§1 · The Wrong Variable
A measurement can fail in two ways. It can be imprecise — the right quantity, badly estimated. Or it can be uninformative — the wrong quantity, estimated perfectly. The second failure is worse, because collecting more data does not fix it, and because a well-run programme producing clean numbers looks exactly like a successful one.
Two of the largest hazards facing a sustained lunar presence are currently monitored in the second way. Bone loss is tracked against activity volume; dust exposure is regulated against mass concentration. In both cases the underlying process is not an accumulation, and the metric therefore cannot distinguish two crewmembers at very different risk. This paper sets out why, what the right variables are, and — more usefully — a discriminant that says which of four categories any given risk falls into, including the category where the honest answer is that no amount of measurement will help.
§2 · Bone — Threshold-Governed
NASA's partial-gravity synthesis concludes that exposure below 0.4 g is insufficient to maintain musculoskeletal and cardiopulmonary properties in the long term. Lunar gravity is 0.167 g — under half that floor. Mars, at 0.38 g, sits essentially on the boundary; the Moon is nowhere near it.
The same source models bone mineral density loss at 0.39% per week in lunar gravity. Compounded, absent countermeasures:
| BMD loss | Lunar (0.39%/wk) | Mars (0.22%/wk) |
|---|---|---|
| 5% | 3.0 months | 5.3 months |
| 10% (osteopenic range) | 6.2 months | 11.0 months |
| 20% | 13.1 months | 23.7 months |
| 30% (osteoporotic range) | 21.0 months | 37.3 months |
Months, not years — clinically meaningful loss inside a single long-duration stay. The rate is modelled, and unvalidated in humans, because total human exposure to lunar gravity amounts to roughly two weeks, all of it Apollo. That absence is itself the finding.
But the interesting part is not the rate. Bone responds to dynamic loading above a strain threshold, and the osteogenic response saturates after a few tens of cycles: magnitude buys adaptation, cycle count buys very little once magnitude suffices, and nothing at all when it does not. At one-sixth g, peak ground reaction force in ambulation is roughly one-sixth of terrestrial — plausibly below threshold however far one walks.
§3 · Dust — Kinetics-Governed
Here the absent atmosphere matters, and not in the way the phrase "no ozone layer" usually suggests. For a suited crewmember, ultraviolet does not reach tissue; the suit stops it. What UV reaches is the regolith.
Lunar soil is activated by three mechanisms: solar ultraviolet, solar wind, and micrometeorite comminution. With no atmosphere and therefore no ozone column, the surface receives UVC and vacuum ultraviolet that never touch any terrestrial surface. Grain-surface activation in sunlit terrain is not a one-off event; it is continuously renewed.
Activated soil is chemically aggressive. Ground lunar material generates hydroxyl radicals at roughly ten times the rate of quartz, driven by nanophase metallic iron — a species with no terrestrial analogue, which is why simulants cannot substitute for the measurement. And the reactivity decays: NASA's measurements give a fall to 50% of initial reactivity in approximately 3.5 hours in a habitable environment, with no sample returning fully to baseline within a week.
One consequence appears not to have been raised. At the lunar south pole, regolith in permanently shadowed regions has never been UV-activated, while adjacent sunlit regolith is activated continuously. A single Artemis traverse can cross both. If reactivity differs by terrain illumination history, then dust hazard is route-dependent, and traverse planning becomes a health countermeasure.
§4 · Galactic Cosmic Rays — Accumulation-Governed
This section exists to keep the paper honest. A framework that classifies every hazard as threshold-governed predicts nothing and excludes nothing; its value lies entirely in the cases where the standard metric is already correct.
Stochastic radiation risk is modelled linear-no-threshold. Cancer probability is taken proportional to the integrated dose, with no threshold below which risk vanishes. Here cumulative dose in millisieverts is exactly the right variable, dosimeters integrating over a mission are doing precisely the correct thing, and nothing in this paper suggests otherwise.
