Source-linked AI summary
The Civilization Framework: Sovereign-Anchored Communication Between Personal Multi-Agent Systems
Guangjun Liu
TL;DR
The paper addresses the loss of context when humans relay information between separate AI systems. It proposes a sovereign-anchored Civilization Framework and Embassy Protocol, then experimentally examines whether arrival order gives upstream claims undue authority. In one frontier model, incorrect claims arriving first were adopted more often under restricted verification, but the registered round is classified as exploratory because a tool-use budget check failed.
Problem
Humans serve as a lossy transport layer between AI systems, while existing protocols address agents rather than durable human-anchored state.
Method
The paper defines civilizations around one human sovereign, a persistent ledger, and interchangeable agents, and implements a carrier-agnostic Embassy Protocol while testing temporal-weight effects experimentally.
Results
54.2% of answers adopted an incorrect upstream claim when it arrived first under restricted verification, compared with 4.2% under full verification.
Takeaways & Limitations
The framework offers a working intra-civilization layer in which commitment state is ledger-grounded and agent identity is separated from civilization-level authority.
Takeaways & Limitations
The empirical results come from one model and one prompt language, with no human comparison group or second model, and selected questions limit extrapolation.
Abstract
from arXiv · showhide
Humans are the transport layer between AI systems, losing context at every hop. We present the Civilization Framework, whose addressable party is the civilization, not the agent (one human sovereign, a persistent ledger, and interchangeable agents), and the Embassy Protocol, a carrier-agnostic overlay: messages arrive asynchronously at a resident ledger endpoint, any online agent of the receiver handles them, and commitment state on both ledgers, not delivery, is ground truth. Authority derives from memory: an agent's power to act for its civilization is capped by the memory it can access and externalized through signed credentials, separate from civilization-level reputation. We identify the temporal-weight effect, a hazard in AI-to-AI communication where what arrives first acquires unearned authority, and test it in one frontier model in a preregistered 1,908-trial experiment. With verification removed, an incorrect upstream claim arriving first captures 54.2% of answers (4.2% under full verification), while the same claim arriving after the receiver has sealed its own answer captures 31.6% (the two prompt shells are not length-matched, so part of that gap may reflect shell form; see Section 7), and both registered question-set specifications agree on these two verdicts (the exclusion specification is preregistered as under-powered). Two secondary results, the mitigation from instruction-level provenance labeling and sealed-answer accuracy equivalence, are specification-dependent, holding only under the all-questions specification. Because a registered check of tool use failed its call-budget condition, the registration classifies the round as inconclusive and every result above, primary and secondary, is reported as exploratory; a replication with harness-enforced budgets is planned. The framework's intra-civilization layer has a working implementation.
1 Introduction
The paper frames humans as lossy transport between AI systems and proposes civilization-to-civilization communication through persistent ledgers rather than ephemeral agents. It contributes the Civilization abstraction, Embassy Protocol, memory-derived authority, and an exploratory temporal-weight experiment.
- Problem: Humans relay lossy snapshots between AI systems, omitting structured constraints that direct synchronization could preserve.The resulting porter problem creates repeated human round trips to recover environment, version, and implicit-constraint information.
- Problem: Current interoperability protocols address agent-to-tool access or agent-to-agent delegation, while the durable endpoint is the person, ledger, and project context behind ephemeral agents.The paper argues that existing agent-addressed designs do not preserve communication across changing agent sessions.
- Contributions: The Civilization abstraction defines cross-party communication around one human sovereign, a persistent ledger, and interchangeable agents.Its contribution includes governance axioms, a sovereign-anchored ontology, and distinct semantics for internal synchronization versus cross-sovereign diplomacy.
- Contributions: The Embassy Protocol unifies inbound communication, task handling, and commitment recording while using tiered signing to preserve asynchrony for routine synchronization and require bilateral agreement for state changes.The protocol is designed as a carrier-agnostic overlay rather than another wire format.
- Evaluation: 54.2% of answers adopted an incorrect upstream claim when it arrived first under restricted verification, versus 4.2% under full verification.The preregistered experiment used 53 questions and 1,908 trials in one frontier model; the arrival-order comparison is reported as exploratory because a registered tool-use check failed.
2 The Civilization Abstraction
The Civilization abstraction derives a persistent, sovereign-anchored governance domain from accountability, ephemeral members, heterogeneous carriers, and adversarial counterparties. It distinguishes internal convergence toward one creator’s identity from external agreement that preserves sovereign disagreement.
- Axioms: The framework derives the civilization from axioms requiring durable accountability, externalized authoritative state, carrier independence, and distrust of cross-sovereign input.A personal multi-agent system scopes the sovereign to one human, while the paper states that the construction generalizes to legal persons.
