Rules explained09 / 10
Health and Risk Controls
In 30 seconds
- Whitepaper design: risk controls protect system limits, not a price
- Higher risk means less emission, down to zero, then a step-by-step recovery
- The base sell fee is 3%, up to 28% in total when prices deviate sharply
What risk control protects
The whitepaper is direct about it: risk control does not protect any particular price. It protects four core boundaries.Whitepaper p. 153
Emission + Liquidity + Reserve + Governance
Four principles:Whitepaper p. 153–154
- The market may move freely. The protocol promises no fixed price, and the model does not depend on holding one.
- The protocol must be able to contract. The higher the risk, the less new economic load the protocol itself adds.
- Governance leads emission cuts. Market capacity supplies the risk signal; governance votes decide how far actual emission comes down, to zero in the extreme.
- Recovery happens in steps. Contract first, then observe, then recover.
The Gauge HealthScore
Whatever emission a Gauge wins through votes has to pass a HealthScore gate before it is executed, to check that the pool has the real economic quality to absorb it.Whitepaper p. 108
HealthScore = 0.30L + 0.20V + 0.20F + 0.20P + 0.10S
| Component | Meaning | Weight |
|---|---|---|
| L | Real liquidity health | 30% |
| V | Real trading activity | 20% |
| F | Fee efficiency | 20% |
| P | Price stability | 20% |
| S | Capital stability | 10% |
Each component is mapped to a 0 to 100 score before weighting. Voting incentives, veAiLGNS votes and a project voting for itself do not count towards the HealthScore, so concentrated votes or large incentives cannot steer final emission directly.Whitepaper p. 108
How much emission can actually run
| HealthScore H | Maximum share of emission executed |
|---|---|
| 80 ≤ H ≤ 100 | 100% |
| 60 ≤ H < 80 | 80% |
| 40 ≤ H < 60 | 50% |
| H < 40 | 0%, new emission paused |
ExecutableGaugeBudget = GrossGaugeBudget × HealthCap
Emission cut by the HealthScore is not handed to other Gauges. It is booked separately as Health-Withheld Budget and moved to the Insurance Reserve.Whitepaper p. 109
Votes ≠ Final Emission · Buy Votes ≠ Buy Health
ELR: the Economic Load Ratio
ELR measures how much economic load the market still has to carry after internal liquidity balancing, as a share of total market capacity.Whitepaper p. 140
ELR = EconomicLoad / Global Capacity
Economic load has three parts: the value of newly emitted tokens entering the market, plus pressure from the LSP's existing inventory, minus effective buying through the Turbine. It never goes below zero.Whitepaper p. 140
EconomicLoad = max[0, NewEntry + InventoryPressure − EffectiveBuy]
Four reference bands
| ELR | Market state |
|---|---|
| ELR ≤ 60% | Healthy |
| 60% < ELR ≤ 80% | Controllable |
| 80% < ELR ≤ 100% | High load |
| ELR > 100% | Overloaded |
The whitepaper stresses that ELR has no permanent threshold: these values are for initial operation and stress testing, not permanent economic constants.Whitepaper p. 140 Its stress tests use ELR ≤ 80% as the V1 reference safety line.Whitepaper p. 146
Four risk states
| State | Market | Protocol response |
|---|---|---|
| Green | Normal | Normal operation |
| Yellow | Rising pressure | Slow down expansion |
| Red | High risk | Sharply cut emission and capital deployment |
| Black | Black swan | Emergency protection and module isolation |
The state is not decided by price alone but by several indicators together:Whitepaper p. 154
ELR + Liquidity + LSPInventory + HealthScore + Reserve + AbnormalActivity
In the whitepaper's words, a falling price is not in itself a black swan; losing the capacity to carry the system is the real risk.Whitepaper p. 154
What triggers each state
- Yellow: ELR keeps rising, the LSP takes clearly longer to clear its inventory, some pools' HealthScores drop, organic volume falls and liquidity starts to shrink. The protocol first slows emission growth, LSP releases and reserve deployment, without jumping to extreme measures.Whitepaper p. 155
- Red: several indicators worsen at once, for example ELR above 100% together with falling liquidity and rising inventory coverage. Actual emission and LSP execution come down, reserve deployment turns conservative, and emission to abnormal Gauges goes to zero. Normal user trading stays open as far as possible.Whitepaper p. 155
- Black: extreme events that ordinary parameter changes can no longer contain, such as core liquidity vanishing, oracle failure, a major router fault, a critical contract vulnerability, a large-scale attack, a cross-chain security incident, or serious risk to reserves or POL. The goal switches to stopping the risk from spreading.Whitepaper p. 156
Black does not mean pausing everything. It means module-level isolation: pause only what is failing, for example just the Turbine router, the LSP, or one abnormal Gauge.Whitepaper p. 156
Contraction and recovery
When market capacity falls sharply, the risk system signals governance first, and governance steps actual emission down:Whitepaper p. 157
100% → 80% → 50% → 20% → 0%
Zero emission is a protective tool in a risk state, not the end of the emission plan. Recovery is also stepped rather than an instant return to 100%, while ELR, liquidity, inventory coverage, HealthScores and organic volume are watched; if risk returns, the protocol contracts again.Whitepaper p. 157 Whitepaper p. 161
0 → 20% → 50% → 80% → 100%
Other controls:
- Isolating abnormal pools: rapid liquidity loss, wash trading, fake volume, incentive manipulation, badly distorted prices or security risks lower a pool's HealthScore. As it approaches zero, the pool's emission goes to zero; if needed its qualification is suspended, and governance decides after a review whether to restore or remove it.Whitepaper p. 157
- Isolating routes: with the Turbine, users decide whether to trade and the protocol picks the pool to buy in; with the LSP, the protocol controls release pace, size and the pools it sells into. Abnormal pools are removed from routing.Whitepaper p. 158
- Reserves are not an unlimited buyer: reserve deployment falls as risk rises, to zero in the extreme. Assets already in POL stay protocol-owned but can be moved or redeployed.Whitepaper p. 158
The price-protection fee
The base sell fee for AiLGNS is 3%. When the price moves well below its reference, the protocol adds a protection fee along a continuous curve, with no fixed price-drop tiers:Whitepaper p. 159
TotalSellFee = 3% + ProtectionFee ≤ 28%, 0% ≤ ProtectionFee ≤ 25%
- The reference price is a TWAP; the decline is measured between the reference price and the current TWAP.
- Governance sets the trigger, TWAP window, curve sensitivity and curvature, maximum surcharge and recovery confirmation; the oracle supplies data and the contract executes automatically with the approved parameters.
- As the price recovers the surcharge falls gradually along a continuous curve, and once the stability conditions are met it returns to 0%, leaving the 3% base fee.Whitepaper p. 159
Even under price protection, the protocol uses a public, preset fee mechanism rather than closing ordinary users' right to sell. Emergency pause targets abnormal modules, routes and pool emission; blocking normal selling is not a routine risk tool.Whitepaper p. 160
Permission limits
High-risk permissions (Turbine routing, LSP execution, the treasury, POL management, Gauge management, veAiLGNS, OTC, emergency pause) should not sit with a single ordinary address but combine multisig, timelock and DAO.Whitepaper p. 160 Governance tiers and the timelock are covered in veAiLGNS Governance.


