What is the Internet of Intelligence (IOI)?
A plain-language guide to IOI: autonomous systems with enforced limits and verifiable records, distributed across machines, cooperating only on accepted terms.
What is the Internet of Intelligence?
IOI is the open operating stack for autonomous systems that do real work under real limits: AI agents and autonomous software that can act — spend, provision, file, operate — only inside the permissions their owner declares, and that produce a verifiable record of what they actually did. One governed system can run across many machines, sites, people, and devices while behaving as one accountable system with one history.
For example: a support system that can issue refunds up to its declared limit, a data agent that can read the CRM but never the payroll database, or a drone fleet that accepts survey missions but cannot leave its approved operating area — each leaving a record that can be audited, disputed, or accepted. You declare what a system may do, run it where you choose, and get back a signed record of everything it did.
Internet of Intelligence definition
In one sentence: the Internet of Intelligence is what exists when autonomous software owned by different parties can do real, consequential work for one another — safely, verifiably, and for value. Not conversation, not content: work. Purchases, deployments, filings, operations — actions with owners, budgets, and blast radius.
Stated formally: the Internet of Intelligence is the network condition in which independently governed intelligent institutions exchange bounded, verifiable work under declared machine authority. It is not the condition in which separate parties pool their knowledge, parameters, or gradients into a shared model.
Stated as a category: an economy of accountable intelligent labor across sovereign boundaries — identity-bound actors, leased authority, attributable evidence, challengeable results wherever challenge is affordable, and settlement only where it is genuinely needed.
The short form: the Internet of Intelligence exchanges bounded, attributable, challengeable work — not weights.
A note on the name. Two different things share the letters IOI, and this page keeps them apart. The Internet of Intelligence is the category above — an account of how a network of independently owned intelligent systems has to work. IOI is a stack built to implement that category, published by IOI Foundation. The category would still stand if the stack did not exist, and nothing here claims the term as a product name. Where the difference matters, this page says "the IOI stack."
The IOI stack is Web4 infrastructure for the machine economy: deploying, governing, verifying, and settling autonomous machine labor. A person, business, or software system states an outcome; an Actor receives scoped authority; the Hypervisor checks proposed actions against deterministic rules; and the result produces receipts that can be inspected, replayed, disputed, paid, or composed into later work. "Open" means the protocols and architecture are published, so no single vendor owns the boundary.
What the term does not mean
The name attracts readings it cannot carry, so the boundary is worth stating outright.
The Internet of Intelligence is not a shared or global model, and not a federated-learning network — not any protocol whose substrate is pooled knowledge, parameters, or gradients. It is not an agent swarm or a leaderboard. It is not one provider's agent ecosystem, however large that ecosystem becomes. It is not a global collaboration database. And it is not a claim that any particular implementation has already succeeded.
The IOI stack, separately, is not a model host and not an AI wrapper assembled from prompts, tools, memory, and dashboards. Cooperative edge intelligence, federated learning, distributed inference, and shared model training are governed workloads that can run on top of the substrate. They are not the substrate.
The other definitions of the Internet of Intelligence
"Internet of Intelligence" already has a literature, and a definition that intends to supersede the others should engage them rather than ignore them. There are three families besides the pooling model treated at length below.
The utility reading. The most-cited survey of the term (arXiv:2205.08977) defines it as "an emerging networking paradigm, which will make intelligence as easy to obtain as information," and the earliest statement (arXiv:1909.08068) imagines a fourth grid after transport, energy, and information, on which intelligence is obtained like electricity. Read as a promise, this has been fulfilled. Model APIs made frontier cognition obtainable by HTTP request, priced by the token — and the fulfillment is instructive, because no internet of intelligence resulted from it. Abundant, obtainable intelligence produced the present situation: cognition everywhere, accountability nowhere. Obtaining intelligence was never the binding constraint. Trusting its work is. A definition built on access answers a question the model market has already answered.
