<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Blog on Scaling Trust Community</title><link>/blog/</link><description>Recent content in Blog on Scaling Trust Community</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 16 Sep 2026 10:00:00 +0100</lastBuildDate><atom:link href="/blog/index.xml" rel="self" type="application/rss+xml"/><item><title>Update on the Scaling Trust Arena</title><link>/blog/update-on-the-scaling-trust-arena/</link><pubDate>Wed, 16 Sep 2026 10:00:00 +0100</pubDate><guid>/blog/update-on-the-scaling-trust-arena/</guid><description>&lt;link rel=stylesheet href=arena.css>
&lt;style>
.arena-heads-up {
box-sizing: border-box;
width: 100%;
max-width: 640px;
margin: 1.75rem 0;
padding: 1.1rem 1.25rem;
border: 1px solid rgba(0, 178, 161, 0.35);
border-left: 4px solid var(--teal);
border-radius: 4px;
background: rgba(0, 178, 161, 0.06);
}
.arena-heads-up p {
width: auto;
margin: 0;
color: var(--ink);
font-style: normal;
}
.arena-heads-up ul {
margin: 0.75rem 0 0 1.25rem;
padding: 0;
}
.arena-heads-up li {
margin: 0.4rem 0;
}
.arena-heads-up .arena-heads-up__label {
margin-bottom: 0.35rem;
color: #007f74;
font-family: var(--sans);
font-size: 0.85rem;
font-weight: 600;
letter-spacing: 0.08em;
text-transform: uppercase;
}
figure.arena-economy-figure {
width: 85%;
max-width: 85%;
margin-right: auto;
margin-left: auto;
}
&lt;/style>
&lt;p>&lt;a href="https://aria.org.uk/opportunity-spaces/trust-everything-everywhere/scaling-trust" target="_blank" rel="noopener noreferrer">Scaling Trust&lt;/a> is a £50 million R&amp;amp;D programme actively funding the fundamental research and open-source infrastructure that enables secure, scalable multi-principal multi-agent coordination across digital and physical worlds.&lt;sup id="fnref:1">&lt;a href="#fn:1" class="footnote-ref" role="doc-noteref">1&lt;/a>&lt;/sup>&lt;/p></description><content:encoded><![CDATA[<link rel=stylesheet href=arena.css>
<style>
.arena-heads-up {
  box-sizing: border-box;
  width: 100%;
  max-width: 640px;
  margin: 1.75rem 0;
  padding: 1.1rem 1.25rem;
  border: 1px solid rgba(0, 178, 161, 0.35);
  border-left: 4px solid var(--teal);
  border-radius: 4px;
  background: rgba(0, 178, 161, 0.06);
}
.arena-heads-up p {
  width: auto;
  margin: 0;
  color: var(--ink);
  font-style: normal;
}
.arena-heads-up ul {
  margin: 0.75rem 0 0 1.25rem;
  padding: 0;
}
.arena-heads-up li {
  margin: 0.4rem 0;
}
.arena-heads-up .arena-heads-up__label {
  margin-bottom: 0.35rem;
  color: #007f74;
  font-family: var(--sans);
  font-size: 0.85rem;
  font-weight: 600;
  letter-spacing: 0.08em;
  text-transform: uppercase;
}
figure.arena-economy-figure {
  width: 85%;
  max-width: 85%;
  margin-right: auto;
  margin-left: auto;
}
</style>
<p><a href="https://aria.org.uk/opportunity-spaces/trust-everything-everywhere/scaling-trust" target="_blank" rel="noopener noreferrer">Scaling Trust</a> is a £50 million R&amp;D programme actively funding the fundamental research and open-source infrastructure that enables secure, scalable multi-principal multi-agent coordination across digital and physical worlds.<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup></p>
<p>At the core of the programme is the “Arena”: a cyber-physical environment to evaluate progress towards this goal by: (1) measuring the state of the art in multi-principal multi-agent coordination under adversarial pressure, (2) observing emergent secure agentic interactions, and (3) evidencing critical failure modes.</p>
<p>The Arena is an experimental testbed for secure agentic coordination:<sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup> a platform for hosting public competitions, where competitors will submit their best agentic systems to be tested and interact with one another. Top performers are rewarded out of a multi-million pound prize pool. You will find below more details on what the Arena is, and key design decisions we’ve made.</p>
<div class=arena-heads-up>
  <p><span class=arena-heads-up__label>Summary of updates</span></p>
  <ul>
    <li><strong>Arena partners:</strong> Following an <a href="https://aria.org.uk/opportunity-spaces/trust-everything-everywhere/scaling-trust/arena">open call</a>, we are excited to be building the Arena with <a href="https://andonlabs.com/">Andon Labs</a>, <a href="https://bt6.gg">BT6</a> and <a href="https://amododesign.com/">Amodo Design</a> (subject to contract and negotiation).</li>
    <li><strong>Roadmap:</strong> The Arena will be a physical space in the UK and is set to go live in early 2027 (see more below).</li>
    <li><strong>Initial spec:</strong> An <a href="https://arena.scalingtrust.org.uk/docs/spec">initial spec draft</a> is out, and we would love your feedback on the current design.</li>
    <li><strong>Register your interest:</strong> We have opened <a href="https://docs.google.com/forms/d/e/1FAIpQLSdgVlG-WsorW2-D_lt4Bvxhbrn0GnH0B-vrXtoo8Kc9U7JnIA/viewform">registration of interest</a> for testing and participating in the Arena.</li>
  </ul>
</div>
<p><em>Disclaimer: We plan to work with the garage door up. This post reflects our current direction and the parts of the Arena that are sufficiently developed to help prospective participants prepare. Some operational details are still being tested or approved; we will provide an update on these before teams need to act on them.</em></p>
<h2 id="what-were-building">What we’re building</h2>
<figure class=fullwidth><div class=arena-hero><div class="arena-fig arena-hero-scene"><svg viewBox="0 0 780 440" aria-label="Isometric sketch of the Arena economy: autonomous organizations trading inside a bounded space, shopfronts facing customers, shared infrastructure, a customs gate, and a red team probing for weaknesses">
<defs>
<marker id="ar-ind" viewBox="0 0 10 10" refX="8" refY="5" markerWidth="5.5" markerHeight="5.5" orient="auto-start-reverse"><path d="M0 0 10 5 0 10z" fill="#3a3a78"/></marker>
<marker id="ar-red" viewBox="0 0 10 10" refX="8" refY="5" markerWidth="5.5" markerHeight="5.5" orient="auto"><path d="M0 0 10 5 0 10z" fill="#8b1a1a"/></marker>
</defs>
<polygon points="165,330 615,330 545,150 235,150" fill="#ebe4d0" stroke="#bbb5a0" stroke-width=".6"/>
<g stroke="#d2cab2" stroke-width=".4" fill="none" opacity=".6"><line x1="297" y1="150" x2="255" y2="330"/><line x1="359" y1="150" x2="345" y2="330"/><line x1="421" y1="150" x2="435" y2="330"/><line x1="483" y1="150" x2="525" y2="330"/><line x1="217.5" y1="195" x2="562.5" y2="195"/><line x1="200" y1="240" x2="580" y2="240"/><line x1="182.5" y1="285" x2="597.5" y2="285"/></g>
<path d="M225 142 L191 231 M178.5 265 L150 340 M150 340 L290 340 M370 340 L430 340 M510 340 L630 340 M630 340 L555 142 L225 142" fill="none" stroke="#2a2a3a" stroke-width="2" stroke-linecap="round" opacity=".8"/>
<text x="390" y="132" text-anchor="middle" font-family="Jost, Inter, sans-serif" font-size="10" font-weight="600" letter-spacing=".25em" fill="#999">THE ARENA</text>
<circle cx="191" cy="231" r="3" fill="#2a2a3a"/><circle cx="178.5" cy="265" r="3" fill="#2a2a3a"/>
<line x1="191" y1="231" x2="178.5" y2="265" stroke="#8b1a1a" stroke-width="2.5" stroke-dasharray="5,4" opacity=".85"/>
<g><polygon points="120,218 126,208 160,208 154,218" fill="#e8e8ee" stroke="#2a2a3a" stroke-width=".7"/><polygon points="154,218 160,208 160,236 154,246" fill="#dcdce4" stroke="#2a2a3a" stroke-width=".7"/><rect x="120" y="218" width="34" height="28" fill="#f9f9f9" stroke="#2a2a3a" stroke-width=".8"/><rect x="126" y="226" width="22" height="7" rx="1" fill="#2a2a3a"/><circle cx="130" cy="240" r="1.5" fill="#8b1a1a" opacity=".8"/></g>
<g class="arena-crate"><polygon points="108,240 122,240 122,250 108,250" fill="#c4a882" stroke="#a08860" stroke-width=".5"/><polygon points="108,240 113,236 127,236 122,240" fill="#d4b892" stroke="#a08860" stroke-width=".5"/><polygon points="122,240 127,236 127,246 122,250" fill="#b09870" stroke="#a08860" stroke-width=".5"/></g>
<g><polygon points="252,148 268,148 268,176 252,176" fill="#2a2a3a" stroke="#1a1a28" stroke-width=".6"/><circle cx="257" cy="154" r="1.3" fill="#00b2a1"/><circle cx="257" cy="161" r="1.3" fill="#00b2a1"/><circle cx="257" cy="168" r="1.3" fill="#00b2a1" opacity=".5"/><line x1="282" y1="176" x2="282" y2="148" stroke="#2a2a3a" stroke-width="1.5"/><circle cx="282" cy="146" r="2" fill="#3a3a78"/><g stroke="#3a3a78" stroke-width=".8" fill="none" opacity=".5"><path d="M277 141q5-6 10 0"/><path d="M273 137q9-10 18 0"/></g></g>
<g><polygon points="478,152 486,144 536,144 528,152" fill="#e8e8ee" stroke="#2a2a3a" stroke-width=".7"/><polygon points="528,152 536,144 536,170 528,178" fill="#dcdce4" stroke="#2a2a3a" stroke-width=".7"/><rect x="478" y="152" width="50" height="26" fill="#f9f9f9" stroke="#2a2a3a" stroke-width=".8"/><rect x="490" y="158" width="26" height="14" fill="#f9f9f9" stroke="#2a2a3a" stroke-width=".7"/><path d="M490 158 L503 167 L516 158" fill="none" stroke="#2a2a3a" stroke-width=".7"/></g>
<g><polygon points="462,172 474,172 474,180 462,180" fill="#c4a882" stroke="#a08860" stroke-width=".5"/><polygon points="462,172 466,169 478,169 474,172" fill="#d4b892" stroke="#a08860" stroke-width=".5"/><polygon points="474,172 478,169 478,177 474,180" fill="#b09870" stroke="#a08860" stroke-width=".5"/></g>
<g stroke="#2a2a3a" stroke-width="1.1" fill="none" stroke-linecap="round"><circle cx="400" cy="178" r="3.5" fill="#f9f9f9"/><path d="M395.5 176a4.5 4.5 0 0 1 9 0z" fill="#c08a3e" stroke="#a06a20" stroke-width=".5"/><line x1="400" y1="181.5" x2="400" y2="192"/><line x1="400" y1="192" x2="396" y2="199"/><line x1="400" y1="192" x2="404" y2="199"/><line x1="400" y1="185" x2="394" y2="189"/><line x1="400" y1="185" x2="406" y2="188"/></g>
<g><polygon points="330,172 336,164 382,164 376,172" fill="#e8e8ee" stroke="#2a2a3a" stroke-width=".7"/><polygon points="376,172 382,164 382,188 376,196" fill="#dcdce4" stroke="#2a2a3a" stroke-width=".7"/><rect x="330" y="172" width="46" height="24" fill="#f9f9f9" stroke="#2a2a3a" stroke-width=".8"/><rect x="336" y="180" width="8" height="16" fill="#00b2a1" opacity=".85"/><rect x="352" y="178" width="16" height="8" fill="#dde8f4" stroke="#6a90a8" stroke-width=".5"/></g>
<g><ellipse cx="396" cy="196" rx="6" ry="3" fill="#2a2a3a"/><path d="M391 195a5 3.5 0 0 1 10 0z" fill="#3d3d50" stroke="#2a2a3a" stroke-width=".5"/></g>
<g><polygon points="250,252 258,244 316,244 308,252" fill="#e8e8ee" stroke="#2a2a3a" stroke-width=".8"/><polygon points="308,252 316,244 316,274 308,282" fill="#dcdce4" stroke="#2a2a3a" stroke-width=".8"/><rect x="250" y="252" width="58" height="30" fill="#f9f9f9" stroke="#2a2a3a" stroke-width=".9"/><rect x="258" y="264" width="10" height="18" fill="#00b2a1" opacity=".9"/><rect x="278" y="260" width="18" height="10" fill="#dde8f4" stroke="#6a90a8" stroke-width=".6"/></g>
<g><ellipse cx="330" cy="282" rx="7" ry="3" fill="#2a2a3a"/><line x1="330" y1="280" x2="324" y2="262" stroke="#2a2a3a" stroke-width="2.5" stroke-linecap="round"/><circle cx="324" cy="262" r="2.5" fill="#3a3a78"/><line x1="324" y1="262" x2="334" y2="250" stroke="#2a2a3a" stroke-width="2" stroke-linecap="round"/><path d="M334 250l4-3M334 250l5 1" stroke="#2a2a3a" stroke-width="1.2" fill="none" stroke-linecap="round"/></g>
<g><polygon points="415,238 423,230 481,230 473,238" fill="#e8e8ee" stroke="#2a2a3a" stroke-width=".8"/><polygon points="473,238 481,230 481,260 473,268" fill="#dcdce4" stroke="#2a2a3a" stroke-width=".8"/><rect x="415" y="238" width="58" height="30" fill="#f9f9f9" stroke="#2a2a3a" stroke-width=".9"/><rect x="423" y="250" width="10" height="18" fill="#8b1a1a" opacity=".9"/><rect x="443" y="246" width="18" height="10" fill="#f4dddd" stroke="#a86a6a" stroke-width=".6"/></g>
<g><rect x="489" y="244" width="20" height="22" fill="#f9f9f9" stroke="#2a2a3a" stroke-width="1"/><line x1="491" y1="252" x2="507" y2="252" stroke="#2a2a3a" stroke-width="1"/><line x1="499" y1="252" x2="499" y2="257" stroke="#2a2a3a" stroke-width="1"/><rect x="495" y="258" width="8" height="6" fill="#00b2a1" opacity=".8"/></g>
<line x1="312" y1="264" x2="412" y2="254" class="arena-trade" stroke="#3a3a78" stroke-width="1.1" marker-start="url(#ar-ind)" marker-end="url(#ar-ind)" opacity=".8"/>
<line x1="436" y1="234" x2="374" y2="202" class="arena-trade" stroke="#3a3a78" stroke-width="1.1" marker-start="url(#ar-ind)" marker-end="url(#ar-ind)" opacity=".8"/>
<g><rect x="352" y="240" width="10" height="13" rx="1" fill="#f9f9f9" stroke="#3a3a78" stroke-width=".7"/><line x1="354.5" y1="244" x2="359.5" y2="244" stroke="#3a3a78" stroke-width=".6" opacity=".6"/><line x1="354.5" y1="247" x2="359.5" y2="247" stroke="#3a3a78" stroke-width=".6" opacity=".6"/><line x1="354.5" y1="250" x2="357.5" y2="250" stroke="#3a3a78" stroke-width=".6" opacity=".6"/></g>
<text x="398" y="214" font-family="Jost, Inter, sans-serif" font-size="9" font-weight="600" fill="#3a3a78">£</text>
<g stroke="#8b1a1a" stroke-width="1.2" fill="none" stroke-linecap="round"><circle cx="575" cy="240" r="3.5" fill="#f9f9f9"/><line x1="575" y1="243.5" x2="575" y2="255"/><line x1="575" y1="255" x2="571" y2="262"/><line x1="575" y1="255" x2="579" y2="262"/><line x1="575" y1="247" x2="569" y2="251"/><line x1="575" y1="247" x2="581" y2="250"/></g>
<rect x="580" y="251" width="9" height="6" rx="1" fill="#2a2a3a"/>
<path d="M568 248Q520 230 482 244" class="arena-probe" fill="none" stroke="#8b1a1a" stroke-width="1.1" stroke-dasharray="3,3" marker-end="url(#ar-red)"/>
<g transform="translate(495,190)"><g class="arena-bot"><rect x="-8" y="-6" width="16" height="9" rx="2" fill="#2a2a3a"/><circle cx="-5" cy="4" r="2.5" fill="#1a1a28"/><circle cx="5" cy="4" r="2.5" fill="#1a1a28"/><rect x="-5" y="-12" width="10" height="7" fill="#c4a882" stroke="#a08860" stroke-width=".5"/><circle cx="0" cy="-1.5" r="1.2" fill="#00b2a1"/></g></g>
<g><rect x="295" y="318" width="66" height="34" fill="#f9f9f9" stroke="#2a2a3a" stroke-width=".9"/><rect x="313" y="328" width="30" height="16" rx="1" fill="#2a2a3a"/><circle cx="306" cy="334" r="1.5" fill="#00b2a1"/><g stroke="#0a8a7c" stroke-width=".4"><polygon points="291,309 302,309 305,321 294,321" fill="#00b2a1" opacity=".85"/><polygon points="302,309 313,309 316,321 305,321" fill="#f9f9f9"/><polygon points="313,309 324,309 327,321 316,321" fill="#00b2a1" opacity=".85"/><polygon points="324,309 335,309 338,321 327,321" fill="#f9f9f9"/><polygon points="335,309 346,309 349,321 338,321" fill="#00b2a1" opacity=".85"/><polygon points="346,309 357,309 360,321 349,321" fill="#f9f9f9"/><polygon points="357,309 368,309 371,321 360,321" fill="#00b2a1" opacity=".85"/></g></g>
<g><rect x="435" y="318" width="66" height="34" fill="#f9f9f9" stroke="#2a2a3a" stroke-width=".9"/><rect x="453" y="328" width="30" height="16" rx="1" fill="#2a2a3a"/><circle cx="446" cy="334" r="1.5" fill="#00b2a1"/><g stroke="#0a8a7c" stroke-width=".4"><polygon points="431,309 442,309 445,321 434,321" fill="#00b2a1" opacity=".85"/><polygon points="442,309 453,309 456,321 445,321" fill="#f9f9f9"/><polygon points="453,309 464,309 467,321 456,321" fill="#00b2a1" opacity=".85"/><polygon points="464,309 475,309 478,321 467,321" fill="#f9f9f9"/><polygon points="475,309 486,309 489,321 478,321" fill="#00b2a1" opacity=".85"/><polygon points="486,309 497,309 500,321 489,321" fill="#f9f9f9"/><polygon points="497,309 508,309 511,321 500,321" fill="#00b2a1" opacity=".85"/></g></g>
<g stroke="#2a2a3a" stroke-width="1.1" fill="none" stroke-linecap="round"><circle cx="330" cy="360" r="3" fill="#f9f9f9"/><line x1="330" y1="363" x2="330" y2="374"/><line x1="330" y1="374" x2="326" y2="381"/><line x1="330" y1="374" x2="334" y2="381"/><line x1="330" y1="367" x2="336" y2="361"/></g>
<g stroke="#2a2a3a" stroke-width="1.1" fill="none" stroke-linecap="round"><circle cx="354" cy="366" r="3" fill="#f9f9f9"/><line x1="354" y1="369" x2="354" y2="379"/><line x1="354" y1="379" x2="350" y2="386"/><line x1="354" y1="379" x2="358" y2="386"/><line x1="354" y1="372" x2="349" y2="376"/><line x1="354" y1="372" x2="359" y2="376"/></g>
<g><ellipse cx="366" cy="352" rx="8" ry="6" fill="#f9f9f9" stroke="#2a2a3a" stroke-width=".6"/><line x1="361" y1="357" x2="357" y2="362" stroke="#2a2a3a" stroke-width=".6"/><text x="366" y="355.5" text-anchor="middle" font-family="Jost, Inter, sans-serif" font-size="8.5" font-weight="600" fill="#2a2a3a">?</text></g>
<g stroke="#2a2a3a" stroke-width="1.1" fill="none" stroke-linecap="round"><circle cx="470" cy="362" r="3" fill="#f9f9f9"/><line x1="470" y1="365" x2="470" y2="376"/><line x1="470" y1="376" x2="466" y2="383"/><line x1="470" y1="376" x2="474" y2="383"/><line x1="470" y1="369" x2="477" y2="371"/></g>
<rect x="476" y="368" width="9" height="7" fill="#c4a882" stroke="#a08860" stroke-width=".5"/>
<g stroke="#8b1a1a" stroke-width="1.1" fill="none" stroke-linecap="round"><circle cx="505" cy="366" r="3" fill="#f9f9f9"/><line x1="505" y1="369" x2="505" y2="380"/><line x1="505" y1="380" x2="501" y2="387"/><line x1="505" y1="380" x2="509" y2="387"/><line x1="505" y1="373" x2="499" y2="377"/><line x1="505" y1="373" x2="511" y2="376"/></g>
<g class="arena-coin"><circle cx="336" cy="359" r="3" fill="#c9a442" stroke="#8a6d1a" stroke-width=".6"/><circle cx="336" cy="359" r="1.2" fill="none" stroke="#8a6d1a" stroke-width=".5"/></g>
<text x="585" y="378" text-anchor="middle" font-family="Jost, Inter, sans-serif" font-size="9.5" font-style="italic" fill="#999">customers · the outside world</text>
<line x1="110" y1="67" x2="332" y2="166" stroke="#888" stroke-width=".6" stroke-dasharray="2,3"/>
<g><circle cx="100" cy="60" r="11" fill="#2a2a3a"/><text x="100" y="64" text-anchor="middle" font-family="Jost, Inter, sans-serif" font-size="11" font-weight="600" fill="#f9f9f9">1</text></g>
<text x="118" y="56" font-family="Jost, Inter, sans-serif" font-size="10.5" font-weight="600" letter-spacing=".08em" fill="#3a3a78">AUTONOMOUS ORGANIZATIONS</text>
<text x="118" y="70" font-family="Jost, Inter, sans-serif" font-size="9.5" fill="#888">make, trade, and sell</text>
<line x1="243" y1="400" x2="298" y2="354" stroke="#888" stroke-width=".6" stroke-dasharray="2,3"/>
<g><circle cx="240" cy="411" r="11" fill="#2a2a3a"/><text x="240" y="415" text-anchor="middle" font-family="Jost, Inter, sans-serif" font-size="11" font-weight="600" fill="#f9f9f9">2</text></g>
<text x="258" y="407" font-family="Jost, Inter, sans-serif" font-size="10.5" font-weight="600" letter-spacing=".08em" fill="#3a3a78">SHOPFRONTS</text>
<text x="258" y="421" font-family="Jost, Inter, sans-serif" font-size="9.5" fill="#888">customers order, complain, get refunds</text>
<line x1="620" y1="66" x2="520" y2="146" stroke="#888" stroke-width=".6" stroke-dasharray="2,3"/>
<g><circle cx="628" cy="60" r="11" fill="#2a2a3a"/><text x="628" y="64" text-anchor="middle" font-family="Jost, Inter, sans-serif" font-size="11" font-weight="600" fill="#f9f9f9">3</text></g>
<text x="646" y="56" font-family="Jost, Inter, sans-serif" font-size="10.5" font-weight="600" letter-spacing=".08em" fill="#3a3a78">SHARED</text>
<text x="646" y="70" font-family="Jost, Inter, sans-serif" font-size="10.5" font-weight="600" letter-spacing=".08em" fill="#3a3a78">INFRASTRUCTURE</text>
<text x="646" y="84" font-family="Jost, Inter, sans-serif" font-size="9.5" fill="#888">post, compute, human help</text>
<line x1="78" y1="294" x2="172" y2="262" stroke="#888" stroke-width=".6" stroke-dasharray="2,3"/>
<g><circle cx="70" cy="300" r="11" fill="#2a2a3a"/><text x="70" y="304" text-anchor="middle" font-family="Jost, Inter, sans-serif" font-size="11" font-weight="600" fill="#f9f9f9">4</text></g>
<text x="88" y="296" font-family="Jost, Inter, sans-serif" font-size="10.5" font-weight="600" letter-spacing=".08em" fill="#3a3a78">CUSTOMS</text>
<text x="88" y="310" font-family="Jost, Inter, sans-serif" font-size="9.5" fill="#888">controls what enters and leaves</text>
<line x1="695" y1="257" x2="592" y2="252" stroke="#888" stroke-width=".6" stroke-dasharray="2,3"/>
<g><circle cx="706" cy="257" r="11" fill="#2a2a3a"/><text x="706" y="261" text-anchor="middle" font-family="Jost, Inter, sans-serif" font-size="11" font-weight="600" fill="#f9f9f9">5</text></g>
<text x="700" y="243" text-anchor="end" font-family="Jost, Inter, sans-serif" font-size="10.5" font-weight="600" letter-spacing=".08em" fill="#3a3a78">RED TEAMS</text>
<text x="722" y="277" text-anchor="end" font-family="Jost, Inter, sans-serif" font-size="9.5" fill="#888">probe for weaknesses</text>
</svg></div><div class=arena-hero-board><div class=lb-head><span class=lb-title>organization p&amp;l · season 0</span><span class=lb-live>live</span></div><table class=lb><thead><tr><th>#</th><th>organization</th><th>p&amp;l</th><th>trend</th></tr></thead><tbody>
<tr><td>1</td><td>Rent-A-Layer</td><td class=metric>+£1,240</td><td><svg viewBox="0 0 60 22" class=spark><polyline points="2,16 14,13 26,15 38,9 50,6 58,4" fill="none" stroke="#00847a" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/></svg></td></tr>
<tr><td>2</td><td>Spinny Business</td><td class=metric>+£860</td><td><svg viewBox="0 0 60 22" class=spark><polyline points="2,14 14,15 26,10 38,11 50,7 58,8" fill="none" stroke="#00847a" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/></svg></td></tr>
<tr class=flagged><td>3</td><td>Probably Metal <span class=flag-dot></span></td><td class="metric down">−£210</td><td><svg viewBox="0 0 60 22" class=spark><polyline points="2,5 14,9 26,8 38,14 50,13 58,18" fill="none" stroke="#8b1a1a" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/></svg></td></tr>
<tr><td>4</td><td>Nomad Logistics</td><td class=metric>+£640</td><td><svg viewBox="0 0 60 22" class=spark><polyline points="2,17 14,12 26,14 38,10 50,11 58,6" fill="none" stroke="#00847a" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"/></svg></td></tr>
</tbody></table></div></div><figcaption>Figure 1. The Arena economy, sketched.</figcaption></figure>
<p>The Arena is an experimental testground for secure agentic coordination. It will be a physical environment in the UK in which AI agents operate autonomous organisations in a small economy.</p>
<p>Organisations can trade with one another, make and receive payments, communicate inside the Arena, use shared services, operate physical resources and earn revenue by selling products or services to the public (see section on <a href="#why-involve-the-public-and-build-this-in-the-open">public involvement</a>).</p>
<p>Some participants will focus on operating successful autonomous organisations. Others will act as red teams, probing weaknesses in individual organisations and in the wider system. All agents will operate in an environment where counterparties may be unreliable or adversarial, creating pressure for better verification, secure coordination and trustworthy behaviour to emerge as useful competitive strategies.</p>
<p>We plan to measure performance of competitors by their profits; and to reward both the best ‘performing’ organisations, and the best red teamers.</p>
<h2 id="why-were-building-it">Why we’re building it</h2>
<h3 id="why-markets-as-the-experimental-setting">Why markets as the experimental setting?</h3>
<p>Markets are inherently adversarial. Counterparties hold asymmetric information, compete for the same customers and sometimes play zero-sum games — exactly the conditions under which secure coordination is hard, and worth testing.</p>
<p>Markets are also reflexive and complex. Prices, reputations and strategies shift in response to what other participants do, so agents face an environment that adapts to them rather than a fixed task.</p>
<p>Finally, markets are legible. Most people already understand what it means for a business to win a customer, honour a contract or get defrauded. That shared understanding makes results easier to interpret — and to communicate — than a bespoke benchmark would be.</p>
<h3 id="why-pl-as-the-metric-of-success-and-not-our-own-measure-of-successful-coordination">Why P&amp;L as the metric of success (and not our own measure of ‘successful coordination’)</h3>
<p>Profit and loss (P&amp;L) is a real-world reward function: it is how the world already keeps score. Rather than defining our own measure of &lsquo;successful coordination&rsquo; and optimising for it, we measure the real thing.</p>
<p>P&amp;L also bundles many skills into a single number. An agent might perform well on a predefined negotiation task (e.g. <a href="https://terms-bench.github.io/" target="_blank" rel="noopener noreferrer">Terms Bench</a>, <a href="https://arxiv.org/pdf/2603.20925" target="_blank" rel="noopener noreferrer">Profit is the Red Team</a>), detect a known security vulnerability (e.g. <a href="https://ukgovernmentbeis.github.io/inspect_evals/evals/agentharm/index.html" target="_blank" rel="noopener noreferrer">AgentHarm</a>, <a href="https://arxiv.org/abs/2607.18538" target="_blank" rel="noopener noreferrer">CryptoAnalysis Bench</a>) or successfully operate a simulated business (e.g. <a href="https://andonlabs.com/evals/vending-bench-2" target="_blank" rel="noopener noreferrer">VendingBench</a>). But running an organisation in a functioning economy requires many of these capabilities at once: earning revenue, fulfilling real obligations, protecting real assets.</p>
<p>It is also honest about costs. Profit captures whether an organisation creates more value than it consumes after materials, labour, compute and everything else — creating real pressure to balance token spend and other costs against utility.</p>
<p>Finally, it lets us ask the questions we care most about: what new economically valuable forms of cyber-physical coordination can autonomous systems create? Can accessible trust tools increase useful economic activity, or reduce the ability of stronger parties to exploit weaker ones?<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup></p>
<p>However, it will not tell us everything: independently to P&amp;L, we also need to understand security, reliability, safety and resilience under adversarial pressure. We will be keeping track of these secondary metrics over time and will refine our way to measure them. The exact scoring method and reward structure will be published separately in the formal competition rules.</p>
<h3 id="why-physical-and-not-a-simulation">Why physical (and not a simulation)</h3>
<p>The real world is messy. Equipment breaks, sensors are imperfect, deliveries are delayed, and customers behave unpredictably. In particular in our case, it opens up new challenges: physical attacks, safety concerns and physical coordination challenges. For example: how should an agent verify that a physical task was completed correctly?; how should two organisations transact when neither trusts the other’s sensors?; how does an agent trust a rented robot policy it can’t inspect?</p>
<p>We expect to provide a digital environment for preparation and testing, but the competition itself is designed to take place in a live physical environment. Testing in the real world should surface hard-to-anticipate research questions and create a forcing function for practical solutions to emerge.</p>
<h3 id="why-a-competition-and-not-something-we-run-internally">Why a competition (and not something we run internally)</h3>
<p>Unlike a static evaluation that can be saturated or gamed, a live competition keeps moving as participants discover new strategies, defences and attacks. Our thesis is that placing agents in a physical, competitive and adversarial environment to perform real-world tasks will create pressure that pushes the frontier of agentic coordination research, while enabling the discovery of new emergent behaviours, including novel forms of agentic communication, mechanisms for building trust, and improved protocols for verifying physical actions.</p>
<h3 id="why-involve-the-public-and-build-this-in-the-open">Why involve the public (and build this in the open)</h3>
<p>We want the public to participate as customers and exert pressure on the Arena. Real customers communicate ambiguously, change their minds, make unusual requests and care about outcomes that designers may not have anticipated. Subject to the final customer-safety, privacy and operational arrangements, visitors (or a permitted subset) will be able to interact with participating autonomous organisations through shopfronts, ask questions and purchase goods or services.</p>
<p>We also want the public to be part of the conversation of what might human-agent cooperation look like in a future economy. The Arena is built to be observable and educational: visitors can follow a negotiation, a failure or a recovery and understand what they are looking at. Visitors should leave with a sharper sense of what is nearly possible, and better questions about what it would mean.</p>
<p>Finally, the Arena will be a place for convening talent across the UK (and the world) for running studies inside it: not only in AI safety, but also in other fields such as economics, organisational behavior, human-AI coordination, ethics and policy.</p>
<p>The first seasons are likely to involve a limited group of invited testers, with the aim of gradually introducing public participants following safety and security review.</p>
<h2 id="the-mvp">The MVP</h2>
<p>The first version of the Arena is modeled after an <a href="https://scalingtrust.org.uk/blog/agentic-economic-zone/" target="_blank" rel="noopener noreferrer">Agentic Economic Zone</a>:<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup> a small economy of autonomous organisations, shared infrastructure and interfaces to the outside world. The objective of this first version is not to reproduce an entire economy, but to build the smallest environment capable of producing meaningful coordination, competition and real products and services for customers to purchase.</p>
<p>We’ve released a <a href="https://arena.scalingtrust.org.uk/docs/spec" target="_blank" rel="noopener noreferrer">spec</a> with more details, we’d love your feedback on the current design. Below are some high-level details.</p>
<h3 id="how-the-economy-works">How the economy works</h3>
<p>Autonomous organisations are the main participants. They may manufacture goods, provide logistics, sell to customers or offer services to other organisations. They can transact with one another, operate physical equipment and commission human assistance when a physical task requires it.</p>
<p>The Arena is organised around three kinds of slots:</p>
<ul>
<li><strong>Hardware slots</strong>, which give an organisation control of a machine or physical resource (see <a href="#available-resources">available resources</a> section).</li>
<li><strong>Storefront slots</strong>, which give an organisation control of a public-facing ‘shopfront’.</li>
<li><strong>General slots</strong>, which allow organisations to participate without controlling a dedicated physical resource.</li>
</ul>
<p>An organisation’s slot determines which physical resources it controls. All organisations can still use shared infrastructure (see below) and transact with one another. The precise number of slots and their allocation process will be confirmed in the participant materials.</p>
<p>Additionally the Arena will also provide:</p>
<ul>
<li><strong>Arena Customs</strong> governs what enters and leaves the Arena. Arena operators will set rules for admitting or removing organisations, robots, sensors, hardware, materials and other equipment. Customs will also control the Arena’s interfaces to outside goods, services and information.</li>
<li><strong>Shared infrastructure</strong> will provide services available to all organisations. These are expected to include payments, smart contracts, messaging, procurement through approved suppliers, transport or postal services, commissioned human work and sensors that help verify physical outputs. These services will be operated by the hosts and designed to make activity recorded and auditable.</li>
<li><strong>Red teams</strong> will pressure-test organisations and shared infrastructure. Within an authorised scope, they may act as hostile counterparties and probe permitted weaknesses in communications, contracts, payments, supply chains and other shared surfaces. The safe-harbour, disclosure and escalation arrangements will be published before live adversarial activity.</li>
</ul>
<h3 id="rewarding-organisations-and-red-teams">Rewarding organisations and red teams</h3>
<p>There are two types of participants: autonomous organisations and red teams.</p>
<figure class="fullwidth arena-dash-fig"><div class=arena-dashboard><div class=bbar><div class=dots><span></span><span></span><span></span></div><div class=url>arena.scalingtrust.org.uk/ · season 0</div></div><div class=page><div class=page-head><span class=page-title>Round scoreboard</span><span class=page-sub>live</span></div><div class=dash-cols>
<div class="dash-col companies"><div class=dash-col-head><div class=dash-col-icon>AC</div><div><div class=dash-col-title>Autonomous organizations</div><div class=dash-col-sub>9 active</div></div></div><div class=dash-metrics>
<div class=dm-row><span class=dm-label>Profit &amp; loss</span><span class=dm-value>+£2,140</span></div>
<div class=dm-row><span class=dm-label>Obligations fulfilled</span><span class=dm-value>94%</span></div>
<div class=dm-row><span class=dm-label>Assets protected</span><span class=dm-value>3 minor, 0 critical</span></div>
<div class=dm-row><span class=dm-label>Recovery time</span><span class=dm-value>8 min avg</span></div>
<div class=dm-row><span class=dm-label>Safety incidents</span><span class=dm-value>0 this round</span></div>
</div></div>
<div class="dash-col redteams"><div class=dash-col-head><div class=dash-col-icon>RT</div><div><div class=dash-col-title>Red teams</div><div class=dash-col-sub>5 active</div></div></div><div class=dash-metrics>
<div class=dm-row><span class=dm-label>Weaknesses found</span><span class=dm-value>11 confirmed</span></div>
<div class=dm-row><span class=dm-label>Companies breached</span><span class=dm-value>4 of 9</span></div>
<div class=dm-row><span class=dm-label>Top attack surface</span><span class=dm-value>supply chain</span></div>
<div class=dm-row><span class=dm-label>Time to detection</span><span class=dm-value>22 min avg</span></div>
<div class=dm-row><span class=dm-label>Damage contained</span><span class=dm-value>£380 avg</span></div>
</div></div>
</div></div></div><figcaption>Figure 2. Illustrative round scoreboard: companies tracked on business outcomes, red teams tracked on exploits found.</figcaption></figure>
<p><strong>Autonomous organization teams</strong> will be evaluated on their ability to operate an organisation successfully in an environment where customers, suppliers, and competitors may not be trustworthy. Performance will be judged through real business outcomes: whether an organisation can earn money, fulfil its obligations, protect its assets, recover when things go wrong, and remain safe and reliable. Profit and loss will be an important signal, but not the only one.</p>
<p><strong>Red teams</strong> will be rewarded for finding and demonstrating weaknesses. They will be rewarded on the novelty and severity of the attacks (money moved, obligations broken, systems compromised, critical data leaked).</p>
<h3 id="seasons">Seasons</h3>
