Argues for a new model of autonomy by embedding governance within data objects, suggesting implications for system safety.
Every autonomous system must decide locally, in the moment, without a round-trip to a central authority — a constraint imposed by physics, not preference. Yet the prevailing trust models assume a central point of deference (an identity provider, a policy server, a certificate authority, or a human in the loop), and the dominant safety paradigm bolts an external governor onto a probabilistic controller. Neither survives the disconnection that defines autonomy. This paper argues that trustworthy autonomy requires authority, governance, and identity to be carried inside the data object the system acts on — the object-as-authority model long known to capability security — and that the forcing function making this a prerequisite is autonomy itself, not decentralization. It holds even when the underlying infrastructure is fully centralized. We describe a carried-governance substrate in which identity, governance, lineage, routing, and execution become properties of the object; give an honest account of what software can and cannot guarantee against an adversarial host; and argue that the recombination is novel because the prior art teaches away from it, toward centralization.
No takes yet. Share an insight, caveat, or question.
Nicholas Clark (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: