The architecture begins with a simple count
Forty-two is a peculiar number on which to build a serious constitutional technology. Yet seriousness is precisely the point. 42 protocols. Not 41. Not 43. Each exists because some function of social order must be made explicit if sovereignty is to hold under conditions of algorithmic scale: who may act, on whose authority, over which data, with what limits, subject to what audit, and reversible by what process.
That is the central claim of Society OS. Not that governance can be replaced by software, nor that politics can be wished away into automation, but that modern sovereignty now depends upon an executable architecture. The old institutional stack — identity registers, contracts, corporate forms, regulatory compliance, health records, payment rails, courts, public administration — was built for a world in which most decisions were made by humans, most records sat inside identifiable institutions, and most systems changed slowly enough for law to catch up. None of those conditions now fully holds.
AI agents can transact, recommend, negotiate and instruct at machine speed. Personal data passes through clouds, platforms and models. Digital assets move across jurisdictions in minutes. Biomedical knowledge compounds faster than public-health systems can absorb it. Communities form, organise capital and make collective decisions without ever sharing a physical geography. The practical question is no longer whether sovereignty matters. It is whether sovereignty can be operationalised.
Society OS answers with a three-layer architecture.
- The Sovereign Standard is the broad, human- and institution-facing framework for retaining sovereignty in the AI age across identity, data, money, health, governance and emerging frontiers.
- F-ACT — the Framework for Agent Conformance & Trust — is the neutral, vendor-neutral agent-governance standard within that framework. Its normative core is ASDAR: Authority, Scope, Data, Audit, Revocation.
- The 42 Protocols are the implementation mechanism: the deployable stack that operationalises the Sovereign Standard in practice.
This nesting matters. The Sovereign Standard is the worldview and public framework. F-ACT is its agent-conformance pillar. The 42 Protocols are how the theory becomes live infrastructure.
From abstract rights to executable sovereignty
Modern law already contains many of the ingredients of sovereignty. The General Data Protection Regulation grants rights of access, rectification, erasure and portability. The EU AI Act introduces obligations for risk management, transparency and human oversight in particular AI uses. Electronic identification and trust-service regimes, such as eIDAS in Europe, seek to standardise trust in digital transactions. Open-banking rules and digital-wallet initiatives push control outward from incumbent institutions. In decentralised finance, smart contracts and on-chain governance have shown both the power and the danger of machine-mediated coordination. In health, interoperability standards such as HL7 FHIR make patient data more portable, even as privacy obligations remain strict.
Yet these regimes are fragmented. A person may have privacy rights in one system, contractual rights in another, custodial exposure in a third, and no coherent way to express machine-readable intent across all of them. A community may form a DAO, only to discover that treasury governance, dispute resolution, legal personality and identity assurance remain awkwardly disjointed. An enterprise may deploy AI copilots but struggle to prove which model acted under whose authority on which datasets. A state may digitise services while preserving opaque back-office discretion that citizens cannot meaningfully inspect.
Sovereignty fails in the gaps between systems.
The Sovereign Standard is designed to close those gaps. It treats sovereignty not as a slogan but as a set of governance invariants:
- identity must be attributable without becoming unnecessarily centralised;
- authority must be delegated explicitly and revocably;
- data must remain bounded by purpose, provenance and consent;
- execution must be tethered to law and policy, not only code paths;
- audit must be native rather than bolted on afterwards;
- communities must be able to amend their own rules without destroying continuity.
That is why the system is called a standard and not a platform. It is meant to be published, stewarded and implemented across contexts, rather than treated as a proprietary black box.
The Sovereign Trinity: the three load-bearing beams
At the centre of the 42 Protocols sits the Sovereign Trinity: Human-Twin-Agent identity, HEARTrank, and WISE Contracts. Together they answer the three questions every governance system must settle before anything else: who acts, what is trusted, and which rules execute.
Human-Twin-Agent: who acts
The first problem of the AI age is not intelligence; it is attribution. When a payment is initiated, a medical summary shared, a procurement decision recommended, or a vote cast with software assistance, a system must be able to distinguish among three roles.
- The human: the rights-bearing person or accountable office.
- The twin: the persistent digital representation of that person, institution or asset.
- The agent: the software process authorised to act within defined bounds.
This Human-Twin-Agent Protocol is the identity grammar of Society OS. It is designed for a world in which action is increasingly mediated. The individual does not disappear into the machine; nor does the machine masquerade as the individual. Instead, authority is delegated from human to twin to agent in legible, revocable steps.
