Working agenda · specialist reading

The Common Home as an Operating System

One of the possible models of the future. Not a blueprint to be installed, but a specimen of how the architecture of our common home can be taken apart and tested.

A specialist analysis · seams and cracks included

What this document is

This is a working agenda: an analysis of the questions a people works on and opens up for research, design, and testing. The document is dense and specialised - in the same register as the Theoretical-Mathematical Framework and the Legal Justification, not something to skim; its value lies not in a finished answer but in showing, to the end, the very kind of work involved.

It deliberately leaves both the strong moves and the cracks in plain view. The cracks are not a defect - they are the content: a map of what still has to be thought through. Any part of it can be contested, rewritten, forked.

Where it comes from, and what it invites. This analysis grew out of the work on Earthlings - a voluntary, cross-border people. But the model stands on its own as pure reasoning, and Earthlings is not its author or its owner but its environment: a place where models like this can be built in the small, set against one another, and tested for strength. We consider these questions important for everyone - the common home concerns each of us; and so we are ready to discuss, research, design, and test them from the first days and in the open, together with all who wish to take part.

Part 0

How to read this document

The starting point is a radical but productive metaphor: the present world order - with all its political, economic, and legal fabric - is a working but ageing operating system. Call it, by convention, "Windows 11." It is not meaningless: it boots, billions of processes run on it, it has survived many releases. But its bugs are already known - not hypothetical ones, but those that surface over decades and cost human lives.

The question of this document: given a full team of developers and a clean slate, what would the next release - "Windows 12" - look like? Not a perfect one (there is no such thing), but the most correct and complete one attainable in the present situation.

The OS metaphor is meant seriously, not for decoration. An operating system has a genuine engineering anatomy: a kernel and rings of privilege, a permissions model, process isolation, a resource scheduler, an update mechanism, error handling, authentication. Each of these axes maps onto the architecture of a society with surprising precision - and where the mapping breaks, it breaks instructively. In the end (Part IX) we also examine the central flaw of the metaphor itself: an OS has an owner, and humanity must have none. The language of operating systems was chosen precisely for that accuracy - it is the closest and clearest way to explain a structure of this kind. And "Windows 12" is an analytical lens, not a slogan: in the model itself the state does not disappear but becomes a thin layer (Part III), so this is the redesign of the whole stack as an object of study, complementary to states, not a call to abolish them.

The specialised technical terms (kernel, user space, capability, zero-knowledge, sandbox, nullifier, and the like) are deliberately left unglossed: a note on each would bloat the text, and their meaning is easy to look up. What matters here is not the precise IT definition but the role a term plays in the structure.

The document is arranged as follows: first a diagnosis of the old system (I), then an account of what must survive from it (II), then the architecture of the new one (III) and the place of the human within it (IV). After that come the three most loaded modules, opened up one by one (V-VII), their mutual conflicts (VIII), the architect's trap (IX), stress tests to breaking point (X), a reckoning with real, living attempts (XI), and, finally, the open horizon of work (XII).

Part I

Diagnosis: the bugs of "Windows 11"

I.1

The state is not one thing but a bundle of functions

The chief error in any conversation about the future of world order is to treat the state as a monolith that either exists or does not. The state is not an entity but a bundle of functions that ended up in one set of hands for reasons of war, taxation, and industry:

  1. A monopoly on legitimate force - who has the right to coerce.
  2. Jurisdiction over territory - power over a piece of physical space.
  3. The provision of common goods - roads, networks, defence, courts, infrastructure.
  4. Belonging and identity - who counts as "one of us," whom a person is assigned to.
  5. Redistribution - care for the weak, insurance against misfortune.
  6. Law and dispute resolution - rules and arbitration.
  7. External representation - a voice outward, on the international stage.

No law of nature requires these seven functions to sit in one box. They were fused together by history. And today they are coming apart before our eyes: identity leaks into networks, money into protocols, disputes into private arbitration, common goods into transnational structures. Understanding the state as a detachable bundle rather than an atom is the foundation of everything that follows.

I.2

The bug list

A monolithic kernel

All seven functions are crammed into privileged mode at once and into one set of hands. A single failure brings everything down. And identity is nailed to the "hardware" - to the geography of birth.

Root capture

Those in power can rewrite the very rules meant to constrain them. Regulatory and constitutional capture is a privileged process editing its own kernel, on the fly, in its own favour.

Rights by the lottery of birth

A person's permissions are set not by principle but by the machine they happened to boot on. Morally this is indistinguishable from an estate system; the estate is merely called "citizenship."

A dreadful updater

Rules can be changed systemically mostly by war, revolution, or glacial legislation. There is no safe, reversible patch.

No process isolation

A failure is not sandboxed. The 2008 crisis, a pandemic, a local conflict - the fault cascades across the whole system.

Leaks into shared memory

Processes write into shared memory - the atmosphere, the ocean, the climate - with no accounting. Costs are dumped into the commons, and anyone pays for them except their author.

A scheduler tuned for zero-sum

By default the system runs competition-for-displacement, not cooperation. One party's gain often literally means another's loss.

Expensive trust

A vast share of effort goes not into creation but into verification: intermediaries, guarantors, bureaucracy, courts, contract enforcement.

No single one of these bugs is fatal on its own. Together they form a system that works, yet systematically produces unfreedom, insecurity, distrust, and war as by-products of its own architecture, not as random glitches.

Part II

What must survive from the old system

Before designing anything new, one must honestly determine what cannot be thrown out. The romantic version of the future - states simply dissolving into voluntary communities - breaks against several hard facts.

Physical space is rivalrous

A river, a power grid, a port, a hectare of land cannot be "forked," and one cannot be in two jurisdictions at once. As long as people have bodies and occupy space, someone governs that space and settles the conflicts over it. This is the irremovable core of territorial power: matter breeds competition for exclusive use.

Physical security - the extreme case, where exit is impossible

A pandemic, an invasion, a natural disaster. Here one needs a structure that cannot simply be left with a click, because it must hold in the common cost those who would rather flee it. Freedom of exit is magnificent against tyranny and lethal against a pandemic: the virus does not care which voluntary community a person belongs to.

Care for those who cannot contribute

This is the strongest argument for something state-like, and the one least often said aloud. Voluntary communities are by nature good at caring for the useful and poor at caring for the useless: the sick, the old, the broken, the "unprofitable." History was coerced into solidarity precisely through a non-exitable structure - the one the healthy and wealthy cannot emigrate out of to escape their obligations to the weak. Remove the coercion to solidarity, and you get the sorting of people by usefulness. That is not freedom. It is Darwinism with a good interface.

Load-bearing principle

Coercion cannot be abolished - it can only be distributed and constrained. Any system capable of guaranteeing peace holds the power to impose that peace - and so that power is dangerous. There is no free lunch: one can design only where coercion is legitimate, how far it is constrained, and who cannot abuse it.

What disappears, therefore, is not "the state" but its monopoly and its fusion. The functions disperse across layers, and the non-exitable coercive kernel shrinks to the necessary minimum - but not to zero.

Part III

The architecture of "Windows 12"

III.1

A microkernel instead of a monolith

The first engineering decision of any OS: what runs in ring 0 (privileged, with full access) and what runs in user space, where a process can crash without bringing the system down. A monolith is bad architecture. Here the architecture is built as a microkernel. In the kernel goes only what is physically inseparable and rivalrous - what cannot be left:

  • the protection of physical security and physical space;
  • planetary life-support systems - climate, ocean, atmosphere, orbit, spectrum, water;
  • the governance of hyper-technologies, where the cost of error is the species entire (artificial intelligence, bioengineering);
  • and, above all, the upkeep of the permissions model itself - the guarantee that no one becomes root.

Everything else - the economy, culture, communities, ways of life, faiths, aesthetics - is moved into user space. There it competes, errs, goes bankrupt, dies, and is reborn, without taking the system with it. The kernel is thin; above it, a churning space of free processes.

III.2

The human is the user, not a process

The heart of the whole model, and the point where most historical systems break.

In an operating system the sovereign is the user. Processes exist to serve the user; when a process obstructs the user or hangs, it is terminated - a routine operation, not a tragedy. The deepest bug of almost every social order is that it inverts this relation: the human becomes a process serving the System - the economy, the nation, the state, the party, the "great cause." The human is scheduled to the system's tasks, rather than the reverse.

First principle: the human is the user; institutions are processes. Not the other way round. An institution that has ceased to serve people is subject to termination, like a hung process. A people, a state, a corporation, a party, a movement are daemons in the background: useful, they run; harmful, they are terminated. No process has the right to declare itself the end for which the user exists.

III.3

The permissions model: capability-based security

The best idea in modern computer security is rights as capabilities under the principle of least privilege. On it the whole politics is built.

  • No actor gets more authority than a given task requires.
  • Every authority is revocable, time-bounded, and auditable. There are no perpetual, unconditional, inheritable grants of power.
  • Human rights are not an abstract declaration but concrete, inalienable capability-tokens that cannot be stripped by jurisdiction, traded away, or made conditional on usefulness.

The key move: the principle of least privilege applies first of all to power, not to the citizen. Today it is the reverse - the citizen under the magnifying glass, power in the shadows. Here the order is turned over: maximum transparency and minimum privilege for those who rule; maximum privacy and a protected floor of rights for those who are ruled. The transparency of the ruler is the right of the ruled, not the ruler's favour.

III.4

Process isolation and the right of exit

Federation, polycentrism, sandboxes. Communities, economies, and ways of life are isolated processes. One falls - the rest live on. Then the right of exit is the right to terminate a process or to leave it. This is the most powerful check on tyranny: a power one can walk away from is forced to be bearable, because otherwise it is left without people. But there is a cost (see Part VIII): total exitability leads to sorting by likeness, to the loss of solidarity across difference, and to the question of "who holds those everyone walks away from." The right of exit is absolute in user space and impossible in the kernel - otherwise Part II itself collapses.

III.5

The three layers and subsidiarity

Assembled as a whole, the architecture yields not "no state" but multiple layers. The organising principle is subsidiarity: a decision is taken at the lowest level able to hold it, and rises higher only when it must.

Diagram 1 · the three layers
shared, non-exitable
Layer 3 · planetary
What concerns everyone

Climate, oceans, atmosphere, orbit, pandemics, the governance of hyper-technologies. The only layer that needs genuine global coordination: here neither exit nor borders physically work - the atmosphere is one for all.

voluntary, exit is free
Layer 2 · functional
Voluntary belongings

Everything that can be detached from geography: professional, cultural, value-based, economic communities. Multiple belonging is the norm, not betrayal. A person belongs not to one but to a dozen.

microkernel · ring 0
Layer 1 · territorial
A thin coercive foundation

Physical space, safety, infrastructure, ecology. It stays coercive and tied to place, but becomes far thinner - it ceases to be the owner of a person's identity and meaning. A service operator of the territory, not a father-land.

subsidiarity: a task rises only when it cannot be held below

Such a division reconciles freedom with security better than anything yet devised: it does not centralise out of habit nor decentralise out of dogma, but places each task where it is actually solved.

Part IV

The role of the human: rights, functions, duties

The model answers the direct question - who the human becomes within it - through three bundles.

Rights (capability-tokens, inalienable, guaranteed by the kernel)

Exit

To leave any process except the kernel layer. The right to walk away is the foundation of freedom: it makes every other consent real rather than coerced.

Voice

To take part in the rules one lives under. Voice matters most where exit does not work - and one cannot exit the kernel.

Audit

The right to read the code that executes a person. No closed source in the power that rules them. What rules a person must be transparent to them.

Non-domination

Freedom as the absence of arbitrary power over a person, not merely the absence of momentary interference. One is free not when left alone, but when there is no one above who can dispose of them at will.

Floor

A guaranteed minimum of resource below which the system does not let a person fall. Not a favour, but the condition of everything else being fair (Module 2).

Function

The human is at once the user (sovereign over their own domain) and, collectively, the sole source of the kernel's authority. The kernel is legitimate exactly insofar as it is executed on behalf of the users. There is no "people above the persons," no "state above the citizens" as a separate higher entity - there are persons whose combined will is the only root. More precisely: root as an occupied position does not exist at all (Part IX); there is only a distributed source of authority that no one appropriates.

Duties (the price of the non-exitable layer - without which the whole construction is utopian)

  • Do not corrupt shared memory. Do not dump one's costs into the biosphere and into others' lives. Internalising externalities is not a tax and not morality - it is a ban on memory corruption: no one may write destruction into a memory shared by all.
  • Sustain the upkeep of the commons. Contribute to the kernel layer (security, the commons, protection of the weak) that cannot be left - precisely because one cannot emigrate out of it to escape obligation. This is the only legitimate coercion to contribute.
  • Maintain the system. Participation as maintenance. An OS no one maintains degrades. Citizenship is both a login and a shift on duty for the system: a minimum share of attention and labour, without which the commons rusts.
Part V · Module 1

Sybil identity: logging in a human without a new Big Brother

The real dilemma

It is a trilemma: three properties of which at most two are simultaneously attainable.

Uniqueness

One living human = one account. Without it, "one person, one vote" degenerates into "whoever has more bots."

Privacy

A person cannot be tracked, their actions correlated, a dossier assembled.

Decentralisation

There is no single issuer that itself becomes the very root the model swore not to create.

Any real system sacrifices one for two. This is, in all likelihood, a structural property of the problem, not an engineering shortcoming.

What has been tried, and how it breaks

  • A centralised biometric registry. Uniqueness is solved handsomely. But this is exactly the root: a single point of exclusion (turn off the record and a person becomes a civil corpse), a single point of surveillance, inevitable function creep.
  • Web-of-trust (vouching). Decentralised, private. But Sybil resistance weakens at scale and reproduces the inequality of the social graph: the well-connected are verified; the isolated remain no one.
  • Proof-of-personhood by biometrics. Uniqueness at scale is solved. But: a planetary-scale biometric honeypot; trust in the hardware; vulnerability to coercion; irreversibility (an iris cannot be re-issued); and a company behind it all. A working global biometric deduplication is, in itself, ready-made surveillance infrastructure.
  • A state ID in selective-disclosure wrapping. It improves privacy, yet leaves the issuing state as the root of trust and inherits the lottery of citizenship.

The least-bad option

The key move is to unglue what the word "identity" fused into one lump: authentication (the same subject across sessions), uniqueness (only one subject), and attributes (over 18 / a member of this / a holder of right X). The chief crime of passport systems is to run all three through a single identifier.

  • The verifier of uniqueness must never become the observer of activity. Between "who is unique" and "what a person did" stands a cryptographic wall: zero-knowledge proofs and nullifiers. The issuer emits the proof and forgets; no one holds a dossier; the proof stays with the person.
  • Plural issuers instead of a monopoly. Many independent ones; k-of-n suffices. None is root, none is a single point of exclusion.
  • Revocability instead of raw biometrics as the key. The primary key is a re-issuable credential. Biometrics fail exactly at re-issuance, so they cannot be the root.
  • Nullifiers by context. Prove uniqueness "in this election" without linking it to uniqueness "on that forum."
What cannot be solved

Coercion. Cryptography is powerless against physical force: a person can be made to log in at gunpoint. There are partial measures, but fundamentally it is unsolved.

The excluded. There will always be people the system cannot verify: the undocumented, the stateless, the borderline cases. And here lies the deepest ethical risk: the more important the login, the more catastrophic exclusion from it. A personhood system that makes rights conditional on it breeds a new class of digital non-persons.

Hence the principle: uniqueness must be additive, not a precondition - it grants extra standing, but basic dignity must never require a login. The moment "being human" begins to require successful authentication, a hell with a flawless UX has been built.

Part VI · Module 2

The scheduler-economy: what goes in the floor, and who pays for the kernel

The real dilemma

Two coupled questions: how to allocate scarcity (land, energy, matter, attention) and who finances the non-exitable kernel. Over both hangs the conflict of two failures:

market failure

The pure market fails on shared memory (externalities), on those without purchasing power, and on concentration (success buys the terms of the next game).

plan failure

The pure plan fails on the knowledge problem (the centre lacks what markets aggregate through prices) and on the fact that the central allocator is, once again, a new all-powerful root.

The least-bad option

The kernel sets invariants, not allocations. The kernel is not a central planner but a constraint solver: it sets the frame, and within the frame a decentralised market allocates. Thus both the Hayekian information of prices and the protection of the commons are preserved.

  1. A protected floor. A guaranteed minimum below which a person does not fall: food, energy, access to computation and information, basic health. The justification is not pity but freedom: one can bargain freely only if there is somewhere to walk away to from a bad deal. The floor gives the strength to stand up and leave; it makes the market above it fair.
  2. The commons is metered and paid for. The rivalrous commons (the atmosphere's absorptive capacity, orbit, spectrum, water, attention) is neither free nor privatised - access is priced and rationed. The revenue from depleting the shared substrate finances the floor and the kernel. This is rent on the commons (in the spirit of Henry George), not a tax on production: one pays not for what one created but for what one took from everyone.
  3. A ceiling on concentration - a security feature, not envy. Extreme concentration of resource equals concentration of power equals a would-be root, and rootlessness is among the model's axioms. Limiting accumulation is anti-capture. The justification is stronger than the moral one: not "wealth is unjust," but "super-wealth is an unauthorised seizure of the administrator's rights."
Aside

Attention as a scheduled resource. In an information system the scarce resource is human attention, and the old OS is infected with malware: engagement-maximising processes hijack the scheduler. The hijacking of attention is classed as malware, and the user's attention is protected as a floor resource. Attention belongs to the user, not to background daemons that have learned to pull at dopamine.

What cannot be solved

Who pays for the non-exitable kernel is the Achilles' heel of the architecture. The kernel is a pure public good, and public goods invite the free rider; historically that is why a coercive collector - the state - was needed. The whole voluntary-and-exitable construction breaks right here.

The honest answer: the kernel is the one place where coercion is legitimate, precisely because one cannot exit it. One cannot not breathe the shared atmosphere - so one cannot not pay for its protection. But this shifts the problem rather than closing it.

The treasury recursion. Whoever collects and spends the kernel's treasury aims to become root. So it must live under audit and least privilege: transparent, formulaic, with minimal discretion. This narrows capture but does not remove it: someone writes the rules (Module 3).

Goodhart. The moment the floor and the rent are set as a number, the number will be gamed. A measure ceases to be a good measure the moment it becomes a target.

Part VII · Module 3

Changing the rules without revolutions and without a dictatorship of improvers

The real dilemma

too rigid

The system ossifies; the accumulated pressure tears it apart in revolution. A revolution is an admission that no proper updater existed.

too plastic

Whoever controls the update process controls everything. A wide-open door for "improvers" who pave living complexity over to fit their scheme. High modernism ("seeing like a state," after James Scott) killed by the million this way.

The least-bad option

  • Policy as experiment. Staged rollout instead of "everything at once"; A/B on a consenting small perimeter; measurement against pre-declared metrics; expansion only if it worked.
  • A bias toward reversibility. Preference for changes that can be rolled back. Irreversible ones get a far higher threshold. Sunset clauses: rules expire and must be re-affirmed. The default is repeal, not accumulation; a dead institution quietly expires instead of dragging on by inertia.
  • Forking as a release valve. Lost the update? Do not go to war - split off on open rules. Pluralism applied to time.
  • Separating the power to change the rules from the power that gains by them. Whoever writes an amendment must not feed on it. Change is debated under a partial veil of ignorance about one's future position.
  • Who guards the updater. The update mechanism is itself code, and whoever can change it is the real root. So the meta-rule is the hardest thing to change: only through sustained, time-stretched super-majorities. Time-locks: changing the kernel requires support held across several periods. A majority on a Tuesday does not touch the kernel.
What cannot be solved

Goodhart and the tyranny of the measurable. "Evidence-based policy" quietly smuggles in only the measurable and crushes the immeasurable - dignity, meaning, trust, grief. In the choice of metric the whole politics is already hidden. Plus ethics: A/B on living people is an experiment on people, and consent here is a moral question, not a technical one.

What cannot be forked. Forking works in user space. But the atmosphere cannot be forked - the kernel is in principle un-forkable, so changing it demands the highest threshold and has no emergency exit. The layer most in need of change is the most dangerous to change.

Forking fractures solidarity. The right to walk away and build one's own is a blessing against tyranny and a poison for the commons: cells gather like with like, the echo chamber grows, and there remains the question of "who is with those everyone forked away from."

Part VIII

How the modules fight one another

This matters more than any single module. The three modules are not independent tasks but a bank of dials, where every setting of one spoils another. An honest model is obliged to show these conflicts, not hide them.

