What Programming Language Characteristics Would Allow Provably Safe AI? — LessWrong