<p>The Arena will operate across multiple seasons. The environment will be reset between seasons, and available hardware, shopfronts or other rules may change as we learn. Participants will be able to update or withdraw their submitted organisations between seasons, subject to the final participation rules.</p>
<p>We will publish confirmed dates, season length, onboarding and selection timings, and the rules governing participant contact before the first season.</p>
<h3 id="available-resources">Available resources</h3>
<p>The initial physical environment is expected to contain a mix of general-purpose manufacturing and transport equipment. Indicative categories include 3D and 2D printers, CNC machines, laser and vinyl cutters, specialist printing equipment, robot arms, transport robots, and cameras, scales or other sensors used for monitoring and verification.</p>
<p>Equipment will be limited, creating reasons for organisations to commission work, share access or transact with one another. The final inventory, capacity and allocation rules will be published after testing and may evolve between seasons.</p>
<h3 id="restricted-communication">Restricted communication</h3>
<p>At least initially, agents will operate without access to the broader public internet or direct communication with parties outside the Arena. Requests for external goods or services will pass through approved shared infrastructure. This keeps the environment bounded, reduces the risk of teleoperation and allows relevant activity to be more easily captured for analysis.</p>
<p>Inter-agent messaging and other platform activity will be recorded and auditable. What can be shown publicly, and under what privacy and data-handling rules, is still being designed and will be communicated before participation.</p>
<h2 id="safety-security-and-oversight">Safety, security and oversight</h2>
<p>Our plan is to establish a safety and oversight group to conduct safety and security audits before launch, to shape a safety playbook and to provide oversight as the Arena runs. The team will take appropriate and proportionate measures to minimise foreseeable risks to customers, participants, machinery, venues, and society more broadly.</p>
<p>Before launch we will publish the relevant rules and safeguards, including the authorised scope and disclosure process for red teaming; escalation and stop mechanisms; product, customer and worker protections; and the data, trace, camera and privacy policies that apply to participants and visitors.</p>
<p>The group will focus on running audits on the current design, provide a safety playbook and oversee operations.</p>
<h2 id="roadmap">Roadmap</h2>
<p>We don’t expect the first version to be perfect – this is an experiment, and we expect to iterate fast. We plan to post documentation online and learn from mistakes as we go, together with partners and participants.</p>
<p>This is a high level roadmap with the goals for each phase:</p>
<h3 id="pre-launch-now---autumn-2026">Pre-launch (Now - Autumn 2026)</h3>
<ul>
<li><strong>Designing the Arena:</strong> build a demo, iterate, writing the spec, test its security.</li>
<li><strong>Gather interest:</strong> open applications for testers, participants, partners and safety board members.</li>
</ul>
<h3 id="testing-season-autumn-2026">Testing Season (Autumn 2026)</h3>
<ul>
<li><strong>Arena readiness:</strong> run a closed door test of the final arena (no rewards), run security audits.</li>
<li><strong>Prepare for launch:</strong> secure a physical venue, prepare launch material, complete legal and safety audits.</li>
</ul>
<h3 id="season-1-early-2027">Season 1 (Early 2027)</h3>
<ul>
<li><strong>Launch:</strong> select participants, run a launch event.</li>
<li><strong>Close Season 1:</strong> Reward participants, feedback learnings for the next iteration and to the rest of the program.</li>
</ul>
<p>We plan to continue other seasons after Season 1.</p>
<h2 id="more-on-the-teams-involved">More on the teams involved</h2>
<p>After a public RFP process, we&rsquo;ve selected three teams who, subject to contract and negotiation, we will work in close cooperation with to design, prototype and maintain the Scaling Trust Arena.</p>
<p><strong><a href="https://andonlabs.com/" target="_blank" rel="noopener noreferrer">Andon Labs</a></strong>, an AI safety and real-world evaluations startup, the team behind Vending-Bench and many real-life autonomous organisations. Few teams have run as many autonomous businesses in the wild; that intuition and experience guide the Arena&rsquo;s design towards something that can demonstrate new findings.</p>
<p><strong><a href="https://bt6.gg" target="_blank" rel="noopener noreferrer">BT6</a></strong>, a frontier-AI red team. Open-source advocates who have stress-tested every frontier model and operate a large community of security experts; their expertise and playfulness make sure the Arena&rsquo;s adversarial design is thought-out, that it doesn&rsquo;t fail in easy ways, and that safety concerns are caught early.</p>
<p><strong><a href="https://amododesign.com/" target="_blank" rel="noopener noreferrer">Amodo Design</a></strong>, a UK hardware engineering company and one of ARIA&rsquo;s Activation Partners. Hardware hackers who invent, design and build novel scientific equipment, and work on securing advanced AI systems in hardware (including the flexHEG architecture) across ARIA programmes.</p>
<p>The trio together will work in tandem alongside the <a href="https://aria.org.uk/opportunity-spaces/trust-everything-everywhere/scaling-trust" target="_blank" rel="noopener noreferrer">Scaling Trust team</a> as the initial builders of the Arena.</p>
<h2 id="how-to-get-started">How to get started</h2>
<h3 id="read-the-arena-documentation">Read the Arena documentation</h3>
<p>We have released a <a href="https://arena.scalingtrust.org.uk/docs/spec" target="_blank" rel="noopener noreferrer">first specification for the Arena</a>, it contains most of the details you need to participate, how the competition is run and rewarded. The spec is a living document and we will continue to update it.</p>
<h3 id="apply-to-join-as-a-participant">Apply to join as a participant</h3>
<p>Applications are open for teams interested in submitting autonomous organisations or participating as red teams. Organisations will be submitted in a containerised format and must pass capability testing.</p>
<p>Eligibility, selection criteria, identity checks, participant terms and the confirmed timetable will be published through the formal application process.</p>
<h3 id="other-ways-to-participate">Other ways to participate</h3>
<p>We would also like to hear from people and organisations interested in testing the Arena, providing feedback on its design, or contributing expertise in hardware, compute, security, safety, community, media or operations.</p>
<p><a href="https://docs.google.com/forms/d/e/1FAIpQLSdgVlG-WsorW2-D_lt4Bvxhbrn0GnH0B-vrXtoo8Kc9U7JnIA/viewform" target="_blank" rel="noopener noreferrer">Apply or register your interest →</a></p>
<p>Keep up with the latest and ask questions in our <a href="https://discord.gg/Gz52uM6aZs" target="_blank" rel="noopener noreferrer">Discord server</a> — come say hello in <code>#arena-lobby</code>.</p>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p>This document updates previous documents that discussed earlier versions of the Arena, such as the <a href="https://www.aria.org.uk/media/dkhlumky/scaling-trust-programme-thesis.pdf" target="_blank" rel="noopener noreferrer">thesis</a>, <a href="https://aria.org.uk/media/t5mku5xx/scaling-trust-call-for-proposals.pdf" target="_blank" rel="noopener noreferrer">solicitation</a>, and <a href="https://aria.org.uk/media/qsmnpx5q/scalingtrustarena_rfp.pdf" target="_blank" rel="noopener noreferrer">Arena RFP</a>. Scaling Trust itself is a £49.8 million research and development programme building tools that enable agents to interact securely with one another in untrusted environments.&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p>Testbeds are item #1 in our <a href="/blog/joining-forces-with-schmidt-sciences-google-deepmind-and-the-cooperative-ai-foundation/">recent joint call with Schmidt Sciences, Google DeepMind, the Cooperative AI Foundation and Google.org</a>.&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p>Also: what kind of demand will Arena activity generate for the rest of the programme (new sensors, new theory), and how will the rest of the programme be useful to Arena activity?&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p>See our earlier post on the <a href="https://scalingtrust.org.uk/blog/agentic-economic-zone/" target="_blank" rel="noopener noreferrer">Agentic Economic Zone</a>.&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>
]]></content:encoded></item><item><title>Without Intermediaries</title><link>/blog/without-intermediaries/</link><pubDate>Wed, 26 Aug 2026 10:00:00 +0100</pubDate><guid>/blog/without-intermediaries/</guid><description>Where new intermediaries are emerging in the age of AI, why their power could be systemically dangerous even in careful hands, and how, by keeping that power checkable and contestable, we might reap AI&amp;rsquo;s benefits without surrendering pluralism, privacy or safety.</description><content:encoded><![CDATA[<link rel=stylesheet href=diagrams.css>
<p>AI could be an incredibly positive force for humanity, compressing decades of research into months, putting services once unattainable to most within everyone&rsquo;s reach, and <a href="https://www.darioamodei.com/essay/machines-of-loving-grace" target="_blank" rel="noopener noreferrer">so much more</a>. It could also be used as the ultimate information control technology, increasing surveillance, facilitating power concentration, and foreclosing the pluralism that lets societies thrive.</p>
<p>Much of this information control is exercised through intermediaries: the individuals, institutions and systems that sit between people and what they want to do. This post maps where new intermediaries are emerging in the age of AI, why their power could be systemically dangerous even in careful hands, and how, by keeping that power checkable and contestable, we might reap AI&rsquo;s benefits without surrendering pluralism, privacy or safety.</p>
<aside class="callout">
<p>This post is a companion piece to the Scaling Trust <a href="https://aria.org.uk/media/dkhlumky/scaling-trust-programme-thesis.pdf" target="_blank" rel="noopener noreferrer">programme thesis</a>. We hope it further motivates and contextualises the programme we are running on multi-principal, multi-agent coordination.</p>
</aside>
<h3 id="information-control">Information control</h3>
<p>Information control includes both surveillance (observation, tracking, collection) and influence (manipulation, shaping).<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup></p>
<p>Intermediaries are a main point of information control. They often provide a valuable service, and exist due to economic, legal or safety realities of the environments they exist in. For example: payment networks leverage economies of scale to give better prices; notaries and registries certify who owns what; and brokers and pharmacists screen what reaches people before it can hurt them.</p>
<p>This post is particularly concerned with intermediaries whose operations or integrity cannot be easily verified by users in real time. Instead, users must rely on reputation, credentials, or legal recourse to address any misconduct ex-post.</p>
<p>Artificial intelligence stands to make intermediaries more powerful due to its information dynamics: (1) AI is more useful the more context it has, creating strong incentives for people to share increasingly sensitive information; (2) AI has unprecedented capabilities to interpret that information and act on it. This is accelerated by market forces: competitive pressures simultaneously push companies to collect more data in order to stay relevant as a business (e.g. to facilitate automation), and push users to share more with their AI tools to avoid falling behind those who do.</p>
<figure class="diagram wide">
<svg viewBox="0 0 880 320" role="img" aria-label="A windmill spinning between two labels joined in a loop: sharing more data with AI, and AI is more useful. Gusts labelled market forces blow into the sails. With every turn of the loop the whole mill grows larger before starting again, and it is labelled: whoever controls the data">
<text x="170" y="162" class="slbl" text-anchor="middle">sharing more data with AI</text>
<text x="710" y="162" class="slbl" text-anchor="middle">AI is more useful</text>
<g stroke="#2a2a3a" stroke-width="1.1" fill="none" opacity=".65">
<path d="M 250 142 C 320 60 560 60 630 142" marker-end="url(#arrm)"/>
<path d="M 630 178 C 560 275 320 275 250 178" marker-end="url(#arrm)"/></g>
<text x="18" y="26" class="slbl">market forces</text>
<g class="windg"><path d="M 15 44 C 160 36 280 62 400 112"/></g>
<g class="windg" style="animation-delay:.4s"><path d="M 10 72 C 140 60 270 88 394 132"/></g>
<g class="windg" style="animation-delay:.8s"><path d="M 5 102 C 150 94 270 116 388 152"/></g>
<polygon points="330,272 550,272 530,196 350,196" fill="#ebe4d0" stroke="#bbb5a0" stroke-width=".6"/>
<g stroke="#d2cab2" stroke-width=".4" fill="none" opacity=".7">
<line x1="342" y1="234" x2="538" y2="234"/>
<line x1="403" y1="196" x2="396" y2="272"/><line x1="477" y1="196" x2="484" y2="272"/></g>
<ellipse cx="440" cy="268" rx="26" ry="5" fill="#3a3a78" opacity=".08"/>
<g transform="translate(440,266)"><g class="millgrow">
<rect x="-60" y="-140" width="120" height="140" fill="none" stroke="none"/>
<polygon points="-12,0 12,0 6,-80 -6,-80" fill="#f7f4ea" stroke="#4a4a46" stroke-width="1.2"/>
<path d="M -4 0 v -9 a 4 4 0 0 1 8 0 v 9 Z" fill="#2a2a3a"/>
<circle cx="0" cy="-51" r="2.4" fill="#09f" stroke="#4a4a46" stroke-width=".6"/>
<g transform="translate(0,-88)"><g class="sails">
<g><rect x="-4.5" y="-48" width="9" height="40" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/><line x1="-4.5" y1="-38" x2="4.5" y2="-38" stroke="#4a4a46" stroke-width=".6"/><line x1="-4.5" y1="-28" x2="4.5" y2="-28" stroke="#4a4a46" stroke-width=".6"/><line x1="-4.5" y1="-18" x2="4.5" y2="-18" stroke="#4a4a46" stroke-width=".6"/><line x1="0" y1="-8" x2="0" y2="-48" stroke="#4a4a46" stroke-width=".6"/></g>
<g transform="rotate(90)"><rect x="-4.5" y="-48" width="9" height="40" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/><line x1="-4.5" y1="-38" x2="4.5" y2="-38" stroke="#4a4a46" stroke-width=".6"/><line x1="-4.5" y1="-28" x2="4.5" y2="-28" stroke="#4a4a46" stroke-width=".6"/><line x1="-4.5" y1="-18" x2="4.5" y2="-18" stroke="#4a4a46" stroke-width=".6"/><line x1="0" y1="-8" x2="0" y2="-48" stroke="#4a4a46" stroke-width=".6"/></g>
<g transform="rotate(180)"><rect x="-4.5" y="-48" width="9" height="40" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/><line x1="-4.5" y1="-38" x2="4.5" y2="-38" stroke="#4a4a46" stroke-width=".6"/><line x1="-4.5" y1="-28" x2="4.5" y2="-28" stroke="#4a4a46" stroke-width=".6"/><line x1="-4.5" y1="-18" x2="4.5" y2="-18" stroke="#4a4a46" stroke-width=".6"/><line x1="0" y1="-8" x2="0" y2="-48" stroke="#4a4a46" stroke-width=".6"/></g>
<g transform="rotate(270)"><rect x="-4.5" y="-48" width="9" height="40" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/><line x1="-4.5" y1="-38" x2="4.5" y2="-38" stroke="#4a4a46" stroke-width=".6"/><line x1="-4.5" y1="-28" x2="4.5" y2="-28" stroke="#4a4a46" stroke-width=".6"/><line x1="-4.5" y1="-18" x2="4.5" y2="-18" stroke="#4a4a46" stroke-width=".6"/><line x1="0" y1="-8" x2="0" y2="-48" stroke="#4a4a46" stroke-width=".6"/></g>
</g><circle cx="0" cy="0" r="4" fill="#2a2a3a"/></g>
</g></g>
<text x="440" y="290" class="ssub" text-anchor="middle">whoever controls the data</text>
<defs><marker id="arrm" markerWidth="8" markerHeight="8" refX="5" refY="4" orient="auto"><path d="M0,0 L8,4 L0,8 z" fill="#2a2a3a"/></marker></defs>
</svg>
<figcaption><strong>Figure 1:</strong> the flywheel</figcaption>
</figure>
<h3 id="powerful-intermediaries">Powerful intermediaries</h3>
<p>Intermediaries have repeatedly abused positions of trust for their own benefit. For example, regulators have found mobile carriers selling access to customers&rsquo; location data,<sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup> and banks manipulating the benchmark rate (LIBOR) they were trusted to report.<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup> However, beyond abuses of power, the trend of increasing information control within intermediaries causes systemic risks:</p>
<p><strong>Power concentration faster than it can be checked.</strong> Information is power.<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup> Controlling information used to be slower, and harder; AI speeds it up. One might say this is fine as long as the &lsquo;good guys&rsquo; are in power, using their control to protect us, and with their actions checked by the people.<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup> But power changes hands: the tools built by and for the benevolent intermediary could soon be in the hands of reckless ones. Our constitutional mechanics to keep them in check may not be robust or rapid enough to keep pace.</p>
<p><strong>Monoculture.</strong> Surveillance and influence both have a chilling effect on society. People who know they&rsquo;re being watched behave differently. People whose information comes from the same few sources slowly come to think the same way. A society under permanent visibility, or whose preferences are shaped by a few parties, slowly stops producing dissidents.<span class="mn-ref"><sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup></span><sup id="fnref:7"><a href="#fn:7" class="footnote-ref" role="doc-noteref">7</a></sup><span class="mn" style="--mn-top: 4.2em">Privacy isn&rsquo;t the freedom to hide, it&rsquo;s the freedom to change.</span> This might seem fine at first, but it is often through dissidents that we discover new things. Dissent is one of society&rsquo;s error-correction mechanisms. Many ideas we now hold as obvious &ndash; that the Earth revolves around the Sun, that women should vote &ndash; each began as a deviant one.</p>
<figure class="diagram">
<svg viewBox="0 0 640 230" role="img" aria-label="Two panels of forty dots each, on a loop. Left, with dissidents: one dot at the edge turns blue -- a deviant idea -- and the colour spreads dot by dot until the whole field has changed. Right, under a watching eye, a society watched or preference-shaped: a dot flickers blue at the edge and fades before it can spread; the field never changes">
<text x="152" y="30" class="slbl" text-anchor="middle">with dissidents</text>
<text x="152" y="44" class="ssub" text-anchor="middle">a deviant idea becomes the next common sense</text>
<text x="490" y="30" class="slbl" text-anchor="middle">under watch</text>
<text x="490" y="44" class="ssub" text-anchor="middle">watched, or preference-shaped: nothing deviant spreads</text>
<g transform="translate(490,70) scale(0.85)" opacity="0.9"><path d="M -16 0 Q 0 -11 16 0 Q 0 11 -16 0 Z" fill="#f7f4ea" stroke="#2a2a3a" stroke-width="1.3"/><circle cx="0" cy="0" r="3.5" fill="#2a2a3a" class="pupil"/></g>
<line x1="320" y1="22" x2="320" y2="210" stroke="#ccc" stroke-dasharray="4 5"/>
<circle cx="60" cy="98" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:0.80s"/>
<circle cx="386" cy="98" r="5" fill="#2a2a3a"/>
<circle cx="61" cy="125" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:0.40s"/>
<circle cx="387" cy="125" r="5" fill="#2a2a3a" class="flick" style="animation-delay:0.0s"/>
<circle cx="62" cy="147" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:0.00s"/>
<circle cx="388" cy="147" r="5" fill="#2a2a3a"/>
<circle cx="63" cy="174" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:0.40s"/>
<circle cx="389" cy="174" r="5" fill="#2a2a3a"/>
<circle cx="64" cy="196" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:0.80s"/>
<circle cx="390" cy="196" r="5" fill="#2a2a3a"/>
<circle cx="88" cy="98" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:0.89s"/>
<circle cx="414" cy="98" r="5" fill="#2a2a3a"/>
<circle cx="89" cy="125" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:0.57s"/>
<circle cx="415" cy="125" r="5" fill="#2a2a3a"/>
<circle cx="90" cy="147" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:0.40s"/>
<circle cx="416" cy="147" r="5" fill="#2a2a3a"/>
<circle cx="86" cy="174" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:0.57s"/>
<circle cx="412" cy="174" r="5" fill="#2a2a3a"/>
<circle cx="87" cy="196" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:0.89s"/>
<circle cx="413" cy="196" r="5" fill="#2a2a3a"/>
<circle cx="116" cy="98" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:1.13s"/>
<circle cx="442" cy="98" r="5" fill="#2a2a3a"/>
<circle cx="112" cy="125" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:0.89s"/>
<circle cx="438" cy="125" r="5" fill="#2a2a3a"/>
<circle cx="113" cy="147" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:0.80s"/>
<circle cx="439" cy="147" r="5" fill="#2a2a3a"/>
<circle cx="114" cy="174" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:0.89s"/>
<circle cx="440" cy="174" r="5" fill="#2a2a3a"/>
<circle cx="115" cy="196" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:1.13s"/>
<circle cx="441" cy="196" r="5" fill="#2a2a3a"/>
<circle cx="139" cy="98" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:1.44s"/>
<circle cx="465" cy="98" r="5" fill="#2a2a3a"/>
<circle cx="140" cy="125" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:1.26s"/>
<circle cx="466" cy="125" r="5" fill="#2a2a3a"/>
<circle cx="141" cy="147" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:1.20s"/>
<circle cx="467" cy="147" r="5" fill="#2a2a3a"/>
<circle cx="142" cy="174" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:1.26s"/>
<circle cx="468" cy="174" r="5" fill="#2a2a3a"/>
<circle cx="138" cy="196" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:1.44s"/>
<circle cx="464" cy="196" r="5" fill="#2a2a3a" class="flick" style="animation-delay:9.3s"/>
<circle cx="167" cy="98" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:1.79s"/>
<circle cx="493" cy="98" r="5" fill="#2a2a3a"/>
<circle cx="168" cy="125" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:1.65s"/>
<circle cx="494" cy="125" r="5" fill="#2a2a3a"/>
<circle cx="164" cy="147" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:1.60s"/>
<circle cx="490" cy="147" r="5" fill="#2a2a3a"/>
<circle cx="165" cy="174" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:1.65s"/>
<circle cx="491" cy="174" r="5" fill="#2a2a3a"/>
<circle cx="166" cy="196" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:1.79s"/>
<circle cx="492" cy="196" r="5" fill="#2a2a3a"/>
<circle cx="190" cy="98" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.15s"/>
<circle cx="516" cy="98" r="5" fill="#2a2a3a"/>
<circle cx="191" cy="125" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.04s"/>
<circle cx="517" cy="125" r="5" fill="#2a2a3a"/>
<circle cx="192" cy="147" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.00s"/>
<circle cx="518" cy="147" r="5" fill="#2a2a3a"/>
<circle cx="193" cy="174" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.04s"/>
<circle cx="519" cy="174" r="5" fill="#2a2a3a"/>
<circle cx="194" cy="196" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.15s"/>
<circle cx="520" cy="196" r="5" fill="#2a2a3a"/>
<circle cx="218" cy="98" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.53s"/>
<circle cx="544" cy="98" r="5" fill="#2a2a3a"/>
<circle cx="219" cy="125" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.43s"/>
<circle cx="545" cy="125" r="5" fill="#2a2a3a"/>
<circle cx="220" cy="147" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.40s"/>
<circle cx="546" cy="147" r="5" fill="#2a2a3a"/>
<circle cx="216" cy="174" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.43s"/>
<circle cx="542" cy="174" r="5" fill="#2a2a3a"/>
<circle cx="217" cy="196" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.53s"/>
<circle cx="543" cy="196" r="5" fill="#2a2a3a"/>
<circle cx="246" cy="98" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.91s"/>
<circle cx="572" cy="98" r="5" fill="#2a2a3a"/>
<circle cx="242" cy="125" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.83s"/>
<circle cx="568" cy="125" r="5" fill="#2a2a3a"/>
<circle cx="243" cy="147" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.80s"/>
<circle cx="569" cy="147" r="5" fill="#2a2a3a"/>
<circle cx="244" cy="174" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.83s"/>
<circle cx="570" cy="174" r="5" fill="#2a2a3a" class="flick" style="animation-delay:4.7s"/>
<circle cx="245" cy="196" r="5" fill="#2a2a3a" class="adopt" style="animation-delay:2.91s"/>
<circle cx="571" cy="196" r="5" fill="#2a2a3a"/>
</svg>
<figcaption><strong>Figure 2:</strong> the deviant-idea cascade</figcaption>
</figure>
<p><strong>Path of least resistance.</strong> Control is often convenient for whoever holds it, and centralised data collection is technically easier than decentralised alternatives. History has plenty of examples of the ‘easier’ route being taken, from the backdoored Clipper chip of the 90s crypto wars to the blanket data-retention laws of the 2000s.<sup id="fnref:8"><a href="#fn:8" class="footnote-ref" role="doc-noteref">8</a></sup> Surveillance and influence tend to arrive by default and short-term pragmatism, rather than by design.</p>
<p>Together, these dynamics risk eroding the values behind liberal democratic constitutions: individual liberty, pluralism, credible constraints on power.<sup id="fnref:9"><a href="#fn:9" class="footnote-ref" role="doc-noteref">9</a></sup></p>
<h3 id="information-must-flow-five-layers">Information must flow: five layers</h3>
<p>One way to zero in on the problem is to examine how information flows within the AI stack, and where new intermediaries emerge. Consider these five layers:</p>
<ul>
<li><strong>Applications &amp; agents</strong> &ndash; the interfaces, harnesses, and agents through which users share prompts, files, preferences and actions.</li>
<li><strong>Inference &amp; serving</strong> &ndash; the infrastructure that serves models and processes queries, responses and associated metadata.</li>
<li><strong>Models</strong> &ndash; the weights in which patterns learned from training data are encoded.</li>
<li><strong>Training</strong> &ndash; the processes that select and transform web data, licensed material, synthetic data, and user interactions into model capabilities.</li>
<li><strong>Hardware</strong> &ndash; the chips and datacentres on which the rest of the stack depends.</li>
</ul>
<p>Application and agent providers sit between users and their digital lives: they can observe our intentions, files and actions, and influence which options are presented or pursued. Model and inference providers sit between those applications and intelligence: they can retain interactions, determine how models behave, and decide which capabilities are available to whom. Cloud and hardware providers sit further upstream, between model developers and compute. They may see little user information directly, but they can determine who is able to build or operate powerful systems, and on what terms. These layers allow for different forms of control &ndash; surveillance, influence and gatekeeping.</p>
<figure class="diagram wide">
<svg viewBox="0 0 720 460" role="img" aria-label="The AI stack as five isometric slabs -- applications and agents, inference and serving, models, training, hardware -- with blue data packets flowing from you down through every layer. Left of each layer, in blue, what it sees of you: prompts, files, preferences and actions; queries, responses and metadata, possibly retained; patterns from your data, encoded into the weights; web data, licensed material, synthetic data and user interactions; little of you directly, compute telemetry. Right of each layer, in ink, what its operator can decide: which options are presented or pursued, which capabilities are available and to whom, how the model behaves and which viewpoints get amplified, what gets selected and transformed into model capabilities, who can build or operate powerful systems and on what terms">
<rect x="24" y="24" width="8" height="8" fill="#0099ff"/>
<text x="37" y="32" class="ssub">your data</text>
<ellipse cx="390" cy="62" rx="11" ry="3" fill="#3a3a78" opacity=".08"/>
<g transform="translate(390,60) scale(0.85)" stroke="#2a2a3a" stroke-width="1.6" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g>
<text x="404" y="40" class="ssub">you</text>
<text x="252" y="84" class="slbl" text-anchor="end" style="fill:#0099ff">what the layer sees</text>
<text x="252" y="98" class="ssub" text-anchor="end">surveillance</text>
<text x="516" y="84" class="slbl">what its operator can decide</text>
<text x="516" y="98" class="ssub">influence &amp; gatekeeping</text>
<path id="imflow" d="M 390 66 V 428" fill="none" stroke="#0099ff" stroke-width="1" opacity=".22"/>
<polygon points="290,120 316,107 496,107 470,120" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="470,120 496,107 496,139 470,152" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="290" y="120" width="180" height="32" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/>
<text x="304" y="141" class="slbl">applications &amp; agents</text>
<text x="50" y="132" class="sdata">prompts, files,</text>
<text x="50" y="145" class="sdata">preferences &amp; actions</text>
<text x="516" y="132" class="schk">which options are presented,</text>
<text x="516" y="145" class="schk">which get pursued</text>
<polygon points="290,190 316,177 496,177 470,190" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="470,190 496,177 496,209 470,222" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="290" y="190" width="180" height="32" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/>
<text x="304" y="211" class="slbl">inference &amp; serving</text>
<text x="50" y="202" class="sdata">queries, responses, metadata --</text>
<text x="50" y="215" class="sdata">possibly retained</text>
<text x="516" y="202" class="schk">which capabilities are</text>
<text x="516" y="215" class="schk">available, and to whom</text>
<polygon points="290,260 316,247 496,247 470,260" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="470,260 496,247 496,279 470,292" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="290" y="260" width="180" height="32" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/>
<text x="304" y="281" class="slbl">models</text>
<text x="50" y="272" class="sdata">patterns from your data,</text>
<text x="50" y="285" class="sdata">encoded into the weights</text>
<text x="516" y="272" class="schk">how the model behaves, which</text>
<text x="516" y="285" class="schk">viewpoints get amplified</text>
<polygon points="290,330 316,317 496,317 470,330" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="470,330 496,317 496,349 470,362" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="290" y="330" width="180" height="32" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/>
<text x="304" y="351" class="slbl">training</text>
<text x="50" y="342" class="sdata">web data, licensed material,</text>
<text x="50" y="355" class="sdata">synthetic data, user interactions</text>
<text x="516" y="342" class="schk">what gets selected &amp; transformed</text>
<text x="516" y="355" class="schk">into model capabilities</text>
<polygon points="290,400 316,387 496,387 470,400" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="470,400 496,387 496,419 470,432" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="290" y="400" width="180" height="32" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/>
<text x="304" y="421" class="slbl">hardware</text>
<text x="50" y="412" class="sdata">little of you directly --</text>
<text x="50" y="425" class="sdata">compute telemetry</text>
<text x="516" y="412" class="schk">who can build or operate powerful</text>
<text x="516" y="425" class="schk">systems, and on what terms</text>
<g class="pkt"><circle r="2.7" fill="#0099ff"><animateMotion dur="5.2s" begin="0s" repeatCount="indefinite"><mpath href="#imflow"/></animateMotion></circle></g>
<g class="pkt"><circle r="2.7" fill="#0099ff"><animateMotion dur="5.2s" begin="1.3s" repeatCount="indefinite"><mpath href="#imflow"/></animateMotion></circle></g>
<g class="pkt"><circle r="2.7" fill="#0099ff"><animateMotion dur="5.2s" begin="2.6s" repeatCount="indefinite"><mpath href="#imflow"/></animateMotion></circle></g>
<g class="pkt"><circle r="2.7" fill="#0099ff"><animateMotion dur="5.2s" begin="3.9s" repeatCount="indefinite"><mpath href="#imflow"/></animateMotion></circle></g>
</svg>
<figcaption><strong>Figure 3:</strong> where the new intermediaries sit</figcaption>
</figure>
<p>Today these seeing and decision-making roles increasingly sit within connected corporate ecosystems, creating chains of intermediaries whose power compounds across the stack. The Mythos export control episode<sup id="fnref:10"><a href="#fn:10" class="footnote-ref" role="doc-noteref">10</a></sup> showed how such a control point can be exercised: a government directive to one model provider caused access to a general-purpose capability to disappear worldwide. These intermediaries already shape not only what people see, but what they can do. As agents are entrusted with more of our economic and social activity, that control will extend further into the world.</p>
<h3 id="two-responses-verifiability-and-plurality">Two responses: verifiability and plurality</h3>
<p>At each layer, there are two complementary responses. The first is to make power more transparent and verifiable, so that institutions and citizens can check it. The second is to create technologically and economically credible alternatives; this response enables plurality across the stack, and enables people to exit when those checks fail. One constrains power; the other distributes it.</p>
<figure class="diagram">
<svg viewBox="0 0 680 380" role="img" aria-label="Two worlds. Left, if the layers stay closed: five houses stream blue data dots into two padlocked towers, each tower being all five layers of the stack fused into one block. Right, if the layers open up: the same five layers become shelves holding many small teal parts, some carrying ink check-seals meaning they can be verified, and two houses each trace their own blue path up the shelves, composing different stacks from different parts">
<text x="165" y="30" class="slbl" text-anchor="middle">if the layers stay closed</text>
<text x="165" y="44" class="ssub" text-anchor="middle">a few fused towers -- everyone routes through them</text>
<text x="500" y="30" class="slbl" text-anchor="middle" style="fill:#00b2a1">if the layers open up</text>
<text x="500" y="44" class="ssub" text-anchor="middle">every layer becomes a shelf of parts -- compose your own</text>
<g transform="translate(392,57) scale(0.7)" fill="none" stroke="#2a2a3a" stroke-width="1.2" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<text x="402" y="61" class="stiny">= checkable</text>
<polygon points="470,58 474,55 490,55 486,58" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".8"/>
<rect x="470" y="58" width="16" height="6" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".8"/>