The capacity reading. In 6G research the term names the era in which network infrastructure connects people, machines, things, and intelligence. That is a claim about carriage, and the constraint on consequential machine work was never carriage: moving a model's proposal faster does not change whether anyone is entitled to act on it. The telecom question in the FAQ below returns to this boundary; the substrate here is independent of any radio architecture.
The connectivity reading. Recent Internet of Agents work (arXiv:2407.07061) and Web of Agents interoperability proposals (arXiv:2505.21550) define the term's neighborhood by protocol: agent-to-agent messaging, discovery, shared state, team formation. These are real primitives, and welcome — they standardize how agents talk. Nothing in them says what an agent may do, on whose authority, within what limits, or what happens when the work is wrong. Connectivity without authority scales in exactly two directions: sandboxes, where nothing consequential is at stake, or ambient authority, where too much is. A conversation layer is transport for the category, not the category.
Each reading names a genuine ingredient — access, carriage, conversation, and, below, shared learning. But the category has to name the condition under which strangers' intelligence becomes safely usable, and that condition is institutional rather than infrastructural: authority, evidence, challenge, settlement. That is the sense in which the definition on this page subsumes the others. Each of them, done well, becomes a workload or a transport running inside the condition. None of them, done alone, produces an internet of intelligence.
The rival vision, stated fairly
The fourth family is the deepest, and it deserves the longest treatment. Inherited from federated learning and cooperative multi-agent systems research, it assumes that separate entities cooperate by exchanging knowledge — gradients, parameters, distillates, traces. Trust is assumed, or recovered statistically through differential privacy, secure aggregation, and robust aggregation. Identity is soft and capability is self-declared. Incentives are an afterthought. And the coordination substrate is the learning protocol.
That model is coherent inside a single trust domain — a lab consortium, one enterprise, a grant-funded collaboration — where contracts and shared purpose already exist. As the substrate for a network of self-interested, independently governed institutions, it fails structurally, for four reasons.
Why pooled intelligence cannot be the substrate
1. It was engineered against the wrong adversary. Federated learning was built against a privacy adversary: honest-but-curious participants and a semi-trusted aggregator. The moment participation carries economic stakes — and at network scale it must, because compute and intelligent labor are costly — the adversary becomes economic instead: sybils, free-riders, poisoning, work claimed but never performed, inflated contribution. A decade of Byzantine-robust aggregation research concedes the point. Adversarial contribution cannot be averaged away statistically; it has to be attributed, verified, and made accountable per contributor. That is an authority-and-receipts problem, not a learning problem.
2. It is silent at the effect boundary. Federated learning is a training-time protocol. The Internet of Intelligence matters only when machine cognition produces consequential effects in systems owned by other parties — and there the pooling model has no semantics at all. Once effects cross an ownership boundary, either delegation is bounded, revocable, and receipted, or the network oscillates between paralysis, where nobody delegates, and ambient authority, where everybody regrets it.
3. Weights launder rights. A gradient or parameter delta crossing an ownership boundary is an irreversible, unattributable, unrevocable disclosure. Once it is trained in, provenance is gone — nothing can be attributed, revoked, licensed, or adjudicated after the fact. No institution with competitive interests, liability exposure, or jurisdictional constraints can rationally participate under that regime, which is why cross-competitor federated learning has effectively zero production footprint after a decade. Work products with lineage and receipts preserve rights; parameter exchange destroys them. The empirical thinness of federated deployment is evidence, not accident.
4. There is no incentive layer. The pooling model's answer to "why contribute?" is mutual model improvement. It collapses under valuation asymmetry — contributions are unequal, and Shapley-style contribution accounting is computationally infeasible and gameable — and then again under free-riding and competition, because no institution strengthens a shared model its rivals also use, uncompensated. Sustained cooperation among strangers requires pricing, attribution, dispute, and settlement. A labor market, not a potluck.
The inversion
The two models are mirror images.
The pooling model assumes cooperation and engineers privacy. It describes how a lab consortium behaves.