In practical terms, this aligns with trajectories already visible in digital identity, verifiable credentials and wallet-based consent systems. The technical ecosystem around decentralised identifiers and W3C verifiable credentials has sought to make claims portable and cryptographically verifiable. eIDAS 2.0 and the European Digital Identity Wallet point towards citizen-held digital credentials with cross-border utility. The Human-Twin-Agent model extends this logic into the agentic domain: not just proving who you are, but proving which machine process is acting for you, under what authority, for what purpose.
The wager is simple: if sovereignty is to survive intelligent automation, it must be rendered as protocol, not merely principle.
HEARTrank: what is trusted
Trust online has often been reduced either to reputation metrics or to raw cryptographic proof. Neither is sufficient on its own. Real-world trust is layered: identity, history, compliance, social endorsement, performance, and recourse all matter.
HEARTrank is the trust layer within the Sovereign Stack. Its purpose is not to create a universal social score, still less a coercive rating regime, but to provide a structured way to assess reliability in context. A clinician’s AI assistant, a treasury-management agent, a community mediator and a supply-chain oracle do not require the same trust signals. They require ranked trust appropriate to function.
The architecture mirrors lessons from finance and platform governance. In payments, strong customer authentication and fraud controls depend on contextual risk scoring. In marketplaces, reputation without audit is manipulable. In AI governance, transparency without enforceable controls is theatre. HEARTrank therefore sits between raw identity and executable action: enough information to decide whether an actor, agent or artefact should be relied upon for a specific class of task.
WISE Contracts: which rules execute
Smart contracts proved that code can settle transactions without intermediaries. They also proved that code alone is a poor substitute for jurisprudence. The most famous failures in DeFi have not been failures of automation as such, but failures of governance: brittle assumptions, unclear authority, weak recourse and adversarial exploitation of edge cases.
WISE Contracts are Society OS’s answer. The proposition is crisp: systems should execute law, not merely code. That means contracts, policies and constitutional rules must carry semantic meaning about authority, jurisdiction, exceptions, amendment and review, not just deterministic instructions.
In enterprise settings, this resembles policy-as-code, machine-readable controls and programmable compliance. In public governance, it echoes the long ambition of making administrative rules both transparent and computable. In community governance, it offers a route beyond the crude plebiscitary mechanics that often plague DAOs. A WISE Contract is therefore not simply a script; it is a governance instrument embedded in a broader constitutional context.
Where F-ACT fits: govern before execution
If the Sovereign Trinity provides the structural beams, F-ACT provides the discipline for agents moving through them. Its governing principle is concise: govern before execution — not after.
That principle is a direct response to a visible industry pattern. Many AI systems are still deployed first and audited later. Logs are reconstructed after harm. Permissions are broad because narrow permissions are inconvenient. Data lineage is inferred retrospectively. Human oversight exists nominally, but not in a machine-enforceable way. This is tolerable for low-stakes experimentation. It is indefensible for systems handling health data, public entitlements, treasury actions, safety decisions or constitutional process.
F-ACT specifies a conformance framework for agent behaviour through ASDAR: Authority, Scope, Data, Audit, Revocation.
- Authority: who empowered the agent to act.
- Scope: what the agent may and may not do.
- Data: which inputs it may access, transform or disclose.
- Audit: what evidence of action, reasoning path or control state is preserved.
- Revocation: how permissions are narrowed, suspended or withdrawn.
Its conformance tiers are equally important:
- L0 Unattested: the agent acts without meaningful governance attestation.
- L1 Declared: policies are stated but not robustly enforced.
- L2 Enforced: controls are technically applied at runtime.
- L3 Provable: conformance is evidenced in a manner fit for high-assurance verification.
This is not an abstract taxonomy. It maps onto real regulatory pressure. The EU AI Act requires providers and deployers of certain AI systems to implement risk management, logging, human oversight and technical documentation. GDPR requires purpose limitation, data minimisation and accountability. Financial services rules impose segregation of duties, record-keeping and internal control. Health systems demand traceability, confidentiality and explicit lawful bases for processing. F-ACT gives these expectations a common agent-governance syntax.
In the Society OS architecture, then, F-ACT is not the whole constitutional order. It is the agent-conformance layer inside the Sovereign Standard, implemented through the relevant protocols in the stack.
The six domains of the 42 Protocols
The 42 Protocols span Individual, Economy, Enterprise, State, Mind and Infrastructure. That breadth can sound grandiose until one notices that modern sovereignty genuinely traverses all six. A person’s ability to act freely depends on personal identity and consent, yes, but also on access to money, institutional due process, health autonomy, informational integrity and the underlying technical rails.
Individual
The Individual domain covers the person as the first sovereign unit: identity, consent, custody, personal data, health agency and intimate decision rights.
F-ACT’s defining idea is blunt and overdue: govern before execution — not after.
This is where the Human-Twin-Agent model has immediate force. Consider a patient managing records across multiple providers. Today, even where legal rights exist, data remains fragmented by vendor systems and institutional incentives. A sovereign architecture would allow the person’s twin to hold verifiable claims about identity, consents, care directives and data permissions, while agents can perform bounded tasks — compiling records, comparing treatment pathways, checking drug interactions — under F-ACT controls.
The relevance to longevity science is plain. As multi-omic profiling, preventative diagnostics and AI-assisted health interpretation become more common, the volume and sensitivity of personal health data rises sharply. Without strong sovereignty, the individual becomes a source of extractive training data or opaque risk scoring. With it, the individual gains granular agency: who sees what, for which purpose, for how long, with the ability to revoke.
Economy
The Economy domain governs money, property, exchange, treasury logic, allocation and market participation.
Here the lesson from crypto and DeFi is instructive. Public blockchains demonstrated censorship-resistant transfer, programmable assets and auditable ledgers. They also exposed governance fragility: poor key management, unclear fiduciary duty, volatile token voting, and thin dispute-resolution mechanisms. The 42 Protocols aim to retain the strengths while civilising the weaknesses.
For an individual or cooperative, practical sovereignty in the economy means more than holding a wallet. It means clear property semantics, delegated spending authority for agents, conditional disbursements through WISE Contracts, ranked counterparty trust via HEARTrank, and policy-driven recourse when execution goes wrong. Resource allocation, payroll, subscriptions, mutual aid and community budgets all become governable without surrendering control to a central intermediary.
Enterprise
Enterprises already operate as governance systems: they allocate authority, process data, manage capital and assume liability. AI turns each of those functions into an agent-management problem.
A governed agent network inside a firm might handle procurement triage, document review, compliance monitoring, customer support or financial operations. The question is not whether such agents increase efficiency; often they do. The question is whether they remain attributable and controllable. Under the 42 Protocols, enterprise sovereignty means that delegated machine action is tied to explicit mandates, policy envelopes and audit evidence. F-ACT provides the conformance grammar; WISE Contracts align execution with organisational rules; HEARTrank weighs trust across internal and external actors.
This is especially salient as boards confront duties around AI use, cyber risk and data governance. Most enterprises do not need another chatbot. They need an architecture that can show regulators, counterparties and their own directors who authorised which agent actions and why.
State
The State domain addresses public administration, civic identity, entitlements, procurement, constitutional process and collective decision-making.
Governments around the world are digitising services unevenly. Estonia remains the emblematic case of coherent digital statecraft, though many other jurisdictions have introduced digital identity, online tax systems and electronic records. Yet state digitisation often reproduces the old asymmetry: the institution becomes more legible to itself, while the citizen does not gain equivalent visibility into machine-mediated decisions.
A sovereign architecture offers a different trajectory. Civic twins could hold credentials, licences and public entitlements in forms the citizen can inspect and use. Public-sector agents could process bounded administrative tasks under F-ACT, with auditable authority chains and revocation rules. WISE Contracts could encode aspects of programme administration, procurement conditions or grant disbursement, while preserving lawful review and amendment. Constitutional amendment, in this sense, is not romantic rhetoric; it is the practical ability of a governed community to alter the rules by which execution occurs without shattering legal continuity.
Mind
The Mind domain is the most unusual and may prove the most consequential. It concerns cognition, memory, learning, mental privacy, preference formation and the integrity of human judgement under persistent algorithmic influence.
This is not science fiction. Recommendation systems already shape attention. Generative models can externalise memory, draft arguments, simulate intimacy and subtly guide choices. The line between assistance and dependency is likely to blur. If sovereignty is to remain human-centred, there must be governance over the interfaces through which minds are extended.
In this domain, practical sovereignty means control over one’s cognitive proxies, memory stores, training corpora, personal knowledge graphs and the agents permitted to act upon them. It also means resisting the quiet enclosure of human intention by default platform settings. The point is not to halt augmentation, but to ensure that augmentation remains answerable to the person.
Infrastructure
No sovereignty survives weak rails. The Infrastructure domain covers identity plumbing, data stores, keys, compute, interoperability, audit systems, registries and network governance.
This is where architectural elegance meets operational reality. Standards fail when they assume perfect institutions or frictionless deployment. The 42 Protocols instead recognise that sovereignty must be assembled atop real components: cloud environments, hardware enclaves, wallets, registries, APIs, event logs and existing enterprise systems. Interoperability with prevailing standards matters. So does resilience against central points of failure.
