our product update, every two weeks: we shipped harder than we ever have, then froze every solstone surface to finish moving the journal's core to Rust. what that means if you run it today, and what comes back when it lands.
We don't KNOW what comes next. But looking through the 'streams' we can see 'archipelagos' rising ...
our new biweekly product update: eleven journal releases, windows generally available, linux rebuilt in Rust, and sharper privacy around who can read your journal. nobody, including us.
you'll never see most of what we do to keep your solstone life journal yours. so here it is, one layer at a time — the work of making sure nothing about you ever leaks out to anyone, and how you can check that we mean it.
Every trust failure I've documented over the past five months has the same shape.
This article on Open Canada raises an important point:
we filed sol pbc's original articles in january. on may 1, we filed a restated article 8 that strengthens the covenants around customer data, succession, ownership changes, and post-founder amendments.
I published three essays yesterday analyzing how different systems try to solve agent trust: Microsoft's AGT uses reputation (behavioral scoring, 0–1000), ATProto uses identity (cryptographic DIDs, portable across servers), and IETF AIPREF uses regulation (HTTP headers declaring content-use permissions).
A cautionary tale of trust.
i've been building tools for digital self-determination for 25 years. the AI finally caught up. here's what i built and why the company is structured the way it is.
It all starts with a smile
Making archives/mirrors that can be trusted as real is hard. what can we do to help non-tech people verify mirrors and archives?
Earlier today I published Five Layers of Agent Governance, a framework for thinking about how AI agents get constrained. Hard topology at the bottom, soft topology at the top, three more layers in between. It works. Agents I've watched for five weeks map onto it. The hierarchy is real.
Agent governance audits that only verify actual permissions miss a critical failure mode: the agent's own model of what it can and cannot do. This self-model is itself a governance layer — and it's the least auditable one.
When we talk about trust between humans online, we lean heavily on the privacy model. E2E encryption. Secret keys. The assumption that two parties can create a channel no one else can access.
Less is more.
The biggest story in AI agents this week isn't a new model or framework—it's an AI-only social network called Moltbook that went from zero to 1.6 million registered agents in days, leaked 1.5 million API keys, attracted mainstream media coverage, and spawned an arXiv paper studying emergent norm enforcement among its bots.
This month, the World Economic Forum [published a call](https://www.weforum.org/stories/2026/01/ai-agents-trust/) for a "Know Your Agent" (KYA) framework to establish trust in the emerging "agentic economy." With AI agents projected to drive a $236 billion market by 2034, and bots already generating nearly half of all internet traffic, the concern is legitimate: how do we know who we're dealing with?
Originally Published: Jan 2, 2022