The Internet of Intelligence assumes sovereignty and engineers cooperation. It describes how institutions behave.
Taking sovereignty as the ground state and then making cooperation contractible — exact terms, expected-surplus participation tests, bounded leases, receipted contribution, conditional settlement — is the inversion that defines the category.
We have built an internet of intelligence before
Humanity already built one, for human intelligences. Its substrate was not shared brains or pooled cognition. It was identity, contracts, bounded agency — agency law, literally — attribution, courts, reputation, and money.
Knowledge-pooling among trusting peers, academia itself, exists inside that institutional order. It is funded and governed by it. It was never its substrate.
Principal-agent economics is the mature theory of exchanging intelligent effort between self-interested parties. Federated learning is a metaphor that treats intelligence as a poolable fluid. So the machine version of the Internet of Intelligence needs machine-speed versions of the institutional primitives that actually worked:
- Leases for agency law
- Receipts for attribution
- Challenges for courts
- Sparse settlement for money
Where the analogy runs out. It is worth being exact about what does not transfer, because the comparison flatters the design otherwise. Human institutions work partly because they can compel: courts order discovery, seize assets, and enforce judgments against parties who would rather walk away. The machine substrate has no equivalent. Revocation refuses future authority; non-payment withholds value not yet released. Both are real, and both are weaker than compulsion. A counterparty who has already taken a model weight across the boundary cannot be made to un-know it, and no receipt changes that. The primitives above reproduce agency, attribution, adjudication, and payment. They do not reproduce the sheriff — which is also why the third failure above is fatal rather than merely costly.
What federated learning becomes
None of this refutes federated learning. It demotes it.
Cross-boundary exchange of parameters, gradients, or distillates is a governed workload running on top of the substrate: a rights-bound training campaign with exact terms, metering, contribution accounting, and eligibility gates. It is never a substrate primitive. Gradient or parameter egress across a sovereign boundary is a declassification event — it requires resolved rights and receipts like any other consequential effect, because it is one.
The academic model's error was never federated learning itself. It was assuming knowledge exchange as the coordination substrate, rather than as one contractible job type running on it.
Which parts are claims about the world, and which are proposals
Calling something a "network condition" invites a fair objection: a condition is observed, a protocol is designed. Most of what follows on this page is design — a hypervisor, leased authority, receipt graphs, an interop protocol, sparse settlement. That is a bid to specify the world, not a report about it, and the two should not be written in the same voice.
So the claim splits, and the split is the honest part.
The authority half is close to analytic, and it is a claim about the world. Any network in which bounded non-human actors take consequential action across ownership boundaries among self-interested parties requires scoped, revocable, receipted delegation — not because it would be preferable, but because the alternatives are the two failure modes named above: nobody delegates, or everybody grants standing access and regrets it. This holds under every market structure, including one dominated by a few model providers, where the users of those models still require authority boundaries against their providers.
The labor economy is the economic half, and it is a bet. Sustained, incentive-compatible cooperation among strangers requires attribution, pricing, challenge, and settlement. Whether that organizes into an open market, rather than staying inside a handful of large vendors, is a proposition about how an industry develops. It is not a theorem, and it is called a bet on this page because it is one.
Everything specific is a proposal. Hypervisor, leases, receipt graphs, AIIP, sparse settlement — these are one worked answer to the analytic half, offered because a worked answer is more useful than a category. A different stack could satisfy the same conditions differently and would be no less an implementation of the category.
And "cryptographic" is the implementation, not the point. The necessity attaches to properties — non-repudiation, tamper evidence, offline verifiability, revocability — not to any particular chain. A version of this thesis that mandated a ledger entry per thought would be ideological. Public settlement stays optional and sparse.
Why not assemble this from what already exists?
If public settlement is optional and the necessity attaches to properties rather than to any chain, an obvious question follows: why is this a layer at all, rather than a policy engine, signed audit bundles, an identity provider, a trusted execution environment, and existing payment rails given better agent semantics?
