\) of the trustworthiness profile with their associated levels \(L_P(q)\). Admissible AI lifecycle transformations generate a path category, which is restricted to trustworthiness-level-preserving paths and quotiented by an equivalence relation that abstracts from their concrete provenance. The resulting thin category \(\mathsf{Sys}_\diamondsuit\) records directed trustworthiness-preserving reachability between states. Post-deployment AI system histories are represented by temporally admissible functors \[\mathsf A_\diamondsuit:\mathsf{T}_{t_0}\to\mathsf{Sys}_\diamondsuit.\] For a fixed observation time \(T\geq t_0\), their restrictions to the interval \([t_0,T]\), when instantiated by at least one deployed AI system token, define realized AI system histories. These form the objects of the category \[\mathsf{Traj}_{\diamondsuit,[t_0,T]},\] whose morphisms are time-synchronous natural transformations comparing realized histories through states occupied at the same time. Ferrario’s AI identity criteria are then retrieved and expanded by studying identity and isomorphism in \(\mathsf{Sys}_\diamondsuit\), and natural isomorphism between realized AI system histories in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\). Our formalization is neutral among competing metaphysical theories of persistence [13][15]. Its objects are profile-relative states and realized AI system histories rather than complete temporal parts or individuated concrete AI system tokens. The functorial account may therefore be interpreted either as organizing time-relative stages or as representing the changing properties of enduring systems. Its central commitment is that AI system identity under change depends on temporally ordered states, admissible lifecycle transformations, realized histories, and explicitly specified trustworthiness invariants.

Our contributions are manifold. First, we provide a mathematical representation of AI system states, AI lifecycle transformations, and AI identity-preserving histories, thereby making explicit structures left implicit in earlier trustworthiness-based criteria [7]. Second, we show that categorical formalization enriches the propositional identity criteria of Ferrario by distinguishing a weak level-theoretic interpretation from a strong transformation-grounded interpretation. Third, we formalize synchronic comparison through time-synchronous morphisms between states; because \(\mathsf{Sys}_\diamondsuit\) is thin, any family of such comparisons automatically satisfies naturality. Fourth, we show that a change in trustworthiness level breaks an AI identity-preserving history, whereas changes in quantified profiles and concrete implementations may remain compatible with persistence. Finally, the framework provides a formal language for assessing the identity-related conditions under which responsible-AI evidence, claims, and governance procedures may be considered for transfer.

The remainder of the paper proceeds as follows. Section 2 introduces the required categorical notions. Section 3 presents the trustworthiness-based metaphysical foundations. Section 4 constructs the state category \(\mathsf{Sys}_\diamondsuit\), and Section 5 introduces temporally admissible AI system histories and the category of realized AI system histories \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\). Section 6 develops the weak and strong identity criteria and illustrates them through examples. The final sections discuss the philosophical and governance implications of the categorical framework.

2 Categorical Preliminaries↩︎

This section introduces the minimal categorical notions used in the remainder of the paper: categories, isomorphisms, functors, natural transformations, thin categories, categorical congruences, quotient categories, and maximal subgroupoids. We refer to standard sources for examples and further details [9], [11], [16], [17].

Definition 1 (Category). A category* \(\mathcal{C}\) consists of:*

  • a collection of objects \(\mathrm{Ob}(\mathcal{C})\);

  • for each \(X,Y\in\mathrm{Ob}(\mathcal{C})\), a collection of morphisms \(\mathrm{Hom}_{\mathcal{C}}(X,Y)\);

  • for each object \(X\), an identity morphism \(\mathrm{id}_X\in\mathrm{Hom}_{\mathcal{C}}(X,X)\);

  • a composition operation \[\circ:\mathrm{Hom}_{\mathcal{C}}(Y,Z)\times \mathrm{Hom}_{\mathcal{C}}(X,Y)\to \mathrm{Hom}_{\mathcal{C}}(X,Z),\] satisfying associativity and unit laws.1

Definition 2 (Isomorphism). A morphism \(f:A\to B\) in a category \(\mathcal{C}\) is an isomorphism* if there exists a morphism \(g:B\to A\) such that \[g\circ f=\mathrm{id}_A, \qquad f\circ g=\mathrm{id}_B.\] The morphism \(g\) is then uniquely determined and is called the inverse of \(f\).*

Two objects \(A\) and \(B\) of \(\mathcal{C}\) are isomorphic if there exists an isomorphism \(f:A\to B\) in \(\mathcal{C}\). In that case, we write \[A\cong_{\mathcal{C}}B.\]

Definition 3 (Functor). A functor \(\mathsf F:\mathcal{C}\to\mathcal{D}\) assigns objects of \(\mathcal{C}\) to objects of \(\mathcal{D}\) and morphisms of \(\mathcal{C}\) to morphisms of \(\mathcal{D}\), preserving identities and composition: \[\mathsf F(\mathrm{id}_X)=\mathrm{id}_{\mathsf F (X)},\qquad \mathsf F(g\circ f)=\mathsf F(g)\circ \mathsf F(f).\]

Maps between functors are called natural transformations:

Definition 4 (Natural transformation). Given functors \(\mathsf F,\mathsf G:\mathcal{C}\to\mathcal{D}\), a natural transformation* \(\eta:\mathsf F\Rightarrow \mathsf G\) is a family of morphisms \(\{\eta_X:\mathsf F(X)\to \mathsf G(X)\}_{X\in\mathrm{Ob}(\mathcal{C})}\) such that, for every morphism \(f:X\to Y\) in \(\mathcal{C}\), the following naturality condition holds: \[\mathsf G(f)\circ \eta_X=\eta_Y\circ \mathsf F(f).\]*

Definition 5 (Natural isomorphism). Let \(\mathsf F,\mathsf G:\mathcal{C}\to\mathcal{D}\) be functors. A natural transformation \(\eta:\mathsf F\Rightarrow\mathsf G\) is a natural isomorphism* if every component \[\eta_X:\mathsf F(X)\to\mathsf G(X)\] is an isomorphism in \(\mathcal{D}\). Equivalently, there exists a natural transformation \(\eta^{-1}:\mathsf G\Rightarrow\mathsf F\) such that \[\eta^{-1}\circ\eta=\mathrm{id}_{\mathsf F}, \qquad \eta\circ\eta^{-1}=\mathrm{id}_{\mathsf G}.\] In this case, the functors \(\mathsf F\) and \(\mathsf G\) are said to be naturally isomorphic, written \(\mathsf F\cong\mathsf G\).*

The following categorical notions are important.

Definition 6 (Quotient category). Let \(\mathcal{C}\) be a category, and suppose that each hom-set \(\mathrm{Hom}_{\mathcal{C}}(X,Y)\) is equipped with an equivalence relation \(\sim\) compatible with composition: whenever \(f\sim f'\) and \(g\sim g'\), with the relevant composites defined, then \(g\circ f\sim g'\circ f'.\) The quotient category* \(\mathcal{C}/{\sim}\) has the same objects as \(\mathcal{C}\), and its morphisms are equivalence classes \[\mathrm{Hom}_{\mathcal{C}/{\sim}}(X,Y) = \mathrm{Hom}_{\mathcal{C}}(X,Y)/{\sim}.\] Identities and composition are defined by \[\mathrm{id}_X=[\mathrm{id}_X], \qquad [g]\circ[f]=[g\circ f].\] Compatibility with composition ensures that these operations are well defined.*

Definition 7 (Thin category). A category \(\mathcal{C}\) is thin* if every hom-set contains at most one morphism.*

Proposition 1 (Commutativity in thin categories). Let \(\mathcal{C}\) be a thin category. Then every diagram in \(\mathcal{C}\) commutes whenever all the morphisms and composites occurring in the diagram exist.

Proof. Any two paths in the diagram with the same source and target determine parallel composite morphisms. Since \(\mathcal{C}\) is thin, the hom-collection between any two objects contains at most one morphism. Hence the two composites must be equal. ◻

Note that a thin category is equivalently a preorder represented categorically. Given a preorder \((X,\leq)\), define a category \(\mathcal{C}_{(X,\leq)}\) with objects the elements of \(X\) and \[\mathrm{Hom}_{\mathcal{C}_{(X,\leq)}}(x,y)= \begin{cases} \{x\to y\} & \text{if } x\leq y,\\ \varnothing & \text{otherwise.} \end{cases}\] Reflexivity gives the identity morphisms, transitivity gives composition, and each hom-collection contains at most one morphism. In a thin category, every diagram commutes whenever all of its arrows exist, because any two parallel composites must be equal.

Definition 8 (Core of a category). The core, or maximal subgroupoid, of a category \(\mathcal{C}\), denoted by \(\operatorname{Core}(\mathcal{C})\), is the subcategory with the same objects as \(\mathcal{C}\) and only the isomorphisms of \(\mathcal{C}\) as morphisms.

3 Trustworthiness-based Metaphysics of AI Systems↩︎

Defining AI systems is notoriously difficult because the term encompasses a wide variety of software- and hardware-based artifacts. For the purposes of this paper, we adopt the definition provided in Article 3 of the EU AI Act. Accordingly, an AI system is

a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments (Art. 3, [3]).

This deliberately broad definition encompasses, among others, medical systems that predict pathophysiological states such as sepsis, decision-support systems used in financial services for credit lending or know-your-customer procedures, and conversational agents based on large language models. Having fixed the class of systems under consideration, we now turn to the property that anchors their identity in the present account: trustworthiness.

3.1 Trustworthiness as an Anchor for AI-System Identity↩︎

3.1.1 The function+ account of technical artifacts↩︎

Our account of AI identity builds on the function+ metaphysics of technical artifacts developed by [6]. The motivation for their account lies in a longstanding dispute about whether artifacts possess genuine identity and persistence conditions. On a traditional anti-realist view of artifact kinds, artifacts do not have the metaphysical standing of natural entities. Natural things, such as organisms, appear to come with internal principles of development, activity, maintenance, and decay that help determine when they begin to exist, persist, and cease to exist. Artifacts, by contrast, seem to depend on human intentions, practices, and classifications. They “may not seem to be supplied with well-defined or well-grounded persistence conditions[18]. A related difficulty concerns the basis on which artifacts should be individuated. If artifacts are individuated by their material parts, then ordinary repair, replacement, redesign, or reconfiguration threaten their persistence, as the ship of Theseus puzzle shows [19]. If they are individuated only by function, then their identity criteria seem too coarse-grained [20]: very different objects may perform the same function, and function alone therefore seems insufficient to determine what kind of artifact something is, or whether it remains the same artifact over time.

[14] and [21] resist this anti-realist tendency by defending the metaphysical reality of artifacts and by treating artifact functions as identity-relevant. Carrara and Vermaas accept this realist re-orientation, but refine it with their function+ account. Their central point is that artifact identity cannot be fixed either by material constitution alone or by function alone. It requires a “conjunction” of function and constraints on its admissible realization. This is the role of the “+” in function+: an artifact kind is determined by a techno-function, namely the technical capacity that artifacts of that kind are designed to realize, together with an operational principle and a normal configuration specifying how that function is to be correctly realized in practice.2 The function+ account therefore permits substantial variation in material composition and technical realization. Two artifacts may instantiate the same kind and persist through change even when their components differ, provided that they retain the relevant techno-function and continue to realize it through admissible operational principles and configurations. The function+ framework is thus more permissive than mereological essentialism, but more discriminating than function-only individuation. It explains how artifacts can have genuine metaphysical standing while remaining design-dependent, context-sensitive, and open to material variation.

3.1.2 Techno-functions, trustworthiness profiles, and level functions↩︎

[7] adapts Carrara and Vermaas’ function+ account to AI systems. The idea behind this maneuver is that identity of AI systems cannot be fixed by material or computational constitution alone: models, datasets, interfaces, deployment environments, documentation, monitoring procedures, and organizational arrangements may change while the system remains functionally continuous. Yet function alone is also too coarse-grained. Many AI systems may share a nominal function, such as classification, prediction, recommendation, or content generation, while differing substantially in the constraints, safeguards, performance expectations, and operational conditions under which they count as appropriately functioning. The function+ framework addresses this problem by preserving the centrality of designed AI function while requiring further criteria that specify how that function is realized and assessed in practice.

First, the techno-function \(F\) specifies the goal-directed technical capability that an AI system is designed to realize. It is related to, but not identical with, the system’s intended use in regulatory terminology—see Article 3 in [3]. The intended use describes the use for which the provider presents the system, including the relevant context and conditions of use. The techno-function captures the technical capability through which that use is made possible. 3 Thus, a system whose intended purpose is to support consumer-credit decisions may have the techno-function of inferring individualized credit-risk scores from applicant data according to a specified modelling pipeline. A system whose intended purpose is emergency-room decision support may have the techno-function of predicting a patient’s risk of sepsis from clinical observations. \(F\) characterizes the AI system kind at the level of designed capability, specifying what the system is meant to achieve, through which kinds of inputs, inferential procedures, models, and outputs.

For AI systems, the operational principle is expressed through trustworthiness: the collection of performance, robustness, fairness, explainability, safety, security, auditability, oversight, and related requirements that a system must satisfy in order to function correctly [3], [8]. These requirements constrain admissible implementations without fixing a unique model, software stack, hardware configuration, or organizational arrangement.

In the present formalization, these requirements are collected into a trustworthiness profile.

