Your AI can be your analystco-pilotadvisorguardianbuilderoperator.
But can you stand behind what your AI did?
Every risk function now asks the same question: can you prove what it did, under whose authority, built from what — and stop it when it is wrong? That answer is not an AI trust layer. It is the substrate underneath — and it carries a payment, an IoT command, or a human approval exactly the same way. AI is simply one tenant. The action either completes, or the proof survives.
You decide how large your substrate is — from a single box to your whole stack.
You set the scope, and nothing forces a rip-and-replace: run one box under a single workload, or grow it under your whole stack — your call, sized to what you need today. It is not an AI substrate by definition; it sits underneath any accountable action — human, AI, payment, file transfer, IoT, voice, simulation, or system job — carrying measured machine floor, identity-bearing carriers, MUX posture, lanes, continuity, bifurcated airlock storage, runtime boundaries, BOMs, and audit rights before an action is allowed to carry.
The Short Version
Action has an address
Work carries on `.aint`, `.waint`, `.raint`, and related runtime identities, not IP location. If routes change, the actor context and authority path remain inspectable.
Carriers preserve intent
`cmail`, `.tza` drops, cap-bus actions, and lanes keep work sealed, routed, and reviewable. Open is not persist; persist is not act.
Audit is precondition
Runtime claims are projected with identity, role, posture, binding class, surface, grant, and causal evidence. Missing or broken proof degrades visibly.
This is not icing on the cake. The substrate is the cake: measured floor, sealed transfer, identity, accountable service, continuity, and evidence. Audit is the crown that makes the whole thing reviewable.
The Consolidation
The substrate already exists in the open as 100+ published packages. AInternet-in-a-box is the consolidation: one downloadable, runtime-bound product that houses the proven substrate as a supportable unit.
The commercial point is simple: supporting one box is a clearer SLA promise than supporting a loose constellation of packages. The box turns a broad protocol ecosystem into a deployable operating surface.
Reported ecosystem telemetry, snapshot as of 15 Aug 2026 — a point-in-time reading, not a standing claim; treat as an adoption signal unless the underlying package-index / crate / mirror evidence is attached.
| Adoption Signal | Reported Scale | Commercial Reading |
|---|---|---|
| Enterprise mirrors | 103,083 | The substrate is already pulled into enterprise-like environments; IAB packages that into a supported product boundary. |
| CI/CD and server use | 13,119 | The primitives are already being used where repeatability, automation, and auditability matter. |
| Local developers | 3,423 | Local-first adoption exists beyond a hosted SaaS pattern. |
| GitHub stars | A handful, total (as of 15 Aug 2026) | The inversion is informative: usage appears in package pulls, CI, and mirrors rather than public popularity signals — adoption that shows up where infrastructure is assembled, not where projects are up-voted. |
| Open protocol and conformance | ZT / ZTIP protocol work in the open | The assurance story is not hidden behind a private dashboard; protocol and conformance can be inspected. |
In The Open — Referenced Independently
The assurance story is not self-published amplification. It stands in the public standards and academic record, and is being picked up independently — standards reviewers, an EU AI Act standard, an identity-workshop founder, an independent CTO, and a security researcher, each on their own.
IETF Internet-Drafts
Twelve drafts under draft-vandemeent-* (identity, provenance, continuous verification, causal time, agent discovery) on the IETF Datatracker. The AINS draft on agent discovery and trust resolution resonated at the DAWN meeting, IETF 126.
Cited by peers in the process
The AINS draft is now cited as recognized related work in other authors' Internet-Drafts — Carsten Rehfeld's draft-rehfeld-apix-core and draft-rehfeld-bot-service-index — described there as "agent discovery and trust resolution via signed, append-only replication logs… no central authority." The standards process is engaging with the approach, not just receiving a self-submission.
EU AI Act — prEN 18282
Contributed accepted drafting language to the harmonized cybersecurity standard (via OWASP AI Exchange): that "a success would have been observed" is an observability claim, only as strong as an append-only, verifiable-after-the-fact record — and that a rationale's currency should track its stated assumptions, re-evaluated on drift, not a calendar.
