AIOS Proresearch
AIOS Intelligence System · Research Overview

Part VI · Evaluation, Economics, and Research Positioning

Economic Architecture, Sovereignty, and Decentralized Intelligence

AIOS begins with a product and architecture decision: the durable intelligence of a person or organization should remain in a system they govern. Canonical files, relationships, provenance, evaluation criteria, permissions, and accepted judgments belong to that durable layer. Models contribute reasoning to it, but no model provider needs to own the complete relationship among the person, the work, and its history.

Knowledge, history, standards, and permissions stay under a person’s or organization’s control while different models are used selectively. The economic question is whether this lowers the total cost of outcomes that are actually usable and accepted.

Semantic capitalAccepted-outcome economicsLocal custodyProvider portability

For an organization, that durable layer can productize intent as locally installed operating knowledge. Purpose, expertise, established best practices, document standards, workflows, evidence requirements, and operational boundaries can become inspectable and revisable ground that shapes reasoning and production where the work occurs. Standardization then concerns the quality conditions, records, and authorized processes of work—not automatic agreement on every conclusion or a transfer of semantic authority to the software.

That decision has economic consequences. Local custody can turn accumulated work into reusable semantic capital. Purpose-composed context can reduce repeated reconstruction. Policy-gated routing can reserve expensive or externally exposed computation for the cognitive movements that actually require it. Verification and reintegration can convert a model response into an accepted outcome rather than another fragment that must later be rediscovered or repaired.

None of these gains is automatic. The architecture creates a way to pursue them and a way to measure whether they are real.

Local semantic capital to accepted outcomes

Locally governed knowledge composes movement-specific context, routes eligible computation, and returns verified outcomes to the durable system.

flowchart LR C["Local custody\nfiles · relationships · authority"] --> S["Governed semantic capital\naccepted knowledge · methods · tests"] S --> X["Purpose-composed context\nfor one cognitive movement"] X --> R["Policy-gated routing\nlocal · specialized · confidential · frontier"] R --> V["Verification and human judgment"] V --> O["Accepted outcome"] O -->|"correction · promotion · reintegration"| S
Accepted-outcome economics · canonical25-economic-architecture-sovereignty-and-decentralized-intelligence--m01.mmd
Text equivalent

Local custody — files · relationships · authority → Governed semantic capital — accepted knowledge · methods · tests; Governed semantic capital — accepted knowledge · methods · tests → Purpose-composed context — for one cognitive movement; Purpose-composed context — for one cognitive movement → Policy-gated routing — local · specialized · confidential · frontier; Policy-gated routing — local · specialized · confidential · frontier → Verification and human judgment; Verification and human judgment → Accepted outcome.

Follow the loop rather than any single call: local custody becomes reusable ground, ground is composed for one movement, policy excludes ineligible routes before capability and cost selection, and human verification turns a result into an accepted outcome that can correct or extend the capital.

Does not establish Local custody is not universal local inference, routing is not model equivalence, and the loop is an architectural hypothesis—not evidence of lower total cost or infrastructure displacement.

The loop matters more than any individual model call. It is the economic expression of the same whole-system architecture described throughout this overview.

Durable intelligence as semantic capital

People and institutions already accumulate a form of capital that conventional software handles poorly: distinctions that prevent recurring mistakes; trusted sources; definitions and standards; decision rationales; reusable methods; relationships among artifacts; known exceptions; tests; review practices; and records of what failed and why.

AIOS calls this semantic capital when the structure remains intelligible, governed, and useful in future work. It is not simply a large memory store. A transcript, embedding index, or folder becomes capital only when the system can still tell:

This capital can lower the cost of future work by reducing repeated explanation, search, reconstruction, correction, and institutional forgetting. It can also improve continuity when a project pauses, a collaborator changes, or a model is replaced.

At organizational scale, it can also reduce the repeated cost of translating intent into practice. A purpose-linked local knowledge system can make the same accepted evidence standard, document contract, workflow, or operating boundary available across many teams while preserving which version applied, which local authority accepted it, and where an authorized departure occurred. Organizational knowledge becomes an operating asset only when people can inspect and revise that path from purpose to practice; an invisible policy prompt or copied folder is not equivalent semantic capital.