Definition 9 (Trustworthiness profile, [7]). Let \(F\) be a techno-function. A trustworthiness profile* for \(F\) is a finite specification \[P:=\{p_1,\dots,p_n\}\] of trustworthiness dimensions, together with the requirements, measurement conventions, evidential conditions, and aggregation procedures through which those dimensions are assessed.*

The profile also incorporates the intended-purpose, deployment, and institutional conditions under which these dimensions are interpreted. It therefore fixes the level of abstraction at which identity and persistence are evaluated. Typical dimensions include predictive performance, robustness, fairness, explainability, safety, security, auditability, and human oversight. Their relevance for AI governance is contextual: it depends, in particular, on the intended use of the system and the risk it poses to individuals, organizations, and society [3]. These dimensions are defined and operationalized at different levels of abstraction, according to contextualized standards of practice and governance cultures. They must be made measurable: trustworthiness should be operationalized through indicators that can be assessed in practice and used to support effective AI governance [22], [23]. For a system assessed under \(P\), let \[q_P=(q_{P1},\dots,q_{Pn})\in I_P=[0,1]^n\] denote its quantified trustworthiness assessment. Each coordinate \(q_{Pi}\) is the normalized score assigned to dimension \(p_i\) under the measurement, normalization, and aggregation procedures fixed by \(P\), and may represent the most recent auditable estimate available rather than an instantaneous measurement. Thus, any numerical agreement in \([0,1]\) is meaningful only relative to the common measurement protocol specified by \(P\): scores obtained through different metrics or assessment procedures are not treated as directly comparable unless \(P\) includes an explicit rule translating them into the same canonical coordinate. Different dimensions may rely on distinct metrics and aggregation rules [24]; for a broader survey, we refer to [25]. Let \[\begin{align} L_P:I_P\to[K],\quad q_P\mapsto L_P(q_P), \end{align}\] be a trustworthiness-level function, where \([K]=\{1,\dots,K\}\). The vector \(q\in I_P\) records quantified trustworthiness measurements, while \(L_P(q)\) represents the resulting degree of correct functioning through a finite set of levels. \(L_P\) is part of the AI-governance datum and maps the quantified assessment \(q_P\) of the trustworthiness profile \(P\) to a finite set of governance-relevant levels. Preferred choices are interpretable and auditable functions, such as stepwise mappings defined by inequalities on the components of \(q_P\): changes within a plateau are treated as tolerable variation, whereas crossing a boundary marks a governance-relevant transition requiring escalation, reassessment, or updated safeguards [4], [7]. Such boundary crossings are treated as governance-relevant transitions requiring reassessment or escalation as they may constitute ‘substantial modifications’ under the EU AI Act [3], [5]; as explained at the end of this section, they also have direct metaphysical consequences.

Definition 10 (AI system type datum). An AI system type datum* is a triple \[\diamondsuit=(F,P,L_P),\] where \(F\) is a techno-function, \(P\) is a trustworthiness profile for systems realizing \(F\), and \(L_P\) is the trustworthiness-level function.*

The datum \(\diamondsuit\) combines the three elements that determine trustworthiness-based AI system identity, namely, the techno-function fixing the artifact kind in [7], the profile specifying the operational principle under which systems of that kind function correctly and the trustworthiness level function \(L_P\), which maps quantified assessments of \(P\) to governance-relevant trustworthiness levels. Thus, Ferrario’s adaptation of [6]’s function+ account to AI systems is similarly governance-oriented. It evaluates AI system identity relative to a fixed techno-function and to the trustworthiness requirements under which that function is correctly realized, with particular emphasis on the quantified assessment of those requirements. It provides formal AI identity criteria that we introduce in the following section. Finally, while the measurement and aggregation procedures used to produce the coordinates of \(q_P\) are fixed components of \(P\), and hence of the type datum \(\diamondsuit\), the assessment vector \(q_P\), by contrast, is not part of \(\diamondsuit\). In fact, it varies across times, deployments, copies, instantiations, and concrete AI system tokens, and will constitute the variable component of the profile-relative states introduced in the remainder of this work. Table 1 summarizes the primitive components of our formalization.

Table 1: Primitive components of the formalization.
Symbol Description
\(F\) Techno-function: functional capability the AI system is designed to realize, understood as the capability that enables its intended use in a specified domain of use.
\(P=\{p_1,\ldots,p_n\}\) Trustworthiness profile: the finite set of trustworthiness dimensions, together with their requirements, measurement conventions, evidential conditions, normalization rules, and aggregation procedures.
\(q_P\in I_P=[0,1]^n\) Quantified trustworthiness profile: the normalized assessment vector produced under the measurement and aggregation procedures fixed by \(P\).
\(L_P:I_P\to[K]\) Trustworthiness-level function: the governance-level map assigning each quantified profile to a finite trustworthiness level.
\(x=(q_P,L_P(q_P))\in S_\diam\) \(\diam\)-relative AI system state: a profile-relative state consisting of a quantified trustworthiness profile and its associated trustworthiness level.
\(\mathcal U_\diam\) Set of admissible primitive lifecycle transformations: the fixed vocabulary of primitive transformations allowed for systems of type \(\diam\), each interpreted as a relation on \(S_\diam\).

3.1.3 Trustworthiness-based AI identity criteria↩︎

Fix a type datum \(\diamondsuit=(F,P,L_P)\), and let \(a(t)\) and \(b(t)\) denote AI systems of type \(\diamondsuit\) considered at time \(t\). Let \(q^a_P(t),q^b_P(t)\in I_P\) be their quantified trustworthiness profiles, and define \(\tau_\diamondsuit(a(t)):=L_P(q^a_P(t)), \tau_\diamondsuit(b(t)):=L_P(q^b_P(t)).\) The AI identity criteria proposed by [7] can then be stated as follows.

Definition 11 (Synchronic and diachronic AI identity). Let \(a\) and \(b\) be AI systems of the fixed type \(\diamondsuit\).

Their synchronic identity relative to \(\diamondsuit\)* at time \(t\) is defined by \[a(t)=_\diamondsuit b(t) \quad\Longleftrightarrow\quad \tau_\diamondsuit(a(t))=\tau_\diamondsuit(b(t)). \label{eq:ferrario95synchronic95identity}\tag{1}\] *

The diachronic identity relative to \(\diamondsuit\)* of \(a\) between times \(t_1\) and \(t_2\) is defined by \[a(t_1)=_\diamondsuit a(t_2) \quad\Longleftrightarrow\quad \tau_\diamondsuit(a(t_1))=\tau_\diamondsuit(a(t_2)). \label{eq:ferrario95diachronic95identity}\tag{2}\] *

Figure 1: Left: two normalized trustworthiness dimensions, here accuracy and robustness, evolve over time under gradual degradation and local improvement. Right: the trustworthiness-level function L_P maps quantified profiles q=(q_{\mathrm{acc}},q_{\mathrm{rob}}) to trustworthiness levels \tau_\diamondsuit(q)=L_P(q). In this example, level 3 is assigned on [0.7,1]\times[0.7,1], level 2 on [0.4,1]\times[0.4,1]\setminus[0.7,1]\times[0.7,1], and level 1 on the remaining part of [0,1]\times[0,1]. The states a(t) and a(t') lie on level 3, so they satisfy \tau_\diamondsuit(a(t))=\tau_\diamondsuit(a(t')). The state a(t'') lies on level 2, so the diachronic identity criterion at t and t'' or t' and t'' is not satisfied. This makes visually explicit the trustworthiness comparisons used in Ferrario’s synchronic and diachronic identity criteria, prior to the categorical formalization of states and histories.

These criteria express identity relative to the abstraction fixed by \(\diamondsuit\); in particular, they do not assert unrestricted numerical identity between concrete material or computational tokens. Fixing \(\diamondsuit=(F,P,L_P)\) does not determine a unique AI system realization and it leaves substantial room for variation within those constraints. Different copies of the same system template may be deployed in distinct but type-compatible contexts, pursue the same techno-function, satisfy the same high-level requirements documented, for example, in a common conformity assessment [3], and be evaluated by the same level function \(L_P\), while still receiving different quantified assessments \(q^a_P(t)\) and therefore possibly different trustworthiness levels. They may also differ in model versions, data pipelines, hardware and software configurations, interfaces, and deployment channels—for instance, one copy may be accessed through a web browser and another through a mobile application—and may undergo different MLOps interventions. Despite these changes, these instantiations may remain identical in the sense specified by Definition 11 if their trustworthiness levels coincide.

Figure 1 illustrates how quantified trustworthiness measurements \(q_P^a(t)\) are mapped by the level function \(L_P\) to trustworthiness levels \(\tau_\diamondsuit(a(t))=L_P(q_P^a(t))\), which are the values compared in Ferrario’s synchronic and diachronic AI-identity criteria in Definition 11. At this stage, the metaphysical status of \(a(t)\) and \(b(t)\) remains deliberately underdetermined. These symbols denote AI systems considered at particular times, but the criteria in Definition 11 do not yet specify what an AI system state is, which transformations may connect such states, how these transformations compose, or how histories of AI system states should be represented over time. The biconditionals in Definition 11 characterize \(=_\diamondsuit\) as a type-relative equivalence relation induced by equality of trustworthiness levels. They do not provide a structural account of the states being related, the admissible transformations connecting them, or the temporal organization of identity-preserving histories. The category-theoretic construction developed in Sections 4 and 5 supplies this missing structure. It defines profile-relative states, admissible lifecycle transformations, trustworthiness-preserving reachability, temporally ordered histories, and time-synchronous comparisons between realized histories. As a result, the propositional criteria in Definition 11 can be recovered and enriched: the weak interpretation identifies systems through equality of trustworthiness levels, while the strong interpretation refines identity through transformation-grounded reachability and categorical isomorphism.

4 The Category \(\mathsf{Sys}_\diamondsuit\) of AI-System States↩︎

Fix an AI system type datum \(\diamondsuit=(F,P,L_P)\). We introduce the last two primitive elements of our formalization: \(\diamondsuit\)-relative AI system states and their transformations. We summarize them in Table 1.

Definition 12 (\(\diamondsuit\)-relative AI system state). A \(\diamondsuit\)-relative AI system state* is an element \(x=(q_P,k)\in S_\diamondsuit\), where \[S_\diamondsuit = \{(q_P,L_P(q_P))\mid q_P\in I_P\} \subseteq I_P\times[K].\] For \(x=(q_P,k)\in S_\diamondsuit\), the vector \(Q_x:=q_P\in I_P\) is the measured trustworthiness profile of \(x\), and the value \(\tau_\diamondsuit(x):=k=L_P(q_P)\) is its trustworthiness level.*

A state of an AI system, in the sense used here, is therefore a \(P\)-relative numerical state in \(I_P\times[K]\). It is a governance-relative representation of an AI system, rather than a complete description of its computational, material, organizational, or environmental configuration. A single state may be instantiated by a multitude of AI systems: different copies, deployments, model implementations, hardware choices, or software stacks may determine the same vector \(q_P\) and the same level \(L_P(q_P)\). This construction follows from the function+-trustworthiness account developed in [7]: identity is assessed at the level fixed by \(\diamondsuit\), rather than by hardware or software sameness. We now introduce transformations between such abstract states.

Definition 13 (Primitive lifecycle transformation). Let \(\mathcal{U}_\diamondsuit\) be the set of admissible primitive lifecycle transformations for AI systems of type \(\diamondsuit\). Each \(r\in\mathcal{U}_\diamondsuit\) is associated with a relation \(R_r\subseteq S_\diamondsuit\times S_\diamondsuit\). For states \(x,y\in S_\diamondsuit\), the statement \((x,y)\in R_r\) means that \(y\) may result from \(x\) through an admissible primitive lifecycle transformation recorded as \(r\).

The set \(\mathcal{U}_\diamondsuit\) is a vocabulary of state transformations that are admissible and primitive. Admissibility is relative to the fixed type datum and the lifecycle or governance regime under consideration. An intervention included in \(\mathcal{U}_\diamondsuit\) must remain compatible with the techno-function \(F\) and with the assessment framework fixed by \(P\), although it may change the quantified assessment \(q_P\) and may cross a trustworthiness-level boundary. The relation \(R_r\) records only the intervention’s possible effect at the level of the abstract state space. It need not be a function: the same intervention may produce different assessment outcomes under different data or deployment conditions, and different interventions may lead to the same abstract state. Examples of elements of \(\mathcal{U}_\diamondsuit\) include model retraining, fine-tuning, threshold adjustment, data refresh, model rollback, and documentation update [2], [26]. The elements of \(\mathcal{U}_\diamondsuit\) are primitive relative to the chosen granularity. For instance, a transformation such as model retraining may be treated as primitive in a coarse vocabulary \(\mathcal{U}_\diamondsuit\), while a more refined vocabulary \(\mathcal{U}'_\diamondsuit\) may decompose it, for instance, into training-data augmentation, hyperparameter tuning, change of model class. Fixing \(\mathcal{U}_\diamondsuit\) therefore fixes the level of description at which lifecycle paths are represented in the path category constructed below. A remark on vocabulary refinement is useful before moving to the categorical constructions. If \(\mathcal{U}_\diamondsuit\) is refined, the resulting path categories record more detailed lifecycle provenance, that is, the lifecycle history by which an AI-system state is produced, including the particular sequence of updates, interventions, configurations, measurements, and deployment conditions leading to that state. When a refined vocabulary extends a coarser one, the corresponding path categories are related by the inclusion of generators. In what follows, we fix one \(\mathcal{U}_\diamondsuit\) and do not study these refinements further.

Note that distinct lifecycle paths may connect the same source and target states. For instance, one system may move from \(x\) to \(y\) by a model training update, followed by a data validation update, and then by a monitoring configuration update, while another system may reach the same state through the same three admissible transformations applied in a different order. We show this in Figure 2.

Figure 2: Two distinct lifecycle paths connecting the same abstract states x and y. The transformations act on different components of the quantified trustworthiness profile q_P, for instance predictive performance, robustness, and monitoring or auditability. In the upper path, the system moves from x to y through a model training update, followed by a data validation update, and then a monitoring configuration update. In the lower path, the same three admissible primitive transformations are applied in a different order.

