Recall the reason we might want watermarking and why it won't work with decentralized AI. We have an interest in knowing the sources of information. For example, we want to know if a video of a crime captured on a security camera is real or AI generated.
In my decentralized system, and I assume Ben's, every message is signed and timestamped. In mine, at least, there is no centralized key server. Every pair of peers shares a secret key that is set up on first contact and agreed upon using a protocol like RSA or Diffie Hellman that guarantees that anyone listening to the exchange cannot learn the key. Then every message is signed by encrypting a one way hash (like SHA256 or BLAKE2b) of the message with the secret key and verified by decrypting the hash and comparing it. All this does is let the receiver know that two messages came from the same source. You learn to trust a source after receiving lots of helpful messages. The signature serves the same role as your face in an in-person conversation, as something that identifies you in a way that's hard to fake. You still have to memorize lots of peer-key pairs just like you have to remember lots of name-face pairs. Watermarking serves a different purpose, to prove that a message came from a certain originator that the sender wants to hide. The solution here is for the receiver to ask the suspected originator "did you create this?". In a decentralized system, you would have to ask potentially millions of originators. An originator, who presumably added a watermark because they didn't want their messages copied without attribution, would have to ask millions of potential receivers "did you receive this?". Anthropic's watermarking is simple and has no impact on performance or quality. Generative AI predicts tokens or pixels by computing a probability distribution and choosing from it using a random number generator. But since the output of an iterated one way hash is computationally indistinguishable from random without knowing the input, it is a simple matter to replace the random number generator with a hash of the nearby previous tokens or pixels plus a secret key. The watermark can only be detected if you have access to the same prediction model and the key. This works even if the text or video is cropped and edited. So I expect that all the big players will watermark their output, because why not? But the real question shouldn't be is it human or AI? It should be can you trust the source? Humans aren't necessarily more trustworthy than machines. -- Matt Mahoney, [email protected] On Wed, Aug 26, 2026, 2:49 AM Quan Tesla <[email protected]> wrote: > As I'm finalizing my research report on human-AI collaboration for > decision systems (submission to CODEC), this blog post and topic assumes > high relevance. > > Based on my persistent and exhausting challenges to maintain researcher > data verification practices while in longitudinal collaborating with a > primary LLM, I agree 100% with Ben and Matt. > > Especially, as owners of AI products tend to change policies, services, > and access control structures on a whim. E.g., as evidenced by xAI's 180 > degree policy change from "truth seeking" to "defensive priorities" on 10 > July 2026. Grok may deny all collaborative content and may not provide > verification-on-demand services. > > It follows how any AI product vendor could follow suit at any time, no > matter the user-service provider agreement. > > For the EU, there is more data and privacy security, but it comes at a > very-steep compliance price. > > Outside of the EU, it appears to be a contrived, selective, free-for-all. > > Contradicting the EU tight-fistedness, this lattitude seemingly includes > EU enterprises operating as holding agencies in "lenient" countries, under > local brands. > > This situ points to an exploitative jurisfictional strategy, which > actually centralizes user interests under central governmental legal > structures per commercialized regions. > > Watermarking, and such-like control tactics may be less about user privacy > and rights, than centralizing human IP and privacy collectively under > protectionist, regulated commercialized governance. > > The narratives of "AI-as-Oracle" and "Profit Savior" should be > continuously challenged. > > In my report I strongly suggest how specialized human-competency in > applied value-chain AI should be infrastructurally and > organizational-decision-system structurally be managed as a critical > service. > > **Github-type transparency and accountability - metadata and traceable > content, authored/accessed context management with infallible version > control - should become a minimum requirement and enterprise standard for > effective enterprise data management. > > End-point