Skip to content

Repository files navigation

Ouroboros

Self-Auditing Governance That Starts at Community Scale and Grows Only by Consent

License: CC BY-SA 4.0

Start here: Ouroboros in Brief | PDF. The whole idea in five minutes.

📄 Full vision: Markdown | PDF. Every mechanism, every open question.

📝 Current version: v2.5 (amended August 8, 2026; v2.4 and v2.2 August 2, 2026; v2.1 August 1, 2026; v2.0 released June 15, 2026). Every amendment is logged with its reason in Appendix C. v1.0 is archived.

🗳️ Supporting documents (in /supporting): Six Repairs, a near-term program on one page. The Convention We Never Held, the working brief, including where each repair can legally be adopted today and where it cannot. Sources and Support, every claim of public support graded, with weak sources named as weak.


What this is

A way of governing that uses AI as a tool, keeps humans in charge of every real decision, gives everyone a floor to stand on, and repairs itself on a schedule instead of rotting.

It starts at the size of one community that agrees to it. It binds nobody who has not agreed. It has no army, no police, and no way to make anyone join.

Why now

Twenty-five percent of American voters say they trust the federal government. Among people under thirty it is fifteen percent, and half of them say people like them have no real say. Those numbers are the same on both sides of the aisle.

Meanwhile the people building AI are publishing their own odds of it going badly. Anthropic's CEO says twenty-five percent. Musk has said as high as twenty. The heads of OpenAI, Google DeepMind, and Anthropic all signed a statement putting extinction risk from AI alongside pandemics and nuclear war.

Something will replace systems failing this badly. The only question is whether it gets built on purpose or by default, by whoever moves first with the most money.

Is this direct democracy?

No. It keeps one piece of it and rejects the rest.

What it keeps. One person, one vote, with no weighting of any kind. No property test, no credential test, no productivity test. On constitutional questions and on the five-year audit, the whole franchise decides directly and nobody decides for them.

What it rejects. Majority vote on everything, for three reasons. Nobody can vote on everything, so the few who show up end up deciding, which is capture with better manners. Technical questions put to an unprepared vote go to whoever mobilizes best rather than whoever is right. And a majority can vote away a minority's protections, which is why a short list of prohibitions here is deliberately not votable at all.

What it uses instead. Direct votes on the things that define the system. Citizen councils drawn by lot, like juries, so the body that watches for corruption cannot be campaigned into place. One elected office that can slow a decision and send it back, and cannot override what the people decide.

What it will never do

The refusals are the load-bearing part. Most of them are written as descriptions of what the thing is rather than as policies it holds, so no emergency can suspend them.

  • No power over your body, your movement, your home, your business, your school, or your church. Not at any tier, not under any emergency, not ever.
  • No list of you. No registry of who has been verified. No number that follows you between contexts. Nothing to leak, subpoena, sell, or seize.
  • No authority to take a human life. No executions, and the founding design does not provide for revisiting that.
  • No military authority of any kind.
  • No AI decides anything. The audit body publishes what it finds and does nothing else with it. It cannot delay a vote, extend a deliberation, quarantine a campaign, trigger a revote, or label a source.
  • No AI starts an emergency. A human always acts first.
  • No vote outweighs another, and vote weights are never adjusted under any circumstance.
  • It never decides what you may say. It can require a platform to show how it shapes what you see. It cannot touch what people write.
  • It does not bind anyone who has not agreed to it on ordinary matters.
  • It does not run your life. It is a floor, not a ceiling. It exists to stop catastrophes, not to optimize your days.
  • It does not promise speed. Reforming concentrated capital under consent is a multi-decade job and the document says so.

What it commits to

Nobody gets a list of you. Five prohibitions, stated as prohibitions and not suspendable: no central registry of verified people, no universal identifier, no way to link one verification to another, nothing kept after it expires, and verification required for nothing except counting a ballot. Your own assistant runs on your own device by default and is never the system's sensor.