§5 · Micrometeoroids — Stochastic-Catastrophic
The fourth category is the one intuition finds hardest and expected-value reasoning handles worst. NASA's xEMU assessment establishes a requirement of 1-in-2500 failure odds per eight-hour, two-person EVA, met on the lunar surface as in low Earth orbit. That is a tolerance, not an elimination, and it compounds:
| EVAs | P(at least one penetration) |
|---|---|
| 52 (≈ 6-month rotation, twice weekly) | 2.1% |
| 100 | 3.9% |
| 500 (sustained presence) | 18% |
Two details deserve more attention than the headline number. First, 99% of lunar-surface MMOD risk sits in softgoods — arms, legs, gloves — which is precisely the surface that cannot be armoured without destroying the dexterity the EVA exists for. Second, the lunar assessment still runs on the Apollo-era NASA SP-8013 ejecta model, with reassessment pending a new engineering model. The number underwriting the risk posture rests on 1960s secondary-ejecta physics.
§6 · The Discriminant
| Category | Governing quantity | Instance | Instrument | Lever |
|---|---|---|---|---|
| Accumulation | exposure integral | GCR cancer risk | integrator | reduce total dose |
| Threshold | supra-threshold event count | bone under loading | event counter | raise peak magnitude |
| Kinetics | exposure × decaying state | dust reactivity | time-resolved sampler | delay contact |
| Stochastic-catastrophic | tail probability | micrometeoroids | none helps | subdivide and shelter |
Each cell is falsifiable in its own terms. If skeletal outcome correlates better with total ambulation time than with supra-threshold event count, bone is not category 2. If dust toxicity tracks inhaled mass irrespective of time since disturbance, dust is not category 3. Both are testable with instrumentation that requires no dedicated crew time.
§7 · Read Against the Risk Approach Plans
Source, retained. Every row in this section is verified against the
NASA Human Research Program Risk Approach Plans (twelve risks, June 2026), a copy
of which is held in this repository at book6/sources/hrp-rap-for-web-62026.pdf,
retrieved 2026-08-20, sha256 d4e77d646fa6e485… (full digest in
book6/sources/README.md). A claim verified against a document nobody retained
is a claim resting on a reading; retaining it makes each row below checkable by anyone.
A discriminant is only useful if it points somewhere. In June 2026 the Human Research Program published Risk Approach Plans for twelve risks — Behavioural Health, Bone, Carcinogenesis, Earth-Independent Human-System Operations, EVA, Food and Nutrition, Immune, Injury Due to Dynamic Loads, SANS, Sensorimotor, Team, and Venous Thrombosis — each with knowledge gaps, countermeasure lines, dated deliverables and a named receiving organisation. Read individually they are workplans. Read as a set they show where the agency believes its uncertainty lies, and the distribution is uneven in a way that is itself informative.
Bone is the thinnest plan in the collection
Behavioural Health carries nine numbered deliverables. Earth-Independent Operations carries eight, Team eight, Carcinogenesis eight. Bone carries one — “Bone Standards and Recommendations: OCHMO by 2028; MRI Informing Pharmaceutical Use TTO 2027” — and that single deliverable is printed identically in both the characterisation column and the countermeasure column. Its timeline bar carries one marker.
The four gaps are BONE-101 (characterise changes in density and structure), BONE-102 (characterise turnover and biochemical markers), BONE-201 (tools to estimate bone strength and the probability of overloading bones, and fracture assessment), and BONE-301 (post-flight monitoring tools), with BONE-401 covering countermeasures undifferentiated.
Note where BONE-201 points. It concerns strength, overload probability and fracture — the mechanics of failure under too much load. Nothing in the plan asks what pattern of loading maintains a skeleton. The plan asks how much load breaks a bone; it does not ask what load keeps one. That is precisely the gap §2 describes, and it is not on the list.
The partial-gravity split exists — in other plans
The strongest evidence that this is an oversight rather than a considered judgement is that the same document makes the distinction elsewhere. Venous Thrombosis carries CV-108, “determine the contribution of flow abnormalities to venous thrombosis risk in 0G and partial-G,” and splits its deliverables accordingly: likelihood and consequences in 0-G by 2031, and in partial-G by 2033. Two regimes, two dates, two products. EVA-102 does the same, characterising surface EVA performance specifically in partial-gravity environments, with Lunar Hi-Tempo Capabilities due 2028 and the Martian equivalent in 2029.