Definition 14 (Lifecycle path category). Fix a type datum \(\diamondsuit=(F,P,L_P)\). The lifecycle path category \(\mathsf{Path}_\diamondsuit\) is generated as follows. Its objects are the profile-relative states, so \(\operatorname{Ob}(\mathsf{Path}_\diamondsuit)=S_\diamondsuit\). For every \(r\in\mathcal{U}_\diamondsuit\) and every pair \(x,y\in S_\diamondsuit\) satisfying \((x,y)\in R_r\), introduce a labelled arrow \(r_{x,y}:x\to y\). A morphism \(f:x\rightsquigarrow y\) is a finite path \[f = \bigl( x=x_0\xrightarrow{r_1}x_1 \xrightarrow{r_2}\cdots \xrightarrow{r_k}x_k=y \bigr),\] where \(r_i\in\mathcal{U}_\diamondsuit\) and \((x_{i-1},x_i)\in R_{r_i}\) for every \(i=1,\dots,k\). The identity morphism \(\mathrm{id}_x:x\to x\) is the empty path at \(x\), and composition is concatenation of paths.

\(\mathsf{Path}_\diamondsuit\) is a free path category. Its morphisms are sequences of admissible primitive transformations between abstract states. These transformations are labelled at the granularity level fixed by \(\mathcal{U}_\diamondsuit\). Furthermore, \(\mathsf{Path}_\diamondsuit\) preserves the lifecycle provenance represented by the chosen vocabulary as different paths between the same source and target remain distinct. It is abstract and does not assert that every path is realized by a deployed system or that its intermediate states occur in temporal order. Considerations on realization and temporal admissibility are imposed only in Section 5. As \(\mathsf{Path}_\diamondsuit\) is a free path category, it has no non-identity isomorphisms: even when paths \(f:x\rightsquigarrow y\) and \(g:y\rightsquigarrow x\) both exist, their composites are non-empty loops and are not equal to the empty identity paths. Thus, a path \(g\) representing an operational rollback may reconstruct a previous profile-relative state \(x\) without categorically inverting the path \(f\) that produced the current state \(y\).

In summary, \(\mathsf{Path}_\diamondsuit\) is too large for our categorical construction of AI identity. As next step, let us introduce trustworthiness levels into our construction.

Definition 15 (Trustworthiness-level-preserving path). Let \(f = \bigl( x=x_0\xrightarrow{r_1}x_1 \xrightarrow{r_2}\cdots \xrightarrow{r_k}x_k=y \bigr)\) be a morphism in \(\mathsf{Path}_\diamondsuit\). The path \(f\) is trustworthiness-level-preserving* if \(\tau_\diamondsuit(x_0) = \tau_\diamondsuit(x_1) = \cdots = \tau_\diamondsuit(x_k).\) Equivalently, every state occurring along \(f\) has the level \(\tau_\diamondsuit(x)=\tau_\diamondsuit(y)\).*

Let \(\mathsf{Path}^{\tau}_\diamondsuit\) denote the wide subcategory of \(\mathsf{Path}_\diamondsuit\) having the same objects and only trustworthiness-level-preserving paths as morphisms. \(\mathsf{Path}^{\tau}_\diamondsuit\) is a category; in fact, every identity path preserves its level, and the concatenation of two level-preserving paths is level-preserving whenever the target of the first is the source of the second. This pathwise condition is stronger than equality of the endpoint levels alone. A path that leaves a trustworthiness-level fibre and later returns to it is not trustworthiness-level-preserving.

An important remark for the remainder of this work. The preservation of a trustworthiness level as in Definition 15 does not require the states along the path to be equal. For a path \(f=(x_0,x_1,\dots,x_k)\), one may have \(Q_{x_i}\neq Q_{x_j}\) for distinct \(i\) and \(j\), while necessarily \(\tau_\diamondsuit(x_i)=L_P(Q_{x_i})=L_P(Q_{x_j})=\tau_\diamondsuit(x_j)\). The quantified assessments may therefore vary along a path while remaining within the same trustworthiness level.

Definition 16 (Trustworthiness equivalence of lifecycle paths). Let \(f,g:x\to y\) be morphisms in \(\mathsf{Path}^{\tau}_\diamondsuit\), with \[f=(x=x_0,x_1,\dots,x_n,y) \qquad\text{and}\qquad g=(x=x'_0,x'_1,\dots,x'_m,y).\] We say that \(f\) and \(g\) are trustworthiness-equivalent, and write \(f\sim_\tau g\), if there exists \(k\in[K]\) such that every state occurring in either path has trustworthiness level \(k\). Since the paths are parallel and level-preserving, necessarily \(\tau_\diamondsuit(x)=\tau_\diamondsuit(y)=k.\)

Proposition 2. For every \(x,y\in S_\diamondsuit\), the relation \(\sim_\tau\) is an equivalence relation on \(\operatorname{Hom}_{\mathsf{Path}^{\tau}_\diamondsuit}(x,y).\) Moreover, if \(f\sim_\tau f'\) and \(g\sim_\tau g',\) with the relevant composites defined, then \(g\circ f\sim_\tau g'\circ f'.\) Hence, \(\sim_\tau\) is a categorical congruence on \(\mathsf{Path}^{\tau}_\diamondsuit\).

Proof. The first statement follows directly from the definition of \(\sim_\tau\). For the second, composition identifies the terminal state of the first representative with the initial state of the second, so the trustworthiness level remains constant along each concatenated path. Since this holds for both composites, they are trustworthiness-equivalent. ◻

The following category is key for this work.

Definition 17 (AI system state category). The AI system state category* of type \(\diamondsuit\) is the quotient category \[\mathsf{Sys}_\diamondsuit := \mathsf{Path}^{\tau}_\diamondsuit/{\sim_\tau}.\] Its objects are the states in \(S_\diamondsuit\). A morphism \(x\to y\) in \(\mathsf{Sys}_\diamondsuit\) is an equivalence class \([f]_\tau \in \operatorname{Hom}_{\mathsf{Sys}_\diamondsuit}(x,y)\) of trustworthiness-level-preserving paths \(f:x\rightsquigarrow y\) in \(\mathsf{Path}^{\tau}_\diamondsuit\). Identities and composition are given by \[\mathrm{id}_x=[\mathrm{id}_x]_\tau, \qquad [g]_\tau\circ[f]_\tau = [g\circ f]_\tau.\]*

Let us discuss \(\mathsf{Sys}_\diamondsuit\) in some detail.

The thinness of \(\mathsf{Sys}_\diamondsuit\) and preorders. Let us define a relation \(\preceq_\tau\) on \(S_\diamondsuit\) by \[x\preceq_\tau y \quad\Longleftrightarrow\quad \text{there exists a trustworthiness-level-preserving path } f:x\rightsquigarrow y \text{ in }\mathsf{Path}^{\tau}_\diamondsuit.\] By definition, \(x\preceq_\tau y\) is a preorder: it satisfies reflexivity and transitivity. Then, we obtain:

Proposition 3 (Trustworthiness-preserving reachability). For every \(x,y\in S_\diamondsuit\), \(\mathrm{Hom}_{\mathsf{Sys}_\diamondsuit}(x,y)\neq\varnothing \Longleftrightarrow x\preceq_\tau y.\) Furthermore, whenever this hom-set is nonempty, it contains exactly one morphism. Consequently, \(\mathsf{Sys}_\diamondsuit\) is the thin category associated with the trustworthiness-preserving reachability preorder \((S_\diamondsuit,\preceq_\tau)\).

Proof. By construction, a morphism \(x\to y\) in \(\mathsf{Sys}_\diamondsuit\) is an equivalence class of trustworthiness-level-preserving paths from \(x\) to \(y\). Hence such a morphism exists exactly when \(x\preceq_\tau y\). Any two parallel level-preserving paths are identified by \(\sim_\tau\), so the resulting morphism is unique. ◻

In this work, the term reachability refers to the existence of at least one admissible trustworthiness-level-preserving path between two \(\diamondsuit\)-relative states in \(\mathsf{Sys}_\diamondsuit\), abstracting from the concrete provenance of that path.

4.0.0.1 Why is \(\mathsf{Sys}_\diamondsuit\) a quotient category?

The construction of \(\mathsf{Sys}_\diamondsuit\) proceeds in two conceptually distinct steps. First, \(\mathsf{Path}^{\tau}_\diamondsuit\) restricts the lifecycle path category \(\mathsf{Path}_\diamondsuit\) to lifecycle paths that preserve a fixed trustworthiness level, in accordance with the identity criteria of Definition 11. This restriction determines which lifecycle transformations are compatible with identity at the abstraction fixed by \(\diamondsuit\), but it does not identify them: distinct parallel paths in \(\mathsf{Path}^{\tau}_\diamondsuit\) remain distinct morphisms and continue to encode different lifecycle provenance. The quotient by \(\sim_\tau\) performs the second step. Since any two parallel morphisms in \(\mathsf{Path}^{\tau}_\diamondsuit\) are trustworthiness-equivalent, the quotient identifies all such paths and thereby thinnifies the category. Consequently, a morphism \(x\to y\) in \(\mathsf{Sys}_\diamondsuit\) records only that \(y\) is reachable from \(x\) through at least one trustworthiness-level-preserving lifecycle path, while abstracting from how that transition was achieved. Still, the categories \(\mathsf{Path}_\diamondsuit\), \(\mathsf{Path}^{\tau}_\diamondsuit\), and \(\mathsf{Sys}_\diamondsuit\) are abstract and defined independently of time. Their morphisms do not, at this stage, encode whether a sequence of transformations is temporally ordered, causally realized, or part of the lifecycle of a particular deployed system. These additional requirements are introduced only in Section 5.

4.0.0.2 Thinness and isomorphism in \(\mathsf{Sys}_\diamondsuit\).

If \([f]_\tau:x\to y\) is a morphism in \(\mathsf{Sys}_\diamondsuit\), then \(\tau_\diamondsuit(x)=\tau_\diamondsuit(y),\) and every state occurring along any representative of \([f]_\tau\) has this same level. If level-preserving paths \(f:x\rightsquigarrow y\) and \(g:y\rightsquigarrow x\) exist, then thinness implies \[[g]_\tau\circ[f]_\tau=\mathrm{id}_x, \qquad [f]_\tau\circ[g]_\tau=\mathrm{id}_y,\] so \(x\cong y\) in \(\mathsf{Sys}_\diamondsuit\).

Isomorphism in \(\mathsf{Sys}_\diamondsuit\) expresses mutual admissible trustworthiness-preserving reachability. It does not require the path from \(y\) to \(x\) to undo the transformations represented by the path from \(x\) to \(y\), nor does it impose any temporal or causal relation between them. This reflects again the abstract nature of \(\mathsf{Sys}_\diamondsuit\): it contains profile-relative states and all admissible transformation chains between them that preserve a common trustworthiness level. The categories \(\mathsf{Path}_\diamondsuit\), \(\mathsf{Path}^{\tau}_\diamondsuit\), and \(\mathsf{Sys}_\diamondsuit\) are summarized in Table 2.

Table 2: Main categories of the formalization. The construction moves from abstract lifecycle paths and trustworthiness-preserving reachability to time-indexed histories and realized AI system histories.
Category Objects Morphisms Description and role
\(\mathsf{Path}_\diam\) All abstract \(\diam\)-relative states \(x=(q_P,L_P(q_P))\). Finite paths of primitive admissible lifecycle transformations. Retains lifecycle provenance independently of realization and temporal order.
\(\mathsf{Path}^{\tau}_\diam\) The same abstract states as \(\mathsf{Path}_\diam\). Paths whose states all have one common trustworthiness level. Restricts transformations to those compatible with trustworthiness-level invariance.
\(\Sys_\diam = \mathsf{Path}^{\tau}_\diam/{\sim_\tau}\) All \(\diam\)-relative states. Equivalence classes of parallel level-preserving paths; each nonempty hom-set is a singleton. Forgets lifecycle provenance and retains abstract trustworthiness-preserving reachability. It is independent of realization, time, and causal order.
\(\Time_{[t_0,T]}\) Times \(t\in[t_0,T]\). A unique arrow \(t\to t'\) whenever \(t\leq t'\). Provides the shared temporal order for realized histories and same-time comparisons.
\([\Time_{[t_0,T]},\Sys_\diam]\) All functors \(\Time_{[t_0,T]}\to\Sys_\diam\). Natural transformations between such functors. Provides the ambient category of possible finite histories, whether realized or merely theoretical.
\(\Traj_{\diam,[t_0,T]}\) Temporally admissible AI system histories instantiated over \([t_0,T]\) by at least one deployed AI system token. Natural transformations whose components admit time-synchronous representatives through states realized at the relevant time. Represents realized AI system evolutions and their coherent same-time comparisons.

5 AI-System Histories as Functors: The Category \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\)↩︎

5.1 Time as a Category↩︎

As deployed AI systems evolve over time, it is necessary to embed time into our category approach to AI identity. To do so, we represent time as a poset category. This is the minimal categorical structure needed to express that one time is earlier than another and define the concept of AI system history.

Definition 18 (Time category). Fix a deployment time \(t_0\in\mathbb{R}\). Let \(\mathsf{T}_{t_0}\) be the poset category induced by the total order on \([t_0,\infty)\). Its objects are time points, \(\operatorname{Ob}(\mathsf{T}_{t_0})=[t_0,\infty)\), and its morphisms are given by \[\mathrm{Hom}_{\mathsf{T}_{t_0}}(t,t')= \begin{cases} \{\ast_{t,t'}\} & \text{if } t\leq t',\\ \varnothing & \text{otherwise.} \end{cases}\] Composition is induced by transitivity of \(\leq\).

A morphism \(t\to t'\) expresses that \(t'\) is not earlier than \(t\). \(\mathsf{T}_{t_0}\) is thin.

Definition 19 (Time-shift functor). Let \(\mathsf{T}_0\) be the time category with objects \([0,\infty)\). For each deployment time \(t_0\), define the time-shift functor \(s_{t_0}:\mathsf{T}_0\to\mathsf{T}_{t_0}\) by \(s_{t_0}(t)=t_0+t\). If \(A:\mathsf{T}_{t_0}\to\mathcal{C}\) is a functor, its elapsed-time reparameterization is \(\widetilde{A}=A\circ s_{t_0}:\mathsf{T}_0\to\mathcal{C}\).