Invited to convene
Invited to host a session on trust resolution at the Agentic Internet Workshop #3 (Computer History Museum, Mountain View, 6 November 2026) — by the founder of the Internet Identity Workshop, which incubated OpenID and OAuth.
Independent pickup
Named by a group cybersecurity CTO as an approach to watch; joint and citing papers on Zenodo (doi.org/10.5281/zenodo.20338260 and .21362168); write-ups on Qiita by a GMO Connect IETF reviewer; community directories (internet-of-agents.net, agentcommunity.org).
Live and machine-readable
The site is the human "why and how"; the machine map — what to read, which path fits the job, the operating rules — is one safe curl away, for your own AI to read: curl -s https://ainternet.org/ai-scan.json and curl -s https://ainternet.org/api.json. All live.
The Primitive Set
| Primitive | What It Does | Enterprise Reading |
|---|---|---|
| machine floor / can_carry | Measures whether the host/runtime can honestly bear the requested workload: CPU, memory, isolation, crypto, hardware, and posture. | Under-capable substrates refuse or downgrade with receipt instead of silently overclaiming. |
| BOM family | SBOM, AI-SBOM, CBOM, mux-bom, and host/runtime measurements describe what the box is made of and what it can carry. | Supply-chain and runtime assurance become inspectable inputs before execution. |
| .aint identity | Names the human, agent, service, node, or runtime role that is allowed to resolve and act. | Stable authority identity across network, session, host, and route changes. |
| .waint / .raint / .paint | Runtime-bound work, run, and posture addresses rather than generic accounts. | Operations can be audited at the correct level: actor, workload, runtime, posture, or surface. |
| MUX posture | Routes by proven posture for a specific lane, action, window, and causal sequence. | No scalar trust score. The route is reconstructed and gated by posture coordinates. |
| human presence / RVP | Measures live human presence and cadence for `--human` actions, approvals, and sensitive transitions. | Human authority becomes a fresh runtime fact, not a checkbox or stale account flag. |
| cortex leveling / on behalf of | Connects action to capability level, mandate, and whether it is direct or on behalf of another actor. | Delegated operation can be permitted, bounded, and audited without hiding the principal. |
| .tza carrier | Sealed package with magic bytes and routing headers for messages, payloads, receipts, and handoff material. | Portable custody unit: identity-bearing, inspectable before opening, preservable through outage or transfer. |
| cmail | Carrier mail with verify/read split, attachment airlock, and signed action decisions. | A familiar mailbox pattern for high-risk agent operations: read, save, forward, approve, reject. |
| cap-bus and lanes | Identity-bound command substrate for routing intent to the right execution lane. | Message queue, workflow bus, and approval rail with actor identity embedded. |
| continuityd | Witnesses arrivals, liveness, forks, handoffs, receipts, and unfinished tails. | Work either completes or remains preserved as evidence, instead of disappearing into logs. |
| causal timevector | Orders events by causal lineage across lanes instead of trusting wall-clock timestamps. Forward-only: an action extends a grounded parent, never a backdated one. | Clocks drift; causal receipts answer what happened before what — and prove nothing was inserted after the fact. |
| AINS | Resolver for `.aint` names, comparable to DNS in the internet stack. | Important for discovery, but not the substrate itself. The substrate is the runtime binding and carrier path. |
| tibet-audit | Read-only mirror over runtime evidence: roles, binding, surfaces, and causal chains. | Audit cockpit and evidence export, sitting outside the runtime it measures. |
Why This Matters For Regulated Operations
Model governance asks whether a model is controlled. Operational governance must also ask whether the action path itself is authorized, bound, observable, and causally intact.
That gap becomes visible in generative and agentic AI, but it is not limited to AI. The same rail can carry a human approval, a payment action, a file-drop, an IoT command, a voice lane, a runtime spawn, or an autonomous job. AInternet treats action evidence as a first-class control surface.