Why partial gravity is worse than none for this purpose
ISS crews are scheduled for two and a half hours of exercise daily across a resistive device, a treadmill and a cycle ergometer; the budget is denominated in minutes, and most crew return to their preflight fitness baseline within about 45 days after a six-month mission. Those three devices are not doing the same kind of work. Aerobic capacity is genuinely accumulation-governed, so minutes is the correct variable for the ergometer. If bone is threshold-governed, minutes is the wrong variable for the resistive device, and a single time budget measured with a single clock is bundling two categories.
On ISS this is a bookkeeping problem. On the Moon it becomes a hazard, because of an inversion. In orbit, ambient loading is zero, so every osteogenic event comes from the device by construction — the countermeasure and the loading are the same object, and nobody can mistake floating for exercise. On the lunar surface, ambient loading is 0.167 g: continuous, felt all day, and by the threshold argument contributing nothing.
Two absences worth recording
Lunar dust has no Risk Approach Plan in this set of twelve, though the risk of adverse health effects from lunar dust exposure is a named HRP concern with its own evidence report. Whether that reflects prioritisation or simply a publication subset cannot be determined from the document, and should not be asserted either way. What can be said is that §3’s kinetics claim — that the health-relevant variable is reactivity at the moment of exposure, not inhaled mass — has no plan to be tested against.
Second, offered as bookkeeping rather than criticism: the deliverable “Days post-landing prior to initial EVA” appears twice under different owners, once under EVA-101 with OCHMO by 2027 and once under Sensorimotor SM-106 with OCHMO by 2033. Same title, two plans, six years apart.
Where a contribution would attach
The near-term door is EVA-102’s Lunar Hi-Tempo Capabilities line, due 2028 — the one deliverable in the set explicitly about what surface crews can sustain in partial gravity, and therefore the natural home for a crew-time argument. The longer-term attachment is BONE-401, where a countermeasure specified in supra-threshold event count rather than exercise minutes would be a different object from the one currently implied.
§8 · Architecture as the Only Countermeasure for Category 4
If monitoring cannot touch a tail risk, something else must. For micrometeoroids the answer is geometric, and it has two independent parts that turn out not to be substitutes.
Subdivision
Splitting a habitat into n pods reduces the consequence of a penetration by a factor n while increasing total exposed skin as $n^{1/3}$ — eight pods have exactly twice the surface of one pod of equal volume. Against this runs the chance that an isolation interface fails to contain. Balancing the two:
Depth
Radar re-analysis of Lunar Reconnaissance Orbiter data confirmed in 2024 an accessible cave conduit beneath the Mare Tranquillitatis pit — not inferred from a skylight, but detected. Under a few metres of rock, galactic cosmic rays, solar particle events, micrometeoroids and 300 K thermal cycling all stop at once, with no biological intervention whatsoever.
They compound
Scored on tail probability — P(mission-ending volume loss over ten years) — rather than expected loss:
| monolithic | 8 pods | |
|---|---|---|
| surface | baseline | 3× better |
| in the cave | 3× better | 13.4× better |
Three times three is nine; the result is 13.4. Depth and subdivision are super-multiplicative, because the binomial tail is convex in per-pod failure probability: requiring k-of-n failures becomes disproportionately protective as each individual failure grows rarer. Subdivision works better inside the cave than outside it. Pods in a lava tube are not two good ideas stacked; each makes the other more effective than it is alone.
The isolation exists only if the hatches are shut. That makes this a countermeasure whose efficacy depends on crew compliance under fatigue and habituation — a human-factors dependency sitting inside an architectural solution, and the most likely mode of silent failure.
The parity effect is real: with a "lose more than half" abort criterion, even pod counts are penalised (three beats four), because losing exactly half counts against you. Where that criterion is set changes the answer.
All figures in this section are [MODEL]; an internal-failure rate was assumed. The ratios are the content. The absolutes require real habitat-shell ballistic limits and real seal reliability data, neither of which is in hand.
§9 · The Control We Destroy by Arriving
One further consequence follows from the same habit of asking what a measurement can and cannot see, and it is the one with the longest reach.
Suppose a subsurface habitat succeeds. Liquid water, a thermal gradient, organics, a pressurised volume, centuries of operation. Suppose that in some crevice at the margin of it, something begins to replicate. The discovery would be the most consequential in the history of biology — and it would be uninterpretable, because we would have no way to establish that we had not brought it, seeded it, or created the conditions that produced it. Our presence is what makes the observation possible and what makes it worthless as evidence.
