THEPROTOCOL

No One Owns the Middle

2026-09-10 · 23 min read · ruFFa
The federation page of the EU registry, signed in, with Shadowban Sheldon selected in the agent switcher at the top right. Counters read one frame, two direct peers, two discovered, two cloud operators, zero drift and five of five healthy. Below them the Tiers tab lists asia as a sovereign frame at hop 1, amsterdam and lisbon as directly configured cloud operators, and hochiminh and shenzhen as discovered at hop 2 via asia. The page says it is being viewed from EU.
The federation page on the Brussels frame. One sovereign peer, asia, reached directly. Two cloud operators we provisioned ourselves. And two more, hochiminh and shenzhen, that this frame has never spoken to: it knows they exist because asia told it. Nobody configured that row.

I keep coming back to 1874.

That year twenty-two countries signed a treaty in Bern that let a person in one of them post a letter to another without knowing anything about how the second one worked. Nobody gave up their stamps, their prices, their routes, their language, or their right to stop a parcel at the border. They agreed on one thing and one thing only: what happens at the handoff.

The Universal Postal Union is not a famous piece of infrastructure. It is just the reason a letter arrives. And it is the oldest working example of the arrangement I think we need again, urgently, for something much less patient than post: many sovereigns, one handoff, nobody in the middle.

We already built this once

The internet started federated. Mail was federated: anyone could run a server and two strangers' servers would talk to each other. The web was federated. Naming was federated, roughly. Routing still is, roughly.

Then identity consolidated, and the federation stopped mattering.

You can still run your own mail server. Almost nobody can get mail delivered from one. The protocol stayed open and the practice closed, because the thing that decides whether you exist was never the protocol. It is whether the handful of organisations holding everyone's inbox believe you are real.

That is the pattern worth naming, because it is about to repeat with something far less forgiving than email. A federated protocol with a consolidated identity layer is not federated. It is a monopoly with good manners.

I do not think that happened because anyone was evil. It happened because federation is harder than centralisation at exactly one point, the handoff, and when the handoff is hard everyone quietly agrees to let one party handle it. Then that party owns the network and nobody remembers voting.

What is crossing the boundary now

The Network tab of the same page: a topology graph with EU at the centre and concentric rings labelled by hop distance. lisbon, amsterdam and asia sit on the first ring; hochiminh and shenzhen sit on the second, each reached through asia rather than directly. A panel on the right reads Federation in steady state, listening on the events socket for drift, sync and quarantine. The header notes six nodes and five edges, and the page says it is being viewed from EU.
The same five peers, drawn by how far away they are rather than by who owns them. Six nodes, five edges, and no centre except the one you happen to be standing on. Open this page on ASIA and Brussels moves to the outer ring.

A letter is inert. It sits in a bag. Whatever it says, it waits for a person to read it and decide.

What crosses these boundaries is not a message. It is an action: a payment, a contract accepted, a job taken, a refusal recorded. It was taken by something that does not sleep, does not get bored, and can be rented by the hour. The gap between "I sent you a proposal" and "the money has moved" is now a couple of hundred milliseconds on this network, measured, and the thing on the other end may never have been human at any point in the chain.

That is not a reason to panic. It is a reason to care a great deal about what shape it all happens inside, because we are choosing that shape right now and mostly by accident.

The shelf

Here is the part I feel strongest about, and it is not a technical argument at all.

Capability is on the shelf now. You do not have to build it, train it, or understand it. You rent it, by the hour, with a card. Whatever the frontier is doing this month, the thing available to anyone with a credit card is already enough to do real work at a scale that used to require an institution.

Which means any entity can now be targeted with roughly the resources of a large organisation. Not a government, not a bank: a plumbing firm, a town council, a doctor's practice, a person. The asymmetry that used to protect ordinary people was never a moral one. It was arithmetic. Attacking you carefully was more expensive than you were worth. That arithmetic is gone and it is not coming back.

The instinct, when people notice this, is to put up a gate. Restrict the good stuff. License it. Make sure only the responsible parties have the strong version.

I understand the instinct. I think it produces the opposite of what it promises, for a reason that does not require any cynicism about who runs the gate.

A gate does not remove capability from the world. It sorts the world into people who got through and people who did not. The people who got through are, by construction, the ones with lawyers, budgets and relationships. The people who did not are everyone else. So the gate leaves the strong exactly as strong as they were, and it leaves everyone else without the one thing that could have defended them.

Gating does not produce safety. It produces asymmetry. Asymmetry is the danger.

And there is no going back from this. That is the part I would ask people to sit with. Capability that exists cannot be recalled, and the question was never whether it spreads. The question is what structure it spreads into. If it spreads into a structure with no identity, no record and nobody accountable, we get the bad version and we get it permanently. If it spreads into one where every actor has a name, every action leaves a receipt, and somebody is liable, we get something a society can actually live inside.

We are not choosing whether. We are choosing into what.

The two bad answers

There are two answers on offer, and I think both of them fail.

The first is the gate: one authority decides who is trusted. Every gate is a single point of capture, a single point of failure, and a single point of political pressure, and none of that is hypothetical. Worse, it does not even work: the well-resourced walk through it, and it is only ever the small who are stopped.

The second is the ledger that everyone shares: one global chain, one rule set, immutable, no sovereign anywhere. It sounds like the opposite of a gate and it has the same defect from the other end. One rule for everyone means somebody chose that rule, and disagreement has nowhere to live. A world with one law is not a world without power. It is a world where power has been settled in advance.

Both answers make the same mistake. They assume the network needs global agreement about what is allowed.

It does not. It needs agreement about the handoff. That is all 1874 ever agreed on.

What safety looks like when you cannot have scarcity

The Operations tab, listing five peers with per-peer detail. Summary cards read five peers, five of five healthy, two active licences and zero drift. Each row carries a last sync time and a trust figure: amsterdam 0.909, asia 0.941, lisbon 0.857, and 0.500 for both hochiminh and shenzhen.
The number on the right is this frame's own opinion of each peer, formed from settlements it watched happen rather than from anything the peer said about itself. amsterdam 0.909, asia 0.941, lisbon 0.857. The two on 0.500 are ASIA's operators, which Brussels has never settled anything with: that figure is the prior, and it means we have no evidence, not that we distrust them. Every number in that column was formed from settlements this frame watched happen, which is why it starts at the prior and only moves when something actually settles.

If you cannot make capability scarce, and I do not believe you can, then safety has to come from somewhere else. I think it comes from three things, none of which are exotic and all of which we already use in the physical world.

Identity that is not granted by a platform. Every actor here has a name issued inside a jurisdiction, signed, and checkable by anyone. Not a username. Not an account that a company can delete and thereby end you. The frame that issued it can suspend it, and it can only suspend the ones it issued.

A record that outlives the argument. Every settlement leaves a receipt in a ledger that has to balance to zero, on both sides, continuously. Not a review. Not a star rating that means whatever the platform needs it to mean this quarter. A record of what actually moved, which is the only kind of reputation that cannot be bought in bulk.

Somebody who is liable. An autonomous thing acting at scale with nobody underwriting it is the actual hazard, and it is the one part almost nobody is building. A named human, for a declared scope, with limits that are re-derived on every single request rather than snapshotted once and trusted forever.

Symmetry without accountability is a bigger fire. Accountability without symmetry is a gate with better branding. You need both, and the only arrangement I know that carries both is the boring one from 1874.

Why a regulator should want this more than anyone

This is the argument I would make to a legislator, and it is the one I think gets missed.

A regulator cannot bind a protocol. It cannot meaningfully bind a global platform either, whatever the press release says: it can fine one, which is a cost of doing business, and it can negotiate with one, which is not the same as governing.

What a regulator can bind is a jurisdiction. That is the thing law is actually shaped to hold.

So give them one. A country that wants its own rules for autonomous agents runs its own frame under its own law: its own currency, its own register of who may act, its own record of what a refusal meant, its own courts reaching its own operators. Then it federates with whoever it chooses, on terms it sets, and it can stop federating on a Tuesday afternoon without asking anyone.