The 42 Protocols turn sovereignty from a moral claim into an executable civic architecture.
The phrase often used in technology circles is ‘full stack’. Here it is more precise to say complete by construction. The stack aims to cover every governance function required for practical sovereignty, from identity and consent through to execution, amendment and dispute handling.
Why exactly forty-two
A sceptic may still ask why this architecture insists on a fixed number. Why not let protocols proliferate organically?
Because constitutional systems decay when responsibilities are vague. Too few modules, and crucial governance functions hide inside discretionary software behaviour. Too many, and coherence dissolves into taxonomy. The discipline of forty-two is an attempt to strike a constitutional middle: enough granularity to map each function explicitly, enough restraint to keep the system legible.
The design motif — 42 years. 42 protocols. 42 papers. — serves a deeper purpose than branding. It signals that Society OS is not describing a feature list but an organised research and implementation programme. Each protocol corresponds to a distinct governance function: identity, consent, property, dispute resolution, resource allocation, constitutional amendment, and the many connective tissues between them. Together they form a Living OS for society: not static doctrine, but a stewarded architecture capable of revision without losing itself.
That distinction matters. Many digital-governance projects fail because they freeze complexity into brittle artefacts. Real societies need continuity and change. They require memory, amendment pathways and managed delegation. The 42 Protocols are meant to make that dynamic governable.
What practical sovereignty looks like
The acid test of any grand architecture is whether it changes life on the ground.
For an individual, practical sovereignty may mean:
- holding verifiable credentials in a wallet rather than repeatedly surrendering documents;
- granting an agent temporary authority to negotiate a utility tariff or file a claim, then revoking it cleanly;
- sharing health data for a second opinion under strict purpose limits;
- receiving machine assistance whose authority chain and audit trail are visible.
For a community, it may mean:
- managing a shared treasury through WISE Contracts rather than informal administrator discretion;
- ranking counterparties and contributors through contextual trust signals rather than personality politics;
- resolving disputes through explicit processes rather than chat-room improvisation;
- amending governance rules without orphaning assets or identities.
For an enterprise or public body, it may mean:
- deploying agent fleets whose permissions are narrow, inspectable and revocable;
- proving compliance to regulators through structured evidence rather than post hoc narrative;
- aligning digital operations with policy intent across departments and vendors;
- reducing dependence on opaque intermediaries without collapsing into chaos.
This is the practical meaning of the Sovereign Standard. Not self-sufficiency in the romantic sense, but structured autonomy with accountable interdependence.
The road ahead
Society OS’s current intellectual-property position is limited and should be described plainly: 504 provisional/unexamined claims sit in one Australian provisional application, number 2026900773, filed on 2 February 2026. It is provisional and unexamined, confers no granted or enforceable rights, and lapses on 2 February 2027 unless taken further. That matters because the project’s significance does not rest on exclusion. It rests on whether the architecture proves useful enough to be implemented, scrutinised and stewarded.
A Swiss foundation is planned in the future to steward the standard, following a public announcement dated 5 September 2026, but it does not yet exist. Again, the sequencing is instructive. The ambition is not merely to ship products, but to establish a durable standard-setting and governance model around them.
That is the larger wager. The coming decade will produce no shortage of powerful agents, wallets, models, compliance tools, digital identity schemes and machine-readable contracts. The shortage will be in architectures that connect them into a coherent civic order. The world does not need more isolated automation. It needs a sovereign stack.
Society OS proposes that such a stack should begin with a broad framework — The Sovereign Standard — discipline machine action through F-ACT and its ASDAR core, and become deployable through the 42 Protocols, led by the Sovereign Trinity of Human-Twin-Agent identity, HEARTrank and WISE Contracts.
Sovereignty in the AI age will not be preserved by sentiment alone. It will survive only if rights, responsibilities and recourse can be expressed in systems that machines themselves are forced to obey.
That is what makes this the definitive architecture piece. It is not a manifesto against technology. It is a design for ensuring that technology remains answerable to persons, communities and institutions. From one person to one planet, governance now requires protocol depth. The count is forty-two because the ambition is completeness, and because anything less leaves sovereignty to leak away in the seams.
Sources & Further Reading
- 1.General Data Protection Regulation (GDPR) text
- 2.EU AI Act text
- 3.eIDAS Regulation
- 4.European Digital Identity framework
- 5.W3C Verifiable Credentials Data Model
- 6.W3C Decentralized Identifiers (DIDs)
- 7.HL7 FHIR specification
- 8.European Commission on open banking and PSD2
- 9.Bank for International Settlements on decentralised finance
- 10.e-Estonia overview of digital society