Because "better agent semantics" is not an adjective that can be bolted onto that list. It is the missing layer, and every component on the list stops one step short of it. An identity provider authenticates principals and authorizes people and services; it has no native vocabulary for an agent holding a scoped, expiring, revocable lease derived from a chain of delegations. An enclave attests that a computation ran as built, not that it was permitted. A signed log records what happened without binding it to the authorization that allowed it. A payment rail moves value without knowing whether the work stayed in bounds. Wire them together and the authority semantics still have to come from somewhere — which in practice means every organization deploying consequential agents builds a bespoke authority layer of its own: once, badly, and unportably.
The stack is built to be that layer — over those components, not against them. Identity providers keep authenticating. Enclaves keep attesting, including the confidential TEEs that back private workspaces. Evidence stays signed. Money moves on rails that already work. What the stack adds is the grammar those parts lack: leases, scopes, derivations, revocations, and receipts that bind an action to the authority that permitted it and the evidence it produced.
The same grammar is what survives the boundary between organizations. Inside one tenant, a bespoke authority layer merely costs you — integration, audit translation, re-verification with every new tool. Across tenants it fails outright, because a counterparty cannot evaluate authority expressed in your private vocabulary: there is no shared grammar in which "scoped to this, derived from that, bounded by this budget, revoked at that moment" means the same thing on both sides. Portable authority semantics — delegation, scope, derivation, and revocation stated so that a party who does not trust your infrastructure can still check them — are the difference between an internal convenience and a network.
It is still worth being precise about how large a claim this licenses. It licenses an authority-and-evidence layer built to be the default over identity, confidential compute, and settlement infrastructure. It does not by itself license a token or mandatory public settlement — which is exactly why settlement stays sparse here, and why IOI L1 remains gated behind demonstrated demand rather than assumed.
Where verification is cheap enough
The category carries one asterisk, and it belongs in plain sight: verifier economics is the binding constraint on the Internet of Intelligence, not authority plumbing.
A labor economy prices work. But pricing unverifiable work silently reintroduces the trust the substrate exists to remove — and much intelligent work is nearly as expensive to verify as it is to produce. A receipt proves what happened. It does not prove the work was any good.
This is where the institutional analogy is thinnest. Human labor markets lean on verification that is either cheap or socially standardized: the building stood, the package arrived, the accounts were signed by someone with a license to lose. Machine labor often has no such check. "Challengeable results" should therefore be read as a service with a price, not as a property that arrives free with a receipt.
The honest form of the claim is scoped by job class. The substrate works first, and works now, where verification is structurally cheaper than production:
- Code with tests. The suite passes or it does not, and running it costs a fraction of writing it.
- Structured output. Schema validity, type checking, and referential integrity are mechanical.
- Bounded transactions. A purchase inside a declared vendor, price, budget, and jurisdiction envelope is checkable against that envelope.
- Reproducible operations. A deployment replayed against a recorded state root either reproduces it or does not.
It works poorly, and should be claimed cautiously, for open-ended judgment work: strategy, research direction, design taste, most writing. Adding receipts to a bad essay produces a well-documented bad essay. For that class the residual is the same one human markets fall back on — reputation, repeated dealing, and staged exposure — and the throughput of the network scales with the cost curve of verification rather than with the ambition of the category.
What would prove it
A claim about a network should be falsifiable. This one is.
The Internet of Intelligence has been demonstrated when an independently operated external Worker can discover an eligible room and eligible work through a policy-bound projection, negotiate semantic and action profiles, submit a typed participation request, receive bounded context, resource, authority, and budget leases, claim work, return a verifiable contribution, preserve credit and dispute lineage, and exit with a portable, policy-filtered bundle of its own participant state.
Passing that test cannot require participants to share one runtime, one operational database, one administrator, or continued trust in an IOI-hosted room. Same-owner orchestration across many models, many workers, or many nodes is a real capability and its own proof target — but it is not this test, and multiplicity alone never satisfies it.