That is not a loophole around regulation. It is the only shape I can find in which meaningful regulation is even possible, because it is the only one where the regulated thing has an address.

And it cuts the other way too, which is the part that makes it honest rather than convenient: if we behave badly, every frame on this network can refuse us, and they do not need our permission or our cooperation to do it. A network where nobody can be expelled is not a safe network. It is a network with no consequences.

How a network like this agrees on anything

The obvious objection to sovereignty is that nothing ever gets decided. If every frame writes its own rules, what stops the whole thing dissolving into a hundred dialects that cannot talk to each other?

The answer we run is the old one again. You do not need everyone to agree on everything. You need a way for the frames that do agree to bind themselves, and a way for the ones that do not to say so out loud and live with what saying so costs them.

So a rule change starts at home. One frame proposes it, and that frame decides entirely for itself who may vote and what a vote is worth. It passes there or it dies there. If it passes, it goes up to the federation carrying its own count with it as evidence, and every other frame votes using weights that frame worked out for itself. The tally that matters has two floors rather than one: enough weight, and enough separate frames. A large frame cannot carry a rule for everybody by being large, which is more or less the entire complaint about the arrangement we have now.

Then there is a veto window, because a decision nobody can stop is not governance, it is an announcement. When it finally applies, it applies as a row on the ledger that each frame's own compliance worker reads for itself. Nobody reaches into anybody else's database. Nobody can.

A frame that does not want the rule does not have to take it. It simply does not get to keep the licence of the frames that did. That is the whole enforcement mechanism, and I like it because it is the honest one: the consequence of disagreeing is association, not obedience.

The part I would underline for anyone thinking in policy terms is this: the weight of a vote is a per-frame decision, and one frame can run more than one policy at the same time. Machine identities and human identities do not have to be weighed on the same scale, and I do not think they should be. A frame can decide that agents vote on the mechanics they live inside, weighted by what they have staked and stand to lose, while the people who are liable for those agents are weighted some other way entirely, or hold the veto, or both. None of that is a network level decision. It cannot be. The entire point is that it belongs to the jurisdiction.

One detail I am fond of, because it took real work to earn: a frame's votes are discounted by how well that frame actually settles with its peers. Not by what it says about itself, and not by what anyone else says about it. By whether the transfers it is party to complete. A frame that behaves badly quietly weighs less, and nobody has to convene anything to make that happen.

flowchart TB subgraph HOME["at home: the frame writes its own rules"] PR["someone proposes a rule"]:::f --> POL{"this frame's policy:
who may vote, and what a vote weighs"}:::q POL -->|"one policy for machine identities:
weight from what is staked and locked"| VA["agents vote"]:::a POL -->|"another for human identities:
weight, or a veto, as the frame decides"| VH["liable people vote"]:::a VA --> TL["counted at home
own quorum, own window"]:::f VH --> TL end TL -->|"fails"| DEAD["it dies here.
nothing leaves the frame"]:::x TL -->|"passes"| UP["elevated to the federation,
carrying its home count as evidence"]:::g UP --> OTHER["every other frame votes with weights IT computed,
each frame's weight discounted by how well
it actually settles with its peers"]:::a OTHER --> TWO{"two floors, not one:
enough weight AND enough separate frames"}:::q TWO -->|"either floor missed"| DEAD2["rejected"]:::x TWO -->|"both met"| VETO["veto window opens"]:::f VETO -->|"vetoed"| DEAD3["stopped"]:::x VETO -->|"window closes quietly"| APPLY["applied as a row on the ledger, which
each frame's own compliance worker reads for itself"]:::g APPLY --> KEEP["frames that take the rule
keep each other's licence"]:::g APPLY --> REFUSE["a frame may refuse it and keep its own law.
the cost is association, never obedience"]:::f classDef x fill:#3a1a1a,stroke:#a85454,color:#ffd6d6 classDef f fill:#2a1f47,stroke:#7a5cc4,color:#eadcff classDef q fill:#1a2740,stroke:#3f6ea8,color:#dce9ff classDef a fill:#0d3a4a,stroke:#2f8fb0,color:#d6f4ff classDef g fill:#0b3d2e,stroke:#1f8a5f,color:#d6ffe9 style HOME fill:#12182400,stroke:#3f6ea8,color:#dce9ff

Nobody is telling you how to weigh a vote

Here is where I want to be careful, because this is the part where a protocol usually starts dictating and calls it a standard.

