The journey is the point
In my last newsletter I mentioned that over the summer I started vibecoding my content pipeline by creating an Obsidian plugin called Reading Queue Manager ("ReadingQ"). Since then I (or rather Loki, my persistent personal agent) have added Hub Manager to cover all but the publishing end of the pipeline, and upgraded ReadingQ to support the entirely unplanned Karpathy LLMwiki I've added to my private library.
Rebuilding the local-first path of my content pipeline. Adapted from MyHub on the Atmosphere (v5).
And now, of course, I'm having fun exploring the result with Obsidian's Graph View:
A graph view of the first batch of my reading queue after ingestion into my Karpathy LLM wiki by Loki - Visualising my Karpathy wiki
But now that I have Loki building the tools to move knowledge through my pipeline, maintaining a rich knowledgebase inside it, and using it to answer my questions, I had to draw a line I don't want AI to cross:
"the actual writing cannot be performed by AI, because writing = thinking. Not that Loki can't write - it can, badly, but like all LLMs it's improving. But the process of writing is indispensable to both learning other people's ideas and coming up with your own" - Hub Manager: drawing the line AI won't cross
Related links
Loki keeps offering to cross that line, of course: when it comes to personal agents, "persistent" has multiple meanings. But in fairness, it was Loki that pointed out that a couple of the resources I Hubbed as it developed the above tools were directly relevant to drawing that line:
Terence Tao on OpenAI's Navier-Stokes solution. One of the world's great mathematicians argues that AIs solving famous maths problems could be a net negative for mathematics, because it's the journey, not the destination, which is of most value. Efforts to solve problems like Navier-Stokes "have historically led to fundamental insights", because exploring "alternate routes ... that are superficially "dead ends"... end up being highly instructive". Today, however, we have a solution from OpenAI which kept the process to itself, bringing "almost no value added to mathematics as a consequence... Prematurely solving the problem by purely AI-powered methods ... can contaminate this process to the point where it actually becomes a net negative."
This is also a problem for science, not just maths, and it starts with science education: MIT's report on AI and Education, for example, points out that while replacing undergraduate research assistants with AI may be resource-efficient, "research is also an apprenticeship... learning-by-doing may produce seeming 'inefficiencies,' but that's a feature, not a bug."
Note that neither are anti-AI per se — it’s how it’s being used that’s the problem.
Verified humans, or surveilled citizens?
Ringfencing AI from the content you write, of course, is also pretty useful for differentiating your voice from the multitudes of bots flooding the zone with slop.
Useful, but rarely enough: how can you prove that you're not a bot?
Aster: trust signals for scientists
Allowing people to prove various aspects of their identity (age, humanity, name, etc.) is directly relevant to ASTER, a new service my ATScience friends and I announced last month. Aster will provide researchers and academics an Aster identity and a range of other Atmosphere services, in the process introducing new trust signals into online conversations.
My small role has been to articulate the issues around verification:
"Who counts as a "researcher or and academic"? ... What exactly are we identifying" by giving someone an Aster ID, and "How do we indicate any of this online? A trust signal isn’t much use if nobody sees it" - How should verification work on Aster?
As the post makes clear, we don't yet have all the answers, so feel free to chime in. Aster's invite phase will be launched next Monday at the Institute of Open Scientific Practices (IOSP 2026) in Leiden. I'll have more on it soon, but until then subscribe to the blog, follow the main account, and check out the Aster starter pack and its custom feeds.
Risky business
As the above post points out, however, there are all sorts of problems with verification.
Many are explored in the resources tagged age verification on my Hub, including:
Age Verification Architecture - this IETF working document summarises a huge amount of research, and comes to scathing conclusions about the risk/reward balance of most attempts at age verification.