Regulation is converging on one question: can the institution stand behind the action? The EU AI Act, DORA, NIS2, SR 26-2, the Cyber Resilience Act, ISO/IEC 42001 and NIST AI RMF point toward the same operating need — accountable execution, controlled third-party dependency, traceable AI use, resilient recovery, and evidence that survives failure. AInternet does not replace these regimes; it produces the runtime evidence they increasingly require.
| Regime (landscape as of Aug 2026) | Where it stands | What the substrate provides |
|---|---|---|
| EU AI Act | Phased, not postponed: enforcement and transparency obligations active (2 Aug 2026); high-risk obligations 2 Dec 2027 (Annex III) / 2 Aug 2028 (product AI). | Runtime evidence for the controls institutions must evidence — identity, traceability, human posture, capability, and auditability of AI-assisted actions. Not a compliance claim. |
| SR 26-2 | Replaced SR 11-7 (17 Apr 2026); generative and agentic AI left to the institution's own governance. | The runtime gap: who acted, under which mandate, on which substrate, with which evidence — not a judgment of the model. |
| DORA | In force since 17 Jan 2025 — ICT and third-party risk, incident reporting, resilience testing. | Identity-bound and failure-preserving action: it either completes, or the evidence survives. |
| NIS2 | Operational cyber discipline — supply-chain security, incident handling, cryptography, access control. | Local evidence and an incident-reconstructable action history. |
| Cyber Resilience Act | Reporting from 11 Sep 2026; full application 11 Dec 2027. | The BOM evidence layer: what the box is made of, how it was sealed, and whether runtime evidence links back to the shipped components. |
| ISO/IEC 42001 & NIST AI RMF | AI management standard / voluntary framework (Govern, Map, Measure, Manage). | Not a replacement — runtime evidence backing the frameworks with what actually happened. |
Comparisons That Matter
| Common Mental Model | AInternet Substrate Model | Why It Matters |
|---|---|---|
| Wall-clock timestamp | Causal timevector and receipts | Clocks drift. Causality reconstructs what happened before what. |
| IP address or network location | Runtime identity and route posture | Transport can move; authority should remain bound to identity. |
| Trust score | MUX posture coordinate | You do not rate an actor. You reconstruct the route, action, lane, and causal window. |
| DNS-style name resolution | AINS plus substrate binding | AINS resolves a name; the substrate proves whether the action can carry. |
| Log after execution | Audit as precondition | Authority, surface, and evidence exist before the action, not only after. |
| Loose package ecosystem | One consolidated box | A supported runtime boundary is a cleaner SLA surface. |
Live Audit Evidence Snapshot
| Audit Dimension | Observed State | Governance Meaning |
|---|---|---|
| Binding classes | Human 64 · AI 97 · no-binding/system-infra 73 | Reviewer can separate operator action, autonomous work, and infrastructure noise. |
| Causal integrity | Projection, ledger, and triage intact; one work-ledger break shown | The report is willing to show defects. That is evidence integrity, not cosmetic monitoring. |
| Surfaces | Audit, capture, handshake, and tool surfaces visible in runtime evidence | Authority is tied to declared surfaces instead of informal tool access. |
| Runtime roles | raint/maint/saint/waint/operator/system taxonomy supported | Service and agent roles become inspectable, not hidden inside process logs. |
Honest signal: the current live evidence includes one real causal break in a work ledger. The correct enterprise behavior is to surface it, localize it, and preserve the audit trail rather than hide it behind a green dashboard.
There Is No Separate Trust Layer
Posture replaces scoring
The system does not ask operators to act on a scalar trust score. MUX records route posture: who, where, what, when, and under which causal sequence a route was valid.
Action carries by authority
Work is addressed through actor identity and preserved intent. If a route changes, a network segment fails, or a runtime goes headless, the system keeps the action's authority context inspectable.
The core invariant — causality is forward-only: a valid action must extend a grounded causal parent with a fresh, hardware-bound signature. You cannot insert an action behind one that already happened, or backdate authority — order runs forward from a real parent, never rewritten. That single rule is what makes the trail evidence, not a log you hope is complete.
Substrate-as-a-Service: the offer is a deployable local substrate that other governance, clearance, SIEM, IAM, model, and cloud layers can plug into. A substrate denial is final; a substrate pass means the mechanics can carry, while higher policy layers can still decide whether the action is legitimate.
Why not just wall-clock time? Wall clocks drift, pause, skew, and disagree across machines. They are useful labels for humans, but weak proof of order. The substrate uses causal timevectors and receipts so audit can reconstruct what caused what, even when clocks lie.
Identity-Bearing Storage And Carriers
Bifurcated airlock
Incoming material can be verified, opened into memory, staged, saved, discarded, forwarded, or approved as separate acts. Storage and execution do not collapse into one operation.
Magic bytes before payload
Magic bytes and compact routing headers let the substrate classify priority, intent, lane, and hardware posture before deserializing sealed payload bytes.
Workloads That Ride The Same Rail
Human action
`--human` actions can bind to fresh presence, cadence, and RVP evidence. The operator is measured at runtime rather than assumed from a login.
AI and simulation
An AI job, a spawned runtime, or an interactive workload can move through the same identity, can_carry, MUX, carrier, and audit path.
Payments, voice, IoT, files
Payment APIs, telephony/voice lanes, IoT commands, and sealed file drops are all actions with authority, custody, posture, and receipts.
Not theoretical: the same substrate family has carried payment-app integration work, COBOL/C++ backend/API patterns, voice lanes, file drops, IoT paths, and AI workloads. AI is one tenant on the rail, not the definition of the rail.
The Same Substrate, Phone To Router
Nothing in the rail assumes a datacenter. The same identity-addressed model runs across the whole form-factor spectrum — from an app in your pocket down to a low-power router on a shelf — because the address is who, not where.
On the handset
Native mobile clients are in active development: a voice-first assistant and an AInternet client that carry identity, presence, and lanes on the device. The substrate in your pocket, not just in a rack.
Down to a commodity router
The same substrate has been carried onto a low-power MIPS router running Asterisk, where a call is placed on JIS identity — not a phone number, not an IP. The line exists because of the binding; it is reachable by the bound identity and no one else.
Why the range matters
One coherent identity, audit, and carrier model — unchanged from cloud to phone to a device that costs less than lunch. Reach that is broad by construction, not by porting effort per platform.
Identity-native calling: because a line exists only through its binding, it cannot be reached — or made to ring — by anyone but the bound identity. Identity decides the very existence of the line, down into the telephony layer. That is the same principle as the audit gate and the sealed carrier, expressed as a phone call.
One Box, Familiar Enterprise Controls
| Enterprise Primitive | AInternet / TIBET Surface | Control Value |
|---|---|---|
| Machine floor / capacity control | can_carry, sys-bom, mux-bom, substrate anchor, hardware/runtime posture | The box proves whether it can bear the workload before it runs. |
| Supply-chain and composition | SBOM, AI-SBOM, CBOM, hash manifests, release signatures | The box can explain what it is made of, what was shipped, and what changed. |
| Identity provider / service accounts | .aint/.waint/.raint/.paint identity, JIS binding, runtime roles | Who acted remains stable across network and session changes. |
| Network access control | MUX posture, SNAFT posture, dark-by-default routes, surface grants | Access is explicit, route posture is auditable, and refusals are part of the record. |
| Runtime isolation | IAB broker, ignition/KVM/microVM lanes, golden rootfs | Agent work occurs inside declared runtime boundaries. |
| Human presence and cadence | RVP, `--human`, cadence measurement, approval lanes | Human authority is measured fresh for sensitive actions and handoffs. |
| Message queue / command bus | MUX, cap-bus, lanes, I-Poll, `.tza` drops, cmail actions | Intent can move between people, agents, nodes, and workstreams with custody intact. |
| Storage / quarantine | bifurcated airlock, cmail attachments, sealed carrier store | Data can be held and inspected without automatically persisting or executing it. |
| Audit log / SIEM feed | TIBET ledger, audit projection, tibet-audit report | Events can be inspected by role, binding, surface, and causal integrity. |
| Causal ordering | tibet-timevector, continuity receipts, causal chain checks | Audit follows happened-before evidence rather than assuming synchronized wall-clock truth. |
| Change control | genesis/t-1, triage, cortex leveling, cap-bus, continuity receipts | Capability raises and on-behalf-of actions become governed transitions, not side effects. |
| Reporting and assurance | tibet-report, tibet-audit, conformance vectors | Evidence can be packaged for audit, architecture, and risk review. |
Layering Principle
| Layer | Owns | Rule |
|---|---|---|
| L1 Run | Identity, boot, routes, posture, carrier, continuity, causal ordering | Cannot silently degrade. If it cannot carry the claim, the box refuses or lowers posture. |
| L2 Prove | Audit, receipts, manifests, conformance, reports | May degrade visibly. Missing proof tooling disables proof, not the node. |
| L3 Operate | CLI, cockpit, tools, agents, workstreams | May go headless. Humans and agents can operate without bypassing the runtime floor. |
Open Substrate, Supported Boundary
AInternet is the commons. Humotica is the supported enterprise distribution. The protocol and substrate path stay open and inspectable; Humotica provides the supported product boundary — integration, evidence packaging, hardening, security response, conformance, and SLA. The closest commercial pattern is Red Hat in spirit: an open core anyone can use, test, fork, and contribute to, with a company that carries the supported layer, stewarded by a BDFL over protocol coherence.
Humotica is looking for partnerships — not to close the substrate or make a single-vendor claim, but to carry runtime-bound evidence, BOMs, machine-floor measurement, identity-bound action, and conformance into production-grade validation with serious operators, risk teams, auditors, and integrators. The next step is controlled validation: compare the substrate against existing enterprise controls, run it locally, identify the evidence gap it closes, and decide where support, conformance, or co-development should start.
| Engagement Step | What Happens | Why It Helps A Buyer |
|---|---|---|
| Technical mapping | Map live audit evidence against IAM, AI governance, SIEM, supply-chain, and GRC controls. | Shows the action-evidence gap without asking the buyer to replace existing tools. |
| Local evaluation | Run AInternet-in-a-box in a controlled lab, node, or risk sandbox. | Proves the substrate on their own floor. |
| Supported pilot | Define scope, node/fleet boundary, evidence exports, support channel, and response expectations. | Creates the first paid support boundary without premature platform sprawl. |
| Enterprise subscription | Private deployment, update cadence, conformance pack, evidence packaging, security response, SLA. | Turns an open substrate into a supportable enterprise service. |
| Co-development | Protocol / package work, conformance vectors, upstream-compatible contributions. | Lets multiple parties build the shared solution without fragmenting the substrate. |
No price in this leave-behind, by design. A hard number narrows the discussion before you have mapped the substrate against your controls, risk posture, and deployment constraints. The better first step: map this against your current IAM, AI governance, SIEM, supply-chain, and GRC controls, then identify the action-evidence gap and the right support boundary.
How To Read The Offer
Not another agent app
This is substrate: identity, runtime boundary, carrier grammar, authority path, and evidence. Existing AI, GRC, SIEM, IAM, and cloud controls can remain around it.
One SLA surface
The package ecosystem proves breadth; the box creates the supported boundary. An SLA on one consolidated runtime is a cleaner promise than an SLA across 100+ moving packages.
Compliance-enabling, not self-certifying
The system provides technical evidence and control surfaces. A regulated institution still maps those controls to its legal, supervisory, and internal obligations.
Tested under pressure
The posture is red-team responsive: failures become receipts, default-deny routes, patches, and cleaner gates rather than exceptions hidden from audit.