But every durable system also accumulates semantic debt: stale conclusions, unresolved contradictions, compressed context that has lost its qualifications, duplicated representations, poisoned memory, unclear permissions, maintenance burden, and rules that persist after their reasons have disappeared. The relevant proposition is therefore:

net semantic capital
= future value of reuse, continuity, and correction
- cost of staleness, contradiction, privacy, maintenance, and rollback

More memory is not necessarily more value. AIOS must earn compounding advantage through selective promotion, provenance, correction, retirement, and periodic reconstruction from canonical artifacts, sources, and standing-aware records. The experiments in Capability Horizons, Experiments, Proof, and Falsification are where this claim becomes testable rather than rhetorical.

The economic unit is the accepted outcome

Token price is useful for buying inference. It is not a sufficient measure of the cost of completed reasoning work.

The relevant unit is an accepted outcome: a result that meets the governing purpose, reaches an adequate quality threshold, respects authority, survives the required checks, and lands coherently in the work that follows. Its cost includes more than the successful model call:

accepted-task cost
= inference and hardware
+ context construction and retrieval
+ orchestration and tool use
+ retries and escalation
+ human review and correction
+ evidence, assurance, and compliance work
+ synchronization and continuity
+ failures, regressions, and recovery

This changes how model and architecture choices should be evaluated. A low-cost call that creates plausible but unusable output may be expensive once review, rework, or downstream failure is counted. A more capable model may be economical when it resolves a difficult movement once. A smaller or local model may be economical when composed context, a bounded task, and a strong verifier let it satisfy the same acceptance criterion. A complex multi-agent workflow may add value in one task and create costly coordination overhead in another.

The Stanford AI Index 2025 and Epoch AI’s inference-price analysis document rapid declines in the price of reaching selected benchmark capability levels. That is important, but those measures do not include the complete production system. A 2025 preprint on the cost of dynamic reasoning shows why the distinction matters: agentic designs can multiply model calls, token use, latency, energy, and run-to-run cost, with diminishing returns in some settings.

AIOS therefore makes no general promise that more scaffolding is cheaper. Its economic claim is conditional: the right structure should improve accepted outcomes per unit of total cost, and unnecessary structure should be removed when it does not.

Local custody, plural execution

Local-first means local custody, not universal local execution. The durable system can remain person- or institution-controlled while particular reasoning movements use different computational resources.

Execution pathAppropriate whenRequired boundary
On-device or localPrivacy, latency, offline continuity, or bounded repeated work dominatesDevice security, resource limits, model adequacy, and local lifecycle controls
Specialized model or toolA narrow operation has a strong domain fit or external verifierExplicit scope, provenance, versioning, and result validation
Confidential or institution-governed serviceShared infrastructure is needed inside a defined trust and legal boundaryContract, identity, logging, retention, jurisdiction, and access controls
Frontier serviceNovelty, ambiguity, broad knowledge, or high reasoning difficulty requires itMinimum necessary disclosure, policy eligibility, evidence, and reintegration as a proposal

Routing should occur at the level of a bounded cognitive movement, not an entire project. It begins by excluding endpoints that are not eligible under privacy, authorization, disclosure, jurisdiction, tool-access, or consequence rules. Only then should the system choose the least-cost eligible model–harness configuration expected to meet the quality threshold. Failed checks, weak evidence, or unfamiliar conditions should trigger escalation.

PalmBench supports the practicality of bounded on-device language-model workloads while documenting device-dependent capability and efficiency tradeoffs. RouteLLM shows that routing can reduce inference cost at matched benchmark quality. Neither establishes a universal local replacement for frontier models, and current routers remain sensitive to the model portfolio, evaluator, endpoint, and task distribution.

This is also the bounded meaning of personal AGI in AIOS: not one small model that possesses every capability, but a locally governed general reasoning system that can compose durable knowledge and selectively call different models without surrendering its continuity or authority to any one of them.

Sovereignty includes the ability to leave

Sovereignty is weak if a person can download files but cannot reconstruct how the system works. A credible provider exit requires three kinds of portability:

  1. Technical portability: canonical artifacts, metadata, identities, versions, and relationships can be moved or rebuilt through documented formats.
  2. Behavioral portability: evaluations, examples, routing rules, and regression tests reveal when a new model or provider changes important behavior.
  3. Semantic portability: standing, purpose, provenance, authority, exceptions, and correction history remain intelligible after the move.