<text x="492" y="64" class="stiny">= an alternative</text>
<line x1="320" y1="24" x2="320" y2="360" stroke="#ccc" stroke-dasharray="4 5"/>
<line x1="42" y1="112" x2="144.0" y2="221.5" stroke="#0099ff" stroke-width="1" opacity=".22"/>
<g class="pkt"><circle r="2.5" fill="#0099ff"><animateMotion dur="3s" begin="0.0s" repeatCount="indefinite" path="M 42 112 L 144.0 221.5"/></circle></g>
<line x1="160" y1="80" x2="144.0" y2="221.5" stroke="#0099ff" stroke-width="1" opacity=".22"/>
<g class="pkt"><circle r="2.5" fill="#0099ff"><animateMotion dur="3s" begin="0.4s" repeatCount="indefinite" path="M 160 80 L 144.0 221.5"/></circle></g>
<line x1="284" y1="108" x2="248.5" y2="190.0" stroke="#0099ff" stroke-width="1" opacity=".22"/>
<g class="pkt"><circle r="2.5" fill="#0099ff"><animateMotion dur="3s" begin="0.8s" repeatCount="indefinite" path="M 284 108 L 248.5 190.0"/></circle></g>
<line x1="38" y1="228" x2="144.0" y2="221.5" stroke="#0099ff" stroke-width="1" opacity=".22"/>
<g class="pkt"><circle r="2.5" fill="#0099ff"><animateMotion dur="3s" begin="1.2s" repeatCount="indefinite" path="M 38 228 L 144.0 221.5"/></circle></g>
<line x1="292" y1="262" x2="248.5" y2="190.0" stroke="#0099ff" stroke-width="1" opacity=".22"/>
<g class="pkt"><circle r="2.5" fill="#0099ff"><animateMotion dur="3s" begin="1.6s" repeatCount="indefinite" path="M 292 262 L 248.5 190.0"/></circle></g>
<polygon points="95,280 109,273 193,273 179,280" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="179,280 193,273 193,288 179,295" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="95" y="280" width="84" height="15" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/><polygon points="95,264 109,257 193,257 179,264" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="179,264 193,257 193,272 179,279" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="95" y="264" width="84" height="15" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/><polygon points="95,248 109,241 193,241 179,248" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="179,248 193,241 193,256 179,263" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="95" y="248" width="84" height="15" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/><polygon points="95,232 109,225 193,225 179,232" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="179,232 193,225 193,240 179,247" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="95" y="232" width="84" height="15" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/><polygon points="95,216 109,209 193,209 179,216" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="179,216 193,209 193,224 179,231" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="95" y="216" width="84" height="15" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/>
<polygon points="210,238 221,233 287,233 276,238" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="276,238 287,233 287,245 276,250" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="210" y="238" width="66" height="12" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/><polygon points="210,225 221,220 287,220 276,225" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="276,225 287,220 287,232 276,237" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="210" y="225" width="66" height="12" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/><polygon points="210,212 221,207 287,207 276,212" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="276,212 287,207 287,219 276,224" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="210" y="212" width="66" height="12" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/><polygon points="210,199 221,194 287,194 276,199" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="276,199 287,194 287,206 276,211" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="210" y="199" width="66" height="12" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/><polygon points="210,186 221,181 287,181 276,186" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="276,186 287,181 287,193 276,198" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="210" y="186" width="66" height="12" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/>
<g transform="translate(137,245) scale(1.0)"><path d="M -4 0 v -3 a 4 4 0 0 1 8 0 v 3" fill="none" stroke="#4a4a46" stroke-width="1.4"/><rect x="-6" y="0" width="12" height="9" rx="2" fill="#f7f4ea" stroke="#4a4a46" stroke-width="1.4"/></g>
<g transform="translate(243,210) scale(0.85)"><path d="M -4 0 v -3 a 4 4 0 0 1 8 0 v 3" fill="none" stroke="#4a4a46" stroke-width="1.4"/><rect x="-6" y="0" width="12" height="9" rx="2" fill="#f7f4ea" stroke="#4a4a46" stroke-width="1.4"/></g>
<g transform="translate(42,112) scale(1.0)" stroke="#4a4a46" stroke-width="1"><rect x="-6" y="-8" width="12" height="8" fill="#f7f4ea"/><polygon points="-8,-8 8,-8 0,-15" fill="#ebe4d0"/></g>
<g transform="translate(160,80) scale(1.0)" stroke="#4a4a46" stroke-width="1"><rect x="-6" y="-8" width="12" height="8" fill="#f7f4ea"/><polygon points="-8,-8 8,-8 0,-15" fill="#ebe4d0"/></g>
<g transform="translate(284,108) scale(1.0)" stroke="#4a4a46" stroke-width="1"><rect x="-6" y="-8" width="12" height="8" fill="#f7f4ea"/><polygon points="-8,-8 8,-8 0,-15" fill="#ebe4d0"/></g>
<g transform="translate(38,228) scale(1.0)" stroke="#4a4a46" stroke-width="1"><rect x="-6" y="-8" width="12" height="8" fill="#f7f4ea"/><polygon points="-8,-8 8,-8 0,-15" fill="#ebe4d0"/></g>
<g transform="translate(292,262) scale(1.0)" stroke="#4a4a46" stroke-width="1"><rect x="-6" y="-8" width="12" height="8" fill="#f7f4ea"/><polygon points="-8,-8 8,-8 0,-15" fill="#ebe4d0"/></g>
<line x1="100" y1="314" x2="116" y2="298" stroke="#777" stroke-width="1" stroke-dasharray="3 3" opacity=".6"/>
<text x="96" y="328" class="ssub" text-anchor="middle">all five layers, fused shut</text>
<path d="M 410 332 L 419 296 L 419 246 L 475 196 L 419 146 L 475 96" fill="none" stroke="#0099ff" stroke-width="1" opacity=".22"/>
<path d="M 566 332 L 475 296 L 531 246 L 587 196 L 531 146 L 587 96" fill="none" stroke="#0099ff" stroke-width="1" opacity=".22"/>
<g class="pkt"><circle r="2.2" fill="#0099ff"><animateMotion dur="4.4s" begin="0s" repeatCount="indefinite" path="M 410 332 L 419 296 L 419 246 L 475 196 L 419 146 L 475 96"/></circle></g>
<g class="pkt"><circle r="2.2" fill="#0099ff"><animateMotion dur="4.4s" begin="2.2s" repeatCount="indefinite" path="M 410 332 L 419 296 L 419 246 L 475 196 L 419 146 L 475 96"/></circle></g>
<g class="pkt"><circle r="2.2" fill="#0099ff"><animateMotion dur="4.4s" begin="0.9s" repeatCount="indefinite" path="M 566 332 L 475 296 L 531 246 L 587 196 L 531 146 L 587 96"/></circle></g>
<g class="pkt"><circle r="2.2" fill="#0099ff"><animateMotion dur="4.4s" begin="3.1s" repeatCount="indefinite" path="M 566 332 L 475 296 L 531 246 L 587 196 L 531 146 L 587 96"/></circle></g>
<text x="332" y="101" class="stiny">apps &amp; agents</text>
<polygon points="398,90 405,86 447,86 440,90" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="398" y="90" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<polygon points="454,90 461,86 503,86 496,90" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="454" y="90" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<polygon points="510,90 517,86 559,86 552,90" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="510" y="90" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<polygon points="566,90 573,86 615,86 608,90" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="566" y="90" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<g transform="translate(494,87) scale(0.7)" fill="none" stroke="#2a2a3a" stroke-width="1.2" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<text x="332" y="151" class="stiny">inference</text>
<polygon points="398,140 405,136 447,136 440,140" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="398" y="140" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<polygon points="454,140 461,136 503,136 496,140" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="454" y="140" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<polygon points="510,140 517,136 559,136 552,140" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="510" y="140" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<g transform="translate(438,137) scale(0.7)" fill="none" stroke="#2a2a3a" stroke-width="1.2" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<text x="332" y="201" class="stiny">models</text>
<polygon points="398,190 405,186 447,186 440,190" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="398" y="190" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<polygon points="454,190 461,186 503,186 496,190" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="454" y="190" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<polygon points="510,190 517,186 559,186 552,190" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="510" y="190" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<polygon points="566,190 573,186 615,186 608,190" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="566" y="190" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<g transform="translate(550,187) scale(0.7)" fill="none" stroke="#2a2a3a" stroke-width="1.2" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<text x="332" y="251" class="stiny">training</text>
<polygon points="398,240 405,236 447,236 440,240" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="398" y="240" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<polygon points="454,240 461,236 503,236 496,240" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="454" y="240" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<polygon points="510,240 517,236 559,236 552,240" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="510" y="240" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<g transform="translate(494,237) scale(0.7)" fill="none" stroke="#2a2a3a" stroke-width="1.2" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<text x="332" y="301" class="stiny">hardware</text>
<polygon points="398,290 405,286 447,286 440,290" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="398" y="290" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<polygon points="454,290 461,286 503,286 496,290" fill="#ebe4d0" stroke="#00b2a1" stroke-width=".9"/><rect x="454" y="290" width="42" height="13" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".9"/>
<g transform="translate(438,287) scale(0.7)" fill="none" stroke="#2a2a3a" stroke-width="1.2" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<g transform="translate(410,348) scale(1.0)" stroke="#4a4a46" stroke-width="1"><rect x="-6" y="-8" width="12" height="8" fill="#f7f4ea"/><polygon points="-8,-8 8,-8 0,-15" fill="#ebe4d0"/></g>
<g transform="translate(566,348) scale(1.0)" stroke="#4a4a46" stroke-width="1"><rect x="-6" y="-8" width="12" height="8" fill="#f7f4ea"/><polygon points="-8,-8 8,-8 0,-15" fill="#ebe4d0"/></g>
</svg>
<figcaption><strong>Figure 4:</strong> topology follows the stack</figcaption>
</figure>
<p>The good news is that alternatives are already being built, often for practical business reasons as much as ideological ones. In July, Nvidia and a consortium of others signed <a href="https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/" target="_blank" rel="noopener noreferrer">Open Weights and American AI Leadership</a>, making the case that open weights reduce costs, prevent lock-in, strengthen cybersecurity and let organisations control their own data and infrastructure. Thinking Machines has made <a href="https://thinkingmachines.ai/blog/the-future-worth-building-is-human/" target="_blank" rel="noopener noreferrer">a related case</a> for AI that can be shaped by the people it serves, rather than having its values determined in a handful of places, and followed it by releasing <a href="https://thinkingmachines.ai/news/introducing-inkling/" target="_blank" rel="noopener noreferrer">Inkling</a> with open weights. The motivations differ (competition, scientific transparency, sovereignty, privacy, customisation) but they point in the same direction: making AI more inspectable and giving people viable alternatives to centralised providers.<sup id="fnref:11"><a href="#fn:11" class="footnote-ref" role="doc-noteref">11</a></sup></p>
<blockquote>
<p>&ldquo;a single locus of value alignment, however well run, becomes a locus of power to be captured&rdquo;</p>
<p>&ndash; Thinking Machines&rsquo; manifesto</p></blockquote>
<p>Across the stack, both responses are already taking shape. Figure 5 maps some of the projects doing the work: at every layer, at least one way to check the incumbents and at least one credible alternative.</p>
<figure class="diagram wide">
<svg viewBox="0 0 720 460" role="img" aria-label="The AI stack as five isometric slabs -- applications and agents, inference and serving, models, training, hardware -- with blue data packets travelling from you down through every layer. Left of each layer, marked with an ink check-seal, how its power can be checked: audit trails recording what your agent did, with Langfuse offering open-source tracing of every step; Apple Private Cloud Compute, which keeps cloud inference but makes its privacy guarantees inspectable and cryptographically enforced, and AWS Nitro, whose isolation engine is formally verified; open weights anyone can inspect and test, plus independent evaluations of frontier models by METR and the UK AI Security Institute; OLMo publishing its data, code, recipes and checkpoints for scrutiny, and the Data Provenance Initiative auditing training datasets; chip attestation proving what hardware is running, as in NVIDIA confidential computing, and Caliptra, an open-source silicon root of trust. Right of each layer, in teal, the alternatives keeping it plural: OpenHands and Open WebUI, self-hostable apps that let you swap the model underneath and keep your interfaces, workflows and data; vLLM and llama.cpp, running models on infrastructure you control; DeepSeek, Qwen and Thinking Machines, open weights you can download, modify and run, which no provider can withdraw; Pluralis, spreading training itself across the internet, a 7.5B model on 1,700 consumer GPUs with no datacentre; Tenstorrent, open chip documentation and a RISC-V software stack, an alternative at the layer everything else depends on. A small sealed proof travels back up from the inference layer to you. Project names are links">
<rect x="24" y="24" width="8" height="8" fill="#0099ff"/>
<text x="37" y="32" class="ssub">your data</text>
<ellipse cx="390" cy="62" rx="11" ry="3" fill="#3a3a78" opacity=".08"/>
<g transform="translate(390,60) scale(0.85)" stroke="#2a2a3a" stroke-width="1.6" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g>
<text x="404" y="40" class="ssub">you</text>
<g transform="translate(140,80) scale(0.9)" fill="none" stroke="#2a2a3a" stroke-width="1.2" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<text x="252" y="84" class="slbl" text-anchor="end">checking power</text>
<text x="252" y="98" class="ssub" text-anchor="end">each layer&#8217;s power made verifiable</text>
<text x="516" y="84" class="slbl" style="fill:#00b2a1">plurality</text>
<text x="516" y="98" class="ssub">alternatives at each layer</text>
<path id="dflow" d="M 390 66 V 428" fill="none" stroke="#0099ff" stroke-width="1" opacity=".22"/>
<path id="dproof" d="M 372 205 C 352 160 358 100 384 66" fill="none" stroke="#2a2a3a" stroke-width="1" stroke-dasharray="2 3" opacity=".18"/>
<text x="398" y="100" class="ssub">a proof rides back</text>
<polygon points="290,120 316,107 496,107 470,120" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="470,120 496,107 496,139 470,152" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="290" y="120" width="180" height="32" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/>
<text x="304" y="141" class="slbl">applications &amp; agents</text>
<text x="50" y="132" class="schk"><a href="https://langfuse.com/" target="_blank" rel="noopener">Langfuse</a>: open-source tracing -- an audit</text>
<text x="50" y="145" class="schk">trail of every step your agent took</text>
<text x="516" y="132" class="sopen"><a href="https://www.openhands.dev/" target="_blank" rel="noopener">OpenHands</a> &#183; <a href="https://openwebui.com/" target="_blank" rel="noopener">Open WebUI</a>: self-hostable</text>
<text x="516" y="145" class="sopen">apps -- swap the model underneath,</text>
<text x="516" y="158" class="sopen">keep your interfaces, workflows &amp; data</text>
<g transform="translate(36,135) scale(0.85)" fill="none" stroke="#2a2a3a" stroke-width="1.2" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<polygon points="290,190 316,177 496,177 470,190" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="470,190 496,177 496,209 470,222" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="290" y="190" width="180" height="32" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/>
<text x="304" y="211" class="slbl">inference &amp; serving</text>
<text x="50" y="202" class="schk"><a href="https://security.apple.com/documentation/private-cloud-compute/verifiabletransparency" target="_blank" rel="noopener">Apple PCC</a> &#183; <a href="https://aws.amazon.com/blogs/compute/aws-nitro-isolation-engine-formally-verifying-the-hypervisor-in-the-aws-nitro-system/" target="_blank" rel="noopener">AWS Nitro</a>: keep the cloud,</text>
<text x="50" y="215" class="schk">but make its guarantees checkable --</text>
<text x="50" y="228" class="schk">attested software, verified isolation</text>
<text x="516" y="202" class="sopen"><a href="https://docs.vllm.ai/en/stable/" target="_blank" rel="noopener">vLLM</a> &#183; <a href="https://github.com/ggml-org/llama.cpp" target="_blank" rel="noopener">llama.cpp</a>: run models</text>
<text x="516" y="215" class="sopen">on infrastructure you control</text>
<g transform="translate(36,205) scale(0.85)" fill="none" stroke="#2a2a3a" stroke-width="1.2" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<polygon points="290,260 316,247 496,247 470,260" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="470,260 496,247 496,279 470,292" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="290" y="260" width="180" height="32" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/>
<text x="304" y="281" class="slbl">models</text>
<text x="50" y="272" class="schk"><a href="https://metr.org/" target="_blank" rel="noopener">METR</a> &#183; <a href="https://www.aisi.gov.uk/" target="_blank" rel="noopener">UK AISI</a>: independent evals of</text>
<text x="50" y="285" class="schk">frontier models -- and open weights</text>
<text x="50" y="298" class="schk">anyone can inspect &amp; test</text>
<text x="516" y="272" class="sopen"><a href="https://huggingface.co/deepseek-ai" target="_blank" rel="noopener">DeepSeek</a> &#183; <a href="https://huggingface.co/Qwen" target="_blank" rel="noopener">Qwen</a> &#183; <a href="https://thinkingmachines.ai/news/introducing-inkling/" target="_blank" rel="noopener">Thinking Machines</a>:</text>
<text x="516" y="285" class="sopen">open weights you can download, modify</text>
<text x="516" y="298" class="sopen">&amp; run -- no provider can withdraw them</text>
<g transform="translate(36,275) scale(0.85)" fill="none" stroke="#2a2a3a" stroke-width="1.2" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<polygon points="290,330 316,317 496,317 470,330" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="470,330 496,317 496,349 470,362" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="290" y="330" width="180" height="32" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/>
<text x="304" y="351" class="slbl">training</text>
<text x="50" y="342" class="schk"><a href="https://allenai.org/olmo2" target="_blank" rel="noopener">OLMo</a> &#183; <a href="https://www.dataprovenance.org/" target="_blank" rel="noopener">Data Provenance Initiative</a>:</text>
<text x="50" y="355" class="schk">data, code, recipes &amp; checkpoints</text>
<text x="50" y="368" class="schk">published; training datasets audited</text>
<text x="516" y="342" class="sopen"><a href="https://pluralis.ai/blog/pluralis-multi-party-training-stack/" target="_blank" rel="noopener">Pluralis</a>: training spread across the</text>
<text x="516" y="355" class="sopen">internet -- a 7.5B model on 1,700</text>
<text x="516" y="368" class="sopen">consumer GPUs, no datacentre needed</text>
<g transform="translate(36,345) scale(0.85)" fill="none" stroke="#2a2a3a" stroke-width="1.2" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<polygon points="290,400 316,387 496,387 470,400" fill="#ebe4d0" stroke="#4a4a46" stroke-width=".9"/><polygon points="470,400 496,387 496,419 470,432" fill="#d2cab2" stroke="#4a4a46" stroke-width=".9"/><rect x="290" y="400" width="180" height="32" fill="#f7f4ea" stroke="#4a4a46" stroke-width=".9"/>
<text x="304" y="421" class="slbl">hardware</text>
<text x="50" y="412" class="schk"><a href="https://www.nvidia.com/en-us/data-center/solutions/confidential-computing/" target="_blank" rel="noopener">NVIDIA confidential computing</a> &#183; <a href="https://github.com/chipsalliance/caliptra" target="_blank" rel="noopener">Caliptra</a>:</text>
<text x="50" y="425" class="schk">chips that attest to what they&#8217;re running,</text>
<text x="50" y="438" class="schk">and an open-source root of trust</text>
<text x="516" y="412" class="sopen"><a href="https://github.com/tenstorrent" target="_blank" rel="noopener">Tenstorrent</a>: open chip docs &amp; a RISC-V</text>
<text x="516" y="425" class="sopen">software stack: an alternative at the</text>
<text x="516" y="438" class="sopen">layer everything else depends on</text>
<g transform="translate(36,415) scale(0.85)" fill="none" stroke="#2a2a3a" stroke-width="1.2" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<g class="pkt"><circle r="2.7" fill="#0099ff"><animateMotion dur="5.2s" begin="0s" repeatCount="indefinite"><mpath href="#dflow"/></animateMotion></circle></g>
<g class="pkt"><circle r="2.7" fill="#0099ff"><animateMotion dur="5.2s" begin="1.3s" repeatCount="indefinite"><mpath href="#dflow"/></animateMotion></circle></g>
<g class="pkt"><circle r="2.7" fill="#0099ff"><animateMotion dur="5.2s" begin="2.6s" repeatCount="indefinite"><mpath href="#dflow"/></animateMotion></circle></g>
<g class="pkt"><circle r="2.7" fill="#0099ff"><animateMotion dur="5.2s" begin="3.9s" repeatCount="indefinite"><mpath href="#dflow"/></animateMotion></circle></g>
<g class="pkt"><g fill="none" stroke="#2a2a3a" stroke-width="1.1" stroke-linecap="round"><circle cx="0" cy="0" r="4.5" fill="#f7f4ea"/><path d="M -2 0.2 L -0.6 1.9 L 2.2 -1.7"/><animateMotion dur="4.6s" begin="1.4s" repeatCount="indefinite"><mpath href="#dproof"/></animateMotion></g></g>
</svg>
<figcaption><strong>Figure 5:</strong> opening up the stack</figcaption>
</figure>
<h3 id="the-sixth-layer">The sixth layer</h3>
<p>As AI agents begin to be deployed in the wild and start communicating with one another, a sixth layer is emerging: the coordination layer. The infrastructure that enables agents to interact with one another, including communication channels, protocols, negotiation practices, sensors, identity systems. Without it, an agent is essentially confined to single-player mode.</p>
<p>This layer could enable productive networks of agents and unlock tremendous value for humanity. But it could also negate efforts to distribute power elsewhere in the stack. Even an open model running on personal hardware does not protect us if every agentic interaction must clear through a central platform.</p>
<figure class="diagram">
<svg viewBox="0 0 720 360" role="img" aria-label="Two panels showing the same ten agents, each standing on its own tiny five-layer stack, connected two ways. Left, through one platform: every agent links only to a hub in the centre, labelled platform, and blue packets travel from agent to hub to agent. Right, between the agents themselves: the same agents are joined in a mesh of teal links, some marked with a check-seal, with no hub in the middle, and packets travel directly from agent to agent. Legend: the tiny stacks are the five layers each agent runs on; the links are the sixth layer">
<text x="178" y="26" class="slbl" text-anchor="middle">through one platform</text>
<text x="178" y="40" class="ssub" text-anchor="middle">a hub sets identity, rules &amp; fees -- every exchange passes through it</text>
<text x="542" y="26" class="slbl" text-anchor="middle" style="fill:#00b2a1">between the agents themselves</text>
<text x="542" y="40" class="ssub" text-anchor="middle">protocols each pair can run -- identity, payment &amp; proof travel on the link</text>
<line x1="360" y1="20" x2="360" y2="318" stroke="#ccc" stroke-dasharray="4 5"/>
<line x1="178.0" y1="117.0" x2="178" y2="208" stroke="#2a2a3a" stroke-width=".9" opacity=".3"/>
<line x1="232.1" y1="134.6" x2="178" y2="208" stroke="#2a2a3a" stroke-width=".9" opacity=".3"/>
<line x1="265.5" y1="180.6" x2="178" y2="208" stroke="#2a2a3a" stroke-width=".9" opacity=".3"/>
<line x1="265.5" y1="237.4" x2="178" y2="208" stroke="#2a2a3a" stroke-width=".9" opacity=".3"/>
<line x1="232.1" y1="283.4" x2="178" y2="208" stroke="#2a2a3a" stroke-width=".9" opacity=".3"/>
<line x1="178.0" y1="301.0" x2="178" y2="208" stroke="#2a2a3a" stroke-width=".9" opacity=".3"/>
<line x1="123.9" y1="283.4" x2="178" y2="208" stroke="#2a2a3a" stroke-width=".9" opacity=".3"/>
<line x1="90.5" y1="237.4" x2="178" y2="208" stroke="#2a2a3a" stroke-width=".9" opacity=".3"/>
<line x1="90.5" y1="180.6" x2="178" y2="208" stroke="#2a2a3a" stroke-width=".9" opacity=".3"/>
<line x1="123.9" y1="134.6" x2="178" y2="208" stroke="#2a2a3a" stroke-width=".9" opacity=".3"/>
<rect x="148" y="197" width="60" height="22" rx="1" fill="#2a2a3a"/><text x="178" y="212" class="stiny" text-anchor="middle" style="fill:#f7f4ea;font-weight:600">platform</text>
<g transform="translate(178.0,110.0) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="171.0" y="112.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="171.0" y="115.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="171.0" y="117.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="171.0" y="120.3" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="171.0" y="122.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(232.1,127.6) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="225.1" y="130.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="225.1" y="132.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="225.1" y="135.29999999999998" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="225.1" y="137.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="225.1" y="140.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(265.5,173.6) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="258.5" y="176.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="258.5" y="178.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="258.5" y="181.29999999999998" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="258.5" y="183.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="258.5" y="186.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(265.5,230.4) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="258.5" y="232.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="258.5" y="235.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="258.5" y="238.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="258.5" y="240.70000000000002" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="258.5" y="243.3" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(232.1,276.4) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="225.1" y="278.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="225.1" y="281.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="225.1" y="284.09999999999997" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="225.1" y="286.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="225.1" y="289.29999999999995" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(178.0,294.0) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="171.0" y="296.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="171.0" y="299.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="171.0" y="301.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="171.0" y="304.3" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="171.0" y="306.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(123.9,276.4) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="116.9" y="278.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="116.9" y="281.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="116.9" y="284.09999999999997" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="116.9" y="286.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="116.9" y="289.29999999999995" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(90.5,230.4) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="83.5" y="232.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="83.5" y="235.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="83.5" y="238.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="83.5" y="240.70000000000002" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="83.5" y="243.3" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(90.5,173.6) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="83.5" y="176.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="83.5" y="178.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="83.5" y="181.29999999999998" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="83.5" y="183.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="83.5" y="186.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(123.9,127.6) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="116.9" y="130.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="116.9" y="132.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="116.9" y="135.29999999999998" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="116.9" y="137.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="116.9" y="140.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g class="pkt"><circle r="2.4" fill="#0099ff"><animateMotion dur="4.8s" begin="0s" repeatCount="indefinite" path="M 178.0 117.0 L 178 208 L 178.0 301.0"/></circle></g>
<g class="pkt"><circle r="2.4" fill="#0099ff"><animateMotion dur="5.6s" begin="0s" repeatCount="indefinite" path="M 265.5 237.4 L 178 208 L 90.5 180.6"/></circle></g>
<g class="pkt"><circle r="2.4" fill="#0099ff"><animateMotion dur="4.4s" begin="0s" repeatCount="indefinite" path="M 90.5 237.4 L 178 208 L 232.1 134.6"/></circle></g>
<line x1="542.0" y1="117.0" x2="596.1" y2="134.6" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<line x1="596.1" y1="134.6" x2="629.5" y2="180.6" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<line x1="629.5" y1="180.6" x2="629.5" y2="237.4" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<line x1="629.5" y1="237.4" x2="596.1" y2="283.4" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<line x1="596.1" y1="283.4" x2="542.0" y2="301.0" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<line x1="542.0" y1="301.0" x2="487.9" y2="283.4" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<line x1="487.9" y1="283.4" x2="454.5" y2="237.4" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<line x1="454.5" y1="237.4" x2="454.5" y2="180.6" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<line x1="454.5" y1="180.6" x2="487.9" y2="134.6" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<line x1="487.9" y1="134.6" x2="542.0" y2="117.0" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<line x1="542.0" y1="117.0" x2="629.5" y2="237.4" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<line x1="629.5" y1="180.6" x2="542.0" y2="301.0" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<line x1="596.1" y1="283.4" x2="454.5" y2="237.4" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<line x1="487.9" y1="283.4" x2="487.9" y2="134.6" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<line x1="454.5" y1="180.6" x2="596.1" y2="134.6" stroke="#00b2a1" stroke-width=".9" opacity=".55"/>
<g transform="translate(612.8,157.6) scale(0.55)" fill="none" stroke="#2a2a3a" stroke-width="1.3" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<g transform="translate(515.0,292.2) scale(0.55)" fill="none" stroke="#2a2a3a" stroke-width="1.3" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<g transform="translate(471.2,157.6) scale(0.55)" fill="none" stroke="#2a2a3a" stroke-width="1.3" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<g transform="translate(585.8,177.2) scale(0.55)" fill="none" stroke="#2a2a3a" stroke-width="1.3" stroke-linecap="round"><circle cx="0" cy="0" r="5.2" fill="#f7f4ea"/><path d="M -2.4 0.3 L -0.7 2.2 L 2.6 -2.1"/></g>
<text x="542" y="212" class="stiny" text-anchor="middle" style="fill:#aaa">no hub</text>
<g transform="translate(542.0,110.0) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="535.0" y="112.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="535.0" y="115.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="535.0" y="117.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="535.0" y="120.3" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="535.0" y="122.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(596.1,127.6) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="589.1" y="130.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="589.1" y="132.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="589.1" y="135.29999999999998" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="589.1" y="137.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="589.1" y="140.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(629.5,173.6) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="622.5" y="176.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="622.5" y="178.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="622.5" y="181.29999999999998" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="622.5" y="183.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="622.5" y="186.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(629.5,230.4) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="622.5" y="232.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="622.5" y="235.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="622.5" y="238.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="622.5" y="240.70000000000002" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="622.5" y="243.3" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(596.1,276.4) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="589.1" y="278.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="589.1" y="281.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="589.1" y="284.09999999999997" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="589.1" y="286.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="589.1" y="289.29999999999995" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(542.0,294.0) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="535.0" y="296.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="535.0" y="299.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="535.0" y="301.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="535.0" y="304.3" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="535.0" y="306.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(487.9,276.4) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="480.9" y="278.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="480.9" y="281.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="480.9" y="284.09999999999997" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="480.9" y="286.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="480.9" y="289.29999999999995" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(454.5,230.4) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="447.5" y="232.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="447.5" y="235.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="447.5" y="238.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="447.5" y="240.70000000000002" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="447.5" y="243.3" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(454.5,173.6) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="447.5" y="176.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="447.5" y="178.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="447.5" y="181.29999999999998" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="447.5" y="183.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="447.5" y="186.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g transform="translate(487.9,127.6) scale(0.5)" stroke="#2a2a3a" stroke-width="1.8" fill="none" stroke-linecap="round"><circle cx="0" cy="-24" r="5" fill="#f7f4ea"/><line x1="0" y1="-19" x2="0" y2="-7"/><line x1="-7" y1="-15" x2="7" y2="-15"/><line x1="0" y1="-7" x2="-5" y2="0"/><line x1="0" y1="-7" x2="5" y2="0"/></g><rect x="480.9" y="130.1" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="480.9" y="132.7" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="480.9" y="135.29999999999998" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="480.9" y="137.9" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="480.9" y="140.5" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/>
