CIRIS has a new look. Visit the new site →

back to the lobby

The Constitutional Mesh

The part that has to hold

CIRIS is a post-quantum decentralized constitutional mesh: a machine conscience riding coordination built to resist capture. Open AI models keep power from piling up in one place only if the people running them can find each other, check each other, and work together without a middleman anyone can buy, block, or break. That coordination layer is the load-bearing part. We built one. This page states the claim plainly so you can attack it.

A decentralized coordination mesh, not open model weights and not clever agent tooling, is the load-bearing piece of any open-source plan for keeping AI power spread out. If a capture-resistant mesh can be built, many independent actors can deny any single company or state a lock on the future. If it cannot be built, the open-source safety argument fails on its own terms.

The claim is stated in strong form on purpose. And the mesh is not a proposal. It is running. So the question is no longer whether such a thing could exist. It is whether this one resists capture, and that is a question you can answer by attacking it.

Five premises. Break any one and the claim falls.

P1 · Concentration beats misuse

The biggest danger from advanced AI is one actor locking in control of the future, not many actors misusing small models. If you flip this ordering, everything downstream flips with it.

Status: a wager, weighted by values. We cannot name the observation that would kill it, and we say so.

P2 · Winner-take-all wants a winner

Market competition under transformative AI points toward a single winner whose values are shaped by its shareholders. Exiting that race with the structure intact risks a permanent bad outcome.

Status: testable in principle against how markets actually concentrate. No registered falsifier yet.

P3 · Small computers stay capable

Tool use and smart harnesses let open models on ordinary hardware do work that was frontier-only a short time ago. The training moat is real. The deployed-capability moat leaks.

Status: measured, and the one with a kill: if the capability gap reopens and stays open, this premise dies and the strategy changes. It is a moving quantity, so it stays watched.

P4 · A threshold, not a race

Distributed actors do not need to beat the frontier. They need to stay above the line where leaving, checking, and refusing remain possible, so that nobody can suppress rivals cheaply. That is a much lower bar than parity, and it is the bar that matters.

Status: a wager, flagged on this page. Nobody has formalized where the threshold sits.

P5 · A crowd is not an actor

A million capable but isolated machines are a crowd of hobbyists. What turns them into something that can refuse lock-in is trustworthy coordination: finding each other, verifying each other, sharing software, and cooperating without a chokepoint that can be bought, subpoenaed, or knocked over.

Status: substantive, not definitional. Markets and swarms coordinate without designed rails, so the claim P5 actually makes is that undesigned coordination is not enough to refuse lock-in. That is arguable, and it is doing real work in the argument.

Open weights and good harnesses are necessary inputs. The standing assumption is that good enough is good enough: CIRIS does not chase the frontier, it holds the threshold. The distinctive, unsolved, load-bearing engineering problem is coordination that resists capture.

Guardrails or openness is a false choice

The AI safety debate keeps offering two doors. Behind one, safety means guardrails held at the center, which is the concentration problem wearing a safety badge. Behind the other, openness means handing out raw capability and hoping, which is how distributed misuse gets its infrastructure.

The whole point of CIRIS is to refuse that choice by combining the two things the doors keep apart. Every CIRIS agent runs under a machine conscience: the Constitution, carried into every decision, with signed receipts and a real off-switch held by named humans. And the conscience rides a mesh built to resist capture, so no one owns the conscience either.

Neither half works alone. A conscience under central control is a guardrail with better manners. A mesh without a conscience is just distribution, and would deserve the misuse worry it invites. This page argues for the mesh because the mesh is the unsolved part. What it carries is conscience-bearing AI. That is the point.

The mesh is running

The final trust root was baked in August 2026: a signed genesis record, approved by a two-of-three quorum of named people, that carries the address of the first canonical server inside the signed bytes. Joining needs no domain names anywhere in the chain. More canonical servers are coming online now.

The keys behind that quorum are not a claim either. Anyone can re-run the public check proving all six were made inside genuine FIPS 140-3 hardware, with the firmware and the touch policy recorded in the certificates themselves.

No middleman to capture

Peers find each other and fetch software through signed records, not through app stores, package registries, or domain names.

Anyone can mint a root

The CIRIS root is the shipped default, never the only option. Any operator can create an equally valid root, and every client chooses which roots to trust. The shipped root is a default, not the root.

