Part VI · Evaluation, Economics, and Research Positioning
Economic Architecture, Sovereignty, and Decentralized Intelligence
AIOS begins with a product and architecture decision: the durable intelligence of a person or organization should remain in a system they govern. Canonical files, relationships, provenance, evaluation criteria, permissions, and accepted judgments belong to that durable layer. Models contribute reasoning to it, but no model provider needs to own the complete relationship among the person, the work, and its history.
Semantic capitalAccepted-outcome economicsLocal custodyProvider portability
For an organization, that durable layer can productize intent as locally installed operating knowledge. Purpose, expertise, established best practices, document standards, workflows, evidence requirements, and operational boundaries can become inspectable and revisable ground that shapes reasoning and production where the work occurs. Standardization then concerns the quality conditions, records, and authorized processes of work—not automatic agreement on every conclusion or a transfer of semantic authority to the software.
That decision has economic consequences. Local custody can turn accumulated work into reusable semantic capital. Purpose-composed context can reduce repeated reconstruction. Policy-gated routing can reserve expensive or externally exposed computation for the cognitive movements that actually require it. Verification and reintegration can convert a model response into an accepted outcome rather than another fragment that must later be rediscovered or repaired.
None of these gains is automatic. The architecture creates a way to pursue them and a way to measure whether they are real.
Local semantic capital to accepted outcomes
Locally governed knowledge composes movement-specific context, routes eligible computation, and returns verified outcomes to the durable system.
Text equivalent
Local custody — files · relationships · authority → Governed semantic capital — accepted knowledge · methods · tests; Governed semantic capital — accepted knowledge · methods · tests → Purpose-composed context — for one cognitive movement; Purpose-composed context — for one cognitive movement → Policy-gated routing — local · specialized · confidential · frontier; Policy-gated routing — local · specialized · confidential · frontier → Verification and human judgment; Verification and human judgment → Accepted outcome.
Follow the loop rather than any single call: local custody becomes reusable ground, ground is composed for one movement, policy excludes ineligible routes before capability and cost selection, and human verification turns a result into an accepted outcome that can correct or extend the capital.
Does not establish Local custody is not universal local inference, routing is not model equivalence, and the loop is an architectural hypothesis—not evidence of lower total cost or infrastructure displacement.
The loop matters more than any individual model call. It is the economic expression of the same whole-system architecture described throughout this overview.
Durable intelligence as semantic capital
People and institutions already accumulate a form of capital that conventional software handles poorly: distinctions that prevent recurring mistakes; trusted sources; definitions and standards; decision rationales; reusable methods; relationships among artifacts; known exceptions; tests; review practices; and records of what failed and why.
AIOS calls this semantic capital when the structure remains intelligible, governed, and useful in future work. It is not simply a large memory store. A transcript, embedding index, or folder becomes capital only when the system can still tell:
- what a claim means and what purpose it served;
- where it came from and which source state it reflects;
- whether it is proposed, accepted, qualified, disputed, or superseded;
- who had authority to approve it;
- where it applies and where it does not;
- what evidence or later decision would reopen it; and
- how it should enter a new cognitive movement without displacing the present situation.
This capital can lower the cost of future work by reducing repeated explanation, search, reconstruction, correction, and institutional forgetting. It can also improve continuity when a project pauses, a collaborator changes, or a model is replaced.
At organizational scale, it can also reduce the repeated cost of translating intent into practice. A purpose-linked local knowledge system can make the same accepted evidence standard, document contract, workflow, or operating boundary available across many teams while preserving which version applied, which local authority accepted it, and where an authorized departure occurred. Organizational knowledge becomes an operating asset only when people can inspect and revise that path from purpose to practice; an invisible policy prompt or copied folder is not equivalent semantic capital.
But every durable system also accumulates semantic debt: stale conclusions, unresolved contradictions, compressed context that has lost its qualifications, duplicated representations, poisoned memory, unclear permissions, maintenance burden, and rules that persist after their reasons have disappeared. The relevant proposition is therefore:
net semantic capital
= future value of reuse, continuity, and correction
- cost of staleness, contradiction, privacy, maintenance, and rollback
More memory is not necessarily more value. AIOS must earn compounding advantage through selective promotion, provenance, correction, retirement, and periodic reconstruction from canonical artifacts, sources, and standing-aware records. The experiments in Capability Horizons, Experiments, Proof, and Falsification are where this claim becomes testable rather than rhetorical.
The economic unit is the accepted outcome
Token price is useful for buying inference. It is not a sufficient measure of the cost of completed reasoning work.
The relevant unit is an accepted outcome: a result that meets the governing purpose, reaches an adequate quality threshold, respects authority, survives the required checks, and lands coherently in the work that follows. Its cost includes more than the successful model call:
accepted-task cost
= inference and hardware
+ context construction and retrieval
+ orchestration and tool use
+ retries and escalation
+ human review and correction
+ evidence, assurance, and compliance work
+ synchronization and continuity
+ failures, regressions, and recovery
This changes how model and architecture choices should be evaluated. A low-cost call that creates plausible but unusable output may be expensive once review, rework, or downstream failure is counted. A more capable model may be economical when it resolves a difficult movement once. A smaller or local model may be economical when composed context, a bounded task, and a strong verifier let it satisfy the same acceptance criterion. A complex multi-agent workflow may add value in one task and create costly coordination overhead in another.
The Stanford AI Index 2025 and Epoch AI’s inference-price analysis document rapid declines in the price of reaching selected benchmark capability levels. That is important, but those measures do not include the complete production system. A 2025 preprint on the cost of dynamic reasoning shows why the distinction matters: agentic designs can multiply model calls, token use, latency, energy, and run-to-run cost, with diminishing returns in some settings.
AIOS therefore makes no general promise that more scaffolding is cheaper. Its economic claim is conditional: the right structure should improve accepted outcomes per unit of total cost, and unnecessary structure should be removed when it does not.
Local custody, plural execution
Local-first means local custody, not universal local execution. The durable system can remain person- or institution-controlled while particular reasoning movements use different computational resources.
| Execution path | Appropriate when | Required boundary |
|---|---|---|
| On-device or local | Privacy, latency, offline continuity, or bounded repeated work dominates | Device security, resource limits, model adequacy, and local lifecycle controls |
| Specialized model or tool | A narrow operation has a strong domain fit or external verifier | Explicit scope, provenance, versioning, and result validation |
| Confidential or institution-governed service | Shared infrastructure is needed inside a defined trust and legal boundary | Contract, identity, logging, retention, jurisdiction, and access controls |
| Frontier service | Novelty, ambiguity, broad knowledge, or high reasoning difficulty requires it | Minimum necessary disclosure, policy eligibility, evidence, and reintegration as a proposal |
Routing should occur at the level of a bounded cognitive movement, not an entire project. It begins by excluding endpoints that are not eligible under privacy, authorization, disclosure, jurisdiction, tool-access, or consequence rules. Only then should the system choose the least-cost eligible model–harness configuration expected to meet the quality threshold. Failed checks, weak evidence, or unfamiliar conditions should trigger escalation.
PalmBench supports the practicality of bounded on-device language-model workloads while documenting device-dependent capability and efficiency tradeoffs. RouteLLM shows that routing can reduce inference cost at matched benchmark quality. Neither establishes a universal local replacement for frontier models, and current routers remain sensitive to the model portfolio, evaluator, endpoint, and task distribution.
This is also the bounded meaning of personal AGI in AIOS: not one small model that possesses every capability, but a locally governed general reasoning system that can compose durable knowledge and selectively call different models without surrendering its continuity or authority to any one of them.
Sovereignty includes the ability to leave
Sovereignty is weak if a person can download files but cannot reconstruct how the system works. A credible provider exit requires three kinds of portability:
- Technical portability: canonical artifacts, metadata, identities, versions, and relationships can be moved or rebuilt through documented formats.
- Behavioral portability: evaluations, examples, routing rules, and regression tests reveal when a new model or provider changes important behavior.
- Semantic portability: standing, purpose, provenance, authority, exceptions, and correction history remain intelligible after the move.
