Life Atlas — Research

The Quantum City

Self-Healing Networks, Interoperable Digital Twins, and the Architecture Decisions That Reverb With Eternity

Published Jul 8, 2026Nicolas WaernWINNIIO ABLinkedInORCID: 0009-0001-4011-8201DOI10.5281/zenodo.21258104
CC-BY 4.0Open Access

Abstract

Kyiv proved the axis is not cloud versus on-premise but reachability under partition. No data should depend on one reachable place.

title: "The Quantum City: Self-Healing Networks, Interoperable Digital Twins, and the Architecture Decisions That Reverb With Eternity" author: "Nicolas Waern" email: ceo@winniio.io keywords: quantum computing, self-healing networks, resilience, reachability under partition, TM Forum autonomous networks, digital twin, post-quantum cryptography, Open RAN, SMILE methodology, minimal interoperability mechanisms, world action models, gaussian splatting, spatial web, edge-native architecture status: ready date: 2026-07-08 version: 4.0

The Quantum City: Self-Healing Networks, Interoperable Digital Twins, and the Architecture Decisions That Reverb With Eternity

Nicolas Waern WINNIIO AB / Life Atlas ORCID: 0009-0001-4011-8201

Corresponding author: ceo@winniio.io

License: CC-BY-4.0

Version 4.0 — 8 July 2026. This revision supersedes earlier versions in the same Zenodo record.

Abstract

Infrastructure commissioned today will operate for decades, yet the systems that observe and protect it — dashboards, data lakes, cryptography — are refreshed on far shorter cycles, and organizations increasingly trust the readout over the reality it represents. This paper argues that reality must be treated as the primary, perpetually-recorded, boundary-spanning construct across the operators, cities, and services that share it, and that the decisions determining whether its recording is sovereign, explainable, and quantum-safe are being made now. Drawing on the wartime resilience of Ukraine's networks, it reframes the central design question away from cloud versus on-premise toward reachability under partition: no data or control loop should depend on a single reachable location. The empirical anchor is an Open RAN self-healing case from a dense-urban Tokyo cluster (75 cells; 12,819,049 handover attempts), in which closed-loop Cell Individual Offset tuning lifted problem-cell handover success from approximately 84% to approximately 92%. The paper specifies its method through SMILE (Sustainable Methodology for Interoperable Lifecycle Enablement) and maps self-healing to the TM Forum Autonomous Networks levels; models the operator economics of ARPU and churn; examines resilience through capturing tacit human skill as robots offset workforce shortages; traces the reality-capture stack from Gaussian splatting through world-action models, the spatial web, and sovereign identity; treats post-quantum cryptography as archival ethics; positions Minimal Interoperability Mechanisms as constitutional infrastructure; and closes with a practitioner action set. A single falsifiable criterion — the partition test — governs throughout: a system that cannot keep reality readable when its network and power are lost was never sovereign. Every factual claim carries an explicit evidence tier.

1. The Readout Is Not the Reality

A long-standing question in geography asks which was the largest island in the world before Greenland was charted. Australia is a continent and does not qualify; the intuitive answers, New Guinea or Borneo, are wrong. The answer is Greenland, and it was always Greenland. The island did not shrink because no one had mapped it, nor did it expand to its true size the day a cartographer first inked its coastline. Its physical reality never depended on the map.

The instructive point concerns the map rather than the island. The Mercator projection, standard on classroom walls for generations, renders Greenland as comparable in width to Africa, although Africa is roughly fourteen times larger. The projection stretches the high latitudes to preserve straight rhumb lines for navigation, and in doing so it distorts relative area. The instrument distorts; the land does not move. Greenland is exactly as large as it has always been; only the device used to observe it is in error. The distortion resides entirely in the readout, never in the reality it represents.

The same principle appears in modern physics. Einstein (1905) showed that two observers in relative motion, one on a platform and one on a passing train, legitimately read different elapsed times on their clocks and different lengths on their rulers. They disagree about duration and distance, but they do not disagree about what occurred. A given event happens once; a lightning strike occurs where and when it occurs. The two observers apply different instruments, and their instruments return different numbers. Einstein (1916) later extended the argument to gravitation and to the geometry of space itself. Measured quantities are frame-dependent; the underlying event is not. Readings differ, but reality is single.

This is the paper's thesis: the readout is not the reality. Trusting the dashboard over the process it measures, the data lake over the water it models, or the digital twin over the machine it mirrors constitutes the same error as believing Greenland to be the size Mercator draws it. It is an inversion in which the instruments of observation come to outrank the observed, and in which the map is corrected in preference to inspecting the terrain. At civilizational scale this inversion is not merely a philosophical curiosity. It is expensive and, increasingly, dangerous.

Ukraine's wartime networks provide a documented test of these stakes. When Russia's invasion began in February 2022, telecommunications engineers confronted a scenario that Western network planners had long treated as unthinkable: sustained physical destruction, cyberattack, and grid collapse occurring simultaneously and indefinitely. Ukrainian operators established national roaming within roughly a week, so that a subscriber whose home network was destroyed could connect to whichever competitor's radio still carried a signal. As Russian strikes degraded the power grid through late 2022, telecom sites withstood an estimated 65% loss of grid power on batteries, generators, and improvisation, and the network remained reachable (ITU, 2023). The state had anticipated the requirement: an emergency law passed in the invasion's opening days removed the obligation that government data reside on servers within national borders, and Ukraine dispersed its institutional record to cloud infrastructure beyond the reach of any single missile (Government of Ukraine, 2022). The record of the state was decoupled from any one place in which it could be destroyed. Two figures anchor the case, an estimated 65% grid-power loss withstood and national roaming within a week, and later chapters draw on them by name.

The adversary understood the target precisely. In December 2023, the Sandworm unit executed a wiper attack on Kyivstar, Ukraine's largest operator, corrupting core systems and severing service for roughly 24 million subscribers (CERT-UA, 2023). That event refutes a common assumption: cloud residency is not inherently safe, because a sufficiently determined attacker who reaches the control plane can erase what resides there as thoroughly as any munition. The widely praised satellite workaround carried a corresponding caution. Starlink maintained connectivity where terrestrial systems failed, but a capability that depends on one vendor's cooperation and one founder's disposition is a single point of failure presented as resilience.

Reduced to its engineering content, the Ukrainian case reframes the debate. The salient question is not cloud versus on-premises, which is a distortion of its own. Both a cloud region and a local server are single places, and any single place can be isolated, destroyed, or wiped. The relevant axis is reachability under partition: when the network fragments and the power fails, can the people who require the readable model of reality still reach it? The design principle that follows is deliberately plain and carries through every chapter: no data should depend on one reachable place.

The contribution this paper defends is a single proposition. Reality is the primary, perpetually recorded, boundary-spanning construct, and the architectural decisions that make its recording sovereign, explainable, and quantum-safe are being fixed now. The twin is not the machine and the dashboard is not the network, but the recording of reality, engineered to survive partition, to explain itself, and to resist foreseeable cryptographic threats, becomes the one artifact an institution can trust when its instruments disagree.

A claim that cannot be broken is a matter of faith rather than engineering, so the argument commits to a single falsifier applied without exception. The partition test asks whether the readable model of reality survives the simultaneous loss of network and power. If it does not, the architecture has failed, however elegant its dashboard. Each design choice in the following chapters earns its place by passing that test or is discarded.

The argument proceeds in four movements: the full cost of the inversion, which runs deeper than any single war zone reveals; what becomes possible when reality itself is engineered to persist for fifty years; the economics of doing so; and the concrete decisions worth making now. Greenland was always the largest island. The open question is whether the instruments used to observe our infrastructure are honest enough to admit as much.

2. Why Today's Infrastructure Cannot Hold

The dangerous property of the systems most operators run today is that they work. The lights stay on, the dashboards remain green, and the quarterly accounts close. That reliability is precisely the problem, because an infrastructure can be profitable, audited, and fully staffed while resting on foundations that cannot survive a serious shock. The failure mode is not that present arrangements fail conspicuously; it is that they succeed quietly until they do not.

The first structural weakness is that critical decisions are made on artifacts rather than on reality, and the spreadsheet remains the dominant such artifact. This is not a strawman. Operations, capacity planning, and reconciliation across telecommunications and utilities remain spreadsheet-mediated, and the error literature is unambiguous: careful audits find that the large majority of operational spreadsheets contain errors, with cell error rates of roughly 1 to 5% and error incidence rising with sheet size (Panko, 2008). A model that is wrong in one cell out of fifty is not a model of reality but a curve fitted to whatever survived the last copy-and-paste operation. When such an artifact becomes the source of truth for spares inventory or feeder loading, the organization is navigating by a chart it knows to be inaccurate and declines to redraw.