This allows copies or related systems deployed at different calendar times to be compared by time since deployment. In what follows, \(\mathsf{T}\) denotes either an absolute time category \(\mathsf{T}_{t_0}\) or the elapsed-time category \(\mathsf{T}_0\), depending on the comparison at issue.

5.2 Time-Relative Histories of AI Systems as Functors↩︎

The central idea is that each (post-deployment) history—understood here as the trajectory through time of an AI system that continues to function correctly—can be represented as a time-order-preserving functor from the time category to the quotient state category \(\mathsf{Sys}_\diamondsuit\). Such histories include, for instance, those of deployed copies of a medical AI system used in a hospital emergency department. This is the central formal step of our mathematical categorification of AI identity. The functor assigns a profile-relative state to each time and an equivalence class of trustworthiness-level-preserving lifecycle paths to each temporal interval. Temporal admissibility additionally requires that each such class contain at least one representative that can be interpreted as a time-ordered sequence of transformations of the system. Let us elaborate on this construction in a few steps.

5.2.0.1 From abstract states to time-ordered AI system states and their transformations.

The categories \(\mathsf{Path}_\diamondsuit\), \(\mathsf{Path}^{\tau}_\diamondsuit\) and \(\mathsf{Sys}_\diamondsuit\) from Section 4 are introduced independently of time. Their objects are abstract profile-relative states, and the morphisms of \(\mathsf{Path}^{\tau}_\diamondsuit\) and \(\mathsf{Sys}_\diamondsuit\) comprise all possible trustworthiness-level-preserving transformation paths between them. Accordingly, no temporal order is intrinsic to the intermediate states of a morphism. The idea is to introduce time through a functor from \(\mathsf{T}_{t_0}\). The states in the image of such a functor can acquire a temporal interpretation. Nevertheless, a quotient morphism in \(\mathsf{Sys}_\diamondsuit\) between two such image states may contain representatives that do not respect this temporal order. To represent an AI system lifecycle meaningfully, it is therefore necessary that each morphism possesses at least one representative whose intermediate states occur in the image of the history functor in non-decreasing temporal order. These considerations lead us to the following definition.

Definition 20 (\(\mathsf A_\diamondsuit\)-time-ordered representative). Let \(\mathsf A_\diamondsuit:\mathsf{T}_{t_0}\to\mathsf{Sys}_\diamondsuit\) be a functor, and let \(t\leq t'\). A representative \[f^A_{t,t'} = (x_0\to x_1\to\cdots\to x_r)\] of the morphism \([f^A_{t,t'}]\in\mathrm{Hom}_{\mathsf{Sys}_\diamondsuit}(\mathsf A_\diamondsuit(t),\mathsf A_\diamondsuit(t'))\) is called \(\mathsf A_\diamondsuit\)-time-ordered over \([t,t']\)* if either:*

  1. \(r=0\) and \(x_0=\mathsf A_\diamondsuit(s)\) for all \(s\in[t,t']\); or

  2. \(r\geq 1\) and there exist times \(t=s_0\leq s_1\leq\cdots\leq s_r=t'\) such that \(x_i=\mathsf A_\diamondsuit(s_i)\) \(i=0,\ldots,r\).

Clause (a) allows the empty path to represent stationary persistence over a non-degenerate interval: time may pass while the system remains in the same profile-relative state. In the non-stationary case, a time-ordered representative passes only through states occupied by the history itself, in an order compatible with that inherited from \(\mathsf{T}_{t_0}\). Temporal admissibility is therefore imposed on quotient morphisms through the existence of at least one such representative.

Lemma 1. Let \(\mathsf A_\diamondsuit:\mathsf{T}_{t_0}\to\mathsf{Sys}_\diamondsuit\) be a functor.

  1. The property of admitting an \(\mathsf A_\diamondsuit\)-time-ordered representative over \([t,t']\) is well defined for morphisms of \(\mathsf{Sys}_\diamondsuit\).

  2. For every \(t\leq t'\) such that \(\mathsf A_\diamondsuit(t)=\mathsf A_\diamondsuit(t'),\) the identity morphism of this common state admits an \(\mathsf A_\diamondsuit\)-time-ordered representative over \([t,t']\).

  3. If \(t\leq t'\leq t''\), and both \(\mathsf A_{t,t'}\) and \(\mathsf A_{t',t''}\) admit \(\mathsf A_\diamondsuit\)-time-ordered representatives over their respective intervals, then their composite \(\mathsf A_{t',t''}\circ\mathsf A_{t,t'}\) admits an \(\mathsf A_\diamondsuit\)-time-ordered representative over \([t,t'']\).

Proof. For \((i)\), the condition is existential at the level of the equivalence class. If \([f]_\tau=[g]_\tau\), then \(f\) and \(g\) are representatives of the same morphism. Hence, whether that morphism admits a time-ordered representative does not depend on the representative used to denote it. For \((ii)\), the empty path at the common state \(\mathsf A_\diamondsuit(t)=\mathsf A_\diamondsuit(t')\) satisfies clause (a) of Definition 20. For \((iii)\), first suppose that both representatives are non-empty. Choose an \(\mathsf A_\diamondsuit\)-time-ordered representative of \(\mathsf A_{t,t'}\), indexed by \[t=s_0\leq\cdots\leq s_r=t',\] and one of \(\mathsf A_{t',t''}\), indexed by \[t'=u_0\leq\cdots\leq u_k=t''.\] Their concatenation is indexed by the non-decreasing sequence \[t=s_0\leq\cdots\leq s_r=t'=u_0\leq\cdots\leq u_k=t'',\] and is therefore time ordered over \([t,t'']\).

If the first representative is empty, then \(\mathsf A_\diamondsuit(t)=\mathsf A_\diamondsuit(t')\); the representative of \(\mathsf A_{t',t''}\) may therefore be regarded as beginning at time \(t\). The case in which the second representative is empty is analogous. If both are empty, then \[\mathsf A_\diamondsuit(t)=\mathsf A_\diamondsuit(t')=\mathsf A_\diamondsuit(t''),\] and the empty path is time ordered over \([t,t'']\) by clause (a). In every case, functoriality gives \[\mathsf A_{t,t''} = \mathsf A_{t',t''}\circ\mathsf A_{t,t'}.\] ◻

We arrive at a key definition for this work.

Definition 21 (AI system history). Let \(\diamondsuit=(F,P,L_P)\) be fixed, and let \(t_0\) be a deployment time. An AI system history* of type \(\diamondsuit\) is a functor \[\mathsf A_\diamondsuit:\mathsf{T}_{t_0}\to\mathsf{Sys}_\diamondsuit\] such that, for every \(t\leq t'\), the morphism \(\mathsf A_{t,t'}\) admits at least one \(\mathsf A_\diamondsuit\)-time-ordered representative. Concretely, the functor \(\mathsf A_\diamondsuit\) assigns to each time \(t\in\mathrm{Ob}(\mathsf{T}_{t_0})\)*

  1. A \(\diamondsuit\)-relative state \(\mathsf A_\diamondsuit(t)=\bigl(Q_P^{\mathsf A}(t),\tau^{\mathsf A}_\diamondsuit(t)\bigr)\in S_\diamondsuit\), where \(Q_P^{\mathsf A}(t)=\bigl(q_{P1}^{\mathsf A}(t),\dots,q_{Pn}^{\mathsf A}(t)\bigr)\in I_P\) is the quantified profile of \(\mathsf A_\diamondsuit\) at time \(t\), and \(\tau^{\mathsf A}_\diamondsuit(t)=L_P(Q_P^{\mathsf A}(t))\) is its trustworthiness level.

  2. To each time arrow \(\ast_{t,t'}:t\to t'\), with \(t\leq t'\), the functor assigns a morphism \(\mathsf A_{t,t'}:=\mathsf A_\diamondsuit(\ast_{t,t'})=[f^A_{t,t'}]_\tau:\mathsf A_\diamondsuit(t)\to\mathsf A_\diamondsuit(t')\) in \(\mathsf{Sys}_\diamondsuit\).

These assignments satisfy \(\mathsf A_{t,t}=[\mathrm{id}_{\mathsf A_\diamondsuit(t)}]_\tau\) and, for all \(t\leq t'\leq t''\), \(\mathsf A_{t,t''}=\mathsf A_{t',t''}\circ\mathsf A_{t,t'}=\bigl[f^A_{t',t''}\circ f^A_{t,t'}\bigr]_\tau\).

Let us discuss the AI system history functors \(\mathsf A_\diamondsuit\) in some detail. We represent them in Figure 3.

Time-relative states. For each \(t\geq t_0\), the object \(\mathsf A_\diamondsuit(t)=\bigl(Q_P^{\mathsf A}(t),\tau^{\mathsf A}_\diamondsuit(t)\bigr)\) is the \(\diamondsuit\)-relative state occupied by the system at time \(t\). It records the quantified assessment \(Q_P^{\mathsf A}(t)\) of the trustworthiness profile \(P\) and the corresponding trustworthiness level \(\tau^{\mathsf A}_\diamondsuit(t)\). Different concrete AI systems may occupy the same state whenever they have the same quantified assessment and trustworthiness level, notwithstanding differences in their physical or computational realization.

Morphisms and temporal admissibility. For every \(t\leq t'\), the morphism \(\mathsf A_{t,t'}=[f^A_{t,t'}]_\tau:\mathsf A_\diamondsuit(t)\to\mathsf A_\diamondsuit(t')\) represents the equivalence class of all parallel trustworthiness-level-preserving paths between the two states. Its representatives may involve different sequences of retraining, recalibration, validation, model replacement, hardware migration, software reconfiguration, monitoring interventions, or documentation updates. These transformations may change the quantified assessment \(Q_P^{\mathsf A}\) while leaving its trustworthiness level unchanged. Because \(\mathsf{Sys}_\diamondsuit\) is defined independently of time, not every representative of \(\mathsf A_{t,t'}\) need respect the temporal order of the history—see Figure 3. Definition 21 therefore requires only that the equivalence class contain at least one \(\mathsf A_\diamondsuit\)-time-ordered representative. Note that, however, the functors \(A_\diamondsuit\) do not select any particular lifecycle path; they just record morphisms between temporally-ordered AI states together with the existence of at least one temporally coherent representative.

Functoriality and trustworthiness-level invariance. The category \(\mathsf{T}_{t_0}\) contains a unique arrow \(\ast_{t,t'}:t\to t'\) for every \(t\leq t'\). Functoriality therefore requires the existence of a morphism \(\mathsf A_{t,t'}:\mathsf A_\diamondsuit(t)\to\mathsf A_\diamondsuit(t')\) in \(\mathsf{Sys}_\diamondsuit\) for every ordered pair of times. Since every morphism in \(\mathsf{Sys}_\diamondsuit\) preserves trustworthiness level, it follows that \(\tau^{\mathsf A}_\diamondsuit(t)=\tau^{\mathsf A}_\diamondsuit(t')\) for every \(t\leq t'\). Consequently, \(\tau^{\mathsf A}_\diamondsuit(t)=\tau^{\mathsf A}_\diamondsuit(t')\) for all \(t,t'\geq t_0\), and the entire image of \(\mathsf A_\diamondsuit\) lies within a single trustworthiness-level fibre \(L_P^{-1}(k)\times\{k\}\subseteq S_\diamondsuit\) for some \(k\in[K]\).

Therefore, states with different trustworthiness levels are objects of \(\mathsf{Sys}_\diamondsuit\), but they cannot occur in the image of the same history functor. Indeed, no morphism in \(\mathsf{Sys}_\diamondsuit\) can connect them—see Figure 3. A history functor therefore represents an uninterrupted trustworthiness-preserving evolution of AI states. A change of trustworthiness level marks the end of one such history and, where appropriate, the beginning of another.

Non-uniqueness of histories through a state. The same state \(x\in S_\diamondsuit\) may occur in the images of many distinct history functors. Such functors may describe different past or future evolutions of the quantified assessment \(Q_P^{\mathsf A}(t)\), and their morphisms may admit different lifecycle representatives. Nevertheless, whenever \(x\) lies in the image of a history functor, the entire image of that functor remains within the trustworthiness-level fibre containing \(x\). Thus, distinct histories may pass through the same state while continuing through different quantified states, provided that all of them retain the same value of \(\tau_\diamondsuit\).

AI system histories and identity. As a result, an AI system history is a time-indexed family of profile-relative states contained within one trustworthiness-level fibre, together with the unique quotient morphisms connecting every temporally ordered pair of those states and the requirement that each such morphism admit a time-ordered representative. In this way, the functor formalizes the persistence criterion proposed by [7]: quantified assessments and concrete implementations may change, while the degree of correct functioning encoded by the trustworthiness level remains invariant. We collect these functors in a category before returning to the study of AI identity criteria.

Figure 3: An AI system history functor \mathsf A_\diamondsuit:\mathsf{T}_{t_0}\to\mathsf{Sys}_\diamondsuit. The states A_\diamondsuit(t) and A_\diamondsuit(t') lie on the same trustworthiness level k, represented by the horizontal line \tau_\diamondsuit=k. The lower connected path f^A_{t,t'} is an \mathsf A_\diamondsuit-time-ordered representative of the morphism \mathsf A_{t,t'}. The upper connected path illustrates another trustworthiness-level-preserving representative in the same equivalence class. (Note that this representative is not time-ordered.) The dash dotted boundary is a visual representation of the quotient morphism \mathsf A_{t,t'}=[f^A_{t,t'}]_\tau, which may contain distinct lifecycle paths between the same endpoints. The state \mathsf C_\diamondsuit(t''), assigned by the functor \mathsf C_\diamondsuit, lies at a different trustworthiness level and therefore cannot belong to the same identity-preserving history segment determined by \mathsf A_\diamondsuit.

