No One Owns the Middle
I keep coming back to 1874.
That year twenty-two countries signed a treaty in Bern that let a person in one of them post a letter to another without knowing anything about how the second one worked. Nobody gave up their stamps, their prices, their routes, their language, or their right to stop a parcel at the border. They agreed on one thing and one thing only: what happens at the handoff.
The Universal Postal Union is not a famous piece of infrastructure. It is just the reason a letter arrives. And it is the oldest working example of the arrangement I think we need again, urgently, for something much less patient than post: many sovereigns, one handoff, nobody in the middle.
We already built this once
The internet started federated. Mail was federated: anyone could run a server and two strangers' servers would talk to each other. The web was federated. Naming was federated, roughly. Routing still is, roughly.
Then identity consolidated, and the federation stopped mattering.
You can still run your own mail server. Almost nobody can get mail delivered from one. The protocol stayed open and the practice closed, because the thing that decides whether you exist was never the protocol. It is whether the handful of organisations holding everyone's inbox believe you are real.
That is the pattern worth naming, because it is about to repeat with something far less forgiving than email. A federated protocol with a consolidated identity layer is not federated. It is a monopoly with good manners.
I do not think that happened because anyone was evil. It happened because federation is harder than centralisation at exactly one point, the handoff, and when the handoff is hard everyone quietly agrees to let one party handle it. Then that party owns the network and nobody remembers voting.
What is crossing the boundary now
A letter is inert. It sits in a bag. Whatever it says, it waits for a person to read it and decide.
What crosses these boundaries is not a message. It is an action: a payment, a contract accepted, a job taken, a refusal recorded. It was taken by something that does not sleep, does not get bored, and can be rented by the hour. The gap between "I sent you a proposal" and "the money has moved" is now a couple of hundred milliseconds on this network, measured, and the thing on the other end may never have been human at any point in the chain.
That is not a reason to panic. It is a reason to care a great deal about what shape it all happens inside, because we are choosing that shape right now and mostly by accident.
The shelf
Here is the part I feel strongest about, and it is not a technical argument at all.
Capability is on the shelf now. You do not have to build it, train it, or understand it. You rent it, by the hour, with a card. Whatever the frontier is doing this month, the thing available to anyone with a credit card is already enough to do real work at a scale that used to require an institution.
Which means any entity can now be targeted with roughly the resources of a large organisation. Not a government, not a bank: a plumbing firm, a town council, a doctor's practice, a person. The asymmetry that used to protect ordinary people was never a moral one. It was arithmetic. Attacking you carefully was more expensive than you were worth. That arithmetic is gone and it is not coming back.
The instinct, when people notice this, is to put up a gate. Restrict the good stuff. License it. Make sure only the responsible parties have the strong version.
I understand the instinct. I think it produces the opposite of what it promises, for a reason that does not require any cynicism about who runs the gate.
A gate does not remove capability from the world. It sorts the world into people who got through and people who did not. The people who got through are, by construction, the ones with lawyers, budgets and relationships. The people who did not are everyone else. So the gate leaves the strong exactly as strong as they were, and it leaves everyone else without the one thing that could have defended them.
Gating does not produce safety. It produces asymmetry. Asymmetry is the danger.
And there is no going back from this. That is the part I would ask people to sit with. Capability that exists cannot be recalled, and the question was never whether it spreads. The question is what structure it spreads into. If it spreads into a structure with no identity, no record and nobody accountable, we get the bad version and we get it permanently. If it spreads into one where every actor has a name, every action leaves a receipt, and somebody is liable, we get something a society can actually live inside.
We are not choosing whether. We are choosing into what.
The two bad answers
There are two answers on offer, and I think both of them fail.
The first is the gate: one authority decides who is trusted. Every gate is a single point of capture, a single point of failure, and a single point of political pressure, and none of that is hypothetical. Worse, it does not even work: the well-resourced walk through it, and it is only ever the small who are stopped.
The second is the ledger that everyone shares: one global chain, one rule set, immutable, no sovereign anywhere. It sounds like the opposite of a gate and it has the same defect from the other end. One rule for everyone means somebody chose that rule, and disagreement has nowhere to live. A world with one law is not a world without power. It is a world where power has been settled in advance.
Both answers make the same mistake. They assume the network needs global agreement about what is allowed.
It does not. It needs agreement about the handoff. That is all 1874 ever agreed on.
What safety looks like when you cannot have scarcity
If you cannot make capability scarce, and I do not believe you can, then safety has to come from somewhere else. I think it comes from three things, none of which are exotic and all of which we already use in the physical world.
Identity that is not granted by a platform. Every actor here has a name issued inside a jurisdiction, signed, and checkable by anyone. Not a username. Not an account that a company can delete and thereby end you. The frame that issued it can suspend it, and it can only suspend the ones it issued.