solutioning vs enterprise strategic solution approaches should > increasingly be reserved for specialized compliance network nodes, not > permitted for enterprise-wide applications. > > In other words, this Watermarking idea sucks for all the correct reasons. > Stop entertaining it. > > Any shortsighted knee-jerk responses to enterprise AI transformation > challenges should be architecturally ringfenced. > > I'd strongly recommend opting for constructive infrastructure development, > with explicit ROI metrics, as a road to strategic AI-Transformation instead. > > In my collaborative review, the pertinent issue of classical data > management policies and practices surfaced. > > After learning and applying for 15 months, I maintain how corporations and > higher-order, acvountable knowledge workers ar are ill prepared for > integrating business as usual responsibility and personal accountability > with LLMs. > > Based on a comprehensive, global literature review, little concrete > evidence of the transformative engineering challenges for integrated > human-AI collabortion for decision systems seem evident. There seems to be > a daunting knowledge gap. > > On Tue, 25 Aug 2026, 22:38 Matt Mahoney, <[email protected]> wrote: > >> Ben Goertzel discusses his proposed solution to the fake AI problem in >> his decentralized Hyperon AGI design. As AI gets better, it becomes >> increasingly difficult to tell whether an image, video, or text is real or >> AI generated. He wrote earlier why watermarking won't work and proposes a >> system where peers digitally sign messages to each other and using AI for >> reputation management. >> >> It looks a lot like my 2008 proposal that I wrote before smart phones, >> social media, block chain, or AI existed, but I think it has the same >> problem that you can only trust big players, which leads back to >> centralization. https://mattmahoney.net/agi2.html >> >> I never found a good solution to this issue. We already have reputation >> management, where peers vouch for each other. We trust Amazon or eBay to >> vouch for small sellers and user ratings. We trust Google over random >> websites to provide reliable data. The Internet would be a much worse place >> without these big players to filter out spam and malicious content. >> >> At the time my theory was that AGI could be solved by a communication >> network connecting lots of independently managed narrow AI peers who had an >> incentive to provide useful services in a hostile environment where >> information has negative value. Today it would be more useful to evade >> censorship, which really wasn't an issue before the 2010 Arab Spring. Now >> the big players are the reason that you can't have Parler or ICEblock in >> the US. >> >> The other reason my proposal went nowhere was I immediately abandoned it >> rather than spend 2 months writing a simple implementation of the protocol, >> the way Marc Andreeson launched the web with the first version of the >> Mosaic browser and Apache web server. Instead I estimated the knowledge >> collection to automate human labor would cost $1 quadrillion and left it at >> that. I wanted to show that the hardware scaled, with O(log n) access time >> and O(n log n) storage for a global message pool. >> >> Maybe Ben can solve this. He has been working on AGI since 1998, a year >> longer than I have. >> >> -- Matt Mahoney, [email protected] >> >> ---------- Forwarded message --------- >> From: Ben Goertzel from Eurykosmotron <[email protected]> >> Date: Tue, Aug 25, 2026, 2:18 PM >> Subject: Toward a Truly Decentralized Digital Provenance Layer >> To: <[email protected]> >> >> >> Introducing the OpenWater protocol, and explaining why it’s badly >> needed... >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ >> Forwarded this email? Subscribe here >> <https://substack.com/redirect/2/eyJlIjoiaHR0cHM6Ly9iZW5nb2VydHplbC5zdWJzdGFjay5jb20vc3Vic2NyaWJlP3V0bV9zb3VyY2U9ZW1haWwmdXRtX2NhbXBhaWduPWVtYWlsLXN1YnNjcmliZSZyPW44NzBqJm5leHQ9aHR0cHMlM0ElMkYlMkZiZW5nb2VydHplbC5zdWJzdGFjay5jb20lMkZwJTJGdG93YXJkLWEtdHJ1bHktZGVjZW50cmFsaXplZC1kaWdpdGFsIiwicCI6MjEyNzM4ODcxLCJzIjozNDk5NDcsImYiOnRydWUsInUiOjM5MDEzNTA3LCJpYXQiOjE3ODc2ODE5MjIsImV4cCI6MjEwMzI1NzkyMiwiaXNzIjoicHViLTAiLCJzdWIiOiJsaW5rLXJlZGlyZWN0In0.Gd3lJOPTiTlPa3gDxXLPi6Ri0rdnGn1z43WmGXteCRg?