Your vote counts once, and nobody knows it was yours. The system verifies ballots, not people. It never needs to know who voted and is built so it cannot find out. This matters because fake participants are cheap and getting cheaper, and a million manufactured voices can outvote a town. Where someone cannot verify through no fault of their own, the default is to let them vote.

The same rules reach everyone. One vote each. The heaviest sanctions apply to the worst crimes regardless of who committed them. Every conviction at that level gets reviewed again on a clock, with outside defense counsel, looking for reasons it was wrong.

You can talk. You cannot pay. Speech, writing, assembly, petition, and volunteering are protected. Transferring money or anything of value to an official is not. That includes jobs promised later, sponsored research, and the revolving door.

Nothing runs on a rule it will not say out loud. Every rule public in principle. Dissents published. Minority reports required. An official who declares an emergency that turns out to have been overstated carries personal liability for it.

A floor under everyone. Food, water, shelter, healthcare, education, energy, and information access. Not as charity. Somebody choosing between rent and a prescription is not going to research a ballot measure, and self-government has a capacity requirement. Education runs through advanced study, and the assistant puts it within reach of anyone regardless of where they live or what they earn.

Pay for cures, not for management. Public prizes for curing high-harm diseases, with the results manufactured at cost instead of owned. The current structure pays more for managing a condition for thirty years than for ending it, and that is a choice somebody already made. The malpractice-driven distortion of care delivery gets restructured too.

Building beats rent-seeking. Capital gains on making something taxed lightly. Capital gains on extracting from something taxed heavily. The publicly traded model at planetary scale is named as a corruption vector, and so is the surveillance-advertising business model.

Permits should not be the reason nothing gets built. Housing codes, building permits, and healthcare approvals get standardized where they can be and reformed where local variation is real. Bureaucratic corruption gets targeted with the same seriousness as financial corruption.

Whoever profits from cutting your job pays for the landing. The company that automates the work carries the retraining and the income bridge, not the taxpayer. No public money or tax break goes to automation that cuts headcount, tested on the actual number afterward rather than on stated intent. Large firms report how many jobs their automation removed, because right now nobody knows. And the document says plainly what it cannot fix: a payment keeps a person fed and does not give them back a place in the world.

Credit should describe who you are now. A resolved problem should stop following someone on a fixed schedule disconnected from what they have actually done since.

The places people live do not get wrecked, and you get a say over what goes in near you. Clean water in the floor. Large-scale ecological destruction treated as one of the gravest crimes there is. The system pays full retail for its own power and water, takes no tax breaks, may never push its costs onto a household bill, and may build nothing in a community that has not said yes.

Prison is what happens after everything else failed. Restitution, supervised liberty, and treatment come first. Prison is for when public safety requires it, not as the default. Nobody under the age of majority can be held permanently for an ordinary crime. Where children turn up inside an atrocity, the adults who put them there are the first target.

Attention is treated as a commons. It can be polluted, captured, and extracted, so concentration of attention-shaping power above a threshold triggers automatic review. Your right to know how content is shaped for you, and to change it, outranks every other commitment in that section when they conflict.

Problems that take decades get funded like they take decades. Bounties reserved for generational work. Every authority expires so permanence has to be earned again instead of inherited.

How it's built

Only humans are sovereign. Every AI is an instrument.

  • The foundation: a private AI assistant for every person. Yours, aligned to you, never the system's sensor. It is what makes one-person-one-vote real instead of formal.
  • Tier 1, the humans: the People, and one elected office called the Tribune. Co-equal, neither above the other. The Tribune brokers, speaks for the system, and can slow things down. It cannot pass a law, raise a tax, spend a dollar, or punish anyone alone. One six-year term. Never again.
  • Tier 2, the instrument: a citizens' council drawn by lot, the per-community representative AIs, and a twelve-member audit body. Three branches, none sovereign, each checking the other two.

Power runs through one spine. Any branch can pull a low-bar reversible pause on an action, and the People settle any reversal. Civilization-scale emergencies need a high bar to authorize, expire by default, and escalate to the People for anything irreversible.