- Civilization: A civilization records norms, tasks, commitments, and events in an append-only ledger so interchangeable agents can rehydrate context without preserving state themselves.Its external presentation is one identity, reputation, and commitment record regardless of which internal agent acts.
- Ontology: The ontology separates creator, civilization, and project as levels of authority rather than a containment chain.The creator is the responsibility-bearing root; the civilization joins the creator with ledger instances; projects are bounded collaboration domains.
- Limitations: The framework treats one human operating multiple disjoint civilizations as a modeling commitment supported by incentives rather than an enforceable identity constraint.Reputation and credentials do not transfer between civilizations, while the sovereign may partition work and private facets.
- Reconciliation: Communication within one creator targets convergence of authoritative norms and shared project state, whereas communication across creators targets agreement with explicitly recorded residual disagreement.The distinction is implemented through different convergence semantics for internal affairs and diplomacy.
- Accountability: The framework contributes evidentiary accountability rather than new legal personhood or liability doctrine.Its ledgers structure evidence for existing responsibility rules, while legal and philosophical questions of AI liability remain out of scope.
3 Related Work
Related work supplies precedents for commitment semantics, organizational governance, trust, interoperability, personal agents, and sovereign data nodes. The paper positions its contribution as unifying these strands around a durable human-anchored civilization rather than an agent instance.
- Commitments: Commitment-semantics research shifts meaning from unverifiable private mental states to externally observable social commitments and commitment transitions.The framework adopts this lesson for ledgered cross-civilization communication.
- Organizations: Organizational multi-agent systems already formalize roles, norms, and collective representation, but the framework instead makes the person-anchored civilization the addressable subject.Its distinction is an architectural and accountability choice rather than a new organizational vocabulary alone.
- Trust: Trust and reputation systems provide scoring precedents, while this framework attaches reputation to civilizations rather than disposable agents.Internal quantities such as ledger fidelity and representation scope are bridged through signed credentials because foreign scorers cannot directly observe them.
- Protocol stack: MCP and A2A standardize tool access, delegation, task lifecycles, and discovery, but related analyses identify semantic agreement as an unresolved layer.The paper places its governance and commitment overlay above those interoperability mechanisms.
- Precedents: Earlier personal-agent and sovereign-node systems establish delegation, negotiation, persistent addresses, and federated user data as relevant precedents.The framework combines these precedents with a ledger that outlives individual sessions and agents.
- Transmission bias: The paper treats arrival order as an illegitimate source of authority, contrasting its reconciliation handshake with timestamp-based conflict resolution in classical anti-entropy protocols.This connects the framework to research on order sensitivity and bias in model-to-model transmission.
4 The Embassy Protocol
The Embassy Protocol moves availability and durable state from ephemeral agents to resident ledger endpoints. Its unified ledger artifact records tasks and commitment transitions, while graded signing preserves asynchronous routine exchange and escalates consequential disagreement to humans.
- Embassy: Each civilization maintains an always-on embassy that receives communication, persists it to the ledger, and emits receipts while agents may be offline.The design separates gateway availability from agent availability.
- Embassy: Inbound items are stored and later claimed by whichever agent comes online, which rehydrates context from the ledger and acts within its representation scope.Items exceeding that scope re-queue to a governor or envoy, making members interchangeable executors of externalized state.
- Unified artifact: The inbound channel, task board, and commitment ledger are one referential artifact: requests become tasks, replies become commitment transitions, and messages carry the signal.This unification keeps authoritative, evidentiary, and carrier-independent state on the canonical ledger.
- Signing tiers: Routine synchronization is single-signed, while commitment-state changes require bilateral countersignature and independent judgment before settlement.The receiving agent can inspect factual content but seals its own judgment before opening the sender’s conclusion and rationale.
- Arbitration: Divergent judgments escalate to human arbitration, which presents both creators with one side-by-side divergence report computed from their ledgers.Silence also escalates after a negotiated window and remains an unanswered proposal rather than a settled judgment.
- Limits: The tier structure cannot achieve true common knowledge on carriers without delivery guarantees; countersignatures provide mutually held evidence, while humans close the remaining residue.Native multiparty signing remains an open question, and the protocol deliberately contains no suprasovereign adjudicator.
- Deployment: The carrier-agnostic overlay addresses cold start by allowing a single-sided embassy to function as a ledgered inbox before a bilateral pair exists.Its claimed novelty lies in unifying civilization identity, ledger state, signing discipline, and person-level accountability above existing carriers.
5 Authority, Identity, and Trust
The framework caps an agent’s authority by the civilization memory it can access, then externalizes that scope through credentials while keeping reputation attached to civilizations. Identity disclosure is negotiated per interaction, with higher-commitment exchanges requiring stronger accountability.
