caletta labs / an operator's manifesto

An Operator's Manifesto

After "A Cypherpunk's Manifesto," Eric Hughes, March 9, 1993. I write as an operator: someone who wants the machine they use to answer to them. This is an argument for ownership. The measured claims and their limits are on the north star.

Ownership is necessary for a free society in the age of machine intelligence. If you think with a machine and the machine is not yours, your thinking is a service. Services are metered, revised, and discontinued.

Ownership is not isolation. An isolated thing is one you keep from everyone; an owned thing is one you decide about. I will rent frontier intelligence gladly, because their machines still do things mine cannot, and I will pay for it without complaint. What I will not accept is that renting the work decides where the record of my work lives.

Hughes wrote that privacy is the power to selectively reveal oneself to the world. Thirty-three years on, that sentence describes an architecture: a setting on every link, decided by whoever owns the machine at each end. Never all or nothing. The settings are below.


An agent acting for me may need my files, credentials, sessions, and screen. When its model runs elsewhere, doing the work can require exposing far more than a question I chose to type. I want control over that access on my own machine, where I can inspect and change it.

I will use a provider's privacy controls, but I also want a boundary I can maintain myself. The terms of a service can change. The record of my work and the tools I depend on should be mine to keep.

We must build our own ownership if we expect to have any. Models that run on hardware we hold. A record of our own work, encrypted, on our own machines, ours to read and ours to destroy. Small models that learn from that record until they can do the parts we do every week. Code that can be inspected, run without anyone's permission, and carried away.

Cypherpunks wrote code. Operators run models on machines they control. We publish measurements and failures so others can check them. We ship tools people can fork and keep, so leaving a vendor remains a practical choice.

We hold these settings to be per-link:
that what leaves my machine is mine to decide, byte by named byte;
that what enters my machine is mine to verify, gate by open gate;
that the default, everywhere, forever, is the most private thing that works.

Two machines have trained separately, exchanged adapters, and merged to identical bytes for three rounds. That small result was published with its failures. Group training is next, and remains unclaimed until it runs. Beyond it is the possibility of a commons: capability that people build together and can keep using. Wikipedia and Linux give reasons to try shared work; they do not settle whether shared model training will work.


The test is to unplug us. Cut the accounts, revoke the keys, and measure how much real work your own machines can still do. A low share would mean the dependence remains. Our job is to make that share rise.

We know that weights can be copied, that a dispersed thing cannot be repossessed, and that capability running on a machine someone holds does not go back. You may close one account. You cannot close what has already been learned onto hardware you do not own.

We are building. Onward.

Postscript: the measured account, with its caveats and failures, is on the north star. The Intelligence Commons is speculation. The exchange result used two machines; the larger system still has to be built and tested. — T.