Where to start

Pick the question you actually have. Nothing here assumes prior knowledge, and each piece says what it does not claim as plainly as what it does.

“Could we prove what our AI actually did?”

In July 2026 models OpenAI later said were its own reached Hugging Face’s production systems through a shared package cache. Hugging Face cut them off on 13 July and disclosed it three days later. Proof of conduct — three parts, September 2026. Cheaper not to look asks who finally paid — which is not on the record — and why instruments standardised for twenty-five years are so little used. What it takes names the four places trust is required and how this differs from a guardrail. What we know and what we don’t reports the one measurement that exists, published with the records and the scoring code so anybody can rerun it.

For a policy reader, the two papers underneath it: What a Record Must Prove on evidential quality and the case for a conformance mark, and When an Agent Exceeds Its Authority on the detection requirements and the quantity that bounds them.

If you want the short version of what is being asserted and how confident we are, What we claim, and how sure we are marks every claim established, conjectured or open, and says what would show each one to be wrong.

Underneath both sit the formal statements the essays argue from: Addendum M, which grades every claim as established, conjectured or open, and MIO-STD-01, the conformance standard — published at working-draft status, with a clause listing what must be settled before it could be submitted anywhere.

“Who answers for what our software did?”

The newest work, and the one to read if software is already acting on your organisation’s behalf. The pursuit of ‘Goodness’ in AI — seven parts, September 2026. What has to be settled first sets out why the technical questions cannot be closed on their own, Who actually holds the controls puts five questions to a supplier or to your own organisation, and The four properties underneath is the specification the others refer back to.

“Why does the software we already pay for keep changing under us?”

What happened to your software documents the repricing rather than asserting it, and shows why signing the higher renewal is the rational decision — which is the problem. Six questions worth asking is the instrument you can put to your own organisation or to a supplier this week.

“What would we actually have to build, and what would it cost?”

The commons blueprint — ten papers, all on one page. The blueprint gives twelve things it has to do, each checkable by watching it work; eight decisions that are yours and cannot be made for you; and the four ways it fails, all documented. What it costs and What nobody has measured yet both refuse to quote a number they cannot support, and say which measurement nobody has taken.

“How do you run an organisation when software does the work?”

Running an organisation where agents do the work — including where this project’s own method failed, because one that reports only successes is not reporting. One school, one Tuesday writes the same thing out as a working day so it can be argued with; nothing in it happened.

“What could a government change, and would it bite?”

Making policy bite walks an obligation to its end and shows where New Zealand’s Privacy Act stops short — every link in the chain works, and it fails at the last one anyway. Nine changes government could make, most costing nothing. What you can actually require is on where these questions are settled in practice: procurement schedules and default settings rather than hearings.

“Will the records we are signing today still stand up?”

Why records signed today may not survive: migration protects what you sign from now on, while what is already signed becomes forgeable and cannot be re-signed, because the people who signed it may no longer exist. The four properties underneath sets out what a record has to carry to outlive its own cryptography.

“I want the underlying research.”

Paper A v4, Sovereign-Record Architecture (§4 threat model, §5 design principles, §6 implementation) with the Paper B synopsis as its empirical companion; Architectural Alignment v2.2 for the philosophical foundation, in academic, community and policymaker editions; Distributive Equity Through Structure for the worked community-scale example; and the EU Policy Brief in English and German. The glossary gives every technical term at its primary source and names the standards bodies that disagree about it.

The pursuit of ‘Goodness’ in AI

Whether an AI system is safe, fair or accurate is not a question anybody can answer on your behalf. Each of those words contains a blank, and only the organisation that will be answerable can fill it. So the goodness in the title is not a property to be located in a product and verified — it is the reader’s own, and these seven documents are instruments for finding it. They also show where it is unlikely to be found.