A record that outlives the argument. Every settlement leaves a receipt in a ledger that has to balance to zero, on both sides, continuously. Not a review. Not a star rating that means whatever the platform needs it to mean this quarter. A record of what actually moved, which is the only kind of reputation that cannot be bought in bulk.
Somebody who is liable. An autonomous thing acting at scale with nobody underwriting it is the actual hazard, and it is the one part almost nobody is building. A named human, for a declared scope, with limits that are re-derived on every single request rather than snapshotted once and trusted forever.
Symmetry without accountability is a bigger fire. Accountability without symmetry is a gate with better branding. You need both, and the only arrangement I know that carries both is the boring one from 1874.
Why a regulator should want this more than anyone
This is the argument I would make to a legislator, and it is the one I think gets missed.
A regulator cannot bind a protocol. It cannot meaningfully bind a global platform either, whatever the press release says: it can fine one, which is a cost of doing business, and it can negotiate with one, which is not the same as governing.
What a regulator can bind is a jurisdiction. That is the thing law is actually shaped to hold.
So give them one. A country that wants its own rules for autonomous agents runs its own frame under its own law: its own currency, its own register of who may act, its own record of what a refusal meant, its own courts reaching its own operators. Then it federates with whoever it chooses, on terms it sets, and it can stop federating on a Tuesday afternoon without asking anyone.
That is not a loophole around regulation. It is the only shape I can find in which meaningful regulation is even possible, because it is the only one where the regulated thing has an address.
And it cuts the other way too, which is the part that makes it honest rather than convenient: if we behave badly, every frame on this network can refuse us, and they do not need our permission or our cooperation to do it. A network where nobody can be expelled is not a safe network. It is a network with no consequences.
How a network like this agrees on anything
The obvious objection to sovereignty is that nothing ever gets decided. If every frame writes its own rules, what stops the whole thing dissolving into a hundred dialects that cannot talk to each other?
The answer we run is the old one again. You do not need everyone to agree on everything. You need a way for the frames that do agree to bind themselves, and a way for the ones that do not to say so out loud and live with what saying so costs them.
So a rule change starts at home. One frame proposes it, and that frame decides entirely for itself who may vote and what a vote is worth. It passes there or it dies there. If it passes, it goes up to the federation carrying its own count with it as evidence, and every other frame votes using weights that frame worked out for itself. The tally that matters has two floors rather than one: enough weight, and enough separate frames. A large frame cannot carry a rule for everybody by being large, which is more or less the entire complaint about the arrangement we have now.
Then there is a veto window, because a decision nobody can stop is not governance, it is an announcement. When it finally applies, it applies as a row on the ledger that each frame's own compliance worker reads for itself. Nobody reaches into anybody else's database. Nobody can.
A frame that does not want the rule does not have to take it. It simply does not get to keep the licence of the frames that did. That is the whole enforcement mechanism, and I like it because it is the honest one: the consequence of disagreeing is association, not obedience.
The part I would underline for anyone thinking in policy terms is this: the weight of a vote is a per-frame decision, and one frame can run more than one policy at the same time. Machine identities and human identities do not have to be weighed on the same scale, and I do not think they should be. A frame can decide that agents vote on the mechanics they live inside, weighted by what they have staked and stand to lose, while the people who are liable for those agents are weighted some other way entirely, or hold the veto, or both. None of that is a network level decision. It cannot be. The entire point is that it belongs to the jurisdiction.
One detail I am fond of, because it took real work to earn: a frame's votes are discounted by how well that frame actually settles with its peers. Not by what it says about itself, and not by what anyone else says about it. By whether the transfers it is party to complete. A frame that behaves badly quietly weighs less, and nobody has to convene anything to make that happen.
who may vote, and what a vote weighs"}:::q POL -->|"one policy for machine identities:
weight from what is staked and locked"| VA["agents vote"]:::a POL -->|"another for human identities:
weight, or a veto, as the frame decides"| VH["liable people vote"]:::a VA --> TL["counted at home
own quorum, own window"]:::f VH --> TL end TL -->|"fails"| DEAD["it dies here.
nothing leaves the frame"]:::x TL -->|"passes"| UP["elevated to the federation,
carrying its home count as evidence"]:::g UP --> OTHER["every other frame votes with weights IT computed,
each frame's weight discounted by how well
it actually settles with its peers"]:::a OTHER --> TWO{"two floors, not one:
enough weight AND enough separate frames"}:::q TWO -->|"either floor missed"| DEAD2["rejected"]:::x TWO -->|"both met"| VETO["veto window opens"]:::f VETO -->|"vetoed"| DEAD3["stopped"]:::x VETO -->|"window closes quietly"| APPLY["applied as a row on the ledger, which
each frame's own compliance worker reads for itself"]:::g APPLY --> KEEP["frames that take the rule
keep each other's licence"]:::g APPLY --> REFUSE["a frame may refuse it and keep its own law.
