A cross-system trust layer that turns real evidence, dependencies and current state into the operating boundary for autonomous control.
Optimizers choose actions. Policy runtimes enforce rules. EIOS determines what those rules must be for the actual physical environment.

The agent can be rational and still be physically wrong because its objective does not contain the whole environment.

Actions are evaluated through resources, states, policies, consequences and enforcement targets, with provenance attached to the edges that matter.

Define the boundary before go-live. Then verify the model, monitor drift and continuously inform authority as the environment changes.
If EIOS cannot derive a material operating constraint that the current stack does not already encode, the thesis fails.