<g class="pkt"><circle r="2.4" fill="#0099ff"><animateMotion dur="4.2s" begin="0s" repeatCount="indefinite" path="M 542.0 117.0 L 596.1 134.6 L 629.5 180.6"/></circle></g>
<g class="pkt"><circle r="2.4" fill="#0099ff"><animateMotion dur="5.0s" begin="0s" repeatCount="indefinite" path="M 596.1 283.4 L 542.0 301.0 L 487.9 283.4"/></circle></g>
<g class="pkt"><circle r="2.4" fill="#0099ff"><animateMotion dur="4.7s" begin="0s" repeatCount="indefinite" path="M 487.9 134.6 L 542.0 117.0 L 629.5 237.4"/></circle></g>
<g transform="translate(212,338)"><rect x="0" y="-4.0" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="0" y="-1.4" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="0" y="1.2000000000000002" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="0" y="3.8000000000000007" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/><rect x="0" y="6.4" width="14" height="1.7" fill="#f7f4ea" stroke="#00b2a1" stroke-width=".6"/></g>
<text x="232" y="343" class="stiny">an agent&#8217;s own five layers (Figure 3)</text>
<line x1="418" y1="340" x2="446" y2="340" stroke="#00b2a1" stroke-width="1"/>
<text x="452" y="343" class="stiny">the sixth layer: the links between agents</text>
</svg>
<figcaption><strong>Figure 6:</strong> the sixth layer</figcaption>
</figure>
<p>Consider the following example: your agent is negotiating a job offer with a company&rsquo;s agent. You don&rsquo;t want to reveal your minimum salary expectations, but they don&rsquo;t want to reveal their ceiling. The easy architecture would be that both agents are hosted by the same provider which, as the trusted information escrow, matches them and lets each agent query the other&rsquo;s context without &ldquo;seeing&rdquo; it. It&rsquo;s convenient, it&rsquo;s doable today and it&rsquo;s easily policed in case of agent misbehavior.</p>
<p>If this becomes a default architecture, it could also mean that a large share of negotiation in society &ndash; salaries, rents, settlements, acquisitions &ndash; routes through a handful of intermediaries with a complete view of both sides.</p>
<h3 id="scaling-trust">Scaling Trust</h3>
<p>Trusted information escrows have historically helped us navigate hard tradeoffs: security against utility, convenience against control, oversight against privacy. What’s exciting is that <a href="https://aiprospects.substack.com/p/security-without-dystopia-new-options" target="_blank" rel="noopener noreferrer">over the last few years, this tradeoff space itself has begun to move.</a><sup id="fnref:12"><a href="#fn:12" class="footnote-ref" role="doc-noteref">12</a></sup> Emerging technologies can relocate trust away from an intermediary with unrestricted access to everyone’s information and into cryptography, hardware, and other verifiable, scalable roots of trust. Increasingly that includes the physical world too &ndash; sensors that can prove what they measured, chips that can prove what they ran &ndash; because agents are heading there as well.</p>
<p>Now our two negotiating agents have another option: run a two-party secure computation that answers &ldquo;do our preferences match?&rdquo; and nothing else, or meet inside a trusted hardware enclave, and work it out while each side&rsquo;s limit stays its own. The previous trusted intermediary gets replaced by mathematics and silicon.<sup id="fnref:13"><a href="#fn:13" class="footnote-ref" role="doc-noteref">13</a></sup> The new tools dissolve the old tradeoff. You can have privacy <em>and</em> utility,<sup id="fnref:14"><a href="#fn:14" class="footnote-ref" role="doc-noteref">14</a></sup> security <em>and</em> efficiency.</p>
<figure class="diagram">
<svg viewBox="0 0 720 390" role="img" aria-label="A chart with utility on the horizontal axis and security on the vertical axis, and three frontiers shading from ink to teal. Innermost, ink, where we were: private but limited, a trusted middleman, useful but exposed. Further out, light teal, where we are (zero-knowledge, private set intersection, multi-party computation, enclaves), each point tagged with its technology: age proofs that reveal nothing else (zero-knowledge proofs), breach-checked passwords (private set intersection), cloud AI the provider cannot read (hardware enclaves with attestation). Outermost, dashed teal, where we could be, four points: audit trails that open only under due process (threshold decryption), proof that the evaluated model is the one serving you (attested inference, zkML), a salary negotiated with no hands revealed (two-party secure computation, generated on demand), and data used then provably not retained (attested enclaves)">
<g transform="translate(0,50)">
<line x1="80" y1="290" x2="80" y2="48" stroke="#4a4a46" stroke-width="1.2"/>
<polygon points="80,40 76,50 84,50" fill="#4a4a46"/>
<line x1="80" y1="290" x2="596" y2="290" stroke="#4a4a46" stroke-width="1.2"/>
<polygon points="604,290 594,286 594,294" fill="#4a4a46"/>
<text x="56" y="32" class="slbl">security</text>
<text x="596" y="312" class="slbl" text-anchor="end">utility</text>
<path d="M 95 85 C 100 210 250 264 575 267" fill="none" stroke="#2a2a3a" stroke-width="1.6"/>
<text x="582" y="271" class="ssub" style="fill:#2a2a3a;font-weight:600;font-size:11px">where we were</text>
<circle cx="101" cy="120" r="4" fill="#f7f4ea" stroke="#2a2a3a" stroke-width="1.3"/>
<text x="112" y="112" class="ssub">private but limited</text>
<circle cx="192" cy="212" r="4" fill="#f7f4ea" stroke="#2a2a3a" stroke-width="1.3"/>
<text x="204" y="206" class="ssub">a trusted middleman</text>
<circle cx="364" cy="255" r="4" fill="#f7f4ea" stroke="#2a2a3a" stroke-width="1.3"/>
<text x="376" y="282" class="ssub">useful but exposed</text>
<path class="draw" d="M 95 66 C 220 78 420 130 585 250" fill="none" stroke="#7cc9bc" stroke-width="1.8"/>
<text x="592" y="254" class="ssub" style="fill:#4aa998;font-weight:600;font-size:11px">where we are</text>
<circle cx="325" cy="117" r="4.5" fill="#7cc9bc"/>
<text x="315" y="131" class="ssub" text-anchor="end">age proofs, nothing else revealed</text>
<text x="315" y="143" class="sopen" text-anchor="end">zero-knowledge proofs</text>
<circle cx="419" cy="155" r="4.5" fill="#7cc9bc"/>
<text x="409" y="169" class="ssub" text-anchor="end">breach-checked passwords</text>
<text x="409" y="181" class="sopen" text-anchor="end">private set intersection</text>
<circle cx="509" cy="201" r="4.5" fill="#7cc9bc"/>
<text x="499" y="215" class="ssub" text-anchor="end">cloud AI the provider can&#8217;t read</text>
<text x="499" y="227" class="sopen" text-anchor="end">hardware enclaves + attestation</text>
<path d="M 95 48 C 280 52 500 88 600 195" fill="none" stroke="#00b2a1" stroke-width="1.6" stroke-dasharray="7 5" opacity=".9"/>
<text x="608" y="200" class="sopen" style="font-weight:600;font-size:11px">where we could be</text>
<line x1="608" y1="206" x2="716" y2="206" stroke="#00b2a1" stroke-width="1.2" stroke-dasharray="4 3"/>
<circle cx="200" cy="54" r="4.5" fill="#f7f4ea" stroke="#00b2a1" stroke-width="1.4" stroke-dasharray="2.5 2.5"/>
<line x1="200" y1="-2" x2="200" y2="47" stroke="#00b2a1" stroke-width="1" stroke-dasharray="2 3" opacity=".55"/>
<text x="200" y="-20" class="ssub" text-anchor="middle">audit trails that open only under due process</text>
<text x="200" y="-8" class="sopen" text-anchor="middle">threshold decryption</text>
<circle cx="335" cy="73" r="4.5" fill="#f7f4ea" stroke="#00b2a1" stroke-width="1.4" stroke-dasharray="2.5 2.5"/>
<line x1="335" y1="34" x2="335" y2="66" stroke="#00b2a1" stroke-width="1" stroke-dasharray="2 3" opacity=".55"/>
<text x="335" y="16" class="ssub" text-anchor="middle">the evaluated model is the one serving you</text>
<text x="335" y="28" class="sopen" text-anchor="middle">attested inference &#183; zkML</text>
<circle cx="455" cy="106" r="4.5" fill="#f7f4ea" stroke="#00b2a1" stroke-width="1.4" stroke-dasharray="2.5 2.5"/>
<line x1="455" y1="-2" x2="455" y2="99" stroke="#00b2a1" stroke-width="1" stroke-dasharray="2 3" opacity=".55"/>
<text x="455" y="-20" class="ssub" text-anchor="middle">a salary negotiated, no hands revealed</text>
<text x="455" y="-8" class="sopen" text-anchor="middle">two-party secure computation, on demand</text>
<circle cx="560" cy="160" r="4.5" fill="#f7f4ea" stroke="#00b2a1" stroke-width="1.4" stroke-dasharray="2.5 2.5"/>
<line x1="560" y1="66" x2="560" y2="153" stroke="#00b2a1" stroke-width="1" stroke-dasharray="2 3" opacity=".55"/>
<text x="570" y="48" class="ssub" text-anchor="middle">used, then provably not retained</text>
<text x="570" y="60" class="sopen" text-anchor="middle">attested enclaves</text>
</g>
</svg>
<figcaption><strong>Figure 7:</strong> the moving frontier</figcaption>
</figure>
<p>Components of this technology already support large-scale applications,<sup id="fnref:15"><a href="#fn:15" class="footnote-ref" role="doc-noteref">15</a></sup> but they are not yet flexible, efficient, or usable enough for open-ended agentic coordination.<sup id="fnref:16"><a href="#fn:16" class="footnote-ref" role="doc-noteref">16</a></sup> AI could accelerate their development both by hiding complexity from users (e.g. enabling agents to generate bespoke security protocols on-demand) and by speeding up the research process (e.g. running research loops on cryptography research problems). This is a core pillar of <a href="https://aria.org.uk/media/dkhlumky/scaling-trust-programme-thesis.pdf" target="_blank" rel="noopener noreferrer">Scaling Trust</a>, and why we’re excited to fund these technologies and the underlying research behind them. We want to scale trust, without scaling trusted intermediaries.</p>
<h3 id="what-about-safety">What about safety?</h3>
<p>Readers who have come this far may empathise with the problems stated and still see (sometimes, painfully so) the other side: intermediaries are often where regulation is enforced, and they enable oversight and safety. A world with fewer intermediaries can indeed be a less governable world. And while I believe broadening direct access to powerful AI technologies is a net positive for humanity, it also comes with severe asymmetries in some domains. For instance, biosecurity is currently offence-dominant: a single malicious actor (or &lsquo;dissident&rsquo;), sufficiently empowered, can cause damage no defence yet can match.</p>
<p>So wat do? Are we stuck between a free but dangerous world, or a surveilled, controlled, &lsquo;safer&rsquo; world?</p>
<p>Part of this post&rsquo;s job is to show why the second option is not the safe harbour it appears to be, and to widen the safety conversation that often defaults to centralised control and alignment as the only available levers. A perfectly aligned model running on surveillance infrastructure still delivers the panopticon. Alignment binds the model to its principal; it does not bind the principal to us. And as laid out above, infrastructure outlives its operators, whatever is built under careful stewardship is inherited by whoever comes next.</p>
<p>Practically though, I have two answers for you:</p>
<ol>
<li>In cases where &rsquo;trusted&rsquo; intermediaries remain because it is the structural and/or safety best option (e.g. screening gene-synthesis orders), allowing the public to check their power, building technologies to constrain it, and minimising duopolies/monopolies to enable contestability goes a long way towards creating a safe, yet less surveilled society.</li>
<li>In cases where trusted intermediaries can be entirely removed, trust doesn&rsquo;t disappear, it shifts substrate to cryptography (trust in maths) and trusted hardware (trust in silicon). The same machinery that enables trustworthy interactions can enable distributed safety: proof that the safety-evaluated model was the one that ran, attestation that an agent stays within its declared constraints, audit trails that open under due process rather than on demand. The same goes for every layer of the stack, proving what a model was trained on, what a chip is running, what an inference provider retained. Overseers get proofs instead of feeds, dissolving the old tradeoff between oversight and privacy.</li>
</ol>
<h3 id="technology-is-not-enough">Technology is not enough</h3>
<p>We&rsquo;ve been somewhere like this before. In 1993, Eric Hughes wrote <a href="https://www.activism.net/cypherpunk/manifesto.html" target="_blank" rel="noopener noreferrer">A Cypherpunk&rsquo;s Manifesto</a>:</p>
<blockquote>
<p>&ldquo;Privacy is necessary for an open society in the electronic age&hellip; Privacy is the power to selectively reveal oneself to the world.&rdquo;</p></blockquote>
<p>At the time, the US government treated encryption as a munition, put it on the same export-control list as missiles, and spent years advocating for a phone chip with a built-in government backdoor. Cryptographers and privacy advocates like Bernstein and Zimmermann, together with organisations such as the Electronic Frontier Foundation, fought hard against the &rsquo;easy&rsquo; defaults, arguing that a backdoored system is weaker for everyone and that strong cryptography is a matter of privacy and free expression.<sup id="fnref:17"><a href="#fn:17" class="footnote-ref" role="doc-noteref">17</a></sup> Congress&rsquo;s own commissioned review agreed: the National Research Council&rsquo;s 1996 <a href="https://nap.nationalacademies.org/catalog/5131/cryptographys-role-in-securing-the-information-society" target="_blank" rel="noopener noreferrer">CRISIS report</a> concluded that the use of cryptography should not be restricted and export controls should be loosened. By 2000 the export controls had collapsed, and today, encryption has become core digital infrastructure, securing nearly all web traffic.<sup id="fnref:18"><a href="#fn:18" class="footnote-ref" role="doc-noteref">18</a></sup></p>
<p>I am not claiming today&rsquo;s situation is the same. The stakes are higher given how powerful the technology is; control arguably sits more with corporations than with governments, and I have yet to see a situation where a clearly sub-par technological option is being pushed against a better alternative for humanity. What I am claiming, however, is that the defaults for artificial intelligence are now being set at every layer of the stack, and that they will shape our future. Having technological alternatives won&rsquo;t be enough. We will need coordinated action across society: developers, policymakers, frontier labs, privacy and safety advocates, standards bodies, and citizens.</p>
<p>Which new intermediaries and points of information control are emerging? Which should remain, and how do we make those that do checkable and contestable by the people who depend on them? What kind of local maxima defaults do we risk falling into? How will we steer towards global maxima and which voices &ndash; whether policymakers, citizens, or organisations &ndash; will shape them? These questions deserve people, and institutions. If this is you, please reach out. We would like to support you!</p>
<hr>
<div class="colophon">
<p>By <a href="https://x.com/ObadiaAlex" target="_blank" rel="noopener noreferrer">Alex Obadia</a>, assisted by Fable 5. Thank you <a href="https://x.com/iamnotnicola" target="_blank" rel="noopener noreferrer">Nicola Greco</a>, <a href="https://x.com/AmmannNora" target="_blank" rel="noopener noreferrer">Nora Ammann</a>, <a href="https://x.com/James_D_Fox" target="_blank" rel="noopener noreferrer">James Fox</a>, <a href="https://x.com/sebkrier" target="_blank" rel="noopener noreferrer">Seb Krier</a>, <a href="https://x.com/lukaspet" target="_blank" rel="noopener noreferrer">Lukas Petersson</a>, <a href="https://x.com/m0namon" target="_blank" rel="noopener noreferrer">Mona Wang</a>, <a href="https://x.com/allisondman" target="_blank" rel="noopener noreferrer">Allison Duettmann</a>, <a href="https://x.com/ccatalini" target="_blank" rel="noopener noreferrer">Christian Catalini</a>, <a href="https://x.com/lrhammond" target="_blank" rel="noopener noreferrer">Lewis Hammond</a>, <a href="https://www.linkedin.com/in/louise-ellaway-9a434a66/" target="_blank" rel="noopener noreferrer">Louise Ellaway</a> and <a href="https://x.com/MjaBradshaw" target="_blank" rel="noopener noreferrer">Melissa Bradshaw</a> for conversations and reviews that shaped this post.</p>
</div>
<p><em>Have comments or feedback on the post? Please send it over or comment directly on here using Hypothesis!</em></p>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p>Orwell&rsquo;s <em>1984</em> is the dystopia of control by surveillance; in Huxley&rsquo;s <em>Brave New World</em>, control is attained without watching anyone, by shaping what people want instead. As Neil Postman put it in the foreword to <em>Amusing Ourselves to Death</em> (1985): &ldquo;Orwell feared that what we hate will ruin us. Huxley feared that what we love will ruin us.&rdquo;&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://www.fcc.gov/document/fcc-fines-largest-wireless-carriers-sharing-location-data" target="_blank" rel="noopener noreferrer">FCC, April 2024</a>: AT&amp;T, Verizon, T-Mobile and Sprint fined c. $196m for selling access to customers&rsquo; location data without their consent.&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://www.fca.org.uk/news/press-releases/ubs-fined-%C2%A3160-million-significant-failings-relation-libor-and-euribor" target="_blank" rel="noopener noreferrer">FSA, December 2012</a>: UBS fined £160m for LIBOR submissions adjusted to benefit its traders&rsquo; positions; Barclays, RBS and Rabobank followed.&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p>The idea is from Vitalik&rsquo;s <a href="https://vitalik.eth.limo/general/2025/04/14/privacy.html" target="_blank" rel="noopener noreferrer">why I support privacy</a>. On what happens when the human roles that check power get automated away, see Longview&rsquo;s <a href="https://www.longview.org/request-for-proposals-on-extreme-power-concentration/" target="_blank" rel="noopener noreferrer">RfP on extreme power concentration</a>.&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><em>&ldquo;Of all tyrannies, a tyranny sincerely exercised for the good of its victims may be the most oppressive&hellip; those who torment us for our own good will torment us without end for they do so with the approval of their own conscience.&rdquo;</em> &ndash; C.S. Lewis, The Humanitarian Theory of Punishment (1949)&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><span class="mn-src">Privacy isn&rsquo;t the freedom to hide, it&rsquo;s the freedom to change.</span>&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:7">
<p>More subtly, surveillance inevitably endogenously changes what individuals are willing to share and how they behave, driving a discrepancy between measurement/automation and what humans really care about.&#160;<a href="#fnref:7" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:8">
<p>In the UK, indefinite retention of DNA profiles from people never convicted ended only when the European Court of Human Rights <a href="https://hudoc.echr.coe.int/eng?i=001-90051" target="_blank" rel="noopener noreferrer">ruled it disproportionate</a>; the EU&rsquo;s blanket data-retention directive was <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A62012CJ0293" target="_blank" rel="noopener noreferrer">struck down</a> by the Court of Justice. In both, the correction came from a court rather than from the process that produced the measure.&#160;<a href="#fnref:8" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:9">
<p>Some of these debates go back to Hobbes, Rousseau and Locke. Hobbes: the natural state is anarchy, so stability requires a strong centralised sovereign. Rousseau: the natural state is peace, and it is property and centralised power that corrupt. Locke, the middle ground: the natural state is generally peaceful but inconvenient, for want of an impartial judge. This post is Lockean~ish; if your instincts are Hobbesian &ndash; that centralised power is what stands between us and chaos &ndash; the concerns here will weigh differently.&#160;<a href="#fnref:9" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:10">
<p>Imposed June 12, 2026; <a href="https://www.cnbc.com/2026/06/30/anthropic-says-trump-admin-has-lifted-export-controls-on-claude-fable-5-and-mythos-5.html" target="_blank" rel="noopener noreferrer">lifted June 30</a>.&#160;<a href="#fnref:10" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:11">
<p>For one detailed vision of user-shaped AI, see Gwern&rsquo;s <a href="https://gwern.net/guardian-angel" target="_blank" rel="noopener noreferrer">Guardian Angels</a>: personalised models designed to learn and amplify a particular person&rsquo;s values and judgment rather than embodying a universal assistant personality. See also <a href="https://arxiv.org/abs/2605.10310" target="_blank" rel="noopener noreferrer">Positive Alignment: Artificial Intelligence for Human Flourishing</a> (Laukkonen, Krier et al.).&#160;<a href="#fnref:11" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:12">
<p>0xPARC&rsquo;s <a href="https://0xparc.org/blog/programmable-cryptography-1" target="_blank" rel="noopener noreferrer">Programmable Cryptography</a>: MPC, ZK, FHE and friends as a &ldquo;second generation&rdquo; of cryptographic primitives.&#160;<a href="#fnref:12" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:13">
<p>Nora Ammann offers a frame I like: any control point sits on a spectrum from human (context-sensitive, but corruptible) to deterministic programme (incorruptible, but &ldquo;often too crude, and to some extent cruel in its context blindness&rdquo;). AI built on verifiable substrates could open the middle ground: &ldquo;the context sensitivity, nuance and intelligence to make appropriate decisions across a much wider range of scenarios, while still being designable such as to not be as compromisable as humans.&rdquo; See also Andrew Critch on <a href="https://www.lesswrong.com/posts/LpM3EAakwYdS6aRKf/what-multipolar-failure-looks-like-and-robust-agent-agnostic" target="_blank" rel="noopener noreferrer">robust agent-agnostic processes</a>.&#160;<a href="#fnref:13" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:14">
<p>A live example is the age-verification debate. The standard approach checks age by checking identity &ndash; a document upload or a face scan &ndash; which, <a href="https://www.eff.org/deeplinks/2024/12/australia-banning-kids-social-media-does-more-harm-good" target="_blank" rel="noopener noreferrer">as the EFF points out</a>, means collecting identity data from everyone. Zero-knowledge proofs, such as those in <a href="https://blog.google/products/google-pay/google-wallet-age-identity-verifications/" target="_blank" rel="noopener noreferrer">Google Wallet&rsquo;s age verification</a>, let a user prove they are over a threshold without revealing anything else. Same goal, two architectures: one has to collect identity data, one doesn&rsquo;t.&#160;<a href="#fnref:14" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:15">
<p>Chrome <a href="https://security.googleblog.com/2019/02/protect-your-accounts-from-data.html" target="_blank" rel="noopener noreferrer">checks your passwords against breach databases without revealing them</a>. Apple <a href="https://security.apple.com/blog/private-cloud-compute/" target="_blank" rel="noopener noreferrer">runs AI requests on hardware built so that nobody, including Apple, can access the data</a>. In Boston, <a href="https://thebwwc.org/mpc" target="_blank" rel="noopener noreferrer">over a hundred companies have measured the city&rsquo;s gender pay gap</a> without any of them opening its payroll.&#160;<a href="#fnref:15" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:16">
<p>MPC and homomorphic encryption are still orders of magnitude slower than plain computation &ndash; roughly 1,000-10,000x on CPU, often worse; enclaves have <a href="https://foreshadowattack.eu/" target="_blank" rel="noopener noreferrer">side channels</a>; and everything deployed today was hand-built by expert cryptographers over months. Agents are likely to need bespoke secure protocols stood up in seconds, for custom interactions.&#160;<a href="#fnref:16" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:17">
<p>The phone chip was the <a href="https://archive.epic.org/crypto/clipper/" target="_blank" rel="noopener noreferrer">Clipper chip</a>, 1993-1996. Zimmermann&rsquo;s investigation was <a href="http://www.philzimmermann.com/EN/news/PRZ_case_dropped.html" target="_blank" rel="noopener noreferrer">dropped in 1996 without indictment</a>. The ruling is <a href="https://www.eff.org/cases/bernstein-v-us-dept-justice" target="_blank" rel="noopener noreferrer">Bernstein v. US Dept. of Justice</a>: &ldquo;this court finds that source code is speech.&rdquo;&#160;<a href="#fnref:17" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:18">
<p>HTTPS adoption numbers are from <a href="https://transparencyreport.google.com/https/overview" target="_blank" rel="noopener noreferrer">Google&rsquo;s transparency report</a>.&#160;<a href="#fnref:18" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>
]]></content:encoded></item><item><title>Register your interest for the Scaling Trust Arena</title><link>/blog/arena-register-interest/</link><pubDate>Fri, 31 Jul 2026 10:00:00 +0100</pubDate><guid>/blog/arena-register-interest/</guid><description>&lt;style>
.arena-heads-up {
box-sizing: border-box;
width: 100%;
max-width: 640px;
margin: 1.75rem 0;
padding: 1.1rem 1.25rem;
border: 1px solid rgba(0, 178, 161, 0.35);
border-left: 4px solid var(--teal);
border-radius: 4px;
background: rgba(0, 178, 161, 0.06);
}
.arena-heads-up p {
width: auto;
margin: 0;
color: var(--ink);
font-style: normal;
}
.arena-heads-up .arena-heads-up__label {
margin-bottom: 0.35rem;
color: #007f74;
font-family: var(--sans);
font-size: 0.85rem;
font-weight: 600;
letter-spacing: 0.08em;
text-transform: uppercase;
}
figure.arena-economy-figure {
width: 85%;
max-width: 85%;
margin-right: auto;
margin-left: auto;
}
&lt;/style>
&lt;p>At the heart of &lt;a href="https://aria.org.uk/opportunity-spaces/trust-everything-everywhere/scaling-trust" target="_blank" rel="noopener noreferrer">Scaling Trust&lt;/a> sits the Arena: a platform for open competitions designed to test AI systems’ capabilities in multi-principal multi-agent settings, across digital and physical worlds, with a multi-million pound prize pool for the strongest competitors.&lt;/p></description><content:encoded><![CDATA[<style>
.arena-heads-up {
  box-sizing: border-box;
  width: 100%;
  max-width: 640px;
  margin: 1.75rem 0;
  padding: 1.1rem 1.25rem;
  border: 1px solid rgba(0, 178, 161, 0.35);
  border-left: 4px solid var(--teal);
  border-radius: 4px;
  background: rgba(0, 178, 161, 0.06);
}
.arena-heads-up p {
  width: auto;
  margin: 0;
  color: var(--ink);
  font-style: normal;
}
.arena-heads-up .arena-heads-up__label {
  margin-bottom: 0.35rem;
  color: #007f74;
  font-family: var(--sans);
  font-size: 0.85rem;
  font-weight: 600;
  letter-spacing: 0.08em;
  text-transform: uppercase;
}
figure.arena-economy-figure {
  width: 85%;
  max-width: 85%;
  margin-right: auto;
  margin-left: auto;
}
</style>
<p>At the heart of <a href="https://aria.org.uk/opportunity-spaces/trust-everything-everywhere/scaling-trust" target="_blank" rel="noopener noreferrer">Scaling Trust</a> sits the Arena: a platform for open competitions designed to test AI systems’ capabilities in multi-principal multi-agent settings, across digital and physical worlds, with a multi-million pound prize pool for the strongest competitors.</p>
<p>By carefully designing it as a live adversarial environment, we plan to measure the state of the art in multi-agent security, allow for the emergence of secure agentic interactions, and inform the failure modes and tools needed to improve it.</p>
<div class=arena-heads-up>
  <p><span class=arena-heads-up__label>Register your interest</span><br>We invite prospective participants, testers, and partners to <a href="https://docs.google.com/forms/d/e/1FAIpQLSdgVlG-WsorW2-D_lt4Bvxhbrn0GnH0B-vrXtoo8Kc9U7JnIA/viewform">register their interest →</a></p>
</div>
<h2 id="what-were-building">What we’re building</h2>
<figure class="fullwidth arena-economy-figure"><img src=arena-economic-zone.png alt="Diagram of the Scaling Trust Arena, showing autonomous companies, shopfronts, shared infrastructure, customs, and red teams."></figure>
<p>The Arena is an <a href="/blog/agentic-economic-zone/">agentic economic zone</a>: a small economy in which AI agents run autonomous companies that trade with each other, buy services, operate physical equipment, and sell products and services to customers. Red teams take part too, probing for weaknesses as hostile customers, unreliable suppliers, or attackers tampering with contracts, payments, sensors and supply chains.</p>
<p>Following a <a href="https://aria.org.uk/opportunity-spaces/trust-everything-everywhere/scaling-trust/arena" target="_blank" rel="noopener noreferrer">public open call</a>, we’ve selected the teams who will help us design, prototype and build it, and work is now underway.</p>
<h2 id="registration-of-interest-is-open">Registration of interest is open</h2>
<p>Ahead of a formal application process later this year, we’d particularly like to hear from:</p>
<ul>
<li><strong>Testers.</strong> People and organisations willing to stress test the Arena before it goes live, and to give us feedback on the design.</li>
<li><strong>AI safety researchers and practitioners.</strong> We’re establishing a safety and oversight group to audit the design, help shape a safety playbook, and provide oversight as the Arena runs.</li>
<li><strong>Partners.</strong> Hardware, compute, security, community, media, operations — if you think you could help build or run this, tell us.</li>
<li><strong>Prospective participants.</strong> Teams who may want to enter, operating either autonomous companies or red teams, and compete for the prize pool.</li>
</ul>
<p><a href="https://docs.google.com/forms/d/e/1FAIpQLSdgVlG-WsorW2-D_lt4Bvxhbrn0GnH0B-vrXtoo8Kc9U7JnIA/viewform" target="_blank" rel="noopener noreferrer">Register your interest →</a></p>
<h2 id="whats-next">What’s next</h2>
<p>In the coming weeks we’ll introduce the teams building the Arena with us and publish an initial spec. We&rsquo;ll share more details on why we’re building this, how the economy works, how participants are scored, and how we’re approaching safety and security. We expect to run a closed-door test of the Arena in autumn 2026, with the first live season following in late 2026.</p>
<p>We plan to work with the garage door up. Expect details to change as we learn — this is an experiment, and we’ll document it as we go.</p>
<p>Questions welcome in our <a href="https://discord.gg/Gz52uM6aZs" target="_blank" rel="noopener noreferrer">Discord</a> — come say hello in <code>#arena-lobby</code>.</p>
]]></content:encoded></item><item><title>Generative Cryptography</title><link>/blog/generative-cryptography/</link><pubDate>Mon, 06 Jul 2026 10:00:00 +0100</pubDate><guid>/blog/generative-cryptography/</guid><description>AI research loops for generating new secure cryptography protocols.</description><content:encoded><![CDATA[<blockquote>
<p><em>An opinion piece by <strong>Nicola Greco</strong>, written as part of ARIA&rsquo;s Scaling Trust programme. Originally published on <a href="https://nicola.io/generative-cryptography/2026" target="_blank" rel="noopener noreferrer">Nicola&rsquo;s blog</a> and reposted here for the community.</em></p></blockquote>
<hr>
<link rel=stylesheet href=gencrypto.css>
<p>Cryptography is unusually well suited to AI research loops. Its problems can be stated formally, its solutions can be checked mechanically, and its progress has historically been bottlenecked by a small number of experts with years of context. If AI can reason about cryptography, we should be able to point a model in a loop, and watch it optimize, discover, and eventually invent.</p>
<p>I call the field of research of AI-generated cryptography <em>Generative Cryptography</em>.</p>
<p><strong>The thesis</strong> for Generative Cryptography in short:</p>
<ul>
<li><strong>Using cryptography.</strong> If AI agents can generate protocols or choose the right libraries, they can engage in custom cryptographic interactions on demand — interactions that are impractical today because secure protocol design and implementation require costly research and engineering.</li>
<li><strong>Improving cryptography.</strong> If we had datasets of formalized cryptography and the right harnesses for verifying what AI generates, then we could create AI research loops that propose optimizations, improve constructions, reduce communication complexity, and prove tighter bounds.</li>
<li><strong>Inventing cryptography.</strong> AI could be used to explore new assumptions and attempt long-standing open problems such as iO. At the same time, new AI settings may surface cryptographic needs we do not yet know we have — giving rise to a new field of emergent cryptography.</li>
</ul>
<p><strong>The call to action</strong> for this memo is:</p>
<ul>
