01 Foxora Fennec

A model that reads a contract, not a conversation.

Fennec is the world's first Agentic Language Model — the first model whose native interface is a governance contract, not conversation. It runs Foxora. Trained against GRIP, inside the Runtime. It is built and ready; public release has not happened yet.

StatusReady · awaiting release · waitlist open

No release date · no benchmark · nothing to install

Fig. 01 — the mark, drawn live
Scale 1 : 1 · drawn live— points
Every point is one dot of ink on the drafting grid, and together they are the mark. Move across it — the figure is drawn, not printed.

[00] Frontispiece

The fable opens. The proof follows.

FIG. 00 is a produced animation, made for this sheet — felt, clay and paint, shot as a fable. It is not a screen recording, nothing in it is software running, nothing in it is a demonstration, and no figure in it is measured. Everything this sheet stands behind is drawn below, and the two ledgers at [07] and [09] are where it ends.

Fig. 00 · the fableSheet 00 · 1:00 · with sound

A frame from the film: a gold, many-armed toy robot holding a hammer, a paintbrush, a scroll and a stack of coins all at once, while a small felt child beside it looks up, worried. Green hills and white clouds behind them.

Medium · produced animation · not a captureMP4 · 1280 × 720 · served from this site

[02] The boundary

Its interface is a contract. Its output is an act.

Two of the four criteria are about the edge of the model — what may cross in, and what may cross out. Neither side of that edge is prose, and neither side is negotiable at runtime.

The only thing it accepts is a shape.Fig. 02-A
FIG. 02-A · THE SHAPE THAT FITSSHEET 02 2A RAW PROMPT NO SLOT THE INTAKE CONTEXT CONTRACT BUDGET PROVENANCE INCLUDED SEALED

Contract input. Its only input is a compiled context contract — budgeted and provenance-carrying, never a raw prompt. A sentence typed at it is not a smaller version of that. It is the wrong shape, and there is no slot for it.

The only thing it emits is a message.Fig. 02-B
FIG. 02-B · WHAT LEAVES BY THE DIESHEET 02 2B THE DIE TYPED · SCHEMA-VALID · DECODED UNDER CONSTRAINT WHAT IS NEVER PRODUCED AS AN ACT FREE PROSE · NOT AN ACT

Typed output. What it produces are protocol messages under constrained decoding — never free prose offered as an action. Text that merely describes an intention is not a smaller version of a message either. It cannot leave by the die.

[03] What graded it

The gates were the teacher.

A conversational model is graded by a person's opinion of a sentence. This one is graded by four machines that were already there: the runtime's own gates. They do not read the reply. They decide whether the act may run, whether it may act, whether it can afford to, and whether it settled — and their verdict is the signal.

FIG. 03-A · THE FOUR GATESSHEET 03 3A THE RUNTIME'S OWN GATES ADMISSIONMAY IT RUN? AUTHORITYMAY IT ACT? BUDGETCAN IT AFFORD IT? SETTLEMENTDID IT SETTLE? THE WORKSETTLED EVERY ACT PASSES ALL FOUR
  1. 01

    Admission

    Whether this piece of work is allowed to start at all, under the frame it arrived in.

  2. 02

    Authority

    Whether the worker holds a live, scoped right to the particular act it is about to attempt.

  3. 03

    Budget

    Whether what it is about to spend is inside the ceiling the contract arrived carrying.

  4. 04

    Settlement

    Whether what happened was accounted for, and closed, rather than merely produced.

Fig. 03-B · the returnA refusal is as much of a signal as a pass — and there are more of them.
FIG. 03-B · THE VERDICT COMES BACKSHEET 03 3B FENNEC Graded. ADMISSION AUTHORITY BUDGET SETTLEMENT FOUR VERDICTS, EVERY TIME THE VERDICT IS THE SIGNAL

Verifier-trained. The runtime's own gates — admission, authority, budget, settlement — are the training signal. Nothing here is graded on how the sentence read.

[04] The authority

It does not hold its own keys.

A model that can be talked into an action holds the authority for that action. This one holds none. What it may do is a capability lease — scoped, time-bound, issued elsewhere — and the lease is enforced inside the runtime's transaction, not inside the model.

External authority. Capability leases enforced in the runtime's transaction. The consequence is the useful part: persuading the model does not move the boundary, because the boundary was never inside it to move.

FIG. 04 · WHERE THE AUTHORITY IS KEPTSHEET 04 04 THE AUTHORITY IS NOT IN THE MODEL THE MODEL NO STANDING AUTHORITY ASKS THE ACT CAPABILITYSCOPED · TIME-BOUND ENFORCED ONE TRANSACTION IN THE RUNTIME

[05] Four words for a model

Three of them describe. One of them binds.