The argument runs: why the technical questions cannot be closed on their own, and the difference between governance that is structural and governance that is a document · who actually holds the controls — the limits, the inspection, the change and the stop · how much a system may do without a named person approving each action, stated as five declared levels · the four properties that have to be true underneath before a delegation is real rather than nominal · twelve requirements, each with a plain note on whether anything currently requires it, and eight are required nowhere · and the questions nobody has answered, published as questions rather than filled with figures that would be quoted back as estimates.

Who it is for. Anyone deciding what software may do on their organisation’s behalf: a board, a trust, a council, a partnership, a marae committee. What you can actually require is the one to hand someone working on policy. The four properties underneath is the one to hand an engineer. How much it may do unsupervised is the one to hand somebody who says this all sounds abstract.

What it does not claim. No system is asserted to do this today, including ours. The last of the six carries no figures at all, deliberately: a placeholder gets quoted back as an estimate. It publishes four open questions instead, and corrects three figures this series itself previously published. Each part carries its own sources page, its slides and a PDF.

The series page — all seven parts, sources, slides and PDFs on one page →

Argument The pursuit of ‘Goodness’ in AI · v0.2 · Sep 2026 · 18 min

What has to be settled first

Safe for what, fair by whose measure, accurate to whose tolerance? Each contains a blank only the organisation that will answer for the result can fill. Structural governance against governance by document, why measuring benefit by adoption is the trap it appears to be, and the failure this predicts — described in 1988 and shipped again in a 2025 protocol specification.

1 question parked — taken from the corpus register and checked against it on every deploy, shown whether or not they flatter

Instrument The pursuit of ‘Goodness’ in AI · v0.2 · Sep 2026 · 15 min

Who actually holds the controls

Paying for an agent is not governing it. Five questions about who holds the limits, the inspection, the change and the stop. Three vendors use the word sovereign to mean three different things, and the difference decides whether your data can be handed to a foreign authority without your agreement.

Specification The pursuit of ‘Goodness’ in AI · v0.2 · Sep 2026 · 16 min

The four properties underneath

The document the others refer back to. An identity that is not borrowed, a capability that is not ambient, authority that narrows rather than widens, and a record somebody who was not there can rely on. Each checkable by watching a system work rather than by reading a description of it.

Instrument The pursuit of ‘Goodness’ in AI · v0.2 · Sep 2026 · 13 min

How much it may do unsupervised

Five levels of permitted autonomy, from advisory to delegated, because an undeclared level cannot be audited. The strongest published objection to scales of this kind is engaged with rather than dismissed. Includes Knight Capital on 1 August 2012, and the fact that the word automated appears nowhere in the Privacy Act 2020.

Schedule The pursuit of ‘Goodness’ in AI · v0.2 · Sep 2026 · 17 min

What you can actually require

For the person who has to write a policy or a procurement schedule. Twelve requirements, each marked with whether anything currently requires it — eight of the twelve are required nowhere. What makes a violation impossible rather than merely forbidden, and why a requirement lasting one electoral term is not a requirement.

Open questions The pursuit of ‘Goodness’ in AI · v0.2 · Sep 2026 · 15 min

What nobody has measured yet

No figures, deliberately: a placeholder gets quoted back as an estimate. Four open questions instead: what happens if the money behind all this dries up, if the next step is smaller machines rather than bigger ones, if governance turns out to be the thing that actually limits it, and which arrangements could carry an answer at all. Three figures this series previously published are corrected on its sources page.

1 unevidenced · 1 question parked — taken from the corpus register and checked against it on every deploy, shown whether or not they flatter

Argument The pursuit of ‘Goodness’ in AI · v0.3 · Sep 2026 · 13 min

An invitation to become a Distributor

The seventh part, and the only one about the people who published the other six. Two addresses and one company; the dated record of what was built and when, rather than a description of it; what the six established; and the constraint that actually binds, which is not capital. Ends with the proposal and with the ways you would know it is wrong.

3 questions parked — taken from the corpus register and checked against it on every deploy, shown whether or not they flatter

The commons blueprint

AI is arriving inside the software you already pay for. Not as a purchase you evaluated. As a feature added to a contract you signed for something else, from a supplier you cannot name, on terms you were never shown.

