What TLA+ can and can't check
This article discusses the limitations of TLA+ in formal verification for software development. The author warns against over-hyping formal methods as a complete solution for agentic software bugs.
Why it matters
As AI-driven software development grows, understanding the boundaries of formal verification is essential for building reliable, bug-free systems.
Last week Boris Cherny, the inventor of Claude Code, mentioned that Opus was able to use TLA+ 1 to find race conditions in code.
And now everybody on the internet is talking about formal verification.
As a long-time educator ( 1 2 ) and advocate of TLA+, this is really exciting! TLA+ is great at designing complex concurrent systems and making sure they're bug-free. 2 As a long-time advocate of level-headedness, this new euphoria worries me. I read a lot of people saying that formal methods will solve the problem of agentic software development once and for all, and that's nonsense.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in