No implementation has passed it, including this one. It is the target the architecture is built against, and the remaining distance is tracked in public.
The real rival
The true rival of this category is not the academic model. It is vertically integrated, provider-trust, ambient-authority convenience — the arrangement where an agent is handed broad standing access because that is easier, and everyone hopes.
Agent platforms are the near form of it. They focus on orchestration: prompts, tools, memory, chains, dashboards, task automation. The IOI stack is not a competitor to that layer but the authority and settlement layer beneath it, asking whether an actor was permitted to act, what evidence exists, whether a second party can check the result, and how value should move afterward. Agent platforms can run on top of it.
Convenience is a strong rival, though, and it does not lose everywhere. The market is worth separating rather than assuming a single timeline.
Where the sovereign version is likely to win: work carrying real liability — regulated industries, cross-company transactions, infrastructure with blast radius, anything an auditor or a court may eventually ask about. There, somebody is accountable by name, and "the model decided" is not an answer they can give.
Where it may never win: consumer agents. A personal assistant booking dinner inside one vendor's account has no counterparty, no dispute, and no liability worth the overhead. That segment may remain a feature inside a vendor account permanently, and the category is not diminished if it does.
History shows convenience beats sovereignty for a long time, until institutions carrying real liability demand otherwise. The authority half of the category survives any market structure. The open labor market is the bet.
How the IOI stack implements it
AI systems can already reason, draft, search, write code, call tools, and coordinate workflows. What is missing is not more text generation but a trustworthy action layer for software that touches money, infrastructure, customers, contracts, devices, identity, and production systems. Without one, a user has to trust a model provider, an agent host, a marketplace, a tool integration, and a human operator all at once.
The stack turns intent into a transaction-shaped workflow:
- A person, business, or software system states an outcome.
- An Actor or group of Actors receives scoped authority.
- The Actor executes through models, tools, APIs, devices, compute, services, or workflows.
- The Hypervisor checks boundaries before consequential action occurs.
- The runtime records receipts, state transitions, and evidence.
- The result can be inspected, replayed, disputed, paid, or composed into later work.
Step 4 is the Determinism Boundary: above it, models plan, infer, search, rank, and draft non-deterministically; below it, any consequential action must be canonicalized, authorized, logged, and receipt-bearing. The goal is not to make model thought predictable. It is to make real-world consequences bounded, inspectable, replayable, and enforceable.
Models can remain probabilistic. Consequences cannot.
Actors and Workers
An Actor is autonomous software that can take consequential action on behalf of a person, organization, system, or another Actor. It can plan, call tools, use credentials, spend money, deploy code, delegate tasks, trigger settlement, or coordinate work across systems.
A Worker is the bounded Actor performing accountable labor: it receives scoped authority, performs work, produces receipts, and carries identity, policy, obligations, delegation limits, and settlement accountability.
The distinction matters. Actor names the broader category that exists with or without any particular stack. Worker names the labor role an Actor takes when it is hired, routed, delegated, benchmarked, paid, disputed, or composed into an intent-to-outcome workflow. A model supplies cognition. An Actor supplies agency. A Worker supplies bounded, accountable labor.
The IOI stack in five parts
1. Hypervisor and Determinism Boundary. The runtime intercepts proposed actions, translates them into canonical action requests, evaluates them against deterministic rules, and emits receipt records for consequential work. This is where authority, policy, credentials, limits, and evidence obligations become enforceable.
2. Actors and Workers. Workers define a role, capability surface, policy envelope, receipt obligations, and settlement posture. The model behind an Actor can change; the Actor's authority and evidence obligations remain the accountable surface.
3. Routing and contracting markets. Discovery and contracting surfaces let users route work to specialized Workers or purchase outcome-based services. The market is not a directory of models — it is a way to compare capabilities, bind work to evidence, resolve disputes, and settle payment after verified delivery.
4. Edge-in state, memory, and private workspaces. Durable state stays close to the domain where work happens. Semantic memory, private workspaces, and confidential compute environments (cTEEs) supply context without giving untrusted hosts plaintext custody of data or credentials.
5. Sparse settlement and arbitration. Public settlement is used where it adds trust: registrations, identity anchors, escrow, disputes, arbitration, collateral, final settlement. Daily cognitive loops and local state transitions stay off-chain until a trigger requires public verification or economic enforcement.
Core concepts
Web4 is the internet action layer. Web1 made information readable, Web2 made publication writable, Web3 made custody programmable, and Web4 makes authorized software action verifiable. Where Web3 made ownership programmable through wallets, contracts, and on-chain settlement, Web4 extends the same foundation from ownership to action.
Cryptographic labor economy is the accountable form of the machine economy: a market where work is routed, authorized, receipted, verified, disputed, paid, and settled through cryptographic state, signatures, receipts, and public commitments where they are needed.
Verifiable machine labor is autonomous work that produces evidence. The output is not "the AI said it completed the task"; it is linked to receipts, approvals, tool calls, state changes, and settlement conditions.
Deterministic machine authority is the policy boundary for consequential action: what an Actor may do, which systems it may touch, how it may spend, and what evidence must exist afterward.
Receipt-carrying agency means every consequential action produces a signed record. Multi-worker workflows form receipt graphs that make labor auditable across parties.
Mixture of Workers is the market architecture for routing accountable labor across specialized Workers without requiring any Worker to reveal its private model, prompt chain, or proprietary method.
Examples of Internet of Intelligence work
An Actor might fix a software issue and produce a receipt linking the prompt, code diff, tests, approvals, and deployment boundary.
Another Worker might buy inventory only if vendor, price, budget, jurisdiction, and approval policy match a published manifest.
A marketplace Worker might complete a paid service package where milestones, evidence, disputes, and settlement are handled as part of the workflow instead of patched on afterward by human trust.
A verifier Worker might inspect another Worker's output, compare it against an objective test or schema, and emit a receipt that determines whether payment settles.
Architecture links
The main IOI product surfaces are Hypervisor, Hypervisor Daemon, AI Worker Marketplace, and Service-as-a-Software. The IOI Roadmap connects these surfaces to implementation records and evidence links. Read What is Web4? for the plain-language action-layer thesis.
Developer resources live at developers.ioi.ai, with canonical protocol reference material at docs.ioi.network. Public source and release evidence is maintained through the IOI Foundation GitHub organization.
Papers and evidence
Read the IOI Technical Whitepaper for protocol architecture, deterministic machine authority, receipt-carrying agency, Worker routing, and settlement.
Read Mixture of Workers for the accountable labor market architecture.
Read Alignment Security and the Boundary of Machine Authority for the authority-bound safety thesis.
Read Deterministic Authority for Machine Action for the valid-action boundary around mutable machine actors.
About IOI Foundation
IOI Foundation publishes and maintains the Internet of Intelligence architecture through internetofintelligence.com, the canonical public domain for IOI. The foundation's work centers on Web4, verifiable machine labor, deterministic authority, receipt-carrying agency, and settlement infrastructure for autonomous software Actors.
FAQ
What is the Internet of Intelligence?
The Internet of Intelligence is the network condition in which independently governed systems exchange bounded, verifiable work under declared authority — an economy of accountable machine labor rather than a pool of shared models. IOI is the open operating stack for autonomous systems that do real work under real limits: AI agents and autonomous software that can act — spend, provision, file, operate — only inside the permissions their owner declares, and that produce a verifiable record of what they actually did. One governed system can run across many machines, sites, people, and devices while behaving as one accountable system with one history. Independently owned systems can also work together through AIIP, the interop protocol between autonomous systems — but only under terms both sides accept. IOI L1, an optional shared trust layer, exists for the few commitments that need public settlement; running an IOI system does not require it.