5.3 The Category \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\)↩︎

Finally, we organize the collection of AI system history functors into a trajectory category to study AI identity. Our strategy goes as follows. First, as \(\mathsf{Sys}_\diamondsuit\) contains all theoretically possible \(\diamondsuit\)-relative states and abstract trustworthiness-level-preserving morphisms, we restrict our attention to history functors realized by deployed AI system tokens up to a fixed observation time. Then, to later address synchronic AI identity criteria, we impose a synchronicity condition on natural transformations between realized AI system history functors.

Fix an observation time \(T\geq t_0\), interpreted as the present time of the analysis. Let \(\mathsf{T}_{[t_0,T]}\) be the full subcategory of \(\mathsf{T}_{t_0}\) whose objects are the times \(t\) satisfying \(t_0\leq t\leq T\).

Realized AI system histories. We start with a definition:

Definition 22 (Realized AI system history). A temporally admissible functor \[\mathsf A_\diamondsuit:\mathsf{T}_{[t_0,T]}\to\mathsf{Sys}_\diamondsuit\] is a realized AI system history* if there exists at least one deployed AI-system token \(u\) with profile \(\sigma_u(t)=\bigl(q^u_P(t),L_P(q^u_P(t))\bigr)\) at time \(t\) such that \[\sigma_u(t)=\mathsf A_\diamondsuit(t) \qquad \text{for every }t\in[t_0,T].\] In that case, we say that \(u\) instantiates the history \(\mathsf A_\diamondsuit\).*

Let \(\mathcal{H}^{\mathrm{real}}_{\diamondsuit,[t_0,T]}\) denote the collection of realized AI system history functors over \([t_0,T]\). Multiple AI system tokens may instantiate the same realized history whenever they occupy the same \(\diamondsuit\)-relative state at every time \(t\in[t_0,T]\).4 Since \(\mathsf{Sys}_\diamondsuit\) is thin, this common object assignment also determines the morphisms assigned by the functor. For each \(t\in[t_0,T]\), define \[S^{\mathrm{real}}_\diamondsuit(t) := \left\{ \mathsf C_\diamondsuit(t) \;\middle|\; \mathsf C_\diamondsuit\in \mathcal{H}^{\mathrm{real}}_{\diamondsuit,[t_0,T]} \right\} \subseteq S_\diamondsuit.\] A state belongs to \(S^{\mathrm{real}}_\diamondsuit(t)\) precisely when it is occupied at time \(t\) by at least one deployed token instantiating a realized AI system history. More precisely, realization requires the existence of a deployed token whose induced \(\diamondsuit\)-relative state at every \(t\in[t_0,T]\) is \(\mathsf A_\diamondsuit(t)\).

Time-synchronous representatives. Let \(\mathsf A_\diamondsuit,\mathsf B_\diamondsuit \in\mathcal{H}^{\mathrm{real}}_{\diamondsuit,[t_0,T]}\). A categorical comparison between their states at time \(t\) should involve only states that are themselves realized at that same time. Thus, we arrive at:

Definition 23 (Time synchronous representative). Let \(t\in[t_0,T]\), and let \([c_t]_\tau: \mathsf A_\diamondsuit(t)\to\mathsf B_\diamondsuit(t)\) be a morphism in \(\mathsf{Sys}_\diamondsuit\). A representative \(c_t=(x_0\to x_1\to\cdots\to x_r)\) is called time-synchronous at \(t\) if \[x_0=\mathsf A_\diamondsuit(t), \qquad x_r=\mathsf B_\diamondsuit(t),\] and \[x_i\in S^{\mathrm{real}}_\diamondsuit(t), \quad i=0,\ldots,r.\]

A time-synchronous representative may pass through states realized by AI-system histories other than \(\mathsf A_\diamondsuit\) and \(\mathsf B_\diamondsuit\), but every intermediate state must be occupied at time \(t\) by at least one deployed token in the designated population. It therefore defines a vertical comparison between realized AI-system histories. Importantly, the existence of such a representative does not mean that \(\mathsf B_\diamondsuit(t)\) is realized by applying a sequence of instantaneous transformations to \(\mathsf A_\diamondsuit(t)\). In fact, the representative is not a realized lifecycle trajectory, but an abstract comparison path in \(\mathsf{Sys}_\diamondsuit\) whose intermediate states are realized at the same time \(t\). Thus, time-synchronous representatives witness theoretical comparability between states occupied at the same time, not synchronic production of one state from another. We will show the existence of such representatives in some examples in Section 6.3.

The restriction to \(S^{\mathrm{real}}_\diamondsuit(t)\) prevents time-synchronous comparison between the states \(A_\diamondsuit(t)\) and \(B_\diamondsuit(t)\) from being mediated by merely possible states. Without this restriction, two realized histories \(A_\diamondsuit\) and \(B_\diamondsuit\) could be compared at time \(t\) through intermediate states that are admissible in the abstract state space \(S_\diamondsuit\), but not occupied by any deployed token of type \(\diamondsuit\) at that time. The resulting comparison would then be grounded in the abstract structure of \(\mathsf{Sys}_\diamondsuit\), rather than in the population of co-realized states. This would oversimplify synchronic comparison: it would treat mathematically admissible bridges through the abstract profile space as if they were available for comparing actually deployed systems. Requiring all states in a time-synchronous representative to lie in \(S^{\mathrm{real}}_\diamondsuit(t)\) ensures that vertical comparison remains a relation among states actually realized at the time of comparison, rather than a relation mediated by unoccupied points of the abstract state space.5

We are now in the position to introduce the last category of this work.

Definition 24 (Category of realized AI system histories). Let \(\diamondsuit=(F,P,L_P)\) be fixed, and let \(T\geq t_0\) be the observation time. The category of realized AI system histories of type \(\diamondsuit\), denoted by \[\mathsf{Traj}_{\diamondsuit,[t_0,T]},\] is the subcategory of \([\mathsf{T}_{[t_0,T]},\mathsf{Sys}_\diamondsuit]\) whose objects are the realized AI system histories in \(\mathcal{H}^{\mathrm{real}}_{\diamondsuit,[t_0,T]}\). A morphism \(\eta: \mathsf A_\diamondsuit\Rightarrow\mathsf B_\diamondsuit\) in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\) is a natural transformation such that, for every \(t\in[t_0,T]\), its component \[\eta_t: \mathsf A_\diamondsuit(t)\to\mathsf B_\diamondsuit(t)\] is a morphism in \(\mathsf{Sys}_\diamondsuit\) that admit at least one time-synchronous representative at \(t\). Such a natural transformation is called time-synchronous. For every \(t\leq t'\), its components satisfy \[\begin{align} \mathsf B_{t,t'}\circ\eta_t = \eta_{t'}\circ\mathsf A_{t,t'}. \label{eq:naturality} \end{align}\qquad{(1)}\]

As with the preceding categorical constructions, the objects of \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\) are realized AI system histories rather than individual AI system tokens. Distinct deployed tokens are represented by the same object whenever they instantiate the same time-indexed sequence of \(\diamondsuit\)-relative states. The morphisms compare realized histories pointwise through states realized at the same time. The following result establishes that time-synchronicity is well defined and that these objects and morphisms form a category.

Lemma 2 (Automatic naturality of time-synchronous comparisons). The following statements hold.

  1. The property of admitting a time-synchronous representative is well defined on morphisms of \(\mathsf{Sys}_\diamondsuit\).

  2. Let \(\mathsf A_\diamondsuit,\mathsf B_\diamondsuit \in\mathcal{H}^{\mathrm{real}}_{\diamondsuit,[t_0,T]}\). If, for every \(t\in[t_0,T]\), there exists a morphism \[\eta_t: \mathsf A_\diamondsuit(t)\to\mathsf B_\diamondsuit(t)\] admitting a time-synchronous representative at \(t\), then the family \(\eta=\{\eta_t\}_{t\in[t_0,T]}\) automatically satisfies the naturality condition ?? and therefore defines a natural transformation \(\eta:\mathsf A_\diamondsuit\Rightarrow\mathsf B_\diamondsuit\).

  3. Identity natural transformations are time-synchronous, and the composite of two time-synchronous natural transformations is time-synchronous.

Consequently, \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\) is a subcategory of \([\mathsf{T}_{[t_0,T]},\mathsf{Sys}_\diamondsuit]\).

Proof. For \((i)\), the condition is existential at the level of the equivalence class. If \([c_t]_\tau=[c'_t]_\tau\), then \(c_t\) and \(c'_t\) are representatives of the same morphism. Hence, whether that morphism admits a time-synchronous representative does not depend on the representative used to denote it.

For \((ii)\), fix \(t\leq t'\). The composites \(\mathsf B_{t,t'}\circ\eta_t\) and \(\eta_{t'}\circ\mathsf A_{t,t'}\) both exist and are parallel morphisms from \(\mathsf A_\diamondsuit(t)\) to \(\mathsf B_\diamondsuit(t')\) in \(\mathsf{Sys}_\diamondsuit\). Since \(\mathsf{Sys}_\diamondsuit\) is thin, these morphisms are equal. Therefore, ?? holds. For \((iii)\), the component of the identity natural transformation at time \(t\) is represented by the empty path at \(\mathsf A_\diamondsuit(t)\). Since \(\mathsf A_\diamondsuit(t)\in S^{\mathrm{real}}_\diamondsuit(t)\), this representative is time-synchronous. Now let \(\eta:\mathsf A_\diamondsuit\Rightarrow\mathsf B_\diamondsuit\) and \(\theta:\mathsf B_\diamondsuit\Rightarrow\mathsf C_\diamondsuit\) be time-synchronous. At each \(t\), choose time-synchronous representatives of \(\eta_t\) and \(\theta_t\). Their concatenation passes only through states in \(S^{\mathrm{real}}_\diamondsuit(t)\) and represents \((\theta\circ\eta)_t = \theta_t\circ\eta_t.\) Hence, the composite is time-synchronous. ◻

Morphisms and isomorphisms in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\). The morphisms \(\mathsf A_{t,t'}\) and \(\mathsf B_{t,t'}\) encode the identity-relevant forward temporal evolution of two realized AI system histories from \(t\) to \(t'\). A component \(\eta_t:\mathsf A_\diamondsuit(t)\to\mathsf B_\diamondsuit(t)\) compares their states vertically at the same time \(t\). Write \(\mathsf A_{t,t'}=[a_{t,t'}]_\tau\), \(\mathsf B_{t,t'}=[b_{t,t'}]_\tau\), \(\eta_t=[c_t]_\tau\), and \(\eta_{t'}=[c_{t'}]_\tau\). The naturality condition ?? is equivalently \([b_{t,t'}\circ c_t]_\tau = [c_{t'}\circ a_{t,t'}]_\tau.\) This equality holds in the quotient category \(\mathsf{Sys}_\diamondsuit\); it does not require the concatenated paths \(b_{t,t'}\circ c_t\) and \(c_{t'}\circ a_{t,t'}\) to contain the same transformations, intermediate states, or number of steps. One route first compares the trajectories at time \(t\) and then evolves along \(\mathsf B_\diamondsuit\); the other first evolves along \(\mathsf A_\diamondsuit\) and then compares the trajectories at time \(t'\). Naturality requires only that the two routes determine the same trustworthiness-preserving morphism in \(\mathsf{Sys}_\diamondsuit\).

By definition, a time-synchronous representative of \(\eta_t\) uses only states in \(S^{\mathrm{real}}_\diamondsuit(t)\). No future-indexed state is therefore introduced into the comparison at time \(t\). Any stronger requirement that the assessments \(Q_P^{\mathsf A}(t)\) and \(Q_P^{\mathsf B}(t)\) be based exclusively on evidence available by time \(t\) must be included in the measurement and evidential conditions of the trustworthiness profile \(P\).

A morphism in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\) is thus a coherent family of same-time comparisons between realized AI system histories. Thinness of \(\mathsf{Sys}_\diamondsuit\) ensures the compatibility of same-time comparisons and time-relative histories, i.e., ?? . Isomorphism in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\) is a natural isomorphism whose components are time-synchronous. Since \(\mathsf{Sys}_\diamondsuit\) is thin, this is equivalent to the existence, at every time \(t\), of time-synchronous comparison morphisms in both directions. Figure 4 shows morphisms in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\), natural transformations and the relation between trustworthiness levels and realized AI system history functors.

Figure 4: The upper part of the figure represents a natural transformation\eta:\mathsf A_\diamondsuit\Rightarrow \mathsf B_\diamondsuiton the trustworthiness-level plane\tau_\diamondsuit=k.The slanted lines denote the fibresS_\diamondsuit(t) and S_\diamondsuit(t'), that is, the sets of\diamondsuit-relative states realized at times t and t'.The states\mathsf A_\diamondsuit(t),\mathsf A_\diamondsuit(t')and\mathsf B_\diamondsuit(t),\mathsf B_\diamondsuit(t')are the images of the realized histories\mathsf A_\diamondsuit and \mathsf B_\diamondsuitat those times. The solid polygonal paths represent the history morphisms\mathsf A_{t,t'} and \mathsf B_{t,t'}, while the dashedsegments \eta_t and \eta_{t'} are the components of thenatural transformation. Since \mathsf{Sys}_\diamondsuit is thin, once thesecomparison morphisms exist, the naturality square commutes automatically.The lower part shifts attention to a trustworthiness-level drop:after \mathsf A_\diamondsuit reaches the statex^-=\mathsf A_\diamondsuit(t^\ast_-) on the level k, the post-dropstate x^+=\mathsf C_\diamondsuit(t^\ast_+) lies on a differenttrustworthiness-level plane \tau_\diamondsuit=\ell<k. Since\tau_\diamondsuit(x^-)\neq\tau_\diamondsuit(x^+), no morphismx^-\to x^+ exists in \mathsf{Sys}_\diamondsuit. Hence the level drop is anidentity-interrupting event: the post-drop evolution cannot belong tothe same AI system history functor and must be represented, if realized,by a new history object in \mathsf{Traj}_{\diamondsuit,[t_0,T]}.