The distinction is economically material. The UK Competition and Markets Authority’s cloud-services investigation documents technical, commercial, licensing, and operational barriers to switching and multicloud use. A 2026 peer-reviewed study by Jahani and colleagues shows, in bounded experimental tasks, that users adapt their prompting behavior to model behavior and that the amount of adaptation varies by task. Exporting content alone therefore may not preserve the human–model practices that produced useful results.
AIOS addresses this by treating canonical local files, relations, evaluation criteria, and accepted practices as exit assets. That can improve continuity and bargaining power. It does not make migration effortless: schemas may become obscure, embeddings may be provider-specific, local conventions may be undocumented, and behavior can still shift under a new model.
Privacy and regulated use are lifecycle properties
Local custody can reduce unnecessary disclosure and make important controls inspectable. It does not automatically produce privacy, security, or legal compliance.
The relevant boundary extends across the complete lifecycle: imported files, prompt injection, retrieval indexes, embeddings, memory promotion, caches, logs, backups, synchronization, software updates, model weights, tool calls, external endpoints, generated outputs, endpoint compromise, and the hardware and software supply chain. A confidential document stored locally can still be exposed by a malicious tool result, an overbroad sync rule, an unreviewed log, or a model call that receives more context than it needs.
AIOS can nevertheless be compliance-enabling because its architecture can preserve an evidence chain across:
purpose → source state → composed context → model and version
→ permissions → tool calls → proposed effect → exact effect
→ tests → human approvals → monitoring → correction or revocation
For organizational knowledge, the chain also needs to preserve which package and version supplied the applicable standard, its scope and guidance strength, the authority and exception policy under which it operated, and any authorized departure. Epistemic standing, guidance strength, exception policy, scope, and authority remain separate even when one interface presents them together. This makes the operating ground auditable without implying that a recorded decision was correct or that an audit trail by itself satisfies a regulation.
That chain can support documentation, monitoring, review, audit, data minimization, and incident reconstruction. It can also give a regulated organization clearer places to attach its own policies and legal obligations. The EU AI Act makes lifecycle documentation, logging, human oversight, robustness, and post-market monitoring important for covered high-risk systems. NIST AI 800-4 similarly emphasizes monitoring that joins technical, operational, human, security, compliance, and societal evidence.
Architecture can make those practices possible and less fragmented. Only the applicable institution, process, and evidence can establish compliance in a particular case.
Attestable domain packages and peer intelligence
Local ownership does not require isolated knowledge. A person, professional community, company, university, public institution, or peer network could publish a bounded domain package containing selected sources, relationships, definitions, methods, evaluations, and operating guidance. A recipient could inspect it, verify its provenance, combine it with private local knowledge, and decide what standing it receives.
The package should be called attestable when its origin, contents, versions, and relevant actions can be checked. It should be called certified only when a named authority has applied a defined certification process. A signature can establish who issued a claim and whether it changed; it does not establish truth, freshness, legal authority, shared meaning, or fitness for a new context.
Existing standards make parts of this architecture practical. RO-Crate 1.3 provides a way to package files with structured descriptions of entities, actions, provenance, and relationships. W3C Verifiable Credentials 2.0 provides a data model for issuer-bound, verifiable claims. These can support exchange without making a central graph, protocol, or institution the owner of every domain’s meaning.
The larger institutional possibility is a network of self-governing intelligence systems joined by shared evidence contracts. An organization could standardize identity, permissions, provenance, return conditions, revocation, and audit while letting teams retain local vocabularies and judgments. Peer communities could circulate inspectable methods without exposing all private context. Public-interest institutions could maintain trusted packages that local systems adapt rather than merely query.
This is decentralization at the level of durable meaning and authority. It is compatible with centralized compute where centralized compute remains useful.
For packages to operate across a fleet of local knowledge systems, distribution needs a complete lifecycle:
stable package identity and version
→ dependency and compatibility declaration
→ signed distribution where issuer identity and integrity matter
→ local verification and acceptance
→ permitted local variation or authorized departure
→ supersession, revocation, migration, or rollback
The signature and version can establish which package was distributed; they do not establish truth, fitness, adoption, or compliance. Local installations do not remain consistent automatically. Devices can be offline, teams can defer an update, dependencies can differ, and authorized departures can produce legitimate variation. A central issuer can publish, attest, supersede, or revoke a package, but each governed installation must determine and record what actually became active locally. Unknown or unreported installations remain unknown rather than being counted as conforming.
This creates both value and cost. Reusable packages can reduce repeated method authoring, training, document repair, workflow interpretation, and assurance preparation. Fleet operation adds compatibility testing, distribution security, local review, divergence analysis, revocation, rollback, and stewardship. The economic question is whether shared semantic capital and purpose traceability reduce total coordination and failure cost more than this lifecycle costs to maintain.
Infrastructure displacement is a serious conditional implication
If locally governed semantic capital and selective routing work at scale, the application layer of AI could change materially. The likely effect is not the disappearance of frontier laboratories or data centers. It is a redistribution of which work must be reconstructed and executed remotely, which assets create switching power, and who owns the continuing intelligence relationship.
| Potential effect | Architectural implication |
|---|---|
| Repeated context reconstruction declines | More purpose, history, and accepted knowledge are composed from durable local ground |
| Some remote inference is displaced | Bounded movements run locally or through specialized tools when they meet the threshold |
| Provider-owned application memory becomes less central | Canonical continuity resides with the person or institution |
| Device, synchronization, security, and stewardship work grows | Costs move to new layers rather than disappearing |
| Frontier training, chips, burst capacity, and difficult inference remain concentrated | Upstream infrastructure continues to matter |
| New uses become economical | Lower friction can increase total reasoning and create rebound in calls, energy, and review |
The magnitude of this shift is unknown. It depends on local-model capability, hardware, energy, maintenance, assurance requirements, task mix, and whether the harness actually reduces rework. The International Energy Agency’s analysis of energy and AI reinforces the scale and concentration of current infrastructure while also showing why local execution cannot be described as costless or energy-free.
The serious thesis is therefore not “AIOS eliminates centralized infrastructure.” It is that centralized infrastructure may become a selectively invoked capability layer rather than the default owner of the application, memory, context, and user relationship. That is a potentially large economic change even if frontier compute remains highly concentrated.
AI as electricity: the useful part of the analogy
AI is often compared with electricity. The analogy is useful when it points to complementary redesign. Electrification did not create its full productive effect merely by replacing one power source with another; institutions and production systems had to reorganize around what distributed electric power made possible. The OECD’s 2025 assessment concludes that generative AI plausibly has important characteristics of a general-purpose technology while emphasizing uncertainty about diffusion, complementary investment, and productivity effects.
AIOS is one proposal for that complementary redesign at the level of knowledge work. Models become broadly available reasoning resources. The surrounding architecture determines how purpose, context, memory, evidence, authority, tools, and results are organized so that capability becomes usable over time.
The analogy stops there. Electricity is comparatively standardized, fungible, and measurable. Reasoning is semantic, contextual, variable, and entangled with human judgment. Model outputs cannot be treated as homogeneous current, and the analogy does not establish inevitable productivity, a particular regulatory regime, or a simple grid-versus-device future.
The economic claim and its evidence boundary
AIOS preserves an ambitious possibility: durable intelligence can move toward people and institutions while models remain plural, selectively invoked resources. If the architecture works, it could reduce repeated reconstruction, improve provider exit, support private and regulated reasoning, make domain expertise portable, and shift part of the AI application economy away from centralized ownership.
The evidence currently supports the mechanisms and boundary conditions more strongly than the total outcome. On-device inference is viable for bounded workloads. Harness and routing choices can alter cost and realized capability. Cloud switching has technical and behavioral dimensions. Provenance standards can carry attestable relationships. Regulation creates demand for lifecycle evidence. None of this yet proves the magnitude of AIOS’s cumulative advantage or infrastructure displacement.
Those are system-level claims. They must be evaluated through accepted-task cost, quality, privacy, continuity, switching, assurance, human authority, and semantic debt across time. The research foundation descends through the system capability brief, local-sovereign AI brief, and economics and institutions brief, each of which links to its full memo and original sources.
The next chapter places that economic architecture inside the broader research landscape and explains precisely what kind of contribution AIOS claims.