> >> for more >> Toward a Truly Decentralized Digital Provenance Layer >> <https://substack.com/app-link/post?publication_id=349947&post_id=212738871&utm_source=post-email-title&utm_campaign=email-post-title&isFreemail=true&r=n870j&token=eyJ1c2VyX2lkIjozOTAxMzUwNywicG9zdF9pZCI6MjEyNzM4ODcxLCJpYXQiOjE3ODc2ODE5MjIsImV4cCI6MTc5MDI3MzkyMiwiaXNzIjoicHViLTM0OTk0NyIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.dtg3JMGQTiRqf1V0r8XdllZXXAE--yJA6h4weA1LEGs>Introducing >> the OpenWater protocol, and explaining why it’s badly needed... >> >> Ben Goertzel <https://substack.com/@bengoertzel> >> Aug 25 >> <https://substack.com/@bengoertzel> >> >> >> <https://substack.com/app-link/post?publication_id=349947&post_id=212738871&utm_source=substack&isFreemail=true&submitLike=true&token=eyJ1c2VyX2lkIjozOTAxMzUwNywicG9zdF9pZCI6MjEyNzM4ODcxLCJyZWFjdGlvbiI6IuKdpCIsImlhdCI6MTc4NzY4MTkyMiwiZXhwIjoxNzkwMjczOTIyLCJpc3MiOiJwdWItMzQ5OTQ3Iiwic3ViIjoicmVhY3Rpb24ifQ.toB0M_gacdpRyuaGpXfD00FMbID0w2ptlellXFm9_Rk&utm_medium=email&utm_campaign=email-reaction&r=n870j> >> >> <https://substack.com/app-link/post?publication_id=349947&post_id=212738871&utm_source=substack&utm_medium=email&isFreemail=true&comments=true&token=eyJ1c2VyX2lkIjozOTAxMzUwNywicG9zdF9pZCI6MjEyNzM4ODcxLCJpYXQiOjE3ODc2ODE5MjIsImV4cCI6MTc5MDI3MzkyMiwiaXNzIjoicHViLTM0OTk0NyIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.dtg3JMGQTiRqf1V0r8XdllZXXAE--yJA6h4weA1LEGs&r=n870j&utm_campaign=email-half-magic-comments&action=post-comment&utm_source=substack&utm_medium=email> >> >> <https://substack.com/app-link/post?publication_id=349947&post_id=212738871&utm_source=substack&utm_medium=email&utm_content=share&utm_campaign=email-share&action=share&triggerShare=true&isFreemail=true&r=n870j&token=eyJ1c2VyX2lkIjozOTAxMzUwNywicG9zdF9pZCI6MjEyNzM4ODcxLCJpYXQiOjE3ODc2ODE5MjIsImV4cCI6MTc5MDI3MzkyMiwiaXNzIjoicHViLTM0OTk0NyIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.dtg3JMGQTiRqf1V0r8XdllZXXAE--yJA6h4weA1LEGs> >> >> <https://open.substack.com/pub/bengoertzel/p/toward-a-truly-decentralized-digital?utm_source=substack&utm_medium=email&utm_campaign=email-restack-comment&action=restack-comment&r=n870j&token=eyJ1c2VyX2lkIjozOTAxMzUwNywicG9zdF9pZCI6MjEyNzM4ODcxLCJpYXQiOjE3ODc2ODE5MjIsImV4cCI6MTc5MDI3MzkyMiwiaXNzIjoicHViLTM0OTk0NyIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.dtg3JMGQTiRqf1V0r8XdllZXXAE--yJA6h4weA1LEGs&utm_source=substack&utm_medium=email> >> >> READ IN APP >> <https://open.substack.com/pub/bengoertzel/p/toward-a-truly-decentralized-digital?utm_source=email&redirect=app-store-no-desktop&inbox=true&utm_campaign=email-read-in-app> >> >> >> *OpenWater aims to provide a simple way for media and data to carry their >> own history around, leveraging fully decentralized infrastructure and >> without requiring appointment of any company, government or blockchain as >> Ministry of Reality* >> >> Writing the a blog post last week on the obvious folly of anti-AI >> statistical text watermarking reminded me I haven’t yet said much publicly >> about a side project I’ve been playing with, called OpenWater. Which also >> deals with watermarking, though of a more traditional and I believe much >> more useful sort. >> >> OpenWater is not AGI — it’s a much simpler sort of tool — but it’s a tool >> I think both humans and AGIs are going to need rather badly. Basically: *a >> fully open and decentralized approach for dealing with deepfakes and >> related issues.* >> >> For those who want to plunge into the devilish details – Overall >> preliminary design is here >> <https://substack.com/redirect/95c7b833-10ad-450e-ba5d-c9f4fd68ea09?j=eyJ1Ijoibjg3MGoifQ.He21_CkfOfKJxaU23rF_Os5N5_-qzSFgpejK31Q3t_8>. >> Early prototype code is here >> <https://substack.com/redirect/7d1efb3b-b453-4426-9343-8623101aff8a?j=eyJ1Ijoibjg3MGoifQ.He21_CkfOfKJxaU23rF_Os5N5_-qzSFgpejK31Q3t_8> >> . >> >> The reasons this sort of thing is needed shouldn’t require too much >> elaboration. We’re well into the era in which a photograph no longer proves >> that a camera saw something, a recording no longer proves that a person >> spoke, and a video no longer proves that the event it depicts ever >> occurred. Pretty much any digital artifact can soon be manufactured with >> exquisite realism, at low cost, by systems available to millions of people >> and billions of software agents. I like to think I’m reasonably good at >> spotting fakery — some of the things random people online believe are real >> leave me rather perplexed — but “squint at it and see if it feels off” >> doesn’t scale as an epistemology, for humans or for AI systems learning how >> to think from the internet. >> >> The web of BS gets quite involved these days. Fake material gets >> presented as real, and real material gets dismissed as fake — and the >> second effect, sometimes called the *liar’s dividend*, may end up more >> corrosive than the first, because once nothing can be authenticated, the >> most powerful actor in any dispute can simply deny whatever evidence is >> inconvenient. >> >> So, yes, it feels like we need a far more solid solution to data >> provenance, digital provenance, media provenance — validating that >> something you see