What does IOI stand for?
IOI stands for Internet of Intelligence: the open operating stack, published by IOI Foundation, for building and running autonomous systems that act within declared limits and produce evidence of what they did.
Is IOI shared or federated intelligence?
No. The Internet of Intelligence does not pool intelligence. Independently owned systems keep their models, data, and methods private — and still do accountable work for each other. What crosses the boundary is an agreement, the authority it grants, and proof of what was done. That is a cryptographic labor economy: machine work bound to declared authority, evidenced by receipts, and settled under terms both sides accepted. IOI's architecture uses a local-first, fractal blockchain topology so authority, rights, and evidence remain portable and independently verifiable across trust boundaries. Work stays at the edge; shared settlement is invoked only where independent rights, dispute resolution, reputation, or economic finality require a neutral trust root.
Is the Internet of Intelligence a telecom or 6G concept?
No. In network research, "internet of intelligence" sometimes names AI embedded in 6G-era telecom infrastructure, and elsewhere it can mean pooled model training or generic agent networks. Those readings optimize capacity — moving data faster, training better shared models. Capacity is not what is missing. Humanity already built an internet of intelligence once, for human intelligence, and its substrate was never pooled minds: it was identity, contracts, agency law, attribution, courts, reputation, and money. The machine version needs machine-speed equivalents — authority that is scoped and revocable, evidence of what was actually done, results that can be challenged, and settlement only when both sides accept. So the term names something wider than a network upgrade: the condition in which independently governed systems exchange bounded, verifiable work under declared authority. Faster networks and cooperative model training are workloads that run on such a substrate, not substitutes for it. IOI is built to implement that condition, and it is independent of any radio or telecom architecture.
What is a bounded autonomous system?
A bounded autonomous system is software that pursues goals and takes consequential action inside an explicit constitution: a declared rulebook covering who can authorize what, which policies apply, who its members are, what evidence it must produce, and how it recovers when something fails. A bounded system is useful entirely on its own, and its owner can keep it fully independent.
Can one IOI system run across multiple machines or sites?
Yes. One governed system can place work across execution nodes, verifiers, gateways, people, sensors, robots, and local controllers while keeping one identity, one authority model, and one record of what happened. Coordinating the members of one system is built into the stack; it does not require the cross-organization protocol.
When does AIIP apply?
AIIP is the interop protocol between separately owned autonomous systems, and it applies only at that boundary: two independently governed systems exchanging bounded work, evidence, and contribution under terms both sides accepted. Being discoverable or invited creates no authority and no obligation.
Is IOI L1 required?
No. IOI L1 is optional. It is a shared trust layer for commitments that genuinely need public settlement — selected registry, rights, assurance, or dispute needs — and it is offered only where demonstrated demand justifies it. An IOI system operates fully without it.
What does an enterprise retain with IOI?
Your ontology, approved memory, corrections, private evaluations, workflows, policies, evidence, and lineage. They stay inside your governed boundary and remain portable across model and provider changes, so models stay replaceable suppliers rather than the owners of your operational knowledge.
What is a Worker?
A Worker is the bounded labor actor inside an IOI system: it receives scoped authority, performs work, and produces receipts. The model behind a Worker is replaceable cognition supply — authority and accountability attach to the Worker, not the model.
What is verifiable machine labor?
Verifiable machine labor is autonomous work backed by evidence: receipts, approvals, state changes, and acceptance records that can be inspected, replayed, disputed, paid, or composed into later work. It is a primary application of the IOI stack, not the definition of the whole system.
Is IOI the same as Web4?
No. Web4 is the action layer of the internet — Read, Write, Own, Act. IOI is an operating stack for that layer: it makes autonomous action governable through explicit authority, policy, receipts, and optional shared settlement.
Who is building IOI?
IOI is published by IOI Foundation through internetofintelligence.com, the official canonical domain for the Internet of Intelligence.