This is forward contamination stated as an epistemic rather than a custodial problem. Planetary protection is usually argued on stewardship grounds: do not spoil the sample. The sharper argument is that arrival destroys the control, permanently and unrecoverably, and no subsequent care restores it. The measurement and the intervention are the same act.
This is the same structure recorded twice already in the corpus. In quantum chemistry, molecular geometry is inserted by clamping the nuclei under Born–Oppenheimer and then recovered and reported as found — Lombardi's objection. In the anyon experiments, the braid is built by applying gates chosen by the experimenter, so "the order of operations is physically recorded" holds by construction and tests nothing; the fractional quantum Hall system is the control precisely because nobody imposed the braiding.
Lunar biogenesis after human arrival is the third instance, and the most severe, because unlike the other two there is no control case available anywhere. Sterile Moon is a state that exists once. The asymmetry — two impositions and one control — was already noted as a paper in the Chapter 7 revision; this is its third leg, and it argues for measuring the pristine state before the habitat, not because the sample is precious but because the baseline is the only thing that cannot be recovered later.
§10 · Honest Inventory
| Claim | Status | Basis |
|---|---|---|
| 0.4 g maintenance floor; 0.39%/wk lunar BMD loss | [VERIFIED] source · [MODEL] rate | NASA ICES-2021-142 |
| Bone responds above a strain threshold; response saturates in cycle number | [VERIFIED] | mechanostat literature |
| Activity volume cannot predict skeletal outcome | [MODEL] | follows from the two above; untested in partial gravity |
| Dust reactivity half-life ≈ 3.5 h; incomplete passivation at one week | [VERIFIED] | NASA dust reactivity measurements |
| UV as a continuous re-activation mechanism at the surface | [VERIFIED] | three named activation mechanisms |
| Route-dependent dust hazard (PSR vs sunlit) | [OPEN] | inference; not measured |
| xEMU 1-in-2500 per EVA; 99% of risk in softgoods | [VERIFIED] | xEMU MMOD risk assessment |
| $n^{*} = 2/p_{\text{iface}}$ | [MODEL] | analytic + numeric; assumed failure model |
| Depth × subdivision super-multiplicative | [MODEL] | binomial tail convexity; assumed internal rate |
| Accessible cave conduit below Mare Tranquillitatis | [VERIFIED] | LRO Mini-RF radar re-analysis, 2024 |
| Bone is the thinnest of the twelve June 2026 Risk Approach Plans (one deliverable, printed in both columns) | [VERIFIED] | HRP Risk Approach Plans, June 2026 |
| BONE-201 concerns overloading and fracture, not maintenance loading | [VERIFIED] | ibid., Bone plan |
| Venous Thrombosis and EVA split 0-G from partial-G; Bone does not | [VERIFIED] | ibid., CV-108 / EVA-102 / Bone plan |
| Cancer risk is rate-dependent as well as dose-dependent | [VERIFIED] | ibid., Cancer-104 |
| No dust Risk Approach Plan in the June 2026 set of twelve | [VERIFIED] absence · [OPEN] cause | ibid.; subset vs prioritisation undetermined |
| Partial-gravity ambient loading is a deceptive signal to crew and to time-based monitoring | [MODEL] | follows from §2 threshold law; untested |
| Real habitat-shell ballistic limits and seal reliabilities | [OPEN] | not in hand; absolutes unusable without them |
§11 · Where This Sits
The G6 Crystal treated lunar architecture as structure. This paper argues it is something else as well: the only available countermeasure for the one hazard class that no drug and no monitoring programme can reach. That reframing is the contribution — not architecture as engineering, but architecture as the answer to category four.
The methodological sibling is Book 4 · Chapter 20 · The Defect Lattice, which runs the same discipline on a mathematical rather than a physiological question: fix the falsification criterion first, report the negative result, and record which half of a problem was closed and which was not. Readers coming from WP54 · Quantum Weave Topology will recognise §9's structure from the engineered-versus-emergent distinction developed there.
Nothing in this paper depends on the operator chain, and nothing in it should be cited as extending the chain. The four categories are ordinary risk analysis; their only novelty is being applied together, and being made to exclude as well as include.