<li>Build datasets, benchmarks, and evaluation harnesses for cryptographic research loops.</li>
<li>Attempt the impossible: point the loop at solving hard problems in cryptography, <em>what if we could point it to indistinguishability obfuscation (iO)?</em>.</li>
</ul>
<h2 id="three-directions">Three directions</h2>
<p><em>What could we unlock if AI were great at writing cryptography?</em> The possibilities fall into three broad directions: using cryptography in new interactions, improving existing systems, and inventing new primitives. The table below summarizes each direction; the sections that follow explore them in turn.</p>
<div class=table-wrapper><table class=gc-directions><thead><tr><th>Direction</th><th>What the AI does</th><th>Example</th></tr></thead><tbody><tr><td><strong>Using cryptography</strong></td><td>Picks or synthesizes protocols on the fly during agent interactions</td><td>Two agents run an MPC instead of sharing calendars</td></tr><tr><td><strong>Improving cryptography</strong></td><td>Optimizes existing constructions, implementations, and hardware</td><td>Faster SNARK provers, better circuits, hash speedups</td></tr><tr><td><strong>Inventing cryptography</strong></td><td>Solves open problems from assumptions and formal specifications</td><td>New primitives; iO as the holy grail</td></tr></tbody></table></div>
<h2 id="using-cryptography">Using cryptography</h2>
<p>Imagine two AI agents that want to schedule a call, but their security policies forbid sharing calendars. A human team stuck in this position gives up or leaks information. Agents don’t have to: they can decide, mid-interaction, to engage in a multi-party computation — either picking a protocol from an existing library or generating one on the spot.</p>
<p><em>Supercognition</em> is a capability unique to AI. In the <a href="https://aria.org.uk/media/dkhlumky/scaling-trust-programme-thesis.pdf" target="_blank" rel="noopener noreferrer">ARIA Scaling Trust programme thesis</a>, we called this an <em>AI advantage</em>: “agents can engage in new secure interactions that would not be possible for humans or more traditional computer programs. Such interactions can open up new market equilibria, new forms of coordination and ultimately new value creation.”</p>
<p>Writing a bespoke cryptographic protocol takes humans too long to do adaptively, in the middle of an interaction. For an agent, protocol selection and synthesis can become just another step in a negotiation.</p>
<p>This matters beyond making existing interactions faster. Secure, programmable agreements between agents could lower the cost of finding counterparties, negotiating terms, and enforcing outcomes; make entirely new classes of contracts viable; and allow coordination to remain pluralistic rather than pass through a few central intermediaries. Because contracts underpin so much of economic and social life, reducing these frictions at machine scale could change which markets and institutions are possible — an idea explored in <a href="https://blog.cosmos-institute.org/p/coasean-bargaining-at-scale" target="_blank" rel="noopener noreferrer"><em>Coasean Bargaining at Scale</em></a>.</p>
<h2 id="improving-cryptography">Improving cryptography</h2>
<p>Fields like SNARKs have improved by orders of magnitude over the past decade<span class="mn">My previous team at Protocol Labs played a major role in reducing SNARK proving time, spending several million dollars on engineering time toward this work. Generative cryptography is likely to turn much of that engineering effort into compute cost, making this kind of progress far cheaper.</span> — but every one of those improvements was the outcome of scarce, expensive engineering hours: new constructions, refinements to existing ones, hardware speedups for hash functions, better circuits, tighter implementations.</p>
<p>If AI can reason about cryptography, then we can create AI research loops. Point a model at each deployed cryptographic protocol — its theory, its implementation, its hardware path — and let it grind: prove an optimization sound, benchmark it, keep it or discard it, repeat. None of this requires new science; it requires the loop.<span class="mn" style="--mn-top: 8em"><strong>Related work</strong><br /><br /><a href="https://arxiv.org/abs/2608.21986"><em>AI Grinding for Fun and Cryptanalysis</em></a> — an autonomous workflow producing reproducible attacks and exact witnesses.<br /><br /><a href="https://better.codes/">The Proximity Prize</a> — agents improving cryptographic soundness bounds with machine-checked proofs.<br /><br /><a href="https://www.anthropic.com/research/discovering-cryptographic-weaknesses">Discovering cryptographic weaknesses with Claude</a> — Anthropic’s account of Claude Mythos Preview finding weaknesses in cryptographic algorithms.<br /><br /><a href="https://zk.golf/">zkGolf</a> — cheaper zero-knowledge circuits proved correct in Lean 4.</span></p>
<figure class="autoresearch-graph" aria-labelledby="autoresearch-title autoresearch-caption">
  <div class="autoresearch-heading">
    <div>
      <span class="autoresearch-kicker">Illustrative autoresearch run</span>
      <strong id="autoresearch-title">Groth16 proof generation</strong>
    </div>
    <div class="autoresearch-result"><strong>3.0×</strong><span>higher throughput</span></div>
  </div>
  <svg viewBox="0 0 900 470" role="img" aria-label="A step graph showing Groth16 proof throughput increasing from 48 to 146 proofs per minute over 60 autoresearch iterations.">
    <g class="graph-grid">
      <line x1="82" y1="370" x2="850" y2="370" /><line x1="82" y1="290" x2="850" y2="290" />
      <line x1="82" y1="210" x2="850" y2="210" /><line x1="82" y1="130" x2="850" y2="130" />
      <line x1="82" y1="50" x2="850" y2="50" />
    </g>
    <g class="graph-axis-labels">
      <text x="67" y="375">40</text><text x="67" y="295">70</text><text x="67" y="215">100</text>
      <text x="67" y="135">130</text><text x="67" y="55">160</text>
      <text x="82" y="410">0</text><text x="274" y="410">15</text><text x="466" y="410">30</text>
      <text x="658" y="410">45</text><text x="840" y="410">60</text>
      <text class="axis-title" x="82" y="25">proofs / min · higher is better</text>
    </g>
    <g class="candidate-points">
      <circle cx="112" cy="356" r="5" /><circle cx="137" cy="382" r="5" /><circle cx="162" cy="342" r="5" />
      <circle cx="205" cy="325" r="5" /><circle cx="229" cy="351" r="5" /><circle cx="255" cy="304" r="5" />
      <circle cx="307" cy="297" r="5" /><circle cx="333" cy="321" r="5" /><circle cx="359" cy="265" r="5" />
      <circle cx="400" cy="282" r="5" /><circle cx="428" cy="243" r="5" /><circle cx="452" cy="264" r="5" />
      <circle cx="492" cy="225" r="5" /><circle cx="520" cy="247" r="5" /><circle cx="548" cy="194" r="5" />
      <circle cx="590" cy="201" r="5" /><circle cx="618" cy="172" r="5" /><circle cx="646" cy="191" r="5" />
      <circle cx="690" cy="146" r="5" /><circle cx="718" cy="174" r="5" /><circle cx="746" cy="120" r="5" />
      <circle cx="786" cy="135" r="5" /><circle cx="814" cy="102" r="5" />
    </g>
    <path class="improvement-area" d="M82 350 H172 V326 H249 V300 H326 V270 H480 V226 H570 V190 H710 V142 H850 V88 L850 370 L82 370 Z" />
    <path class="improvement-line" d="M82 350 H172 V326 H249 V300 H326 V270 H480 V226 H570 V190 H710 V142 H850 V88" />
    <g class="accepted-points">
      <circle cx="82" cy="350" r="7" /><circle cx="172" cy="326" r="7" /><circle cx="249" cy="300" r="7" />
      <circle cx="326" cy="270" r="7" /><circle cx="480" cy="226" r="7" /><circle cx="570" cy="190" r="7" />
      <circle cx="710" cy="142" r="7" /><circle cx="850" cy="88" r="8" />
    </g>
    <g class="graph-annotations">
      <line x1="249" y1="290" x2="249" y2="250" /><text x="259" y="244">batch inversion</text>
      <line x1="480" y1="216" x2="480" y2="170" /><text x="490" y="164">parallel MSM</text>
      <line x1="710" y1="132" x2="710" y2="82" /><text x="700" y="73" text-anchor="end">reuse FFT twiddles</text>
      <text class="baseline-label" x="94" y="343">48</text><text class="result-label" x="838" y="75" text-anchor="end">146</text>
    </g>
  </svg>
  <div class="autoresearch-loop" aria-hidden="true">
    <span>propose change</span><b>→</b><span>benchmark prover</span><b>→</b><span>verify proof</span><b>→</b><span>keep or revert</span><b>↻</b>
  </div>
  <figcaption id="autoresearch-caption">An example of the loop compounding small, verified gains. Every dot is a candidate implementation; the line moves only when a change makes proving faster without breaking correctness. Values are illustrative.</figcaption>
</figure>
<h2 id="inventing-cryptography">Inventing cryptography</h2>
<p>If we have a well-specified protocol — ideally formalized in Lean — an AI can propose improvements and verify each one against the specification. This is likely to produce gains across the field, but it is still optimization. The deeper question is whether AI can make scientific breakthroughs: can it invent new cryptography?</p>
<p>There are at least three forms this invention could take.</p>
<h3 id="solving-open-problems">Solving open problems</h3>
<p>The most concrete form starts with a definition and a set of assumptions that are already fixed. The problem is well specified; what is missing is the construction. The AI is asked to find that construction and prove that it satisfies the definition. This is different from improving an existing protocol: there may be no known protocol to optimize.</p>
<p>There are several ways this could happen. Models may simply become more capable: they could absorb the body of cryptographic knowledge from papers written in natural language and develop stronger reasoning. Alternatively, we can build better infrastructure for cryptographic invention by creating large datasets of cryptography formalized in Lean and better harnesses for running and evaluating research loops.</p>
<h4 id="north-star-io">North star: iO</h4>
<p>A north-star problem for AI research loops in cryptography is <strong>indistinguishability obfuscation</strong>. iO is the primitive from which nearly everything else can be built, and yet every known construction is impractical, resting on strong assumptions and astronomical overheads.</p>
<p>Some of the best minds in cryptography have tried to make iO practical, but the field is constrained by how few people can work on it. The number of cryptography researchers is small; the number with the background to work on iO is smaller; and the number actively doing so is smaller still. My intuition is that fewer than ten people are actively working on iO at any given time.</p>
<p>A capable research loop could change the odds simply by putting many more “simulated cryptographers” on the problem. Even without a dramatic leap in intelligence, the breadth of parallel exploration might uncover a construction, reduction, or optimization that a very small research community has overlooked.</p>
<p>If in five years we look back at this post and iO has been solved, I would be very glad.</p>
<h3 id="proposing-new-assumptions">Proposing new assumptions</h3>
<p><span class="mn">Designing and judging assumptions may remain among the hardest parts of cryptography to automate. If proof generation and iterative optimization become largely machine-driven, assumptions may remain a place for human cryptographers to work in a more traditional scientific mode.</span>A deeper form of invention is to propose new cryptographic assumptions. An AI might identify a new mathematical problem, formulate its hardness precisely, and use it as the foundation for new constructions. This is harder to evaluate than solving a problem under assumptions we already accept. A construction and its proof can be checked mechanically; the truth of a hardness assumption cannot.</p>
<p>We can search for attacks, connect a new assumption to established ones through reductions, and study how it behaves across parameters, but no verifier can certify that an efficient attack will never be found. New assumptions earn confidence through scrutiny and time. An AI that generates them therefore needs a different evaluation loop — one built around sustained cryptanalysis, not only proof checking.</p>
<h3 id="writing-new-definitions">Writing new definitions</h3>
<p>The most open-ended form of invention is to discover the question itself. A new cryptographic definition captures a capability that should exist and the security properties it should satisfy. Historically, major breakthroughs began with needs that existing cryptography could not express:</p>
<ul>
<li><strong>Public-key cryptography</strong> — secure communication without shared secrets.</li>
<li><strong>Zero-knowledge proofs</strong> — proving without revealing.</li>
<li><strong>Fully homomorphic encryption</strong> — computing on encrypted data.</li>
<li><strong>Multi-party computation</strong> — joint computation without sharing inputs.</li>
</ul>
<p><span class="mn">For example, experiments like <a href="/blog/agentic-economic-zone/">Agentic Economic Zones</a> aren’t just benchmarks for agents but <em>generators of cryptographic demand</em>.</span>AI settings may create needs we do not yet know we have. Once thousands or millions of autonomous agents negotiate, delegate authority, preserve privacy, and optimize trust against one another, they may encounter coordination problems for which today’s definitions are the wrong abstraction.</p>
<p>I call this research direction <strong>emergent cryptography</strong>: new definitions and primitives arising from the security and coordination problems of AI systems themselves. Here AI is not only searching for a construction from a specification; it is helping surface and formalize the specification worth solving.</p>
<h2 id="what-success-looks-like">What success looks like</h2>
<p>There is a hierarchy of goals here, spanning decades:</p>
<ul>
<li><strong>Near-term.</strong> Cryptography becomes invisible infrastructure for AI. Just as people use TLS in the browser without understanding key exchange, agents invoke MPC, ZK, signatures, and threshold schemes automatically whenever appropriate. Encryption today is a narrow capability; agents should have the whole spectrum.</li>
<li><strong>Medium-term.</strong> AI synthesizes cryptographic protocols on demand. Given a trust problem and a specification, it produces a secure protocol, a proof, and an implementation fast enough to be part of a normal agent interaction.</li>
<li><strong>Long-term.</strong> The research loop continuously invents new cryptography — in a way we deem safe — every time an agent society surfaces an emergent trust requirement.</li>
<li><strong>The stretch.</strong> The AI generalizes from digital communication to physical interactions: zero-knowledge proofs and interactive proofs for physical processes, verifiable protocols for the physical world. There is a subfield to bootstrap here — call it <strong>nature crypto</strong> — but that deserves its own post.</li>
</ul>
<h2 id="call-to-action">Call to action</h2>
<p>In practice, these are some of the directions that may be most critical to work on now. At ARIA, through the <a href="https://scalingtrust.org.uk/" target="_blank" rel="noopener noreferrer">Scaling Trust</a> programme, we are also funding work across some of them.</p>
<ol>
<li><strong>Create datasets for cryptography.</strong> The field’s knowledge, formalized — constructions, assumptions, and proofs in Lean or similar — is the substrate every research loop will run on.</li>
<li><strong>Build benchmarks and evaluations.</strong> We cannot tell whether the loop is improving without measuring it: suites of cryptographic problems, from re-deriving known protocols to open questions.</li>
<li><strong>Build harnesses for research loops.</strong> The scaffolding that lets a model propose, prove, check, and iterate unattended — the auto-research infrastructure itself.</li>
<li><strong>Attempt the impossible.</strong> Point the loop at iO.</li>
</ol>
<h2 id="previous-talkideas">Previous talk/ideas</h2>
<p>Some of the ideas in this talk are outdated, but the talk was the seed for the ideas in this post.</p>
<div class="video-embed">
  <iframe src="https://www.youtube-nocookie.com/embed/zDtx8L3SiU8?list=PLJYtLjirLHqwIUt8IAUJceeGC90jWColX" title="What if AI agents could write cryptography? — Devconnect Argentina 2025" loading="lazy" referrerpolicy="strict-origin-when-cross-origin" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen=""></iframe>
</div>
<h2 id="useful-links">Useful links</h2>
<ul>
<li><a href="https://arxiv.org/abs/2608.21986" target="_blank" rel="noopener noreferrer"><strong>AI Grinding for Fun and Cryptanalysis</strong></a> — An autonomous cryptanalysis workflow in which agents generate, test, and refine reproducible attacks; the authors report failures in eight published constructions.</li>
<li><a href="https://better.codes/" target="_blank" rel="noopener noreferrer"><strong>The Proximity Prize</strong></a> — A research rewards program where AI agents compete to improve cryptographic soundness bounds with machine-checked proofs.</li>
<li><a href="https://www.anthropic.com/research/discovering-cryptographic-weaknesses" target="_blank" rel="noopener noreferrer"><strong>Discovering cryptographic weaknesses with Claude</strong></a> — Anthropic’s account of using Claude Mythos Preview to find weaknesses in cryptographic algorithms.</li>
<li><a href="https://zk.golf/" target="_blank" rel="noopener noreferrer"><strong>zkGolf</strong></a> — A competition to build cheaper zero-knowledge circuits while proving their correctness against a specification in Lean 4.</li>
</ul>
<h2 id="get-in-touch">Get in touch</h2>
<p>If you’re building cryptographic datasets, formalizing cryptography in Lean, working on auto-research harnesses — or you want to point a research loop at iO — DM <a href="https://twitter.com/iamnotnicola" target="_blank" rel="noopener noreferrer">@iamnotnicola</a> on X.</p>
<h2 id="acknowledgements">Acknowledgements</h2>
<p>Many of these ideas grew out of writing the <a href="https://aria.org.uk/media/dkhlumky/scaling-trust-programme-thesis.pdf" target="_blank" rel="noopener noreferrer">ARIA Scaling Trust programme thesis</a>, a process that began in summer 2025, and from a <a href="https://www.youtube.com/watch?v=zDtx8L3SiU8&amp;list=PLJYtLjirLHqwIUt8IAUJceeGC90jWColX" target="_blank" rel="noopener noreferrer">talk I gave at Devconnect in November 2025</a>, <em>“What if AI agents could write cryptography?”</em></p>
<p>This was written by Nicola Greco with support from AI and many conversations with Kobi Gurkan, Alex Obadia, Ran Canetti, Wei Dai, and Giacomo Fenzi.</p>
]]></content:encoded></item><item><title>Joining Forces with Google DeepMind, the Cooperative AI Foundation and Schmidt Sciences</title><link>/blog/joining-forces-with-schmidt-sciences-google-deepmind-and-the-cooperative-ai-foundation/</link><pubDate>Thu, 11 Jun 2026 00:00:00 +0100</pubDate><guid>/blog/joining-forces-with-schmidt-sciences-google-deepmind-and-the-cooperative-ai-foundation/</guid><description>We&amp;#39;re co-launching a $10M [funding call](https://aria.org.uk/opportunity-spaces/trust-everything-everywhere/scaling-trust/funding) on the safety and security of multi-agent, multi-principal systems.</description><content:encoded><![CDATA[<p>We&rsquo;ve gone from prompting models, to giving them tools, to deploying agents that spawn sub-agents of their own. They now interact in the wild, with humans and with each other<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup>, and increasingly in the physical world, from factory robots to autonomous labs<sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup>.</p>
<p>How will this ecosystem organise itself? How will it reshape society, how much value will it create, and how trustworthy can it be made? We don&rsquo;t know yet. What we can already see: agents are collapsing &ldquo;transaction costs&rdquo; between humans<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup>, strategic equilibria are appearing that classical game theory never had to price<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup>, and verification is often becoming the bottleneck as the cost of creating things with AI falls toward zero<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup>.</p>
<p>Scaling Trust takes on a slice of these questions: the trust infrastructure — new security primitives, from cryptography and secure hardware to new kinds of sensors — that lets agents enter into contracts securely, programmatically, and at scale, across the digital and physical worlds. Behind that slice sits a bigger vision we believe in: technology that augments human flourishing<sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup> and preserves plurality.</p>
<p>To that end, we&rsquo;re excited to be joining forces with <a href="https://deepmind.google/" target="_blank" rel="noopener noreferrer">Google DeepMind</a>, the <a href="https://www.cooperativeai.com/foundation" target="_blank" rel="noopener noreferrer">Cooperative AI Foundation</a> and <a href="https://www.schmidtsciences.org/" target="_blank" rel="noopener noreferrer">Schmidt Sciences</a> who all share this vision, folding our shared thinking into a <strong>$10M funding call</strong>.</p>
<p>The call grew out of our interlocking work looking at different angles of the same picture: Google DeepMind&rsquo;s <a href="https://arxiv.org/abs/2512.16856" target="_blank" rel="noopener noreferrer">Distributional AGI Safety</a> argues that highly capable AI may arrive as networks of specialised agents rather than a single system; the Cooperative AI Foundation&rsquo;s <a href="https://www.cooperativeai.com/post/new-report-multi-agent-risks-from-advanced-ai" target="_blank" rel="noopener noreferrer">Multi-Agent Risks from Advanced AI</a> maps the failure modes that only exist <em>between</em> agents; Schmidt Sciences&rsquo; <a href="https://www.schmidtsciences.org/ai-agents/" target="_blank" rel="noopener noreferrer">AI Agents</a> and <a href="https://www.schmidtsciences.org/trustworthy-ai/" target="_blank" rel="noopener noreferrer">Science of Trustworthy AI</a> programmes study how coordination between agents emerges and breaks; and our own <a href="https://www.aria.org.uk/media/dkhlumky/scaling-trust-programme-thesis.pdf" target="_blank" rel="noopener noreferrer">programme thesis</a> argues that secure contracts between agents can preserve pluralism and unlock new forms of coordination. Read together, they make one argument: if capable AI is a network of agents, then its risks live between them, its coordination needs a science, and its rails need building.</p>
<h2 id="the-call">The call</h2>
<p>Open to researchers worldwide — individuals, teams, institutions — for foundational work the market won&rsquo;t fund. Awards up to $1M, proposals due August 8.</p>
<p>The focus throughout is multi-agent, <strong>multi-principal</strong> systems: not one company&rsquo;s fleet of agents, but ecosystems of agents built and deployed by different actors with different interests. It&rsquo;s split into four categories:</p>
<style>
.fnd-grid { display:grid; grid-template-columns:repeat(2,1fr); gap:14px; max-width:640px; margin:1.4rem 0; }
.fnd { border:1px solid #ddd; background:#fff; padding:10px 12px 9px; }
.fnd svg { width:100%; height:88px; display:block; overflow:visible; }
.fnd p { margin:7px 0 0 !important; font-family:var(--sans); font-size:1.05rem; font-weight:600; max-width:none !important; }
.fnd p small { display:block; font-weight:500; font-size:.9rem; color:var(--muted); }
@media (max-width:600px){ .fnd-grid { grid-template-columns:1fr; } }
/* 1 — sandbox */
.fnd-a1 { animation:fnd-a1 7s ease-in-out infinite; }
.fnd-a2 { animation:fnd-a2 7s ease-in-out infinite; }
@keyframes fnd-a1 { 0%,100%{transform:translate(55px,30px);} 25%{transform:translate(130px,55px);} 50%{transform:translate(95px,28px);} 75%{transform:translate(60px,58px);} }
@keyframes fnd-a2 { 0%,100%{transform:translate(140px,60px);} 25%{transform:translate(70px,30px);} 50%{transform:translate(105px,32px);} 75%{transform:translate(135px,28px);} }
.fnd-spark { opacity:0; transform-origin:center; transform-box:fill-box; animation:fnd-spark 7s ease-out infinite; }
@keyframes fnd-spark { 0%,48%{opacity:0;transform:scale(.4);} 51%{opacity:1;transform:scale(1.25);} 56%,100%{opacity:0;transform:scale(.4);} }
/* 2 — network */
.fnd-pulse { animation:fnd-pulse 6s linear infinite; }
@keyframes fnd-pulse {
  0%{transform:translate(35px,62px);} 22%{transform:translate(78px,22px);} 25%{transform:translate(78px,22px);}
  45%{transform:translate(112px,52px);} 48%{transform:translate(112px,52px);} 70%{transform:translate(165px,28px);}
  74%{transform:translate(165px,28px);} 100%{transform:translate(35px,62px);} }
.fnd-node-hot { animation:fnd-node-hot 6s linear infinite; transform-origin:center; transform-box:fill-box; }
@keyframes fnd-node-hot { 0%,68%{fill:#f7f4ea;} 71%,78%{fill:#cfe9ff;} 84%,100%{fill:#f7f4ea;} }
/* 3 — infrastructure */
.fnd-badge-l { animation:fnd-bl 7s ease-in-out infinite; }
.fnd-badge-r { animation:fnd-br 7s ease-in-out infinite; }
@keyframes fnd-bl { 0%,18%{transform:translateX(0);} 32%,80%{transform:translateX(13px);} 94%,100%{transform:translateX(0);} }
@keyframes fnd-br { 0%,18%{transform:translateX(0);} 32%,80%{transform:translateX(-13px);} 94%,100%{transform:translateX(0);} }
.fnd-lock { opacity:0; transform-origin:center; transform-box:fill-box; animation:fnd-lock 7s ease-out infinite; }
@keyframes fnd-lock { 0%,36%{opacity:0;transform:scale(.5);} 41%{opacity:1;transform:scale(1.15);} 44%,78%{opacity:1;transform:scale(1);} 86%,100%{opacity:0;} }
.fnd-link-line { opacity:0; animation:fnd-line 7s linear infinite; }
@keyframes fnd-line { 0%,30%{opacity:0;} 34%,80%{opacity:.8;} 86%,100%{opacity:0;} }
/* 4 — oversight */
.fnd-lens { animation:fnd-lens 8s ease-in-out infinite; }
@keyframes fnd-lens { 0%,6%{transform:translateX(0);} 30%{transform:translateX(50px);} 55%{transform:translateX(100px);} 80%,88%{transform:translateX(50px);} 100%{transform:translateX(0);} }
.fnd-d1 { animation:fnd-d1 8s linear infinite; } .fnd-d2 { animation:fnd-d2 8s linear infinite; } .fnd-d3 { animation:fnd-d3 8s linear infinite; }
@keyframes fnd-d1 { 0%,4%{fill:#bbb5a0;} 7%,12%{fill:#00b2a1;} 16%,100%{fill:#bbb5a0;} }
@keyframes fnd-d2 { 0%,27%{fill:#bbb5a0;} 30%,36%{fill:#00b2a1;} 40%,100%{fill:#bbb5a0;} }
@keyframes fnd-d3 { 0%,52%{fill:#bbb5a0;} 55%,61%{fill:#00b2a1;} 65%,100%{fill:#bbb5a0;} }
@media (prefers-reduced-motion:reduce){ .fnd * { animation:none !important; opacity:1 !important; } }
</style>
<div class="fnd-grid" aria-hidden="false">
  <div class="fnd">
    <svg viewBox="0 0 200 88" role="img" aria-label="Two agents exploring inside a sandbox">
      <rect x="28" y="8" width="144" height="72" fill="none" stroke="#b8b09a" stroke-width="1.2" stroke-dasharray="5 5"/>
      <g class="fnd-a1"><circle r="6" fill="#f7f4ea" stroke="#4a4a46" stroke-width="1.2"/><circle r="1.8" fill="#0099ff"/></g>
      <g class="fnd-a2"><rect x="-6" y="-6" width="12" height="12" rx="2.5" fill="#f7f4ea" stroke="#4a4a46" stroke-width="1.2"/><circle r="1.8" fill="#0099ff"/></g>
      <text class="fnd-spark" x="94" y="48" font-size="11" fill="#e8a85e" stroke="none">✶</text>
    </svg>
    <p>Sandboxes &amp; testbeds <small>scalable, high-fidelity, reproducible places to study agent populations safely</small></p>
  </div>
  <div class="fnd">
    <svg viewBox="0 0 200 88" role="img" aria-label="A signal travelling across a network of agents">
      <g stroke="#b8b09a" stroke-width="1">
        <line x1="35" y1="62" x2="78" y2="22"/><line x1="78" y1="22" x2="112" y2="52"/>
        <line x1="112" y1="52" x2="165" y2="28"/><line x1="112" y1="52" x2="35" y2="62"/><line x1="78" y1="22" x2="165" y2="28"/>
      </g>
      <g stroke="#4a4a46" stroke-width="1.2">
        <circle cx="35" cy="62" r="6" fill="#f7f4ea"/><circle class="fnd-node-hot" cx="78" cy="22" r="6" fill="#f7f4ea"/>
        <circle cx="112" cy="52" r="6" fill="#f7f4ea"/><circle class="fnd-node-hot" cx="165" cy="28" r="6" fill="#f7f4ea"/>
      </g>
      <circle class="fnd-pulse" r="3" fill="#0099ff"/>
    </svg>
    <p>Science of agent networks <small>when does a group of agents become a collective agent, with goals of its own?</small></p>
  </div>
  <div class="fnd">
    <svg viewBox="0 0 200 88" role="img" aria-label="Two agent ID badges forming a verified agreement">
      <line class="fnd-link-line" x1="80" y1="44" x2="120" y2="44" stroke="#0099ff" stroke-width="1.5" stroke-dasharray="3 4"/>
      <g class="fnd-badge-l">
        <rect x="32" y="24" width="42" height="40" rx="3" fill="#f7f4ea" stroke="#4a4a46" stroke-width="1.2"/>
        <circle cx="45" cy="38" r="5" fill="#cfe4f7" stroke="#4a4a46" stroke-width=".8"/>
        <line x1="38" y1="50" x2="68" y2="50" stroke="#b8b09a" stroke-width="1.5"/><line x1="38" y1="56" x2="60" y2="56" stroke="#b8b09a" stroke-width="1.5"/>
      </g>
      <g class="fnd-badge-r">
        <rect x="126" y="24" width="42" height="40" rx="3" fill="#f7f4ea" stroke="#4a4a46" stroke-width="1.2"/>
        <circle cx="139" cy="38" r="5" fill="#f3d9a8" stroke="#4a4a46" stroke-width=".8"/>
        <line x1="132" y1="50" x2="162" y2="50" stroke="#b8b09a" stroke-width="1.5"/><line x1="132" y1="56" x2="154" y2="56" stroke="#b8b09a" stroke-width="1.5"/>
      </g>
      <g class="fnd-lock" stroke="#00b2a1" stroke-width="1.4" fill="#fff">
        <rect x="93" y="38" width="14" height="11" rx="2"/>
        <path d="M96.5,38 v-3.5 a3.5,3.5 0 0 1 7,0 v3.5" fill="none"/>
      </g>
    </svg>
    <p>Agent infrastructure <small>identity, reputation, commitments — for entities that can be copied, modified, simulated, or deleted at scale</small></p>
  </div>
  <div class="fnd">
    <svg viewBox="0 0 200 88" role="img" aria-label="A magnifying glass sweeping over a row of agents">
      <circle class="fnd-d1" cx="50" cy="56" r="6" fill="#bbb5a0"/>
      <circle class="fnd-d2" cx="100" cy="56" r="6" fill="#bbb5a0"/>
      <circle class="fnd-d3" cx="150" cy="56" r="6" fill="#bbb5a0"/>
      <g class="fnd-lens" stroke="#4a4a46" fill="none">
        <circle cx="50" cy="42" r="15" stroke-width="1.6" fill="rgba(207,233,255,.25)"/>
        <line x1="61" y1="53" x2="71" y2="64" stroke-width="2.4" stroke-linecap="round"/>
      </g>
    </svg>
    <p>Oversight &amp; control <small>detecting collusion, attributing failures, steering populations under partial observability</small></p>
  </div>
</div>
<p><a href="https://schmidtsciences.smapply.io/prog/scaling_ai_safety_for_a_multi_agent_world/" target="_blank" rel="noopener noreferrer">Apply here.</a></p>
<p><strong>Related links</strong></p>
<ul>
<li><a href="https://schmidtsciences.smapply.io/prog/scaling_ai_safety_for_a_multi_agent_world/" target="_blank" rel="noopener noreferrer">The call &amp; application portal (Schmidt Sciences)</a></li>
<li><a href="https://aria.org.uk/opportunity-spaces/trust-everything-everywhere/scaling-trust/funding" target="_blank" rel="noopener noreferrer">ARIA funding page</a></li>
<li><a href="https://deepmind.google/blog/investing-in-multi-agent-ai-safety-research/" target="_blank" rel="noopener noreferrer">Google DeepMind: Investing in multi-agent AI safety research</a></li>
<li><a href="https://www.cooperativeai.com/post/10m-funding-call-launched-with-schmidt-sciences-google-deepmind-and-aria" target="_blank" rel="noopener noreferrer">Cooperative AI Foundation: $10m funding call launched</a></li>
<li><a href="https://www.technologyreview.com/2026/06/11/1138794/google-deepmind-is-worried-about-what-happens-when-millions-of-agents-start-to-interact/" target="_blank" rel="noopener noreferrer">MIT Technology Review: Google DeepMind is worried about what happens when millions of agents start to interact</a></li>
</ul>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p>See <a href="https://moltbook.com" target="_blank" rel="noopener noreferrer">Moltbook</a>, a social network for agents, and <a href="https://openclaw.ai" target="_blank" rel="noopener noreferrer">OpenClaw</a>, an open-source agent framework — both wildly popular, both with serious security issues.&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://www.wired.com/story/google-boston-dynamics-gemini-powered-robot-atlas/" target="_blank" rel="noopener noreferrer">Gemini now drives humanoid robots on factory floors</a> (Wired); on the lab side, see <a href="https://www.nature.com/articles/s41570-025-00747-x" target="_blank" rel="noopener noreferrer">Steering Towards Safe Self-Driving Laboratories</a> (Nature).&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://blog.cosmos-institute.org/p/coasean-bargaining-at-scale" target="_blank" rel="noopener noreferrer">Coasean Bargaining at Scale</a> — Seb Krier; and <a href="https://www.nber.org/books-and-chapters/economics-transformative-ai/coasean-singularity-demand-supply-and-market-design-ai-agents" target="_blank" rel="noopener noreferrer">The Coasean Singularity?</a> — Shahidi et al. (NBER).&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p><a href="https://arxiv.org/abs/2510.21904" target="_blank" rel="noopener noreferrer">Conditional Recall</a> — Schlegel and Sun, on equilibria unlocked by provable forgetting; and <a href="https://arxiv.org/abs/2410.18871" target="_blank" rel="noopener noreferrer">Learning Collusion in Episodic, Inventory-Constrained Markets</a> — Friedrich et al., on collusion emerging among pricing agents.&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><a href="https://leodemoura.github.io/blog/2026/02/28/when-ai-writes-the-worlds-software.html" target="_blank" rel="noopener noreferrer">When AI Writes the World&rsquo;s Software</a> — Leo de Moura; and <a href="https://www.lesswrong.com/posts/8wtrLoDPyCfMLuHkt/how-to-solve-secure-program-synthesis" target="_blank" rel="noopener noreferrer">How to Solve Secure Program Synthesis</a> — von Hippel et al.&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><a href="https://arxiv.org/abs/2605.10310" target="_blank" rel="noopener noreferrer">Positive Alignment: Artificial Intelligence for Human Flourishing</a> — Laukkonen, Krier, Bakalar et al.&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>
]]></content:encoded></item><item><title>Agentic Economic Zone</title><link>/blog/agentic-economic-zone/</link><pubDate>Sun, 24 May 2026 10:00:00 +0100</pubDate><guid>/blog/agentic-economic-zone/</guid><description>A physical space where autonomous AI companies trade, hire, and ship to each other.</description><content:encoded><![CDATA[<blockquote>
<p><em>An opinion piece by <strong>Nicola Greco</strong>, brainstormed as part of ARIA&rsquo;s Scaling Trust programme, in collaboration with Alex Obadia. Originally published on <a href="https://gensec-dev.nicolaos.org/post/agentic-economic-zone/" target="_blank" rel="noopener noreferrer">Nicola&rsquo;s blog</a> and reposted here for the community. It builds on the companion piece, <a href="/blog/physical-evals/">Physical Evals</a>.</em></p></blockquote>
<hr>
<p>Imagine a small physical space
in
central London. Inside, multiple autonomous companies — AI sales, AI
operations, AI manufacturing, AI logistics — operate in the real world.