The distinction is economically material. The UK Competition and Markets Authority’s cloud-services investigation documents technical, commercial, licensing, and operational barriers to switching and multicloud use. A 2026 peer-reviewed study by Jahani and colleagues shows, in bounded experimental tasks, that users adapt their prompting behavior to model behavior and that the amount of adaptation varies by task. Exporting content alone therefore may not preserve the human–model practices that produced useful results.

AIOS addresses this by treating canonical local files, relations, evaluation criteria, and accepted practices as exit assets. That can improve continuity and bargaining power. It does not make migration effortless: schemas may become obscure, embeddings may be provider-specific, local conventions may be undocumented, and behavior can still shift under a new model.

Privacy and regulated use are lifecycle properties

Local custody can reduce unnecessary disclosure and make important controls inspectable. It does not automatically produce privacy, security, or legal compliance.

The relevant boundary extends across the complete lifecycle: imported files, prompt injection, retrieval indexes, embeddings, memory promotion, caches, logs, backups, synchronization, software updates, model weights, tool calls, external endpoints, generated outputs, endpoint compromise, and the hardware and software supply chain. A confidential document stored locally can still be exposed by a malicious tool result, an overbroad sync rule, an unreviewed log, or a model call that receives more context than it needs.

AIOS can nevertheless be compliance-enabling because its architecture can preserve an evidence chain across:

purpose → source state → composed context → model and version
→ permissions → tool calls → proposed effect → exact effect
→ tests → human approvals → monitoring → correction or revocation

For organizational knowledge, the chain also needs to preserve which package and version supplied the applicable standard, its scope and guidance strength, the authority and exception policy under which it operated, and any authorized departure. Epistemic standing, guidance strength, exception policy, scope, and authority remain separate even when one interface presents them together. This makes the operating ground auditable without implying that a recorded decision was correct or that an audit trail by itself satisfies a regulation.

That chain can support documentation, monitoring, review, audit, data minimization, and incident reconstruction. It can also give a regulated organization clearer places to attach its own policies and legal obligations. The EU AI Act makes lifecycle documentation, logging, human oversight, robustness, and post-market monitoring important for covered high-risk systems. NIST AI 800-4 similarly emphasizes monitoring that joins technical, operational, human, security, compliance, and societal evidence.

Architecture can make those practices possible and less fragmented. Only the applicable institution, process, and evidence can establish compliance in a particular case.

Attestable domain packages and peer intelligence

Local ownership does not require isolated knowledge. A person, professional community, company, university, public institution, or peer network could publish a bounded domain package containing selected sources, relationships, definitions, methods, evaluations, and operating guidance. A recipient could inspect it, verify its provenance, combine it with private local knowledge, and decide what standing it receives.

The package should be called attestable when its origin, contents, versions, and relevant actions can be checked. It should be called certified only when a named authority has applied a defined certification process. A signature can establish who issued a claim and whether it changed; it does not establish truth, freshness, legal authority, shared meaning, or fitness for a new context.

Existing standards make parts of this architecture practical. RO-Crate 1.3 provides a way to package files with structured descriptions of entities, actions, provenance, and relationships. W3C Verifiable Credentials 2.0 provides a data model for issuer-bound, verifiable claims. These can support exchange without making a central graph, protocol, or institution the owner of every domain’s meaning.

The larger institutional possibility is a network of self-governing intelligence systems joined by shared evidence contracts. An organization could standardize identity, permissions, provenance, return conditions, revocation, and audit while letting teams retain local vocabularies and judgments. Peer communities could circulate inspectable methods without exposing all private context. Public-interest institutions could maintain trusted packages that local systems adapt rather than merely query.

This is decentralization at the level of durable meaning and authority. It is compatible with centralized compute where centralized compute remains useful.