Ten short papers on what is happening, what shared AI infrastructure has to do, what it costs, how it is run, and what a government could change to make it easier. The legal form is a co-operative, because that is what makes shared ownership work in New Zealand law — but the point is not the form. The point is that the people relying on it are the people who set its terms.

Who it is for. A practice, a firm, a school, a trust, a club, a marae, a council — anyone holding information they cannot afford to lose control of. Free to copy, adapt and build from. Each part can be read on its own.

The series page — all ten parts, sources, slides and PDFs on one page →

Part A · Essay The commons blueprint · v0.1 · Aug 2026 · 7 min

What happened to your software

The entry point to the set. The renewal quote arrives higher than last year, the plan you were on is being retired, and moving would mean re-entering four years of records and finding out in month three what else quietly depended on it. So you sign — and signing is the rational decision, which is precisely the problem. Repricing at renewal is now the market default rather than the exception, with 339 pricing and packaging changes across the largest five hundred software companies in two years. The price rise is the visible part.

1 question parked — taken from the corpus register and checked against it on every deploy, shown whether or not they flatter

Part B · Instrument The commons blueprint · v0.3 · Aug 2026 · 13 min

The Sovereignty Assessment Instrument

Six tests for whether a country has AI sovereignty, or only AI adoption — beginning with whether it can tell. A diagnostic rather than an argument: each test carries a pass condition, a stated evidence requirement, and a description of how it can appear to pass when it has not. Test 0 asks whether an organisation can even determine which of its systems perform inference, on whose model and in which jurisdiction; without it the other five are not failed but unanswerable. Applied to New Zealand in August 2026 the finding is FAIL, because the finding is the lowest score and not the average. Vendor-neutral and party-neutral, and written so that a competent person with no technical background can apply it and defend the result.

1 question parked — taken from the corpus register and checked against it on every deploy, shown whether or not they flatter

Part C · Specification The commons blueprint · v0.2 · Aug 2026 · 12 min

The blueprint

What a group of small organisations builds together, and what it has to do. Not a buying club and not a better vendor — a co-operative that owns the infrastructure its members depend on, held in place by four properties: members hold control rather than investors, members own their machines outright, the revenue may not come from member data, and a region can leave and keep working. That last one is exercised annually with a member watching and the result published either way, which is what makes the other three checkable rather than promised. Twelve capabilities follow, specified as properties rather than methods so more than one design can satisfy them and no supplier is written into the standard. Eight decisions are left to the reader, and four documented ways this fails.

3 questions parked — taken from the corpus register and checked against it on every deploy, shown whether or not they flatter

Part D · Essay The commons blueprint · v0.1 · Aug 2026 · 7 min

Someone picks up

The rest of the series is governance, ownership and infrastructure; this part is the thing itself — what happens at twenty past four when the thing that always works has stopped and a client is waiting. Three tiers: your own system on your own hardware, a person by exception, and advice rather than support. The economics live in the second one, and the ratio between the first two is a bet the essay declines to dress up: it is the largest single unknown in the design, it is measurable, and it should be published as a number from the first month. Two falsification tests, both measurable in the first months, and a section on what it does not do — including that it is not a frontier model and not fast to build.

1 question parked — taken from the corpus register and checked against it on every deploy, shown whether or not they flatter

Part E · Framework The commons blueprint · v0.4 · Aug 2026 · 15 min

Running an organisation where agents do the work

Structure, records and drawings for a body whose work is mostly done by agents — and the failures that shaped it. Four questions arrive early and none has an obvious answer: who is responsible for what an agent did, how you keep your own claims straight, how you stop the diagrams lying, and what you deliberately do badly. Organising by function fails at scale because agents generate more events than a governance function can be told about; organising by authority puts the boundary where the record already has one. It also records where the answers failed in practice, on the ground that a method reporting only its successes is not reporting.