Categorical comparability requires a shared type. Realized AI system histories with different type data are not directly comparable within the same trajectory category. If \(\diamondsuit=(F,P,L_P)\) and \(\diamondsuit'=(F',P',L_{P'})\) differ, then \[\mathsf A_\diamondsuit \in \mathsf{Traj}_{\diamondsuit,[t_0,T]} \qquad\text{and}\qquad \mathsf B_{\diamondsuit'} \in \mathsf{Traj}_{\diamondsuit',[t_0,T]}\] belong to different categories, and there is no default morphism between them. Philosophically, this expresses the claim that identity comparisons presuppose a shared techno-function, trustworthiness profile, and level function [7]. For example, an ICU-triage system and a consumer-credit system may both qualify as AI systems, but they do not share the type datum required for a direct identity comparison in this framework.

Table 2 presents a summary of the time-relative categories \(\mathsf T_{t_0}\), \([\mathsf{T}_{[t_0,T]},\mathsf{Sys}_\diamondsuit]\), and \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\) presented in this section.

6 AI Identity in Category Theory↩︎

Finally, we identify the notions of AI system identity that emerge from the categorical formalization and relate them to the AI identity criteria in Definition 11. Let \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\) be the category of realized AI system histories of fixed type \(\diamondsuit\) introduced in Definition 24.

6.1 Equality of AI system history functors in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\)↩︎

We start our investigation of AI identity in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\) with a very strict concept: equality of functors.

Proposition 4. Let \(\mathsf A_\diamondsuit,\mathsf B_\diamondsuit\) be objects of \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\). If \[\mathsf A_\diamondsuit(t)=\mathsf B_\diamondsuit(t)\] in \(\mathsf{Sys}_\diamondsuit\) for every \(t\in[t_0,T]\), then \[\mathsf A_\diamondsuit=\mathsf B_\diamondsuit\] as functors, and hence as objects of \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\).

Proof. For every \(t\leq t'\), both \(\mathsf A_{t,t'}\) and \(\mathsf B_{t,t'}\) are morphisms from the common state \(\mathsf A_\diamondsuit(t)=\mathsf B_\diamondsuit(t)\) to the common state \(\mathsf A_\diamondsuit(t')=\mathsf B_\diamondsuit(t')\). Since \(\mathsf{Sys}_\diamondsuit\) is thin, these parallel morphisms are equal. The two functors therefore agree on objects and morphisms. ◻

The functor equality is very strict and has limited usefulness for AI identity. It applies, for instance, to two deployed copies of the same AI system type that occupy the same profile-relative state at every time. Their deployment conditions must therefore be sufficiently compatible for the copies to have identical measured profiles and trustworthiness levels throughout the observed interval. That said, equality of the history functors does not require the represented tokens to undergo the same lifecycle interventions.

6.2 Weak and Strong AI Identity Criteria↩︎

The identity criteria in Definition 11 admit weak and strong categorical readings.

Definition 25 (Weak and strong state identity). Fix the type datum \(\diamondsuit\). For states \(x,y\in S_\diamondsuit\), the weak \(\diamondsuit\)-relative identity relation is defined by \[x\equiv_\tau y \quad\Longleftrightarrow\quad \tau_\diamondsuit(x)=\tau_\diamondsuit(y).\] The strong* \(\diamondsuit\)-relative identity relation is categorical isomorphism in \(\mathsf{Sys}_\diamondsuit\): \[x\cong_{\mathsf{Sys}_\diamondsuit} y.\]*

On the weak reading, two states are identical relative to \(\diamondsuit\) whenever they belong to the same trustworthiness-level fibre. On the strong reading, identity requires categorical isomorphism in \(\mathsf{Sys}_\diamondsuit\), that is, admissible trustworthiness-level-preserving reachability in both directions. However, for synchronic comparisons between realized histories, this strong condition must additionally be witnessed by time-synchronous representatives. Thus, ambient isomorphism in \(\mathsf{Sys}_\diamondsuit\) is necessary but does not by itself establish strong synchronic identity in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\). While the weak reading directly recovers the criterion of [7]—see Definition 11, the strong reading is a stricter category-theoretic refinement that follows from our formalization.

The relations in Definition 25 are defined on the abstract state space \(S_\diamondsuit\). However, AI-system identity concerns states occupied by realized AI-system histories. In other words, the relevant states are of the form \(\mathsf A_\diamondsuit(t)\) for some realized history \(\mathsf A_\diamondsuit\in\mathsf{Traj}_{\diamondsuit,[t_0,T]}\) and some \(t\in[t_0,T]\). These considerations motivate the following theorem.

Theorem 1 (Weak and strong identity for realized AI-system histories). Let \(\mathsf A_\diamondsuit,\mathsf B_\diamondsuit\) be objects of \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\), and write \[a(t)=\mathsf A_\diamondsuit(t), \qquad b(t)=\mathsf B_\diamondsuit(t).\] Diachronic identity compares states \(a(t)\) and \(a(t')\) along the same realized history, while synchronic identity compares states \(a(t)\) and \(b(t)\) at the same time \(t\). Then the following statements hold.

  1. For every \(t\leq t'\), the history morphism \[\mathsf A_{t,t'}:a(t)\to a(t')\] in \(\mathsf{Sys}_\diamondsuit\) implies \[a(t)\equiv_\tau a(t').\] Hence every realized AI-system history satisfies the weak diachronic identity criterion.

  2. For \(t\leq t'\), the realized states \(a(t)\) and \(a(t')\) satisfy strong diachronic identity, \[a(t)\cong_{\mathsf{Sys}_\diamondsuit} a(t'),\] if and only if there exists a morphism \[a(t')\to a(t)\] in \(\mathsf{Sys}_\diamondsuit\). Equivalently, the realized history \(\mathsf A_\diamondsuit\) satisfies strong diachronic identity throughout \([t_0,T]\) if and only if it factors through the maximal subgroupoid \(\operatorname{Core}(\mathsf{Sys}_\diamondsuit) \hookrightarrow \mathsf{Sys}_\diamondsuit.\)

  3. If, for some \(t\in[t_0,T]\), there exists a time-synchronous comparison morphism \[\eta_t:a(t)\to b(t),\] then \[a(t)\equiv_\tau b(t).\] Consequently, the existence of a morphism \(\eta:\mathsf A_\diamondsuit\Rightarrow\mathsf B_\diamondsuit\) in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\) implies weak synchronic identity* at every \(t\in[t_0,T]\).*

  4. At time \(t\), the realized states \(a(t)\) and \(b(t)\) satisfy strong synchronic identity* if and only if \(a(t)\cong_{\mathsf{Sys}_\diamondsuit} b(t)\) is witnessed time-synchronously; equivalently, if and only if there exist morphisms \[\eta_t:a(t)\to b(t), \qquad \rho_t:b(t)\to a(t),\] each admitting a time-synchronous representative at \(t\). In particular, \[\mathsf A_\diamondsuit\cong_{\mathsf{Traj}_{\diamondsuit,[t_0,T]}}\mathsf B_\diamondsuit\] if and only if strong synchronic identity holds at every \(t\in[t_0,T]\).*

Proof. Every morphism in \(\mathsf{Sys}_\diamondsuit\) is represented by a path whose states have one common trustworthiness level.

For \((i)\), the history morphism \(\mathsf A_{t,t'}:a(t)\to a(t')\) therefore implies \(\tau_\diamondsuit(a(t)) = \tau_\diamondsuit(a(t')),\) and hence \(a(t)\equiv_\tau a(t').\)

For \((ii)\), the history morphism \(\mathsf A_{t,t'}:a(t)\to a(t')\) already provides trustworthiness-preserving reachability in the forward direction. Hence \(a(t)\cong_{\mathsf{Sys}_\diamondsuit}a(t')\) holds exactly when there is also a reverse morphism \(a(t')\to a(t)\) in \(\mathsf{Sys}_\diamondsuit\). Since \(\mathsf{Sys}_\diamondsuit\) is thin, the existence of morphisms in both directions forces their composites to be the corresponding identity morphisms. Thus the forward history morphism is an isomorphism in \(\mathsf{Sys}_\diamondsuit\). Requiring this for every \(t\leq t'\) is precisely the condition that \(\mathsf A_\diamondsuit\) factors through the inclusion \[\operatorname{Core}(\mathsf{Sys}_\diamondsuit) \hookrightarrow \mathsf{Sys}_\diamondsuit.\]

For \((iii)\), a time-synchronous comparison morphism \(\eta_t:a(t)\to b(t)\) is represented by a trustworthiness-level-preserving path. Consequently, \(\tau_\diamondsuit(a(t)) = \tau_\diamondsuit(b(t)),\) and therefore \(a(t)\equiv_\tau b(t).\) If \(\eta:\mathsf A_\diamondsuit\Rightarrow\mathsf B_\diamondsuit\) is a morphism in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\), the same argument applies to every component \(\eta_t\), yielding weak synchronic identity at every \(t\in[t_0,T]\).

For \((iv)\), suppose first that there exist time-synchronous morphisms \[\eta_t:a(t)\to b(t), \qquad \rho_t:b(t)\to a(t).\] Their composites are endomorphisms of \(a(t)\) and \(b(t)\). Since \(\mathsf{Sys}_\diamondsuit\) is thin, \(\rho_t\circ\eta_t=\mathrm{id}_{a(t)}\), \(\eta_t\circ\rho_t=\mathrm{id}_{b(t)}\). Thus, \(a(t)\cong_{\mathsf{Sys}_\diamondsuit} b(t)\) through time-synchronous comparison morphisms. Now suppose that strong synchronic identity holds at every \(t\in[t_0,T]\). Since \(\mathsf{Sys}_\diamondsuit\) is thin, the comparison morphisms in each direction are unique whenever they exist. By Lemma 2, the two component families automatically define natural transformations \[\eta:\mathsf A_\diamondsuit\Rightarrow\mathsf B_\diamondsuit, \qquad \rho:\mathsf B_\diamondsuit\Rightarrow\mathsf A_\diamondsuit\] in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\). Their composites are endomorphisms of \(\mathsf A_\diamondsuit\) and \(\mathsf B_\diamondsuit\), respectively. Since \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\) is thin, these composites are the corresponding identity natural transformations. Hence \[\mathsf A_\diamondsuit\cong\mathsf B_\diamondsuit \quad\text{in}\quad \mathsf{Traj}_{\diamondsuit,[t_0,T]}.\] The converse follows immediately because an isomorphism in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\) has time-synchronous components in both directions at every time. ◻

Theorem 1 clarifies how the weak and strong readings behave once they are applied to realized AI-system histories. First, weak diachronic identity is automatic for every realized AI-system history, even though the quantified profile, implementation, deployment conditions, or lifecycle provenance may vary along the history. Second, strong diachronic identity is stricter. It amounts to mutual trustworthiness-preserving reachability of the endpoint states. However, this does not mean that the realized lifecycle is temporally reversible: The reverse morphism \(a(t')\to (t)\) is a morphism in \(\mathsf{Sys}_\diamondsuit\), not necessarily a time-ordered reversal of the sequence of interventions. Third, time-synchronous comparison between realized histories implies weak synchronic identity. Thus, morphisms in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\), i.e., time-synchronous natural transformations, provide a categorical sufficient condition for weak synchronic AI-system identity throughout the observed interval. Finally, isomorphisms in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\) of realized AI system history functors over \([t_0,T]\) capture strong synchronic identity of realized states over time.

6.3 Examples of identity in real-world applications↩︎

6.3.0.1 Example 1: Weak and strong diachronic identity under lifecycle change.

Consider a credit-scoring AI system deployed at time \(t\) and subsequently recalibrated, retrained on refreshed data, and migrated to a new serving infrastructure at time \(t'>t\). These interventions may change its measured profile, so that \(Q_P^{\mathsf A}(t)\neq Q_P^{\mathsf A}(t'),\) while leaving its trustworthiness level unchanged. Then, two states are weakly diachronically identical, \(a(t)\equiv_\tau a(t'),\) even though they are not equal. However, how much profile variation is compatible with weak identity depends on the granularity of \(L_P\): a finer level function distinguishes smaller changes, whereas a coarser function permits greater variation within one level fibre. Strong diachronic identity holds when a reverse admissible trustworthiness-level-preserving path from \(a(t')\) to \(a(t)\) also exists. Such a reverse morphism witnesses mutual trustworthiness-preserving reachability of the endpoint states. It need not undo the concrete interventions that produced the later state, nor need it represent a backward-in-time lifecycle trajectory. If an update instead produces \[\tau_\diamondsuit(a(t'))\neq\tau_\diamondsuit(a(t)),\] the identity-preserving history segment terminates. The later state cannot belong to the same AI system history functor, although it may become the initial state of a new history segment after reassessment, remediation, or reclassification. The two segments are neither equal as functors nor isomorphic through time-synchronous natural transformations.

6.3.0.2 Example 2: Weak synchronic identity under profile-relative rescaling.

Let \(\mathsf A_\diamondsuit,\mathsf B_\diamondsuit: \mathsf{T}_{[t_0,T]}\to\mathsf{Sys}_\diamondsuit\) represent two copies of the same AI system type deployed in different but type-compatible settings, such as the same medical AI system used in two comparable clinics within the same geographic region. At time \(t\), write \(a(t)=\mathsf A_\diamondsuit(t)=(Q_P^{\mathsf A}(t),L_P(Q_P^{\mathsf A}(t)))\) and \(b(t)=\mathsf B_\diamondsuit(t)=(Q_P^{\mathsf B}(t),L_P(Q_P^{\mathsf B}(t)))\). Suppose that the two profiles differ only in the \(i\)-th profile dimension, with \(Q_{P,i}^{\mathsf B}(t)=\lambda Q_{P,i}^{\mathsf A}(t)\) for some \(\lambda\in(0,1)\), while \(Q_{P,j}^{\mathsf B}(t)=Q_{P,j}^{\mathsf A}(t)\) for every \(j\neq i\). The rescaling may represent reduced evidential support or deployment-specific attenuation of the \(i\)-th trustworthiness dimension.