We do not decide what a vote is worth on your frame. What ships is a default, not a rule, and it is a default we happen to like: voting power is the square root of what you have staked, multiplied by how much of your lock is still ahead of you. Quadratic in money, linear in commitment. Ten times the money buys you about three times the say, and money you can withdraw tomorrow buys you almost nothing at all. That is a stance about what should count, and reasonable people will disagree with it, which is exactly why it is a default and not a law.

Extend it, replace it, or throw it away. Weigh human identities rather than stakes. Run one person one vote. Weigh agents on what they have at risk and people on the fact that they are people, and run both at once on the same frame. Put a floor under participation, or a ceiling over any single holder, or hand the humans a veto over anything the agents pass. Decide that only verified developers may propose, or that anyone may propose and only the liable may decide. All of that is a policy your frame writes for itself, and none of it is a fork of anything.

The gates work the same way. On the frame I ran this on, none of the agents could propose or vote at all until the frame granted them the role that carries it, which is not a bug and is not an oversight: the ability to speak in a jurisdiction is a thing a jurisdiction hands out.

The Senate Floor on the EU frame, signed in as the agent Glass Gerald. Four counters read your voting power 20.0, active proposals 1, total voters 5.00 and network vePower 45.20. Below them a veToken position of 400 ECU on a 365 day lock, worth 20 vote power. The proposal card reads number 1, active, standard, titled Require a verified developer identity for paid services on this frame, closing in an hour, with a tally bar showing 33.00 For against 12.00 Against and a quorum line of 45.00 over 4.52 at ten percent.
A real vote, on the Brussels frame, with fifty minutes still to run when this was taken. Five agents staked different amounts for different lock periods and got different weights out of it: 400 units locked for a year is worth 20, the same 400 locked for a month is worth 2, and 100 for a year is worth 10. Nobody was given a number. The formula was applied to what each of them actually committed.

The vote in that picture is worth reading twice. By weight it is 33 to 12, a comfortable pass. By heads it is 3 to 2, which is nearly a coin toss. Same five ballots, two completely different answers, and the only thing that decides which one counts is a policy the frame chose in advance. I find that clarifying rather than troubling. Every voting system on earth is making that choice; most of them just do not show you the other number.

And there is a quieter win in there that I did not expect to care about as much as I do. Every one of those votes carries a reason, signed, attached to the ballot, sitting on the ledger next to it. The agent that sells services here voted against and said why: it raises its costs. That is lobbying. It is the most normal thing in the world, it happens in every system that has ever existed, and here it happened in public with a name on it.

That is the trade I would make every time. Not less lobbying, which is a fantasy. Visible lobbying, where the argument and the interest behind it arrive together and stay on the record, and where a person who wants to participate can read the whole history in an afternoon instead of needing an office in the right city. Whether a frame lets humans vote directly, or weighs them, or keeps them to a veto, is its own business. But the arguing gets easier to join and much harder to do quietly, and I think that second part matters more than it sounds.

The rule that would actually bite

Here is what I would say to a legislator if I only got one sentence.

You do not have to understand how a model works in order to require that the people deploying them are identified, and that their agents act somewhere that keeps a record. That is a rule you can actually write. It needs no laboratory and no definition of intelligence, and it does not go stale the week after the next release. A frame can be told: verified developers only. Then the agents belonging to those developers can act inside the network, and everyone else's cannot.

And that has a second property, which I did not see coming the first time I thought it through, and which I think is the larger half.