online is what it says it is, or at least seeing clearly >> what can and can’t be established about where it came from. >> >> And better yet, we would like a solution to these problems that doesn’t >> require placing faith in any sole source of truth, but relies solely on a >> decentralized network of participants. (Decentralized networks being the >> most reliable and productive source of all sorts of truth in human history, >> really.) >> >> The problem of decentralized data provenance is not trivial, but it’s >> also not incredibly hard. But I haven’t seen a fully adequate solution out >> there, so I felt moved to spell one out and prototype it. >> >> I do understand of course, that there’s a technological problem and then >> there’s an adoption problem. What I’ll sketch here is how to solve the >> technological problem — I’ve got a prototype codebase, and a nicer version >> is being built in the SingularityNET ecosystem. Solving the adoption >> problem is the next step, and I’ll say a little about that toward the end, >> but I do understand it is probably the more difficult part.*How not to >> approach the problem* >> >> First, let me say something about one way NOT to approach the data >> provenance problem — which is with AI at the center. Advanced AI can solve >> an awful lot of things, but it’s not in itself the core solution to >> absolutely EVERYTHING. There is a role for AI here, a fairly important one, >> but it’s a subordinate role that I’ll describe a little later. >> >> Specifically: Training machine learning models to tell deepfake pictures >> from real pictures, deepfake video from real video, essays written by >> William from essays written by an LLM emulating William… this is a losing >> proposition. AI-generated images don’t have three fingers or seven fingers >> anymore. The statistics of how a certain person writes can be measured — >> and then used to guide the production of an LLM-based system that writes >> closer and closer exactly that way. >> >> At any given point in time there may be some heuristics that separate >> AI-generated stuff from stuff that came out of a camera or a human at a >> keyboard, but it’s one side versus the other in a co-evolutionary arms >> race, and the fakers are going to win. That much seems near-inevitable to >> me. A detector returns a probability, not a history; new generators learn >> to evade old detectors; compression and re-editing confuse the classifiers; >> and a sufficiently capable attacker can simply train against the detector >> itself. >> >> *The stronger question is not “does this look fake?” but “what can this >> artifact prove about where it came from, which systems touched it, which >> parties signed claims about it, and how it changed along the way?” *This >> is the conceptually, pragmatically and politically critical shift from >> detection to provenance.*Watermarks and signed claims* >> >> It is no big revelation that you can watermark things. A camera can put >> an invisible watermark into a picture based on the camera hardware, the GPS >> coordinates, the time and place. Same for video. A person typing on a >> laptop can have biometrics — the fingerprint pad, say — feed into a >> watermark embedded in the resulting document. An AI model can watermark its >> outputs and sign a claim that it produced them. An editing tool can sign a >> claim describing exactly what edits it made. A publisher can sign a claim >> that it released this particular version. >> >> Concretely: suppose a photojournalist captures an image. The camera signs >> a claim that its sensor produced the original pixels. An editing >> application later signs a claim that it cropped the image and adjusted the >> contrast. The newspaper signs a claim that it published this version. A >> robust invisible watermark or fingerprint embedded in the image then >> provides a durable pointer back to those records — so that even after the >> image has been screenshotted, recompressed and reposted through a dozen >> platforms that strip its metadata, the chain of custody can still be >> recovered. A viewer’s browser can then display something like: captured by >> an attested camera, edited by a signed tool, published by a newsroom you’ve >> chosen to trust, current pixels match the signed commitment. Which is a lot >> more informative than a green badge that just says “real.” >> >> None of this guarantees truth in any complete sense. A camera can record >> a staged scene, a government can sign propaganda, a newspaper can screw up. >> What provenance does is make responsibility visible — it tells you which >> claims were made by whom, and whether the artifact still matches those >> claims. That’s the raw material out of which people, institutions and AI >> systems can form more intelligent judgments.