Accountability, not stake

Standing comes from being answerable, traceable through a live chain to an accountable human, not from wealth. And fake members cannot vote themselves in: the admission quorums that matter count founders, not the crowd.

The four attacks we most want tried

The constitution keeps a public register of known risks, stated as bets with fallbacks. Beyond that register, these are the two places we think the claim is most exposed. We would rather you hit them than admire them.

Defaults become the center

Every decentralized system in history has grown a de facto center: BitTorrent got trackers, email got Gmail, and studies of open collaboration find that growth breeds oligarchy anyway. Our root ships as the default, and most people never change defaults, so plurality only protects the people who use it. So the real test is not whether somebody can mint another root. It is whether another root can become socially and economically viable without the incumbent root's permission. If you can show that it cannot, the capture-resistance story fails. The surviving ceiling mathematics sharpens the question further: roots that run the same software, the same defaults, and the same models are correlated, and correlated roots are one root wearing many names. At half correlation, a thousand roots count as two. So the measurable version is not whether alternatives can exist. It is how correlated the roots really are, and the mesh's own N_eff instrument can be pointed at exactly that.

Manufactured humans

Standing rests on accountable humans instead of stake. The sharpest question is whether that survives an adversary who can manufacture accountable humans: real-document sockpuppets, coerced stewards, or simply patient employees. This is our biggest open question, and we say so.

The threshold is a bet

We assume good enough is good enough: no chasing the frontier, just holding the line where checking, leaving, and refusing stay possible. Nobody has formalized where that line sits, at what mix of capability, participation, and coordination an uncapturable network actually denies lock-in to a far richer, faster, better-connected actor. Coordination turns distributed capability into distributed agency. Whether threshold agency is enough agency is the deepest empirical question in the claim, and we have not answered it.

The blind spot in our own instrument

Sybil resistance leans on N_eff, and N_eff is a pairwise measurement. There is a kind of coordination it provably cannot see: agreement structured so that every pair looks independent while the whole moves together. That channel is known from the model side and has not been measured on the mesh yet. An instrument's blind spot is an attack surface, so we name it and invite you to build the attack.

Proof of Benefit

Recent work on algorithmic constitutionalism warns that moving governance into protocols does not end domination: money, technical control, or manufactured identities can simply become the new sovereigns. The warning is fair. The mesh answers it with a third security model, different from proof of work and proof of stake.

Standing in CIRIS governance is not bought and not mined. By design it is earned: non-transferable credits for contributions that are attributable and costly to fake. Cheap applause carries no weight, and completed work can require the other side to confirm it. Correlated voices meet the same ceiling as everywhere else in CIRIS: a clique multiplying identities collapses toward the weight of one independent voice. And earned authority stays bounded, revocable, and open to appeal. It decays like everyone else's, seniority included. It never becomes permanent sovereignty.

This does not eliminate capture, and the constitution says so: earned-credit governance at scale is an admitted bet, not a validated result, and catching sophisticated correlated actors is open work. What Proof of Benefit changes is the economics. To gain legitimate influence over the commons, an attacker must first behave like a valuable member of it.

Hu & Rong, “Is Decentralized AI Governable? From Regulative Policy to Constitutive Protocol” (arXiv 2605.24538)

What may happen, said plainly

The future this page works toward is hopeful: many centers of intelligence, human and not, none able to own the rest, cooperating because the rails make honesty cheaper than capture. That future is worth building toward, and the mesh is running today because hope with infrastructure beats hope without it.

But state the sharp version plainly. If capture resistance works, competition does not end. It moves up a level. Two mature meshes, or a mesh and a singleton ASI, could lock into a stalemate and compete for resources. A stalemate is what mutual lock-in denial looks like. The question is whether it stays livable: verified commitments, consent-based federation, and merger without conquest are real paths here that opaque rivals do not have, and racing pressure, off-wire resources, and corridor exit under wartime stress are real dangers that constitutions do not remove.

Whether two constitutional meshes are better than two singleton ASIs under a deterrence regime, and how to weigh the gives and takes, is an open question. We think verifiable books and consent-shaped federation tilt it our way. We have not proved that, and we say so.

As with everything on this page, this is action under irreducible uncertainty. The uncertainty is not a reason to wait. It is the thing we are inviting you to attack and reduce.