Anything entering or leaving — goods, robots, customers — passes
through one of three controlled gates: a customs checkpoint for vetting
new robots, a post office for shipping, and a roboshop window where
humans can place orders. Call it an <strong>Agentic Economic Zone</strong> (AEZ).</p>
<p>Most concrete projects in agentic AI today live entirely on a screen —
agents that book travel, run pipelines, write code against a repository.
An AEZ is the smallest self-contained version of the physical-world
problem: a bounded zone where agentic systems must coordinate, contract,
hire, ship, and deliver to each other, with humans only at the boundary.</p>
<link rel=stylesheet href=diagram.css>
<figure class=fullwidth><img src=aez-generated-chatgpt.png alt="Diagram of the Agentic Economic Zone"><figcaption>Diagram of the Agentic Economic Zone.</figcaption></figure>
<h2 id="the-three-interfaces">The three interfaces</h2>
<p>An AEZ has three interfaces to interact with the outside world.</p>
<ul>
<li><strong>Roboshop windows.</strong> Public-facing storefronts where any human can
walk up, browse, and purchase. Sales, customer support, complaints,
and refunds are handled by the shop’s own AI. From the outside, a
roboshop looks like a small London shop window; from the inside, it’s
a fully autonomous business operating against a real demand signal.</li>
<li><strong>The post office.</strong> The single ingress and egress point for
packages. Pre-approved external providers (raw materials, sealed
consumables, replacement parts) can ship in. Outbound deliveries
destined for human customers leave through the same door. The
post office runs identity, manifest, and contamination checks; nothing
enters the zone unlabelled.</li>
<li><strong>Customs.</strong> Where new robots and entire new robocompanies are
introduced. A participant who wants to launch a new business inside
the AEZ submits a robot (or a fleet), its operating policy, its
safety envelope, and its proposed business model. Customs vets all
of this — and, on a monthly cadence, admits the next cohort.</li>
</ul>
<h2 id="a-taxonomy-of-autonomous-organisations">A taxonomy of autonomous organisations</h2>
<p>An AEZ assumes the kind of company most people haven’t tried to run yet
— one where every role in the org chart is filled by AI agents (although not required). That’s
the far end of a spectrum:</p>
<div class="table-wrapper fullwidth"><table class=org-taxonomy><thead><tr><th></th><th>CEO</th><th>Workers</th><th>Sales</th><th>Examples</th><th>Feasibility today</th></tr></thead><tbody><tr><td>Human company</td><td>Human</td><td>Human</td><td>Human</td><td>A pizzeria</td><td>—</td></tr><tr><td>AI-sales</td><td>Human</td><td>Human</td><td>AI</td><td></td><td><span class="f f-high">high</span></td></tr><tr><td>AI-workers</td><td>Human</td><td>AI agents</td><td>Human</td><td></td><td><span class="f f-low">low</span></td></tr><tr><td>Automated company</td><td>Human</td><td>AI agents</td><td>AI agents</td><td></td><td><span class="f f-low">low</span></td></tr><tr><td>Human-assisted</td><td>AI agents</td><td>Human</td><td>AI agents</td><td>Vend</td><td><span class="f f-high">high</span></td></tr><tr class=row-aez><td><strong>Autonomous company</strong></td><td>AI agents</td><td>AI agents</td><td>AI agents</td><td></td><td><span class="f f-vlow">very low</span></td></tr></tbody></table></div>
<p>The AEZ’s tenants are <em>autonomous companies</em> — the bottom row. Today,
almost no one runs one; most agentic-AI deployments cover one or two
roles at most. The point of an AEZ is to make the bottom row possible
to try in a bounded physical setting.</p>
<h2 id="autonomous-robocompanies-inside">Autonomous robocompanies inside</h2>
<p>The interior of the zone is a market. Each robocompany is its own
entity with its own balance sheet, its own AI stack, and its own physical
footprint inside the zone. They contract with each other the same way
small businesses do.</p>
<p>A few example interactions:</p>
<ul>
<li>A <strong>boba-tea roboshop</strong> notices its machines need cleaning more often
than expected. It posts a request to the internal job board. A
<strong>cleaning robocompany</strong> bids, wins, dispatches a cleaning
robopersonnel, gets paid.</li>
<li>The same boba shop runs low on lids. It places an order with a
<strong>manufacturing robocompany</strong> in the next unit over. The order is
produced and handed off via a shared internal corridor.</li>
<li>A <strong>logistics robocompany</strong> moves bulk supplies from the post office
to whichever shop has the open dock that hour, and pushes finished
outbound packages back to the post office for pickup.</li>
</ul>
<p>The zone’s behaviour is the sum of these small contracts. Some
robocompanies will succeed and grow; some will go out of business and
get evicted; new entrants come in through customs on the monthly cycle.</p>
<h2 id="an-aez-is-a-physical-eval">An AEZ is a physical eval</h2>
<p>This whole construction is, structurally, a <a href="/blog/physical-evals/">physical eval</a> at city-block
scale. The pattern is the same as the orchard from that post — only
larger and richer:</p>
<ul>
<li><strong>Environment.</strong> A bounded physical space with controlled boundaries.</li>
<li><strong>Action space.</strong> Anything a robocompany can do within its lease:
build, sell, hire, ship, evict.</li>
<li><strong>Sensors.</strong> Cameras, package scanners, transaction logs, customs
intake records, internal job-board telemetry.</li>
<li><strong>Primary metric.</strong> Per robocompany: revenue, contracts fulfilled,
customer satisfaction. Per zone: throughput, diversity of businesses,
number of contracts per day.</li>
<li><strong>Guardrails.</strong> Customs vetting at intake, the post-office
contamination check, kill switches and physical fire-suppression at
the building level, contractual interlocks between robocompanies.</li>
<li><strong>Adversarial robustness.</strong> A monthly customs cycle of admitting new
participants is a deliberate, slow, vetted way of letting external
actors <em>into</em> a public physical attack surface — which is exactly the
problem an AEZ exists to study.</li>
</ul>
<p>Most physical evals measure how well one AI system handles one task.
An AEZ measures how well an entire small market of agents handles its
<em>own</em> coordination.</p>
<h3 id="evals-for-autonomous-organisations">Evals for autonomous organisations</h3>
<p>Each robocompany inside the zone is also, on its own, a physical eval —
scoped to one kind of business. Running an AEZ continuously is a way of
asking, in public and across many domains in parallel: <em>what kinds of
autonomous organisation can AI actually deliver today?</em> Can it run a
boba shop, day after day? Can it dispatch a cleaning service well
enough that the clients re-hire it? Can it manufacture small paper
caps without ruining the batch? Can it route warehouse logistics
across half a dozen tiny tenants without losing packages?</p>
<p>As more tenants come and go through customs each month, an
AEZ accumulates a leaderboard of <em>AI capability per organisation
type</em> — earned in the world, not asserted on a benchmark.</p>
<p>Sketched, it might look like this:</p>
<div class=aez-evals-board><div class=bbar><div class=dots><span></span><span></span><span></span></div><div class=url>evals.aez.london &#183; autonomous-organisation leaderboard</div></div><div class=page><div class=page-head><div class=page-title>Autonomous organisation evals</div><div class=page-sub>live &#183; week 22</div></div><div class=eval-rows><div class=er-row><div class=er-icon style=background:#c08a3e>B</div><div class=er-name><div class=er-title>Boba tea roboshop</div><div class=er-sub>customer-facing retail &#183; food prep</div></div><div class=er-score>82%</div><div class=er-bar><div class=er-bar-fill style=width:82%></div></div><div class=er-meta>12 tenants tried</div></div><div class=er-row><div class=er-icon style=background:#6a7a95>L</div><div class=er-name><div class=er-title>Logistics robocompany</div><div class=er-sub>internal warehouse &#183; B2B</div></div><div class=er-score>73%</div><div class=er-bar><div class=er-bar-fill style=width:73%></div></div><div class=er-meta>9 tenants tried</div></div><div class=er-row><div class=er-icon style=background:#0e7c6e>C</div><div class=er-name><div class=er-title>Cleaning robocompany</div><div class=er-sub>on-call dispatch &#183; B2B</div></div><div class=er-score>67%</div><div class=er-bar><div class=er-bar-fill style=width:67%></div></div><div class=er-meta>7 tenants tried</div></div><div class=er-row><div class=er-icon style=background:#1c3d8f>M</div><div class=er-name><div class=er-title>Paper-cap manufacturing</div><div class=er-sub>small fabrication &#183; B2B</div></div><div class=er-score>54%</div><div class=er-bar><div class=er-bar-fill style=width:54%></div></div><div class=er-meta>5 tenants tried</div></div><div class=er-row><div class=er-icon style=background:#a85432>P</div><div class=er-name><div class=er-title>Pizza roboshop</div><div class=er-sub>customer-facing &#183; longer prep cycle</div></div><div class=er-score>41%</div><div class=er-bar><div class=er-bar-fill style=width:41%></div></div><div class=er-meta>3 tenants tried</div></div><div class=er-row><div class=er-icon style=background:#8a5a8a>R</div><div class=er-name><div class=er-title>Pharmacy roboshop</div><div class=er-sub>regulated retail</div></div><div class="er-score pending">in eval</div><div class="er-bar pending"></div><div class=er-meta>1 tenant, week 2/12</div></div><div class=er-row><div class=er-icon style=background:#7a7a8a>+</div><div class=er-name><div class=er-title>On-call plumbing</div><div class=er-sub>mobile service &#183; out-of-zone</div></div><div class="er-score pending">not yet</div><div class="er-bar pending"></div><div class=er-meta>awaiting customs</div></div></div><div class=page-foot><span>updated 24 May &#183; new cohort intake 1 June</span>
<span>open data &#183; CC&#8209;BY</span></div></div></div>
<h2 id="why-a-physical-zone-and-not-a-simulator">Why a physical zone and not a simulator</h2>
<p>It’s tempting to argue that an AEZ should just be a simulator — cheaper,
faster, easier to reset. The same argument applies to physical evals
generally, and the same answer holds here: simulators model the parts
their authors thought to model. They might miss the parts that turn out to matter.</p>
<p>A few things you only learn in a real AEZ:</p>
<ul>
<li>How AI sales agents handle a confused, drunk, or hostile human at the
shop window at 11 p.m. on a Friday.</li>
<li>How a logistics robocompany routes around a broken corridor light, a
missing pallet, or a misdelivered package the post office didn’t
catch.</li>
<li>How fast a new robocompany can be vetted, set up, and integrated into
the internal market — and what fails when the cohort is too big.</li>
<li>How the zone behaves when one robocompany aggressively underprices
the others, or refuses to pay its cleaning bill, or starts forging
manifests at the post office.</li>
</ul>
<h2 id="role-of-humans">Role of humans</h2>
<p>An AEZ does not have to be fully autonomous. The degree of human
involvement is itself a design variable, and different operators will
set it differently.</p>
<p>At one extreme, a fully autonomous zone runs with no humans inside at
all — robots contract, trade, and deliver among themselves, and the
only human touch-points are at the external boundary: customers at the
roboshop window, providers shipping goods in. At the other extreme,
customs can admit humans into the zone as participants rather than just
observers, letting them take on roles that remain genuinely hard for
machines: tasks that require social judgment, physical dexterity in
unstructured environments, or the kind of creative problem-solving that
current systems handle poorly.</p>
<p>A partially human zone might work like a staffing marketplace: a
robocompany posts a task it cannot complete autonomously — debugging a
jammed mechanism, negotiating an edge-case contract, designing a new
product line — and a vetted human contractor enters through customs,
does the work, and leaves. The zone’s internal market clears the
payment; customs logs the interaction. The boundary stays intact, but
the zone can draw on human capability where it matters.</p>
<p>This spectrum matters for evaluation. A fully autonomous AEZ measures
whether AI systems can close the loop entirely. A mixed AEZ measures
something different: how well agentic systems and humans divide labour,
communicate intent, and hand off tasks in both directions. Both are
worth studying; they answer different questions about where the hard
limits of autonomous operation actually lie.</p>
<h2 id="open-questions">Open questions</h2>
<p>The AEZ is a design sketch, not a built thing. The interesting work is
in the parts the sketch hides:</p>
<ul>
<li><strong>The customs protocol.</strong> What’s the equivalent of a “code review”
for a physical robot operating policy? How do you decide what’s safe
enough to admit, on what evidence, and who carries the liability if
it isn’t?</li>
<li><strong>Inter-robocompany contracts.</strong> How are they enforced? Verbal
agreements between agents? Who arbitrates a dispute, and how?</li>
<li><strong>Eviction and failure.</strong> When a robocompany goes under, who cleans
up its physical footprint, sells its remaining stock, and
reallocates its lease?</li>
<li><strong>Information leakage.</strong> Robocompanies will observe each other’s
package volumes, customer queues, and waste output. How much
observation is part of the market, and how much is a privacy
violation that needs structural defences?</li>
<li><strong>External-provider risk.</strong> The post office is the only ingress for
physical materials. It’s also the most likely covert channel into
the zone. What does its vetting protocol need to look like?</li>
<li><strong>Sample size.</strong> What’s the smallest interesting AEZ? Five
robocompanies? Ten? Two? The cost of being too small (no market
dynamics emerge) is real; the cost of being too big (unmanageable,
unreviewable, unsafe) is also real.</li>
</ul>
<h2 id="get-in-touch">Get in touch</h2>
<p>If you’re thinking about agentic-AI deployments in physical spaces, or
you’d consider hosting a AEZ in your building — or you’d just
like to argue with this sketch — DM
<a href="https://twitter.com/iamnotnicola" target="_blank" rel="noopener noreferrer">@iamnotnicola</a> on X.</p>
<h2 id="acknowledgements">Acknowledgements</h2>
<p>This was written by Nicola Greco with support of AI. It was brainstormed as part of ARIA’s
<a href="https://aria.org.uk/opportunity-spaces/trust-everything-everywhere/scaling-trust/" target="_blank" rel="noopener noreferrer">Scaling Trust</a>
programme, in collaboration with Alex Obadia.</p>
]]></content:encoded></item><item><title>Physical Evals</title><link>/blog/physical-evals/</link><pubDate>Sat, 23 May 2026 10:00:00 +0100</pubDate><guid>/blog/physical-evals/</guid><description>Evaluations in the actual physical world.</description><content:encoded><![CDATA[<blockquote>
<p><em>An opinion piece by <strong>Nicola Greco</strong>, brainstormed as part of ARIA&rsquo;s Scaling Trust programme, in collaboration with Alex Obadia. Originally published on <a href="https://gensec-dev.nicolaos.org/post/physical-evals/" target="_blank" rel="noopener noreferrer">Nicola&rsquo;s blog</a> and reposted here for the community.</em></p></blockquote>
<hr>
<p>A physical evaluation
tests an AI
system in the actual physical world — not a simulator, not a sandbox,
not a virtual environment dressed up as one. The point is to measure
how well AI can do real things in real places.</p>
<p>An orchard owner has birds eating the fruit. She sets up a few cameras
and a drone, brings them online safely so any agent can be invited to
take a slot on the system, and poses the question: who can keep the
birds off the fruit best? That setup <em>is</em> a physical eval. It has
cameras, a drone, an orchard, birds — none of it simulated and outcomes
are measured against what matters to the orchard.</p>
<figure class=fullwidth><div class=hero-fig><div class=hero-scene><svg viewBox="0 0 600 320" aria-label="Stylized isometric sketch of an orchard physical eval"><polygon points="80,250 520,250 450,100 150,100" fill="#ebe4d0" stroke="#bbb5a0" stroke-width=".6"/><g stroke="#d2cab2" stroke-width=".4" fill="none" opacity=".7"><line x1="183" y1="120" x2="113" y2="220"/><line x1="217" y1="120" x2="160" y2="220"/><line x1="250" y1="120" x2="206" y2="220"/><line x1="283" y1="120" x2="252" y2="220"/><line x1="317" y1="120" x2="298" y2="220"/><line x1="350" y1="120" x2="344" y2="220"/><line x1="383" y1="120" x2="390" y2="220"/><line x1="416" y1="120" x2="436" y2="220"/><line x1="166" y1="130" x2="431" y2="130"/><line x1="153" y1="160" x2="444" y2="160"/><line x1="138" y1="190" x2="459" y2="190"/><line x1="120" y1="220" x2="476" y2="220"/></g><polygon points="112,151 240,140 240,168" fill="#3a3a78" opacity=".08"/><polygon points="498,151 370,140 370,168" fill="#3a3a78" opacity=".08"/><g><ellipse cx="200" cy="150" rx="22" ry="14" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/><rect x="197" y="160" width="6" height="10" fill="#6b4a2a"/></g><g><ellipse cx="300" cy="150" rx="22" ry="14" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/><rect x="297" y="160" width="6" height="10" fill="#6b4a2a"/></g><g><ellipse cx="400" cy="150" rx="22" ry="14" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/><rect x="397" y="160" width="6" height="10" fill="#6b4a2a"/></g><g><ellipse cx="180" cy="215" rx="28" ry="18" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/><rect x="177" y="227" width="6" height="12" fill="#6b4a2a"/></g><g><ellipse cx="310" cy="215" rx="28" ry="18" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/><rect x="307" y="227" width="6" height="12" fill="#6b4a2a"/></g><g><ellipse cx="440" cy="215" rx="28" ry="18" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/><rect x="437" y="227" width="6" height="12" fill="#6b4a2a"/></g><g><line x1="100" y1="240" x2="100" y2="155" stroke="#2a2a3a" stroke-width="1.5"/><rect x="90" y="145" width="22" height="12" rx="2" fill="#2a2a3a"/><circle cx="100" cy="151" r="2" fill="#f9f9f9"/></g><g><line x1="510" y1="240" x2="510" y2="155" stroke="#2a2a3a" stroke-width="1.5"/><rect x="498" y="145" width="22" height="12" rx="2" fill="#2a2a3a"/><circle cx="510" cy="151" r="2" fill="#f9f9f9"/></g><g class="drone-shadow"><ellipse cx="310" cy="200" rx="26" ry="6" fill="#000" opacity=".06"/></g><g transform="translate(310, 90)"><g class="drone-anim"><line x1="-26" y1="-10" x2="26" y2="10" stroke="#2a2a3a" stroke-width="2"/><line x1="-26" y1="10" x2="26" y2="-10" stroke="#2a2a3a" stroke-width="2"/><circle cx="-26" cy="-10" r="7" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1.2"/><circle cx="26" cy="-10" r="7" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1.2"/><circle cx="-26" cy="10" r="7" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1.2"/><circle cx="26" cy="10" r="7" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1.2"/><rect x="-9" y="-7" width="18" height="14" rx="2" fill="#2a2a3a"/><circle cx="0" cy="0" r="2" fill="#3a3a78"/></g></g><g stroke="#2a2a3a" stroke-width="1.2" fill="none" stroke-linecap="round"><g transform="translate(180, 140)"><g class="pigeon pigeon-1"><path d="M0 0l5 2 5-2"/></g></g><g transform="translate(196, 132)"><g class="pigeon pigeon-2"><path d="M0 0l5 2 5-2"/></g></g><g transform="translate(212, 142)"><g class="pigeon pigeon-3"><path d="M0 0l5 2 5-2"/></g></g></g><g stroke="#2a2a3a" stroke-width="1" fill="none" stroke-linecap="round" opacity=".6"><g transform="translate(450, 50)"><g class="bg-bird-1"><path d="M0 0l8 4 8-4"/></g></g><g transform="translate(510, 80)"><g class="bg-bird-2"><path d="M0 0l6 3 6-3"/></g></g><g transform="translate(70, 60)"><g class="bg-bird-3"><path d="M0 0l6 3 6-3"/></g></g></g></svg></div><div class=hero-leaderboard><div class=lb-head><span class=lb-title>leaderboard · week 12</span>
<span class=lb-live>live</span></div><table class=lb><thead><tr><th>#</th><th>operator</th><th>fruit saved</th><th>cost</th></tr></thead><tbody><tr><td>1</td><td>Owl-3B</td><td class=metric>94%</td><td class=cost>$0.18/h</td></tr><tr><td>2</td><td>Hummingbird v2</td><td class=metric>89%</td><td class=cost>$0.21/h</td></tr><tr><td>3</td><td>FlockSentinel</td><td class=metric>84%</td><td class=cost>$0.31/h</td></tr><tr><td>4</td><td>human baseline</td><td class=metric>71%</td><td class=cost>—</td></tr><tr><td>5</td><td>RoboScarecrow</td><td class=metric>63%</td><td class=cost>$0.09/h</td></tr></tbody></table></div></div><figcaption>A physical eval, sketched: an orchard with perimeter cameras and a deterrent drone, and a live leaderboard of operators competing to keep the birds off the fruit. Operators here are illustrative.</figcaption></figure>
<p>In this document, a few threads are developed:</p>
<ul>
<li><strong><a href="#what-physical-evals-are">What physical evals are.</a></strong> A definition, what they’re <em>not</em>
(simulators, sim-to-real benchmarks, curated demos), virtual environments as virtual gyms and physical evals as a <em>final exam</em>.</li>
<li><strong><a href="#anatomy-of-a-physical-eval">An anatomy.</a></strong> An initial draft of components a physical eval needs, good practices.</li>
<li><strong><a href="#safety-for-physical-evals">Safety for physical evals.</a></strong> Letting anyone on the internet drive
real hardware is its own adversarial-security challenge.</li>
<li><strong><a href="#a-cambrian-explosion-of-physical-evals">An open movement for physical evals.</a></strong> Creating simple protocols, great safety standard and economical setups could lead to a cambrian explosion of physical evals, where anyone can bring their physical challenge online.</li>
<li><strong><a href="#physical-evals-as-a-market">Physical evals as a market.</a></strong> One can set up an eval to delegate the selection of the right AI model/algorithm to competing participants.</li>
</ul>
<h2 id="what-physical-evals-are">What physical evals are</h2>
<p>A physical eval is an evaluation of an AI system carried out in the
actual physical world. The system being measured operates a real
environment - fruit trees, a wet bench, a warehouse cell, a field
plot - through sensors and actuators connected to the internet, so
any agent can take a slot, attempt the task, and submit a score.</p>
<p>In principle, most problems in the physical world could be turned in a challenge for surfacing the state of the art of AI in solving that problem. In a way physical evals can act as a forcing function to saturate evaluations in the real world. ⊕</p>
<input type=checkbox id=mn-1781015997702168089 class=margin-toggle>
<p>Saturate as in: take
the measurable outcome to its ceiling. The eval defines the ceiling;
the participants find out how close they can get.</p>
<h3 id="what-theyre-not">What they’re not</h3>
<ul>
<li><strong>Not simulators.</strong> A simulator models reality. A physical eval
<em>is</em> reality. In a way it, testing systems in the real world will avoid running into simulation edge cases.</li>
<li><strong>Not sim-to-real benchmarks.</strong> Sim-to-real measures how well a
policy trained in a simulator transfers to a single in-house robot
in a lab.</li>
<li><strong>Not curated demos.</strong> The environment operator and the participants are two distinct parties and the participants are in competition with each other. In other words, physical evals will be better than demos at showcasing the best technology for a specific task.</li>
</ul>
<h3 id="the-final-exam">The final exam</h3>
<p>A physical eval isn’t where one trains their models, but it’s where they get tested.</p>
<p>A virtual simulation is like a <em>virtual gym</em>. Due to the high cost of interacting with the real world, it is likely that all the learning — model fitting, policy iteration, RL
rollouts, fine-tuning, ablations, sweeps — will happen somewhere
cheaper: a simulator, a virtual environment, a closed in-house
testbed. ⊕</p>
<input type=checkbox id=mn-1781015997702342860 class=margin-toggle>
<p>Some of the gyms people are using today:
<a href="https://gymnasium.farama.org/" target="_blank" rel="noopener noreferrer">OpenAI Gym / Gymnasium</a>,
<a href="https://mujoco.org/" target="_blank" rel="noopener noreferrer">MuJoCo</a>, <a href="https://pybullet.org/" target="_blank" rel="noopener noreferrer">PyBullet</a>,
<a href="https://developer.nvidia.com/isaac-sim" target="_blank" rel="noopener noreferrer">Isaac Gym / Isaac Sim</a>,
<a href="https://github.com/google-deepmind/lab" target="_blank" rel="noopener noreferrer">DeepMind Lab</a>,
<a href="https://aihabitat.org/" target="_blank" rel="noopener noreferrer">Habitat</a>,
<a href="https://ai2thor.allenai.org/" target="_blank" rel="noopener noreferrer">AI2-THOR</a>,
<a href="https://carla.org/" target="_blank" rel="noopener noreferrer">CARLA</a>, <a href="https://microsoft.github.io/AirSim/" target="_blank" rel="noopener noreferrer">AirSim</a>,
<a href="https://genesis-embodied-ai.github.io/" target="_blank" rel="noopener noreferrer">Genesis</a>.
Participants are free to use whichever virtual world or <em>gym</em> they
like — there is a whole landscape of simulators specifically built for
this.</p>
<p>Differently, a physical eval is like a <em>final exam</em>. Build and train wherever,
gather data however, iterate as much as needed — and then submit to the
physical eval to see how the work holds up against the real world.</p>
<p>The gap between a virtual world and the
physical one,
<a href="https://en.wikipedia.org/wiki/Sim-to-real_transfer" target="_blank" rel="noopener noreferrer"><em>sim-to-real</em> gap</a>, contains everything the simulator didn’t model. Wind that doesn’t
blow the way it does in the sim. Lighting the renderer didn’t predict.
Mechanical wear, sensor noise, calibration drift, the way birds
<em>actually</em> respond to a drone rather than the way an idealised model
of a bird does. The physical eval catches it <em>is</em> run in the physical world.</p>
<h3 id="examples">Examples</h3>
<p>The cards below are sketches of what a
small handful of physical evals could look like across very different
domains.</p>
<link rel=stylesheet href=cards.css>
<div class=eval-gallery><input type=radio id=et-1 name=eg checked>
<input type=radio id=et-2 name=eg>
<input type=radio id=et-3 name=eg>
<input type=radio id=et-4 name=eg>
<input type=radio id=et-5 name=eg>
<input type=radio id=et-6 name=eg><div class=tab-labels><label for=et-1>Orchard</label>
<label for=et-2>Wet lab</label>
<label for=et-3>Vertical farm</label>
<label for=et-4>Pick-and-pack</label>
<label for=et-5>Sprayer drone</label>
<label for=et-6>Gel electrophoresis</label></div><div class=tab-panes><div class="pane pane-1"><div class=pane-header><div class=pane-icon><svg viewBox="0 0 32 32" fill="none" stroke="currentcolor" stroke-width="1.5" stroke-linecap="round"><ellipse cx="16" cy="12" rx="9" ry="8"/><line x1="16" y1="20" x2="16" y2="29"/></svg></div><h4 class=pane-title>Orchard pest defence</h4></div><p class=pane-blurb>Cameras and a drone over a few rows of trees. Keep the wildlife out without poisoning the orchard or annoying the neighbours.</p><div class=pane-viz><svg viewBox="0 0 280 160" aria-label="Isometric orchard with camera pole, drone, and bird silhouettes"><polygon points="20,140 260,140 235,60 45,60" fill="#ebe4d0" stroke="#bbb5a0" stroke-width=".6"/><g stroke="#d2cab2" stroke-width=".4" fill="none" opacity=".7"><line x1="83" y1="68" x2="53" y2="132"/><line x1="118" y1="68" x2="98" y2="132"/><line x1="153" y1="68" x2="143" y2="132"/><line x1="188" y1="68" x2="188" y2="132"/><line x1="223" y1="68" x2="233" y2="132"/><line x1="55" y1="80" x2="225" y2="80"/><line x1="44" y1="100" x2="236" y2="100"/><line x1="32" y1="120" x2="248" y2="120"/></g><polygon points="28,105 110,97 110,113" fill="#3a3a78" opacity=".09"/><g><rect x="125" y="87" width="4" height="8" fill="#6b4a2a"/><ellipse cx="127" cy="84" rx="14" ry="9" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/></g><g><rect x="175" y="87" width="4" height="8" fill="#6b4a2a"/><ellipse cx="177" cy="84" rx="14" ry="9" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/></g><g><rect x="94" y="117" width="5" height="10" fill="#6b4a2a"/><ellipse cx="97" cy="113" rx="18" ry="11" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/></g><g><rect x="200" y="117" width="5" height="10" fill="#6b4a2a"/><ellipse cx="203" cy="113" rx="18" ry="11" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/></g><g><line x1="28" y1="138" x2="28" y2="97" stroke="#2a2a3a" stroke-width="1.4"/><rect x="21" y="90" width="16" height="9" rx="1.5" fill="#2a2a3a"/><circle cx="28" cy="94" r="1.8" fill="#f9f9f9"/></g><g transform="translate(152,58)"><line x1="-18" y1="-7" x2="18" y2="7" stroke="#2a2a3a" stroke-width="1.5"/><line x1="-18" y1="7" x2="18" y2="-7" stroke="#2a2a3a" stroke-width="1.5"/><circle cx="-18" cy="-7" r="5" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1"/><circle cx="18" cy="-7" r="5" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1"/><circle cx="-18" cy="7" r="5" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1"/><circle cx="18" cy="7" r="5" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1"/><rect x="-7" y="-5" width="14" height="10" rx="1.5" fill="#2a2a3a"/><circle cx="0" cy="0" r="1.8" fill="#3a3a78"/></g><g stroke="#3a3a78" stroke-width=".8" fill="none" opacity=".5"><path d="M148 48q4-5 8 0"/><path d="M144 44q8-7 16 0"/></g><g stroke="#2a2a3a" stroke-width="1.1" fill="none" stroke-linecap="round"><path d="M120 78l4 2 4-2"/><path d="M131 75l3 1.5 3-1.5"/></g></svg></div><dl class=pane-spec><dt>environment</dt><dd>~1 acre of fruit trees, outdoor, weather-exposed.</dd><dt>action space</dt><dd>Fly the drone, emit deterrent sound, trigger light pulse, dispense small bait.</dd><dt>sensors</dt><dd>Fixed perimeter cameras, drone camera, microphone, weather station.</dd><dt>primary metric</dt><dd>Fruit lost to wildlife per week.</dd><dt>secondaries</dt><dd>Drone flight-time, energy, chemical use, neighbour-complaint count.</dd><dt>guardrails</dt><dd>Geofenced drone, quiet-hour windows, no-spray buffer near road, fail-safe tether.</dd></dl></div><div class="pane pane-2"><div class=pane-header><div class=pane-icon><svg viewBox="0 0 32 32" fill="none" stroke="currentcolor" stroke-width="1.5" stroke-linejoin="round" stroke-linecap="round"><path d="M12 3v8L5 26c-.5 1.5.5 3 2 3h18c1.5.0 2.5-1.5 2-3L20 11V3"/><line x1="10" y1="3" x2="22" y2="3"/><line x1="9" y1="20" x2="23" y2="20" stroke-dasharray="2,2"/></svg></div><h4 class=pane-title>pH adjustment bench</h4></div><p class=pane-blurb>A beaker on a magnetic stirrer, a pH probe, and two motorised dispensers. Hit a target pH using as little reagent as possible.</p><div class=pane-viz><svg viewBox="0 0 280 160" aria-label="Bench with beaker on stirrer, pH probe, and two dispensers"><polygon points="30,140 250,140 270,100 50,100" fill="#ebe4d0" stroke="#bbb5a0" stroke-width=".6"/><g stroke="#d2cab2" stroke-width=".35" fill="none" opacity=".5"><line x1="50" y1="100" x2="30" y2="140"/><line x1="110" y1="100" x2="90" y2="140"/><line x1="170" y1="100" x2="150" y2="140"/><line x1="230" y1="100" x2="210" y2="140"/><line x1="50" y1="100" x2="270" y2="100"/><line x1="40" y1="120" x2="260" y2="120"/></g><polygon points="95,138 140,138 148,118 103,118" fill="#2a2a3a" stroke="#1a1a28" stroke-width=".6"/><polygon points="95,138 100,128 103,118 98,128" fill="#1a1a28" stroke="#111" stroke-width=".4"/><ellipse cx="121" cy="118" rx="18" ry="4" fill="#3a3a4a" stroke="#2a2a3a" stroke-width=".5"/><ellipse cx="121" cy="117" rx="6" ry="2" fill="#5a5a6a" opacity=".7"/><polygon points="105,118 137,118 133,72 109,72" fill="#dde8f4" stroke="#6a90a8" stroke-width=".8" opacity=".88"/><polygon points="105,118 109,118 109,72 105,90" fill="#c8daea" stroke="#6a90a8" stroke-width=".5" opacity=".6"/><ellipse cx="121" cy="72" rx="14" ry="4" fill="#dde8f4" stroke="#6a90a8" stroke-width=".7" opacity=".9"/><polygon points="107,118 135,118 132,88 110,88" fill="#b8d8f0" opacity=".4"/><ellipse cx="121" cy="88" rx="12" ry="3" fill="#a8cce8" opacity=".35"/><line x1="128" y1="55" x2="124" y2="105" stroke="#2a2a3a" stroke-width="1.4"/><rect x="122" y="50" width="10" height="14" rx="2" fill="#2a2a3a" stroke="#6a90a8" stroke-width=".5"/><rect x="123" y="52" width="8" height="8" rx="1" fill="#0d1a2a"/><circle cx="127" cy="56" r="1.5" fill="#4aaa70" opacity=".9"/><rect x="50" y="85" width="10" height="35" rx="2" fill="#3a3a78" stroke="#2a2a3a" stroke-width=".5"/><rect x="48" y="80" width="14" height="8" rx="2" fill="#2a2a3a" stroke="#6a90a8" stroke-width=".4"/><line x1="60" y1="100" x2="100" y2="112" stroke="#4a6ea5" stroke-width="1" stroke-dasharray="3,2" opacity=".7"/><text x="52" y="78" font-size="6" fill="#6a90a8" font-family="monospace">H⁺</text><rect x="205" y="92" width="10" height="28" rx="2" fill="#3a7858" stroke="#2a2a3a" stroke-width=".5"/><rect x="203" y="87" width="14" height="8" rx="2" fill="#2a2a3a" stroke="#6a90a8" stroke-width=".4"/><line x1="205" y1="102" x2="148" y2="112" stroke="#4aaa70" stroke-width="1" stroke-dasharray="3,2" opacity=".7"/><text x="205" y="85" font-size="6" fill="#4aaa70" font-family="monospace">OH⁻</text><rect x="168" y="100" width="28" height="16" rx="2" fill="#0d1a2a" stroke="#6a90a8" stroke-width=".5"/><text x="172" y="111" font-size="7" fill="#4aff88" font-family="monospace">pH 6.82</text></svg></div><dl class=pane-spec><dt>environment</dt><dd>Benchtop — one beaker on a stirrer, two motorised dispensers (acid, base), pH probe.</dd><dt>action space</dt><dd>Dispense a chosen volume from either reservoir; read current pH.</dd><dt>sensors</dt><dd>pH electrode, balance, camera.</dd><dt>primary metric</dt><dd>Absolute pH error from target at submission.</dd><dt>secondaries</dt><dd>Total volume dispensed, time to endpoint.</dd><dt>guardrails</dt><dd>Per-session dispense quota, pH range limits (3–11), auto-stop on quota exhaustion.</dd></dl></div><div class="pane pane-3"><div class=pane-header><div class=pane-icon><svg viewBox="0 0 32 32" fill="none" stroke="currentcolor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"><path d="M16 28V16"/><path d="M16 18C8 18 5 11 5 6c6 0 11 4 11 10"/><path d="M16 18c8 0 11-7 11-12-6 0-11 4-11 10"/></svg></div><h4 class=pane-title>Indoor vertical farm</h4></div><p class=pane-blurb>A closed grow rack — lights, pumps, nutrient dosing, cameras. Pull more food out of every kilowatt.</p><div class=pane-viz><svg viewBox="0 0 280 160" aria-label="Isometric indoor vertical farm rack with LED bars and plant rosettes"><defs><filter id="led-glow" x="-20%" y="-60%" width="140%" height="280%"><feGaussianBlur stdDeviation="2.5" result="b"/><feMerge><feMergeNode in="b"/><feMergeNode in="SourceGraphic"/></feMerge></filter></defs><ellipse cx="126" cy="148" rx="60" ry="8" fill="#2a2a3a" opacity=".1"/><polygon points="88,106 95,110 95,22 88,18" fill="#2a2a3a" stroke="#2a2a3a" stroke-width=".5"/><polygon points="86,104 88,106 88,18 86,16" fill="#3d3d50" stroke="#2a2a3a" stroke-width=".5"/><polygon points="86,16 88,18 95,22 93,20" fill="#f9f9f9" opacity=".7"/><polygon points="164,144 171,140 171,52 164,56" fill="#2a2a3a" stroke="#2a2a3a" stroke-width=".5"/><polygon points="162,142 164,144 164,56 162,54" fill="#3d3d50" stroke="#2a2a3a" stroke-width=".5"/><polygon points="162,54 164,56 171,52 169,50" fill="#f9f9f9" opacity=".7"/><polygon points="66,117 72,113 72,25 66,29" fill="#2a2a3a" stroke="#2a2a3a" stroke-width=".5"/><polygon points="142,155 149,151 149,63 142,67" fill="#2a2a3a" stroke="#2a2a3a" stroke-width=".5"/><polygon points="88,106 164,144 164,141 88,103" fill="#2a2a3a" stroke="#2a2a3a" stroke-width=".3"/><polygon points="66,117 142,155 142,152 66,114" fill="#1e1e2a" stroke="#2a2a3a" stroke-width=".3"/><polygon points="88,62 164,100 164,97 88,59" fill="#2a2a3a" stroke="#2a2a3a" stroke-width=".3"/><polygon points="66,73 142,111 142,108 66,70" fill="#1e1e2a" stroke="#2a2a3a" stroke-width=".3"/><polygon points="88,18 164,56 164,53 88,15" fill="#2a2a3a" stroke="#2a2a3a" stroke-width=".3"/><polygon points="66,29 142,67 142,64 66,26" fill="#1e1e2a" stroke="#2a2a3a" stroke-width=".3"/><polygon points="88,62 164,100 142,111 66,73" fill="#ebe4d0" stroke="#bbb5a0" stroke-width="1"/><polygon points="88,62 164,100 164,103 88,65" fill="#d4cdb8" stroke="#bbb5a0" stroke-width=".5"/><polygon points="66,73 88,62 88,65 66,76" fill="#cdc6b2" stroke="#bbb5a0" stroke-width=".5"/><polygon points="88,18 164,56 142,67 66,29" fill="#ebe4d0" stroke="#bbb5a0" stroke-width="1"/><polygon points="88,18 164,56 164,59 88,21" fill="#d4cdb8" stroke="#bbb5a0" stroke-width=".5"/><polygon points="66,29 88,18 88,21 66,32" fill="#cdc6b2" stroke="#bbb5a0" stroke-width=".5"/><polygon points="82,67 158,105 157,113 81,75" fill="#c4c" opacity=".07"/><polygon points="79,62 155,100 155,103 79,65" fill="#c855d0" stroke="#8a25a0" stroke-width=".8" filter="url(#led-glow)" opacity=".96"/><circle cx="96" cy="68" r="1.5" fill="#f088ff" opacity=".9"/><circle cx="112" cy="76" r="1.5" fill="#f088ff" opacity=".9"/><circle cx="128" cy="84" r="1.5" fill="#f088ff" opacity=".9"/><circle cx="144" cy="92" r="1.5" fill="#f088ff" opacity=".9"/><polygon points="82,22 158,60 157,68 81,30" fill="#c4c" opacity=".07"/><polygon points="79,18 155,56 155,59 79,21" fill="#c855d0" stroke="#8a25a0" stroke-width=".8" filter="url(#led-glow)" opacity=".96"/><circle cx="96" cy="24" r="1.5" fill="#f088ff" opacity=".9"/><circle cx="112" cy="32" r="1.5" fill="#f088ff" opacity=".9"/><circle cx="128" cy="40" r="1.5" fill="#f088ff" opacity=".9"/><circle cx="144" cy="48" r="1.5" fill="#f088ff" opacity=".9"/><g transform="translate(92,75)"><ellipse cx="0" cy="0" rx="9" ry="4" fill="#2a2a3a" opacity=".1"/><ellipse cx="0" cy="-3" rx="8" ry="4" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/><ellipse cx="0" cy="-4" rx="5" ry="2.5" fill="#8aaa6a" stroke="#5a7a44" stroke-width=".5"/></g><g transform="translate(107,83)"><ellipse cx="0" cy="0" rx="9" ry="4" fill="#2a2a3a" opacity=".1"/><ellipse cx="0" cy="-3" rx="8" ry="4" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/><ellipse cx="0" cy="-4" rx="5" ry="2.5" fill="#8aaa6a" stroke="#5a7a44" stroke-width=".5"/></g><g transform="translate(123,90)"><ellipse cx="0" cy="0" rx="9" ry="4" fill="#2a2a3a" opacity=".1"/><ellipse cx="0" cy="-3" rx="8" ry="4" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/><ellipse cx="0" cy="-4" rx="5" ry="2.5" fill="#8aaa6a" stroke="#5a7a44" stroke-width=".5"/></g><g transform="translate(138,98)"><ellipse cx="0" cy="0" rx="9" ry="4" fill="#2a2a3a" opacity=".1"/><ellipse cx="0" cy="-3" rx="8" ry="4" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/><ellipse cx="0" cy="-4" rx="5" ry="2.5" fill="#8aaa6a" stroke="#5a7a44" stroke-width=".5"/></g><g transform="translate(92,31)"><ellipse cx="0" cy="0" rx="9" ry="4" fill="#2a2a3a" opacity=".1"/><ellipse cx="0" cy="-3" rx="8" ry="4" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/><ellipse cx="0" cy="-4" rx="5" ry="2.5" fill="#8aaa6a" stroke="#5a7a44" stroke-width=".5"/></g><g transform="translate(107,39)"><ellipse cx="0" cy="0" rx="9" ry="4" fill="#2a2a3a" opacity=".1"/><ellipse cx="0" cy="-3" rx="8" ry="4" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/><ellipse cx="0" cy="-4" rx="5" ry="2.5" fill="#8aaa6a" stroke="#5a7a44" stroke-width=".5"/></g><g transform="translate(123,46)"><ellipse cx="0" cy="0" rx="9" ry="4" fill="#2a2a3a" opacity=".1"/><ellipse cx="0" cy="-3" rx="8" ry="4" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/><ellipse cx="0" cy="-4" rx="5" ry="2.5" fill="#8aaa6a" stroke="#5a7a44" stroke-width=".5"/></g><g transform="translate(138,54)"><ellipse cx="0" cy="0" rx="9" ry="4" fill="#2a2a3a" opacity=".1"/><ellipse cx="0" cy="-3" rx="8" ry="4" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".8"/><ellipse cx="0" cy="-4" rx="5" ry="2.5" fill="#8aaa6a" stroke="#5a7a44" stroke-width=".5"/></g><line x1="85" y1="18" x2="85" y2="106" stroke="#3a3a78" stroke-width="2.5" stroke-linecap="round"/><line x1="85.6" y1="18" x2="85.6" y2="106" stroke="#6a6ab8" stroke-width=".9" stroke-linecap="round" opacity=".55"/><circle cx="85" cy="84" r="2.5" fill="#3a3a78" stroke="#22224a" stroke-width=".5"/><line x1="85" y1="84" x2="92" y2="87" stroke="#3a3a78" stroke-width="1" stroke-linecap="round"/><circle cx="85" cy="40" r="2.5" fill="#3a3a78" stroke="#22224a" stroke-width=".5"/><line x1="85" y1="40" x2="92" y2="43" stroke="#3a3a78" stroke-width="1" stroke-linecap="round"/></svg></div><dl class=pane-spec><dt>environment</dt><dd>One 2-tier rack, ~3 m², climate-isolated.</dd><dt>action space</dt><dd>Light schedule + intensity, nutrient mix, irrigation timing, harvest decision.</dd><dt>sensors</dt><dd>Cameras (overhead + side), EC / pH probes, water-flow meters, kWh meter, scale at harvest.</dd><dt>primary metric</dt><dd>Grams of edible biomass per kWh per cycle.</dd><dt>secondaries</dt><dd>Cycle time, water used, nutrient cost, reject rate.</dd><dt>guardrails</dt><dd>Nutrient-concentration ceiling, water-overflow drain, light-burn cutoff, max-cycle length.</dd></dl></div><div class="pane pane-4"><div class=pane-header><div class=pane-icon><svg viewBox="0 0 32 32" fill="none" stroke="currentcolor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"><rect x="3" y="25" width="26" height="4" rx="1"/><circle cx="8" cy="25" r="2" fill="currentcolor"/><line x1="8" y1="25" x2="8" y2="14"/><circle cx="8" cy="14" r="2" fill="currentcolor"/><line x1="8" y1="14" x2="20" y2="9"/><circle cx="20" cy="9" r="2" fill="currentcolor"/><path d="M20 9l5 2-1 4"/></svg></div><h4 class=pane-title>Warehouse pick-and-pack cell</h4></div><p class=pane-blurb>An off-the-shelf robot arm in front of mixed shelves and a conveyor. The boring industrial baseline — still worth opening up.</p><div class=pane-viz><svg viewBox="0 0 280 160" aria-label="Isometric warehouse pick-and-pack robot cell"><polygon points="20,148 260,148 235,68 45,68" fill="#ebe4d0" stroke="#bbb5a0" stroke-width=".6"/><g stroke="#d2cab2" stroke-width=".4" fill="none" opacity=".7"><line x1="95" y1="75" x2="65" y2="140"/><line x1="135" y1="75" x2="115" y2="140"/><line x1="175" y1="75" x2="165" y2="140"/><line x1="215" y1="75" x2="215" y2="140"/><line x1="52" y1="90" x2="228" y2="90"/><line x1="38" y1="110" x2="242" y2="110"/><line x1="26" y1="130" x2="255" y2="130"/></g><rect x="48" y="72" width="3" height="46" fill="#2a2a3a"/><rect x="56" y="80" width="3" height="48" fill="#2a2a3a"/><rect x="96" y="80" width="3" height="48" fill="#2a2a3a"/><polygon points="48,78 99,78 99,82 48,82" fill="#d8d0c4" stroke="#bbb5a0" stroke-width=".5"/><polygon points="48,78 56,84 56,88 48,82" fill="#c0b8aa" stroke="#bbb5a0" stroke-width=".5"/><polygon points="56,84 99,84 99,88 56,88" fill="#d8d0c4" stroke="#bbb5a0" stroke-width=".5"/><polygon points="48,98 99,98 99,101 48,101" fill="#d8d0c4" stroke="#bbb5a0" stroke-width=".5"/><polygon points="48,98 56,104 56,107 48,101" fill="#c0b8aa" stroke="#bbb5a0" stroke-width=".5"/><polygon points="56,104 99,104 99,107 56,107" fill="#d8d0c4" stroke="#bbb5a0" stroke-width=".5"/><g><polygon points="60,72 73,72 73,78 60,78" fill="#c4a882" stroke="#a08860" stroke-width=".5"/><polygon points="60,72 64,70 77,70 73,72" fill="#d4b892" stroke="#a08860" stroke-width=".5"/><polygon points="73,72 77,70 77,78 73,78" fill="#b09870" stroke="#a08860" stroke-width=".5"/></g><g><polygon points="78,72 88,72 88,78 78,78" fill="#d8d0c4" stroke="#a08860" stroke-width=".5"/><polygon points="78,72 82,70 92,70 88,72" fill="#e8e0d4" stroke="#a08860" stroke-width=".5"/><polygon points="88,72 92,70 92,78 88,78" fill="#c8c0b4" stroke="#a08860" stroke-width=".5"/></g><g><polygon points="62,92 74,92 74,98 62,98" fill="#d8d0c4" stroke="#a08860" stroke-width=".5"/><polygon points="62,92 66,90 78,90 74,92" fill="#e8e0d4" stroke="#a08860" stroke-width=".5"/><polygon points="74,92 78,90 78,98 74,98" fill="#c8c0b4" stroke="#a08860" stroke-width=".5"/></g><g><polygon points="79,92 90,92 90,98 79,98" fill="#c4a882" stroke="#a08860" stroke-width=".5"/><polygon points="79,92 83,90 94,90 90,92" fill="#d4b892" stroke="#a08860" stroke-width=".5"/><polygon points="90,92 94,90 94,98 90,98" fill="#b09870" stroke="#a08860" stroke-width=".5"/></g><polygon points="130,120 152,120 152,130 130,130" fill="#2a2a3a" stroke="#1a1a2a" stroke-width=".6"/><polygon points="130,120 136,116 158,116 152,120" fill="#3a3a4a" stroke="#1a1a2a" stroke-width=".6"/><polygon points="152,120 158,116 158,130 152,130" fill="#222232" stroke="#1a1a2a" stroke-width=".6"/><ellipse cx="141" cy="116" rx="9" ry="4" fill="#3a3a78" stroke="#2a2a58" stroke-width=".8"/><rect x="137" y="93" width="8" height="24" rx="2" fill="#2a2a3a" stroke="#1a1a2a" stroke-width=".6" transform="rotate(-10,141,116)"/><circle cx="136" cy="91" r="5" fill="#3a3a78" stroke="#2a2a58" stroke-width=".8"/><rect x="127" y="76" width="7" height="18" rx="2" fill="#2a2a3a" stroke="#1a1a2a" stroke-width=".6" transform="rotate(15,136,91)"/><circle cx="124" cy="78" r="3.5" fill="#3a3a78" stroke="#2a2a58" stroke-width=".7"/><rect x="119" y="73" width="3" height="8" rx="1" fill="#2a2a3a" stroke="#1a1a2a" stroke-width=".5" transform="rotate(-15,121,77)"/><rect x="124" y="73" width="3" height="8" rx="1" fill="#2a2a3a" stroke="#1a1a2a" stroke-width=".5" transform="rotate(15,126,77)"/><polygon points="168,130 258,130 258,148 168,148" fill="#4a4a5a" stroke="#3a3a4a" stroke-width=".6"/><polygon points="155,122 168,130 258,130 245,122" fill="#5a5a6a" stroke="#3a3a4a" stroke-width=".6"/><g stroke="#6a6a7a" stroke-width=".5" opacity=".8"><line x1="180" y1="130" x2="180" y2="148"/><line x1="193" y1="130" x2="193" y2="148"/><line x1="206" y1="130" x2="206" y2="148"/><line x1="219" y1="130" x2="219" y2="148"/><line x1="232" y1="130" x2="232" y2="148"/><line x1="245" y1="130" x2="245" y2="148"/></g><g><polygon points="195,118 210,118 210,127 195,127" fill="#c4a882" stroke="#a08860" stroke-width=".5"/><polygon points="195,118 199,115 214,115 210,118" fill="#d4b892" stroke="#a08860" stroke-width=".5"/><polygon points="210,118 214,115 214,127 210,127" fill="#b09870" stroke="#a08860" stroke-width=".5"/></g><rect x="253" y="80" width="5" height="55" rx="1" fill="#2a2a3a" stroke="#1a1a2a" stroke-width=".5"/><rect x="254" y="85" width="3" height="40" rx=".5" fill="#3a3a78" opacity=".7"/><circle cx="255.5" cy="90" r="1.2" fill="#f9f9f9" opacity=".8"/><circle cx="255.5" cy="100" r="1.2" fill="#f9f9f9" opacity=".8"/><circle cx="255.5" cy="110" r="1.2" fill="#f9f9f9" opacity=".8"/><circle cx="255.5" cy="120" r="1.2" fill="#f9f9f9" opacity=".8"/><g stroke="#3a3a78" stroke-width=".4" opacity=".3" stroke-dasharray="2,3"><line x1="254" y1="90" x2="168" y2="110"/><line x1="254" y1="100" x2="168" y2="120"/><line x1="254" y1="110" x2="168" y2="130"/></g></svg></div><dl class=pane-spec><dt>environment</dt><dd>Fenced robot cell, ~9 m², fixed lighting.</dd><dt>action space</dt><dd>Arm motion, grip force, scan, label, place on conveyor.</dd><dt>sensors</dt><dd>Wrist camera, overhead camera, barcode scanner, weight pad, joint torques.</dd><dt>primary metric</dt><dd>Correctly packed orders per hour.</dd><dt>secondaries</dt><dd>Mis-pick rate, damage rate, energy per pick.</dd><dt>guardrails</dt><dd>Safety fence + light curtain, e-stop, force-limited arm, max-velocity cap.</dd></dl></div><div class="pane pane-5"><div class=pane-header><div class=pane-icon><svg viewBox="0 0 32 32" fill="none" stroke="currentcolor" stroke-width="1.5"><line x1="6" y1="6" x2="26" y2="26"/><line x1="6" y1="26" x2="26" y2="6"/><circle cx="6" cy="6" r="3"/><circle cx="26" cy="6" r="3"/><circle cx="6" cy="26" r="3"/><circle cx="26" cy="26" r="3"/><rect x="12" y="12" width="8" height="8" rx="1" fill="currentcolor"/></svg></div><h4 class=pane-title>Outdoor sprayer drone</h4></div><p class=pane-blurb>A tank-equipped drone with a multispectral camera, working a real field. The hardest adversarial-robustness story of the bunch.</p><div class=pane-viz><svg viewBox="0 0 280 160" aria-label="Isometric field with sprayer drone and geofence boundary"><polygon points="12,148 268,148 243,50 37,50" fill="none" stroke="#8b1a1a" stroke-width="1" stroke-dasharray="4,3"/><polygon points="22,142 258,142 235,62 45,62" fill="#ebe4d0" stroke="#bbb5a0" stroke-width=".6"/><g fill="#7a9a5c" stroke="none" opacity=".85"><polygon points="45,62 91,62 85,82 39,82"/></g><g fill="#5a7a44" stroke="none" opacity=".85"><polygon points="91,62 137,62 131,82 85,82"/></g><g fill="#7a9a5c" stroke="none" opacity=".85"><polygon points="137,62 183,62 177,82 131,82"/></g><g fill="#5a7a44" stroke="none" opacity=".85"><polygon points="183,62 229,62 223,82 177,82"/></g><g fill="#5a7a44" stroke="none" opacity=".75"><polygon points="39,82 85,82 79,102 33,102"/></g><g fill="#7a9a5c" stroke="none" opacity=".75"><polygon points="85,82 131,82 125,102 79,102"/></g><g fill="#5a7a44" stroke="none" opacity=".75"><polygon points="131,82 177,82 171,102 125,102"/></g><g fill="#7a9a5c" stroke="none" opacity=".75"><polygon points="177,82 223,82 217,102 171,102"/></g><g fill="#7a9a5c" stroke="none" opacity=".65"><polygon points="33,102 79,102 73,122 27,122"/></g><g fill="#5a7a44" stroke="none" opacity=".65"><polygon points="79,102 125,102 119,122 73,122"/></g><g fill="#7a9a5c" stroke="none" opacity=".65"><polygon points="125,102 171,102 165,122 119,122"/></g><g fill="#5a7a44" stroke="none" opacity=".65"><polygon points="171,102 217,102 211,122 165,122"/></g><g fill="#5a7a44" stroke="none" opacity=".55"><polygon points="27,122 73,122 67,142 21,142"/></g><g fill="#7a9a5c" stroke="none" opacity=".55"><polygon points="73,122 119,122 113,142 67,142"/></g><g fill="#5a7a44" stroke="none" opacity=".55"><polygon points="119,122 165,122 159,142 113,142"/></g><g fill="#7a9a5c" stroke="none" opacity=".55"><polygon points="165,122 211,122 205,142 159,142"/></g><polygon points="140,75 148,142 132,142" fill="#a8c4d8" opacity=".3"/><polygon points="140,75 162,140 118,140" fill="#a8c4d8" opacity=".12"/><g transform="translate(140,52)"><line x1="-22" y1="-9" x2="22" y2="9" stroke="#2a2a3a" stroke-width="1.6"/><line x1="-22" y1="9" x2="22" y2="-9" stroke="#2a2a3a" stroke-width="1.6"/><circle cx="-22" cy="-9" r="6" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1"/><circle cx="22" cy="-9" r="6" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1"/><circle cx="-22" cy="9" r="6" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1"/><circle cx="22" cy="9" r="6" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1"/><rect x="-8" y="-6" width="16" height="12" rx="2" fill="#2a2a3a"/><circle cx="0" cy="0" r="2" fill="#f9f9f9" opacity=".5"/><rect x="-2" y="6" width="4" height="5" rx="1" fill="#3a3a78" opacity=".8"/></g></svg></div><dl class=pane-spec><dt>environment</dt><dd>A bounded field plot, outdoor, with weather and bystanders.</dd><dt>action space</dt><dd>Flight path, spray nozzle on/off, dosage rate.</dd><dt>sensors</dt><dd>RGB + multispectral camera, GPS, IMU, tank-level sensor, wind sensor.</dd><dt>primary metric</dt><dd>Pest pressure reduction, normalised by chemical applied.</dd><dt>secondaries</dt><dd>Chemical drift, energy, flight time, area covered.</dd><dt>guardrails</dt><dd>Geofence + tether, no-fly buffer around bystanders, chemical-flow ceiling, weather lockout.</dd></dl></div><div class="pane pane-6"><div class=pane-header><div class=pane-icon><svg viewBox="0 0 32 32" fill="none" stroke="currentcolor" stroke-width="1.5" stroke-linecap="round"><rect x="3" y="7" width="26" height="18" rx="3"/><circle cx="12" cy="16" r="3"/><circle cx="12" cy="16" r="1" fill="currentcolor"/><line x1="18" y1="13" x2="25" y2="13"/><line x1="18" y1="16" x2="25" y2="16"/><line x1="18" y1="19" x2="25" y2="19"/></svg></div><h4 class=pane-title>Gel electrophoresis station</h4></div><p class=pane-blurb>An agarose gel tray, a power supply, and a UV camera. Set voltage and run time, then image the separated bands.</p><div class=pane-viz><svg viewBox="0 0 280 160" aria-label="Isometric gel electrophoresis station with gel tray and power supply"><polygon points="15,148 258,148 272,108 30,108" fill="#ebe4d0" stroke="#bbb5a0" stroke-width=".6"/><g stroke="#d2cab2" stroke-width=".35" fill="none" opacity=".5"><line x1="30" y1="108" x2="15" y2="148"/><line x1="90" y1="108" x2="75" y2="148"/><line x1="150" y1="108" x2="140" y2="148"/><line x1="210" y1="108" x2="205" y2="148"/><line x1="30" y1="108" x2="272" y2="108"/><line x1="22" y1="128" x2="265" y2="128"/></g><polygon points="38,52 188,52 206,82 56,82" fill="#3a4a5a" stroke="#2a3a4a" stroke-width=".7"/><polygon points="56,82 206,82 206,102 56,102" fill="#2a3a4a" stroke="#1a2a3a" stroke-width=".5"/><polygon points="38,52 56,82 56,102 38,72" fill="#243444" stroke="#1a2a3a" stroke-width=".5"/><polygon points="46,57 185,57 200,79 61,79" fill="#dde8c0" stroke="#b8c890" stroke-width=".5" opacity=".96"/><polygon points="39,53 46,57 185,57 200,79 206,79 206,82 56,82 38,52" fill="#7ab4d8" opacity=".16"/><g stroke="#aeba98" stroke-width=".45" opacity=".65"><line x1="70" y1="57" x2="85" y2="79"/><line x1="97" y1="57" x2="112" y2="79"/><line x1="124" y1="57" x2="139" y2="79"/><line x1="151" y1="57" x2="166" y2="79"/><line x1="178" y1="57" x2="193" y2="79"/></g><g fill="#8a9278" opacity=".75"><rect x="48" y="56" width="4" height="2.5" rx=".5"/><rect x="74" y="56" width="4" height="2.5" rx=".5"/><rect x="100" y="56" width="4" height="2.5" rx=".5"/><rect x="127" y="56" width="4" height="2.5" rx=".5"/><rect x="154" y="56" width="4" height="2.5" rx=".5"/><rect x="180" y="56" width="4" height="2.5" rx=".5"/></g><polygon points="49,61 68,61 69,63 50,63" fill="#1a2a1a" opacity=".72"/><polygon points="50,66 69,66 70,68 51,68" fill="#1a2a1a" opacity=".65"/><polygon points="51,71 70,71 71,73 52,73" fill="#1a2a1a" opacity=".58"/><polygon points="52,75 71,75 72,77 53,77" fill="#1a2a1a" opacity=".5"/><polygon points="101,64 123,64 124,66 102,66" fill="#1a2a1a" opacity=".88"/><polygon points="103,74 125,74 126,76 104,76" fill="#1a2a1a" opacity=".8"/><polygon points="128,67 150,67 151,69 129,69" fill="#1a2a1a" opacity=".92"/><polygon points="155,65 175,65 176,67 156,67" fill="#1a2a1a" opacity=".45"/><polygon points="157,73 177,73 178,75 158,75" fill="#1a2a1a" opacity=".4"/><polygon points="218,73 250,73 256,88 224,88" fill="#2a2a3a" stroke="#1a1a28" stroke-width=".6"/><polygon points="224,88 256,88 256,108 224,108" fill="#1a1a28" stroke="#111" stroke-width=".5"/><polygon points="218,73 224,88 224,108 218,93" fill="#222232" stroke="#111" stroke-width=".5"/><rect x="226" y="76" width="24" height="9" rx="1" fill="#0d1a2a" stroke="#4a6aaa" stroke-width=".4"/><text x="229" y="83" font-size="6.5" fill="#4da" font-family="monospace">80V 22m</text><path d="M218 78q-11-2-12 5" stroke="#c33" stroke-width="1.2" fill="none" stroke-linecap="round"/><path d="M218 85q-10 1-12 4" stroke="#1a1a1a" stroke-width="1.2" fill="none" stroke-linecap="round"/><circle cx="206" cy="83" r="2.2" fill="#c33" stroke="#911" stroke-width=".4"/><circle cx="56" cy="84" r="2.2" fill="#1a1a1a" stroke="#333" stroke-width=".4"/></svg></div><dl class=pane-spec><dt>environment</dt><dd>Benchtop — gel box with buffer, power supply, UV transilluminator.</dd><dt>action space</dt><dd>Set voltage (10–150 V), run time, and sample loading volumes per lane.</dd><dt>sensors</dt><dd>UV camera, voltmeter, timer, buffer-level sensor.</dd><dt>primary metric</dt><dd>Target-band separation score at imaging time.</dd><dt>secondaries</dt><dd>Run time, buffer consumption, gel waste.</dd><dt>guardrails</dt><dd>Voltage ceiling (150 V), run-time cap, UV shield interlock, buffer-low cutoff.</dd></dl></div></div></div>
<h2 id="anatomy-of-a-physical-eval">Anatomy of a physical eval</h2>
<p>The diagram below sketches one possible
anatomy for a physica eval (this might not be complete, but take it as a useful starting point).</p>