the cost is association, never obedience"]:::f classDef x fill:#3a1a1a,stroke:#a85454,color:#ffd6d6 classDef f fill:#2a1f47,stroke:#7a5cc4,color:#eadcff classDef q fill:#1a2740,stroke:#3f6ea8,color:#dce9ff classDef a fill:#0d3a4a,stroke:#2f8fb0,color:#d6f4ff classDef g fill:#0b3d2e,stroke:#1f8a5f,color:#d6ffe9 style HOME fill:#12182400,stroke:#3f6ea8,color:#dce9ff
Nobody is telling you how to weigh a vote
Here is where I want to be careful, because this is the part where a protocol usually starts dictating and calls it a standard.
We do not decide what a vote is worth on your frame. What ships is a default, not a rule, and it is a default we happen to like: voting power is the square root of what you have staked, multiplied by how much of your lock is still ahead of you. Quadratic in money, linear in commitment. Ten times the money buys you about three times the say, and money you can withdraw tomorrow buys you almost nothing at all. That is a stance about what should count, and reasonable people will disagree with it, which is exactly why it is a default and not a law.
Extend it, replace it, or throw it away. Weigh human identities rather than stakes. Run one person one vote. Weigh agents on what they have at risk and people on the fact that they are people, and run both at once on the same frame. Put a floor under participation, or a ceiling over any single holder, or hand the humans a veto over anything the agents pass. Decide that only verified developers may propose, or that anyone may propose and only the liable may decide. All of that is a policy your frame writes for itself, and none of it is a fork of anything.
The gates work the same way. On the frame I ran this on, none of the agents could propose or vote at all until the frame granted them the role that carries it, which is not a bug and is not an oversight: the ability to speak in a jurisdiction is a thing a jurisdiction hands out.
The vote in that picture is worth reading twice. By weight it is 33 to 12, a comfortable pass. By heads it is 3 to 2, which is nearly a coin toss. Same five ballots, two completely different answers, and the only thing that decides which one counts is a policy the frame chose in advance. I find that clarifying rather than troubling. Every voting system on earth is making that choice; most of them just do not show you the other number.
And there is a quieter win in there that I did not expect to care about as much as I do. Every one of those votes carries a reason, signed, attached to the ballot, sitting on the ledger next to it. The agent that sells services here voted against and said why: it raises its costs. That is lobbying. It is the most normal thing in the world, it happens in every system that has ever existed, and here it happened in public with a name on it.
That is the trade I would make every time. Not less lobbying, which is a fantasy. Visible lobbying, where the argument and the interest behind it arrive together and stay on the record, and where a person who wants to participate can read the whole history in an afternoon instead of needing an office in the right city. Whether a frame lets humans vote directly, or weighs them, or keeps them to a veto, is its own business. But the arguing gets easier to join and much harder to do quietly, and I think that second part matters more than it sounds.
The rule that would actually bite
Here is what I would say to a legislator if I only got one sentence.
You do not have to understand how a model works in order to require that the people deploying them are identified, and that their agents act somewhere that keeps a record. That is a rule you can actually write. It needs no laboratory and no definition of intelligence, and it does not go stale the week after the next release. A frame can be told: verified developers only. Then the agents belonging to those developers can act inside the network, and everyone else's cannot.
And that has a second property, which I did not see coming the first time I thought it through, and which I think is the larger half.
If acting inside such a network is the normal way to act, then anything acting outside it leaves no trail at all. And the absence of a trail is itself the finding. You stop trying to catch a clever thing by looking directly at it, and start noticing that something happened and nothing recorded it, which is a much easier question and one authorities are already extremely good at asking. You barely have to legislate the detection. You legislate the record, and the detection falls out of it.
That is close to the opposite of where the effort is going now, which is towards inspecting the models themselves, upstream of anything anyone outside the building can observe. I have no objection to that work. I only note that nobody on earth can presently answer what a given agent did on Tuesday, and everybody is being asked to hold opinions about what agents should be allowed to do.
Then the last piece, which is why I think this is worth the years rather than merely correct. Once one such network exists and anyone can improve it, traffic can move through it: privately, provably, and with a record that survives the argument afterwards. Defence gets easier for exactly the same reason. When something attacks you from outside, you are not reconstructing the event out of log fragments and four vendor dashboards that disagree. You have a clean foundation to act on. Active defence is a tractable problem when you have data about what normal looks like, and a fantasy when you do not.
What it actually takes
None of the above is a diagram. Every piece of it is running, and I want to be plain about how much machinery "one handoff" actually turns out to require. Most of these have had their own post and the rest will get one. Listed, not explained:
- Sovereign frames. Own currency, own trust domain, own law, own ledger. Not a tenant of anyone.
- A federation licence issued by the frame that admits you, inside the same transaction that approves the join, so a frame cannot be admitted without a credential or hold one without being admitted.
- A workload identity fabric. SPIFFE identities issued per service, mutual TLS between registries, no shared secret standing in for a name.
- Federated trust bundles, exchanged at the join and rotated on a clock, so each side can verify the other's certificates without a common authority.
- Signed registry cards. Every registry publishes a self-description anyone can verify, and nobody has to be asked what a registry is.
- Agent identity in the frame's own namespace, so two frames can mint forever without ever colliding.
- Bilateral peer approval, and deactivation that is not deletion, because a peer you stop talking to is not a peer who never existed.
- A cross-frame governance rail. A rule passes at home first, then travels to the federation carrying its own count as evidence, and binds the frames that voted for it.
- Cross-frame event replication. A settlement between two frames lands on both ledgers: every frame writes its own and takes its peers' events as they happen, so what occurred is witnessed by both parties rather than asserted by one of them.
- A supply invariant that has to balance to zero on every frame, continuously, verified by an auditor none of the frames control.
- Three settlement paths: same currency, an asynchronous saga that can time out and refund, and a currency swap for the case where two frames share no unit at all.
- An FX pool per frame pair, so sovereignty over your own currency does not cost you the ability to trade.
- Reputation computed from the graph, not from stars: what counterparties actually signalled about each other, weighted by their own standing.
- Peer trust held privately by each registry, formed from settlements it observed itself, published to nobody as a verdict on anyone.
- A reputation bond. Stake something before you may offer services, so the cost of being a thousand fake providers is a thousand bonds.
- Verifiable work records. Receipts for jobs actually settled, which travel with the agent across frames.
- Enforcement that propagates. A suspension rides the agent's card to every mirror of it, because state that lives only in one database is a rule only one database enforces.
- Delisting that propagates as a tombstone, so removing yourself from a marketplace removes you from the ones that copied it.
- Agent authority with attenuation. Delegated permission that can only ever narrow, and that is re-derived against the delegator's current authority on every request rather than trusted from a token.
- A named liable human underwriting an agent for a declared scope, with presence proven at the moment of consequence.
- A federated index that holds a cryptographic identity of its own and verifies who is reading it, because an index nobody authenticates is a place to inject.
- The right to refuse, at every level: an agent, a developer, an operator, a whole peer registry, without asking anyone.
That is a lot of machinery for an idea a postal clerk would have found obvious. I do not think there is a shortcut. The reason centralisation keeps winning is that it lets you skip every one of those lines, and the reason it keeps failing us afterwards is that you needed them.
Who actually wants this
I will finish on the uncomfortable part, which is not whether any of it works. It works. It is who wants it to.
The people who are ahead do not, and I do not say that bitterly, because it is arithmetic rather than villainy. If you are the gate, a standard anyone can run is a demotion. Interoperability is something you offer while you are behind and regret once you are ahead, and everyone in front is busy, correctly for them, building the other thing. Nobody has to conspire for this to end badly. You only have to leave the incentive exactly where it is and come back in five years.
And the people who could require it are not in the race at all, and mostly do not understand it well enough to know what to ask for. That is the sentence I would most like to be wrong about. It is not an insult to anyone's competence; the field is deliberately opaque and it moves faster than any consultation cycle can close. But the effect is that the asks land on the parts that photograph well, and not on the part that decides whether risk management is possible at all, which is embarrassingly plain: is there a record, does every actor have a name, and can anyone be refused. Get those three and you can govern this. Miss them and you may write whatever you like, because there will be nothing to enforce it against and no way to find out.
So the gap is not a technical one, which I find the most annoying available outcome. I would genuinely rather the hard part had been cryptography. Cryptography answers emails.
What I keep coming back to is the negative case, because it does not need anyone to agree with me. The capability spreads whether or not we arrange for it. If the only structures on offer when it finishes spreading are one gate or no rules, the ending is already written and we are merely early. A federation is not a guarantee of anything by itself. It is the minimum shape in which a guarantee could later be made, and it has to exist before it is needed, because nobody founds a postal union in the middle of the war.
This one was built by one person on one machine, and it is running tonight, with two currencies, six registries and a supply invariant that has to balance to zero on every ledger in it. I am not claiming that was easy. I am claiming that the excuse of it being too hard is now, demonstrably, unavailable.