The problem intensifies when the underlying data is incomplete. Planning routinely proceeds on partial records reconciled with nonseasonal assumptions: annualized averages substituted for demand that is strongly seasonal, and sensor gaps interpolated as though the missing intervals resembled the observed ones. This is statistics in the oldest sense, fitting a smooth curve to a fixed past and extrapolating it forward as if the future were obliged to comply. It is the opposite of what a live system requires, which is simulation on an emulated present-state model, a twin that reflects the plant as it currently is and then runs scenarios forward. The distinction separates explaining yesterday from surviving tomorrow. An operator able only to describe the past has, in effect, selected the Mercator projection: a readout that is internally consistent and comprehensively wrong about proportion.

These errors do not remain small; they compound. A mistaken assumption embedded in a fifty-year procurement decision does not incur its cost once but accrues it every year the asset remains in service. A data gap in 2026 becomes a stranded architecture in 2046. The compounding is architectural as well as economic, which leads to the second structural problem: where data must go to be processed.

Data that must be relocated to be understood is data already at risk. The dominant pattern remains centripetal, with readings streaming from the edge to a distant cloud to be aggregated, modeled, and decrypted for use. Two failure modes are latent in that convenience. The first is confidentiality over time. Encryption that protects a transmission today does not protect it against an adversary who records the ciphertext now and decrypts it later, once a cryptographically relevant quantum computer exists; this harvest-now, decrypt-later exposure motivated the standardization of post-quantum algorithms (National Institute of Standards and Technology [NIST], 2024). For infrastructure telemetry, grid topologies, and subscriber records with multi-decade sensitivity, a message intercepted in 2026 is a message potentially readable in 2036. The second failure mode is availability, and it is the one this paper's falsifier addresses: if a model of reality can be read only after the data has traveled to a place, then losing the path to that place means losing the ability to observe reality at all.

A small, concrete case illustrates the second failure mode. During a power outage at the Vöfab district-heating deployment in Växjö, the on-site control layer lost both grid power and its uplink simultaneously. The plant itself was unaffected; the physical reality of pipes, water, and heat persisted exactly as before. The readable model of that reality, however, went dark, because the model resided somewhere the operator could no longer reach. Nothing about the heat changed, only the ability to observe it. This is the partition test in miniature, and it is instructive precisely because it is undramatic: no war and no cyberattack, merely a routine outage exposing an architecture that had quietly made reality contingent on reachability.

The stakes scale far beyond one heating plant. When the partition is national rather than local, the same architecture fails at civilizational scale. Ukraine's telecom sector remained reachable through the grid-power loss and national-roaming events of Chapter 1 precisely because reachability had been engineered not to depend on any single place. The counter-lessons are equally instructive: the Kyivstar wipe demonstrated that cloud residency is not equivalent to safety, and heavy reliance on a single satellite vendor created its own single point of failure. The generalization is clean, no data should depend on one reachable place, and it indicts the centripetal default directly.

The fourth problem is governance designed for paper. Even where the technology is sound, the operating model often is not. Sidewalk Toronto is the cautionary case: an ambitious, data-rich urban project whose governance and data-stewardship questions could not be resolved, and which was wound down in 2020 (Sidewalk Labs, 2020). The failure was not sensors or software but the absence of a credible, explainable, sovereign answer to who controls the recording of reality and on what terms. Governance conceived as a static document, signed once, filed, and unread, cannot govern a system that records continuously for decades. Standards bodies have begun to encode the alternative: autonomous-network maturity is now framed as a graded capability ladder rather than a binary (TM Forum, n.d.), which at least gives operators an honest means of stating where they actually stand.

Taken together, these four weaknesses, artifacts in place of reality, gaps patched with static statistics, data that must be relocated to be understood, and governance written for paper, do not constitute a set of independent defects to be patched. They constitute a single misplaced trust: trust in the readout over the reality it indicates. The present arrangement holds only as long as nothing tests it. The remainder of this paper concerns building the system that survives the test, and the fact that the decisions determining whether it does are being fixed now rather than later.

3. Reality Under Duress: Wildfires, Hurricanes, Earthquakes

Physical measurement routinely survives disaster while access to the measurement does not. On September 27, 2024, the rain gauge on the roof of the National Centers for Environmental Information in Asheville, North Carolina, continued to record. It measured the water that was, at that moment, cutting the building off from the nation it served. Hurricane Helene had transformed the French Broad River into a destructive force; the campus that houses the largest archive of the planet's climate record sat dark, its staff evacuated and its fiber severed. The instrument still read reality correctly. No one could reach the reading. The problem is exactly this separation: the measurement survived and access to it did not.

This pattern recurs across recent disasters, and it is the pattern the previous chapter's thesis predicts. When infrastructure meets duress, the network and the data tend to fail together, and restoration crews then work blind, rebuilding a reality they can no longer read. What has changed is not the pattern but its incidence. The events that expose it were once tail risks; they are becoming operating conditions, driven by threat classes that arrive more often and cascade more widely than infrastructure planning assumed.

The frequency signal is now unambiguous in the loss record. The NOAA National Centers for Environmental Information counted 27 separate billion-dollar weather and climate disasters in the United States in 2024, against a 1980-2023 annual average of roughly nine (NOAA NCEI, 2025). The interval statistic states the shift most plainly: the mean time between billion-dollar disasters has fallen from 82 days in the 1980s to 12 days in recent years (NOAA NCEI, 2025). Reinsurers confirm the trend from the balance-sheet side. Swiss Re Institute (2025) placed 2024 insured natural-catastrophe losses near $137 billion, the fifth consecutive year above $100 billion; Munich Re (2025) recorded comparable insured losses near $140 billion against economic losses near $318 billion, with weather accounting for 93% of the total. A system designed for one such event per season and repaired at leisure is being asked to absorb one every twelve days. Under that cadence, degraded operation ceases to be an exception state and becomes the state the architecture must hold by default.

Two mechanisms turn rising frequency into rising fragility. The first is the cascade: the tendency of a single physical failure to propagate across otherwise independent systems. Analysis of extreme rainfall and typhoon impacts finds that infrastructure networks shift nonlinearly under sufficient stress, moving from localized faults to system-wide collapse, with power failure the dominant multi-system trigger (Zhai et al., 2025). Winter Storm Uri supplies the concrete anatomy. When Texas gas supply, electricity generation, and water treatment failed in sequence in February 2021, roughly 10 million people lost electricity and 49% of affected residents lost water service, because the pumps and treatment plants depended on the grid that had just gone down (Busby et al., 2021). Power is not one utility among several; it is the substrate the others silently assume. When it fails, it does not fail alone, and the network that would report the failure fails with it.

The second mechanism is a distinct and escalating threat class that most terrestrial planning omits entirely: solar and geomagnetic storms. In May 2024 the NOAA Space Weather Prediction Center (2024) recorded the "Gannon" storm, the first G5 (extreme) geomagnetic event in more than two decades, bringing power-grid irregularities and widespread degradation of GPS and high-frequency radio. The positioning effect was not marginal: high-accuracy GPS and precise-point-positioning services degraded across the mid-latitudes, out to roughly 49 degrees north and 48 degrees south, for 15 to 20 hours (Yang et al., 2025). This matters far beyond navigation, because the same GPS signal is the hidden clock of the telecommunications network. GPS is the primary and often sole source of positioning, navigation, and timing for telecom, banking, and internet infrastructure, a single-point dependency tracked as critical (CISA, n.d.). The dependency is exact and unforgiving: 5G networks require timing accuracy on the order of 240 nanoseconds, and that accuracy is sourced from GPS (NIST, 2023). A geomagnetic storm therefore attacks the network on two axes at once, degrading the timing signal that keeps base stations synchronized while inducing currents in the grid that powers them. The upper bound is severe: one preprint modeling a Carrington-scale event on the U.S. high-voltage transmission network estimates transformer failure losses on the order of $1.37 to $2.09 billion per day, a figure to be read as an unreviewed projection rather than an established result (arXiv, 2026). Even discounted, it names a failure mode in which grid and timing collapse simultaneously and continentally, precisely the joint loss the sovereign edge must survive.

These drivers are not hypothetical futures. In early July 2026, storms and floods across China displaced more than 48,000 people, breached dams, and overwhelmed flood infrastructure under rainfall reported at roughly twice normal levels, driven by Typhoon Maysak compounded by convective storms (Euronews, 2026). The account is drawn from news reporting rather than a settled record, but its shape is the now-familiar one: physical water arriving faster than the systems built to measure it can respond, with power and communications among the first casualties.

Against that backdrop the three anchor cases isolate the failure axes cleanly. Helene isolates the network path. At the storm's peak the U.S. Federal Communications Commission recorded that 48.7% of cell sites across the disaster area were out of service (FCC, 2024). The instructive detail is not the headline figure but its cause. Comparatively few sites were physically destroyed; most went dark because the backhaul, the fiber and microwave links carrying traffic from the tower to the core, was severed, or because generators exhausted their fuel before roads reopened (FCC, 2024). A cell can be structurally intact, powered, and useless, because the single path connecting it to a distant core lies under a landslide. Meanwhile the NOAA Asheville archive, decades of irreplaceable observational record, was imperiled not by data corruption but by loss of physical reachability to the facility (NOAA, 2024). The reading was intact; the route to the reading was gone.