Consent, in two regimes. Ordinary action binds only communities that ratified it, and grows by earning it. One narrow exception is named rather than buried: for a short list of risks that could end civilization, it claims authority to make governments share information and take part in a joint response. That reaches governments and never persons.

What keeps it that way

This is the part most proposals skip. A list of things a country should be is worth nothing without a mechanism that holds when the people in charge stop wanting it.

  • Everything expires. Every authorization, every emergency power, every law ends on a date unless somebody makes the case again against evidence.
  • A public self-audit every five years, on a fixed agenda: every major action, every emergency and the judgment that triggered it, the floor measured against actual outcomes, every permanent sentence rechecked for new exoneration evidence, every open question, and amendments proposed in the open.
  • Standing with the governed is measured, not assumed. Sustained loss of it triggers a fresh election. A sharper loss triggers recall. Any member of the lower tier can be recalled without dissolving the branch.
  • Quarterly public audits between cycles, plus annual review by independent red teams that hold kill-switch authority.
  • Every amendment to this document is logged with its reason, including the ones where I was wrong and had to withdraw a claim. Appendix C is that record.

What it does not address

Worth saying plainly, because a document that only lists what it covers is hiding something.

Immigration. Family formation. Food quality and agricultural policy, beyond putting nutrition in the floor. Foreign policy, beyond refusing military authority outright.

And a common national identity, which it actively runs against. The preamble holds that humanity is plural, and that governance requiring uniformity in order to function is conquest rather than governance.

What's still open

Real questions, carried in the open rather than behind confident assertions. How the first audit consortia get chosen. The economic transition mechanics. The One-Vote Standard's protocol specification. What happens when religious authority and engine principles conflict. What the architecture does against organized authoritarian opposition.

The hardest one is named plainly: somebody has to start it, and there is no perfectly fair way to do that.

How to engage

Read it and tear into it. Specific sections, specific problems, specific fixes. Or take what is useful and build something else.

Issues for problems. Pull requests for text. Discussions for the argument.

The architecture was built and hardened through a four-model adversarial review process (GPT, Gemini, Grok, Claude), then run against four hostile readers picked because they would object. It is offered for more of the same.

Author

Preston T. Winters, solo product builder, Coos County, Oregon. Written with Claude (Anthropic) across many sessions. No organization behind it, no funding ask.

I also build and sell AI software, including the memory engine and personal companion linked below, and this architecture describes a personal companion as public infrastructure. I stand to gain if this direction wins. That is a conflict of interest and you should weigh it. I wrote the architecture to be provider-neutral, and if someone builds a better version of that layer than mine, they should win it.

The window is closing. Better governance will not arrive on its own.

License

CC BY-SA 4.0. Attribution required, derivatives share alike.

Until August 8, 2026 the LICENSE file in this repository contained CC0 1.0 text while every document in it stated CC BY-SA 4.0. The file has been corrected to match the documents. Creative Commons grants are irrevocable, so anyone who received this work while the CC0 file was present retains that grant. Everything from the correction forward is CC BY-SA 4.0.

You are free to share, adapt, and build on this work, including commercially, as long as you give credit and license your contributions the same way. Full terms: Creative Commons Attribution-ShareAlike 4.0 International.

Citation

Winters, P. T. (2026). Ouroboros: Self-Auditing Governance That Starts at
Community Scale and Grows Only by Consent (Version 2.5).
https://github.com/Preston2012/ouroboros

Related work

  • Demiurge. The refusal-first memory engine that makes the personal companion implementable. Open source. TypeScript, SQLite, ONNX. Ships as an MCP server and REST API.
  • AI Council. The multi-model review method used to draft and audit this document, applied to building production software.
  • The Second Frequency. Nineteen short pieces on power, scripture, and repair, plus where I actually stand on the framework underneath this architecture.

Coming next: Memory Sovereignty Principles. A spec and benchmark for personal AI memory providers, operationalizing the privacy commitments above.

Preston Winters. Critique welcome at preston@winterscode.com.

About

Self-auditing governance that starts at community scale and grows only by consent. AI audits, humans decide. Sources graded, every unsolved problem named in the text.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages