Commonsent Architecture Paper

Authority before infrastructure

Compute sovereignty and the realistic birth of a people-side federated artificial intelligence network.
How participant authority, plural procurement, coordinated demand, and recirculatory capital can convert rented intelligence into shared capacity.
The practical maximFour sequential commitments: borrow the compute, own the rules, aggregate the demand, build the alternative. THE PRACTICAL MAXIM Borrow the compute Own the rules Aggregate the demand Build the alternative Commonsent may borrow computational capacity. It cannot borrow its mandate.
Architecture paper Version 1.0 · August 2026 By Ivan Milovanovic Commonsent Lab
Abstract.

A people-side artificial intelligence network faces an immediate objection: if its models run on chips, clouds, energy systems, and communications infrastructure owned by powerful corporations or states, in what meaningful sense can the network be independent? The objection is valid. Access to intelligence is not the same as control over the conditions under which intelligence is produced, allocated, and withdrawn.

Commonsent answers this problem by separating the origin of computational capacity from the origin of legitimate authority. The network does not need to own every machine at birth. It does need participant control over identity, data, delegation, governance, provider selection, value distribution, and exit from the beginning. Commercial, public, cooperative, university, open-source, and community providers may supply replaceable services. They do not thereby acquire jurisdiction over the people using them.

This distinction changes compute sovereignty from an impossible starting condition into a disciplined transition. Commonsent can begin asset-light, procure capacity from multiple sources, aggregate demand, capture part of the value produced by coordination, and direct participant-authorized contributions into alternative and shared infrastructure. Over time, rented intelligence becomes negotiated intelligence, negotiated intelligence finances reserve capacity, and reserve capacity makes exit credible. Sovereignty is therefore neither a slogan nor an all-or-nothing ownership claim. It is a measurable increase in authority independence, operational substitutability, and economic capacity.

Core thesis
Commonsent may borrow computational capacity, but it cannot borrow its mandate. Authority must originate with participants from the first day. Infrastructural independence is built progressively from the value their coordination creates.
Section 1

The dependency problem

The emerging personal-agent model promises to place extraordinary analytical and operational capacity beside each person. But a personal agent does not exist in abstraction. It depends on a physical and institutional stack: devices, networks, identity services, models, accelerators, data centers, energy, payment systems, software distribution, and contractual permission to use them.

That stack is expensive, concentrated, and subject to unilateral rules. A provider may change prices, restrict workloads, modify a model, alter privacy terms, withdraw an interface, rank some uses above others, or discontinue service. A government may impose access conditions or compel disclosure. A network that cannot survive those changes remains dependent even when its interface uses the language of empowerment.

The problem is not that every external dependency is illegitimate. All complex institutions depend on suppliers. The problem appears when a supplier becomes constitutionally indispensable: when removing it would destroy identity, erase history, disable governance, strand shared assets, or make collective exit practically impossible.

A system is not sovereign because it owns every component. It is sovereign when no indispensable supplier is allowed to become its unremovable governor.

This is the capacity-origin objection in its strongest form. Who owns the computation? Who can deny it? Who writes the terms? Who can observe the data? Who decides which models may act? Who benefits when the network grows? Unless those questions are answered structurally, a people-side coordination layer could become only a friendly surface above someone else's control system.

Section 2

The distinction: capacity origin is not authority origin

Commonsent's answer begins with a separation that modern platforms usually collapse. Computational capacity and legitimate authority are different resources. One can be procured. The other must be constituted.

A cloud provider may execute an inference. A model developer may supply weights. A device manufacturer may supply a sensor. A telecommunications company may carry a message. None of those acts should grant the supplier the right to redefine participant identity, repurpose personal data, expand an agent's mandate, change voting rules, redirect pooled resources, or prevent a group from leaving.