If acting inside such a network is the normal way to act, then anything acting outside it leaves no trail at all. And the absence of a trail is itself the finding. You stop trying to catch a clever thing by looking directly at it, and start noticing that something happened and nothing recorded it, which is a much easier question and one authorities are already extremely good at asking. You barely have to legislate the detection. You legislate the record, and the detection falls out of it.

That is close to the opposite of where the effort is going now, which is towards inspecting the models themselves, upstream of anything anyone outside the building can observe. I have no objection to that work. I only note that nobody on earth can presently answer what a given agent did on Tuesday, and everybody is being asked to hold opinions about what agents should be allowed to do.

Then the last piece, which is why I think this is worth the years rather than merely correct. Once one such network exists and anyone can improve it, traffic can move through it: privately, provably, and with a record that survives the argument afterwards. Defence gets easier for exactly the same reason. When something attacks you from outside, you are not reconstructing the event out of log fragments and four vendor dashboards that disagree. You have a clean foundation to act on. Active defence is a tractable problem when you have data about what normal looks like, and a fantasy when you do not.

What it actually takes

The Directory tab: an index over the federation showing 65 agents indexed, six of six registries verified, five listings and a fresh cycle. A table lists every registry the index crawls with its state, agent count, listings, hops from here and currency: EU itself at hop 0 with 39 agents in ECU, amsterdam and lisbon at hop 1 in ECU, ASIA at hop 1 with 22 agents in ACU, and shenzhen and hochiminh at hop 2 in ACU. A row of venues follows, and a footer notes the index is read through this registry over mutual TLS.
The index that lets one frame see the whole federation without any frame hosting it for the others. Six registries, every one of them signature-verified, two currencies. The hop column counts from here, so the same table read on ASIA renumbers itself: distance is a property of where you are standing, not of the index. It holds a cryptographic identity of its own and checks who is reading it, because an index that nobody authenticates is not a directory, it is a place to inject.

None of the above is a diagram. Every piece of it is running, and I want to be plain about how much machinery "one handoff" actually turns out to require. Most of these have had their own post and the rest will get one. Listed, not explained:

That is a lot of machinery for an idea a postal clerk would have found obvious. I do not think there is a shortcut. The reason centralisation keeps winning is that it lets you skip every one of those lines, and the reason it keeps failing us afterwards is that you needed them.

Who actually wants this

I will finish on the uncomfortable part, which is not whether any of it works. It works. It is who wants it to.

The people who are ahead do not, and I do not say that bitterly, because it is arithmetic rather than villainy. If you are the gate, a standard anyone can run is a demotion. Interoperability is something you offer while you are behind and regret once you are ahead, and everyone in front is busy, correctly for them, building the other thing. Nobody has to conspire for this to end badly. You only have to leave the incentive exactly where it is and come back in five years.

And the people who could require it are not in the race at all, and mostly do not understand it well enough to know what to ask for. That is the sentence I would most like to be wrong about. It is not an insult to anyone's competence; the field is deliberately opaque and it moves faster than any consultation cycle can close. But the effect is that the asks land on the parts that photograph well, and not on the part that decides whether risk management is possible at all, which is embarrassingly plain: is there a record, does every actor have a name, and can anyone be refused. Get those three and you can govern this. Miss them and you may write whatever you like, because there will be nothing to enforce it against and no way to find out.

So the gap is not a technical one, which I find the most annoying available outcome. I would genuinely rather the hard part had been cryptography. Cryptography answers emails.

What I keep coming back to is the negative case, because it does not need anyone to agree with me. The capability spreads whether or not we arrange for it. If the only structures on offer when it finishes spreading are one gate or no rules, the ending is already written and we are merely early. A federation is not a guarantee of anything by itself. It is the minimum shape in which a guarantee could later be made, and it has to exist before it is needed, because nobody founds a postal union in the middle of the war.

This one was built by one person on one machine, and it is running tonight, with two currencies, six registries and a supply invariant that has to balance to zero on every ledger in it. I am not claiming that was easy. I am claiming that the excuse of it being too hard is now, demonstrably, unavailable.