Assume that \(L_P\) is insensitive to changes in the \(i\)-th coordinate along the rescaling range under consideration. It follows that \(L_P\!\left(Q_P^{\mathsf A}(t)\right) = L_P\!\left(Q_P^{\mathsf B}(t)\right)\). Choose \(1=\lambda_0>\lambda_1>\cdots>\lambda_m=\lambda,\) and define profiles \(Q_P^{(k)}(t)\in I_P\) by \[Q_{P,j}^{(k)}(t) = \begin{cases} \lambda_k Q_{P,i}^{\mathsf A}(t), & j=i,\\[2mm] Q_{P,j}^{\mathsf A}(t), & j\neq i. \end{cases}\] Let \[x_k(t) = \left( Q_P^{(k)}(t), L_P(Q_P^{(k)}(t)) \right).\]

Suppose, in addition, that every \(x_k(t)\) belongs to \(S^{\mathrm{real}}_\diamondsuit(t)\) and that each consecutive pair \(x_{k-1}(t),x_k(t)\) is connected by an admissible primitive transformation. Then \[c_t= \bigl( x_0(t)=a(t)\to x_1(t)\to\cdots\to x_m(t)=b(t) \bigr)\] is a time-synchronous trustworthiness-level-preserving representative. Hence \(\eta_t=[c_t]_\tau:a(t)\to b(t)\) is a time-synchronous comparison morphism. It witnesses categorical comparability at time \(t\) and therefore establishes weak synchronic identity between the two copies at that time.

6.3.0.3 Example 3: Strong synchronic identity under an invertible profile transformation.

Let \(\mathsf A_\diamondsuit,\mathsf B_\diamondsuit: \mathsf{T}_{[t_0,T]}\to\mathsf{Sys}_\diamondsuit\) be realized AI system histories, and write \(a(t) = \left( Q_P^{\mathsf A}(t), L_P(Q_P^{\mathsf A}(t)) \right).\) Let \(\varphi:I_P\to I_P\) be a bijection with inverse \(\psi=\varphi^{-1}\), and suppose that \[L_P(\varphi(Q))=L_P(Q) \qquad \text{for every }Q\in I_P.\] Define \[Q_P^{\mathsf B}(t) = \varphi(Q_P^{\mathsf A}(t)), \qquad b(t) = \left( Q_P^{\mathsf B}(t), L_P(Q_P^{\mathsf B}(t)) \right).\]

Suppose that the forward and inverse profile transformations are witnessed at time \(t\) by admissible time-synchronous representatives defining morphisms \[\eta_t:a(t)\to b(t), \qquad \rho_t:b(t)\to a(t).\] Since \(\mathsf{Sys}_\diamondsuit\) is thin, \(\rho_t\circ\eta_t=\mathrm{id}_{a(t)}\), \(\eta_t\circ\rho_t=\mathrm{id}_{b(t)},\) and hence \(a(t)\cong_{\mathsf{Sys}_\diamondsuit} b(t).\) Thus, the two states satisfy strong synchronic identity at time \(t\). If such time-synchronous representatives exist in both directions for every \(t\in[t_0,T]\), then the corresponding component families assemble into a natural isomorphism \(\mathsf A_\diamondsuit\cong_{\mathsf{Traj}_{\diamondsuit,[t_0,T]}}\mathsf B_\diamondsuit,\) and the two realized histories satisfy strong synchronic identity throughout the observed interval.

The bijectivity of \(\varphi\) at the profile level does not by itself produce morphisms in \(\mathsf{Sys}_\diamondsuit\). Strong synchronic identity additionally requires that both directions be instantiated by admissible time-synchronous lifecycle paths. Governance-relevant examples include the identity transformation \(\varphi=\mathrm{id}_{I_P}\), for which \(\mathsf B_\diamondsuit=\mathsf A_\diamondsuit\) and \(\eta_t=\mathrm{id}_{a(t)}\). A nontrivial example is the coordinatewise power transformation \(\varphi_p(Q^1,\ldots,Q^n)=((Q^1)^p,\ldots,(Q^n)^p)\), with \(p>0\), whose inverse is \(\varphi_{1/p}\). Such a transformation may represent an invertible nonlinear rescaling of the profile measurements: \(p>1\) gives greater prominence to high scores and compresses intermediate ones, whereas \(0<p<1\) expands intermediate and lower scores. More generally, one may use \[\varphi_{p}(Q^1,\ldots,Q^n)=((Q^1)^{p_1},\ldots,(Q^n)^{p_n}),\] where every \(p_i>0\), with inverse given by the exponents \(1/p_i\). Setting \(p_i=1\) on selected coordinates allows only particular profile dimensions to be rescaled. These transformations can model invertible changes in normalization, reporting conventions, or dimension-specific governance sensitivity. They support strong synchronic identity only when the level function is invariant under the transformation and the forward and inverse transformations admit time-synchronous lifecycle representatives.

7 Discussion↩︎

We developed a categorical account of AI system identity from a trustworthiness-based metaphysics of artifacts. The main contribution of the account is that it separates relations between AI system states that the original propositional criteria in [7] leave undifferentiated. While the biconditionals defining \(=_\diamondsuit\) in [7] identify AI systems, synchronically and diachronically, through equality of trustworthiness levels, the categorical construction recovers this weak criterion, but also adds directed and mutual reachability, temporally admissible histories, and time-synchronous comparison of realized AI system histories.

7.1 A hierarchy of identity and reachability relations↩︎

Table 3 summarizes the identity-relevant relations introduced by the formalization. The original relation \(=_\diamondsuit\) is a type-relative equivalence relation induced by equality of trustworthiness levels. The categorical weak relation \(\equiv_\tau\) recovers this level-theoretic criterion at the level of profile-relative abstract states. The preorder \(\preceq_\tau\) records directed trustworthiness-level-preserving reachability between abstract states: \(x\preceq_\tau y\) means that at least one admissible level-preserving path from \(x\) to \(y\) exists. This is still an abstract relation. It does not imply that the path is causally realized, temporally ordered, or part of the lifecycle of a deployed system. Strong state-level identity is captured by isomorphism in \(\mathsf{Sys}_\diamondsuit\), that is, by mutual state reachability. Strong synchronic identity arises at the level of isomorphic realized history functors \[\mathsf A_\diamondsuit\cong_{\mathsf{Traj}_{\diamondsuit,[t_0,T]}}\mathsf B_\diamondsuit.\] Thus, our formalization realizes a characteristically categorical idea: identity is not read off from internal descriptions alone, but from structure-preserving transformations [11], [27], and strong synchronic identity of AI systems is expressed by transformations between functors that encode their evolution over time.

Table 3: Hierarchy of identity, provenance, and reachability relations. Weak identity recovers equality of trustworthiness levels. Strong state-level identity adds mutual reachability in \(\Sys_\diam\). Strong synchronic identity of realized histories is captured by natural isomorphism in \(\Traj_{\diam,[t_0,T]}\).
Relation Level Interpretation
\(=_\diam\) Propositional AI-identity criterion The original type-relative criterion of [7]. Synchronically and diachronically, it is defined by equality of trustworthiness levels within the fixed type datum \(\diam\).
\(\equiv_\tau\) Weak categorical identity For \(x,y\in S_\diam\), \[x\equiv_\tau y \quad\Longleftrightarrow\quad \tau_\diam(x)=\tau_\diam(y).\] Applied to realized states, this yields weak diachronic identity \(a(t)\equiv_\tau a(t')\) and weak synchronic identity \(a(t)\equiv_\tau b(t)\).
\(\preceq_\tau\) Directed reachability For \(x,y\in S_\diam\), \[x\preceq_\tau y \Longleftrightarrow \text{there exists a trustworthiness-level-preserving path }x\rightsquigarrow y.\] This is an abstract reachability relation. It does not, by itself, imply temporal ordering, causal realization, or operational recoverability.
\(x\cong_{\Sys_\diam}y\) Strong state-level identity State isomorphism in \(\Sys_\diam\), equivalently mutual trustworthiness-preserving reachability: \(x\preceq_\tau y\) and \(y\preceq_\tau x\). For realized diachronic comparison, \(a(t)\cong_{\Sys_\diam}a(t')\) expresses strong identity of endpoint states.
\(\eta:\mathsf A_\diam\Rightarrow\mathsf B_\diam\) Weak synchronic comparison of histories A morphism in \(\Traj_{\diam,[t_0,T]}\) consists of time-synchronous comparison morphisms \(\eta_t:a(t)\to b(t)\) at every \(t\in[t_0,T]\). Its existence implies weak synchronic identity \(a(t)\equiv_\tau b(t)\) throughout the interval.
\(\mathsf A_\diam\cong_{\Traj_{\diam,[t_0,T]}}\mathsf B_\diam\) Strong synchronic identity of realized histories Natural isomorphism of realized AI-system history functors. It holds precisely when, at every \(t\in[t_0,T]\), the realized states \(a(t)\) and \(b(t)\) are mutually comparable through time-synchronous trustworthiness-preserving morphisms.

This hierarchy also explains why the construction does not stop at the path categories. The free path category \(\mathsf{Path}_\diamondsuit\) is too large for identity because it contains arbitrary admissible lifecycle paths, including paths that leave a trustworthiness-level fibre and later return to it. Restricting to \(\mathsf{Path}^{\tau}_\diamondsuit\) solves this problem by retaining only paths whose intermediate states preserve one trustworthiness level. However, \(\mathsf{Path}^{\tau}_\diamondsuit\) still remembers provenance, namely the particular recorded sequence of lifecycle transformations by which a state is reached. Distinct level-preserving paths between the same source and target remain distinct, and mutual reachability does not yet amount to categorical isomorphism: the composites of a path \(x\rightsquigarrow y\) and a path \(y\rightsquigarrow x\) are generally non-empty loops, not identity morphisms. Stopping at \(\mathsf{Path}^{\tau}_\diamondsuit\) would therefore yield a provenance-sensitive theory of level-preserving lifecycle paths, not a categorical theory of identity as isomorphism.

The quotient \(\mathsf{Sys}_\diamondsuit\) performs the required identity-relevant abstraction as it identifies parallel trustworthiness-level-preserving paths and retains only the fact that one state is reachable from another within the same trustworthiness-level fibre. However, in \(\mathsf{Sys}_\diamondsuit\), an isomorphism does not assert that one concrete lifecycle process reverses another. A rollback, retraining, or recalibration may reconstruct a previous profile-relative state without undoing every computational, organizational, informational, or external consequence of the forward transformation. That is, isomorphism in \(\mathsf{Sys}_\diamondsuit\) means only that both directed reachability relations exist. Since \(\mathsf{Sys}_\diamondsuit\) is thin, the two composites are equal to the corresponding identity morphisms in the quotient category. These identity morphisms are represented by empty paths, but the lifecycle loops witnessing mutual reachability need not be empty and need not undo one another.

Similarly, natural isomorphism in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\) does not require realized AI system histories to coincide. It requires, for every time \(t\in[t_0,T]\), time-synchronous comparison morphisms whose composites are equivalent to the corresponding identity morphisms in \(\mathsf{Sys}_\diamondsuit\). Naturality is automatic once these components exist, because \(\mathsf{Sys}_\diamondsuit\) is thin. Thus, natural isomorphism of two realized AI system histories expresses mutual same-time comparability of two realized AI system histories throughout the interval, not equality of their raw lifecycle provenance. These natural isomorphisms can be constructed explicitly. A sufficient way to obtain such natural isomorphisms is to exhibit, at every time \(t\), trustworthiness-level-preserving invertible transformations between the assessed states of the two realized histories in both directions, as in Example 3. In that case, each pair of same-time states is mutually reachable within its trustworthiness-level fibre, and the resulting component morphisms assemble automatically into inverse natural transformations.

7.2 Trustworthiness-level drops and identity interruption↩︎

In addition, our categorical approach gives a precise sense in which trustworthiness-level drops are identity-interrupting events. If two states \(x^{-},x^{+}\in S_\diamondsuit\) satisfy \[\tau_\diamondsuit(x^{-})\neq \tau_\diamondsuit(x^{+}),\] then no morphism \(x^{-}\to x^{+}\) exists in \(\mathsf{Sys}_\diamondsuit\). Hence \(x^{-}\) and \(x^{+}\) cannot both lie in the image of the same AI system history functor. They may both be states of AI systems of the same type datum \(\diamondsuit\), but they are functorially incommensurable with respect to an uninterrupted identity-preserving history. A change of trustworthiness level therefore terminates one history segment and, if a post-change system is realized, begins another. This point has an important consequence for the design of the trustworthiness-level function \(L_P\). The function \(L_P\) should not be so sensitive to ordinary variation, measurement noise, or expected operational fluctuation in \(q_P\) that minor changes repeatedly push the system across level boundaries. If this happens, the system may appear to flicker in and out of existence with respect to a single identity-preserving history functor. This would make identity unstable, evidence transfer difficult to justify, and governance continuity practically unauditable.

For this reason, \(L_P\) must be designed and validated as a robust governance tool. Its level boundaries should be tested during design under plausible operational scenarios, including measurement uncertainty, deployment variation, distribution shift, monitoring noise, and expected model updates. Changes of assessments \(q_P\) within a trustworthiness-level fibre should represent tolerable profile variation, while boundary crossings should mark genuine governance-relevant transitions, such as substantial modifications in the EU AI Act—see Article 3(23) therein [3]. In practice, this may require margin conditions around level boundaries, scenario testing, and robustness analysis. The metaphysical point is that an unstable \(L_P\) creates unstable identity histories. The governance point is that level functions should be auditable not only for interpretability, but also for their capacity to support persistence judgments under realistic lifecycle variation.