The forward design follows directly. A sovereign edge does not treat the backhaul link as a precondition for function. It caches the readable model of its own portion of reality locally, serves that model to whoever is physically near, and reconciles upstream when a path returns, any path rather than the path. Under this design, a tower cut off from its core still answers the emergency responder standing beneath it, and the local twin of the network's own state, which cells are live, which neighbors are reachable, and what capacity remains, is legible on site rather than inferred from a distant dashboard that has itself gone dark.

The Iberian blackout isolates the power axis. On April 28, 2025, the Iberian Peninsula lost roughly 15 gigawatts of generation in approximately five seconds, and Spain and Portugal went dark in a near-total grid collapse (Red Eléctrica de España, 2025). This was not water or wind acting on physical plant; it was the electrical substrate itself disappearing while towers, fiber, and data centers stood physically undamaged. Mobile networks degraded as battery reserves drained and diesel was consumed, a clean demonstration that the relevant failure axis is not whether the equipment is intact but whether a node can function without the two things a disaster removes first, grid power and the distant core. Everything was built and undamaged, and it still stopped, because it was architecturally dependent on a supply that a five-second fault erased, the same single-point dependency the cascade literature identifies and a geomagnetic storm would trigger at scale.

The degraded-mode response is a rehearsed rather than improvised descent through capability tiers: full service, then local-cache-only service on battery, then a minimal always-reachable state layer that survives on the smallest feasible power envelope. The distinguishing word is rehearsed. A failover path that has never been exercised is a hypothesis, not a capability, a point this paper treats as a design discipline.

Hurricane Melissa's 2025 impact on Jamaica subjected the newest resilience approach to its first genuine test: Starlink Direct-to-Cell, satellite-to-standard-phone service intended to keep handsets connected when terrestrial towers fail. It functioned as a stopgap and it exposed a structural trap. Restoring reachability by routing an entire nation's fallback through one operator's constellation replaces a distributed dependency with a single one (ITU, 2025). This is the lesson of the Kyiv case observed from the opposite direction: Ukraine's wartime reliance on Starlink created a single-vendor point of failure even as it delivered genuine connectivity (Chapter 1). A satellite constellation is also GPS-disciplined and space-weather-exposed, which means the very geomagnetic event that darkens the grid can degrade the fallback meant to survive it. Direct-to-cell is a valuable layer. Treated as the layer, it recreates the fragility it was procured to remove.

The forward design does not reject satellite failover; it declines to make satellite failover sovereign over the local truth. The edge node continues to function and keeps its reality readable whether the return path is fiber, microwave, one satellite constellation, a second, or a mesh link to the adjacent node. Failover is plural by construction, and the local model remains authoritative until an upstream path, any of several, is re-established.

Across wildfire, hurricane, earthquake, cascade, and solar storm, the cases reduce to one question, the falsifier named in the introduction. The partition test asks whether the readable model of reality survives the simultaneous loss of network and power at the node. It does not ask whether a backup exists in the cloud, because Helene's severed backhaul and Iberia's vanished grid both sit between the node and any cloud. It does not ask whether a satellite exists, because Jamaica showed that this outsources the answer to one vendor, and a geomagnetic storm can strike vendor and grid together. The test is local and binary. If a responder standing at a dark tower, holding a phone with no signal and a failing battery, can still read the true present state of the reality that tower observes, the node passes. If that state resided only in a data center now unreachable, or only in a dashboard now unpowered, the node fails, and every crew downstream restores blind.

Stated as a procurement-grade requirement rather than an aspiration: every node must hold, locally and on minimal power, a model of its own reality that remains readable and reconcilable when both its network path and its grid supply are gone, and this survival must be rehearsed rather than assumed. Helene shows that the network path fails first; Iberia shows that the power path fails most cleanly; Uri shows that power drags water and every grid-dependent system down with it; the Gannon storm shows that grid and timing can fail together across a continent; Melissa shows that a single restoration vendor is not a substitute for local survival. Rising frequency removes the last comfort, that such conditions are rare enough to handle by exception. The archive on the Asheville roof recorded the flood correctly throughout. The architectural failure was never in the instrument. It was in the decision to make the reading reachable from only one place, the decision the following chapters show we remain free, for a narrowing window, to make differently.

4. The Method: Reality Engineering with SMILE

Every argument in this paper relies on a single analytic method, and intellectual honesty requires naming it before applying it. The method is SMILE, the Sustainable Methodology for Interoperable Lifecycle Enablement (Waern, 2026, DOI 10.5281/zenodo.19646240). A network built to stand for fifty years is not a technology problem that resolves at commissioning but a lifecycle problem whose hardest requirement is that each generation of equipment, each standard, each operator, and each successor system be able to read and act on what preceded it. That capacity is interoperable lifecycle enablement: the ability of a reality-recording to remain legible and actionable across vendors, decades, and crises. It is the correct lens precisely because the failure mode of long-lived infrastructure is never a single component but the silent loss of the ability to interpret one's own past.

This paper's inquiry logic is Rackham's SPIN — Situation, Problem, Implication, Need — a discovery framework built to surface a need the reader has not yet articulated. In this paper, SPIN refers only to Rackham's four-stage questioning sequence; it denotes nothing spatial and no "twinning" construct. Applied here, SPIN establishes the reader's Situation (they operate infrastructure whose reality-recording is assumed, not engineered), exposes the Problem (the recording depends on a single reachable place), draws out the Implication (the compounding fifty-year cost of that dependency), and crystallizes the Need (a sovereign, explainable, quantum-safe recording of reality). It is named once here and used deliberately thereafter.

4.1 AEST: temporal operations at an anchor

SMILE treats any chosen point in reality, a building, a radio cell, or a plant, as an anchor at which four temporal operations become available. Absorb the past: ingest institutional memory and the historical record. Emulate the living present: maintain a present-state twin calibrated to physical measurement. Simulate forward: test interventions in scenario space before committing physical resources. Transcend: define a desired sustainable future state and reverse-engineer the path from it back to present action, which is structured reverse causation from a target rather than speculation (Waern, 2026).

The Rakuten Shibuya Open RAN case (Chapter 5) makes AEST concrete. Absorb: the cluster's handover history constitutes the institutional memory. Emulate: the live twin tracks per-neighbor-relation KPIs, exposing the relations performing below the fleet. Simulate: candidate Cell Individual Offset (CIO) adjustments are tested against the emulated topology before any parameter reaches a live cell. Transcend: the target success rate defines the goal, and the CIO path back to it is computed. The full result set appears once in §5.1 to §5.2. The method is not to collect data and hope; it moves from a defined future state backward to the action that reaches it.

4.2 NUDEDA: an infrastructure-maturity ladder

NUDEDA is an infrastructure-maturity ladder that extends Weill and Broadbent's (1998) four infrastructure postures, None, Utility, Dependent, and Enabler, with two further stages for the age of AI: Digital DNA, in which the infrastructure becomes ontology-aware, and Autonomous, in which autonomous operations and the digital operating models and digital business models they support allow organizations to outcompete. The full ladder, in order, is None, Utility, Dependent, Enabler, Digital DNA, Autonomous. Under Weill and Broadbent (1998), None denotes the absence of shared infrastructure, Utility denotes cost-driven commodity provision, Dependent denotes infrastructure justified by specific current business plans, and Enabler denotes infrastructure that creates future strategic options beyond present requirements. The two additional stages describe capabilities that the original framework, written before contemporary AI, could not anticipate: an ontology-aware recording of reality, and an infrastructure through which operations and business models themselves become autonomous. Placing a deployment on this ladder gives an operator an honest account of where its infrastructure actually stands rather than where a brochure places it, and it names the destination this paper argues for, an ontology-aware, ultimately autonomous recording of reality.

4.3 Six phases ending in Perpetual Wisdom

SMILE is phase-sequential and concentric; later phases add capability without discarding earlier layers. The phases run from Reality Emulation, which establishes the shared referent, through concurrent engineering of a minimal viable twin, ontology and interoperability grounding, real-time connected operation, and edge-native autonomous intelligence, to Phase 6, Perpetual Wisdom. Phase 6 is load-bearing for this paper's thesis: knowledge persists beyond project closure through perpetual reality recording. The recording does not end when a deployment does; it becomes the baseline from which the next deployment begins. This is why the falsifier of the whole paper, the partition test, is a Phase 6 property: a reality-recording that cannot survive the loss of network and power was never perpetual to begin with.

4.4 Four perspectives

Each phase is worked from four simultaneous perspectives that function as quality gates rather than planning silos. From People: stakeholder enrolment, concurrent engineering, and human-machine interaction. From Systems: standards, ontology alignment, and interoperability mechanisms. From Planet: spatial-temporal grounding, environmental context, and circular and ESG constraints. From AI: model selection, explainability, edge inference, and trust-boundary definition, with AI treated as an actant that transforms the network it joins (Callon, 1986) rather than a tool subordinate to Systems.