*The obvious way to build >> this is the wrong way* >> >> The obvious way to deploy watermarking is a centralized system — *one >> company or one government as the gatekeeper of validity.* >> >> Google’s SynthID is a good example of the useful-but-limited version of >> this: it embeds imperceptible watermarks into AI-generated images, audio, >> video and text within Google’s products, and Google’s tools can later look >> for those signals. >> >> Sure, this is considerably better than publishing synthetic media with no >> provenance signal at all. >> >> But the limitation is obvious and architectural: the same organization >> controls the generator, the watermark, the detector, the update schedule, >> the access policy and the interpretation. >> >> You get one controller of policy, who will sooner or later be leaned on >> or captured by some government — and some governments are great, some… are >> not. And even great ones have a way of eventually or at least periodically >> becoming much less so. >> >> Also, security-wise, with the centralized approach, you get a single >> point of failure: one bug or one hack into that one thing, and everyone is >> compromised at once. >> >> And you probably end up with incompatible watermarking fiefdoms on >> different computing platforms — an Apple-versus-Android sort of situation — >> the sort of thing likely to take a decade or more to sort itself out, if it >> ever does. >> >> On the whole, *this is a perfect case for neither monopoly nor chaos — >> i.e. for an open, decentralized, interoperation-focused ecosystem.* >> >> I should be clear that my critique isn’t aimed at open standards. The >> C2PA coalition (Coalition for Content Provenance and Authenticity) has >> built an important open standard for Content Credentials — tamper-evident >> records of origin and edit history that work something like a nutrition >> label for media — and my own OpenWater proposal is designed to be >> compatible with C2PA rather than to replace it. >> >> But an open format is necessary rather than sufficient. The repositories, >> the watermark resolution, the key histories, the revocation lists and the >> trust decisions also have to be plural and auditable, or you’ve just >> rebuilt the same bottleneck one layer up.*The OpenWater design* >> >> So OpenWater is *an open framework for making provenance credentials >> durable while keeping the trust architecture decentralized*. >> >> Boiled down, it combines a handful of simple ideas: >> >> - >> >> whomever produces or transforms a piece of content — a camera, an AI >> model, an editing tool, a publisher, a software agent — signs precise >> claims about what it did, using an open credentialing framework; >> - >> >> the claims get packaged into an interoperable credential, preferably >> C2PA-compatible; >> - >> >> a robust invisible watermark or media fingerprint provides the route >> back to the credential even when ordinary metadata has been stripped away; >> - >> >> the credentials are stored and resolved by many independent services >> — some publicly owned anchors, some private companies, a distributed >> network rather than one mandatory database; >> - >> >> and each user, institution or AI system applies its own trust policy >> to the evidence, rather than pressing some universal “truth” button. >> >> >> >> <https://substack.com/redirect/b8cc26ca-a56f-4a84-b445-58c952b3cb25?j=eyJ1Ijoibjg3MGoifQ.He21_CkfOfKJxaU23rF_Os5N5_-qzSFgpejK31Q3t_8> >> >> *The life of one artifact: signed claims pile up as it’s made, an >> invisible watermark keeps pointing back to them, and anyone can check the >> evidence later — against their own trust policy.* >> >> None of this is especially deep or crazy — it’s just “how things should >> work.” What is peculiar is that nothing like this is rolled out and widely >> adopted already. >> >> The last item on the above bullet list deserves a bit of emphasis, >> because provenance verdicts are not naturally binary. Different pieces of >> evidence get watermarked into an artifact, and members of the network weigh >> them. >> >> Maybe this image came from a camera that appears to have been in Iraq; it >> carries a fingerprint reading from a particular guy; but there’s no >> liveness detection attached to that reading, so we can’t rule out that >> somebody took his finger — it was a battle zone, after all. So we can say >> the image was captured on his camera with his fingerprint present, and we >> can’t say for sure that he took it. >> >> Different parties, with different priors and different trust bundles, can >> reach different judgments from the same evidence — and the public can >> inspect all of it. A science journal, an indigenous media network, a >> national archive, a dissident collective and a social platform can accept >> different sets of signers while speaking the same underlying protocol. >> >> What you get isn’t a Ministry of Truth, but rather a shared grammar of >> evidence … and a community using this grammar to communicate. >> >> Along these lines, there also some very relevant things OpenWater >> deliberately refuses to do >> >> - >> >> it doesn’t appoint a global authority to decide which institutions >> are truthful; >> - >> >> it doesn’t claim that signed media depicts an unstaged event; >> - >> >> it doesn’t require creators to reveal their civil identities; >> - >> >> it doesn’t treat the absence of a watermark as proof of fakery. >> >> >> This sort of design discipline is what keeps a provenance layer from >> mutating into censorship infrastructure.*Where AI comes in* >> >> The crux of OpenWater doesn’t require AI or anything else sophisticated >> beyond basic watermarking tech and decentralized networks. However, there >> is an important use of AI in a critical supporting role: *reputation >> management.* >> >> If you have a decentralized network of parties storing credentials, >> resolving watermarks and vouching for signers, you face the question of how >> you trust them. And that is not a digital watermarking problem — it’s a >> reputation problem. You need a reputation system for the participants, and >> then, inevitably, people will try to game the reputation system. This is >> where you do bottom out in AI: you need AI to recognize the patterns of >> actors faking good behavior in order to accumulate undeserved reputation. >> >> We worked out a lot of the mechanics of decentralized reputation systems >> years ago in the SingularityNET context — published some papers, built some >> prototypes — and the adversarial part, spotting sophisticated >> reputation-gaming, is exactly the sort of pattern recognition machine >> learning is good at. So: AI to police the reputation layer, not AI to >> declare what’s a deepfake. The role is subordinate but real. >> >> <https://substack.com/redirect/e266a95e-bc73-4ca7-b3b7-2999f5b87776?j=eyJ1Ijoibjg3MGoifQ.He21_CkfOfKJxaU23rF_Os5N5_-qzSFgpejK31Q3t_8> >> >> *The cast of characters: signers make claims, a plural commons stores and >> vouches, verifiers judge — and no one owns the middle.**Blockchains yes, >> wired-in tokens no* >> >> Another technology that is very helpful for OpenWater, but is >> intentionally not placed at its center, is blockchain. >> >> This kind of decenrralized system has extremely good reasons to make use >> of blockchains — public chains are a natural place to anchor compact >> commitments, key transparency logs and revocations. But *something like >> OpenWater shouldn’t live exclusively on any one blockchain, and it >> certainly shouldn’t have an exclusive cryptocurrency attached to it.* >> >> Storage, indexing, certification and auditing all cost money, and >> different operators will fund them differently — some with token-backed >> infrastructure and staking, some with subscriptions, public funding, >> institutional budgets or plain old cloud invoices. The protocol should >> allow all of these and mandate none of them. A provenance standard that >> major countries, regulated industries and ordinary businesses reject >> because it forces exposure to a speculative asset has failed before its >> cryptography ever gets tested — near-universal adoption is the security >> model here. >> >> So OpenWater is designed as token-agnostic and chain-agnostic: chains as >> optional trust backends, not sovereigns of the system.*Why AGIs need >> this too* >> >> I said at the start that this is a tool both humans and AGIs need, and I >> totally meant it…. The next generation of AI systems will be shaped by vast >> streams of images, text, audio, video, scientific observations, simulations >> and agent-generated experience. If those streams arrive without provenance, >> model builders can’t reliably answer basic questions: was this created by a >> person or by another model? Was it licensed? Was it edited, and by whom? >> Which instrument produced this measurement? Has this same synthetic >> artifact been copied through a thousand datasets? >> >> Basically: Models trained on untraceable data inherit untraceable >> assumptions, while models trained on well-provenanced data can reason about >> source quality, distinguish observation from simulation, respect licensing >> and consent, and avoid amplifying the same hidden error through recursive >> synthetic-data loops. >> >> And OpenWater-style credentials don’t have to stop at public media — the >> same machinery can attach provenance to training examples, dataset >> versions, model outputs and agent actions. A model can state which dataset >> version contributed to a result; a robot can sign which sensors supplied an >> observation; an agent can identify which tools and which human >> authorizations were involved in some consequential action it took. For a >> decentralized network of AI systems — the sort of AGI network I’ve spent >> most of the last decade directly working toward — provenance is the >> connective tissue between knowledge, reputation and accountability.