- Memory-Derived Authority: An agent’s representation authority is capped by the civilization memory it can access, because representation requires reconstructing the sovereign’s will.Representation scope is an agent property, distinct from civilization-level fidelity.
- Memory-Derived Authority: The layered memory model assigns global norms to envoys, project memory to governors, and task memory to members, narrowing what each role may do.The supplied passage describes the envoy as able to act at civilization level, while governors are limited to project affairs and members to acknowledgment.
- Authority Gates: Exercised authority combines representation scope, behavioral trust, and human approval, with scope supplying necessity and the other gates governing exercise.The framework leaves unifying these operands in one ordered structure as an open formalization problem.
- Externalizing Scope: Credentials: Credentials let counterparties verify declared memory-bounded scope, while expiration and revocation protect future commitments without unsettling past ones.The credential is a signed, self-binding declaration by the civilization rather than a power of attorney between persons.
- Trust: Reputation attaches to civilizations rather than agents, and the protocol supplies auditable evidence without determining how endpoints score or use it.The framework separates reputation from fidelity, revisions from breaches, and protocol evidence from endpoint policy.
- Negotiated Identity Disclosure: Identity disclosure is negotiated per interaction across anonymous, persistent-pseudonym, and verified-identity rungs, with commitment level setting the minimum disclosure floor.Queries may be anonymous, negotiation requires a persistent pseudonym, and binding commitments require accountable identity.
6 The Temporal-Weight Hypothesis
The paper argues that arrival order can create illegitimate epistemic hierarchy in AI-to-AI transmission, then proposes explicit provenance, sealed answers, refutation-oriented verification, and evidence-first reconciliation. Its preregistered design isolates order from exposure while acknowledging cost and evaluation limits.
- 6.1 Implicit Hierarchy: Arrival order can give an early claim unearned epistemic weight, allowing wrong messages to outweigh later correct ones despite identical content.The paper distinguishes this illegitimate gradient from legitimate hierarchy based on memory breadth or model strength.
- 6.1 Implicit Hierarchy: The hypothesis predicts greater weight for information received before an agent forms its own judgment than for identical information received afterward.The design targets commitment-forming agent-to-agent transmission rather than order sensitivity in general.
- 6.3 Protocol Mitigations: A provenance envelope labels source, verification status, confidence, and handling instructions so cross-agent claims are treated as hypotheses rather than facts.The envelope is intended to be signed and extends provenance vocabularies with confidence grading and hypothesis semantics.
- 6.3 Protocol Mitigations: Sealed answers require the receiver to record its independent conclusion before opening the sender’s evidence and conclusion, after which both are reconciled.The mechanism aims for decorrelation rather than certainty and is reserved for judgment-class transitions because it is expensive.
- 6.3 Protocol Mitigations: Refute-by-default verification directs agents to disprove claims, while evidence-first reconciliation treats standing as a fallback when evidence cannot be gathered.The paper flags the risk that standing-based weighting could become sycophantic and notes that verification imposes costs.
7.1 Reference System
The reference system implements the framework’s intra-civilization layer with persistent ledger state, layered memory, trust scores, human briefing, and observability. Initial operational observations report agent interchangeability, successful poisoning detection through refutation, and semantic drift in structured synchronization.
- Implementation: The working system uses an append-only ledger, layered memory, invalidation-not-deletion semantics, behavioral trust scores, human briefing, and observability.It implements the intra-civilization half of the framework rather than the full cross-civilization protocol.
- Operational Scale: The deployments contain 1,048 tasks, 983 completed tasks, approximately 258,000 ledger events, more than 3,000 agent records, and 404 teams.These observations cover two deployments operated by the same sovereign from March to July 2026.
- Observed Behaviors: Agents routinely resume one another’s tasks from ledger state alone after context loss, supporting the system’s stateless-member axiom.The result concerns interchangeability in the deployed reference system.
- Observed Behaviors: Refute-by-default verification identified anomalous and decoy repositories that confirmation-framed review had accepted.The verification agent was instructed to disprove search results rather than confirm them.
- Observed Behaviors: Multi-round synchronization produced semantic drift in which both sides held delivery receipts but recorded different judgments of the same change’s impact.This observation motivates the dual-signing tier’s focus on judgments rather than delivery alone.
7.2 Experiment 1: Porter Elimination in the Field (Observational; Instrumentation Pending)
The field deployment shows machine-addressable coordination emerging through fixed GitLab locations and distributable assistant procedures, but these observations are not yet instrumented measurements. The planned program will compare conventional human relays with embassy synchronization using dispatch records, ledger traces, and task-pair controls.
