Agents only ever see the IAL contract; the Safety & Constraint Engine sits outside any
agent's trust boundary — rejections carry reasons so the agent can revise, but no agent path marks a
protocol safe. Development runs end-to-end against the Virtual Lab Simulator; swapping to real
hardware is one adapter change. IAL aligns with MCP semantics and tracks Anthropic's
Model Hardware Standard.