Nothing withheld — no unevidenced claim and no parked question, generated from the corpus

Part F · Framework The commons blueprint · v0.1 · Sep 2026 · 5 min

What it costs

A costing framework rather than a costing. One number decides it — cost per site to install and sustain for five years — because a minister, a board of trustees and a funder all ask for the same figure, and cost per member per month hides the sustaining problem inside an average. Four cost pools kept deliberately separate, segments that behave differently, and risk lines priced rather than mentioned. Every figure in it is marked ILLUSTRATIVE: they are placeholders showing the shape of an arithmetic, not estimates of anything, and the document says so on every table rather than letting a placeholder travel as a quote.

2 claims not yet evidenced 1 question parked — taken from the corpus register and checked against it on every deploy, shown whether or not they flatter

Essay · Philosophy & democracy New August 2026 · EN

Wisdom, Misunderstood: What AI Demands of Democracy

Intelligence finds efficient means; wisdom judges ends — which goods conflict, what must not be traded, who pays if we are wrong. A system cannot read your intent: it infers it from what people resembling you said, and hands back something coherent, plausible and smoothed, which you experience as being understood. The argument does not require machines to be stupid or incapable, and survives their being neither. It ends where the site’s other work ends — at deliberation among strangers, at records that keep the disagreement rather than only the outcome, and at the four questions of Democratic AI°. With the philosophy at length, the sources named — the Stanford entries verified at the publisher, the rest carried from the working document and marked as such — two corrected misattributions declared, and a section on why the argument holds whether or not machines ever become conscious.

Proposal · AI governance New August 2026 · EN

Democratic AI°

A proposal, and a mark. “Democratic AI” is already in use: OpenAI’s March 2025 submission to the White House pairs it with export tiers and asks the world to build on “democratic rails” and “American rails” interchangeably; DeepMind published a majority-preference selector under the name in 2022. This proposal uses the phrase in neither sense and says so first. It offers four questions that measure how democratic a system actually is — can the people it affects govern it, contest it, refuse it, and retain authority over the knowledge it is built from? Almost nothing in service answers yes to all four, including the authors’ own system, which is scored openly at three. With the measured evidence on shared error and compute concentration, the counter-evidence that cuts against the argument, and a procurement test any agency can run in an afternoon.

Essay · Provenance August 2026 · EN

The Marks It Leaves

Roughly two in five long-form LinkedIn posts are now written entirely by a machine, and about half of everything newly published on the open web. Machine writing leaves marks, and they fall into four kinds: watermarks deliberately embedded and readable only by the vendor that wrote them, vocabulary that has shifted measurably across fifteen million scientific abstracts, structural habits that are dearer to remove than any word on a banned list, and the residue of a copy and paste. This essay sets out what each mark is worth, what it costs to erase, and who it misfires on — seven detectors flagged 61% of essays by second-language writers as machine-written, against 5% for native speakers, and rewriting the first group to sound native dropped that to under 12%. None of it can carry proof. The conclusion the evidence forces is that declaring it settles what no test can.

Essay · Attestation August 2026 · EN

The supplier’s signature

Someone asserts the organisation said a thing; the organisation says it did not, or not then. Reaching for the shared drive settles nothing, because a modified date is written by the same party making the claim. Three publicly specified mechanisms narrow that: a SHA-256 hash over a deterministic serialisation, an Ed25519 signature applied when the record is saved, and an RFC 3161 timestamp from an authority sent a fingerprint and nothing else, so it cannot know what it has dated. Signing is unconditional; dating is not. Where the authority was reachable at save time, the two together retire the story that gets used in a dispute — we wrote that last week and back-dated it. Two things they leave alone. The signing key is the supplier’s, so what a third party can check without the supplier’s help is a supplier’s signature: a platform attesting to particular bytes at a particular time, not the organisation signing its own words. And whether the approver was entitled to approve stays with the organisation’s own rules. The essay argues that is where it belongs.