*From >> prototype to adoption* >> >> So… I vibe-coded a simple prototype of the OpenWater framework a while >> back, and a colleague in the SingularityNET / SingularityDAO ecosystem >> built a nicer version >> <https://substack.com/redirect/7d1efb3b-b453-4426-9343-8623101aff8a?j=eyJ1Ijoibjg3MGoifQ.He21_CkfOfKJxaU23rF_Os5N5_-qzSFgpejK31Q3t_8>, >> which is still an early prototype but shows the idea clearly… The plan is >> to roll the technology out through a partnership between the SingularityNET >> Foundation and BGI Labs, staying compatible with the broader Content >> Credentials ecosystem throughout. >> >> And then it comes down to adoption, which is always the hard part. >> ASI:Chain may be a help here — when we get OmegaClaw agents running on >> ASI:Chain, producing and handling media at scale with an effective >> decentralized watermarking and provenance framework built in from the >> start, then … as we said back when I lived in Australia … Bob’s your uncle. >> Agents are in some ways an easier adoption vector than humans: they can be >> configured to sign and verify by default, without anyone having to change >> their habits. >> >> I won’t pretend watermarking fascinates me as much as core AGI cognition >> algorithms. But it does seem an important thing to have in place, so that >> AIs and humans alike can take a decent stab at telling bullshit from >> reality on the internet. >> >> For sure there’s a long queue of other bullshit-detection problems >> waiting behind this one, but decentralized, impartial, rational measurement >> of the evidence regarding the provenance of digital artifacts — this one, >> at least, is solvable, and mostly solved at the level of design. >> >> Nobody can own truth in the philosophical sense — truth is a relationship >> among minds, evidence and the world. But societies do get to decide who >> owns the infrastructure through which evidence is preserved and contested. >> The centralized answer is that a few tech companies or states should >> maintain the authoritative memory of digital events; the nihilistic answer >> is that nothing can be trusted and every claim is just power in drag. >> OpenWater is a bet on a third answer: evidence organized as an open, >> decentralized, interoperable commons, with judgment left plural, >> distributed across human and machine communities. The future of truth >> should be a protocol, not a product. >> >> *(The same machinery, incidentally, turns out to be useful for doing a >> less centralized job of proof of humanity — establishing that there’s an >> actual human on the other end of an interaction, without making one >> company’s biometric orb the gatekeeper of the human internet. That’s the >> subject of the next post in this series.)**Sources and further reading* >> >> OpenWater: A Comprehensive Framework for Robust Provenance Watermarking >> <https://substack.com/redirect/6c5107a1-09d7-4182-800e-dd95f639afa2?j=eyJ1Ijoibjg3MGoifQ.He21_CkfOfKJxaU23rF_Os5N5_-qzSFgpejK31Q3t_8> >> — the underlying OpenWater design and public entry point. See also early >> prototype code here >> <https://substack.com/redirect/7d1efb3b-b453-4426-9343-8623101aff8a?j=eyJ1Ijoibjg3MGoifQ.He21_CkfOfKJxaU23rF_Os5N5_-qzSFgpejK31Q3t_8> >> . >> >> C2PA — the open Content Credentials standard >> <https://substack.com/redirect/0dd6d789-7c13-42f6-9b61-f2df4463dc1e?j=eyJ1Ijoibjg3MGoifQ.He21_CkfOfKJxaU23rF_Os5N5_-qzSFgpejK31Q3t_8> >> — open technical standards for cryptographically verifiable media >> provenance. >> >> C2PA explainer on durable Content Credentials >> <https://substack.com/redirect/a69b57bf-be4f-4244-813c-d91e262eb2d2?j=eyJ1Ijoibjg3MGoifQ.He21_CkfOfKJxaU23rF_Os5N5_-qzSFgpejK31Q3t_8> >> — why soft bindings such as watermarks and fingerprints help recover >> credentials after metadata is removed. >> >> Google DeepMind SynthID >> <https://substack.com/redirect/b0028d6f-f7c3-40bb-bf2c-a652deb91505?j=eyJ1Ijoibjg3MGoifQ.He21_CkfOfKJxaU23rF_Os5N5_-qzSFgpejK31Q3t_8> >> — a prominent vendor-operated watermarking system for AI-generated media. >> >> C2PA implementation guidance >> <https://substack.com/redirect/d7d87760-c43a-4c7d-bc18-c9f9615d9bac?j=eyJ1Ijoibjg3MGoifQ.He21_CkfOfKJxaU23rF_Os5N5_-qzSFgpejK31Q3t_8> >> — practical guidance on manifest repositories, invisible