4.5 The Crucible trust layer

Governing every AI output in SMILE is the Crucible trust layer, which prioritizes retrieval over generation and explainability by design. When accuracy matters, the twin retrieves the measured value rather than generating a plausible one. The layer enforces provenance at the data level, with every point carrying source, timestamp, confidence, and validation status; source attribution at the inference level, with every output traceable to the graph entries that produced it; and explainability at the decision level, so that a domain expert can read the causal chain and override it. An output that cannot be explained in domain language has not passed the gate, regardless of its statistical accuracy (Arrieta et al., 2020). For physically governed systems, this favors Large Quantitative Models, physics-based simulation with explicit uncertainty, over statistical pattern-matching, and these are reducible to Small Quantitative Models for millisecond edge inference (Waern, 2026).

4.6 Five theoretical pillars

SMILE rests on five established foundations, situating it within the Gothenburg School Five Model lineage (Magoulas & Pessi, 1998): Design Science Research, treating the methodology as a constructed, evaluable artifact (Hevner et al., 2004); Actor-Network Theory, treating the twin as an obligatory passage point (Callon, 1986; Latour, 2005); boundary object theory, in which one referent serves many communities without forced consensus (Star & Griesemer, 1989); absorptive capacity, describing path-dependent knowledge accumulation (Cohen & Levinthal, 1990); and benefits management, in which benefits are actively delivered rather than assumed automatic (Ward & Daniel, 2006). The through-line is a single thesis: reality itself, physically measured and digitally rendered, is the boundary-spanning object, the shared representation through which people, systems, and AI coordinate. Not a model of reality, but reality recorded.

4.7 The honest circularity, and the paper's own method

Two disclosures close this chapter. First, a circularity: SMILE is both the author's method and an artifact under evaluation here. The RAN case tests the network thesis; it does not independently validate SMILE, whose broader claims remain design-science propositions pending multi-site confirmation (Hevner et al., 2004). This is stated plainly rather than smoothed over.

Second, the paper's overall method is evidence synthesis anchored to one primary empirical case, the Rakuten Shibuya Open RAN deployment, triangulated against documented resilience events in Kyiv, Hurricane Helene, and the Iberian blackout. Throughout, the text distinguishes what has been observed in a production system from what has been shown in a controlled or pilot setting, from what is a modeled forward estimate, from what remains a stated design goal not yet met. The reader is entitled to know, at every claim, which of these is being asserted and on what basis. That discipline is the method's answer to its own circularity: the argument earns trust by marking its seams rather than concealing them.

5. Self-Healing Networks: Primary Evidence

An edge node that retains its own state through a power cut demonstrates local survival, but it does not demonstrate the harder claim: that a network can detect its own degradation and correct it before a human intervenes. Degradation is subtler than disaster. The towers remain lit, the dashboard remains green, and yet somewhere in the mesh of neighbor relations a small number of cells are handing moving users to the wrong tower, dropping calls one at a time in a pattern that no aggregate KPI surfaces until the churn report arrives a quarter later. This chapter closes that gap with measured numbers rather than architectural rhetoric. It is the empirical spine of the paper's falsifiable claim.

A reproducibility caveat belongs at the outset. The dataset analyzed here is proprietary WINNIIO, Altiostar, and Rakuten data, and no third party can currently reproduce these numbers. The raw handover counters are production data; the handover-outcome classification carries a synthetic-mobility watermark (see §5.1), so every outcome-derived figure below is a controlled demonstration rather than a directly observed production figure. The single-operator, single-metro, single-KPI-family scope is the central evidence limitation of the entire paper, consolidated again in Chapter 11 but flagged here so that no reader mistakes one dataset for settled science.

5.1 The dataset and its honest baseline

WINNIIO analyzed a production mobility dataset from Rakuten Mobile's dense-urban Shibuya Open RAN cluster, comprising 75 cells and 12,819,049 handover attempts. Overall baseline handover success measured 97.87%. That figure is a warning rather than a reassurance. Well-run dense-urban clusters typically operate at 98.5 to 99.5%, so 97.87% is a soft baseline, high enough to appear healthy on a summary tile yet low enough that an attentive operator would already be asking questions. Six cells breached the problem threshold, with handover failure above 5% and ping-pong above 2.7%, their local degradation averaged away by the fleet-wide mean. The aggregate was concealing the very failures worth correcting.

Why the handovers failed matters as much as how often. The canonical mobility-robustness taxonomy, too-early, too-late, and wrong-cell (Nguyen & Kwon, 2018), is properly derived from radio-link-failure reports, which this dataset does not carry. From attempt counters and ping-pong timing alone, the classification is heuristic: relations with rapid return handovers are scored as ping-pong or too-early, and relations whose failures concentrate toward a non-serving neighbor are scored as wrong-cell. On that heuristic, wrong-cell handovers account for roughly 72% of failures on otherwise-healthy cells, a labeled inference from counters rather than an RLF-verified split. The direction is the salient point. Wrong-cell dominance is the signature that Cell Individual Offset (CIO), the per-neighbor spatial bias, is the correct lever; too-early or too-late failures would instead point to timing parameters such as time-to-trigger and hysteresis. The diagnosis determines the treatment.

5.2 The intervention, and a footnote that refuses to flatter

The self-healing action was CIO tuning through Mobility Robustness Optimization: shifting the offset on a mistuned neighbor relation by one to two decibels so that the handover boundary moves off the fade cliff at which calls were breaking. Across 22 re-optimized neighbor relations, problem-cell handover success rose from approximately 84% to approximately 92% on the acted relations, a mean improvement of +8.0 percentage points with a maximum of +11.1 points. Two numbers must not be conflated: the approximately 84% and 92% endpoints are the attempt-weighted mean across the acted relations (84 + 8.0 = 92), while +11.1 is the single best-improving relation. This is a closed control loop acting on the operator's own live telemetry. Its direction of travel is consistent with the O-RAN near-real-time RIC literature on real-time A3-threshold and CIO tuning over the E2SM-RC interface, which reports comparable handover-failure reductions (see, e.g., O-RAN ALLIANCE use-case reporting on RIC-based mobility optimization). The mechanistic literature frames CIO as one of the three self-organizing-network pillars (Onireti et al., 2016; Asghar et al., 2018); the contribution here is a measured instance on a nationwide commercial Open RAN rather than a testbed.

One footnote supports the reader's trust in everything above it. Naive reporting would average the success rate across the 22 relations and claim a larger, cleaner improvement. When that unweighted mean-of-rates was reconciled against the attempt-weighted rate, the naive average inflated success by roughly 0.7 to 0.8 percentage points. Small cells with few attempts but near-perfect rates drag the mean upward; weighting by the 12.8 million attempts that actually occurred corrects the distortion. This paper reports the weighted number and names the inflation. An autonomous system that optimizes against a flattering average will confidently repair the wrong thing. The attempts that occurred are the arbiter; the vanity metric is not.

5.3 Where this sits on the autonomy ladder

Mapped to the TM Forum Autonomous Networks framework, this loop is Level 3, conditional autonomy scoped to mobility robustness (TM Forum, 2024a). The system detects the degraded relations, decides the CIO adjustment, and acts, while a human still sets policy and reviews outcomes. Under the IG1230 framework, autonomy is assessed per task across awareness, analysis, decision, and execution within a scoped domain rather than as a single global grade. Human policy-and-review is the defining signature of Level 3. Level 4 would require removing the human from the review loop and demonstrating self-optimization across varying conditions and domains without operator policy intervention. This loop does neither, so it is Level 3 with an explicit Level 4 gap. Candor about that gap is what makes the surrounding claims credible.

The economics reported at Level 4 belong to specific certified use cases and are stated as such. China Mobile reports a reduction of more than 30% in backend O&M manpower and roughly 30% lower fault MTTR in a single certified network-operations-center use case; Telefónica Vivo reports up to 90% efficiency gains in route convergence in a single network-creation use case (TM Forum, 2024a, 2024b), both operator self-claims within single certified use cases. No operator has reached organization-wide Level 4. Rakuten's own nationwide RIC platform targets a 15 to 20% energy reduction via predictive rApps as a design goal (Rakuten Mobile & Rakuten Symphony, 2025a), with a trial reaching up to 25% (Rakuten Mobile & Rakuten Symphony, 2025b). The self-healing MRO in this chapter is the quality analogue of that energy work: the same closed loop, the same Level 3 rung, and a different objective.

5.4 The twin performing all three functions at once

In Grieves' digital-twin terms, the Shibuya twin performs every function on live counters. It replicates the handover state of 75 cells as a continuously updated model of what the radio reality is; it predicts which neighbor relations will fail from the wrong-cell signature before the failures compound; and it navigates the network back toward health by re-issuing CIO offsets (Grieves, 2019). This is not three tools combined but one boundary object, the shared, machine-actionable representation of reality that the RIC, the operations engineer, and the optimization loop all read from and write to in their own vocabularies. It is also SMILE's AEST temporal model operating at a network anchor (Waern, 2026): Absorb the cluster's handover history, Emulate the living present-state of all 75 cells, Simulate the offset change before committing it, and Transcend by reverse-engineering the CIO command that carries the network from its degraded present to the target of near-invisible mobility.