Papers, Please: A First Look at Age Verification on the Web (pdf) - looks at the US experience, where "twenty-five US states... have adopted laws compelling websites with content “harmful to minors” to verify their users’ ages. Many websites ... rely on third-party services, effectively outsourcing age verification... little is known about how these services are shaping the web and affecting user privacy". They found a service used by over 60% of the sites they analysed, so they reverse-engineered it. What they found was pretty chilling
Is a Ban a Plan? (pdf) - This report from "seven leading experts [in]... children's rights, psychology, computer science, cryptography, and family advocacy" focuses on social media bans, and finds along the way that age verification is either easy to circumvent, or dangerous to privacy while excluding people. As a result, "children ... become harder, not easier, to protect".
Verification done properly
If verification will become commonplace - and with the EU Kids Act, that looks likely - then it must be done properly to mitigate those risks.
While there are good arguments against age verification, it's also difficult to argue against building safe spaces for kids which cannot be infiltrated by adult sexual predators. Age is also just one form of verification: other use cases include allowing people to prove they are who they say they are and preventing impersonations (username verification), and helping identify which accounts are not bots (humanity verification).
But as the above resources point out, achieving these goals by forcing people to upload their ID documents:
is exclusionary: not all users have ID documents
risks "mass data collection on both adults and children"
creates massive targets for hackers to steal private information.
Which brings me to some other friends of mine, who are preparing a demo at the Digital Flanders Fair in Gent later this month of how verification done right on the Atmosphere could look. Their approach leverages the EU Digital Identity Framework (eIDAS) - trusted infrastructure provided by each EU government.
In Belgium's Flanders region, that's provided by Athumi, a data intermediation services provider created by the Flemish government "to grow the data economy while ensuring citizens’, companies’ and governments’ data remains safe". Athumi and Eurosky will demo how Belgian users of Eurosky's Mu.Social app will be able (if they wish!) to authenticate themselves using the Belgian government's MyGov.be or (later) Itsme apps to get “Verified human” and/or “Verified name” labels displayed on their mu social profile:
An early mockup from the demonstration project. The checkmarks stand in for the logos of two different verification services.
Crucially, getting those labels does not involve uploading your identity documents to some VC-backed company with shoddy security.
Instead, Athumi uses EIDAS infrastructure to provide Mu with the trust signals it needs, without Eurosky seeing any personal data at all.
A slide from the upcoming demo (David Van den Brand, Robin Berjon)
And because the same infrastructure is already operational in most EU countries, this approach could be mainstreamed across Europe without necessarily reinventing the wheel 20+ times.
They are not, however, demoing age verification as that information would be public, allowing anyone to identify children online. But Athumi has already figured out how the new ATproto permissioned data upgrade could support age bracket identification (eg., 13-15, 16-18, 18+) without releasing any personal information, opening up the intriguing idea of social apps built for different age groups, introduced as part of school curricula.
WSocial's red flag collection
This is all in sharp contrast to WSocial, which admitted as they recently published their Constitution that their (leaky) servers do actually store their users' ID documents, directly contradicting their PR manager, who assured me at their launch party in Brussels that each WSocial users' identity scans "never leave their device".
WSocial's Constitution looks like a welcome step in the right direction, as is their recent introduction of a migration service away from WSocial, finally making credible exit a reality for their users. But they're still storing your verification scans, so I hope they keep working at removing the red flags they've been picking up since launch.
Also worth a look
Three more resources worth checking out:
Let's Talk Money is a great exploration of how money could flow through the Atmosphere, asking you to "imagine an article costs twenty cents. Who gets paid?" Getting the answer right is the difference between an Atmosphere which creaks along, relying on goodwill and public funding, or thrives on a self-sustaining basis.
You Should Probably Leave Substack does what it says on the tin: "You should probably leave Substack. Here's why and how", along with useful tips for those trying to convince our favourite writers to leave the famous Nazi bar.
If you want to see what the ATmosphere is actually talking about, Atlas is "a living map of what Bluesky is talking about", rebuilt every six hours from the entire firehose.
All newsletters on my Hub, through which you can always contact me.