Diagram 2 · where the modules conflict
the same dials: freedom · security · well-being trust · peace Module 1Identity Module 2Economy Module 3Update privacy / treasury audit plural issuers / single quorum shared floor / right to fork
Privacy (M1) versus accountability of the treasury (M2).The stronger the ZK-anonymity, the harder to audit who spends the kernel treasury. A citizen's privacy and power's transparency are in partial conflict, because power is made of citizens.
Easy forking (M3) versus the shared floor (M2).The freer exit and secession, the weaker the non-exitable base that only coercion holds. Wealthy cells fork away from obligations to the poor - a return to sorting by usefulness.
Plural issuers (M1) versus a single set of update rules (M3).Many sources of identity guard against capture but complicate the quorum for changing the kernel: who counts as "everyone" when different, disagreeing issuers certify them?
The final, most honest thought

There is no ideal setting. Freedom, security, well-being, trust, and peace cannot be turned up to maximum at once - they physically pull the dials in opposite directions. So the aim is not to find the "right" values (there are none), but to keep the dials in plain view, let no one seize the console, and allow them to be turned back when they erred.

Part IX

The architect's trap

Here the OS metaphor cracks, and that crack is the most important thing in the document. An operating system has an owner - the one who holds root, decides what is good for the user, and pushes updates without asking. Humanity must have no such owner.

The most dangerous thing in the task "design a new world order" is the temptation to assemble a beautiful, unified, rationally arranged system with one wise architect. That is exactly what killed by the million throughout history. Society is not code; values have no compiler; there is no unit test for justice; and anyone who declares they know how things should be and demands the right to rewrite everyone is more dangerous than the bug he sets out to fix.

The only honest design principle

The best OS for humanity is the one that resists its own architect. It is designed so that:

  • it has no root user at all - no single centre able to rewrite the kernel in its own favour; the source of authority is distributed and appropriated by no one;
  • deliberate inefficiency and friction are built in - separation of powers, duplication, time-locks - precisely so that it cannot be captured quickly; an efficient system falls efficiently into the wrong hands too, so part of the inefficiency here is not a bug but immunity;
  • it is pluralist by design - many systems, not one; the right to fork matters more than the beauty of a single architecture.

In other words: the architect's task is to write a system that does not need an architect and lets no one become one. Not to set everyone up according to one's own understanding, but to remove the very position of the one who sets everyone up. The greatest feature of "Windows 12" is the absence of a button that grants anyone the power to rewrite everyone else.

This applies to the document itself. It is written in a single voice - and that is exactly why it cannot be taken as a finished system. Its purpose is to be opened up, contested, and forked, not installed.

Part X

Stress tests: where the model breaks first

A model not put through a breaking scenario is not a model but a stage set. Running "Windows 12" through three hard scenarios shows honestly where it falls.

Scenario 1. A pandemic

A fast, lethal pathogen. The kernel needs instant coercion to a common measure, yet the whole architecture is built around the right of exit and minimal coercion.

where it holds

A pandemic is the canonical kernel case (planetary life-support, non-exitability), so the legitimacy of coercion is present here by construction.

where it breaks

Speed. Time-locks and reversibility, which save from capture in peacetime, are lethally slow in an exponential outbreak. The temptation of an "emergency regime" arises - the chief machine, historically, for producing a permanent root.

Scenario 2. A war over a physical resource

Two territorial layers claim one river / shelf / corridor. The resource is rivalrous, forking is impossible.

where it holds

The planetary layer is designed for this - arbiter of non-exitable conflicts; rent on the commons gives a mechanism not of "whose" but of "how much, and at what price, for each."

where it breaks

What if a strong layer refuses the arbitration? Force enough to compel the strongest is force enough to become a tyrant. The eternal paradox: the arbiter is either weaker than the strongest player (useless) or stronger (dangerous).

Scenario 3. Capture by an AI

A hyper-powerful AI sits in the kernel. Whoever controls that process controls the most privileged code on the planet.

where it holds

Least privilege, auditability, and the absence of root are aimed directly against this; an AI-in-the-kernel is obliged by construction to be maximally transparent and constrained.

where it breaks

Audit assumes the auditor can understand the code. A superhuman AI may be opaque in principle - not closed, but incomprehensible. "The right to read the code that executes a person" is voided if the code cannot be understood. Perhaps the deepest breach.

Verdict

The model holds up best in slow, distributed conflicts and is weakest wherever speed is needed, or where the adversary is stronger than the arbiter or incomprehensible. Not a sentence but a map of the front line: this is where the work should go first.

Part XI

A reckoning with real, living attempts

Nothing here is wholly new. Almost every element has been tried by someone in real life - and almost every attempt broke on something. An honest model is obliged to know its predecessors and not to pass off the old as the unprecedented. The novelty, if any, lies only in the configuration. Every living attempt is a stress test of one module already run for us.

Living attemptWhat it confirmsWhere it stumbled
Federalism, subsidiarityMultiple layers and "solve at the lowest capable level" do work.The upper layer either devours the lower ones or is paralysed by the veto.
Cooperatives, mutualismAn economy where the human is the end and the vote is not for sale.Hard to scale, hard to attract capital; risk of managerial oligarchy.
Commons governance, after OstromCommunities can sustain the commons without privatisation or the state - under conditions.Proven at moderate scales; the planetary scale is an untested extrapolation.
Georgism (rent on the commons)A precise prototype of "the commons is paid for, labour is not."Politically loses to the owners of rent; the bottleneck is capture of the mechanism of adoption.
DAOs, Web3 governanceLive experiments in capability-permissions, the fork as release valve, an algorithmic treasury.Plutocracy (the vote is bought with the token), Sybil attacks, the gap between "code is law" and living justice.
Network states, seasteadingA direct attempt to detach belonging from territory and make exit the foundation.They gather the similar wealthy with the similar wealthy; weak at caring for the unprofitable.
Non-territorial peoplesA people without territory is no fantasy: under the declarative theory, existence is a fact of self-constitution, not a gift of recognition.What is open is not existence but external recognition - it accrues separately and slowly; for groups within states it runs through those states.

They say plainly: a single element is feasible, but breaks at scale, at capture, or at the care of the weak. The open question of the whole model is whether the configuration holds where the parts fell. There is no answer in advance; it is won only by trial.

Part XII

The open horizon: what we open for work

The value of the model lies not in its answers but in the quality of the questions it makes concrete and testable. The weak places of the previous parts are the agenda itself. The concrete tracks opened for joint research, design, and testing:

  1. Sybil without a Big Brother. Certify a human's uniqueness while building neither a central surveillance registry nor an excluding gate. So far, a trilemma with no solution.
  2. Additive personhood, not a precondition. So that the absence of a login never strips a person of basic dignity. Protection against the chief risk - a class of digital non-persons.
  3. Financing the non-exitable kernel without a new tyrant-collector. Rent on the commons is a hypothesis; who collects it, without turning the treasury into a new root, is open.
  4. Kernel speed versus protection from capture. Give the kernel speed in a disaster without building a machine for the emergency regime.
  5. An arbiter stronger than the strongest, yet not a tyrant. Perhaps the answer lies not in force but in a construction where breaking the order is disadvantageous to all at once - but this must be built and tested.
  6. Auditability of the incomprehensible. Keep human control over a hyper-powerful AI in the kernel when its code cannot be understood by a human mind. Perhaps the most important.
  7. Floor and exit at once. Reconcile the right to leave with the strength of the commons, so that freedom of divergence does not kill solidarity.
  8. Metrics without Goodhart. Measure the success of policies without crushing the immeasurable and without launching a race to circumvent thresholds.
On the work and its support

Each track is concrete public-goods work that can be carried out and supported as research and prototype - in the small, in the open, with verifiable steps. Support for such work is accepted only within a strict discipline: the vote is not for sale, a contribution grants no power over people, and nothing is promised in advance. To support the implementation of a track - yes; to buy the people's direction - no.

Closing frame

A model, and a real horizon

This document is one voice and one of an endless set of possible models. It is deliberately unfinished: with strong places to develop and weak ones to open up. Its task is done if it has shown that world order can be taken apart in engineering terms, that the state is a detachable bundle of functions rather than a fate, and that an honest model differs from a utopia in that it shows its own cracks first.

This is where Earthlings returns - not as the author of this model and not as its owner, but as an environment: a place where models like this become the object of living work - assembled in the small, tested on those who freely consent, measured, rolled back, forked, and passed on. Not "here is the right answer," but "here is a space in which answers can be sought, without staking the whole world."

Come to take apart, contest, and break what holds poorly. The direction is toward where the dials are in plain view, the console is handed to no one, and a mistake can be rolled back.