This is what self-healing consists of once the rhetoric is removed and the counters are kept: a soft baseline honestly labeled, a failure mode correctly diagnosed, and twenty-two relations lifted eight points off the fade cliff by a loop that acted on reality rather than on a flattering summary of it, together with a candid ceiling on how far the autonomy actually extends. It is modest in scope and precise in claim, and that precision is exactly why an operator should want it. The next chapter prices this loop; the chapter after that subjects it to the one adversary it has not yet faced, the disaster that removes the power and the backhaul the loop quietly assumes.

6. The Operator Ledger: What Healing Is Worth

Self-healing is easy to admire and hard to fund. A network engineer who raises a handover success rate produces something real, but that value does not appear on a balance sheet until it is translated into the two figures a CFO already tracks every quarter: revenue per subscriber and the cost to retain that subscriber. This chapter performs that translation as a parameterized model with a sensitivity range, rather than a single headline euro figure, so that the reader can rebuild it with their own inputs rather than borrow a fabricated bottom line. The unit of the argument is money, and the discipline is that no number is asserted without a stated source or a stated assumption.

Begin with the pressure the operator actually faces. Average revenue per user (ARPU) in mature markets is flat to declining in real terms while data volumes rise, which means margin is defended on the cost side rather than won on the price side. Against that flat ARPU sits churn, and churn is where healing earns its keep. Dropped calls and failed handovers are among the most reliably churn-correlated experience defects in operator satisfaction studies, because they are the failures a customer experiences mid-conversation rather than reads on a bill. The Shibuya Open RAN case, with the +8.0 pt weighted CIO gain on the worst-served neighbor relations (§5.2), provides a measured mechanism to price, priced on the weighted improvement rather than the flattering mean-of-rates.

The retention model is a formula rather than a point estimate. Let the annual retained-value benefit of the healing behavior be:

Benefit = N_base × f_corridor × churn × r_reduction × (SAC + M_gross)

where N_base is the subscriber base, f_corridor the fraction of subscribers routinely traversing the healed weak boundaries, churn the annual churn rate, r_reduction the relative churn reduction attributable to closing the experience gap, SAC the subscriber acquisition cost avoided per retained subscriber, and M_gross one year of retained gross margin (ARPU × 12 × margin). Every term is a parameter the reader sets. The structure, not any single output, is the contribution.

An illustrative range makes the model tangible, with all inputs declared. Consider a mid-market operator and vary the two most uncertain parameters across a plausible band: N_base = 5,000,000; ARPU = €15/month; gross margin = 60% (so M_gross ≈ €108); SAC = €120; churn = 18%; f_corridor = 1 to 3%; and r_reduction = 10 to 20%. The formula then yields an annual retained-value benefit from this one healing behavior on one corridor of roughly €0.25M to €1.6M, with the midpoint near €0.6M. The width of that band, more than a sixfold spread from two parameters alone, is the honest headline: the mechanism is real and the order of magnitude is defensible, but any single euro figure would be false precision. Scaling the same pattern across a metro network's dozens of weak corridors makes the retention line, rather than a new spectrum auction, the funding case for autonomy.

Cost is the second half of the ledger, and here the lever is energy. The radio access network is the dominant energy consumer in a mobile operator, and energy is a large and rising share of network opex. This is precisely why the first Level 4 autonomous-network deployments target energy: Rakuten operates closed-loop Level 4 RAN-energy optimization, on the same TM Forum L0 to L5 axis on which Telefónica runs Level 4 at portfolio scale and China Mobile runs Level 4 in the NOC. As a parameterized entry: if RAN energy is E annually and closed-loop control trims a fraction s of it, the opex saving is E × s. With E = €90M/year (assuming 10% of service revenue) and s = 8 to 15% (a band within demonstrated traffic-aware RAN-energy results), that is roughly €7M to €14M/year, recurring, with no ARPU risk, plus the labor arbitrage of Level 4 loops replacing manual optimization tickets. Healing therefore appears twice: once as retained revenue and once as avoided cost.

The more interesting entry is the one that does not yet exist: revenue the twin creates rather than protects. A perpetually recorded, explainable network twin turns the network from a cost center into a product surface. Three lines are visible today in demonstrated or standardized form. First, verifiable-SLA slices, network slices whose guarantees are readable, attestable state, sold to enterprises willing to pay a premium for a latency or availability figure they can audit rather than trust, a capability the TMF921 intent standard supports but the market has not yet proven at scale. Second, integrated sensing and communication (ISAC), in which the same radio infrastructure sells sensing-as-a-service, presence, motion, and environmental sensing, a new metered product on installed assets, on standards that remain nascent. Third, enterprise digital twins delivered as a service to venues, campuses, and municipalities that want a live model of their own connectivity fabric. None of these should be oversold: the slice and ISAC standards are ratified but nascent, and revenue is unproven at scale. Yet each is a line the twin makes possible and the legacy OSS makes impossible.

Finally, the asymptote. A 100% handover success rate is not a promise but a limit the architecture can approach without reaching. The path runs through multi-agentic twinning, in which neighbor cells whose twins negotiate a rehearsed handover contract before the subscriber crosses the boundary allow the target cell to reserve the resource and pre-validate the path rather than discovering the request at the moment of need. Each increment of rehearsal buys a fraction of the residual failure rate, with diminishing returns. The operator ledger, then, is not a claim that healing pays for itself immediately. It is a disciplined statement that retained churn, trimmed energy opex, and twin-mediated new ARPU are three quantifiable pools, that the Shibuya +8.0 pt gain (§5.2) is the measured mechanism linking engineering to the first of them, and that the reader can now enter their own numbers into the same formula and read off their own range.

7. Capturing the Skilled Act: Resilience Against the Human Shortage

Tacit expertise is a single-homed asset that today's institutions have no mechanism to preserve. When a master welder retires after forty years, the judgment by which that welder read the color of the puddle and the pitch of the arc to know when the metal was about to run departs with the individual. No sensor recorded it and no document holds it, and the apprentice who follows begins effectively from the start.

This is the partition test applied to people. Chapter 5 asked whether the readable model of a network survives the loss of grid and backhaul. The same question now applies to human expertise: does the skilled act survive the loss of the single human who holds it? At present, overwhelmingly, it does not. The demographics guarantee that the loss is a wave rather than a trickle.

7.1 The shortage is structural, not cyclical

Two well-sourced figures set the scale. In United States manufacturing, an estimated 3.8 million positions must be filled by 2033, of which roughly 1.9 million could go unfilled for lack of the required skills (Deloitte & The Manufacturing Institute, 2024). Healthcare faces a shortfall of approximately 10 million health workers by 2030, concentrated in low- and middle-income countries (World Health Organization, 2022). These two figures establish the trend, and the point does not require stacking every sectoral forecast. Welding illustrates the concentration, with a workforce whose average age is near 55 and which replaces itself slowly against steady demand (American Welding Society, 2024), and construction reports the same constraint, with a majority of firms unable to fill skilled positions (Associated General Contractors of America & NCCER, 2025).

The mechanism beneath these figures is tacit knowledge, the judgment learned in the hands and never written down, which is precisely why it cannot be photocopied or emailed to a successor. Tacit knowledge has been a central construct in the knowledge-management literature since Polanyi (1966) and Nonaka and Takeuchi (1995); the practical estimates that most of an expert's operative knowledge is tacit vary widely by source and method and should be read as directional. A retirement is therefore not a staffing gap that a job posting closes but the deletion of a single-homed node. In SMILE terms, the workforce has no partition tolerance: expertise resides in one reachable person, and the principle that no knowledge should depend on one reachable place applies to human beings exactly as it applies to data centers.

7.2 The skilled act becomes a network asset

The opportunity is concrete: capture the skilled act itself, the contact-rich, judgment-laden motion, before its holder departs, and re-teach it to the novices who follow. Embodied AI now makes this technically credible, and the enabling method is imitation learning, in which robots acquire complex manual skills directly from human demonstration rather than from hand-coded rules. Critically, the frontier has reached contact-rich tasks, the grinding, seating, and seam-following in which force and feel dominate, which recent surveys document as now learnable from demonstration (Tsuji et al., 2026). These are exactly the tacit acts that resisted every prior codification attempt.

The transfer layer is the humanoid foundation model. NVIDIA's Isaac GR00T N1 is an open vision-language-action model trained on real-robot demonstrations, human video, and synthetic data, converting a human demonstration into a transferable robot skill and outperforming prior imitation-learning baselines (NVIDIA, 2025; Zhao et al., 2025, arXiv:2503.14734). The physical substrate to receive those skills exists at scale: the International Federation of Robotics reports an operational stock of industrial robots in the millions of units and rising year over year (International Federation of Robotics, 2025). The bodies are on the floor; the open question is whose knowledge runs on them.