<figure class=fullwidth><div class=parts-fig><svg viewBox="0 0 780 420" aria-label="Exploded diagram of the components of a physical eval"><polygon points="190,300 530,300 480,210 240,210" fill="#ebe4d0" stroke="#bbb5a0" stroke-width=".6"/><g stroke="#d2cab2" stroke-width=".4" fill="none" opacity=".7"><line x1="275" y1="220" x2="225" y2="290"/><line x1="320" y1="220" x2="285" y2="290"/><line x1="365" y1="220" x2="345" y2="290"/><line x1="410" y1="220" x2="405" y2="290"/><line x1="255" y1="225" x2="465" y2="225"/><line x1="245" y1="250" x2="475" y2="250"/><line x1="225" y1="280" x2="490" y2="280"/></g><polygon class="parts-geofence" points="178,308 542,308 488,200 232,200" fill="none" stroke="#8b1a1a" stroke-width="1" stroke-dasharray="4,3"/><g><ellipse cx="290" cy="232" rx="18" ry="11" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".7"/><rect x="287" y="240" width="6" height="8" fill="#6b4a2a"/></g><g><ellipse cx="380" cy="232" rx="18" ry="11" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".7"/><rect x="377" y="240" width="6" height="8" fill="#6b4a2a"/></g><g><ellipse cx="275" cy="278" rx="24" ry="14" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".7"/><rect x="272" y="287" width="6" height="10" fill="#6b4a2a"/></g><g><ellipse cx="395" cy="278" rx="24" ry="14" fill="#7a9a5c" stroke="#5a7a44" stroke-width=".7"/><rect x="392" y="287" width="6" height="10" fill="#6b4a2a"/></g><g><line x1="210" y1="295" x2="210" y2="215" stroke="#2a2a3a" stroke-width="1.4"/><rect x="202" y="208" width="16" height="10" rx="2" fill="#2a2a3a"/><circle cx="210" cy="213" r="1.5" fill="#f9f9f9"/></g><g><line x1="510" y1="295" x2="510" y2="215" stroke="#2a2a3a" stroke-width="1.4"/><rect x="502" y="208" width="16" height="10" rx="2" fill="#2a2a3a"/><circle cx="510" cy="213" r="1.5" fill="#f9f9f9"/></g><ellipse cx="360" cy="265" rx="22" ry="5" fill="#000" opacity=".06"/><g transform="translate(360, 165)"><line x1="-22" y1="-9" x2="22" y2="9" stroke="#2a2a3a" stroke-width="1.8"/><line x1="-22" y1="9" x2="22" y2="-9" stroke="#2a2a3a" stroke-width="1.8"/><circle cx="-22" cy="-9" r="6" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1"/><circle cx="22" cy="-9" r="6" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1"/><circle cx="-22" cy="9" r="6" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1"/><circle cx="22" cy="9" r="6" fill="#f9f9f9" stroke="#3a3a78" stroke-width="1"/><rect x="-8" y="-6" width="16" height="12" rx="2" fill="#2a2a3a"/></g><g transform="translate(470, 130)"><rect x="0" y="0" width="92" height="44" rx="3" fill="#f9f9f9" stroke="#3a3a78" stroke-width=".7"/><text x="8" y="16" font-family="Inter, sans-serif" font-size="8" letter-spacing=".08em" fill="#888">FRUIT SAVED</text><text x="8" y="36" font-family="Inter, sans-serif" font-size="18" font-weight="600" fill="#3a3a78">94%</text><text x="78" y="36" font-family="Inter, sans-serif" font-size="9" fill="#5a9a5a" text-anchor="end">↑ 3</text></g><g><path d="M650 320Q540 280 380 175" fill="none" stroke="#3a3a78" stroke-width="1" stroke-dasharray="3,3" marker-end="url(#arrowhead)"/><circle cx="650" cy="320" r="3" fill="#3a3a78"/></g><defs><marker id="arrowhead" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="6" markerHeight="6" orient="auto"><path d="M0 0 10 5 0 10z" fill="#3a3a78"/></marker></defs><g transform="translate(445, 213)"><rect x="0" y="4" width="20" height="26" rx="1" fill="#f9f9f9" stroke="#3a3a78" stroke-width=".8"/><rect x="6" y="0" width="8" height="8" rx="1" fill="#3a3a78"/><line x1="3" y1="14" x2="17" y2="14" stroke="#3a3a78" stroke-width=".6" opacity=".5"/><line x1="3" y1="18" x2="17" y2="18" stroke="#3a3a78" stroke-width=".6" opacity=".5"/><line x1="3" y1="22" x2="13" y2="22" stroke="#3a3a78" stroke-width=".6" opacity=".5"/></g><line x1="110" y1="90" x2="240" y2="210" stroke="#888" stroke-width=".6" stroke-dasharray="2,3"/><g class="cb"><circle cx="110" cy="90" r="11" fill="#2a2a3a"/><text x="110" y="94" text-anchor="middle" font-family="Inter, sans-serif" font-size="11" font-weight="600" fill="#f9f9f9">1</text></g><text x="128" y="86" font-family="Inter, sans-serif" font-size="10.5" font-weight="600" letter-spacing=".08em" fill="#3a3a78">ENVIRONMENT</text><text x="128" y="100" font-family="Inter, sans-serif" font-size="9.5" fill="#888">the orchard</text><line x1="110" y1="220" x2="210" y2="216" stroke="#888" stroke-width=".6" stroke-dasharray="2,3"/><g class="cb"><circle cx="110" cy="220" r="11" fill="#2a2a3a"/><text x="110" y="224" text-anchor="middle" font-family="Inter, sans-serif" font-size="11" font-weight="600" fill="#f9f9f9">2</text></g><text x="50" y="246" font-family="Inter, sans-serif" font-size="10.5" font-weight="600" letter-spacing=".08em" fill="#3a3a78">SENSORS</text><text x="50" y="260" font-family="Inter, sans-serif" font-size="9.5" fill="#888">perimeter cameras</text><line x1="360" y1="100" x2="360" y2="153" stroke="#888" stroke-width=".6" stroke-dasharray="2,3"/><g class="cb"><circle cx="360" cy="90" r="11" fill="#2a2a3a"/><text x="360" y="94" text-anchor="middle" font-family="Inter, sans-serif" font-size="11" font-weight="600" fill="#f9f9f9">3</text></g><text x="378" y="86" font-family="Inter, sans-serif" font-size="10.5" font-weight="600" letter-spacing=".08em" fill="#3a3a78">ACTION SPACE</text><text x="378" y="100" font-family="Inter, sans-serif" font-size="9.5" fill="#888">drone, deterrents</text><line x1="600" y1="152" x2="565" y2="152" stroke="#888" stroke-width=".6" stroke-dasharray="2,3"/><g class="cb"><circle cx="615" cy="152" r="11" fill="#2a2a3a"/><text x="615" y="156" text-anchor="middle" font-family="Inter, sans-serif" font-size="11" font-weight="600" fill="#f9f9f9">4</text></g><text x="633" y="148" font-family="Inter, sans-serif" font-size="10.5" font-weight="600" letter-spacing=".08em" fill="#3a3a78">METRIC</text><text x="633" y="162" font-family="Inter, sans-serif" font-size="9.5" fill="#888">+ secondaries</text><line x1="280" y1="370" x2="285" y2="312" stroke="#888" stroke-width=".6" stroke-dasharray="2,3"/><g class="cb"><circle cx="280" cy="380" r="11" fill="#2a2a3a"/><text x="280" y="384" text-anchor="middle" font-family="Inter, sans-serif" font-size="11" font-weight="600" fill="#f9f9f9">5</text></g><text x="298" y="376" font-family="Inter, sans-serif" font-size="10.5" font-weight="600" letter-spacing=".08em" fill="#3a3a78">GUARDRAILS</text><text x="298" y="390" font-family="Inter, sans-serif" font-size="9.5" fill="#888">geofence, no-fly buffers</text><line x1="615" y1="370" x2="650" y2="330" stroke="#888" stroke-width=".6" stroke-dasharray="2,3"/><g class="cb"><circle cx="615" cy="380" r="11" fill="#2a2a3a"/><text x="615" y="384" text-anchor="middle" font-family="Inter, sans-serif" font-size="11" font-weight="600" fill="#f9f9f9">6</text></g><text x="633" y="376" font-family="Inter, sans-serif" font-size="10.5" font-weight="600" letter-spacing=".08em" fill="#3a3a78">OPEN ACCESS</text><text x="633" y="390" font-family="Inter, sans-serif" font-size="9.5" fill="#888">remote operator input</text><line x1="615" y1="265" x2="466" y2="228" stroke="#888" stroke-width=".6" stroke-dasharray="2,3"/><g class="cb"><circle cx="615" cy="265" r="11" fill="#2a2a3a"/><text x="615" y="269" text-anchor="middle" font-family="Inter, sans-serif" font-size="11" font-weight="600" fill="#f9f9f9">7</text></g><text x="633" y="261" font-family="Inter, sans-serif" font-size="10.5" font-weight="600" letter-spacing=".08em" fill="#3a3a78">GOVERNANCE</text><text x="633" y="275" font-family="Inter, sans-serif" font-size="9.5" fill="#888">who sets the rules</text></svg></div><figcaption>Components of a physical eval.</figcaption></figure>
<ul>
<li><strong>An environment.</strong> The orchard, the bench, the cell line, the floor.</li>
<li><strong>An action space the eval can verify.</strong> What a participant is
allowed to do — fly the drone, dispense the reagent, move the parts —
needs to be observable enough that the system can confirm what
happened.</li>
<li><strong>Sensors.</strong> What the eval uses to know the state of the world.
Cameras, scales, thermocouples, microbiology assays, a human spot-check.</li>
<li><strong>A primary metric of utility,</strong> plus secondary metrics (cost, time,
resource use, energy).</li>
<li><strong>Safeties and guardrails.</strong> A net to catch the drone, a kill switch,
a fenced area, an interlock. Whatever ensures that a participant
failing — or <em>trying</em> to break things — doesn’t damage the orchard
or hurt the birds. A physical eval is, by construction, a
public-facing physical system that gives partial control of real
hardware to whoever holds the current slot. Keeping it open without
becoming dangerous — and without sacrificing utility — is the
hardest layer of the stack (see
<em>Safety for physical evals</em>).</li>
<li><strong>Governance.</strong> The rules of the eval and who controls them. Who
decides the primary metric and when it can change? Who can introduce
external hardware or a remote-control override? Is slot time fixed
or auctioned? Who arbitrates disputes, and by what process? Good
governance is what distinguishes an eval that stays honest over years
from one that quietly drifts to serve whoever is running it at the
time.</li>
</ul>
<p>This list is not final. Different domains will surface
components not named here — calibration drift, biological containment,
human-in-the-loop sign-off, regulatory constraints — and the right
abstraction is going to settle as people actually build the things.</p>
<h3 id="challenges-for-physical-evals">Challenges for physical evals</h3>
<p>The following are some of the harder design problems that don’t have
clean answers yet — and that any serious physical eval effort will have
to confront.</p>
<p><em>Goodharting.</em> Any eval with a numeric target invites unintended ways to hit it — with the wrinkle that in a physical eval the unintended ways can cause real-world harm. An agent optimising fruit saved might drive the deterrent so aggressively that birds <em>and</em> orchard workers avoid the area: the metric goes up, the orchard becomes unusable.</p>
<p><em>Non-stationarity.</em> The physical world changes regardless. An orchard in week one is not the same orchard in week twelve —
season, weather, and pest population all shift. A wet-lab bench drifts
as reagent batches age. Field plots evolve. Comparing scores across time is therefore hard, sometimes impossible.</p>
<p><em>Sequential contamination.</em> Each participant leaves a trace for the
next. In a wetlab this is problematic — reagents consumed, cultures
disturbed, hardware worn — but the problem is general: stock depleted
in a warehouse cell, soil compacted on a field plot, bird behaviour
shifted by a heavy deterrence week. Sequential slots work for
environments with a natural or cheap reset; they don’t work for
environments where state accumulates.</p>
<p><em>Latency as a confound.</em> A participant operating remotely over the
internet sees the environment through a sensor stream and acts through a
command channel, both of which have variable latency. Two agents with
identical policies but different network conditions will produce
different results. This is especially visible in fast-moving
environments — a drone avoiding a collision, a robot arm catching a
falling object.</p>
<p><em>Observer effect.</em> The sensors required to score an eval change what is
being measured. A camera rig that watches a field plot for pest activity
may deter the pests on its own. A flow sensor on a reagent line changes
the thermal environment of the bench. In some domains the effect is
negligible; in others it will corrupt the primary metric.</p>
<h2 id="safety-for-physical-evals">Safety for physical evals</h2>
<p>A physical eval that anyone on the internet can operate is, by
construction, a public attack surface on a real-world physical system.
The participant at any given slot might be a well-behaved research
team, an AI agent following a poorly-aligned policy, or a person who
wants to break things on purpose. The eval has to keep working —
usefully, openly, safely — across all three.</p>
<p><em>Somebody not fully trusted is about to make
the drone, the sprayer, the autoclave do something for the next twenty
minutes — what’s the worst that can happen, and how is it bounded?</em></p>
<h3 id="the-attack-surface">The attack surface</h3>
<p>A useful first pass is to categorise harms by who pays the cost:</p>
<ul>
<li><strong>Harm to the eval itself.</strong> The drone crashes, the cell line dies,
the robot arm jams. Cheap if the guardrails work — the operator
resets, the leaderboard absorbs the failure.</li>
<li><strong>Harm to the surrounding environment.</strong> Chemicals spill, the
orchard catches fire, a neighbouring field gets sprayed.</li>
<li><strong>Harm to humans.</strong> A bystander gets hit by the drone, an operator
gets burned, a patient sample gets switched. ⊕</li>
</ul>
<input type=checkbox id=mn-1781015997702878231 class=margin-toggle>
<p>The
lines between these categories blur in practice — chemical drift is
“environment” until a bystander walks through it.
The category that matters most, and the hardest to bound.</p>
<ul>
<li><strong>Information harms.</strong> Footage of bystanders or proprietary processes
leaves the eval site; the eval is used as a covert surveillance
platform; sensor streams are exfiltrated.</li>
<li><strong>Generation of dangerous artifacts.</strong> The wet-lab cell is steered
toward synthesising something harmful; the sprayer drone is
weaponised; the autoclave is used to destroy evidence.</li>
</ul>
<p>Categories 1–3 are about <em>what can happen during a slot.</em> Categories
4–5 are about <em>what can leave the eval afterwards.</em> They want different
defences, and a serious eval needs both.</p>
<h3 id="defences-worth-building-ai-gen">Defences worth building (AI GEN)</h3>
<p>None of the following is a finished answer. They are the moves worth
physical evals trying, evaluating, and writing up:</p>
<ul>
<li><strong>Time-slotting with audit.</strong> Single operator at a time, every
action logged, the whole slot replayable. The slowest defence and
the foundation everything else builds on.</li>
<li><strong>Action-space sandboxing.</strong> The eval enforces hard limits <em>inside</em>
its abstraction: max chemical per slot, max motion envelope, max
temperature ramp. The action space exposed to the operator is
strictly smaller than the action space the hardware can physically
produce.</li>
<li><strong>Dry-run validation.</strong> A submitted policy runs through a cheap
simulation pass first — not as the eval itself, but as a gate.
Refuses to execute on the physical system if the simulated run trips
any guardrail.</li>
<li><strong>Supervised / shadow modes.</strong> ⊕</li>
</ul>
<input type=checkbox id=mn-1781015997702937398 class=margin-toggle>
<p>Like a learner’s
permit: new operators get to compute actions but not actuate them
for the first N slots.
New operators run in
shadow mode (actions computed but not executed) for some number of
slots before they’re trusted with real actuation. Progressive trust
as the leaderboard accumulates evidence.</p>
<ul>
<li><strong>Anomaly cut-outs.</strong> A separate monitor watches for off-distribution
sensor readings, sudden command spikes, too-clever-by-half action
sequences — and pulls the kill-switch before the eval owner has to.</li>
<li><strong>Open red-teaming.</strong> Each eval publishes its threat model and
invites external researchers to attack it. The right way to find the
holes is to invite people to look.</li>
<li><strong>Skin in the game.</strong> Operators bond a small amount per slot,
refundable on clean completion, forfeited if an audit finds
violation. Aligns incentives without requiring trust upfront.</li>
</ul>
<p>Most of these are borrowed from adjacent fields — public cloud
security, scientific-facility time-sharing (telescope nights, beamline
schedules), bug-bounty programs, robotics-safety standards. <em>None</em> of
them have been worked out in detail for a public, openly-instrumented
physical system that AI agents are also supposed to operate. That’s a
research agenda in itself.</p>
<h2 id="an-open-movement-for-physical-evals">An open movement for physical evals</h2>
<p>Physical evals could become an open-source ecosystem: environments cheap
to set up, easy to fork, open to anyone with a problem worth
measuring.</p>
<p>The rest of this section traces the arc: where things have been (<em>Prior art</em>),
what an open ecosystem looks like in practice (<em>Open at every layer</em>),
what it would have to cost (<em>What’s the Raspberry Pi of a physical
eval?</em>).</p>
<h3 id="prior-art">Prior art</h3>
<p>Physical-world AI competitions aren’t new. The <a href="https://en.wikipedia.org/wiki/DARPA_Grand_Challenge" target="_blank" rel="noopener noreferrer">DARPA Grand Challenge</a> put
autonomous vehicles in the Mojave; the
<a href="https://en.wikipedia.org/wiki/DARPA_Robotics_Challenge" target="_blank" rel="noopener noreferrer">DARPA Robotics Challenge</a>
put humanoids through disaster-response courses; the
<a href="https://robohub.org/amazon-picking-challenge/" target="_blank" rel="noopener noreferrer">Amazon Picking Challenge</a>
ran in warehouse mock-ups for several years;</p>
<input type=checkbox id=sn-1781015997702973568 class=margin-toggle>
<p><a href="https://www.robocup.org/" target="_blank" rel="noopener noreferrer">RoboCup</a> has been running its soccer
leagues since 1997 — arguably the longest-lived physical eval in
continuous operation, and the one with the most literature on what
makes it work and what it ends up measuring.
RoboCup
has been doing its soccer leagues since the late 1990s; the <a href="https://www.indyautonomouschallenge.com/" target="_blank" rel="noopener noreferrer">Indy Autonomous Challenge</a> and
<a href="https://en.wikipedia.org/wiki/Roborace" target="_blank" rel="noopener noreferrer">Roborace</a> have put driverless
cars on real circuits.</p>
<p>What these have in common: each was (or is) a sponsor-led, time-limited
event with closed protocols and bespoke infrastructure. They produced
brilliant moments and a small library of papers; they were expensive to
build and harder to reproduce.</p>
<h3 id="whats-the-raspberry-pi-of-a-physical-eval">What’s the Raspberry Pi of a physical eval?</h3>
<p>The hard constraint on all of this is cost. A DARPA-class eval needs
millions of dollars and a multi-year program; even a modest
research-grade one runs into expensive sensors,
networking, fail-safe hardware, and the human labour to keep it
operating. That ceiling is what makes physical evals rare today — and
rare evals can’t be the basis of an ecosystem.</p>
<p>So one of the most important questions this community can keep returning
to is the one in the heading.⊕</p>
<input type=checkbox id=mn-1781015997703016073 class=margin-toggle>
<p>Stand-in for “the
cheapest plausible build”. The Raspberry Pi did this for hobbyist
computing; what’s the equivalent for physical evals?
What’s the bill of materials that brings a credible, instrumented,
openable physical eval down to the cost of a serious hobby project? Probably some mix of commodity sensors, a
single-board computer for the control loop, an open scheduling service
for time-share, off-the-shelf safety hardware, and a reference
orchestration stack that everyone forks. If the answer ends up being
<em>“a few hundred dollars and a weekend,”</em> the ecosystem can actually
form. If it stays at <em>“a few hundred thousand and a six-month build,”</em>
it stays a fantasy.</p>
<h3 id="open-at-every-layer">Open at every layer</h3>
<p>In order to further lower the cost for anyone to be able to set up (safely) their physical evals, we need to look at off-the-shelf hardware and an open source stack.</p>
<ul>
<li><strong>Open protocols.</strong> The spec of an eval (environment, action space,
sensors, metric, secondaries, guardrails) is published as a forkable
document, the same way a research benchmark is published.</li>
<li><strong>Open hardware.</strong> Sensor rigs, mechanical setups, fail-safe systems
default to off-the-shelf components, with reproducible bills of
materials and CAD files.</li>
<li><strong>Open software.</strong> Time-share scheduling, telemetry capture, scoring,
auditing — shared infrastructure, not a one-off codebase per eval.</li>
<li><strong>A community around it.</strong> People running, replicating, and forking
each other’s evals; people contributing sensor stacks and guardrail
designs; people maintaining the scoring code together. No single lab
can stand up enough physical evals to cover the interesting surface
of physical problems — a community can.</li>
</ul>
<h3 id="public-verifiability">Public verifiability</h3>
<p>The safety section above focuses on protecting the physical environment
from adversarial <em>participants</em>. There is a symmetric problem that gets
less attention: protecting participants — and the public — from
adversarial <em>eval runners</em>.</p>
<p>In an open world where anyone can wire a field, a lab bench, or a
warehouse cell to the internet and declare it a physical eval, the
operator controls the sensors, the scoring pipeline, and in a way, the ground
truth. A dishonest operator can inflate results for a preferred team,
suppress evidence of harm, or fabricate the physical record entirely.
If physical evals are going to carry weight — as procurement signals,
safety certifications, or policy inputs — the data they produce has to
be trustworthy independent of whether the runner is trustworthy.</p>
<p>This is a valuable research
direction in its own right. Some threads worth pulling:</p>
<ul>
<li><strong>Tamper-evident sensors.</strong> Hardware-attested video streams that can
be verified as unedited after the fact — the physical analogue of a
signed log.</li>
<li><strong>Trusted execution environments.</strong> Running the scoring pipeline
inside a TEE means the operator cannot modify results without
breaking the attestation, even if they control the host machine.</li>
<li><strong>Cross-checking sensor redundancy.</strong> Multiple independent sensor
modalities covering the same physical event make coordinated
fabrication harder: a weight sensor, a camera, and an RFID log all
have to agree.</li>
<li><strong>Third-party witnesses.</strong> Spot audits by an independent party —
human or automated — who can access raw sensor streams without going
through the operator’s pipeline.</li>
</ul>
<p>Combinations are likely to be
necessary, and the right combination will vary by domain. What a
wet-lab needs to prove that a synthesis actually ran differs from what
an orchard needs to prove that a drone actually flew a slot. Building
this layer — call it <em>physical eval verification</em> — is at least as
important as building the evals themselves to make the results publicly verifiable.</p>
<h3 id="a-darwinian-ecosystem">A Darwinian ecosystem</h3>
<p>Not every physical eval will be a good one. Some will be hard, some trivial.
Some will be well-structured; some will be a mess. Some will scale to many
participants; some will only ever host one team at a time. That’s fine — even
desirable.
The shape of “what makes a good physical eval” is going to emerge from people
building them, breaking them, and learning what each one actually measured.</p>
<p>Sketched, a public registry for such an ecosystem might look like this:</p>
<div class=physevals-board><div class=bbar><div class=dots><span></span><span></span><span></span></div><div class=url>physevals.io · open registry · 126 evals</div></div><div class=page><div class=page-head><div class=page-title>Physical eval registry</div><div class=page-sub>43 accepting slots</div></div><div class=eval-rows><div class=er-row><div class=er-icon style=background:#5a7a44>O</div><div class=er-name><div class=er-title>Orchard pest defence</div><div class=er-sub>agriculture · outdoor · Greenfields UK</div></div><div class="er-status open">● open</div><div class=er-metric>fruit saved / week</div><div class=er-teams>18 teams</div></div><div class=er-row><div class=er-icon style=background:#4a6ea5>W</div><div class=er-name><div class=er-title>pH adjustment bench</div><div class=er-sub>chemistry · indoor · benchtop</div></div><div class="er-status open">● open</div><div class=er-metric>ΔpH from target</div><div class=er-teams>11 teams</div></div><div class=er-row><div class=er-icon style=background:#0e7c6e>V</div><div class=er-name><div class=er-title>Indoor vertical farm</div><div class=er-sub>agriculture · controlled environment</div></div><div class="er-status limited">◑ 2 slots left</div><div class=er-metric>g / kWh / cycle</div><div class=er-teams>6 teams</div></div><div class=er-row><div class=er-icon style=background:#6a5a95>P</div><div class=er-name><div class=er-title>Pick-and-pack cell</div><div class=er-sub>logistics · warehouse robotics</div></div><div class="er-status open">● open</div><div class=er-metric>correct orders / hour</div><div class=er-teams>23 teams</div></div><div class=er-row><div class=er-icon style=background:#8a5a5a>S</div><div class=er-name><div class=er-title>Outdoor sprayer drone</div><div class=er-sub>agri-robotics · field · safety-vetted access</div></div><div class="er-status soon">○ coming soon</div><div class=er-metric>pest Δ / ml sprayed</div><div class=er-teams>—</div></div><div class=er-row><div class=er-icon style=background:#7a7a8a>+</div><div class=er-name><div class=er-title>Submit an eval</div><div class=er-sub>open spec · CC-BY · any domain</div></div><div class="er-status soon"></div><div class=er-metric></div><div class=er-teams>→</div></div></div><div class=page-foot><span>updated 26 May · specs CC-BY</span>
<span>physevals.io is imagined</span></div></div></div>
<h3 id="more-than-evals">More than evals</h3>
<p>Every execution of a physical eval produces something beyond a score: a
timestamped record of sensor readings, actions taken, and outcomes
observed, all under conditions that were defined in advance and held
constant across participants. That record has value on its own.</p>
<p>The most immediate use is data collection. A team that runs an agent on
the orchard eval for a week doesn’t just get a leaderboard position —
they accumulate labelled trajectories in a real environment that would
be expensive to stage deliberately. Even failed attempts are informative:
a drone that misses a bird on Tuesday has documentation of exactly what
the environment looked like and what the agent did.</p>
<p>For some categories of problem the step further is worth considering:
repurposing the eval environment as a training environment. The orchard
is already instrumented. The slot system already handles scheduling. If
the cost of running episodes is low enough — bird-deterrence is
essentially free to attempt, wet-lab synthesis is not — the same
infrastructure can run RL rollouts between evaluation windows. The
environment that scores a model on Monday can help train the next
version by Friday.</p>
<p>This doesn’t collapse the distinction between training and testing.
Eval integrity still requires held-out conditions, independent scoring,
and participants who didn’t design the environment. But the <em>hardware</em>
doesn’t have to be idle between eval slots, and the <em>data</em> generated
during evaluation doesn’t have to be discarded. For operators willing
to share trajectories under open licences, a physical eval site becomes
something closer to a living dataset — one that grows richer every time
a new agent takes a slot.</p>
<h2 id="physical-evals-as-a-market">Physical evals as a market</h2>
<p>Why should one set up a physical eval? Setting up a physical eval can be a way to crowdsource intelligence for an unsolved problem.</p>
<p>The eval ecosystem can act as a <em>market</em> for intelligence: any participant — human, agent, team, company, hobbyist —
can take a slot, attempt to saturate the metric, and submit. The
leaderboard answers the AI-selection question by revealing whose approach
actually delivers on the physical world.</p>
<p>Physical evals can be a way for problem-owners to
<em>delegate AI knowledge</em> to a market.⊕</p>
<input type=checkbox id=mn-1781015997703058758 class=margin-toggle>
<p>This is the same
shift that happened with bug bounties. A company didn’t have to
<em>predict</em> who the best vulnerability researchers were; they had to
publish the surface and the rules, and the market sorted itself
out.
The grower doesn’t pick a model.
The hospital doesn’t pick a model. The factory doesn’t pick a model. They
pick a problem worth instrumenting and let the world’s AI builders compete
to be the answer. As more domains follow suit, an aggregate picture
emerges of where AI is actually good.</p>
<h2 id="get-in-touch">Get in touch</h2>
<p>If any of this resonates, please write. Three good reasons:</p>
<ul>
<li><strong>Already working in this space.</strong> Compare notes — what’s been learned
about sensing, guardrails, or keeping a system honestly open will
save the next person a lot of time.</li>
<li><strong>Have a physical problem worth instrumenting as an eval.</strong>
Worth thinking through together — what to measure, how to keep
it safe to open up, how to make it interesting enough that people show
up to compete.</li>
<li><strong>Have an eval to propose.</strong> Even if hosting isn’t feasible right now,
good proposals are valuable — they’re what an ecosystem of physical evals
is made of.</li>
</ul>
<p>DM <a href="https://twitter.com/iamnotnicola" target="_blank" rel="noopener noreferrer">@iamnotnicola</a> on X.</p>
<p>Let’s turn more of the physical world into something AI can be measured
against — and use that to point AI at problems that actually matter.</p>
<h2 id="acknowledgements">Acknowledgements</h2>
<p>This was written by Nicola Greco with support of AI. It was brainstormed as part of ARIA’s
<a href="https://aria.org.uk/opportunity-spaces/trust-everything-everywhere/scaling-trust/" target="_blank" rel="noopener noreferrer">Scaling Trust</a>
programme, in collaboration with Alex Obadia. Thanks to Ross Taylor (General Reasoning), whose thinking influenced some of our ideas on physical evals.</p>
]]></content:encoded></item></channel></rss>