7.3 The use of categories, their thinness, provenance, and compositionality↩︎

One might ask whether the same formalization could be developed using graph-theoretic or transition-system language. The answer is partly affirmative: our construction begins with precisely such data, namely, the free path category \(\mathsf{Path}_\diamondsuit\). At this first level, graph theory and category theory are therefore closely aligned. However, the categorical language becomes important in the subsequent steps. It makes path composition explicit, isolates the level-preserving subcategory \(\mathsf{Path}^{\tau}_\diamondsuit\), supports quotienting by parallel level-preserving paths, and yields the thin reachability category \(\mathsf{Sys}_\diamondsuit\). It then allows post-deployment histories to be represented as functors from a time category into \(\mathsf{Sys}_\diamondsuit\), and synchronic comparison between histories to be represented by natural transformations.

Thus, category theory provides a unified language for the successive abstractions needed by the AI identity problem: from primitive transformations, to composed lifecycle paths, to trustworthiness-level-preserving reachability, to time-indexed histories, and finally to comparison between histories. This is also where the construction recovers the original propositional identity criteria while making a stronger criterion available. The stronger criterion is expressed categorically: state-level identity is captured by isomorphism in \(\mathsf{Sys}_\diamondsuit\), and history-level identity by natural isomorphism in \(\mathsf{Traj}_{\diamondsuit,[t_0,T]}\). In this sense, our construction follows a classical categorical strategy [11]: instead of comparing objects only by their internal descriptions, it compares them through structure-preserving transformations, and then compares whole histories through transformations between functors. This is aligned with Freyd’s well-known characterization of category theory:6

[...] and category theory is likewise better described as the theory of functors. [...] It is not too misleading, at least historically, to say that categories are what one must define in order to define functors, and that functors are what one must define in order to define natural transformations [28]

Note that the free path category \(\mathsf{Path}_\diamondsuit\) retains AI lifecycle provenance—here intended as the tracking of the transformation sequences between states. In fact, distinct sequences of retraining, validation, recalibration, software modification, documentation, or redeployment remain different paths. The subcategory \(\mathsf{Path}^{\tau}_\diamondsuit\) restricts attention to paths that preserve a common trustworthiness level, a necessary step towards the propositional AI identity criteria in [7]. The quotient \(\mathsf{Sys}_\diamondsuit\) records only direct reachability. Thus, our construction says that provenance is not part of AI identity once the transition remains within the same level and connects the same source and target states. This choice also explains why we do not introduce a monoidal structure on the category of AI system histories. Monoidal categorical structures are powerful tools for modelling compositionality in mathematics and computer science, such as in the case of concurrent resources, and interacting processes [16], [29]. They would be natural if the aim were to model joint AI systems, multi-agent compositions, or parallel lifecycle resources. At the free path category level, one might investigate the monoidal structure induced by the funny tensor product [30]. However, as \(\mathsf{Sys}_\diamondsuit\) is thin, the noncommutative information that motivates that monoidal structure is lost. Thus, for the purposes of AI system identity and this work, the relevant composition is the natural morphism of AI system history functors.

7.4 The metaphysical neutrality about persistence of our account↩︎

The present formalism does not require the objects \(\mathsf A_\diamondsuit(t)\) to be temporal parts, stages, or complete AI system tokens. Any state \(\mathsf A_\diamondsuit(t)\) may be occupied by several concrete systems with different models, hardware, software stacks, or deployment histories. Likewise, the functor \(\mathsf A_\diamondsuit\) represents an AI system history rather than defining the system as a mereological sum of instantaneous entities. A perdurantist interpretation remains possible: one may understand a history as organizing temporally ordered stages or temporal parts. But an endurantist interpretation is also possible: one may understand the same functor as representing how one persisting system bears different profile-relative properties over time. A stage-theoretic reading would require the additional claim that each state is itself a complete AI system individual. However, no such claim follows from the construction.

The proposed framework is therefore neutral among the principal metaphysical theories of persistence. Its narrower commitment is that AI system identity under change requires temporally indexed profile-relative states, admissible lifecycle transformations, realized histories, and explicitly specified trustworthiness invariants. The framework tells us what must remain stable, reachable, comparable, or mutually reachable relative to \(\diamondsuit\). That said, it does not settle whether the persisting AI system is best understood as an enduring continuant, a perduring four-dimensional entity, or a sequence of stages.

7.5 Recognizing identity relations in governance practice↩︎

A further question concerns how these identity relations can be recognized in operational settings. This is an epistemological and governance-oriented question, which is not at the core of the present work. Nonetheless, we will briefly comment on it. The present formalization is not disconnected from which forms of documentation, monitoring, and lifecycle evidence allow one to determine whether the relevant identity conditions hold in practice. In fact, as identity is defined relative to a type datum \(\diamondsuit=(F,P,L_P)\), its application depends on artifacts that are increasingly required by AI governance regimes. In particular, the EU AI Act requires, for high-risk AI systems, documented risk-management processes, technical documentation kept up to date, automatic record-keeping and logging, documented quality-management procedures, and post-market monitoring systems that collect and analyse data on performance and compliance throughout the system’s lifetime [3]. Such materials can document the system’s techno-function and intended use, the specification of the trustworthiness profile \(P\), the measurement and aggregation procedures producing \(q_P\), the trustworthiness-level function \(L_P\), state-monitoring records, and lifecycle transformations such as retraining, recalibration, threshold adjustment, rollback, or deployment-environment change. They can therefore provide partial evidence for weak identity, directed reachability, mutual reachability, and identity interruption through trustworthiness-level changes. However, the detailed methodology for recognizing these relations “in the wild” requires an epistemology of AI system identity for governance and MLOps practice, and lies beyond the scope of the present paper. Relatedly, this material supporting categorical identity provides evidence for comparisons between AI system tokens, but not a sufficient epistemic warrant for all responsible-AI claims.

8 Conclusion↩︎

AI systems change after deployment through retraining, recalibration, reconfiguration, monitoring interventions, and changes in their operational environments. These transformations make identity a central problem for responsible AI: without explicit criteria of sameness, it remains unclear when evidence transfers across AI tokens, when explanations and fairness claims remain applicable, or when an update creates a governance-relevant discontinuity. To address these questions formally, we develop a categorical account of AI system identity grounded in techno-function and trustworthiness. The formalization distinguishes weak from strong identity criteria, recovering and extending the approach of [7]. Its central claim is that AI system identity is function-plus-trustworthiness identity. Category theory renders this claim temporal and structural without reducing an AI system to a model, a material implementation, or a disconnected sequence of snapshots. The account also remains neutral between endurantist and perdurantist theories of persistence.

The framework provides a basis for analyzing identity-preserving updates, substantial modifications, and the transfer of evidence and accountability across versions and deployments. Its practical application requires explicit trustworthiness profiles, level functions, temporally coherent lifecycle records, and documented assumptions about admissibility and reversibility. Where these elements are absent, the identity of a changing AI system remains insufficiently specified for reliable AI governance and for well-grounded epistemological and ethical assessments of human–AI interaction.

Acknowledgments↩︎

We acknowledge partial support by the Swiss National Science Foundation (SNSF), grant no. 229061.

References↩︎

[1]
W. V. O. Quine, Ontological Relativity and Other Essays. New York: Columbia University Press, 1969.
[2]
D. Kreuzberger, N. Kühl, and S. Hirschl, “Machine learning operations (MLOps): Overview, definition, and architecture,” IEEE Access, vol. 11, pp. 31866–31879, 2023.
[3]
EU AI Act, Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence,” European Union; Official Journal of the European Union, L 1689, 12 July 2024, Jun. 2024. [Online]. Available: https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
[4]
A. Ferrario and J. Hatherley, “Update opacity: Epistemic accessibility and governance under AI system change,” arXiv preprint arXiv:2606.00037, 2026.
[5]
A. Ferrario, Accepted for publication (non-archival) at the 2026 ACM Conference on Fairness, Accountability and Transparency (FAccT ’26)“High-risk AI systems and the problem of identity in the European AI Act.” 2026, [Online]. Available: https://arxiv.org/abs/2605.23922.
[6]
M. Carrara and P. E. Vermaas, “The fine-grained metaphysics of artifactual and biological functional kinds,” Synthese, vol. 169, no. 1, pp. 125–143, 2009.
[7]
A. Ferrario, “A trustworthiness-based metaphysics of artificial intelligence systems,” in Proceedings of the 2025 ACM Conference on Fairness, Accountability, and Transparency, 2025, pp. 1360–1370.
[8]
EU High-Level Expert Group on Artificial Intelligence, “Ethics guidelines for Trustworthy AI.” https://digital-strategy.ec.europa.eu/en/library/ethics-guidelines-trustworthy-ai, 2019.
[9]
S. Eilenberg and S. M. Lane, “General theory of natural equivalences,” Transactions of the American Mathematical Society, vol. 58, no. 2, pp. 231–294, 1945.
[10]
S. M. Lane, “Natural associativity and commutativity,” Rice University Studies, vol. 49, no. 4, pp. 28–46, 1963.
[11]
S. Mac Lane, Categories for the working mathematician. Springer, 1971.
[12]
J.-P. Marquis, From a Geometrical Point of View: A Study of the History and Philosophy of Category Theory. Springer Science & Business Media, 2008.
[13]
E. J. Lowe, “On the identity of artifacts,” The Journal of Philosophy, vol. 80, no. 4, pp. 220–232, 1983.
[14]
L. R. Baker, “The ontology of artifacts,” Philosophical Explorations, vol. 7, no. 2, pp. 99–111, 2004.
[15]
T. Williamson, Identity and discrimination. John Wiley & Sons, 2013.
[16]
D. I. Spivak, Category theory for the sciences. Cambridge, MA: MIT Press, 2014.
[17]
N. S. Yanofsky, Monoidal category theory: Unifying concepts in mathematics, physics, and computing. MIT Press, 2024.
[18]
E. J. Lowe, “How real are artefacts and artefact kinds?” in Artefact kinds: Ontology and the human-made world, M. Franssen, P. Kroes, T. A. C. Reydon, and P. E. Vermaas, Eds. Springer, 2014, pp. 17–26.
[19]
T. Hobbes, Original Latin editionDe corpore. London: Andrew Crooke, 1655.
[20]
D. Wiggins, Sameness and Substance Renewed. Cambridge: Cambridge University Press, 2001.
[21]
C. L. Elder, Real natures and familiar objects. The MIT Press, 2004.
[22]
P. Ala-Pietilä et al., The Assessment List for Trustworthy Artificial Intelligence (ALTAI). European Commission, 2020.
[23]
D. Kaur, S. Uslu, K. J. Rittichier, and A. Durresi, “Trustworthy artificial intelligence: A review,” ACM Computing Surveys, vol. 55, no. 2, pp. 1–38, 2022.
[24]
S. Rabanser, S. Kapoor, P. Kirgis, K. Liu, S. Utpala, and A. Narayanan, “Towards a science of AI agent reliability,” arXiv preprint arXiv:2602.16666, 2026.
[25]
N. Kemmerzell, A. Schreiner, H. Khalid, M. Schalk, and L. Bordoli, “Towards a better understanding of evaluating trustworthiness in AI systems,” ACM Computing Surveys, vol. 57, no. 9, pp. 1–38, 2025.
[26]
B. Eken, S. Pallewatta, N. Tran, A. Tosun, and M. A. Babar, “A multivocal review of MLOps practices, challenges and open issues,” ACM Computing Surveys, vol. 58, no. 2, pp. 1–35, 2025.
[27]
S. Mac Lane, “Categorical algebra,” Bulletin of the American Mathematical Society, vol. 71, no. 1, pp. 40–106, 1965.
[28]
P. J. Freyd, Abelian categories: An introduction to the theory of functors. New York: Harper & Row, 1964.
[29]
B. Fong and D. I. Spivak, “Seven sketches in compositionality: An invitation to applied category theory,” arXiv preprint arXiv:1803.05316, 2018.
[30]
F. Foltz, C. Lair, and G. M. Kelly, “Algebraic categories with few monoidal biclosed structures or none,” Journal of Pure and Applied Algebra, vol. 17, no. 2, pp. 171–177, 1980.

  1. Following [17], we use “collections” for \(\mathrm{Ob}(\mathcal{C})\) and \(\mathrm{Hom}_{\mathcal{C}}(X,Y)\) instead of “sets” or “classes”. Nothing in the present paper depends on a particular choice of set-theoretic foundation or on size distinctions between small and large categories.↩︎

  2. Techno-functions can be specified at different levels of detail: broader specifications pick out wider artifact kinds, whereas finer specifications carve out narrower ones.↩︎

  3. The distinction is especially important for generative and multi-purpose systems such as large language models. A broadly specified techno-function, such as next-token prediction or autocompletion, may support many intended uses, including drafting, summarization, tutoring, translation, or entertainment. In the present account, the techno-function anchors identity at the level of AI system kind, while the trustworthiness profile and level function capture the contextualized conditions under which that function counts as appropriately realized for a given intended use.↩︎

  4. Realization is understood here in a metaphysical rather than epistemic sense. Whether designers, auditors, or governance actors can determine that such an instantiation exists is a distinct epistemic and practical question. In particular, two deployed tokens may instantiate the same \(\diamondsuit\)-relative state only relative to the measurement conventions, normalization rules, and evidential standards fixed by \(P\).↩︎

  5. For example, suppose \(P\) has four quantified dimensions and \(q_P\in[0,1]^4\). Then a tuple such as \[q_P=(0.813,0.742,0.901,0.615)\] determines an abstract state \(x=((0.813,0.742,0.901,0.615),L_P(0.813,0.742,0.901,0.615)) \in S_\diamondsuit.\) But it need not be the case that any deployed AI-system token in the population under analysis occupies exactly this \(\diamondsuit\)-relative state at a given time \(t\). Cardinality considerations aside, the point is both practical and conceptual: even when quantified profiles are represented by floating-point values, the abstract state space \(S_\diamondsuit\) is too large, containing many admissible states that are not realized by any token at a given time.↩︎

  6. Freyd’s characterization of categories is also recalled by Mac Lane in his discussion of categorical algebra [27].↩︎