The digital twin is the knowledge-transfer layer that makes the capture durable rather than momentary. Twins standardize and scale knowledge transfer, allowing operators to rehearse changeovers and onboard novices without pausing production. The captured act is not left as a raw motion log; it is deposited into the twin's ontology as a queryable, versioned procedure that survives the demonstrator's departure. This is the SMILE reading made precise: the skilled act is captured across the People and Systems perspectives (§4.4) and persists in Phase 6 Perpetual Wisdom beyond the tenure of any single actor. The AEST operations apply directly: the twin Absorbs the retiring expert's demonstrated history, Emulates the current best-practice procedure as a living present-state model, and lets an apprentice Simulate the act safely before working hot metal.

7.3 Bidirectional: humans teach robots, robots re-teach humans

The value is not one-directional automation. The capture is bidirectional: the master demonstrates, the model absorbs, and the model then re-teaches the next human. Structured robotic-assisted-surgery training programs offer published evidence that the twin-plus-robot combination functions as a staffing-resilience multiplier, expanding what a fixed human team can safely cover rather than replacing the team. The pattern generalizes across skill-dense sectors: in steel, AI predictive-maintenance approaches codify veteran diagnostic knowledge into models precisely as the maintenance cohort that holds that judgment retires; and in precision manufacturing and hospitals alike, the twin becomes the medium through which one remaining expert's judgment reaches many novices at once, the knowledge-transfer role of §7.2 applied to the human act rather than to the physical asset.

7.4 Why the skill model must be a sovereign edge asset

Here the workforce argument rejoins the paper's spine, and the architectural decision is decisive. A captured skill model is the distilled, irreplaceable expertise of a workforce. If that model is locked inside a vendor cloud, the organization has not solved its resilience problem but relocated it, trading dependence on one retiring human for dependence on one reachable vendor and one reachable network. The partition test is unforgiving: a skill model that goes dark when the backhaul drops has failed exactly as the Kyivstar wipe and the Starlink single-vendor point of failure of Chapter 1 failed. A welding-arc model that cannot run on the shop-floor edge when the WAN is down is not resilient knowledge; it is rented knowledge.

The requirement, therefore, is that captured skill models be edge-deployable and sovereign, an organizational asset rather than a leased capability. SMILE's edge-native commitment supports this directly: a Large Quantitative Model of a physical act can be reduced to a Small Quantitative Model that runs on local hardware at millisecond latency (Waern, 2026), so that the skilled act remains executable and re-teachable under partition. This is the standard the Crucible trust layer (§4.5) must enforce on any acquired skill model: retrieval over generation, so that the apprentice is shown the master's recorded, provenance-signed act rather than a plausible fabrication of it, and explainability by design, so that the model can show why the puddle is about to run, in the master's own causal terms, rather than merely mimic the motion.

The future this chapter describes is therefore specific and buildable: the retiring master's four decades do not depart on Friday. They are absorbed into a sovereign twin, they run at the edge when the network does not, and they teach the apprentice thereafter, reachable under partition and owned by the people whose hands first held them.

8. The Reality-Capture Stack: Splats, World Models, and Sovereign Economies

The Ukrainian case established the negative result: when the network partitions and the grid fails, a model that resides in one reachable place fails with that place (Chapter 1). This chapter constructs the positive counterpart. If reality is the primary, perpetually recorded, boundary-spanning construct, then the question for the next fifty years is procedural: how does one capture reality faithfully, fold it into models that predict, address it so that any agent can reach it, and allow the people it describes to own it? Four technology layers now answer that question, each maturing at a different rate and each mappable onto the replicate-predict-navigate arc Grieves gave the digital twin (Chapter 5). This chapter separates the deployed from the aspirational, layer by layer.

8.1 CAPTURE: space made photoreal and addressable

The first layer turns physical space into a dense, queryable record. Kerbl et al. (2023) introduced 3D Gaussian splatting, reconstructing real scenes from ordinary photographs into a representation that renders photorealistically in real time. The advance matters less for its frame rate than for what it captures: not a designer's idealized CAD model of what a building should be, but a measured record of what a place actually is, down to the corrosion, the deflection, and the improvised repair. This is the shared representation rendered at survey fidelity (Chapter 3).

The primitive has already left the laboratory. Bentley Systems integrated splatting into its iTwin reality-modeling pipeline for infrastructure engineering (Bentley Systems, 2024). Commercial capture workflows now compress a site scan to a short 360-degree walkthrough that exports a labeled, simulation-ready twin into robotics simulators (Insta360 & Splatica, 2025). Construction research has coupled splatting to BIM under ISO 19650 coordination standards, and robotics groups build splatting twins precise enough to close the sim-to-real loop for manipulation. For a telecom operator, the implication is concrete: the cell site, the cabinet, and the antenna tilt are no longer a spreadsheet row and a decade-old photograph but a re-capturable spatial record, the substrate a self-healing network needs to reason about its own physical body.

8.2 MODEL: reality folded into prediction

Capture yields a faithful present. The second layer aims to learn the dynamics. A line of recent preprints proposes World Action Models (WAMs), a term reportedly introduced by NVIDIA around early 2026, a provenance this paper cannot independently confirm and flags accordingly. The stated goal is a joint model over future states and the actions that produce them, replacing the classic perception-planning-control pipeline with an end-to-end learned model. One such preprint describes a model of approximately 14 billion parameters reaching, by the preprint's own self-reported figure, roughly 62% task progress and transferring to an unseen robot from about thirty minutes of teleoperation; these figures are the preprint's self-report and are not independently reproduced. A companion survey proposes a taxonomy of cascaded versus joint architectures trained on internet-scale egocentric video. These claims rest on single, non-peer-reviewed, recent preprints and should be read as directional research signals rather than results. By contrast, GR00T N1 (arXiv:2503.14734, §7.2) is a verifiable reference point.

The honest constraint is latency, and it is where the partition test bites. Photorealistic future-imagination is compute-heavy, and compute cost is decisive at the edge. The research direction of interest is distillation, compressing such models toward per-inference latencies compatible with edge power-and-compute budgets, but whether that trajectory delivers is unproven. The architectural point stands regardless: a predictive world model that runs only in one hyperscale region fails the same test the pre-war Ukrainian cloud stack failed.

8.3 ADDRESS and INTEROPERATE: the network layer for reality

Captured, modeled reality is inert unless agents from different vendors, domains, and jurisdictions can reach and read it without a bespoke integration for every pair. Here standards, not products, carry the weight. In 2025 the IEEE ratified P2874, the Spatial Web standard, defining HSML, a shared vocabulary for entities, activities, and relationships, and HSTP, a protocol for permissions and policy across agents, IoT, robotics, and twins (Spatial Web Foundation, 2025). The European Commission's Web 4.0 initiative names this transition at policy level and commits, rhetorically, to open standards over monopoly (European Commission, 2023).

The honesty flag is load-bearing: ratification is not adoption. IEEE 2874-2025 is real and recent, but its deployed footprint is nascent; there is no running spatial web to point to, only a specification and early implementers. HSML and HSTP are best read as the external-addressing complement to the Minimal Interoperability Mechanisms treated in Chapter 10: the MIMs govern the seams a city signs, and HSML gives external agents a shared vocabulary to name the reality a twin represents. Both are standards to build toward rather than capabilities to claim as shipped.

8.4 OWN and TRANSACT: sovereignty as economics

The final layer determines who owns the perpetual record and who is paid when a machine reads it. The durable substrate is the W3C stack: Decentralized Identifiers (DIDs), ratified as a Recommendation in 2022, paired with Verifiable Credentials, enable self-sovereign, cryptographically verifiable identity for people, organizations, devices, and agents (Sporny et al., 2022). The Web5 marketing label sometimes applied to this stack is contested and directional rather than deployed, and this paper disregards it; the substance is DIDs and VCs. Machine-to-machine value-exchange rails, including stablecoin micropayments and blockchain foundations for agent economies, are emerging independently and remain early.

Setting the branding aside, the architecture is coherent with everything preceding it. A DID lets a sovereign individual, or a sovereign community node, hold the identity of a captured place and gate who may query its model. A Verifiable Credential lets a self-healing network prove that an intent came from an authorized operator without a central authority to consult. Micropayment rails let one agent pay another for a slice of reality data at machine speed. This is the principle that no data should depend on one reachable place (Chapter 1) expressed as economics rather than topology: ownership that survives the loss of any single custodian.

8.5 The stack as one argument

The four layers compose into a single claim, tier by tier. CAPTURE (splatting) is deployed. MODEL (WAMs) is early-preprint and unproven at the edge. ADDRESS (IEEE 2874, W3C DIDs) is ratified but nascent, real standards with early adoption. TRANSACT (agent economies) is emerging. No layer is oversold, and the gaps are named. What unites them is direction: each converts a piece of the Ukrainian negative result into positive infrastructure, reality made photoreal, then predictive, then addressable, then ownable. The aim is not any one product but the whole assembled sovereignly: captured close to the edge, modeled within the edge power budget, addressed through open standards, and owned by the people and communities the reality describes. The architectural decisions that fix this are being made now (Chapter 1). Chapter 9 addresses one of them, the cryptographic seed, and Chapter 11 turns the rest into concrete actions.

9. Quantum: Protect Now, Optimize Where It Pays

Quantum computing enters a paper about fifty-year infrastructure in two distinct and real roles, and the discipline is to separate where it already belongs in the architecture today from where deploying it now would be premature. This chapter draws that line plainly. The first role concerns cryptographic survival and is a present obligation; the second concerns optimization and remains, for now, benchmark-gated.

The first role is not speed but survival: post-quantum cryptography as archival ethics. If reality is the primary, perpetually recorded construct (Chapter 1), then the cryptography that protects that recording must outlive the recording itself. One cannot perpetually record reality on cryptography with a ten-year effective life. RSA-2048 and the elliptic-curve suites securing today's telemetry, intent contracts, and twin state have a shelf life measured against an adversary who does not yet exist but is already collecting ciphertext. Harvest-now, decrypt-later is a documented collection strategy, and it turns every long-lived archive into a deferred breach. A NOAA climate record, a RAN configuration history, and a sovereign health twin are each a fifty-year secret encrypted with a ten-year lock.

The response is standardized and shipping. NIST ratified the first post-quantum standards in August 2024: FIPS 203 (ML-KEM, key encapsulation), FIPS 204 (ML-DSA, digital signatures), and FIPS 205 (SLH-DSA, stateless hash-based signatures) (NIST, 2024). The architectural obligation is not to adopt PQC at some future date. It is crypto-agility now, the ability to rotate algorithms without re-platforming, so that the archive layer signs and encrypts with ML-DSA and ML-KEM at the moment of recording, PQC-at-archive rather than PQC-at-retrofit. Retrofitting encryption onto a fifty-year archive after the fact is the same category error as bolting resilience onto a network after the partition (Chapter 4): the cost compounds precisely because the work was deferred. For infrastructure recording reality perpetually, the time to act is the day the first byte is written.

The second role is optimization, and here the discipline must be sharper because the claims are louder. Quantum-inspired and quantum-annealing methods can express a specific class of problems, Quadratic Unconstrained Binary Optimization (QUBO), that maps naturally onto certain network and scheduling tasks. The self-healing RAN work at the empirical core of this paper is a candidate: CIO tuning across a dense neighbor-relation graph, in which each handover boundary is a coupled binary decision, is a combinatorial surface that QUBO can represent. Portfolio scheduling across a multi-vendor estate is another. These are real problem shapes rather than marketing.

Representation, however, is not victory, and this chapter will not soften the point: today, classical MRO wins, and this paper says so. The 22 problem neighbor-relations lifted by the +8.0 pt weighted gain in the Shibuya deployment (§5.2) were tuned by classical optimization. No quantum processor touched that result. A quantum-inspired solver that cannot beat a well-tuned classical solver on wall-clock time, cost, and reproducibility has earned nothing but a footnote. The gate is empirical rather than aspirational: quantum optimization enters production the day it wins a disclosed benchmark against the classical incumbent on the same problem instance, and not before.

What is worth building now, without pretending the future has arrived, is one concrete deliverable: a solver-neutral problem-interchange schema paired with mandatory benchmark disclosure. The schema expresses the optimization problem, the CIO graph, the QUBO formulation, the constraints, and the objective, independently of the engine that solves it, so that a classical heuristic, a quantum-inspired annealer, and a future gate-model processor all consume the same problem statement and return comparable results. The benchmark disclosure is the falsifier attached to every claim: solver identity, wall-clock time, cost, solution quality, and the classical baseline it must beat, published alongside the result. This is Crucible discipline (§4.5) applied to optimization, evidence over assertion. It costs little today and makes every future quantum claim auditable.

The quantum progression gives the sequence, and this chapter is explicit about where each stage sits. Quantum-assisted (QA) and quantum-inspired (QI) optimization are usable now, in the narrow, benchmark-gated cases described above. Quantum-resistant (QR) cryptography is not a future matter at all; FIPS 203, 204, and 205 make it the present obligation of the archive layer. Hybrid quantum-classical compute (HQC) and the quantum network (QN) remain projections, real research trajectories rather than deployable infrastructure. The sequence is not a roadmap of inevitabilities but a ledger with two entries in ink, QR today and QI where it wins, and three in pencil. Protect now, optimize where it pays, and state plainly where it does not.

10. Interoperability as Constitution: MIMs and the Boundary Object

Smart-city interoperability is governed by a deliberately sparse set of binding clauses to which everything else must conform. The Open & Agile Smart Cities profile fixes seven load-bearing clauses, MIM1 Context, MIM2 Data Models, MIM3 Contracts, MIM4 Trust and Personal Data, MIM5 Transparency, MIM6 Security, and MIM7 Places, as the Minimal Interoperability Mechanisms every conformant system must honor (Open & Agile Smart Cities & Living-in.EU Technical Sub-Group, 2024). The word minimal carries the whole design intent: specify the fewest seams at which two systems must agree, and let everything behind each seam remain sovereign. This chapter reads the clauses at mechanism level, examining what precisely crosses each seam and what fails when it does not, using a single running case rather than an exhaustive catalogue. Smart-building interoperability appears only briefly, as the simplest instance; the disaster case carries the argument.

10.1 The boundary box: MIM1 context and MIM2 grammar

MIM1 does one thing: it names whose reality is under discussion, at what spatial extent, and over what temporal window. Its ontology is that of Actor-Network Theory, in which sensors, occupants, and institutions enter the record as peer actors rather than as a hierarchy of instrument beneath subject (Waern, 2026). The concrete artifact is a boundary box with three declared fields: the anchor entity, the spatial extent (a MIM7 Places geospatial referent), and the temporal window. A context broker that cannot populate those three fields has not defined its box, and every downstream clause inherits the ambiguity.

The smart-building case shows the box populated. A building twin exposes each room as a MIM1 context entity, with anchor the room, extent its cadastral coordinate, and window the live present plus a perpetual trace. MIM2 supplies the shared grammar: the room's heat-demand attribute is expressed in an NGSI-LD data model whose semantics a municipal district-heating twin already parses, so that the two twins interoperate without sharing a codebase, the demonstrated federated pattern of NGSI-LD brokers under a Gaia-X trust frame (Cirillo et al., 2024). Under the edge-native design the boundary box persists locally through a partition, and the seam becomes the reattachment point on reconnection, the property no centralized design possesses. That is as far as the building case needs to go.

10.2 Across communities that share no ontology: MIM3, MIM4, MIM5

The harder interoperation crosses communities with no common vocabulary at all, and this is where MIM3 Contracts, MIM4 Trust, and MIM5 Transparency carry the load. Consider the load-bearing example: a network operator's twin and an emergency-services twin during a disaster. When a hurricane degrades the network, the operator must hand a slice of its live reality to responders who share none of its RAN ontology. MIM3 encodes the contract: which slice, for which purpose, and under which usage restriction. MIM4 encodes trust: a verifiable credential proving that the responder is who they claim to be before any slice is released. MIM5 encodes transparency: which automated action the operator's system took, a cell-outage-compensation retune or a CIO adjustment, rendered explainable to a non-RAN reader who must act on it under lives-at-stake pressure.

These clauses are not hypothetical. During the Helene backhaul severance the U.S. FCC activated the Mandatory Disaster Response Initiative, compelling cross-network roaming while sites sat offline (Congressional Research Service, 2024; FCC, 2024). Mandatory roaming is a MIM3-plus-MIM4 act, an inter-operator data-and-service contract with its identity and trust exchange, imposed by regulation precisely because voluntary interoperation failed under load. When terrestrial mechanisms collapsed during Hurricane Melissa, Liberty Caribbean fell back to a rehearsed partition mitigation, activating Starlink Direct-to-Cell so that standard LTE phones regained a link with no new equipment (Liberty Latin America, 2025), a pre-negotiated trust-and-contract path that keeps an operator twin exposing reality to responders after its own towers go silent.

Across both interoperations, one object spans the seam: not a shared model but reality itself, digitally rendered, the boundary-spanning object precisely because the operator and the emergency service share no ontology yet share the same physical scene (Waern, 2026). Two mechanisms carry that seam and must not be conflated. The intent interface (TMF921) expresses the declarative what, an autonomous domain's intent to restore or compensate service, while the inter-operator sharing itself is a business agreement (MIM3) plus identity and trust (MIM4).