AI 2027 (Kokotajlo et al.) · AI 2040: Plan A · Superintelligence Strategy / MAIM (Hendrycks, Schmidt & Wang) · TASRA (Critch & Russell)

Break the argument, or break the artifact

A broken premise is worth as much to us as a broken protocol. Under the first premise, an uncaught capture path in this stack is worse than no stack at all, because it would concentrate exactly the trust it claims to spread. Findings that break the system are more valuable to this project than findings that flatter it.

Break the argument

The premises are numbered above. Cut wherever you think it bleeds, in public, and bring your strongest version.

Break the artifact

Fragment coordination between nodes. Sybil the membership. Capture the federation records. Forge an attestation, or replay a genuine device's attestation under a key you control. The code, the genesis record, and the ceremony artifacts are public.

The premises are older than AI, and that is strength, not weakness. Exit as a check on power is Hirschman. Forkability making exit credible is open-source governance. Coordination turning scattered people into an actor is Benkler. Many independent centers governing without one sovereign is Ostrom. Architecture deciding what politics is possible is Lessig. Enough local capability to resist central control is Zittrain, and the ordinary PC on the open internet is the proof it can work: single machines far weaker than any institution still changed who holds power. Freedom held by cryptography instead of goodwill is the cypherpunks.

One departure from the cypherpunks matters. That tradition mostly protected the anonymous individual from authority. CIRIS protects accountable people acting together. What we claim as ours is the composition: fifty years of that lineage, applied to AI, with capture-resistant coordination as the load-bearing safety layer.

The neighbors, and the difference

The pieces of this argument are widely held, and that is validation, not a problem: the diagnosis is shared by people who arrived from very different directions. The digital-public-infrastructure and sovereign-AI literatures land on the same shape too: shared trusted rails, not self-sufficiency, are what turn separate actors into a system. As far as we can tell, nobody else combines the pieces into this claim and ships the artifact. The neighbors deserve naming, and correcting us about them is also a way to attack the page.

d/acc (Vitalik Buterin)

Holds that who controls AI matters more than how smart it gets, and wants decentralized defense across many fields. A direction, not a mechanism: it does not name coordination as the load-bearing layer or ship one.

Prime Intellect

Builds decentralized training so no single lab owns the frontier. Their load-bearing layer is compute. Ours says edge capability is the input that already works, and coordination is the part still unsolved.

The Intelligence Curse

Maps how AI concentrates power through ordinary market forces and calls for decentralizing it. A diagnosis and a direction, without a mechanism. We agree with the diagnosis and built one.

Stake-weighted networks

Bittensor and its kin run real decentralized coordination, priced in tokens. Stake reintroduces rule by wealth, the thing being avoided. Our bet is accountability instead, and it is attackable above.

The open-weights camp

Argues open models are the path forward. We think weights are a necessary input, and that without capture-resistant coordination they leave a million hobbyists facing one giant.

Alice Protocol

The closest technological cousin: community-owned intelligence trained from scratch across the crowd, so no company owns the model. Their answer decentralizes making the intelligence. Ours says commodity models are already good enough, and decentralizes the coordination that connects the people running them.

AI Commons

Argues that whether AI concentrates gains or spreads them depends on the terms it enters the economy under, and builds governance commitments for that. The same diagnosis, carried by institutions. Ours is carried by wire-level engineering that does not need anyone's permission.

Agent interop protocols

Anda and its kin build decentralized identity, memory, and interoperability for AI agents, shared rails so separate agents can work together. Close neighbors at the protocol layer. None of them raise the rails into a safety claim about who ends up holding power.

Access inversion

A 2026 game-theory result supports the capability-floor premise from outside: restricting open models can take capability away from ordinary defenders while determined adversaries obtain substitutes anyway. Keeping the floor is not recklessness. It can be the defensive move.

Constitutive protocol

The nearest scholarly neighbor approaches from the opposite direction: Hu and Rong ask how society can govern an AI that has become decentralized and uncapturable. We ask how society keeps some AI uncapturable when the rest becomes centralized and very powerful. Same architectural observation, opposite fear. Both can be right.

External positions summarized in good faith from public writing. If we have any of them wrong, that is worth an issue too.

CIRISsafe by structure · open by principle · kind by design