The names the field already has all answer the same kind of question: how wide, how big, how skilled. A fourth kind of question is possible — not what a model can do, but what it is held to — and that is the only question whose answer another party can check.

FIG. 05 · FOUR WORDS FOR A MODELSHEET 05 05 LLM SLM LAM ALM DESCRIBES SMALLDESCRIBES DESCRIBES BINDS THESE DESCRIBE THE MODEL THIS BINDS IT
  1. LLMdescribes generality.How wide
  2. SLMdescribes a size.How big
  3. LAMdescribes a skill.How able
  4. ALMdescribes an obligation.What it is held to

[06] The membership test

A class is only a class if you can be thrown out of it.

The four criteria below are not adjectives. Each one is a station on a bench, and each station is something a third party can set up without asking permission: put a model on the rail, run it past all four, read the verdicts off. Anything that fails a station is not in the class — this one included, if it ever stops passing.

Fig. 06-A · the benchFour stations, one rail, and no opinion anywhere in it.
FIG. 06-A · THE BENCHSHEET 06 6A CONTRACT IN? TYPED OUT? TRAINED BY? AUTHORITY? ANY THIRD PARTY CAN RUN THIS BENCH
Fig. 06-B · one probe, read offThe needle does not care what the model says about itself.
FIG. 06-B · ONE PROBE, READ OFFSHEET 06 6B DESCRIBES BINDS THE READING READING · SPECIMEN CONTRACT INPUTPASS TYPED OUTPUTPASS VERIFIER-TRAINEDPASS EXTERNAL AUTHORITYPASS
  1. 01 · Contract input

    Its only input is a compiled context contract — budgeted and provenance-carrying, never a raw prompt.

  2. 02 · Typed output

    Protocol messages under constrained decoding — never free prose as action.

  3. 03 · Verifier-trained

    The runtime's own gates — admission, authority, budget, settlement — are the training signal.

  4. 04 · External authority

    Capability leases enforced in the runtime's transaction — not in the weights, and not in the prompt.

[07] The prior art

The phrase was in the air. The definition was not.

Four letters are not an invention, and this is the register of everyone who reached for them first — including two fields that have used them for decades and have nothing to do with machine learning.

  1. 01 Maurya & Maurya, “Agentic Language Model (ALM)”IRE Journals · April 2026 Uses the exact phrase, and uses it first. It names a task-execution framework — not a model class, and not a membership criterion.
  2. 02 Mialon et al., “Augmented Language Models”arXiv:2302.07842 · 2023 The survey that mapped the territory of models with tools, reasoning and external calls. Different letters, same neighbourhood.
  3. 03 Acikgoz et al., CoALMACL 2025 A conversational agentic language model, published and peer-reviewed. Closest work by name; a model, not a class definition.
  4. 04 Outside machine learningApplication Lifecycle Management · Asset and Liability Management Two established fields have owned the initialism for decades. Neither is going to stop, and neither should have to.

Foxora did not coin the phrase and does not claim to have. What Foxora claims is the first formal definition — a model class whose membership criterion is the governance contract its members operate under, with criteria a third party can test — and a first instance.

That is a claim of the kind that can be taken away. Write down four criteria, hand them to someone who does not work here, and let them run the bench. First by test, not by assertion.

FIRST BY TESTnot by assertion

[08] The name

Fennec, the smallest fox.

Agentic Language Models are naturally small — most of what a large model carries is there to hold up a conversation, and this one does not have conversations. But small is a consequence of the class, never its definition. A very large model that met all four criteria would be an ALM. A tiny one that met none of them would not.

FIG. 07 · THE SMALLEST FOXSHEET 08 07 The smallest fox. 01 02 03 NEITHER IS BOUND UNDER CONTRACT

Small by nature · not defined by size

[09] Where it stands

Built and ready. Not released.

FIG. 08 · SEALED, NOT SHIPPEDSHEET 09 08 SEALED ON THE DOCK · GATE STILL DOWN READYBUILT AND READY PUBLIC RELEASE NOT YET RELEASE HAS NOT HAPPENED
  1. The modelBuilt · ready
  2. Public release[has not happened]
  3. Weights[not published]
  4. Benchmarks[none published]
  5. The protocol it was trained againstGRIP · draft
  6. The runtime it was trained insideOpen source · pre-1.0
  7. WaitlistOpen

There is no number on this sheet you can put in a slide, and that is deliberate: every figure that would go there is a figure about a thing nobody outside this building has run yet. What there is instead is a definition, four criteria, a bench anyone can build, and a model waiting behind a gate that has not gone up.

Ready · awaiting release · waitlist open