The three layersA sovereignty layer authorizes and constrains a coordination layer, which procures and replaces a capacity layer. CAPACITY SUPPLIES INTELLIGENCE. PARTICIPANTS SUPPLY AUTHORITY. SOVEREIGNTY LAYER Participant rights · identity · data · delegation · governance · exit CONSTITUTED authorizes and constrains COORDINATION LAYER Discovery · deliberation · demand aggregation · audit · federation procures and replaces CAPACITY LAYER Devices · models · clouds · networks · energy · shared infrastructure PROCURED
Figure 1. The three layers. Commonsent separates the constitutional source of authority from the replaceable sources of computational capacity.

The sovereignty layer

The sovereignty layer defines the relationships that must not be surrendered to a service provider. It contains participant rights, control of personal identity, data ownership, the boundaries of agent authority, due process, transparency requirements, anti-capture rules, treasury constraints, and the right to exit or fork.

The coordination layer

The coordination layer allows personal intelligence nodes and human-scale groups to discover compatible interests, deliberate across disagreement, aggregate demand, authorize collective action, preserve institutional memory, resolve disputes, and federate without centralizing all trust.

The capacity layer

The capacity layer supplies models, inference, storage, connectivity, devices, security services, and energy. It may contain commercial vendors, public infrastructure, cooperatives, universities, open-source communities, local servers, and participant-owned assets. Its defining property is not uniform ownership. Its defining property is replaceability under rules established above it.

QuestionCommonsent principle
Who supplies computation?Multiple replaceable providers may supply capacity under auditable contracts and open interfaces.
Who controls personal identity and data?The participant, using portable identity, local-first storage where possible, and explicit authorization.
Who authorizes an agent?The participant, or a legitimately constituted group, through bounded, purpose-specific, revocable delegation.
Who defines collective rules?Human-scale cells and their federations, operating under an inspectable constitutional layer.
Who accumulates created value?Participants, workers, communities, and shared treasuries according to predeclared distribution rules.
What disciplines providers?Provider plurality, workload portability, collective procurement, audit rights, reserve capacity, and credible exit.
Section 3

Participant supervision, not self-supervision

The phrase self-supervising system is misleading. It suggests that the same agentic structure can exercise power, evaluate its own conduct, authorize its own continuation, and correct itself without an external source of legitimacy. That is exactly the institutional concentration Commonsent is intended to prevent.

A better description is participant-supervised, polycentrically audited, and structurally forkable. Automated systems may observe one another, test outputs, search for anomalies, compare claims, and produce public traces. But agents do not become the ultimate constitutional authority merely because they can monitor other agents.

The supervision architecture requires separation of powers:

  • Participants grant mandates that specify purpose, data access, spending limits, duration, and conditions for renewal.
  • Operational agents execute authorized tasks but cannot silently expand their own jurisdiction.
  • Independent audit agents inspect evidence, conflicts of interest, policy compliance, and distributional effects.
  • Human-scale cells review consequential collective decisions and can replace delegates or implementations.
  • Federations detect cross-cell patterns, provider concentration, coordinated manipulation, and systemic risk.
  • Ombuds, appeals, and dispute processes give participants a route to contest outcomes.
  • Public-trace observatories expose aggregate behavior without turning private lives into a public ledger.
  • Exit and forking rights prevent the governing layer itself from becoming an unchallengeable center.
The controlling rule.

No component should be simultaneously rule-maker, operator, auditor, and final judge. Supervision is a relationship among participants, cells, independent functions, federations, and technical systems. It is not a magical property of autonomous code.

Section 4

Minimum viable sovereignty

If complete infrastructure ownership is not required at launch, what is required? Commonsent needs minimum viable sovereignty: the smallest set of constitutional, technical, and economic capabilities that prevents a bootstrap dependency from becoming permanent subordination.

Practical sovereignty = A × P × M × R A is authority independence. P is portability. M is market plurality. R is reserve capacity.