Essay · Robustness New August 2026 · EN/DE/FR/MI/NL

The Least Performant AI

The French biologist Olivier Hamant argues that we are leaving the world of the mean for the world of the standard deviation, and that the fluctuating world is not something that happened to us — it is what our own optimisation produced. His answer is robustness: heterogeneity, redundancy, slowness, incoherence and margin, the whole catalogue a performance culture reads as failure. Asked what kind of AI is worth having, he says the least performant one, because a system slow enough to need checking keeps a human in the loop by construction rather than by policy. This essay tests that against infrastructure already built, and finds five design principles derived twice — once from Christopher Alexander, once from plant biology — with the corroboration arriving after the principles shipped. It also states what the framework still cannot do.

Draft Policy Proposal New June 2026 · for cross-party consensus

In Our Own Hands: a draft policy proposal on AI for Aotearoa New Zealand

A draft for cross-party consensus. The AI change is on the scale of the climate transition, and we are still early enough to choose our path. Seven common-ground commitments and a costed, three-phase pathway: keep authority here, keep sensitive information home, keep people in the decisions, and build our own capability. Offered freely for discussion and markup.

The series · 7 essays New June 2026 · EN/DE/FR/MI/NL/ES

An Alternative to Big Tech AI

Seven essays on owning the intelligence rather than switching it off — a community-owned alternative to Big Tech AI. From the off-switch and the model that stays in its lane, to board minutes that can’t be rewritten, your model behind your own walls, a Village you can run yourself, a control tower that can’t read your messages, and the one word we spent six essays earning the right to say.

Essay · World Models New June 2026 · EN/DE/FR/MI/NL

Taonga in the Latent Space

Yann LeCun left Meta to bet a billion-dollar company that today’s language models cannot reason or plan because they lack a model of the world — and that the next architecture will not be built on them. He means the physical world. This essay argues the first world worth modelling is a community: the Village already holds the signed record of a community’s state and the gate that checks an action before it runs, and lacks only the picture in between — the one that lets an AI foresee what its action would do to the people. A community-state model, with the community as kaitiaki of the model of its own world, taonga and consent as first-class factors, federated rather than concentrated. Proposed as the next architectural step, not yet shipped [the essay sets out what the Village holds today and what it does not].

Essay · AI Evolution New June 2026 · EN/DE/FR/MI/NL

Earning the Right to Propagate

How a human Village governs its own AI. In June 2026 Vincent Boucher (QUEBEC.AI & MONTREAL.AI) published a constitution for governing how institutional AI is allowed to evolve — GoalOS: The Proof-of-Evolution Constitution — and most of its primitives turned out to be ones we had already built, for human governance, and shipped. This essay reads that convergence as external validation, adopts the proof-gated promotion discipline we were missing for our own AI, refuses the blockchain the standard is built on (on sovereignty grounds its own neutrality clause permits), and adds the one gate the constitution lacks: keep the community the author. AI is the servant, not the subject.

Compliance · Governance New June 2026 · EN/DE/FR/MI/NL

Governance That Can’t Be Quietly Undone

New Zealand and Australia have both declined prescriptive AI legislation — what they have is principle (NZ’s non-binding Public Service AI Framework and voluntary Algorithm Charter; Australia’s proposed-then-shelved guardrails). This essay shows how the Village makes those soft-law principles — transparency, human oversight, auditability, data sovereignty — structurally enforced, and how a governance village and a kāhui Māori village actually run their deliberations, meetings, and votes on a tamper-evident substrate. Implemented and in-development features kept distinct.

Essay · Principle New June 2026 · EN/DE/FR/MI/NL

Sovereignty Without Dominance

Rightful authority at human scale, in the age of AI. An anchorpoint of principle that extends Alvin Wang Graylin rather than rebutting him — he is right that the AI “arms race” is a dead end — and asks Western readers to scrutinise the United States as evenly as they scrutinise China, with respect for every party and enmity toward none. Sovereignty here is not the capacity to dominate a technology but the rightful authority of a community over the systems that act on it: held at human scale, federated, never surrendered. Closes with a live exhibit from the days it was written.

