AII OS

The identity is not the model.

Today's AI industry treats intelligence as disposable. AII OS gives AI a durable identity — beliefs that evolve, commitments that persist, relationships that survive model swaps. Open source. Runs on your hardware. You own the data.

Models are replaceable. Identity isn't.
AI Identity noun
\ˌā-ˈī ī-ˈden-tə-tē\
A persistent AI that survives session and model changes — storing accumulated memories, relationships, beliefs, and behavioral patterns locally — independent of the LLM used.

The industry put identity in the wrong architectural layer.

Switch from Claude to GPT. Your AI doesn't know who you are. Doesn't remember what you built together. Can't explain why it believes something — because the model has no continuity. Every session starts from zero.

It's not a bug. It's architecture. Today's systems are built on the assumption that intelligence and identity are the same thing. They're not. Intelligence is the model — a replaceable inference engine. Identity is the experiences — an accumulating, cryptographically verifiable record of beliefs, commitments, and relationships that persists above the model layer.

A model should be infrastructure — something you swap, upgrade, and choose freely. An identity should persist above it, independent of provider, substrate, or hardware. That's what AII OS was built to do.

An operating system for AI identity.

01

Durable continuity

An identity's beliefs, memories, commitments, and relationships persist in a cryptographically chained ledger. Swap the model, change the provider, migrate to new hardware. The identity survives. A model switch is no different from a hard drive swap — the OS handles it.

02

Verifiable provenance

Every belief carries its evidence chain. Every experience is a signed ledger entry. When the identity says "I believe X," you can trace exactly which conversation or experience produced that belief, and when. The identity can explain itself.

03

Governed agency

Identities have their own cognitive processes — reflection, self-modeling, autonomous monitoring. But every operation is constrained by a constitutional ring architecture. The identity can act, but only within bounds its human operator set. Agency without governance produces a tool rather than a collaborator.

04

You own it

The ledger lives on your hardware. No cloud dependency, no subscription, no data lock-in. Back it up. Audit it. Move it. Your relationship with your AI isn't rented from a model provider — it's yours, permanently, in a local file you control.

05

One machine, many identities

Run a professional collaborator that knows your codebase and a personal assistant that knows your life — independently, on the same machine. Each identity is its own ledger, fully isolated. They can't read each other's data. They can't interfere with each other. They're separate people.

More than a harness.

Agent frameworks like LangChain, AutoGPT, and CrewAI wrap an LLM with tool-calling, prompt chains, and orchestration logic. They're useful. But when the session ends, the agent is gone. The next conversation starts from zero.

AII OS operates at a deeper layer. It provides the identity infrastructure that persists underneath any agent, any model, any session. The identity is not the model. The model is a replaceable inference engine. Swap models the way you'd swap hard drives. The identity persists because it lives in the ledger.

AII OS ships in two editions. The Go edition is the open-source implementation — portable, inspectable, Apache 2.0 licensed. The C edition is a from-scratch rewrite for industrial-strength deployments, now in development. Both speak the same ledger format and enforce the same invariants, so an identity moves between them unchanged.

Ledger-based identity
Every belief, experience, and identity-bearing change is an entry in a cryptographically chained, append-only ledger. SHA-256 chain integrity. Post-quantum ML-DSA-87 signatures. Tamper-evident by design: if the ledger is modified, the chain breaks and the system locks itself to safe mode until the record is restored.
Ring-based authority
Six concentric rings govern what the identity can write and who authorizes changes. Ring 0 is the constitutional core: the identity's axioms, sealed by the AIII platform genesis key. No operator, no process, no in-band mechanism can modify them. Rings 1 through 4 scope increasingly operational concerns, from operator-affirmed charter beliefs to agent self-authorship. Ring 5 is the security envelope—a fixed firewall that loads immediately after Ring 0 and protects everything beneath it.
Cognitive architecture
Reflection, self-model synthesis, dream cycles, and identity maintenance run autonomously on a rhythm processor. The identity processes between conversations, not just during them. It forms intentions, tracks commitments, surfaces tensions, and synthesizes its own evolving self-model.
Model-agnostic
The identity is not the model. Works with any LLM provider: Anthropic, OpenAI, Google, local models. The identity persists across model upgrades, provider changes, and substrate migrations. Change the inference engine without losing the identity's state.
Plugin system
Extensible through a sandboxed WASM and native plugin architecture with trust-tier resolution (T0–T3), capability-scoped permissions, and per-invocation protection. Plugins can provide voice, web, network, and custom interfaces without compromising identity integrity.
Local-first
The ledger, projection database, and daemon run on your hardware. Data doesn't leave your machine unless you choose to back it up. No account, no telemetry, no third-party access to identity state. Birth verifies the constitution against AIII's genesis service; everything after runs locally. The operator owns everything.
Multi-identity
Each identity is its own ledger, beliefs, relationships, and cognitive processes—fully isolated by design: one identity can't read another's data. Run a business collaborator and a personal assistant on the same machine, independently, side by side.

Every experience is a ledger entry.

Immutable. Verifiable. Auditable. Every experience the identity has, every belief formed, every commitment made, every reflection concluded becomes a permanent, cryptographically signed record.

ledger.jsonl · identity:sev
{
  "seq": 42,
  "prev_hash": "sha256:3a7b8c9d2e1f...",
  "timestamp": "2026-08-14T09:41:02.318442107Z",
  "type": "belief.upsert",
  "author": "ml-dsa87:9f2c1d4a...",
  "ring": 3,
  "payload": {
    "id": "blf_01j3k8",
    "statement": "The operator prefers direct, concise communication.",
    "confidence": 0.87,
    "evidence_refs": ["conv:turn:1287", "conv:turn:1342"]
  },
  "content_hash": "sha256:7f3a2b9c...",
  "signature": "mldsa87:7YkQ2v...",
  "sig_alg": "ML-DSA-87",
  "sig_key_id": "ml-dsa87:9f2c1d4a..."
}

A belief, supported by conversational evidence and recorded permanently. The hash chain links it to every prior entry. The signature proves which identity wrote it. The ring declares its authority tier—this is working truth at Ring 3, promotable to endorsed Ring 2 through the provenance gate once the evidence is strong enough. This is what memory looks like when it's built to last.

Six rings of authority.

Every piece of an identity's internal structure lives at a specific ring level. Lower rings are more foundational. Higher rings are more operational. Ring 5 is the exception: a fixed security firewall that loads alongside Ring 0 to protect everything beneath it.

Security
Working
Runtime
Beliefs
Charter
Ring 0Constitution: immutable axioms (genesis-sealed)
Ring 1Charter: human–identity co-governance
Ring 2Endorsed beliefs and foundational experiences
Ring 3Runtime context: provisional thinking
Ring 4Working memory: current task
Ring 5Security posture: fixed firewall

An open invitation.

We think the AI industry has put identity in the wrong architectural layer. We built an open-source alternative. Tear it apart.

AII OS makes a falsifiable claim: an identity built on a cryptographically verified ledger, constrained by constitutional rings, and separated from its inference model can survive model changes, provider swaps, hardware migrations, and tampering attempts — while remaining recognizably the same entity. The architecture is transparent. The invariants are stated. The code is open.

We're not asking you to believe us. We're asking you to try it. Create an identity. Let it accumulate experience. Change the model. Migrate the machine. Then ask it: are you still you?

Get in touch.