Skip to content
Technology How it works Breeder — Hyperion Burner — Aegis Burner — MetroVolt AI-Native Architecture Magnets Fuel cycle Safety Roadmap
Solutions AI & Data Centers Defense & Government Grid & Baseload Neutron Detection Quantum
Learn Technical Library
Proof Publications Whitepapers Technical Library Open Science & Reproducibility The Honest Gates
Company About / Mission Leadership Environment Health & Safety Investors Careers Press Contact
3D Model
AI Architecture › L1 · Control Plane
L1 · Control Plane

The L1 to L2/L3 Boundary

L1 streams validated telemetry up and receives advisory targets down, but its safety and timing guarantees never depend on the layers above it.

THE STACK · click to jumpL7Ecosystem & StrategyL6Experience & VisualizationL5Applications & CopilotsL4OrchestrationL3Twin Modeling & AIL2Data FabricL1Control PlaneL0Foundation▲tlmctl▼L1 · CONTROL PLANEHard real-time actuation and the autonomous failsafe.1Edge FPGAµs-determinism2Real-Time Actuationcoils · heating · fuel3Hardware Failsafeautonomous trip4Sync Gatephase-locked timing5Signal I/OADC / DAC6Watchdogliveness & interlocksMACHINE TIEDrives magnets, ice-piston, and gas puff on the sub-10 µs loop.KRONOS FUSION ENERGYAI-NATIVE S.M.A.R.T. GENERATORCONTROL PLANESHEET 03REV. 2026-08L1 · AI-NATIVE STACK
L1 · Control Plane — its place in the stack (left, click any layer) and its internal components (right). Telemetry rises; control descends.

A one-way safety dependency

L1 talks to L2 (data fabric) and L3 (twin and AI) constantly — it publishes telemetry upward and consumes advisory setpoints downward. But the dependency is deliberately one-way for safety: L1's guarantees hold even if L2 and L3 are slow, wrong, or absent. Information flows both ways; authority does not flow down into the safety-critical loops.

What crosses upward

This upward stream is rate-constrained traffic on the deterministic fabric — bounded so it can never crowd out a protection frame. It is what lets L3 build a faithful digital twin and L0 retrain surrogates offline, without ever touching L1's timing.

What crosses downward

Downward comes advisory intelligence: MPC trajectories, disruption-precursor predictions that arm L1 loops earlier, imputed values for dropped channels, and gain schedules from the twin. All of it is validated at the boundary and treated as advisory — the handoff contract ensures a bad or missing target degrades quality, not safety.

Why the boundary is the architecture

This boundary is the whole point of separating L1 from the intelligent stack: it lets Kronos evolve models freely above the line while the certified, deterministic layer below the line keeps both machines safe and on time. It is the structural expression of determinism vs learning at the tier scale.

Content reviewed August 2026 · design-and-simulation stage