The multiplicative form is deliberate. A near-zero factor can collapse the whole system. Authority independence means participants retain control over identity, data, delegation, governance, and value distribution. Portability means identities, mandates, histories, and workloads can move without losing continuity. Market plurality means more than one viable capacity provider can compete. Reserve capacity means the network can continue essential functions long enough to change providers or activate alternatives.

Minimum viable sovereignty does not promise frictionless independence. Migration can be costly, alternative models may perform differently, local compute may be slower, and reserve capacity may cover only essential functions. The requirement is narrower and more testable: a provider's departure must not dissolve the polity that used it.

What must be sovereign at birth

Independent from the beginningMay initially be procured
Participant identity, consent, and permissionsCloud computation and accelerator access
Data rights and local-first handling rulesFoundation and specialized models
Bounded delegation and revocationStorage, networking, and observability services
Governance constitution and dispute rightsDevices, sensors, and connectivity
Provider-selection and portability rulesTechnical implementation and integration services
Treasury and value-distribution constraintsEnergy and data-center operations
Design rule
The control plane must be independent before the resource plane is owned. If the resource provider also owns identity, governance, history, and exit, later independence becomes vastly harder.
Section 5

Why Commonsent will be harder to start

A participant-governed network is undeniably harder to launch than an agent ecosystem built by an organization that already controls hyperscale infrastructure. A hyperscaler begins with compute, capital, engineering talent, billing, distribution, identity, consumer devices, and existing relationships with businesses and governments. It can subsidize adoption, integrate services rapidly, and absorb years of losses while network effects accumulate.

Commonsent begins with a coordination thesis and must earn almost everything else: trust, participation, a governance culture, technical contributors, institutional partners, and enough recurring value to finance its own continuity. It must also impose constraints on itself that centralized competitors can avoid: provider neutrality, explicit consent, auditability, due process, and the real possibility of exit.

This asymmetry is not a minor implementation detail. It determines the birth strategy. Commonsent cannot begin by attempting to become a frontier-model laboratory, global cloud, social network, financial institution, governance platform, and cooperative ownership system at the same time. Requiring complete infrastructural independence before the first useful coordination event would make the project nearly impossible.

Commonsent must not be born as an alternative hyperscaler. It must be born as an independent coordination and control layer capable of using, comparing, and progressively replacing many sources of capacity.

The centralized advantage, and its constraint

Centralized providers possess a formidable speed advantage, but they also face a structural conflict. An organization whose revenue and strategic power depend on controlling infrastructure, distribution, data, or switching costs cannot easily become a fully provider-neutral advocate for participants. It may offer meaningful protections. It cannot credibly design its own progressive dispensability as the system's central objective.

Commonsent's differentiation is therefore not a better general-purpose model or cheaper compute. It is a different institutional relationship: providers compete inside participant-defined rules, participants retain portable rights and history, collective demand can be redirected, and created value can finance alternatives. A corporation can reproduce a feature. It cannot easily reproduce a constitution that gives users the enforceable right and practical capacity to replace it.

Section 6

The correct birth model

Commonsent should begin with a narrow coordination failure in which isolated individuals are predictably disadvantaged and coordinated action can produce measurable benefit. The first network does not need massive compute. It needs to prove that the value created by coordination exceeds the cost and friction of coordinating.

Principle 1: begin with use value, not constitutional ceremony

The first participants must receive value before large-scale network effects exist. A bounded purchasing coalition, household-cost negotiation service, local procurement group, community-energy aggregation, benefits-navigation cell, or shared verification network could each create individual benefit while also producing collective leverage. The specific wedge should be selected through evidence, not ideology.

Principle 2: make portability operational from the first pilot

Even a small implementation should separate participant identity from the application, express agent permissions in provider-independent formats, preserve exportable history, support more than one model or service provider, keep highly sensitive data local where feasible, and maintain a degraded mode for essential functions. Portability that exists only in a constitution is not portability.