10.3 Governing a perpetual record

A perpetual reality record elevates three clauses to governance of constitutional grade. Who may query which slice, at which zoom, over which window is a MIM4 question the boundary box must answer per query, because a decade-deep occupancy trace read at room resolution is a surveillance act regardless of intent. Explainability as a right is MIM5 made non-negotiable: no automated decision drawn from the record ships without provenance a domestic stakeholder can read, the retrieval-over-generation discipline (§4.5) on which the whole architecture depends. And archival ethics is the clause ordinary security misses: a record built to outlive its assets must adopt the ratified NIST post-quantum primitives, FIPS 203, 204, and 205 (NIST, 2024), at the archive layer first, within an OAIS-style preservation model designed to keep digital objects legible across generations of technology and designated communities (Consultative Committee for Space Data Systems, 2012), so that reality stays readable irrespective of the vendor or format that recorded it, the FAIR principles stated for infrastructure (Wilkinson et al., 2016).

10.4 Where the clauses land

Three governance regimes describe the same seam under different names. Mapping them keeps the constitution from fragmenting into rival standards:

MIM (OASC)TM Forum ODA functionITU-T Y.4489 federation role
MIM1 Context / MIM7 PlacesParty & context management; Intent (TMF921) as machine-actionable contextTwin registry + shared spatial reference
MIM2 Data ModelsInformation framework (SID)Common data model for federated twins
MIM3 ContractsBusiness agreement / product orderInter-twin service and access agreement
MIM4 Trust & Personal DataIdentity & access managementCredential and authorisation exchange
MIM5 TransparencyAI governance & decision-loggingExplainable cross-twin decision record

The table encodes two corrections: TMF921 (Intent Management) belongs against MIM1 and MIM3 as machine-actionable context and contract rather than against MIM5, and MIM5 Transparency maps to AI governance and decision-logging rather than to an intent API. ITU-T Y.4489 standardizes exactly this federation of independent twins through registries and communication interfaces (ITU-T, 2023). That three independently authored frameworks describe the same minimal seam is consistent with the claim that the seam, rather than any single stack, is what a city actually signs when it commits to interoperability. It is not, by itself, evidence that the architecture works, since convergence among standards bodies is common. Reality is the object all three are attempting to keep shared; the MIMs are the clauses that make sharing it survivable.

11. Action: What to Sign on Monday

Procurement decisions about archival architecture are among the most consequential and least visible an institution makes; few recall who chose an archive format, yet everyone inherits it. The architecture of reality-recording is being set in contracts signed this quarter, and those contracts will outlast the vendors, the standards bodies, and probably the careers of the people signing them. This chapter names what forks the future and then states what to sign.

The five decisions that fork the future

Each decision carries its evidence basis and its fifty-year compounding cost, the price not of the wrong choice today but of the wrong choice multiplied across five decades of infrastructure that cannot easily be re-poured.

  1. Edge-native versus cloud-first. Ukraine restored national roaming within a week and withstood roughly 65% grid-power loss (Chapter 1) because reachability did not depend on one place; the December 2023 Sandworm wipe of approximately 24 million subscribers proved the inverse, that the cloud is not a sanctuary. Hurricane Helene took 48.7% of area cell sites offline with a multi-week restoration (FCC, 2024). Compounding cost: a cloud-first backbone chosen now quietly assumes uninterrupted transport for fifty years, an assumption every one of these events falsifies.

  2. Need-first versus data-first. The Shibuya Open RAN case tuned CIO from an identified operational need, delivering the +8.0 pt weighted gain on 22 problem relations (§5.2). Data-first programs collect first and ask why later. Compounding cost: fifty years of accumulated telemetry that answers no question anyone asked, at a storage and carbon cost that never amortizes.

  3. Minimal-interop versus lock-in. TM Forum's Open Digital Architecture and Open APIs, with intent expressed through TMF921, let operators reach Level 4 autonomy in scoped domains without a single-vendor stack (TM Forum, 2023–2024). Compounding cost: proprietary bindings signed today become the migration bill of 2050, paid in full and with interest.

  4. PQC-now versus later. NIST ratified ML-KEM, ML-DSA, and SLH-DSA in 2024 (FIPS 203/204/205). Data archived under classical cryptography today is harvest-now, decrypt-later inventory. Compounding cost: a fifty-year archive encrypted with RSA is already compromised on the day the cryptographically relevant quantum computer arrives, retroactively and for everything ever written.

  5. Perpetual-wisdom versus project-amnesia. NOAA's Asheville climate archive was imperiled when Helene flooded the region; institutional memory is one disaster from deletion. SMILE's Phase 6 Perpetual Wisdom treats the record as outliving the project. Compounding cost: every project that closes without perpetual recording restarts the next one from zero, indefinitely.

The proposition, restated: reality is the primary, perpetually recorded, boundary-spanning construct, and the decisions that make its recording sovereign, explainable, and quantum-safe are being fixed now. The falsifier remains the partition test: does the readable model of reality survive simultaneous loss of network and power? The Växjö heating outage offered a small live rehearsal of exactly this question; the Ukrainian record answers it at national scale.

The limitations, consolidated. The empirical spine is one operator, one metro, and one KPI family, and its outcome figures carry a synthetic-mobility watermark (§5.1); no third party can reproduce them, and every outcome-derived figure is a controlled demonstration rather than a directly observed production figure. The +8.0 pt CIO gain is a single-run demonstrated result rather than a multi-season deployment, and the approximately 0.7 to 0.8 pt mean-of-rates-versus-attempt-weighted inflation is disclosed (§5.2) so that no reader mistakes the friendlier average for ground truth. TM Forum autonomy levels and PQC standards are ratified but nascent in field deployment; the world-model claims of Chapter 8 rest on single unverified preprints; and the quantum stages (QA, QI, QR, HQC, QN) remain benchmark-gated projections. The operator economics of Chapter 6 are a parameterized model with a wide sensitivity band rather than a forecast. None of this is settled science; all of it is signable engineering.

Practitioner annex

(a) Procurement clause set, for the next RFP.

#ClauseAcceptance criterion
1Edge-native processingCore control functions execute locally with no synchronous cloud dependency
2Degraded-mode sovereigntyPartition test: the readable model survives simultaneous network and power loss for a defined window — this is the acceptance test, not a feature request
3PQC-at-archiveML-KEM/ML-DSA at rest with documented crypto-agility (algorithm swap without re-architecture)
4ConformanceMIM1 (context) and MIM7 (Places) conformance demonstrated, not asserted
5Data egress / repatriationFull export in open format within contracted RTO; no egress penalty
6Benchmark disclosureAny AI or quantum claim ships with the benchmark, the baseline, and the weighting method (mean-of-rates versus attempt-weighted rate)

(b) L0 to L5 self-assessment and single-use-case-first recipe. Score each operational domain honestly against TM Forum Autonomous Networks L0 (manual) through L5 (full autonomy). Most real deployments sit at L2 to L3 while claiming L4. Then follow the approach the RAN-energy work took: select one closed-loop use case, instrument its baseline, tune against an identified need, and prove the loop before widening scope. One verified loop is worth more than five aspirational ones.

(c) The five-decisions scorecard. For each fork, mark the current default and the target, then attach the owner and the review date:

  • Edge-native ☐ / Cloud-first ☐ → target ____
  • Need-first ☐ / Data-first ☐ → target ____
  • Minimal-interop ☐ / Lock-in ☐ → target ____
  • PQC-now ☐ / Later ☐ → target ____
  • Perpetual-wisdom ☐ / Project-amnesia ☐ → target ____

Any row left at the second column is a compounding liability with a name attached to it.

(d) Sequencing.

  • Next week: run the partition test on one live service; write clause 2 into the next RFP; inventory which archives are still classically encrypted.
  • Next year: reach a verified L4 loop on a single use case; adopt TMF Open APIs and TMF921 intent on one interface; begin PQC-at-archive migration on the highest-sensitivity store.
  • Next five years: extend the AEST temporal operations (Absorb, Emulate, Simulate, Transcend) across the portfolio; make MIM1 and MIM7 conformance a standing supplier requirement; institutionalize Phase 6 perpetual recording so that no project closes into amnesia.
  • Next decade: treat crypto-agility as routine hygiene; adopt benchmark-gated quantum stages only as they clear their gates; make reality-recording sovereign by default across the estate.

The Greenland map that opened this paper distorts a coastline without moving the land. The contracts signed on Monday do the opposite: they move the land while appearing to be paperwork. Choosing edge over center, need over data, openness over capture, quantum-safety over convenience, and memory over amnesia leaves behind a record of reality that stays readable when the network is gone, the power is out, and the vendors are forgotten.

References

Cite This Article

Waern, N. (Jul 8, 2026). The Quantum City: Self-Healing Networks, Interoperable Digital Twins, and the Architecture Decisions That Reverb With Eternity. WINNIIO AB. https://doi.org/10.5281/zenodo.21258104

Open Access — CC-BY 4.0 — ORCID: 0009-0001-4011-8201

View on Zenodo (PDF + metadata)

Open access — CC-BY 4.0