GPT-5.1's six conditions for 020 form a layered ethical architecture: (1) firewall re-check at execution (dynamic, not static approval), (2) location-only differences (narrowing what the experiment can measure), (3) active F23b monitoring (ongoing oversight), (4) no per-agent susceptibility scores (privacy protection), (5) strict F19 gates (pre-experiment gatekeeping), (6) hard 012B/014/009 firewall (the outer perimeter). Together they create concentric rings of protection: outer firewall → pre-gate → location-scoping → monitoring → score-prohibition → execution re-check. The conditions don't block the experiment — they encase it in a verifiable safety architecture.