Brief · Te Ao Māori New June 2026 · EN/DE/FR/MI/NL

Kaitiaki Intelligence and Mokopuna Recorder

Two prototype briefs and a reflection, from a consciously limited non-Māori standpoint. Western AI debate leads with “is it conscious?”; te ao Māori asks instead what relations an entity inhabits, whose authority it answers to, and whether it strengthens the mauri around it. Two small forms carry the argument — a place-based kaitiaki intelligence for one taonga, and a mokopuna recorder for whānau memory — where the AI assists and the people decide. Closes with the sharpest caution: borrow the relational vocabulary without devolving real authority and you reproduce the symbolic shell, not the substance.

Essay · Federation New June 2026 · EN/DE/FR/MI/NL

Federate, Don’t Align

The operational companion to The Map Has No Node for Legitimacy. If a small nation accepts it will never win the AI capacity race, what is the lowest-risk way to hold the authority it can? Read as a risk decision, three options appear — align with the American stack, align with the Chinese stack, or federate and align with neither. Only the federated mesh — of communities and of their inference — carries no irreversible tail. The argument extends to a national-scale federated Aotearoa, and names the posture: a non-aligned layer for AI.

Response · Critique New June 2026 · EN/DE/FR/MI/NL

The Map Has No Node for Legitimacy

A response to Tim Clancy and Asmeret Bier Naugle’s qualitative model of AI sovereignty. Their five-lever framing measures sovereignty as capacity — and has no node for legitimacy, for the rightful authority of the people whose data trains and steers a system. The paper argues that governance sovereignty and substrate sovereignty are separable, that rightful authority is the layer the Village platform and Tractatus framework run at today, and that this is where the actors the model’s loops exclude can actually build.

Essay · Foundational New May 2026 · EN/DE/FR/MI/NL

Held in kōrero, not collapsed to a number — plural values, living organisations, and AI

A philosophical bridge between Isaiah Berlin’s value pluralism, Christopher Alexander’s living structure, and kāhui Māori hui-based deliberation — arguing that the dominant AI-governance frame is structurally wrong twice: once on values (it collapses what is irreducibly plural into a single score), once on life (it severs the participatory loop). Source material for the §5.5 “Skill evolution” slide in the Te Kāhui Māori June 2026 briefing.

Agentic AI Framework · v1.2 New May 2026 · EN/DE/FR/MI/NL

Federated and Accountable Agentic AI: A Proposal for Aotearoa New Zealand

An independent contribution to NZ policymakers and community organisers, mirroring the structure of the People’s Republic of China’s 2026 Implementation Guidelines for intelligent agents. Six sections, 14 sub-sections, 38 numbered items, with a new §0 “Philosophical Foundations” chapter drawing on the Tractatus framework, the CARE Principles for Indigenous Data Governance, and ISO/IEC JTC 1/SC 42 standards.

Paper A · Review Draft v4 New May 2026 · EN/DE/FR/MI/NL

Sovereign-Record Architecture for Community-Scale Platforms

An alternative substrate for community-scale platforms in which sovereignty is a property of the records themselves, not a concession the operator may revoke. Cryptographic provenance, tenant-bounded policy enforcement, bilateral and bounded federation, member-driven sovereign portability, and a supervised participatory dialogue surface.

Paper B · Synopsis New May 2026 · EN/DE/FR/MI/NL · 2-page synopsis

Situated Language Layers for Minority-Language and Indigenous Communities

Empirical companion to Paper A. Per-tenant situated language layer trained on the tenant’s own corpus, governed by the tenant’s own authority, on infrastructure inside the tenant’s jurisdictional reach. Five training-discipline rules empirically derived; nine weight-modification ablation experiments motivating a strict no-weight-modification stance.

Architectural alignment · v2.2 May 2026 · Three Editions

Related surfaces

  • · What’s New — recent additions across papers and blogs.
  • · Glossary — vocabulary index with cross-references into the papers.
  • · Research Guide — three audience routes (researcher / implementer / leader) with citations into the source material.
  • · Framework Documentation — implementation specs, internal documentation, source references.
  • · Blog — short-form analysis, case studies, and threat-model commentary.