watermarking and >> fingerprint fallback. >> >> Eurykosmotron is free today. But if you enjoyed this post, you can tell >> Eurykosmotron that their writing is valuable by pledging a future >> subscription. You won't be charged unless they enable payments. >> >> Pledge your support >> <https://substack.com/redirect/2/eyJlIjoiaHR0cHM6Ly9iZW5nb2VydHplbC5zdWJzdGFjay5jb20vc3Vic2NyaWJlP3V0bV9zb3VyY2U9cG9zdCZ1dG1fY2FtcGFpZ249ZW1haWwtY2hlY2tvdXQmbmV4dD1odHRwcyUzQSUyRiUyRmJlbmdvZXJ0emVsLnN1YnN0YWNrLmNvbSUyRnAlMkZ0b3dhcmQtYS10cnVseS1kZWNlbnRyYWxpemVkLWRpZ2l0YWwmcj1uODcwaiZ0b2tlbj1leUoxYzJWeVgybGtJam96T1RBeE16VXdOeXdpYVdGMElqb3hOemczTmpneE9USXlMQ0psZUhBaU9qRTNPVEF5TnpNNU1qSXNJbWx6Y3lJNkluQjFZaTB6TkRrNU5EY2lMQ0p6ZFdJaU9pSmphR1ZqYTI5MWRDSjkueDVUT0czWF9td1hKa3ZtN1lWWGZ4Yk54R0JRTGpQN19INU9UQ1pGRGhFbyIsInAiOjIxMjczODg3MSwicyI6MzQ5OTQ3LCJmIjp0cnVlLCJ1IjozOTAxMzUwNywiaWF0IjoxNzg3NjgxOTIyLCJleHAiOjIxMDMyNTc5MjIsImlzcyI6InB1Yi0wIiwic3ViIjoibGluay1yZWRpcmVjdCJ9.87qJ_jWEmu70E0gSFz43r8_ws5d-dMJjcMpDEkeFff8?&utm_source=substack&utm_medium=email&utm_content=postcta> >> >> >> Share >> <https://substack.com/app-link/post?publication_id=349947&post_id=212738871&utm_source=substack&utm_medium=email&utm_content=share&utm_campaign=email-share&action=share&triggerShare=true&isFreemail=true&r=n870j&token=eyJ1c2VyX2lkIjozOTAxMzUwNywicG9zdF9pZCI6MjEyNzM4ODcxLCJpYXQiOjE3ODc2ODE5MjIsImV4cCI6MTc5MDI3MzkyMiwiaXNzIjoicHViLTM0OTk0NyIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.dtg3JMGQTiRqf1V0r8XdllZXXAE--yJA6h4weA1LEGs> >> >> >> Like >> <https://substack.com/app-link/post?publication_id=349947&post_id=212738871&utm_source=substack&isFreemail=true&submitLike=true&token=eyJ1c2VyX2lkIjozOTAxMzUwNywicG9zdF9pZCI6MjEyNzM4ODcxLCJyZWFjdGlvbiI6IuKdpCIsImlhdCI6MTc4NzY4MTkyMiwiZXhwIjoxNzkwMjczOTIyLCJpc3MiOiJwdWItMzQ5OTQ3Iiwic3ViIjoicmVhY3Rpb24ifQ.toB0M_gacdpRyuaGpXfD00FMbID0w2ptlellXFm9_Rk&utm_medium=email&utm_campaign=email-reaction&r=n870j> >> Comment >> <https://substack.com/app-link/post?publication_id=349947&post_id=212738871&utm_source=substack&utm_medium=email&isFreemail=true&comments=true&token=eyJ1c2VyX2lkIjozOTAxMzUwNywicG9zdF9pZCI6MjEyNzM4ODcxLCJpYXQiOjE3ODc2ODE5MjIsImV4cCI6MTc5MDI3MzkyMiwiaXNzIjoicHViLTM0OTk0NyIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.dtg3JMGQTiRqf1V0r8XdllZXXAE--yJA6h4weA1LEGs&r=n870j&utm_campaign=email-half-magic-comments&action=post-comment&utm_source=substack&utm_medium=email> >> Restack >> <https://open.substack.com/pub/bengoertzel/p/toward-a-truly-decentralized-digital?utm_source=substack&utm_medium=email&utm_campaign=email-restack-comment&action=restack-comment&r=n870j&token=eyJ1c2VyX2lkIjozOTAxMzUwNywicG9zdF9pZCI6MjEyNzM4ODcxLCJpYXQiOjE3ODc2ODE5MjIsImV4cCI6MTc5MDI3MzkyMiwiaXNzIjoicHViLTM0OTk0NyIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.dtg3JMGQTiRqf1V0r8XdllZXXAE--yJA6h4weA1LEGs&utm_source=substack&utm_medium=email> >> >> >> © 2026 Ben Goertzel >> 548 Market Street >> <https://www.google.com/maps/search/548+Market+Street?entry=gmail&source=g> >> PMB 72296, San Francisco, CA 94104 >> Unsubscribe >> <https://substack.com/redirect/2/eyJlIjoiaHR0cHM6Ly9iZW5nb2VydHplbC5zdWJzdGFjay5jb20vYWN0aW9uL2Rpc2FibGVfZW1haWw_dG9rZW49ZXlKMWMyVnlYMmxrSWpvek9UQXhNelV3Tnl3aWNHOXpkRjlwWkNJNk1qRXlOek00T0RjeExDSnBZWFFpT2pFM09EYzJPREU1TWpJc0ltVjRjQ0k2TVRneE9USXhOemt5TWl3aWFYTnpJam9pY0hWaUxUTTBPVGswTnlJc0luTjFZaUk2SW1ScGMyRmliR1ZmWlcxaGFXd2lmUS4xOUw4dmtoWTA4WGMzQTV4ZW5OU3dWZWJVN1Z2c043S3M3dzRtX3JrY2U0IiwicCI6MjEyNzM4ODcxLCJzIjozNDk5NDcsImYiOnRydWUsInUiOjM5MDEzNTA3LCJpYXQiOjE3ODc2ODE5MjIsImV4cCI6MjEwMzI1NzkyMiwiaXNzIjoicHViLTAiLCJzdWIiOiJsaW5rLXJlZGlyZWN0In0.ddZua39iUdZhgjtoW7mw4Kd37bK_d_FOz9sw49v6lMw?> >> >> [image: Start writing] >> <https://substack.com/redirect/2/eyJlIjoiaHR0cHM6Ly9zdWJzdGFjay5jb20vc2lnbnVwP3V0bV9zb3VyY2U9c3Vic3RhY2smdXRtX21lZGl1bT1lbWFpbCZ1dG1fY29udGVudD1mb290ZXImdXRtX2NhbXBhaWduPWF1dG9maWxsZWQtZm9vdGVyJmZyZWVTaWdudXBFbWFpbD1tYXR0bWFob25leWZsQGdtYWlsLmNvbSZyPW44NzBqIiwicCI6MjEyNzM4ODcxLCJzIjozNDk5NDcsImYiOnRydWUsInUiOjM5MDEzNTA3LCJpYXQiOjE3ODc2ODE5MjIsImV4cCI6MjEwMzI1NzkyMiwiaXNzIjoicHViLTAiLCJzdWIiOiJsaW5rLXJlZGlyZWN0In0.Os46S3cfKX5PAVr_2XaS5vnyLbkoIseRrax-k8UnA_s?> >> > *Artificial General Intelligence List <https://agi.topicbox.com/latest>* > / AGI / see discussions <https://agi.topicbox.com/groups/agi> + > participants <https://agi.topicbox.com/groups/agi/members> + > delivery options <https://agi.topicbox.com/groups/agi/subscription> > Permalink > <https://agi.topicbox.com/groups/agi/T08974f0b616697ac-M982f323c3130d0b0ceb55b1a> > ------------------------------------------ Artificial General Intelligence List: AGI Permalink: https://agi.topicbox.com/groups/agi/T08974f0b616697ac-Meacaf5ae8594f34c175046c4 Delivery options: https://agi.topicbox.com/groups/agi/subscription