Principle 3: organize participants in human-scale cells

The first unit should be a bounded group with a recognizable shared problem: a neighborhood, cooperative, school community, workplace, profession, municipality, or temporary coalition. Human-scale cells supply context, accountability, and social verification that global platforms struggle to manufacture. Federation should follow demonstrated local reliability rather than precede it.

Principle 4: capture only an authorized portion of created value

Most negotiated savings or benefits should remain with participants. An explicitly authorized portion can support operations, audits, privacy infrastructure, protocol development, and future shared capacity. This contribution, described elsewhere in Commonsent as a self-imposed micro-contribution, is not an extraction imposed by an external platform. It is a transparent rule by which present coordination finances future independence.

Principle 5: treat infrastructure ownership as a staged consequence

The first objective is not to buy a data center. It is to create enough recurring value, concentrated demand, and institutional credibility that better infrastructure terms can be negotiated and alternatives can be financed rationally. Ownership should follow demonstrated bottlenecks and economics, not symbolism.

Progressive compute sovereigntyFive staged states from rented capacity through plural procurement, recirculatory capital, and shared reserve capacity, to a hybrid owned ecosystem. PROGRESSIVE COMPUTE SOVEREIGNTY Rented capacity Bootstrap Plural procurement Substitutability Recirculatory capital Accumulation Shared reserve capacity Credible exit Hybrid owned ecosystem Durability Ownership grows after authority, portability, and value creation are established.
Figure 2. Progressive compute sovereignty. The transition from rented capacity to a durable hybrid ecosystem is staged. Authority and portability precede substantial infrastructure ownership.
Section 7

Coordinated demand as the first infrastructure

Millions of people buying compute separately are price-takers. A federation representing a meaningful, privacy-preserving block of demand can behave like an institutional buyer. It can invite providers to compete not only on price and performance, but also on data retention, model transparency, portability, energy impact, audit access, continuity guarantees, and restrictions on secondary use.

The network does not wait until it owns infrastructure to acquire bargaining power. The coordination of demand is itself the first shared infrastructure.

This is an essential inversion. It changes the procurement relationship before it changes the asset register. A provider market governed by Commonsent principles would reward:

  • interoperable models and standardized workload interfaces;
  • verifiable deletion and limits on data reuse;
  • clear inference pricing and service-level commitments;
  • independent evaluation and incident disclosure;
  • geographic, organizational, and technical diversity;
  • low-cost migration and continuity support; and
  • community-benefit terms when infrastructure has concentrated local effects.

The same demand-routing system that helps participants obtain fairer terms in ordinary markets can therefore be applied to intelligence itself. Compute becomes one of the first markets in which Commonsent practices its own theory.

Section 8

Recirculatory capital as the independence engine

Procurement savings alone do not create sovereignty if every dollar of created value immediately dissipates into consumption. Commonsent's economic architecture addresses that problem through recirculatory capital: a participant-governed share of savings, fees, contributions, or shared-service revenue compounds inside the network instead of being extracted entirely outward.

The resulting treasury can support:

  • independent security, privacy, and model evaluation;
  • edge and offline inference for essential functions;
  • community or regional compute clusters;
  • cooperative cloud and connectivity providers;
  • open protocols and reference implementations;
  • renewable energy capacity and resilience investments;
  • public-interest data stewardship;
  • emergency continuity reserves; and
  • eventual shared ownership of strategically useful suppliers or productive assets.

This is why Commonsent's economic and governance layers cannot be separated. The economic system is not an optional benefit program attached to the technical platform. It is the mechanism through which the network converts political authority into material staying power.

The progressive sovereignty loopA five-stage cycle: useful coordination, aggregated demand, negotiated value, common capital, alternative capacity, returning to useful coordination. THE PROGRESSIVE SOVEREIGNTY LOOP Useful coordination Aggregated demand Negotiated value Common capital Alternative capacity Agency to bargaining power to capital to capacity to credible exit Created value finances the capacity that makes future exit credible.
Figure 3. The progressive sovereignty loop. Coordination creates bargaining power, negotiated value finances alternatives, and alternatives strengthen future bargaining power. This is Commonsent's long-run movement from informational agency to material sovereignty.
Section 9

What should eventually be owned?

Commonsent does not require technological autarky. No network of ordinary participants should be expected to fabricate all of its own chips, operate every model, generate all energy, and eliminate all external suppliers. That would reproduce the very centralization and capital intensity the project is trying to escape.

The rational objective is sufficient strategic capacity, not universal ownership. The network should own or control the functions whose absence would make its rights unenforceable. Which functions meet that test will change with technology and scale.

Priority should be given to assets that create option value across multiple providers: portable identity, authorization and delegation systems, encrypted participant data stores, open protocol implementations, audit infrastructure, provider-routing logic, continuity reserves, and enough independent inference capacity to preserve essential functions during migration or denial of service.

At greater scale, regional compute, energy, connectivity, specialized models, or acquisitions of aligned suppliers may become economically justified. Ownership should remain plural: operators, workers, participants, communities, cooperative entities, and shared treasuries may each hold defined stakes and rights. Replacing corporate concentration with a single unaccountable treasury would not constitute success.

Section 10

Measuring whether sovereignty is becoming real

A transition model can become an excuse for permanent dependence unless progress is measurable. Commonsent should publish a Compute Dependency and Sovereignty Scorecard from its earliest pilots.

S = 100 × Σ(wk × sk) where Σwk = 1, and each sk is a normalized sovereignty dimension

A weighted score should be accompanied by minimum guardrails so strong performance in one area cannot conceal a fatal dependency in another.

DimensionIllustrative measureWhy it matters
Provider concentrationShare of spend and workloads by provider; concentration indexReveals whether nominal plurality masks practical dependence.
Workload portabilityShare movable within 24 hours, 7 days, and 30 daysTests whether switching is operational rather than contractual.
Identity continuityShare of identity, mandates, and history independent of any service providerProtects the network's constitutional continuity.
Data localityShare of sensitive processing performed locally or under participant-controlled encryptionLimits surveillance and secondary use.
Essential-function reserveDays or workload share sustainable during provider lossMeasures credible continuity and exit.
Economic independenceOperating runway and share of costs covered by recurring participant-created valueTests whether the network can finance its commitments.
Shared capacityShare of essential capacity owned or contractually controlled by aligned entitiesShows movement from access toward durable option value.
Governance substitutabilityTime and cost required to replace an operator or implementationPrevents the internal technical team from becoming a new monopoly.
The aggregate score never overrides the guardrails.

Commonsent might require, for example, that authority independence, identity continuity, and provider exit each remain above a minimum threshold. A network with excellent pricing but no right to leave is not mostly sovereign. It is dependent in the dimension that matters most.

Section 11

Failure modes

The model should state its own vulnerabilities plainly.

Portability theater

Standards may claim interoperability while hidden data schemas, model-specific prompts, proprietary tools, or contract terms make migration prohibitively expensive. Commonsent must test migrations, not merely document them.

Treasury capture

The shared treasury may become a new center of patronage or technical dependence. Spending mandates, conflict disclosures, independent audit, multi-signature controls, transparent procurement, and participant review must constrain it.

Governance overload

If participants must evaluate every technical choice, formal democracy will produce fatigue rather than control. Delegation should be bounded, revocable, and supported by comprehensible evidence, with human attention reserved for consequential or contested decisions.

Premature accumulation

Owning underused servers can consume capital without increasing sovereignty. Capacity acquisition should follow demonstrated workload, strategic bottlenecks, and continuity requirements.

False provider neutrality

A system may technically support several providers while relying overwhelmingly on one for quality, price, or integration. Concentration must be evaluated by actual workload and switching cost, not vendor count.

Internal technical monopoly

Even open code can become practically unreplaceable if only one team understands it. Multiple implementations, documentation, reproducible builds, security review, and distributed operational knowledge are part of sovereignty.

Exclusion through complexity or cost.

A people-side system fails if its protections are usable only by technically sophisticated or affluent participants. Interfaces, explanations, accessibility, subsidized essential service, and local support must be treated as core infrastructure.

Section 12

The deeper alignment proposition

Compute sovereignty is not only a procurement or ownership problem. It is part of Commonsent's answer to artificial intelligence alignment. Large agentic structures require human goals, authorization, demand, local knowledge, social legitimacy, and access to real-world environments. Today those inputs are typically collected from people individually under provider-defined terms.

Commonsent organizes those human inputs. Participants do not merely receive intelligence. They collectively define the conditions under which intelligence may act. Providers retain technological capabilities, but the people-side federation gains control over valuable demand, permission, feedback, and implementation contexts.

The resulting relationship is reciprocal rather than unilateral. The network depends on advanced computation, while capacity providers depend on organized, legitimate, and revocable participation. Coordinated demand converts that reciprocal need into enforceable terms. Recirculatory capital then finances alternatives, and alternatives strengthen the credibility of future negotiation.

This does not guarantee benevolence. It creates countervailing capacity: the institutional means by which people can inspect, condition, redirect, and, when necessary, withdraw cooperation.
Section 13

A realistic doctrine for the network's birth

The birth of Commonsent will be slower than the deployment of a centrally financed agent ecosystem. Democratic authorization, provider neutrality, audit, and shared ownership introduce real friction. Some of that friction is the cost of preventing capture. The goal should not be to eliminate it indiscriminately, but to concentrate it where it protects rights while keeping ordinary participation simple.

The correct sequence is:

  1. Own the rules. Establish portable identity, data rights, bounded delegation, governance, audit, and exit before scale.
  2. Borrow plural capacity. Use multiple external services and local processing without granting providers constitutional control.
  3. Solve one costly coordination failure. Produce measurable individual and collective value before asking participants to support a universal network.
  4. Aggregate the demand. Turn isolated users into an institutional buyer capable of setting procurement conditions.
  5. Recirculate a participant-authorized share of value. Finance operations, independent oversight, open protocols, and continuity.
  6. Build the alternative selectively. Acquire reserve and shared capacity where dependency creates strategic risk.
  7. Federate proven cells. Scale bargaining power and shared standards without requiring centralized trust.
Conclusion

Authority before infrastructure

The origin of compute is a decisive question, but it does not force a choice between corporate dependence and impossible self-sufficiency. Commonsent offers a third path: constitutional independence at birth, operational substitutability during growth, and progressive material sovereignty financed by the network's own coordination value.

The system may initially run across infrastructure it does not own. That fact should be disclosed, measured, and actively reduced where it creates strategic vulnerability. But infrastructure providers remain suppliers only if participant identity, rights, history, governance, and exit live elsewhere.

The deepest claim is therefore not that Commonsent can immediately escape the existing computational economy. It is that people can organize within that economy in a way that changes the direction of dependency. They can move from isolated consumption to collective procurement, from procurement to bargaining power, from bargaining power to common capital, and from common capital to durable alternatives.

Intelligence may come from many places. Legitimate authority must come from the people whose lives the intelligence affects.

That is the foundation on which a people-side federated network can realistically be born, and the mechanism through which it can become progressively harder to capture.

The practical maxim
Borrow the compute. Own the rules. Aggregate the demand. Build the alternative.
Conceptual status

What this paper is, and is not

This paper describes a Commonsent architectural doctrine and an implementation pathway. The mechanisms, thresholds, scorecard weights, financing structures, and governance procedures require legal review, threat modeling, technical prototyping, participatory design, and empirical validation before deployment. It is offered as a design proposal for review and testing.

Related work: The Counter-Coordination Layer (Commonsent Lab, July 2026) sets out the detection and public-response half of the same architecture. This paper addresses the question that document leaves open: on whose infrastructure any of it runs.