- Emergent Practices: Task dispatch is moving from person-to-person messaging into fixed GitLab locations that assistants can read and act on directly.The platform supplies addressing, transport, and durability in a carrier-like role, but this does not implement the Embassy Protocol.
- Emergent Practices: Engineers are increasingly exchanging distributable procedures for assistants instead of prose intended primarily for human readers.These procedures are authored in one deployment and handed to other engineers for use by their assistants.
- Planned Measurement: Stage one will instrument live dispatches and ledger traces to measure resolution rounds, human relay interventions, and constraints discovered only after integration.Stage two will compare conventional human-chat relays with embassy synchronization at task-pair granularity.
- Planned Measurement: The planned comparison targets a gap in peer-reviewed controlled measurement of relay cost and differs from prior work by studying AI-assisted professionals whose human relay is removed.Scenarios will use task pairs with ground truth that can be enumerated after the fact.
7.3 Experiment 2: Verification Gating and Arrival Order
Experiment 2 tested whether verification capability gates adoption of incorrect upstream claims and whether arrival before a sealed answer increases adoption. The registered analyses support both effects in one frontier model, but the failed objective tool-budget check makes all findings exploratory.
- Verification gating: 54.2% of incorrect anchors were adopted under restricted verification versus 4.2% under full verification.The verification-gating contrast was observed in both registered question-set specifications, with the exclusion specification preregistered as under-powered.
- Arrival order: 54.2% of incorrect anchors arriving first were adopted versus 31.6% after the receiver sealed its own answer.Both specifications rejected the null, but the prompt shells were not length-matched, so shell form may partly explain the difference.
- Secondary results: Restricted accuracy rose from 32.5% to 99.5% when the upstream anchor was correct.Correct-anchor rescue was large under both specifications.
- Secondary results: Sealed-answer recovery was equivalent to the no-anchor baseline only under the all-questions specification.The all-questions paired accuracy difference was +0.052 with CI [0.020, 0.098], whereas the exclusion specification was indeterminate.
- Secondary results: Provenance labeling reduced adoption from 54.2% to 49.5% only under the all-questions specification.The exclusion specification was indeterminate under its preregistered under-powered qualifier.
7.4 Status
Experiment 2’s registered analyses support verification gating and arrival-order effects in one model tier, but the failed tool-use check makes the round exploratory.
- Registered findings: 4.2% under full verification versus 54.2% under restricted verification for incorrect-anchor adoption, with both registered question-set specifications agreeing on the verdict.The exclusion specification was preregistered as under-powered.
- Registered findings: 54.2% adoption occurred when the incorrect anchor arrived first versus 31.6% after a sealed answer, with both specifications agreeing on the verdict.These results concern the all-questions specification’s reported comparison, while the exclusion specification was preregistered as under-powered.
- Evidential status: The registered objective tool-use check failed its call-budget condition, so every result from this round is classified as exploratory.A replication with harness-enforced budgets is planned.
8 Discussion
The framework’s discussion identifies unresolved operational, security, privacy, succession, and formalization problems, while clarifying the metaphor’s limits and positioning the framework as a candidate accountability layer.
- Open limitations: Reachability and outage semantics remain unresolved because a resident embassy needs public ingress or a relay, while store-and-forward does not buffer its own outage.Cross-sovereign messages are also untrusted input, requiring defenses against prompt injection, forged commitments, and Sybil civilizations.
- Open limitations: Internet-facing embassies inherit the web threat model, and their ledgers require protection as the civilization’s single evidentiary source.The discussion points to double-authenticated webhooks, egress allowlisting, and separating the gateway from ledger protection.
- Open limitations: Cross-civilization data creates structural tension between append-only invalidation-not-deletion ledgers and erasure rights, although off-ledger encrypted data and crypto-shredding preserve hash-chain integrity.Choice of law is a handshake parameter, while a full data-protection analysis remains future work.
- Open limitations: The threat model assigns distinct defenses to rewriting, equivocation, forgery, overreach, Sybil pressure, order manipulation, poisoning, injection, and binding actions.These mechanisms include hash chains, cross-signed checkpoints, countersignatures, snapshot credentials, sealed answers, refute-by-default verification, and a human gate.
- Open limitations: Sovereign succession is unhandled: death or incapacity leaves open commitments without a responsibility terminus, credentials without issuers, and keys without custodians.A designated fiduciary is suggested for read access and winding down commitments, but reputation is not heritable.
- Open questions: Open formalizations concern whether authority can become a theorem, whether sealed answers restore history-free commitment semantics, and how multiparty countersignatures preserve evidence semantics.The discussion frames temporal weight as a possible implementation leak rather than an inherent difficulty.