The questions a careful reader asks, answered plainly, with the real limits stated.
“The least performant AI” sounds like an excuse for building something slow and bad. Is it?
No, and the distinction matters. The argument is not that slowness is a virtue. It is that a system fast enough and fluent enough that nobody checks it has removed the human from the loop by construction, whatever the policy document says. The property being sought is verifiability by a person, and on current architectures that costs throughput. If someone builds a system that is both fast and genuinely verifiable, the argument gets what it wanted and the trade-off disappears.
You sell sovereign infrastructure. Isn’t this philosophy working backwards from a sales pitch?
That is the right question to ask of anyone, and the check is the sequence. The five Alexander principles were published before any of Hamant’s work was read here. The convergence was found afterwards, and it can be dated. What the essay cannot claim is independence of interest: I build and sell this kind of infrastructure, and the argument favours what I sell. Read it as an argument, not as a disclosure-free position.
Hamant is a plant biologist. Why should his views on AI carry weight?
They carry different weights in different registers, and the essay separates them. His empirical claims about living systems are peer-reviewed. His structural claims about systems in general are supported across biological and technical domains, most substantially in work with the computer scientist Stéphane Grumbach. His normative claims about what we should therefore build are argued rather than derived, and they are his and mine to defend. Presenting the last with the authority of the first would be the failure the essay is arguing against. On AI specifically he is an informed critic, not a specialist, and the essay uses him for the systems argument rather than for technical authority.
If robustness is so obviously right, why is almost nobody building this way?
Because performance is a superb adaptation to a stable world, and the world was stable enough for long enough that the adaptation became the default. Slack looks like waste right up until the moment it is the only thing keeping you running. Hamant’s own answer is that the vocabulary is missing: a team that has only the word “optimisation” experiences every argument for margin as an argument for inefficiency.
A cryptographic seal is irreversible. Doesn’t that contradict a preference for reversibility?
It is a real tension and the essay names it rather than smoothing it. The resolution is that correction proceeds by annotation rather than deletion, so what is reversible is the interpretation while the attestation stays fixed. Retractions are recorded inside the document rather than removed from it. There is one genuine exception: erasure. A right to erasure requires that deletion actually happen, so that path exists, is gated on legal hold, and is tombstoned and signed.
What actually stops you from aggregating members anyway?
Three things, and they are not equally strong. The model runs on our own machines, and no code path sends a member’s material to somebody else’s model. Each community’s material is held apart from every other’s, and it is filed by what it says rather than by whose it is. And there are commitments a community cannot edit away, which are checked against what the model says before it stands as an answer. What does not yet exist is a check that reads a community’s own rules against those commitments and refuses a contradiction. A community can write such a rule; it cannot make it win.
Does anything leave the system?
Member chat content goes to DeepL for translation. DeepL is a translation provider rather than a model provider, so the argument against globally averaged language models is unaffected, but any claim that member content never leaves would be wrong, and it is not made here.
Isn’t this just anti-AI?
Hamant is explicit that robustness is technophile, because it favours objects that can be repaired locally. The target is not machines. It is a particular class of machine that has become a black box to the people who build it, and a development culture that treats comprehension as an acceptable casualty of capability.
What has actually been built, as against argued?
Built and running: commitments a community cannot edit away, checked against what the model says; sealed records that refuse edits and correct by annotation; inference on our own machines; each community’s material kept apart from every other’s; and a way for two villages in dispute to work through it, ending in a hearing. Argued but not built: the promotion of the aggregation bar to the constitutional layer, which this essay proposes rather than reports. Half-built: sanctions a moderator can apply, but nothing that remembers this is the third time. Not built: any equivalent route for two members who fall out inside one village.
What are the limits you would rather a reader heard from you than found?
It has been tested adversarially from the inside and not from the outside: no independent penetration test, and we do not claim one. Nothing has been measured under load. It runs in production, but everywhere it runs is the same organisation, so it still wants somebody else’s.
And the sharpest one, which we publish on our own governance page. An agent that simply declines to consult the framework is not stopped by it. Where a model’s words reach a member they are checked before they stand as the answer, and the model cannot get round that; but if the check itself fails, the words still go out, because refusing to answer whenever a check breaks is its own harm. What the system will not do is call them clean.
What would falsify the argument?
A system that is highly optimised, tightly coupled and demonstrably more survivable through a decade of genuine volatility than a comparable system built with margin. Or, closer to home, a federation that turned out to have no real internal variety — the same implementation, the same jurisdiction, the same deployment topology everywhere — in which case the design-inbreeding critique lands here too, and the pluralism was rhetorical.
Why philosophers at all? Why not just engineering?
Because the failure being guarded against is not a technical fault. It is values drifting while everyone continues to recite them, which is a thing that has happened repeatedly to institutions staffed by competent people, and which raises no alarm at the time. Arendt is the clearest account of how that happens without anyone deciding to do wrong. Engineering tells you how to build the refusal. It does not tell you which refusals are worth building.