For packages to operate across a fleet of local knowledge systems, distribution needs a complete lifecycle:

stable package identity and version
  → dependency and compatibility declaration
    → signed distribution where issuer identity and integrity matter
      → local verification and acceptance
        → permitted local variation or authorized departure
          → supersession, revocation, migration, or rollback

The signature and version can establish which package was distributed; they do not establish truth, fitness, adoption, or compliance. Local installations do not remain consistent automatically. Devices can be offline, teams can defer an update, dependencies can differ, and authorized departures can produce legitimate variation. A central issuer can publish, attest, supersede, or revoke a package, but each governed installation must determine and record what actually became active locally. Unknown or unreported installations remain unknown rather than being counted as conforming.

This creates both value and cost. Reusable packages can reduce repeated method authoring, training, document repair, workflow interpretation, and assurance preparation. Fleet operation adds compatibility testing, distribution security, local review, divergence analysis, revocation, rollback, and stewardship. The economic question is whether shared semantic capital and purpose traceability reduce total coordination and failure cost more than this lifecycle costs to maintain.

Infrastructure displacement is a serious conditional implication

If locally governed semantic capital and selective routing work at scale, the application layer of AI could change materially. The likely effect is not the disappearance of frontier laboratories or data centers. It is a redistribution of which work must be reconstructed and executed remotely, which assets create switching power, and who owns the continuing intelligence relationship.

Potential effectArchitectural implication
Repeated context reconstruction declinesMore purpose, history, and accepted knowledge are composed from durable local ground
Some remote inference is displacedBounded movements run locally or through specialized tools when they meet the threshold
Provider-owned application memory becomes less centralCanonical continuity resides with the person or institution
Device, synchronization, security, and stewardship work growsCosts move to new layers rather than disappearing
Frontier training, chips, burst capacity, and difficult inference remain concentratedUpstream infrastructure continues to matter
New uses become economicalLower friction can increase total reasoning and create rebound in calls, energy, and review

The magnitude of this shift is unknown. It depends on local-model capability, hardware, energy, maintenance, assurance requirements, task mix, and whether the harness actually reduces rework. The International Energy Agency’s analysis of energy and AI reinforces the scale and concentration of current infrastructure while also showing why local execution cannot be described as costless or energy-free.

The serious thesis is therefore not “AIOS eliminates centralized infrastructure.” It is that centralized infrastructure may become a selectively invoked capability layer rather than the default owner of the application, memory, context, and user relationship. That is a potentially large economic change even if frontier compute remains highly concentrated.

AI as electricity: the useful part of the analogy

AI is often compared with electricity. The analogy is useful when it points to complementary redesign. Electrification did not create its full productive effect merely by replacing one power source with another; institutions and production systems had to reorganize around what distributed electric power made possible. The OECD’s 2025 assessment concludes that generative AI plausibly has important characteristics of a general-purpose technology while emphasizing uncertainty about diffusion, complementary investment, and productivity effects.

AIOS is one proposal for that complementary redesign at the level of knowledge work. Models become broadly available reasoning resources. The surrounding architecture determines how purpose, context, memory, evidence, authority, tools, and results are organized so that capability becomes usable over time.

The analogy stops there. Electricity is comparatively standardized, fungible, and measurable. Reasoning is semantic, contextual, variable, and entangled with human judgment. Model outputs cannot be treated as homogeneous current, and the analogy does not establish inevitable productivity, a particular regulatory regime, or a simple grid-versus-device future.

The economic claim and its evidence boundary

AIOS preserves an ambitious possibility: durable intelligence can move toward people and institutions while models remain plural, selectively invoked resources. If the architecture works, it could reduce repeated reconstruction, improve provider exit, support private and regulated reasoning, make domain expertise portable, and shift part of the AI application economy away from centralized ownership.

The evidence currently supports the mechanisms and boundary conditions more strongly than the total outcome. On-device inference is viable for bounded workloads. Harness and routing choices can alter cost and realized capability. Cloud switching has technical and behavioral dimensions. Provenance standards can carry attestable relationships. Regulation creates demand for lifecycle evidence. None of this yet proves the magnitude of AIOS’s cumulative advantage or infrastructure displacement.

Those are system-level claims. They must be evaluated through accepted-task cost, quality, privacy, continuity, switching, assurance, human authority, and semantic debt across time. The research foundation descends through the system capability brief, local-sovereign AI brief, and economics and institutions brief, each of which links to its full memo and original sources.

The next chapter places that economic architecture inside the broader research landscape and explains precisely what kind of contribution AIOS claims.